
Manufacturers are facing a new paradox in the workplace: the confidence gap, as 78 percent of employees working in vendor payment feel confident that they can identify an AI-driven fraud attack. However, Trustmi's data found that 70 percent of employees rank typos, fonts or grammatical errors as their No. 1 warning sign – which AI-driven fraud is designed to circumvent.
Manufacturers have traditionally been prioritizing the efficiency of supplier, procurement and payment process but given these gleaming numbers, these teams need to rethink how they manage large supplier ecosystems. This is especially important as generative AI makes fraudulent communications increasingly legitimate and accurate and allows hackers to manipulate human trust.
The question they must be asking is not if an email looks licit but whether the request makes sense within the context of the business relationship.
Given this escalation, manufacturing leaders should be equipping their employees with the skills and technology to identify emerging threats. Employers cannot solely rely on employee vigilance, and they need protections built into workflows, especially payment systems.
For manufacturers, this confidence gap can have far-reaching consequences, as finance, procurement, operations and plant teams increasingly rely on digital communications to keep production moving and suppliers paid on time.
From Generic Training to Threat-Specific Security Awareness
Employees are increasingly aware that any external email or message could be fraudulent, with 40 percent reporting that they or a colleague has already been targeted by an impersonation attempt.
What they are missing are modern tools to identify a bad actor trying to slip through the crack and take advantage of their trust. Traditional phishing verifications tactics, such as looking for typos or fake email addresses that employees were trained to recognize years ago, are no longer sufficient ways for identifying threats, given that hackers are presenting perfectly polished resources with little to no errors thanks to AI tools.
A change request such as a supplier updating bank information or a vendor contact asking for an exception to the normal process may not raise any red flags but when various change requests come in at the same time, that should raise reasonable suspicion and reason to verify the request.
The ideal strategy is to give employees the tools to understand what situations call for them to pause and double check. Manufacturers don’t have to be fraud investigators but they need to know that delaying a payment or questioning a long-standing supplier relationship that feels even slightly out of status quo is expected.
This training can be very nuanced especially given that manufacturers' environments are dependent on trusted relationships. The familiarity that is built between manufacturer and supplier, vendors, and logistics partners is essential for the effectiveness and efficiency of operations. According to Trustmi’s data, 81 percent of employees would trust a payment request appearing within an existing email thread. And since manufacturers have been using email to foster long standing relationships, employees need to take a closer look at the context surrounding email communications.
This is where manufacturing leaders must look past a security training and focus on building a security first culture to align with evolving fraud prevention. One off or annual training will not equip teams to be prepared for the evolving threat landscape. What is most needed is security awareness programs that foster a culture of accountability. Generic security training won’t work, leaders need to implement tailored personalized programs that leverage real world examples from the work being done.
Red team and blue team training should reinforce these behaviors with attacks that manufacturers will most likely encounter, such as supply chain attacks, vendor network breaches, and phishing and credential theft. Employees need to be given concrete, customized solutions to combat each different type of threat.
While a security first culture is the first step, there are a few additional techniques and processes that should be added on top to ensure organizations can’t be breached and their networks are clean.
Strengthening Organizational Controls Against Fraud
While employee awareness is the first line of defense, it is most effective when reinforced by strong organizational controls. Proper vendor management and the adoption of tools and technologies can also help manufacturers combat fraud. These techniques, however, may still allow hackers to slip through the cracks and leave blind spots uncovered for attackers to exploit.
Because modern attacks arrive with documentation, context, and operational signals that appear legitimate, traditional controls often fail to detect them. These attacks rely on a single tactic: impersonating a trusted sender using look-alike domains or compromised email accounts. And 39 percent of attacks used fake financial documents to legitimize the requests. Attackers combine fake invoices with fabricated email conversations so the payment request appears to follow an established business exchange.
Modern tools can track changes, and flag suspicious activities to reduce the risk of BEC through compromised or impersonated vendor accounts. Other technology solutions that should be put in place to combat fraud are AI-driven email filters and anomaly detection systems, to monitor for signs of BEC and other email-based threats. Manufacturers must embed these protections into ERP, procurement and accounts payable workflows so suspicious payment requests can be identified before funds are released.
AI is changing what fraud looks like and manufacturers need to be modernizing the signals employees need to be trained to recognize and independently verify when they realize there may be suspicious activity taking place. Manufacturers should focus on where risk is most likely to appear including changes to supplier information, unusual payment requests, and exceptions to standard approval processes.
As payment and procurement processes become more digital and automated, the organizations best positioned to manage fraud will be those that minimize business disruption and downtime from fraud attacks by combining informed employees with technology and processes that make unusual activity easier to recognize before a payment is released.






















