eCommerceNews US - Technology news for digital commerce decision-makers
United States
Trustmi survey finds confidence gap in payment fraud

Trustmi survey finds confidence gap in payment fraud

Thu, 23rd Jul 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Trustmi has released a survey on employees' ability to identify payment fraud at work, highlighting a gap between workers' confidence and the tactics they use to assess suspicious requests.

The survey of 1,000 U.S. employees involved in payment-related workflows found that 78% were confident they could identify a fraudulent payment request. Yet 70% cited typos, fonts or grammatical errors as their main warning sign, even as AI-generated impersonation makes fraudulent messages harder to distinguish from legitimate business communications.

That mismatch runs through much of the research. While respondents recognised that AI is changing the fraud landscape, many still relied on signals more commonly associated with older phishing attempts than with subtler executive impersonation or payment diversion scams.

Trust in familiar channels also emerged as a weak point. Some 81% of employees said they would be likely to assume a payment request was legitimate if it appeared in an existing email thread, suggesting messages embedded in routine workflows may face less scrutiny than standalone requests.

Respondents also identified other factors that made a payment request seem trustworthy. A third cited an existing email thread as the strongest trust signal, while 30% said an executive's work email address would reassure them and 29% said references to real company projects would do the same.

Confidence gap

The youngest workers surveyed appeared especially likely to depend on traditional warning signs. Among Gen Z respondents, 82% said grammar mistakes were a top indicator of fraud, compared with 50% of Baby Boomers.

At the same time, employees broadly acknowledged that new forms of deception are becoming harder to detect. The survey found that 84% believed AI-generated voice, video and message impersonation would make workplace fraud more difficult to spot.

Exposure to attempted fraud was not uncommon. Four in 10 respondents said they or someone at their company had experienced an impersonation attempt, including 22% who said they had been targeted personally.

Shai Gabay, Co-founder and Chief Executive Officer of Trustmi, said the findings showed many organisations were still relying too heavily on training designed for an earlier generation of attacks.

"People have been trained to spot the obvious signs of phishing, but today's payment fraud is designed to blend into trusted business communications," said Shai Gabay, Co-founder and Chief Executive Officer of Trustmi. "When employees are overly confident in their ability to spot fraud, organisations are left exposed to sophisticated AI-powered attacks designed to appear completely legitimate. To keep pace with evolving fraud tactics, organisations cannot rely solely on employee vigilance. They need protections built into payment workflows to catch fraud before money moves."

Layered controls

The research suggests many employees have already reached a similar conclusion about existing safeguards. Nearly four in five respondents, or 79%, said email filters alone were not enough to stop modern workplace fraud.

Asked what additional protections they wanted, 52% called for automated fraud detection, 50% wanted stronger email security and 49% said they needed more fraud-specific awareness training. Another 35% wanted real-time payment workflow alerts, while 34% wanted better visibility into vendor or payment changes.

These responses suggest employees are looking beyond the inbox to controls embedded in payment and finance processes. The survey focused on staff who handle invoices, vendor communications, payment approvals and finance systems, roles often targeted when attackers seek to divert funds or alter payment details.

The findings also suggest routine workplace behaviour can create openings for fraud. Requests that mirror ordinary communications, arrive through known channels or reference real business activity may be more likely to pass initial checks, particularly if employees have been trained to look mainly for spelling errors, strange formatting or unfamiliar addresses.

Training also appears uneven. According to the survey, 61% of respondents said their employer provides fraud training rarely or not at all. That may help explain why traditional warning signs still dominate employees' thinking even as AI tools make forged messages more convincing.

Trustmi said it protects more than USD 240 billion in payments annually and has helped prevent more than USD 1 billion in fraud and USD 5 billion in payment errors. The company was founded in New York in 2021.