Global Payment Fraud: How to Protect Cross-Border Transactions
· · 7 min read
Most cross-border payment fraud is not a technical breach. It is someone impersonating an executive or a supplier and persuading a member of staff to authorise a transfer. That is business email compromise, and it works because the request looks legitimate and the person receiving it has no easy way to check. Payroll is a particular target, because the payments are large, regular and routine enough that an unusual one can pass unnoticed.
The controls that stop it are unglamorous: verification out of band, multi-factor authentication, and limiting who can change bank details. Last updated September 2026.
| Attack | How it works | What stops it |
|---|---|---|
| Business email compromise | Impersonated executive requests a transfer | Verify by a second channel, always |
| Supplier bank change | Fake notice of new account details | Call the known number, not the one in the email |
| Payroll diversion | Employee bank details altered before payday | Change controls and confirmation to the employee |
| Phishing | Credentials harvested, then used | MFA, so credentials alone are not enough |
| Deepfake authorisation | Cloned voice or video approves a payment | Never authorise on a single verbal instruction |
Cross-border payments are a natural target. The amounts are large, the recipients are unfamiliar, and the people approving them are often working across time zones without an easy way to check a request in person.
The Federal Trade Commission reported that consumers alone lost more than $12.5 billion to fraud in 2024, a sharp rise on the previous year. Business losses are reported separately and are not in that figure, but the trend is the same and the techniques overlap.
The case worth knowing is Orion S.A., which lost approximately $60 million in August 2024 after an employee was deceived into making a series of wire transfers. No system was hacked. A person was convinced.
Why are global businesses targeted?
Complexity hides things
Every country has its own rules on payments, tax and reporting. When your finance team is reconciling several jurisdictions, an unusual transaction looks less unusual. Fraud often surfaces weeks later during reconciliation rather than at the moment it happens.
Distributed teams cannot check easily
When approvals travel by email between people in different time zones who rarely meet, the informal checks that catch fraud in a single office are missing. Someone cannot walk over and ask.
The transfers are large and routine
Payroll runs are substantial, regular and expected. That is precisely what makes an inserted or altered payment hard to spot.
This is one reason payroll data security matters as much as payment security. We cover the wider picture in common payroll processing challenges and how to pay a global workforce.
How do you prevent payment fraud?
1. Verify by a second channel
The single most effective control. Any request to move money or change bank details gets confirmed by a different route than the one it arrived on, using a number you already hold rather than one in the message.
This stops business email compromise regardless of how convincing the email is, and it stops deepfake voice requests too.
2. Control bank detail changes
Most payroll diversion starts with an altered account number. Require confirmation directly with the employee, restrict who can make the change, and log every one.
3. Multi-factor authentication everywhere
Stolen credentials are common and cheap. MFA means they are not sufficient on their own.
4. Train people on what the attack looks like
Not generic security awareness. Show your finance and HR teams real examples of executive impersonation, urgency pressure and supplier change requests, because those are what they will actually receive.
5. Monitor for anomalies
Automated detection that flags unusual payees, amounts or timing before a payment clears rather than after.
6. Audit regularly
Review payment systems, payroll processes and access permissions on a schedule. Access accumulates quietly as people change roles, and dormant permissions are a common route in.
What should you look for in a payroll partner?
- Encryption and authentication. End-to-end encryption in transit and at rest, with strong authentication on every account.
- Multi-country experience. Familiarity with payment rules and banking practice in your specific markets, not a general claim of global coverage.
- Real-time visibility. The ability to see transactions as they happen, since fraud found at month end is fraud already paid.
- Named support. Someone who knows your account and can be reached quickly. Response time matters more than anything else once a fraudulent payment is in flight.
Whether a provider owns its entities or works through local partners also affects who is handling your money, which we cover in EOR operating models.
For more on evaluating providers: how to choose the right global payroll software.
How does Global Expansion protect payments?
Our data security and privacy standards cover the payroll platform end to end.
- Infrastructure. Hosted on Microsoft Azure, with scalable global hosting and the protections that come with it.
- Access control. Two-factor authentication, role-based permissions so people see only what their job requires, and SAML 2.0 single sign-on.
- Monitoring. Transactions monitored for suspicious activity, with support available around the clock when something needs checking quickly.
- Certification. ISO 27001 accredited, with independent third-party security audits.
- Backup. Payroll data backed up automatically, so records survive a system failure.
Work with Global Expansion
We run global payroll and act as Employer of Record across 214 countries and territories, with the controls above applied to every payment.
Frequently asked questions
What is business email compromise?
An attacker impersonates an executive, supplier or colleague by email and requests a payment or a change of bank details. There is usually no technical intrusion at all. It works through authority and urgency, which is why technical controls alone do not stop it.
How do I verify a payment request is genuine?
Confirm it through a different channel than the one it arrived on, using contact details you already hold rather than any supplied in the message. If an email asks for a transfer, phone the person on their known number. This single habit prevents most of these attacks.
Are deepfakes actually used in payment fraud?
Yes. Voice cloning and video are now used to impersonate executives authorising transfers, and the quality is good enough that recognising the voice is not sufficient verification. Treat a verbal instruction as a request to be confirmed, not as an authorisation.
What is payroll diversion fraud?
An attacker changes an employee's bank details shortly before payday so the salary is paid to an account they control. The employee reports not being paid, by which point the money has gone. Controlling who can change bank details, and confirming changes with the employee, is the defence.
Who is liable if a fraudulent payment is made?
Usually the business that authorised it, since the payment was technically legitimate. Banks are rarely obliged to reimburse authorised push payments, though rules differ by country. This is why prevention matters more than recovery.
Does using an EOR reduce fraud risk?
It can, because payments run through established local banking relationships with verification built into the process, rather than ad hoc transfers to accounts your team has not paid before. It does not remove the need for your own controls on requests that originate inside your company.
Subscribe to our blog
Receive the latest GX blog posts and updates in your inbox.

