Stay connected
Subscribe to our corporate payments blog to stay on top of payment innovations.
We’re halfway through the year — a good moment to pause and ask a simple question: is your payment process actually working for you, or are you just working around it?
For a lot of finance teams, the answer sits somewhere in between. Payments get made, invoices get paid, month-end closes eventually. But “functional” and “optimized” aren’t the same thing, and the data suggests the gap between the two is wider — and riskier — than most businesses realize.
Here’s what a midyear look at the numbers says, and what it might mean for your payment strategy for the rest of 2026.
According to the 2026 AFP Payments Fraud and Control Survey Report, more than three-quarters of U.S. organizations (76%) experienced attempted or actual payments fraud in 2025.
That’s not a niche problem affecting a handful of unlucky companies. And the survey, which polled hundreds of treasury practitioners at U.S. organizations, points to one payment method as the clear outlier when it comes to risk.
If your business is still leaning on paper checks for supplier payments, this is the stat to sit with: checks remain the payment method most frequently impacted by fraud, with 58% of organizations reporting check fraud in 2025 — outpacing both ACH debits (30%) and wire transfers (25%).
What makes this especially notable is that checks are widely — and incorrectly — perceived as one of the safer payment methods. The AFP survey has tracked this gap for a decade, and the conclusion doesn’t change: the payment method a lot of businesses default to out of habit is the one fraudsters target most.
And yet, checks aren’t going away on their own. Even though checks are the payment method most frequently affected by fraud, 72% of organizations using checks plan to continue using them for the foreseeable future, with 68% of those organizations citing vendor requirements as the reason.
That last point is worth pausing on. A lot of businesses aren’t choosing checks because they’re the best option — they’re stuck with them because switching feels harder than it is.
Checks aren’t the only vulnerability. About three in four organizations (74%) were affected by business email compromise in 2025 — a significant increase from 2023 and 2024.
BEC scams are effective precisely because they don’t look like fraud. A fraudster impersonates a vendor or executive, requests updated banking details or an urgent payment, and the request moves through your normal process because it looks legitimate. In one case detailed in the AFP survey, a fraudster infiltrated a vendor’s email account and sent convincing, properly formatted requests to update banking details — and the payment was initiated before anyone caught it.
That’s the uncomfortable truth about most payments fraud today: it doesn’t look like a hacked system. It looks like a normal invoice.
Fraud isn’t just a security headline — it hits the bottom line directly. Financial losses from fraud were reported by 48% of organizations with revenue under $1 billion, and by 66% of organizations with revenue exceeding $1 billion.
And smaller organizations don’t get off easy just because they’re targeted less often. While smaller firms face fraud less frequently, they lack the recovery infrastructure of larger firms and are therefore much more likely to absorb the full financial loss of a successful fraud attack. In other words: a mid-size business without a treasury team behind it often has fewer resources to catch fraud early — and fewer options to recover funds after the fact.
You might expect AI to already be the standard fraud-fighting tool. It isn’t. Just 17% of organizations currently leverage AI to combat payments fraud, even though the ones that do report real benefits: enhanced efficiency in fraud reporting (49%), improved detection of deepfake technology (45%), and real-time identification capabilities (43%).
That gap between adoption and effectiveness is a signal in itself — most businesses are still relying on manual review and legacy controls to catch fraud that’s getting more sophisticated every year.
If you’re doing your own midyear review, here are the questions worth asking:
The clearest takeaway from this year’s data: sticking with checks because switching feels inconvenient is a bigger risk than the inconvenience itself. Virtual cards address the exact vulnerability checks create. Instead of a static account and routing number that’s exposed on every transaction — and printed right on the document — a virtual card generates a unique, single-use number for each payment. There’s no reusable account data for a fraudster to intercept, alter, or exploit later.
Virtual cards also close the BEC gap in a meaningful way: because payments are tied to specific transactions with built-in spend limits and vendor restrictions, a fraudulent banking-detail change request has a much smaller blast radius. And unlike checks, virtual card transactions come with real-time visibility, so a suspicious payment is easier to catch before it clears — not after.
If a midyear look at your payment process turned up more risk than you’d like, the good news is that closing the gap doesn’t require ripping out your entire AP system. Moving supplier payments to virtual cards is one of the more straightforward ways to cut fraud exposure — and it comes with the added upside of earning rebates on the spend you’re already generating.
Halfway through 2026, the data is clear: payments fraud isn’t slowing down, checks remain the biggest point of exposure, and most businesses are still under-equipped to catch the fraud that’s already targeting them. A midyear check-in is the right moment to ask whether your payment process is actually protecting you — or just getting by.
How common is payments fraud for U.S. businesses in 2026?
According to the 2026 AFP Payments Fraud and Control Survey, 76% of U.S. organizations experienced attempted or actual payments fraud in 2025.
Which payment method is most vulnerable to fraud?
Checks remain the payment method most frequently impacted by fraud, with 58% of organizations reporting check fraud in 2025 — more than ACH or wire fraud.
Why do businesses keep using checks if they’re the riskiest payment method?
Most organizations that continue using checks (72%) plan to keep doing so, primarily because of vendor requirements (cited by 68%), not because checks are actually safer.
What is business email compromise (BEC), and how common is it?
BEC is a scam where a fraudster impersonates a vendor or executive to redirect a payment or change banking details. It affected 74% of organizations in 2025, a significant increase from prior years.
How do virtual cards reduce payment fraud risk?
Virtual cards use a unique, single-use number for each transaction instead of a static, reusable account number. This limits what a fraudster can exploit even if a number is compromised, and pairs with spend limits, vendor restrictions, and real-time visibility that checks simply don’t offer.
Explore how WEX solutions can help you gain efficiencies, cut costs, and generate revenue.
Contact us to get started
For more insights and updates on corporate payments, check out:
Learn more about how WEX payment solutions can be tailored to your business, so you can accelerate and streamline operations while creating lasting growth and success for your organization.
The information in this blog post is for educational purposes only. It is not legal or tax advice. For legal or tax advice, you should consult your own legal counsel, tax, and investment advisers.
Copyright ©2026 WEX Inc. All rights reserved. The information in this document is subject to change without notice.
Subscribe to our corporate payments blog to stay on top of payment innovations.