Posted: September 08, 2026 | Updated: September 09, 2026 at 3:58 PM
A finance team can have a clean invoice of approved purchases through the appropriate channels, and it is still possible for the payment to end up in the bank account of a fraudster instead of the supplier’s bank account. This risk is known as vendor impersonation fraud and has grown large enough to affect the market.
On August 26, 2026, Basware agreed in a binding deal to buy Trustpair, a company that stops fraudulent payments. Basware develops software to help a company process an invoice from receipt to approval. Trustpair examines bank accounts of suppliers to confirm that the accounts are legitimate. Putting the two together provides something that is novel in the market: an assurance that covers the complete process of an invoice and payment.
There are many good reasons for the timing of this acquisition. Criminal groups are using artificial intelligence to make vendor fraud at scale possible. Regulatory bodies are beginning to address the problem. Finance teams have realized that an immaculate invoice has no value if payment is made to a fraudulent account.

Vendor impersonation fraud occurs when a fraudster poses as a regular supplier. The objective is for a business to send payment to an account controlled by that fraudster. Most often, this type of fraud is accomplished through an email request for payment.
One technique is for a fraudster to register a domain name that looks like a regular vendor’s domain, except for one or two substitutions. Another technique is for a fraudster to hack into a vendor’s email account and then wait for the opportunity to send a request to the vendor’s finance department to update payment information.
This type of payment request fraud falls under business email compromise (BEC) scams. BEC is the broad term used to describe a scheme in which a fraudster uses email requests to persuade an employee to transfer funds or company data to the fraudster. Vendor impersonation is the most damaging version of BEC because it affects the accounts payable process.
There are clear patterns to bank account switching scams. Emails to team members in finance purport to be from a reliable source. The sender states that they have switched banks. The email instructs the team to update the supplier account information in the file with a new account number and routing number. An invoice, which may or may not be a new one, is often attached to the email. The fraudster, posing as a supplier employee, may even place a follow-up call.
After the new bank account information is entered, payments to the supplier are transferred to the fraudster. The payment amount is often the amount owed to the supplier, and the invoice may even be genuine. The fraud is often detected several weeks later during the reconciliation process when the real supplier calls to inquire why the invoice was not paid.
The most important control to prevent this type of fraud is bank account validation. A validated bank account is one that has been confirmed to be a supplier’s account by a source outside of the email or the invoice. This confirmation can be a verification phone call, a callback to a verified contact, or even an automated account ownership confirmation. The most important thing is to not use the same communication channel to confirm the bank account change request.
The extent of this issue is now well known. Each year, the FBI’s Internet Crime Complaint Center, IC3, logs Business Email Compromise (BEC) reports. Its 2025 Internet Crime Report shows a considerable increase in the number of BEC reports and losses reported.

Source: FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report.
In 2025, BEC complaints reached 24,768, a 15% increase from 2024. Reported losses increased from $2.77 billion to $3.05 billion. Yet, these numbers only reflect the victim reports. It’s likely much higher.
Other studies also reflect the same findings, but from different perspectives. One study estimates that 8% of revenue is lost to fraud on average. Another study by the Association of Certified Fraud Examiners shows that over the past two years, 75% of anti-fraud professionals witnessed more cases of BEC fraud using generative AI. In contrast, only 7% of anti-fraud professionals felt more than moderately prepared to catch or stop generative AI fraud. This clear shift of increasing BEC fraud with insufficient countermeasures has driven software consolidation.

Basware uses the acquisition of Trustpair to fill that gap. This deal joins two capabilities that up until now have resided in different systems: confirming that the invoice itself is genuine, and confirming that the money lands with the right supplier.
Basware is a leader in software that manages the invoice lifecycle. The company works with over 6,500 clients including DHL, Heineken, and NBC Universal Media, and has developed invoice control systems over the past forty years. For Jason Kurtz, the CEO of Basware, the acquisition of Trustpair has a lot to do with how finance teams run into issues with sending money to an account that isn’t the supplier’s. Invoices are correct, but money can still go to wrong accounts. Trustpair adds to Basware’s fraud detection and duplicate detection tools and allows Basware to have greater control over the payment process.
Trustpair got its start in 2017 and has offices across New York, London, and Paris. Its only focus is stopping payment fraud. Its software verifies the authenticity of a supplier’s bank account at three stages. These stages include adding a new supplier, changes to supplier account information, and right before any payment goes out. The software protects over 600 organizations, which includes many companies in the Fortune 500. Trustpair’s software also carries ISO 27001 and Type II SOC 2 certifications.
Baptiste Collot, Trustpair’s CEO, states that Trustpair’s software was created to combat fraud and that approving a valid invoice is futile if the funds still land in a fraudster’s account. As part of the acquisition, Trustpair is set to keep running under its current brand and structure, so customers on SAP, Oracle, or Coupa can keep their current setup and stay protected.
Trustpair’s acquisition by Basware allows both companies to implement machine learning and artificial intelligence technologies to combat payment fraud. Trustpair is the latest acquisition made by Basware in the last three years, after buying Redmap, Glantus, and AP Matching in the same period. The deal should close before 2026 ends.

Regulators no longer treat fraud in supplier payments as a private business risk. In the U.S., 2026 Nacha rule revisions mandate specific protections for ACH payments. Businesses must implement controls to identify payment authorization fraud, including business email compromise payment fraud. Similar changes are evident in the UK and the EU, where instant payment schemes offer little time to recover fraudulently transferred funds.
This change will impact any business, including small and medium enterprises, which pay their suppliers electronically. Payment-network rules and local laws dictating that businesses must implement control systems vary from state to state. Therefore, businesses must verify the control systems implementation requirements with a payment compliance professional or attorney to avoid legal implications of non-compliance.
The numbers confirm what regulatory changes indicate: now the risk is the new standard, not the exception.

Source: 2026 Payments Fraud and Control Survey Report, underwritten by Truist, AFP.
According to the Association for Financial Professionals’ 2026 survey, 76% of U.S. organizations experienced attempted or actual payments fraud in 2025, and 74% of those organizations were affected by business email compromise. Paper checks were involved in 58% of fraud attacks, and show the use of payment rails, whether digital or not, will keep being exploited as digital fraud increases. Most concerning, only 17% of organizations use AI against payment fraud, while fraudsters increasingly use AI against them.
The survey also reported that classic executive email scams are declining while vendor and third-party impersonation scams are increasing. Finance teams are increasingly able to identify a fake CEO email. Because of this, fraudsters are moving away from executive scams and are now increasingly using supplier scams.
The Basware-Trustpair merger is not something finance teams can wait for. There are controls finance teams can implement now. Never put a request to update the bank details of a supplier through on the strength of the email alone. Call the supplier back using the phone number you have on file, never the number in the request. Before the first payment, new suppliers should undergo an independent account-ownership check. Require two approvers for a payment that is significantly larger than usual or unusual in nature.
Payments staff should be trained to identify scam vendor payment requests such as changes to bank details, last-minute requests to process payments, and urgently sending payments outside the normal protocols. None of these protocols need new technology. They need an organization-wide practice of consistency and willingness to delay, as scams aim to rush you.
Vendor impersonation scams went from being a minor issue in accounts payable to a full-blown boardroom concern. The FBI’s data shows year-on-year climbing losses in BEC. Regulators and payment networks are writing new rules with the assumption that fraud will occur, and that businesses will be required to detect the fraud. The Basware-Trustpair deal also shows that large enterprise software vendors are now integrating payment confirmation services with invoice management software. The bottom line is that any business which pays suppliers, regardless of size, must confirm the payee account for each invoice.
Vendor impersonation fraud happens when a criminal emails a business pretending to be a real vendor and tricks the business into sending the criminal money.
It begins with what looks like a normal email to a business account from a normal supplier, asking accounts payable to enter new bank details so the next payment can be made.
Basware decided to buy Trustpair because they wanted to extend the controls on invoices beyond invoice approval and into the payment.
Bank account validation checks, independent from an e-mail or invoice, if a bank account actually belongs to the supplier being paid.