Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Vendor Payment Fraud topic

No spam. Unsubscribe anytime.

NC Pro internal audit warns recipients about rising vendor‑payment fraud and deep‑fake scams

2134955 · January 21, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Barbara Baldwin, internal audit director in the Office of Budget and Management, warned meeting attendees about a rise in vendor‑payment fraud—including vendor email compromise and AI deep‑fake schemes—and advised verification steps and immediate reporting to financial institutions and federal authorities.

Barbara Baldwin, internal audit director at the Office of State Budget and Management, warned participants that vendor‑payment fraud and sophisticated scams have increased and urged recipients and grant managers to adopt verification policies and training.

Why it matters: vendor‑payment fraud can cause large financial losses to state agencies, grantees and vendors. Baldwin described recent examples, explained common tactics, and gave step‑by‑step guidance attendees can use to reduce risk.

Examples Baldwin described

- Vendor email compromise and social engineering: attackers penetrate vendor email accounts (often via phishing), monitor correspondence and then send convincing change‑of‑payment requests that appear to come from the vendor. Baldwin gave a documented example in which a recipient’s accounts payable staff received an email appearing to be from a vendor pleading for help and asking for the next payment to be sent to a new bank account; the fraudulent message referenced a specific payment amount ($2,448,391) and details the attackers likely learned by reading intercepted email traffic.

- Deep‑fake meetings and personas: Baldwin described a case reported in the news where an accounts‑payable technician attended a virtual meeting that appeared to include the organization’s CFO and other employees and then authorized a $25,000,000 wire transfer. Baldwin said the meeting attendees were deep‑fake personas created with artificial intelligence; all participants were fraudulent.

Practical prevention steps Baldwin recommended

- Verify bank changes via a trusted fourth source: use the vendor master list, a contract phone number, the vendor’s W‑9, or another recorded contact rather than relying on the contact information provided in the suspect email or website. Do not call or click links embedded in the suspect message.

- Use a strict verification policy: require multi‑factor verification (for example, a phone call to a known, trusted number or in‑person approval) before changing vendor banking or mailing information, and do not allow staff to approve changes by email alone.

- Train staff and subrecipients: Baldwin said all staff with access to vendor information and accounts payable should be trained on these scams and that grantees and subrecipients should receive the same training.

- Act immediately if victimized: contact the financial institution immediately to attempt recovery; notify the grantor (which may trigger a state investigative response such as SBI) and report the incident to the FBI (Baldwin described wire fraud as a federal offense that the FBI investigates).

Resources and reporting

Baldwin said she would share links to FBI resources and other guidance in the meeting chat and urged attendees to copy and distribute those resources to accounts payable teams and grantees. She emphasized that the speed of action is critical to recovery and that victims should not delay reporting.

Attribution

Direct explanations and examples above are attributable to Barbara Baldwin, internal audit director, Office of State Budget and Management, who delivered the vendor‑payment fraud warning during the meeting.