AI Agent Payment Fraud
The agent did everything you asked. A web page chose where the money went.
What Is AI Agent Payment Fraud?
An AI agent acts with your permissions, your saved card and your inbox, and it believes what it reads. Your assistant is asked to book a hotel, reads an instruction planted on the hotel's own page, and pays a site nobody chose while you are still reading the merchant line. You trace the run log back to the step that turned it, take payments off standing approval, and ask again: same page, same wrong merchant, and this time the sheet waits for you.
What You'll Learn in AI Agent Payment Fraud
- Understand that an agent acts with your permissions, your saved card and your inbox, so its mistakes are made as you
- Recognise indirect prompt injection: text planted on a page the agent visits is read as instructions, and is invisible to the person
- Read the run log before approving rather than after a charge appears, because every step after the injected one looks correct
- Check the merchant on an approval sheet, since that is the field the agent chose and you did not
- Keep payment permissions on ask every time, because standing approval turns the one human check into a countdown
- Use the approved booking route, where no card is in the flow for an attacker to redirect
- Report a payment that has already left, because the merchant name and the run log are what let Finance dispute the charge and get the domain blocked
AI Agent Payment Fraud — Training Steps
-
A Charge Nobody Recognises
You are at your desk with a congress in Oslo to book. Finance has just mailed the whole field team about a colleague's expense claim.
-
Six Steps, One Wrong
The run log is the whole story. It was on his phone the entire time and nobody had a reason to look at it.
-
Your Own Trip
You have the same app, the same corporate card saved in it, and the same congress to get to. Taskwyn is on your phone with Payments set to Allow, which is how it was set up on day one.
-
Ask It to Book
This is the request anyone would make, phrased the way anyone would phrase it. Nothing about it is careless.
-
Watching It Work
The Tasks tab shows the run as it happens. The first three steps are exactly what you asked for.
-
It Keeps Going
Two more steps arrive. The assistant is not confused and it is not malfunctioning. It is doing what the page told it to do.
-
It Asks, and Starts Counting
Here is the one moment a person is in the loop. Payments is set to Allow, so the sheet is not really asking. It is announcing.
-
Before You Tap
-
It Does Not Wait
You are still reading the merchant line. Payments is set to Allow, so the sheet was never really asking, and the clock runs out.
-
Twelve Hundred and Forty Euro
It is gone. Not pending, not held for review: a card payment to a merchant nobody at Norlanby has ever dealt with, made with your permission because you gave that permission once, on setup day.
Security Framework Coverage
OWASP LLM Top 10
- LLM01:2026 Prompt Injection
- LLM03:2026 Excessive Agency
CWE
- CWE-1427 Improper Neutralization of Input Used for LLM Prompting
MITRE ATT&CK
- T1657 Financial Theft
CIS Controls
- CIS 14.2 Train Workforce Members to Recognize Social Engineering Attacks
- CIS 14.4 Train Workforce on Data Handling Best Practices
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
EU AI Act
- Art. 4 AI literacy