What ACH fraud is
ACH fraud is a payment through the ACH network that the account owner did not truly agree to. It comes in two shapes.
- Money pulled out. Someone uses your routing and account numbers to send a debit you never authorized.
- Money you were tricked into sending. You, or someone using your online banking, send a credit to a criminal’s account.
The ACH rules have changed in recent years to address the second kind.
The main types of ACH fraud
| Type | How it works | Who is hit |
|---|---|---|
| Unauthorized debit | A debit is sent against your account with no authorization | Any account holder |
| Business email compromise | A criminal poses as a supplier or a manager by email and asks you to pay a new bank account | Businesses that pay invoices |
| Vendor impersonation | A fake “we have changed banks” notice redirects real invoice payments | Accounts payable teams |
| Payroll diversion | A fake request changes an employee’s direct deposit details | Employers and employees |
| Account takeover | A criminal gets into your online banking and sends ACH credits from your account | Businesses that originate payments |
Nacha groups several of these under one name: payments made under false pretenses. Its definition is a payment induced by someone misrepresenting their identity, their authority to act for another person, or the ownership of the account to be credited. Nacha says this covers business email compromise, vendor impersonation and payroll impersonation.
The definition does not cover disputes about fake or poor-quality goods.
How big the problem is
- FBI. The Internet Crime Complaint Center’s 2025 report puts losses from business email compromise at $3.05 billion for the year, up from $2.77 billion in 2024. The report lists wire and ACH transfers together as a top reported transaction type.
- AFP. In the 2026 AFP Payments Fraud and Control Survey, 76% of US organizations reported attempted or actual payments fraud in 2025, and 74% were affected by business email compromise. Checks were the most targeted payment type, named by 58%. ACH debits followed at 30% and wires at 25%.
Protect the money you send
The impersonation scams above all rely on a changed bank account. These steps cost almost nothing.
- Call back on a known number. When a supplier or employee asks to change bank details, phone them on a number you already had. Nacha’s advice is to double-check by calling the person directly using a known number. Never use the number in the request.
- Get details on a signed form. A vendor ACH form or direct deposit form gives you a record to compare against.
- Test new details. Send a prenote or a small first payment before a large one.
- Separate the jobs. If you can, have one person set up a payee and another approve the payment. Ask your bank whether its system supports a second approver.
- Protect online banking. Use the security tools your bank offers, and do not share logins.
- Use the required descriptions. Since March 20, 2026, wage payments must carry the description PAYROLL. Nacha says this rule is intended to reduce fraud involving payroll redirection.
Protect your account from debits
A business account has a short window. The bank’s return must reach the sender’s bank by the opening of business on the second banking day after the debit settled. That leaves about one banking day to spot the debit and tell your bank. Ask your bank for its cut-off time. After that the bank cannot simply send it back.
- Check your account every business day. This is the single most useful habit.
- Ask for an ACH debit block or filter. Chase describes its ACH Debit Block as letting a client block all ACH debits or allow some, by company ID. Wells Fargo’s ACH Fraud Filter has a “stop” service that stops all ACH debits except those you pre-authorize, and a “review” service that shows you each one for a pay or return decision.
- Keep a list of approved company IDs. A filter works from the company ID of each biller you allow.
- Use a separate account for incoming payments, with debits blocked, if your bank offers it.
A personal account has more time. Under Regulation E, a person can report an unauthorized transfer within 60 days of the statement that shows it. If the 60 days have passed, they should still tell their bank. See how to stop an unauthorized ACH withdrawal and is ACH safe?
If you collect payments from customers
A business that originates debits has duties of its own.
- Get a real authorization. A signed ACH authorization form is your proof if a customer says the debit was not authorized.
- Validate accounts for online debits. Since March 19, 2021, a business taking debits that consumers authorize online must check the account the first time it uses an account number. See ACH account verification.
- Protect stored account numbers. Non-bank originators that send more than 2 million ACH payments a year must make stored account numbers unreadable, by encryption, truncation, tokenization or a similar method. Smaller businesses should follow the same practice.
- Watch your return rate. Nacha’s level for unauthorized returns is 0.5% of debits.
The Nacha rules that changed
| Date | Rule |
|---|---|
| March 19, 2021 | Account validation required for online (WEB) debits |
| June 30, 2022 | Data security rule reaches originators above 2 million payments a year |
| October 1, 2024 | Receiving banks may return a payment they think is fraudulent. Sending banks may ask for a return for any reason |
| March 20, 2026 | Fraud monitoring, phase 1, for sending banks and the largest originators and receiving banks. PAYROLL and PURCHASE descriptions required |
| June 19, 2026 (June 22 in practice, as June 19 is a federal holiday) | Fraud monitoring, phase 2, for everyone else |
The fraud monitoring rule applies to every business that sends ACH payments, and to every bank. In plain words: you need steps, sized to your risk, for spotting payments that were started by fraud. Nacha’s wording is “risk-based processes and procedures reasonably intended to identify” such payments. Three points are worth knowing.
- The duty applies to the extent relevant to the role you play. A small business is not expected to do what a bank does.
- Checking each payment before it is processed is not required.
- You must review your processes at least once a year.
The wording asks for processes and procedures, not for a named product. For a small business, written steps such as “call back before changing bank details” and “review the account daily” are a sensible start. Ask your bank what it expects.
What to do if fraud happens
Speed matters more than anything else.
- Call your bank at once. Use the number on its website or your card.
- For a debit you did not authorize, ask the bank to return it as unauthorized. A business should do this the same day, because the bank’s deadline is the opening of business on the second banking day after settlement. A person signs a Written Statement of Unauthorized Debit.
- For a credit you sent to a fraudster, ask your bank to request a return from the receiving bank. Since October 1, 2024, a sending bank may request a return for any reason. The receiving bank must reply within ten banking days, but it does not have to return the money.
- Do not rely on a reversal. Reversals are only for the sender’s own errors, such as a duplicate or a wrong amount.
- Report it to the FBI’s Internet Crime Complaint Center at ic3.gov, and keep every email and record.
- Change passwords and review who has access to your banking.
Receiving banks have a tool too. Since October 2024 a bank that suspects a payment is fraudulent can return it using code R17, and it may delay making a suspicious credit available.
Common mistakes
- Trusting an email that changes bank details. Call first, on a number you already had.
- Checking the account once a month. A business has about one banking day to report an unauthorized debit.
- Leaving ACH debits open on every account. Ask for a block or a filter.
- Keeping bank details in email or an open spreadsheet. Store them where few people can reach them.
- Thinking a reversal will fix fraud. It is a tool for errors and is never guaranteed.