ACH fraud prevention

What ACH fraud is, how the common scams work, and the steps a small business can take to prevent it.

By the ACH Forms team. Checked against 17 sources. Last reviewed .

Short answer

ACH fraud is an ACH payment that the account owner did not authorize, or was tricked into sending. To protect a business: check your accounts every day, ask your bank for an ACH debit block or filter, and confirm any change to bank details by calling a number you already know. Act fast. The bank must send an unauthorized debit on a business account back by the opening of business on the second banking day after it settled, so report it the day you see it.

What ACH fraud is

ACH fraud is a payment through the ACH network that the account owner did not truly agree to. It comes in two shapes.

  • Money pulled out. Someone uses your routing and account numbers to send a debit you never authorized.
  • Money you were tricked into sending. You, or someone using your online banking, send a credit to a criminal’s account.

The ACH rules have changed in recent years to address the second kind.

The main types of ACH fraud

TypeHow it worksWho is hit
Unauthorized debitA debit is sent against your account with no authorizationAny account holder
Business email compromiseA criminal poses as a supplier or a manager by email and asks you to pay a new bank accountBusinesses that pay invoices
Vendor impersonationA fake “we have changed banks” notice redirects real invoice paymentsAccounts payable teams
Payroll diversionA fake request changes an employee’s direct deposit detailsEmployers and employees
Account takeoverA criminal gets into your online banking and sends ACH credits from your accountBusinesses that originate payments

Nacha groups several of these under one name: payments made under false pretenses. Its definition is a payment induced by someone misrepresenting their identity, their authority to act for another person, or the ownership of the account to be credited. Nacha says this covers business email compromise, vendor impersonation and payroll impersonation.

The definition does not cover disputes about fake or poor-quality goods.

How big the problem is

  • FBI. The Internet Crime Complaint Center’s 2025 report puts losses from business email compromise at $3.05 billion for the year, up from $2.77 billion in 2024. The report lists wire and ACH transfers together as a top reported transaction type.
  • AFP. In the 2026 AFP Payments Fraud and Control Survey, 76% of US organizations reported attempted or actual payments fraud in 2025, and 74% were affected by business email compromise. Checks were the most targeted payment type, named by 58%. ACH debits followed at 30% and wires at 25%.

Protect the money you send

The impersonation scams above all rely on a changed bank account. These steps cost almost nothing.

  1. Call back on a known number. When a supplier or employee asks to change bank details, phone them on a number you already had. Nacha’s advice is to double-check by calling the person directly using a known number. Never use the number in the request.
  2. Get details on a signed form. A vendor ACH form or direct deposit form gives you a record to compare against.
  3. Test new details. Send a prenote or a small first payment before a large one.
  4. Separate the jobs. If you can, have one person set up a payee and another approve the payment. Ask your bank whether its system supports a second approver.
  5. Protect online banking. Use the security tools your bank offers, and do not share logins.
  6. Use the required descriptions. Since March 20, 2026, wage payments must carry the description PAYROLL. Nacha says this rule is intended to reduce fraud involving payroll redirection.

Protect your account from debits

A business account has a short window. The bank’s return must reach the sender’s bank by the opening of business on the second banking day after the debit settled. That leaves about one banking day to spot the debit and tell your bank. Ask your bank for its cut-off time. After that the bank cannot simply send it back.

  • Check your account every business day. This is the single most useful habit.
  • Ask for an ACH debit block or filter. Chase describes its ACH Debit Block as letting a client block all ACH debits or allow some, by company ID. Wells Fargo’s ACH Fraud Filter has a “stop” service that stops all ACH debits except those you pre-authorize, and a “review” service that shows you each one for a pay or return decision.
  • Keep a list of approved company IDs. A filter works from the company ID of each biller you allow.
  • Use a separate account for incoming payments, with debits blocked, if your bank offers it.

A personal account has more time. Under Regulation E, a person can report an unauthorized transfer within 60 days of the statement that shows it. If the 60 days have passed, they should still tell their bank. See how to stop an unauthorized ACH withdrawal and is ACH safe?

If you collect payments from customers

A business that originates debits has duties of its own.

  • Get a real authorization. A signed ACH authorization form is your proof if a customer says the debit was not authorized.
  • Validate accounts for online debits. Since March 19, 2021, a business taking debits that consumers authorize online must check the account the first time it uses an account number. See ACH account verification.
  • Protect stored account numbers. Non-bank originators that send more than 2 million ACH payments a year must make stored account numbers unreadable, by encryption, truncation, tokenization or a similar method. Smaller businesses should follow the same practice.
  • Watch your return rate. Nacha’s level for unauthorized returns is 0.5% of debits.

The Nacha rules that changed

DateRule
March 19, 2021Account validation required for online (WEB) debits
June 30, 2022Data security rule reaches originators above 2 million payments a year
October 1, 2024Receiving banks may return a payment they think is fraudulent. Sending banks may ask for a return for any reason
March 20, 2026Fraud monitoring, phase 1, for sending banks and the largest originators and receiving banks. PAYROLL and PURCHASE descriptions required
June 19, 2026 (June 22 in practice, as June 19 is a federal holiday)Fraud monitoring, phase 2, for everyone else

The fraud monitoring rule applies to every business that sends ACH payments, and to every bank. In plain words: you need steps, sized to your risk, for spotting payments that were started by fraud. Nacha’s wording is “risk-based processes and procedures reasonably intended to identify” such payments. Three points are worth knowing.

  • The duty applies to the extent relevant to the role you play. A small business is not expected to do what a bank does.
  • Checking each payment before it is processed is not required.
  • You must review your processes at least once a year.

The wording asks for processes and procedures, not for a named product. For a small business, written steps such as “call back before changing bank details” and “review the account daily” are a sensible start. Ask your bank what it expects.

What to do if fraud happens

Speed matters more than anything else.

  1. Call your bank at once. Use the number on its website or your card.
  2. For a debit you did not authorize, ask the bank to return it as unauthorized. A business should do this the same day, because the bank’s deadline is the opening of business on the second banking day after settlement. A person signs a Written Statement of Unauthorized Debit.
  3. For a credit you sent to a fraudster, ask your bank to request a return from the receiving bank. Since October 1, 2024, a sending bank may request a return for any reason. The receiving bank must reply within ten banking days, but it does not have to return the money.
  4. Do not rely on a reversal. Reversals are only for the sender’s own errors, such as a duplicate or a wrong amount.
  5. Report it to the FBI’s Internet Crime Complaint Center at ic3.gov, and keep every email and record.
  6. Change passwords and review who has access to your banking.

Receiving banks have a tool too. Since October 2024 a bank that suspects a payment is fraudulent can return it using code R17, and it may delay making a suspicious credit available.

Common mistakes

  • Trusting an email that changes bank details. Call first, on a number you already had.
  • Checking the account once a month. A business has about one banking day to report an unauthorized debit.
  • Leaving ACH debits open on every account. Ask for a block or a filter.
  • Keeping bank details in email or an open spreadsheet. Store them where few people can reach them.
  • Thinking a reversal will fix fraud. It is a tool for errors and is never guaranteed.

Questions and answers

What is ACH fraud?

ACH fraud is any ACH payment made without the account owner's real permission. It includes debits pulled from an account with no authorization, credits sent by a criminal who has taken over a business's online banking, and payments a business sends itself after being tricked by a fake invoice or a fake change of bank details.

Who is liable for ACH fraud?

It depends on the account and on how fast the fraud is reported. For a personal account, Regulation E limits the consumer's loss. The consumer should report within 60 days of the statement, or they can be liable for unauthorized transfers made after those 60 days. If the 60 days have passed, they should report it anyway. A business account is not covered by Regulation E. Its bank can return an unauthorized debit only until the opening of business on the second banking day after it settled. After that, recovery depends on the account agreement and on the other bank.

What is an ACH debit block?

It is a service from a business's bank that stops ACH debits from posting to an account. A block stops all debits. A filter lets through only the companies you have approved, by their company ID.

How do banks investigate ACH fraud?

For a personal account, the bank has 10 business days to decide whether an error happened. It can take up to 45 days if it gives a temporary credit within those 10 business days. For an unauthorized debit, the bank asks the customer to sign a Written Statement of Unauthorized Debit and returns the payment to the sender's bank.

Can ACH fraud be recovered?

Sometimes. An unauthorized debit can be returned if it is reported in time. A credit that a business sent to a fraudster is harder. The business's bank can ask the receiving bank to return it, but the receiving bank does not have to agree, and the money may already be gone.

What do the Nacha fraud monitoring rules require?

Since 2026, every business that originates ACH payments must have risk-based processes and procedures reasonably intended to identify payments initiated due to fraud, and must review them at least once a year. The wording asks for processes and procedures, not for a named product.

How common is ACH fraud?

In the 2026 AFP Payments Fraud and Control Survey, 76% of US organizations reported attempted or actual payments fraud in 2025. Checks were the most targeted payment type at 58%, followed by ACH debits at 30% and wires at 25%.

Sources

  1. Fraud monitoring, phase 1, Nacha
  2. Fraud monitoring, phase 2, Nacha
  3. Risk management topics effective October 1, 2024, Nacha
  4. Company Entry Descriptions (PAYROLL and PURCHASE), Nacha
  5. Supplementing fraud detection standards for WEB debits, Nacha
  6. Account Validation Resource Center, Nacha
  7. Supplementing data security requirements, Nacha
  8. Watch out for common scams, Nacha
  9. Internet Crime Report 2025, FBI Internet Crime Complaint Center
  10. 2026 AFP Payments Fraud and Control Survey (press release), Association for Financial Professionals
  11. Payments fraud protection (ACH Fraud Filter), Wells Fargo
  12. Additional banking services and fees for business accounts (ACH Debit Block), JPMorgan Chase
  13. 12 CFR 1005.6, Liability of consumer for unauthorized transfers (Regulation E), Consumer Financial Protection Bureau
  14. 12 CFR 1005.11, Procedures for resolving errors (Regulation E), Consumer Financial Protection Bureau
  15. Differentiating unauthorized return reasons, Nacha
  16. Reversals and enforcement, Nacha
  17. Disputed ACH Entries: Consumer vs. Non-Consumer (R29 return deadline), EPCOR

Last reviewed . How we check our information. Report a mistake on this page.

General information, not legal or financial advice. Rules change and banks set their own requirements. Check with your bank before you act. ACH Forms is not affiliated with Nacha.