---
title: "ACH fraud: how it works and how to prevent it"
description: "The four kinds of ACH fraud that hit businesses, why ACH credits are hard to recover, and a practical prevention checklist for AP and treasury teams."
url: https://realpayee.com/blog/ach-fraud-prevention
canonical: https://realpayee.com/blog/ach-fraud-prevention
date_published: 2026-10-05
date_modified: 2026-10-05
updated: 2026-10-05
author: "RealPayee"
site: RealPayee
---

# ACH fraud: how it hits businesses and how to prevent it

> ACH fraud is any unauthorized or deceptive payment over the ACH network. Businesses face two directions: debits pulled from their account without permission, and credits their own team sends to a fraudster after a fake bank-detail change. Debits can often be returned quickly; credits usually cannot, so prevention has to happen before the payment file is released.

_Fraud prevention · Published 2026-10-05 · 6 min read · By the RealPayee team_

## Key takeaways

- Split ACH risk into **debits pulled from you** and **credits pushed by you**. They need different controls.
- ACH positive pay and debit blocks handle most unauthorized debits. Business accounts have a short window to return them, so review daily.
- Credit-push fraud starts with a **changed bank account** on a vendor or employee record. Verify every change with the known contact before the next payment run.
- US ACH credits post by account number. The receiving bank generally does not check the account name, so a matching name proves nothing.

## What is ACH fraud?

The Automated Clearing House network moves payroll, vendor payments, tax payments and direct debits between US banks in batches. ACH fraud is any payment on that network that the account owner did not genuinely intend. For a business it shows up in two very different ways:

- **Debit fraud:** someone uses your routing and account number to pull money out of your account.
- **Credit-push fraud:** your own team sends a legitimate-looking ACH credit to an account the fraudster controls, usually after a vendor's or employee's bank details were changed on a request that looked real.

Most finance teams have decent controls for the first and weak controls for the second. The second is where the larger losses come from, because the payment is authorized by you and the money is often withdrawn before anyone notices. Credit-push fraud usually arrives through business email compromise, which the FBI's IC3 says cost US victims **$2.77 billion** in reported losses in 2024.

## The four ACH fraud schemes finance teams see

| Scheme | How it works | Warning signs | Primary control |
| --- | --- | --- | --- |
| Unauthorized debit | A fraudster uses account and routing numbers from a check or invoice to originate debits against you | Unknown originator name or company ID on the statement | ACH positive pay or debit block |
| Vendor bank-change fraud | A spoofed or compromised vendor email asks AP to update remittance details; the next payment run pays the new account | Change requested by email, urgency, new bank in a different state or a neobank, payment due soon | [Vendor verification](https://realpayee.com/vendor-verification) with the known contact |
| Payroll diversion | An attacker emails HR or logs into the HR portal as an employee and changes direct deposit details | Change requested just before a payroll cutoff, email from a personal address | Confirm by phone or in person with the employee; notify the old account holder |
| Account takeover | Criminals obtain online banking credentials and originate ACH credits from your account | New payees added in the bank portal, logins from unusual locations | Dual control in the bank portal, hardware tokens, payee approval |

## Why ACH credits are so hard to get back

Debits and credits have very different recovery paths, and this is the single most important thing for a controller to understand about ACH risk.

**Unauthorized debits:** Nacha rules let a business return an unauthorized debit, but corporate accounts get a much shorter window than consumers: typically two banking days from settlement. If nobody reviews ACH activity daily, that window closes. This is why ACH positive pay, which stops the debit before it posts, beats monthly reconciliation.

**Credits you sent:** once your bank releases an ACH credit, there is no automatic right to pull it back because you authorized it. Your bank can send a request for return to the receiving bank, but the receiving bank is not obliged to return funds that have already been withdrawn. Fraudsters know this and move money out quickly, often through a chain of accounts.

> [!WARNING]
> **The name on the account is not checked**
> In the US, an ACH credit posts to the account number in the file. Receiving banks generally do not match the beneficiary name, so a payment addressed to your real vendor will land in the fraudster's account if the number is theirs. A matching name on a voided check or bank letter is not proof of ownership either: both are easy to fake.

## How to prevent ACH debit fraud

1. **Turn on ACH positive pay or a debit filter** on every operating account. Allow only the company IDs that legitimately debit you. Our [positive pay guide](https://realpayee.com/blog/what-is-positive-pay) walks through the set-up.
2. **Block all debits** on accounts that should only send money, such as a dedicated payables account.
3. **Separate accounts by purpose.** Keep the account number you print on invoices for collections away from your main operating funds.
4. **Review ACH exceptions every banking day** with a named owner and backup, so returns are made inside the short corporate window.
5. **Reconcile daily, not monthly**, for high-volume accounts. Most bank portals can send an alert for any debit above a threshold.

## How to prevent ACH credit-push fraud

Credit-push fraud almost always begins with a change to a bank account record. Stop the change from being trusted until it is verified, and the payment never goes to the wrong place. The controls below are listed in the order they matter:

1. **Treat every bank-detail change as a payment event.** A changed account on a vendor, employee or customer refund record should trigger the same scrutiny as releasing a large payment.
2. **Verify with the known contact, through a channel you already had.** Call the number stored in your vendor file before the request arrived, or use a verification step bound to that contact. Never use contact details from the change request itself.
3. **Hold the next payment** to that payee until the change is verified, regardless of who asks to rush it.
4. **Separate duties.** The person who edits bank details in the ERP should not be the person who approves or releases the payment run.
5. **Review the change log** before every payment run: list every vendor whose bank details changed since the last run and confirm each has a recorded verification.
6. **Send a confirmation to the old contact** on file after any change, so a real vendor who did not request it can raise the alarm.
7. **Use dual control in your bank portal** for adding payees and releasing ACH files, with hardware or app-based tokens rather than SMS codes where your bank offers it.

The full callback procedure, with script and evidence requirements, is in our free [vendor bank-change verification policy template](https://realpayee.com/templates/vendor-bank-change-policy). The common schemes behind these requests are covered in [vendor fraud: types and examples](https://realpayee.com/vendor-fraud).

## What Nacha's 2026 fraud monitoring rules mean for you

Nacha's newer risk-management rules, phased in during 2026, expect organizations that originate ACH entries, which includes companies sending vendor payments and payroll, to have risk-based processes for identifying payments initiated under false pretenses. In plain terms: "the email looked real" is no longer a complete answer. Your bank may ask how you verify payee bank-detail changes. A written, followed and logged verification procedure is the simplest way to answer. Check the specifics that apply to you with your bank's treasury team.

## What to do in the first hour after ACH fraud

1. **Call your bank's fraud line**, not your relationship manager's email. Ask them to request a return or recall from the receiving bank immediately and get a case number.
2. **For a debit,** confirm the return reason and that it is sent within the corporate return window.
3. **Freeze the record** that was changed: revert the vendor or employee bank details and block further payments to the new account.
4. **File a complaint with the FBI's IC3** at ic3.gov. For larger, recent losses, the FBI can sometimes coordinate with banks to freeze funds.
5. **Preserve evidence:** the original emails with full headers, the change log, payment file, approval records and call notes.
6. **Notify your cyber or crime insurer** early. Many policies have notice deadlines and require proof of a verification procedure.
7. **Check for a compromised mailbox.** If the request came from a real vendor address, tell the vendor; if it came from an internal address, reset credentials and review mailbox rules.

## ACH fraud prevention checklist

| Control | Covers | Owner | Frequency |
| --- | --- | --- | --- |
| ACH positive pay or debit block | Unauthorized debits | Treasury | Allow list reviewed quarterly |
| Exception and return review | Unauthorized debits | AP lead plus backup | Every banking day |
| Bank-detail change verification | Vendor and payroll diversion | AP or vendor master team | Every change, before next payment |
| Change log review before payment run | Vendor and payroll diversion | Controller or approver | Every payment run |
| Dual control on payee adds and file release | Account takeover | Treasury | Always on |
| Fraud drill with a test change request | All credit-push schemes | Controller | Twice a year |

If verification of bank-detail changes is the step your team skips under time pressure, that is exactly what RealPayee automates: it holds the change or payment, confirms it with the real contact out-of-band, and records the evidence. [Book a demo](https://realpayee.com/demo) to see it on your ERP.

## Frequently asked questions

### What is ACH fraud?

ACH fraud is an unauthorized or deceptive payment over the ACH network, either a debit pulled from your account without permission or a credit your team sends to a fraudster's account after being deceived.

### Can you reverse an ACH payment sent to a scammer?

Sometimes, but there is no guarantee. Your bank can request a return, and the receiving bank may return any funds still in the account. Act within hours, call your bank's fraud line and file with IC3.

### Who is liable for ACH fraud on a business account?

For unauthorized debits returned on time, the loss usually falls back on the originator. For credits your team authorized after being deceived, the business usually bears the loss, because the bank followed your instructions. Read your treasury services agreement.

### How long do businesses have to dispute an unauthorized ACH debit?

Corporate accounts have a much shorter return window than consumers, typically two banking days. That is why daily review or ACH positive pay matters for businesses.

### Does ACH positive pay stop vendor payment fraud?

No. ACH positive pay filters debits pulled from your account. Vendor payment fraud uses credits your team sends, so it needs [vendor verification](https://realpayee.com/vendor-verification) of bank-detail changes.

## Sources

- [Nacha: FBI IC3 finds almost $8.5 billion lost to business email compromise in last three years](https://www.nacha.org/news/fbis-ic3-finds-almost-85-billion-lost-business-email-compromise-last-three-years)

## Related

- [What is positive pay? Check, ACH and payee positive pay](https://realpayee.com/blog/what-is-positive-pay) - What positive pay is, how check, payee and ACH positive pay work, what they cost in effort, and the payment fraud they do not stop. A guide for AP teams. (markdown: https://realpayee.com/blog/what-is-positive-pay.md)
- [Vendor onboarding checklist: a fraud-safe process for AP](https://realpayee.com/blog/vendor-onboarding-checklist) - A step-by-step vendor onboarding process and checklist for AP teams: what to collect, how to verify bank details, who approves, and what to log for audit. (markdown: https://realpayee.com/blog/vendor-onboarding-checklist.md)
- [Business email compromise examples and how to stop them](https://realpayee.com/blog/business-email-compromise-examples) - Seven business email compromise (BEC) examples finance teams see, the red flags in each, and the specific control that stops it before money moves. (markdown: https://realpayee.com/blog/business-email-compromise-examples.md)
- [Vendor fraud: types, examples and how to prevent it](https://realpayee.com/vendor-fraud) - What vendor fraud is, the most common schemes (vendor impersonation, fake bank changes, fake invoices) and the controls that stop them. (markdown: https://realpayee.com/vendor-fraud.md)
- [Free vendor bank-change verification policy template](https://realpayee.com/templates/vendor-bank-change-policy) - A free, copy-ready vendor bank-detail change and callback verification policy template plus checklist for AP teams. (markdown: https://realpayee.com/templates/vendor-bank-change-policy.md)

---

**Further reading**
- [Vendor verification guide](https://realpayee.com/vendor-verification.md)
- [Free vendor bank-change policy template](https://realpayee.com/templates/vendor-bank-change-policy.md)
- [Compare: callbacks vs bank-account validation vs RealPayee](https://realpayee.com/compare.md)
- [Pricing](https://realpayee.com/pricing.md)

Canonical HTML: https://realpayee.com/blog/ach-fraud-prevention · Site index for AI agents: https://realpayee.com/llms.txt?src=md-footer · Pricing: https://realpayee.com/pricing.md · Book a demo: https://realpayee.com/demo
