In 2025, 76% of organizations experienced payment fraud attacks or attempts, according to the AFP 2026 Payments Fraud and Control Survey—conducted in January 2026 among 465 U.S. treasury practitioners. ACH transactions rank as the second most targeted payment method, cited by 30% of fraud-affected organizations. B2B ACH volume hit 8.1 billion payments in 2025, a 9.9% increase year over year. More volume, more exposure.
Recovery remains difficult. Financial losses were reported by 48% of organizations with revenue under $1 billion and 66% of larger firms—yet only 17% of all organizations currently use AI-driven tools to combat payment fraud. Most businesses are still relying on manual controls against increasingly automated attacks.
This guide covers eight concrete ACH fraud prevention strategies, how PhotonPay strengthens payment-level controls, and exactly what to do in the first hours after fraud is discovered.
What Is ACH Fraud and How Does It Happen?
ACH fraud is any unauthorized transaction initiated through the Automated Clearing House network using a legitimate business bank account. The barrier to entry is low: a routing number and checking account number—both printed on every check a business issues—are all an attacker needs to attempt an unauthorized debit.
The five attack methods below account for the majority of ACH fraud incidents targeting businesses today.
The 5 Most Common Types of ACH Fraud
-
Unauthorized ACH debits. A criminal obtains account credentials from a stolen check, data breach, or phishing attack, then initiates debit transactions directly. Small test debits often precede larger withdrawals—catching the test is how most businesses stop the larger theft.
-
Business Email Compromise (BEC). BEC affected 74% of organizations in 2025, per the AFP 2026 report. Attackers spoof or compromise a business email account and insert themselves into existing payment threads, submitting updated banking details that redirect ACH transfers to attacker-controlled accounts.
-
Account Takeover (ATO). Stolen credentials—obtained via phishing, malware, or credential-stuffing—give fraudsters direct access to banking portals. They initiate ACH payments from inside the account, making the transaction appear legitimate at the network level.
-
Payroll diversion fraud. An internal bad actor, or an attacker with payroll system access, changes direct deposit routing details to redirect employee paychecks to unauthorized accounts. These changes often go undetected for multiple pay cycles.
-
Vendor impersonation. Fraudsters pose as existing vendors and request a banking details update via email. Without verbal verification, the next scheduled ACH payment goes to the attacker rather than the legitimate vendor.
How to Prevent ACH Fraud: 8 Strategies for Businesses
Each strategy below targets a specific attack vector. Layering multiple controls—rather than relying on a single measure—is what separates an effective program from a compliance checkbox.
-
Enable ACH Debit Blocks and Filters
An ACH debit block instructs your bank to reject all incoming ACH debits automatically—no exceptions, no manual review. An ACH debit filter is narrower: it allows debits only from pre-approved company IDs, blocking everything else.
Contact your bank's commercial banking or treasury team to set these up. For accounts that never receive external debits—internal funding accounts, reserve accounts—a full debit block is the cleanest protection. For operational accounts, use debit filters with an approved vendor whitelist. Most commercial banks offer both at no additional cost.
-
Require Dual Authorization for Every ACH Transaction
Dual authorization requires two separate employees to approve each ACH transaction before it processes: one person initiates, a different person approves. The two roles must be distinct—the same employee cannot perform both steps.
This control neutralizes both insider fraud and BEC attacks. A fraudster who compromises one employee's credentials can initiate a payment but cannot approve it. AFP data consistently identifies dual authorization as one of the highest-impact controls for commercial payment fraud.
Extend this rule to payment detail changes, not just transaction approvals. Any update to a vendor's banking details should require separate sign-off before the new information is used.
-
Implement ACH Positive Pay
ACH Positive Pay is a bank-side service that matches incoming ACH debit attempts against a pre-submitted list of authorized transactions. Entries that don't match are flagged for manual review before they settle—the business decides to pay or return them.
Not all banks offer this service by that exact name. Ask your financial institution specifically for "ACH Positive Pay" or "ACH debit filter with decision." For businesses with high ACH debit volume, this is one of the most direct fraud controls available—it stops unauthorized debits at the bank's gate rather than relying on post-settlement disputes.
-
Verify Bank Account Ownership Before Initiating Payments
Before sending an ACH payment to a new vendor, or updating banking details for an existing one, verify that the account belongs to the actual payee. Call the vendor using a phone number from your own records—not the number provided in the email requesting the change.
Nacha's account validation requirements, effective since 2021, require ACH originators to use commercially reasonable methods to validate accounts before the first debit. Micro-deposit verification, prenote testing, and third-party bank account verification services all satisfy this standard. This single step stops most vendor impersonation fraud before a payment is ever initiated.
-
Monitor Accounts Daily and Configure Real-Time Alerts
The window to dispute an unauthorized ACH debit is narrow. Under Nacha's rules, corporate accounts have two business days from the settlement date to identify and report unauthorized transactions to their Originating Depository Financial Institution (ODFI). After that window closes, returns are no longer guaranteed by the network.
Set up real-time email or SMS alerts for all ACH activity above a threshold your team defines. Log into your banking portal daily. Fraudsters typically test accounts with small transactions—a $1 or $5 unauthorized debit that goes unnoticed lets the attacker confirm the account is active before escalating to much larger amounts.
-
Meet Nacha's Risk-Based Monitoring Requirements
Nacha's expanded fraud monitoring rules require covered ACH participants to implement processes that identify entries suspected of being authorized under false pretenses. The rules specifically target BEC, vendor impersonation, payroll diversion, account takeover, and social engineering fraud.
Three requirements apply directly to monitoring programs: they must be risk-based (not just static rule-based), documented in writing, and subject to annual review. If your business originates ACH payments through a bank, ask your ODFI how their compliance program satisfies these obligations—and request documentation rather than a verbal confirmation.
-
Restrict and Audit ACH Access Permissions Regularly
Limit ACH initiation and approval rights to the smallest set of employees who genuinely need them. Access creep—where permissions accumulate as employee roles change—is one of the most consistent enablers of both insider fraud and ATO attacks.
Conduct a formal access review at minimum every quarter. Immediately revoke ACH access for employees who change roles, resign, or are terminated. Maintain a documented access log that records who holds what permissions, when access was granted, and when it was last reviewed.
-
Train Employees to Recognize BEC and Social Engineering
The AFP 2026 report identifies BEC as the leading payment fraud vector, affecting 74% of organizations in 2025. Most BEC attacks require no technical expertise—they rely on urgency, implied authority, and the assumption that employees won't verify before acting.
Training should cover: how to identify spoofed domains (payables@vendor-corp.co vs. payables@vendorcorp.com), what to do when a payment details change request arrives by email, and how to use internal escalation procedures before approving any modified ACH payment. Quarterly simulations measure awareness far more accurately than annual one-time sessions.
How PhotonPay Strengthens Your Payment Fraud Prevention
Operational ACH controls address fraud at the bank account level.
PhotonPay adds fraud prevention at the payment infrastructure layer—using real-time detection and multi-factor controls to stop suspicious transactions before they originate or reach settlement.
PhotonPay is PCI-DSS Level 1 certified—the highest tier of payment security compliance—and operates under regulatory licenses from multiple jurisdictions including the FCA and FINTRAC. Its fraud prevention architecture directly addresses the attack vectors most commonly exploited against ACH users.
|
Fraud Risk
|
PhotonPay Control
|
|
Unauthorized transaction initiation
|
Multi-layer payout approval workflows require separate authorization before payments are released
|
|
Account takeover
|
Multi-factor authentication (MFA) and 3DS 2.0 add verification beyond login credentials
|
|
Payee identity fraud
|
KYC/AML verification confirms payee identity before payment processing begins
|
|
Unusual transaction patterns
|
AI/ML anomaly detection monitors all transaction behavior 24/7 and flags deviations in real time
|
|
Merchant-side fraud signals
|
Merchant Risk Monitoring identifies pattern anomalies—transaction spikes, high-risk geolocations—before payment
|
|
Sensitive account data exposure
|
Tokenization replaces payment credentials with non-sensitive tokens, eliminating raw account data from the chain
|
The AFP 2026 report found that only 17% of organizations currently use AI-driven tools for fraud mitigation. PhotonPay's AI-powered monitoring applies consistent risk controls across domestic and international payment types—detecting behavioral anomalies, unusual geolocations, and device-level signals that manual rule-based systems miss.
What to Do If Your Business Is Hit by ACH Fraud
Speed determines recovery. For corporate ACH accounts, Nacha's rules allow two business days from the transaction settlement date to file an unauthorized return. After that window closes, recovery requires the receiving bank's voluntary cooperation and is not guaranteed by the network.
Act in this order:
Step 1: Contact your bank's ACH operations team immediately. Request a return using Nacha return code R10 (unauthorized consumer debit) or R29 (corporate customer advises not authorized). Reach the ACH fraud or commercial banking team directly—general customer service lines may not have the authority to initiate a return.
Step 2: Restrict or close the compromised account. Move remaining operational balances to a clean account. Apply an ACH debit block to the compromised account if not already in place.
Step 3: File a report with the FBI's Internet Crime Complaint Center (IC3) at ic3.gov. If the fraud was initiated via BEC, the FBI's Recovery Asset Team may be able to assist—but only if notified quickly, while the funds are still traceable.
Step 4: Report to FinCEN for transactions above $5,000. Financial institutions are required to file Suspicious Activity Reports (SARs). For large losses, consult legal counsel about additional reporting obligations and any applicable cyber insurance requirements.
Frequently Asked Questions About ACH Fraud Prevention
What is the time limit to dispute an ACH fraud charge?
For corporate accounts, Nacha rules allow two business days from the settlement date to report an unauthorized ACH debit and request a return. Consumer accounts have a 60-day window under Regulation E. The corporate deadline is strict—missed windows significantly reduce recovery options and remove your bank's obligation to return the funds.
Can ACH payments be reversed after fraud occurs?
ACH transactions can be returned within the two-business-day corporate window using Nacha return codes (R10 for consumer unauthorized, R29 for corporate unauthorized). Outside that window, reversal requires the receiving bank's cooperation and is not network-guaranteed. Daily monitoring and fast reporting are more effective than any post-fraud recovery measure.
What is the difference between ACH Positive Pay and an ACH debit block?
An ACH debit block rejects all incoming ACH debits automatically—nothing gets through. ACH Positive Pay compares incoming debits against a pre-approved list and flags mismatches for manual review rather than rejecting everything outright. A debit block suits accounts that should never receive external debits. Positive Pay is better for operational accounts with legitimate external debits that need selective approval.
How do I know if my business is at risk for ACH fraud?
Every business that issues paper checks, runs ACH payroll or vendor payments, or accepts ACH debits carries inherent exposure—your account and routing numbers are visible on every check you write. Businesses with high ACH volume, multiple employees with banking access, or frequent vendor payment changes face the most elevated risk, per the AFP 2026 report.
Is ACH safer than a wire transfer for business payments?
Wire transfers are typically irrevocable once sent—no return window, no network recovery mechanism. ACH transactions can be returned within Nacha's two-business-day corporate window, offering a limited but real recovery path. However, ACH fraud is significantly more common due to the lower barriers to initiating unauthorized debits. For a cost and risk comparison across payment types, see our guide on
international wire transfer fees.