Strategic Advice

How to defend against ACH fraud

Cybercrime: Automated Clearing House (ACH) fraud

In the 1970s, the Federal Reserve created the Automated Clearing House (ACH) system to process payments electronically and lessen dependence on paper checks.

Today, billions of electronic funds transfers occur annually on the ACH system. In 2025 alone, the system processed 35.2 billion transactions that encompassed everything from payroll and direct deposit to services like PayPal and Venmo.Disclosure 1 The combined value of those payments totaled $93 trillion.Disclosure 1

This high volume and variety make corporate ACH payments prime targets for fraudsters. In the 2026 AFP Payments Fraud and Control Survey Report, 34% of respondents said their company’s ACH debits were the subject of payments fraud during 2025.

Key concepts

In this article, we’ll explore:

  • What ACH fraud is and how it happens
  • Which strategies may help prevent ACH fraud
  • How Truist can help protect your business against fraud

Video: An introduction to ACH fraud

Component ID : "accordionGridLayout-217370434"
Model : "disclaimer"
Position : "left"

[Fraud prevention 101: ACH fraud] [Truist logo]

[ACH fraud: ACH fraud is one of the fastest-growing types of fraud. Find out how we can help you stay one step ahead.]

Narrator: ACH fraud is one of the fastest-growing types of deception techniques, especially as criminals create more sophisticated scams and use the latest technology to their advantage. A common trick is to infiltrate a vendor’s contact information and respond to a previously sent message so it appears to be part of the same chain or thread.

Some even use details from social media to make the email, text, or online message seem like it’s coming from a trusted contact.

One of the best ways to prevent fraudulent transactions is to have close relationships with vendors.

Check in with them to verify any unusual or first-time requests, changes in contact information or remittance addresses, or changes in wiring or ACH instructions. Whenever possible, confirm any change with two sources.

Monitoring incoming ACH payments is just as critical. Truist offers fraud prevention services that allow you to block or review ACH debit transactions before they deposit to your account.

We also offer a Universal Payment Identification Code, which gives you masked account numbers for receivables to help prevent unauthorized charges to your account.

It can be good to remind everyone within your organization that time spent reviewing ACH transactions upfront can reduce time spent rectifying problems later.

How does ACH fraud happen?

ACH fraud occurs when fraudsters use the ACH Network to steal funds via unauthorized transactions. Examples include:

  • Unauthorized transfers from a victim’s bank account
  • Payment for goods and services scammers have sent to themselves
  • Withdrawals using stolen debit card numbers
  • Scheduling automatic bill payments to a fraudster’s account

ACH fraud relies on social engineering scams such as corporate phishing and business email compromise (BEC). Fraudsters pose as trusted employees, associates, financial institutions, or federal agencies. They trick employees into sharing corporate bank account information that they can use to move company funds into their accounts. For example, hackers may infiltrate a vendor’s contact information and respond to a previously sent message, making it appear to be part of the same chain or thread.

A rectangular box running horizontally contains a large headline. Below the headline sits a horizontal table with four columns and three rows. The headline reads “Methods used for ACH payments fraud.” Below the headline, the table begins. The text and numbers in the table communicate the percentages for instances of payments fraud pertaining to either ACH debit fraud or ACH credit fraud committed using three methods: business email compromise (BEC), telephone call to organization, and text on official mobile device to organization. The row that pertains to ACH debit fraud shows that 34% of all ACH debit fraud was committed using business email compromise (BEC); 27% of all ACH debit fraud was committed using a telephone call to organization; 20% of all ACH debit fraud was committed using a text on official mobile device to organization. The row labelled ACH credit fraud conveys that 31% of all ACH credit fraud was committed using business email compromise (BEC); 33% of all ACH credit fraud was committed using a telephone call to organization; 30% of all ACH credit fraud was committed using a text on official mobile device to organization. Starting in the bottom left corner, below and outside of the table, a line of text reads “Data source: 2026 AFP Payments Fraud and Control Survey Report.”

Scammers tend to direct ACH fraud scams at midsize and smaller businesses, believing they’re less likely than larger companies to have strong cybersecurity programs.

The 2026 AFP Payments Fraud and Control Survey Report found that just over a third of all payments fraud occurred through the direct manipulation of ACH or wire transfer instructions. Survey data also indicates that 65% of the most prevalent form of payments fraud, BEC fraud, relies on tricking employees into turning over sensitive information about ACH credits and debits to scam businesses.

Good news: New ACH rules help combat fraud.

In 2026, the organization governing the ACH Network, Nacha, is upgrading its fraud monitoring rules to enable risk-based, proactive fraud detection for both ACH debits and credits across the network.Disclosure 3 This upgrade will mandate fraud monitoring by all originating depository financial institutions, originators, third-party senders, and receiving depository institutions. These changes will dramatically improve the ability to detect and combat schemes like BEC.Disclosure 3

A plum colored, rectangular box running horizontally contains a large headline that begins in the top left corner, runs sideways across three-quarters of the rectangular box, and extends two-thirds down the height of the rectangular box. The headline reads “Fraudsters manipulate ACH instructions in about a third of all payment fraud instances.” Moving left to right horizontally across the rectangular box, in the final quarter of space, just beyond the large headline text, is a pie chart with two divisions. One portion is colored light purple. The other portion of the pie chart, which is considerably smaller, is colored medium purple. The medium purple section contains the number “33%”, visually confirming that 33%, or one-third, of fraudsters manipulate ACH instructions when committing payments fraud. Starting in the bottom left corner, below and outside the large headline text and the pie chart, in fine print, is a citation indicating the source for the 33% figure used in the pie chart. It reads “Data source: 2026 AFP Payments Fraud and Control Survey Report.” Following the period behind “Report” is a superscripted number two, which indicates the placement of this source in the endnotes for the article.

Did you know? ACH Blanket Block stops all ACH debit attempts.

ACH Blanket Block is a fraud control solution offered by Truist. If there’s an account you don’t use for ACH transfers, request an ACH Blanket Block. If anyone tries to debit money from the account, their request will automatically bounce back—no monitoring required. Talk to your Truist relationship manager to learn more about ACH Blanket Block.

Best practices and prevention

Mitigating the risk of ACH fraud starts with creating a proactive and strong defense plan. Here are some strategies that can help you and your team prevent ACH fraud at your organization.

Prioritize employee training.

Teach employees how to spot password theft and social engineering fraud, two of the most common scams used to obtain ACH information. Stress the importance of keeping company information private. Running a mock phishing campaign can help your IT team identify weak points in your defenses—and give your employees more confidence to handle a real-world scenario.

Strengthen vendor relationships.

requent, clear communication with vendors helps reduce the risk of fraudulent ACH activity. Verified points of contact and regular check-ins with your vendor can help you quickly identify suspicious payment requests, account changes, or unusual transaction behavior. 

Update protective protocols.

Layering protocols can multiply their protective effect. Consider implementing transaction limits, review periods, and dual controls (where two or more employees must approve each transaction). You could even opt to use a credit-only account that accepts deposits but doesn’t permit debits. For updates on the latest ACH news and risk management tools, subscribe to Nacha’s ACH Network newsletter.

Boost your tech defenses.

Update every employee’s antivirus software regularly to help block malware and spam. It’s also helpful to implement multifactor authentication for all ACH payments. For an extra layer of security, ask your Truist relationship manager about a Universal Payment Identification Code (UPIC), an account number alias you can distribute to your partners.

Talk to Truist.

Get peace of mind by assuring you are taking advantage of all the fraud control options available to you. Contact your Truist relationship manager to learn about our ACH fraud control solutions, including ACH Blanket Block and UPIC. These tools can help your employees reduce risk, make informed decisions, and act quickly to stop or minimize losses.

FAQ on ACH fraud

Component ID : "faq-1301646222"
Model : "faq"
Position : "left"

To report ACH fraud related to a Truist account, you can call us at 844-4TRUIST (844-487-8478). You can also contact your relationship manager or treasury consultant. Learn more about reporting fraud at Truist.

You can, and in 2025 nearly one-third of targeted organizations recovered more than 75% of lost funds.Disclosure 2 But recovery is time sensitive. Nacha maintains a two-day return deadline for business accounts from the date of the fraudulent transaction. If an illicit debit is identified, notifying the receiving bank as quickly as possible increases your chances of successfully placing a hold on those funds and getting a return.

Yes. While both are electronic forms of fraud, funds stolen via wire transfer are sent directly from party to party without passing through the ACH network and its layer of fraud protection.

Truist provides several solutions that can help reduce the risk of ACH fraud for your business. These include ACH Fraud Control, ACH Blanket Block, and UPIC. Ask your Truist relationship manager or treasury consultant to review your current defenses and advise if additional or different measures are right for your business.

Truist’s ACH Fraud Control helps prevent unauthorized and erroneous transactions. It enables you to set parameters for transactions (such as upper limits), customize your protections, and receive detailed reports on ACH account debits.

Truist’s ACH Blanket Block prevents all ACH activity on one or more accounts of your choosing. Any attempted debit or credit transaction to a blocked account would be returned to the originator automatically.

A UPIC, or Universal Payment Identification Code, is a unique code created for partners, vendors, and suppliers. It allows them to send you electronic payments without using your actual commercial bank account details. This reduces the risk of a business account number being exposed in a data breach.

Turn to professionals for protection.

To learn more about cybersecurity threats and the various types of fraud facing your organization, connect with one of Truist’s relationship managers.

Wholesale Payments Truist Purple Paper® Developing a treasury ecosystem to propel your business

Learn how a new era of payments technology can transform the way you succeed.

Related resources

Protecting Your Business Against Social Engineering Fraud | Truist

Protecting Your Business Against Social Engineering Fraud | Truist

Fraud How to identify and prevent the most prevalent cyber scam

Preventing social engineering fraud

Article
07/31/2024
Protecting Your Business Against Social Engineering Fraud | Truist

Social engineering involves exploiting a person’s trust to obtain private information or money to commit a crime. Learn how to prevent it here.

How To Defend Against Business Email Compromise

How To Defend Against Business Email Compromise

Fraud How to detect and defend against business email compromise

Article
07/22/2025
How To Defend Against Business Email Compromise

Business email compromise happens when scammers impersonate someone you trust in an attempt to defraud your company. Learn how to spot and prevent BEC.

How to defend your business against password theft

How to defend your business against password theft

Fraud How to defend your business against password theft

Password theft is a foundational cybercrime hackers rely on to access your company’s computer networks. Learn how to spot and stop these attacks.

Article
09/12/2024
How to defend your business against password theft

Password theft is a foundational cybercrime hackers rely on to access your company’s computer networks. Learn how to spot and stop these attacks.

    {0}
    {6}
    {7}
    {8}
    {9}
    {12}
    {10}
    {11}

    {3}

    {1}
    {2}
    {7}
    {8}
    {9}
    {10}
    {11}
    {14}
    {12}
    {13}

    Stay informed and get connected

    Looking for fresh thinking and new insights to help uncover opportunities for your business needs?

    Connect with a Relationship Manager

    Work with a partner who sees your vision and has the resources to help you achieve it. We’re ready to focus on the specific needs of your company—and where you are in your business lifecycle.

    *This form is for prospects. Truist clients should contact their relationship manager with inquiries related to commercial products and services.

    Helpful links




    Sign up for monthly articles on Business Insights

    Sign up to receive our business insights, thought leadership, and client success stories that can help inspire your next bold business move.

    Please enter a first name
    Please enter a last name
    Please enter a valid email address
    Please enter a company name
    I'm also interested in: Please select a campaign option