ACH Fraud: How It Works and Who's Liable When It Hits

ACH fraud uses unauthorized account or routing data or compromised bank access to move money, and liability turns on whether the affected account is consumer or business and how quickly it is reported.

ACH fraud is the use of the ACH network to move money out of a bank account without valid approval. It runs on a stolen routing and account number, a hijacked bank login, or a scam. An ACH dispute carries no reason code and, for most claims, no merchant defense.

I've dug through payment setups for more than 100 merchants in a support role, and banks differ on a disputed transfer every time. The ACH side surprised me most, because there was no code to answer and no evidence packet to send. Read this once and you'll know who pays and which three controls cover which route.

Key takeaways

  1. 01ACH fraud moves money using only a routing and account number.
  2. 02Consumer accounts get up to a 60 day federal reporting window for fraud.
  3. 03Business accounts often get as little as 24 hours under the bank agreement.
  4. 04A new fraud-monitoring rule covers ACH senders by June 19, 2026.
  5. 05Ask your bank for a debit filter to allow-list approved senders.
  6. 06Require a second approver on every outgoing ACH payment.

What is ACH payment fraud?

ACH payment fraud is money moved through the ACH network with no valid approval, or with approval the account holder was tricked into giving. Most cases start with stolen account numbers, a hijacked bank login, or a scam.

The ACH network moves funds between accounts using an account number and a routing number.

Those two numbers alone authorize the transfer. So a stolen pair, or a convincing email, is enough to move money. Card fraud needs card data and a checkout, while ACH fraud needs only the numbers on a paper check. It reaches bank accounts that never touch a card network, which is where true fraud lands instead.

A transfer the account holder really approved falls under an ordinary return reason. A wrong amount, a double charge, or a service that never came all count.

That line decides how long the account holder has to act. On a consumer account, only a truly unapproved debit gets the longer 60 calendar day review window.

How ACH fraud actually happens

Most ACH fraud runs on stolen account numbers, a hijacked bank login, or a scam that gets the victim to pay. The first two work on stolen access, the third on trickery:

  1. Stolen account and routing numbers: A fraudster pulls money using details they should never have had.
  2. Compromised online banking logins: A fraudster takes over the account and redirects real payments.
  3. Business email compromise and vendor impersonation: The account holder sends the money.

Each one works differently, so each needs a different control.

1. Stolen account and routing numbers

A stolen routing and account number is enough to start a debit, because the ACH network checks the numbers rather than the person. Those numbers get printed and shared widely. They appear on every check a business writes, in every vendor form, and in its billing records.

A fraudster holding them can set up a debit that looks like an ordinary biller pull. The receiving bank matches the numbers and releases the funds.

A bank-side block or filter is the only control that stops this route.

2. Compromised online banking logins

A hijacked bank login does more damage than stolen numbers, because it lets a fraudster change where real payments go. With stolen numbers a fraudster gets one debit. With a login they can redirect payments, add payees, and read enough history to make the next transfer look normal.

Credential theft feeds this route. A fake login page, malware on a finance laptop, and a reused password all end in the same place.

Turn on multi-factor login for the bank portal, and set an alert whenever a new payee is added. The same account takeover prevention controls work on the card side.

3. Business email compromise and vendor impersonation

Business email compromise gets a real employee to approve a real transfer using their own legitimate access. A fraudster watches or spoofs an email thread, waits for a live invoice, then sends new bank details.

Suppose your accounts-payable inbox gets a note from a vendor you pay every month. It quotes the right invoice number and says the bank has changed. The payment goes out through your normal approval flow, into the fraudster's account.

Access controls read that payment as legitimate, because the approval was.

Here the account holder moved the money. Older fraud definitions, built around stolen access, miss this route entirely.

Who's liable: consumer, business, and merchant compared

A consumer account gets a bank investigation and usually a refund under Regulation E, while a business account's outcome is set by UCC Article 4A. Regulation E covers consumer accounts only, so business ACH payments fall outside it. It also caps a consumer's exposure and sets bank deadlines by statute.

Under Article 4A, courts ask whether the bank ran a commercially reasonable security procedure. A bank can then shift the loss to a business that skipped an agreed procedure. The account agreement decides the outcome.

The reporting deadlines differ the most:

Consumer accountBusiness account
Governing ruleRegulation EUCC Article 4A
ReimbursementBank investigates and generally reimbursesDepends on the account agreement
Reporting window (typical)Up to 60 days, set by federal lawAs little as 24 hours, set by the agreement

‍

 
Time to report an unauthorized ACH transaction
 
Consumer account
60 days
 
Business account
24 hours
 
Federal floor for consumers against a common business account agreement term.

Those two windows come from different places, federal law on one side and your signed agreement on the other.

A business that skipped its bank's agreed procedure can end up paying for fraud it had no hand in. Bank account agreements most often require dual control and callback verification, and skipping either hands the bank a defense.

A careless consumer still gets an investigation.

Our chargeback alerts cover card-network disputes only. They catch those through Ethoca, RDR, and CDRN before they turn into chargebacks.

Price what card disputes cost you today with our ROI calculator.

How ACH fraud disputes differ from card chargebacks

A card chargeback hands you a reason code and an evidence window, while the receiving bank decides an ACH return against Nacha's fixed list of reasons. That call is usually final.

Nacha sets and enforces the operating rules that assume both parties are banks. So those rules let the receiving bank decide most returns on the account holder's statement and the timing.

Each Visa and Mastercard chargeback reason code states what evidence answers it.

Say you ship an order, the customer pays by ACH, and weeks later they tell their bank the debit was never approved. On the card side you'd pull delivery confirmation, device history, and prior clean orders.

The ACH return process has no field for any of it. The returned funds come straight back out of your account.

A few return reasons do give the merchant a chance to send the bank information, such as an item not received or not as described. The bank still decides in one round.

So for a merchant, an unauthorized ACH return lands on you by default. You lose the goods and the payment, the same double hit a card chargeback creates. You just don't get the reason code telling you what evidence would have helped.

Your leverage comes earlier. Decide whether to accept ACH on orders large enough to hurt, and watch for returns fast enough to stop the next shipment to that buyer.

2026 Nacha rule changes businesses should know

From 2026, Nacha requires businesses that send ACH payments to run risk-based fraud monitoring. That duty used to be the receiving bank's job alone, and it now belongs to the sending business too.

The requirement phases in by volume, on March 20, 2026 and then June 19, 2026:

PhaseDateWho it covers
Phase 1March 20, 2026Business senders with 2023 ACH volume of 6 million transactions or more
Phase 2June 19, 2026Every remaining business sender, whatever its volume

A small business sending ACH through a processor is covered by the June date, well below the Phase 1 threshold.

Picture a business that pays vendors and payroll by ACH. Once that deadline lands, any one of three approaches satisfies the rule:

  1. Batch screening before each payment run releases.
  2. A post-posting review of what already went out.
  3. Payee flags on anyone added in the last 30 days, anyone whose bank details just changed, or any unusually large amount.

The rule aims at fraud in the payments a business sends, including the tricked-into-approving kind.

Incoming bad debits stay under UCC Article 4A and your account agreement.

ACH fraud vs. wire fraud

An ACH debit clears in batches and can be returned for days after, while a wire settles one-to-one and is final on receipt. Both move money between banks, and that difference decides how much time you have.

ACH runs on scheduled batch cycles, and Nacha's rules give the receiving bank a return window after settlement. That window is the chance to claw an ACH debit back. A wire settles under Fedwire rules that make it final on arrival.

The receiving bank can return a wire but is not required to.

Same-day ACH leaves hours instead of days to catch a transfer. Check which ACH speed your bank uses by default, since that setting sets your real return window.

ACH debit fraud vs. ACH credit fraud

ACH debit fraud pulls money out of an account without permission, while ACH credit fraud pushes money out because the victim was tricked. Debit fraud is the common consumer pattern. Credit fraud is the business email compromise pattern.

A debit case is a stolen-access problem. Someone started the pull with details they shouldn't have had, so security controls have something to catch. A credit case is a trickery problem, and the account holder started the payment.

Security tooling struggles most with credit-push fraud.

Payments approved under false pretenses sit between the two, since the account holder did approve them. They still count as fraud under Nacha's 2026 definition, because trickery won that approval.

Bank-side controls: ACH filters and debit blocks

An ACH debit block stops every ACH debit by default, while an ACH debit filter allow-lists senders by company ID. With a block in place, no one can withdraw funds from the account by ACH.

The block is the stricter of the two. It fits an account that never expects an ACH debit, which covers most accounts that only take money in.

The filter fits an account that gets a few real pulls, a recurring vendor or a known biller. The bank automatically returns any debit from a sender outside that list.

Both are bank settings you request rather than software you buy.

A block or filter screens incoming debits only. So a business that approves its own payment under false pretenses walks past both. That gap in coverage is why Nacha put the new duty on senders.

How to prevent ACH fraud

Require dual control on outgoing payments, call vendors back on a number already on file, and put a block or filter on incoming ACH. Each covers a route the others miss:

  1. Require dual control on outgoing payments: Set your bank portal so a second named person approves every ACH payment, and have the bank enforce it.
  2. Call vendors back on a number already on file: When payment details change by email, phone the vendor at a number you checked earlier.
  3. Put a debit block or filter on incoming ACH: Ask your bank for a block if the account should never be debited, or a filter naming approved company IDs.

Write each vendor's checked phone number into their record at onboarding. A change request is the worst moment to look for one, because that's when a fraudster supplies a helpful number.

A transfer that clears both dual control and a callback still goes out.

That happens when a scam takes over the callback number too. A post-release review catches it, comparing each payment against the payee's prior bank details and amount range.

FAQ

What is the ACH network, and who runs it?

The ACH network is a US system that moves money between bank accounts in batches. Payroll, vendor payments, and recurring bills all run on it, under rules Nacha writes and enforces.

Can a business get its money back after ACH fraud?

Sometimes, and it turns on how fast the fraud was reported and whether the business followed its account agreement. Recovery is the bank's call, governed by that agreement rather than federal law.

Does ACH fraud insurance exist for small businesses?

Yes, usually as a crime or cyber policy rider covering funds transfer fraud and social engineering losses. Check whether the policy requires dual control and callback verification, because a claim can be denied if you skipped them.

Can Chargeback.io alerts catch ACH fraud?

No. Our alerts work through the card networks, and an ACH transfer never touches those networks.

Senken Sie noch heute Ihre Streitquote

Schließen Sie sich über 800 Unternehmen an, die Chargeback verwenden, um Rückbuchungen automatisch zu verhindern — die Einrichtung dauert weniger als 2 Minuten.