ACH Payment Fraud: How SMBs Can Prevent And Mitigate Risks
Protect your small business from ACH fraud with simple steps you can put to work today.
Key takeaways
- Recognize the main ACH fraud types, from stolen credentials to social engineering, so you can spot them early.
- Apply layered safeguards like limiting account access, verifying payment changes by phone, and turning on account alerts.
- Act fast if you are targeted by reporting to your bank, local law enforcement, and the FBI to improve your chances of recovery.
- Use a secure digital payment platform so you never share your bank details to send or get paid.
First, what’s an ACH payment?
An ACH (automated clearing house) payment (or ACH bank transfer) is an electronic funds transfer (EFT) made through a network of financial institutions (also known as clearing houses).
The ACH network allows for the secure electronic transfer of money between bank accounts in the U.S. and around the globe. To transfer money through the network, member institutions must abide by the rules and regulations enforced by its governing organization, Nacha.
The ACH network moved 35.2 billion payments worth a total of $93 trillion in 2025. Its popularity can be partly explained by relatively low fees, ranging from a few dollars through most banks to free on some digital accounts payable (AP) tools like Melio.
Common types of ACH payment fraud that affect small businesses
Any theft of funds via an unauthorized or fraudulent ACH payment is considered ACH fraud. Once they have illegally obtained the money, in most cases, the offender will quickly withdraw the funds to a debit card or another account before a dispute can be opened.
Here are the most common ways fraudsters target SMBs for ACH payment fraud.
Stolen credentials
The simplicity of ACH payments is also what makes life so easy for some fraudsters. All they need to do is retrieve your bank account number and routing number. They then use your bank information to send money to an account they control or set up payments for services and goods that you never bought.
These are some of the ways scammers use to get their hands on private banking information:
- Data breach. Your bank information is likely logged not just in your systems but in those of your vendors, service providers, and customers. If any one of those is breached, this could make you vulnerable to an attack. What we’re trying to say is, never keep your bank details out in the open for everyone to see. By the way, a data breach doesn’t have to be the result of hacking. For example, if you keep a sticky note with your bank info on your screen for easy access, then anyone passing through your office could immediately gain access to your funds.
Social engineering
In this scenario, an attacker will impersonate one of your employees or vendors to get you to transfer money to the wrong account. Identity theft often involves the use of some genuine stolen information to increase credibility and make it more likely for you to take the bait.
For identity theft-based ACH fraud, an attacker may use:
- A legitimate but hacked email owned by the person they’re impersonating.
- A fake email with an address that looks similar enough for you to mistake it for genuine.
- Fake invoices with some of your vendor’s real details but the fraudster’s own bank information on them.
- SMS spoofing, which refers to text messages that appear to originate from the person being impersonated.
Kiting
The illegal activity in which the criminal utilizes the time it takes banks to process transactions to fraudulently gain credit or steal additional money is known as kiting.
Kiting inflates a fake balance by shuffling money between accounts. The cycle repeats until the fraudster is caught or cashes out. If your payment lands at the end of the cycle, you take the loss.
Kiting was originally done with paper checks but can also be implemented with ACH transactions that typically take a few days to process.
Here are two scenarios to explain how ACH kiting may affect your small business.
Scenario 1: The fraudster uses ACH to pay from one account with insufficient funds. Before the money is deducted, they use a second account with insufficient funds to send another ACH transfer to cover the first one.
Doing so, they convert the ACH payment into short-term credit without the necessary financial backing.
Scenario 2: A customer makes a purchase and pays using an ACH bank transfer. They then claim there’s an issue with the product, requesting a full or partial refund in cash, via debit or any other immediate method while the ACH transaction is still being processed.
The unsuspecting business issues the refund only to discover a few days later that the original payment was rejected due to insufficient funds, as the scammer already drained the account.
Who is liable for ACH fraud?
Liability for ACH fraud depends on the situation, and the rules generally lean in favor of the customer. Banks usually reimburse a customer for an unauthorized debit when it is reported quickly. Businesses can end up covering the loss when weak internal controls let the fraud through.
Here is how responsibility tends to fall for small businesses:
- Unauthorized debits: your bank often reimburses you if you report the charge within the required window.
- Business email compromise: the business may absorb the loss when an employee approves a fraudulent transfer.
- Vendor and invoice scams: the party that failed to verify the payment change usually carries the loss.
The takeaway is simple. Strong controls and fast reporting protect both your money and your position if a dispute comes up.
8 ACH payment fraud prevention strategies for small businesses
SMBs don’t typically have a lot of resources to fight fraud attempts but not everything costs money. By being more aware of the risks, keeping a close eye on details, and implementing a few extra security measures, you can significantly reduce your business’s exposure to ACH fraud.
Below are eight tips to mitigate risks without breaking the bank (or letting anyone break in).
1. Keep bank details on a need-to-know basis
Your account and routing numbers are all a fraudster needs, so sharing them too widely is a security risk, allowing criminals to pull funds from your account. So, it’s important to minimize the number of people who are exposed to this sensitive information.
Your bookkeeper obviously needs to have them, but not every employee that comes through the door should have this access. Use your good judgment to decide who really needs this information to do their day-to-day job.
2. Use 3-way matching
One way to fend off invoice-based ACH fraud is to perform 3-way matching to make sure you’re paying the right person for the right thing. This process includes comparing the contents of the invoice you received against your purchase order and order receipt. The most important details that need to be matched are the sum, the goods provided, and the vendor’s payment information.
3. Don’t click on random links
This cybersecurity best practice isn’t limited to preventing financial fraud. Malicious links are one of the most common ways hackers use to infect your devices with malware and spyware. These malicious programs can be used by an attacker to cause substantial damage to your business through fraud.
So, always be wary of links and only click them when you’re 100% sure you know who sent them and why and that they are reliable.
4. When in doubt, call
Whenever anything looks suspicious, for example, an email riddled with typos or just an out-of-the-blue request to update the payment details, pick up the phone to double-check with your vendor or employee before sending a payment.
Don’t be tempted to simply text back as you could find yourself conversing with your attacker. With a call, you’ll have a much better chance of knowing you’re talking to the right person. Also, make sure the number you’re calling is the one in your files, not in the suspect invoice or message.
5. Educate yourself (and your team)
As technology advances, attackers are constantly getting more sophisticated so it’s important to stay up to date on the threats relevant to your industry. It’s also crucial to periodically train your team on potential threats and ways to detect them.
6. Make sure you’re covered
If you do fall victim to ACH fraud from an insider threat, having fidelity insurance can help significantly cut your losses. This type of insurance covers your company against monetary and physical damage caused by fraudulent or otherwise dishonest activity by someone on your team.
7. Keep an eye on your money
While Nacha and the bank offer protection against unauthorized and fraudulent ACH payments, it’s your responsibility to monitor the movements in your account and promptly report anything suspicious. So, it’s very important you know exactly what’s going on in your account at all times.
Check with your bank to see if it offers notifications via email or text whenever a transaction is made. This can help make sure no transaction goes unnoticed without requiring daily logins to your account.
8. Use digital payment platforms
A digital payment platform like Melio hides and encrypts your bank details, so you never share account numbers with customers or staff to send or receive a payment. You no longer have to give out your details to customers in order to get paid or to your employees to allow them to pay.
When you input your payment and bank details, they are kept hidden and encrypted to ensure your money stays yours.
These platforms also allow you to establish payment approval workflows so you get the final say on every payment before it goes out.
What to do if you’re targeted by ACH fraud
Acting fast gives you the best chance to limit the damage and recover funds. If you spot a suspicious ACH transaction, treat it as urgent and work through these steps:
- Contact your bank right away and report every unauthorized transaction.
- Freeze or change the affected account credentials so no new payments can go out.
- File a report with local law enforcement to create a record of the crime.
- Report the fraud to the FBI through its Internet Crime Complaint Center.
- Watch your account closely over the following weeks for any further activity.
Keep notes of every call and confirmation. A clear record helps your bank investigate and supports any dispute you need to file.
Keep your business safe and in business
Where there’s money, there are fraudsters, and no business is 100% safe from an attack. But, taking the measures outlined above can go a long way in preventing ACH fraud.
Start by taking a few moments to sign up for Melio today to manage your payments in a secure and transparent way. The best part? There are no subscription fees or strings attached.
ACH fraud FAQs
Can ACH payments be traced?
Yes. ACH payments can be traced. Your bank can file an ACH trace request to follow the transaction, though the process can take several business days.
What can someone do with your bank account and routing number?
With your account and routing number, a fraudster can try to set up unauthorized debits or payments. That is why it is smart to limit who has access to these details.
Is ACH safer than paying by check?
ACH payments avoid the mail theft and check washing that affect paper checks. Both methods carry risk, so controls and monitoring matter more than the method itself.
How long does an ACH payment take to clear?
A standard ACH payment usually takes a few business days to clear. That processing window is one reason fraudsters try schemes like kiting.
*This blog post is intended for informational purposes only and is not intended as financial advice.
**Melio does not provide legal, tax or accounting advice, and you should consult with a professional advisor before making any financial decisions.