search

ACH Fraud: Types, Detection Methods, and Nacha Rule Updates

6/3/2026

ACH fraud is easy to underestimate because individual events are usually small. The exposure is structural rather than dramatic: enormous volume, thin margins on each transaction, return windows measured in days for businesses, and a warranty framework that puts the originating institution on the hook for entries its customer transmitted.

The Two Directions

ACH moves value two ways, and fraud on each behaves differently.

Debit fraud — someone pulls money from an account they are not authorized to debit. They need only a routing number and an account number, both printed on every check ever written. The account holder discovers it on a statement or an alert.

Credit fraud — someone pushes money out of an account, usually after account takeover or through a compromised originator. This is the direction that produces large losses, because the fraudster controls the timing and the destination.

Institutions frequently build controls for debit fraud, which is visible and generates customer complaints, while leaving credit origination less monitored — which is where the money actually leaves.

The Fraud Patterns

Unauthorized consumer debits. A merchant or fraudster debits a consumer account without valid authorization. Reg E and the Nacha Rules both provide recourse, and the return window is comparatively generous.

Unauthorized business debits. The same act against a business account, with a return window of roughly two banking days rather than sixty. Businesses that do not reconcile daily discover these after the window has closed.

Account takeover credit origination. A business customer's online banking credentials are compromised and the attacker originates a batch of credits to mule accounts, frequently timed for a Friday afternoon or before a holiday.

Payroll diversion. An employee's direct deposit details are changed through a compromised self-service portal. Small per event, and it recurs monthly until noticed.

Originator fraud. A business signs up for ACH origination, establishes normal behavior, then transmits a large batch of unauthorized debits and disappears. The originating institution warrants those entries to the network — so when the receivers return them and the originator's account is empty, the loss is the bank's.

Vendor payment redirection. The same social engineering used against wires, executed over ACH. Slower, and therefore occasionally recoverable.

Mule networks. Accounts opened specifically to receive fraudulent credits and move them onward quickly. This is where ACH fraud intersects with new account fraud and BSA reporting.

Return Windows and Why They Decide the Loss

The most operationally important thing to know about ACH.

Consumer unauthorized debits may generally be returned within 60 calendar days of settlement, supported by a written statement of unauthorized debit. Reg E error resolution runs in parallel with its own timeframes.

Corporate entries carry a return window of roughly two banking days. There is no consumer-style protection, and a business that reconciles monthly has no remedy for anything discovered after that window.

Administrative returns for wrong or closed account numbers have their own short windows.

The practical consequence is that business customers must reconcile daily and must use blocks and filters, because the recourse a consumer relies on does not exist for them. A treasury officer who has not explained this has left the customer exposed to something they believe they are protected against.

Originator Risk Management

The ODFI warrants to the network that entries it transmits are authorized and comply with the rules. That warranty is the source of the bank's exposure, and Nacha's risk management requirements exist to contain it.

What sound originator management involves:

  • Due diligence before origination — know the business, its customers, the entry types it will send, and why
  • Exposure limits per originator, per file, and per day, set to actual need and enforced by the system rather than by policy
  • Origination agreements with the required terms
  • Return rate monitoring against Nacha's thresholds for unauthorized and administrative returns, with inquiry and remediation when they are approached
  • Prefunding or reserve requirements for higher-risk originators
  • Third-party sender oversight, which is where concentrations of unknown originators hide
  • Periodic re-review, since an originator's risk changes as its business does

Return rate breaches are the leading indicator. An originator whose unauthorized return rate is climbing is either running a bad process or running a scheme, and either way the trend appears before the loss.

Detection and Prevention

For the bank's own customers:

  • ACH debit blocks — no debits permitted at all, appropriate for accounts that should never be debited
  • ACH debit filters — debits permitted only from an approved originator list
  • ACH positive pay — exceptions reported for customer decision
  • Alerts on originated batches, new payees, and unusual amounts
  • Dual control on origination, with initiation and release separated

Inside the bank:

  • Velocity and anomaly monitoring on origination — batch size, timing, destination concentration, and new receiver accounts
  • Out-of-band verification for changes to origination profiles and limits
  • Daily review of returns by originator
  • Monitoring for inbound credit concentration, which identifies mule accounts on the receiving side

Nacha Rules and Risk Management

Nacha maintains the Operating Rules that bind participating institutions by agreement, and has been progressively strengthening the risk management provisions — including requirements around monitoring, originator and third-party sender oversight, account validation for certain entry types, and obligations aimed at detecting and recovering funds involved in fraud.

NOTE TO EDITOR: Nacha rule amendments take effect on staged dates and the fraud monitoring provisions in particular have phased implementation. Confirm which requirements are currently in force, and their effective dates, before publishing any specific rule reference. Nacha publishes the schedule directly.

The direction of travel is worth understanding even where a specific effective date is pending: obligations are shifting from a purely originator-side model toward shared responsibility, with receiving institutions expected to participate in detecting suspicious inbound credits rather than treating a properly formatted entry as someone else's problem.

Structured coverage is available through our ACH and wire transfer training, Payments and Settlements, and the Certificate in Fraud Prevention.

The Receiving Side Deserves More Attention

Most ACH fraud programs are built around origination, because that is where the bank's warranty exposure sits. But every fraudulent credit lands somewhere, and the receiving institution is frequently the only party positioned to stop the money moving onward.

The signals are visible in deposit behavior rather than in the entries themselves. An account with a modest history receiving a large inbound credit and immediately moving the funds out. Multiple unrelated accounts receiving credits from the same originator within a short window. New accounts whose first meaningful activity is an inbound ACH followed by rapid dispersal. Accounts opened remotely, funded by an inbound credit, with no other relationship activity.

Two reasons to invest here even though the receiving institution rarely bears the loss. First, recovery is only possible while funds remain in the account, and the receiving bank is the only party who can freeze them — a request from the originating institution that arrives after the funds have moved is a formality. Second, an institution whose accounts repeatedly serve as mule destinations has a BSA problem regardless of the fraud loss, and that pattern is visible in its own data long before anyone calls.

The practical addition is a monitoring rule on inbound credit followed by rapid outbound movement, reviewed daily, with authority to place a hold pending review. It generates false positives on legitimate business activity and is still worth running, because the alternative is learning about the mule account from a law enforcement subpoena.

Explaining the Asymmetry to Commercial Customers

The conversation that prevents most commercial ACH loss is uncomfortable, because it involves telling a customer that the protections they assume they have do not exist.

Business owners reason from personal experience. They know that a fraudulent charge on their own debit card gets reversed, and they extend that expectation to the business account without ever being told the two are governed by different rules. The gap is enormous — sixty calendar days for a consumer, roughly two banking days for a corporate entry — and the customer usually discovers it during a loss.

Three things worth saying explicitly at onboarding and repeating at annual review.

The window is days, not weeks. An unauthorized debit found on a month-end reconciliation is generally unrecoverable through the network. Daily review of posted items is not a best practice for a business account; it is the only thing that preserves the remedy.

Blocks and filters are the actual protection. For an account that should never be debited, a block eliminates the exposure completely. For an account with a handful of known originators — a payroll provider, a tax authority, a utility — a filter permits those and rejects everything else. Both are inexpensive and both are declined constantly because nobody explained what they prevent.

Origination credentials are the larger exposure. A customer who originates ACH has the ability to push money out, and compromised credentials can drain far more than any inbound debit. Dual control on origination, with initiation and release held by different people using different credentials, is the control that matters — and it is the one customers most often disable for convenience.

Document the conversation. A customer who declined blocks and dual control in writing, after being told what they protect against, is in a materially different position from one who was never offered them — and so is the bank.

One structural note for institutions weighing where to place ACH risk management. It sits awkwardly between treasury management, which owns the customer relationship and the revenue, and operations, which processes the files, and fraud, which absorbs the loss. Where it reports to treasury alone, exposure limits tend to be set at whatever the customer asks for, because the person setting them is compensated on the relationship. Where it reports only to operations, the risk assessment of new originators is frequently a formality performed after the sale. The arrangement that works assigns originator approval and limit setting to a function independent of the revenue line, with treasury as the advocate rather than the decision maker — the same separation that governs credit approval, and for the same reason.

Frequently Asked Questions

How long does a business have to return an unauthorized ACH debit?

Roughly two banking days for corporate entries — dramatically shorter than the sixty calendar days available for unauthorized consumer debits. Businesses that reconcile monthly routinely discover unauthorized debits after the window has closed, which is why daily reconciliation and ACH blocks or filters are essential for commercial accounts.

What is the difference between an ACH block and an ACH filter?

A block prevents all ACH debits from posting to the account. A filter permits debits only from originators on an approved list, rejecting everything else. Blocks suit accounts that should never be debited; filters suit accounts with a small number of known, legitimate debit originators.

Why is the originating institution liable for its customer's entries?

Because the ODFI warrants to the network that the entries it transmits are authorized and comply with the Nacha Rules. If the originator cannot produce authorization, or transmits improper entries, the ODFI is liable to the receiving institution regardless of whether it can recover from its own customer.

What are Nacha return rate thresholds?

Limits on the proportion of an originator's entries returned as unauthorized or for administrative reasons. Exceeding them triggers inquiry and potential enforcement through the network's process. Rising return rates are the most reliable early indicator that an originator is either running a poor process or running a scheme.

Is ACH fraud covered by Regulation E?

For consumer accounts, yes — unauthorized ACH debits to a consumer account fall within Reg E error resolution and liability provisions. Business accounts are outside Reg E entirely and are governed by the Nacha Rules and the deposit agreement, which is why outcomes for a business and a consumer can differ sharply on identical facts.

What should a receiving institution watch for?

Inbound credits followed by rapid outbound movement, multiple unrelated accounts receiving credits from the same originator, and newly opened accounts whose first meaningful activity is an inbound ACH followed by dispersal. Recovery is only possible while funds remain in the account, and the receiving bank is the only party able to freeze them.

BankTrainingCenter.com 9715 Rod Road Suite A Alpharetta, GA 30022 1-770-410-1219 support@BankTrainingCenter.com
Certifications Webinars Seminars
Stay Up To Date
Need Training Or Resources In Other Areas? Try Our Other Training Center Sites:
HR Accounting Financial Services Insurance Mortgage Payroll Real Estate Safety
Training By Delivery Format & Subjects Covered:
Special Promotions Online Training Resource Materials Seminars Webinars All Banking Subjects
Facebook Copyright BankTrainingCenter.com 2026