Most of the organizations we work with, including small businesses and nonprofits, assume bank fraud is something that happens primarily to larger organizations. In reality, smaller organizations can be attractive targets because they may have fewer controls, fewer reviewers, and less separation of duties.

You do not need to be large to be worth stealing from. You simply need to be reachable and move money.


How the Money Actually Leaves

Business Email Compromise

Vendor payment fraud, executive impersonation, and payroll diversion remain major paths to financial loss. Attackers may compromise a legitimate mailbox, monitor existing conversations, and then insert fraudulent payment instructions at the right moment. They may also spoof or impersonate executives, vendors, attorneys, title companies, or other trusted parties.

The FBI’s guidance on Business Email Compromise recommends independently verifying payment and account changes rather than relying on information contained in the suspicious message itself.

Banking Portal Takeover

Credential theft, malware, phishing, fake support calls, MFA attacks, and stolen browser sessions can provide criminals with access to online banking systems. Once inside, an attacker may attempt to add recipients, change payment instructions, initiate transfers, or alter notification settings.

Check Fraud

Mail theft, counterfeit checks, check washing, and altered checks remain active criminal techniques despite the growth of electronic payments. Organizations that continue to issue checks should consider bank controls such as Positive Pay or Payee Positive Pay.

Unauthorized ACH Debits

Criminals who obtain an organization’s routing and account numbers may attempt unauthorized ACH debits. Bank-side controls such as ACH debit blocks and ACH filters can substantially reduce this risk.

Wire Transfer Fraud

Fraudulent wire instructions are particularly dangerous because funds can move quickly and may be difficult to recover. Most fraudulent wires begin with the impersonation described above, and the wire itself is simply the last step in a sequence that started in someone’s inbox.

Any unexpected change to wire instructions, account numbers, beneficiary information, or payment procedures should be independently verified using contact information that was established before the change request was received.

Voice and Video Impersonation

AI-generated voice and video can make fraudulent calls and virtual meetings appear more credible. Organizations should not rely on someone’s voice, appearance, caller ID, or a familiar-looking video conference as proof of identity.

For sensitive financial requests, call back using a trusted phone number already on file and verify both the person’s identity and the requested transaction. Prearranged verification procedures or passphrases can provide an additional layer of protection.

Insider Fraud

When one individual controls purchasing, payment approval, account access, and reconciliation, fraud may remain undiscovered for extended periods. Separating financial responsibilities makes both internal and external fraud more difficult to execute without detection.


Defenses That Hold Up

Start With Your Bank

Many of the strongest protections against bank fraud are controls that your financial institution enforces rather than policies that exist only inside your organization. Ask your commercial banker which of the following services are available:

  • ACH Debit Blocks or ACH Filters
  • Positive Pay, preferably Payee Positive Pay when available
  • Bank-Enforced Dual Authorization for wires, ACH transactions, and other significant transfers
  • Account Segmentation so operating funds and reserves are not unnecessarily exposed
  • Transaction Limits and Alerts appropriate to the organization’s normal activity

Important: Many consumer banking protections do not apply to accounts established primarily for business purposes. Business accounts may be subject to different laws, agreements, reporting deadlines, and fraud-allocation provisions. For example, the CFPB’s Regulation E definition of an account generally refers to accounts established primarily for personal, family, or household purposes.

Commercial funds transfers are generally governed by Article 4A of the Uniform Commercial Code as adopted in your state, together with the terms of your deposit and treasury-services agreements. Those agreements frequently set a deadline for reporting unauthorized transactions that is far shorter than the timelines many people associate with consumer accounts. Find out what your organization’s actual deadline is before you need to know. Organizations should discuss applicable protections, account agreements, reporting requirements, and fraud-control options with their banker and legal counsel.

Improve Internal Procedures

  • Verify changes to payment instructions, bank accounts, payroll deposits, or vendor information using a trusted phone number already on file.
  • Never rely solely on contact information contained in the email, text message, invoice, or document requesting the change.
  • Treat unusual urgency, secrecy, changes in procedure, and unexpected payment changes as warning signs.
  • Use out-of-band verification procedures and, when appropriate, prearranged passphrases.
  • Require two-person approval for significant transfers whenever possible.
  • Separate purchasing, payment approval, transaction initiation, and reconciliation duties whenever staffing allows.
  • Review bank transactions frequently rather than waiting for the monthly statement.

Strengthen Authentication

  • SMS Codes: Better than passwords alone, but vulnerable to phishing, SIM-related attacks, and other interception techniques.
  • Push Notifications: Convenient, but susceptible to approval-fatigue attacks and some forms of phishing.
  • Authenticator Apps: Generally stronger than SMS, but traditional one-time codes can still be phished.
  • Hardware OTP Tokens: Reduce dependence on a user’s phone and can be a useful option for commercial banking, but one-time passwords are not inherently phishing-resistant.
  • FIDO2 Security Keys and Passkeys: Phishing-resistant authentication and the preferred approach when the service supports it.

CISA recommends moving toward phishing-resistant FIDO authentication where possible. For most organizations, strong bank-supported authentication for financial systems combined with FIDO2 security keys or passkeys for Microsoft 365 and other critical cloud services provides a substantial improvement over relying exclusively on phone-based authentication.

Organizations using Microsoft 365 can review Microsoft’s current guidance on passkeys and FIDO2 authentication in Microsoft Entra ID.

Harden Supporting Technology

  • Disable external email auto-forwarding unless there is a documented business requirement.
  • Monitor for suspicious inbox rules, forwarding rules, and new MFA or authentication registrations.
  • Implement anti-impersonation and anti-phishing protections in your email platform.
  • Deploy and properly configure DMARC, SPF, and DKIM for organizational email domains.
  • Protect administrator accounts more aggressively than ordinary user accounts.
  • Keep operating systems, browsers, financial software, and endpoint security tools updated.
  • Consider using a dedicated banking workstation or tightly controlled device for organizations with significant transaction volume.
  • Review cyber-insurance and crime-insurance coverage specifically for social engineering, funds-transfer fraud, computer fraud, and related losses.

What to Do When It Happens

Speed matters more than certainty. If money has been sent to a fraudulent recipient, begin the response immediately rather than waiting to complete an internal investigation.

The reason is the reporting window. The FBI’s Internet Crime Complaint Center operates a Recovery Asset Team that works with financial institutions and FBI field offices to request that a recipient bank freeze funds transferred under fraudulent pretenses. The formal criteria allow up to 72 hours after the transfer, but investigators consistently advise reporting within 48 hours and preferably the same day, because stolen funds are typically broken up and moved onward within hours of arriving.

  1. Immediately contact your bank’s fraud department. For fraudulent wires or transfers, request an immediate recall or recovery attempt and ask the bank to contact the receiving financial institution. The FBI specifically recommends contacting your financial institution immediately after discovering Business Email Compromise or fraudulent transfers.
  2. File a complaint with the FBI Internet Crime Complaint Center (IC3) the same day. Provide as much transaction and recipient-bank information as possible. For international wires, additional criteria generally apply before the Financial Fraud Kill Chain can be activated, including a transfer of $50,000 or more, an initiated SWIFT recall, and reporting within the 72-hour window.
  3. Contact the appropriate law-enforcement agency. For significant or active cyber-enabled financial fraud, this may include your local FBI field office as well as local law enforcement.
  4. Preserve evidence before cleanup begins. Retain suspicious emails, complete email headers, text messages, invoices, transaction confirmations, bank information, call records, authentication logs, and other relevant records.
  5. Notify your insurance carrier. Cyber, crime, and funds-transfer policies may contain specific reporting requirements or deadlines.
  6. Secure compromised accounts. Reset affected credentials, terminate active sessions where possible, review MFA registrations, inspect inbox and forwarding rules, and investigate how the compromise occurred.

Document these procedures before an incident occurs and make them easily accessible to finance staff, management, and your IT provider. Your response plan should include current telephone numbers for your bank’s fraud department, insurance carrier, IT provider, and other critical contacts.


A Practical Bank Fraud Checklist

  • Two-person approval for significant transfers
  • Independent verification of payment and banking-detail changes
  • Strong MFA for commercial banking
  • Phishing-resistant MFA for Microsoft 365 and other critical systems where supported
  • ACH debit blocks or filters enabled where appropriate
  • Positive Pay or Payee Positive Pay enabled for checking accounts
  • Transaction limits established based on normal business activity
  • Bank alerts sent to multiple appropriate recipients
  • Reserve funds separated from accounts used for routine payments
  • Frequent transaction review and reconciliation
  • Known reporting deadline for unauthorized transactions under your account agreement
  • Written fraud-response procedure with current bank and insurance contact information

Common Questions We Hear

Are text-message codes enough?

They are better than passwords alone, but SMS-based authentication remains vulnerable to phishing and other attack methods. Use stronger authentication when your bank or application supports it, particularly for email, administrative accounts, and systems capable of moving money.

Does my bank offer hardware tokens?

Many commercial banking platforms offer hardware tokens, dedicated authentication devices, or other stronger authentication options, but organizations may need to request them. Ask your commercial banker what authentication methods are available and whether different options can be required for administrators or users who initiate and approve transactions.

What is the single highest-value control?

For many organizations, one of the highest-value combinations is bank-enforced dual approval for significant transfers together with independent verification of changes to payment instructions.

The important distinction is that neither control depends entirely on an email account being trustworthy. Even if an attacker compromises a mailbox and sends convincing instructions, the transaction still encounters an independent verification or approval step.


The Short Version

Ask your bank about Positive Pay, ACH debit blocks or filters, transaction limits, alerts, and bank-enforced dual authorization. Independently verify vendor and payment changes through previously established contact information. Use strong authentication for banking and phishing-resistant security keys or passkeys for critical cloud services where supported. Separate reserve funds from accounts that routinely initiate payments, and document your incident-response procedure before you need it.

If fraud occurs, contact your bank immediately and file with IC3 the same day. Recovery becomes substantially more difficult as time passes.

If you would like a second set of eyes on any of this, we are glad to help. Most of what we have described takes one conversation with your banker and an afternoon of configuration, and we regularly walk clients through exactly which controls their institution offers and which ones are worth turning on. Contact us and we will review your current setup with you.

Katy Computer Systems has supported small businesses, nonprofits, synagogues and churches in the St. Louis area since 1988. Reviewed August 2026. This article is general information and is not legal, insurance, or financial advice.

Skip to content