09/24/2026
Stop Commercial Banking Fraud

Fraud targeting business accounts and payment activity is a significant concern for businesses of all sizes.
While every payment method has some level of risk, criminals tend to focus on certain types of transactions and account activity. At the same time, fraud schemes are becoming more convincing and increasingly incorporate tools such as AI. This makes it especially important for businesses to remain alert, monitor financial activity closely, and establish strong safeguards around their accounts and payment processes.
The Evolving Threat:
Business payment fraud is a significant concern. According to the Association for Financial Professionals’ 2026 Payments Fraud and Control Survey, 76% of businesses experienced attempted or actual payments fraud in 2025. Checks were the most frequently targeted payment method, with 58% of organizations reporting check fraud. Business email compromise was also widespread, affecting 74% of organizations during the year, while ACH and wire fraud affected 30% and 25%, respectively.
The Federal Reserve is also focused on the growing risk to businesses. Federal Reserve Financial Services reported that business email compromise was a leading cause of fraudulent ACH and wire transfers from business deposit accounts. In addition, a 2026 Federal Reserve risk officer survey found that financial institutions continue to see significant fraud involving checks, ACH transactions, wire transfers, account takeovers, and social engineering.
These trends demonstrate why businesses should not rely on a single fraud prevention measure. Strong payment controls, employee awareness, independent verification procedures, transaction monitoring, and timely review of account activity can all play an important role in reducing fraud risk.
Common Fraud Schemes and Ways Businesses Can Reduce Their Risk:
Check Fraud:
Paper checks can be particularly vulnerable to fraud on business accounts because a check contains several pieces of information that a criminal can potentially use or alter, including the business name, bank routing number, account number, check number, and signature.
Some of the main reasons include:
- Checks can be stolen. Checks mailed to vendors or deposited through a mailbox can be intercepted before they reach the intended recipient.
- Information can be altered. Fraudsters may use techniques such as check washing to change the payee or dollar amount on a legitimate check.
- Checks can be copied. Criminals can create counterfeit checks using information from a legitimate business check.
- Account information is exposed. Routing and account numbers printed on checks can potentially be used to create unauthorized transactions.
- Signatures can be forged. A stolen check provides an opportunity for someone to attempt to reproduce an authorized signature.
- Businesses often issue many checks. With a higher volume of transactions, an unauthorized check may be harder to notice without regular reconciliation or a fraud-monitoring service.
- Checks can be intercepted after they are issued. Even when a business follows its normal payment procedures, the check can be altered or redirected after leaving the business’s control.
How to alleviate check fraud: Businesses can take several practical steps to reduce their exposure to check fraud. Keep blank check stock in a secure location and limit access to authorized employees. When mailing checks, use secure mailing practices and avoid leaving outgoing checks in an unsecured mailbox. Whenever possible, consider replacing paper checks with digital payment solutions, which can reduce the risks associated with stolen, altered, or counterfeit checks. Businesses can also use check-monitoring services, such as Positive Pay, to compare checks presented for payment against those the business has authorized, helping identify discrepancies before fraudulent items are paid.
ACH Fraud:
ACH transactions provide an efficient and convenient way to move funds electronically, but they can still be targeted by fraudsters. Unauthorized ACH debits may occur when criminals obtain account information or otherwise gain access to payment details. Fraudulent ACH activity can be difficult to identify before processing and, depending on the circumstances, recovering funds after an unauthorized transaction may be challenging.
Common indicators of potential ACH fraud include unfamiliar or unexpected ACH transactions, requests to change established payment information, communications urging immediate action, suspicious or slightly altered email addresses or domains, and attempts to circumvent established authorization or approval procedures. Customers should carefully verify payment instructions and promptly report any ACH activity they do not recognize.
How to alleviate ACH fraud: Businesses can reduce their exposure to ACH fraud by implementing strong controls over the authorization, initiation, and monitoring of electronic payments. Payment instructions and changes to account information should be independently verified through a trusted method rather than relying solely on email. Businesses should restrict ACH access to employees with a legitimate business need and regularly review account activity. Transaction monitoring services, such as Positive Pay, can provide an additional layer of protection by allowing businesses to review, approve, or reject ACH transactions that do not meet established criteria before funds are withdrawn.
Account takeover fraud:
Business account takeover fraud occurs when an unauthorized individual gains access to a business’s online banking, payment systems, email, or other financial accounts, often through compromised login credentials, phishing schemes, malware, or social engineering. Once access is obtained, the fraudster may alter passwords, security settings, user access, or contact information to prevent legitimate users from accessing the account. The criminal may then use the compromised account to initiate unauthorized payments, transfer funds, add or modify users, or make other changes designed to facilitate fraudulent activity.
Account takeover can be particularly difficult to identify when the unauthorized activity appears to originate from a legitimate user or trusted device. Businesses should be alert to unexpected changes to account settings or user permissions, unfamiliar login activity, new devices or locations, and password or contact information changes that were not requested
How to alleviate account takeover fraud: Businesses can reduce their chances of account takeover fraud by using layered security controls and limiting access to financial systems based on each employee’s role and responsibilities. Strong, unique passwords should be required, and shared login credentials should be avoided. Employees should be trained to recognize phishing emails, suspicious links, social engineering attempts, and other methods used to obtain login credentials. Separating payment preparation from payment approval and requiring dual authorization for certain transactions can provide an additional safeguard.
Business email compromise:
Business Email Compromise (BEC) is a form of fraud in which criminals use compromised email accounts, spoofed addresses, or social engineering to impersonate a business owner, executive, employee, or trusted business partner. The fraudster may use the compromised or fraudulent email account to request payments, provide false payment instructions, obtain sensitive information, or persuade employees to bypass established procedures. BEC schemes can be difficult to recognize because the messages may appear legitimate and often reference actual business relationships or transactions. Warning signs include unexpected requests involving money or account information, changes to previously established payment instructions, unusual urgency or secrecy, requests to bypass normal approval procedures, and subtle changes in email addresses or domains.
How to alleviate BEC: Businesses can reduce the risk of Business Email Compromise (BEC) by establishing clear procedures for verifying payment requests and changes to payment instructions. Employees should independently confirm unusual or high-dollar requests using a known telephone number or other trusted communication method rather than relying on the email itself. Strong email security, multifactor authentication, unique passwords, and regular monitoring for suspicious login activity can help protect business email accounts from compromise.
Vendor fraud:
Vendor fraud involves the use of deceptive practices to obtain unauthorized payments from a business by exploiting its relationships with suppliers, contractors, or service providers. Fraudsters may impersonate legitimate vendors, submit false or inflated invoices, create fictitious vendor accounts, or attempt to redirect legitimate payments to an account they control. In other cases, an individual with access to the business’s purchasing or payment processes may manipulate transactions for personal gain.
How to alleviate vendor fraud: Businesses can reduce the risk of vendor fraud by establishing strong controls over vendor onboarding, invoice processing, and payment changes. Vendor information should be independently verified before a new vendor is added or existing payment instructions are modified, with account changes confirmed using trusted contact information already on file. Regularly reviewing vendor accounts and comparing invoices against purchase orders, contracts, and prior billing can help identify unusual or duplicate charges.
Business Fraud Mitigation Best Practices:
Fraud prevention is most effective when businesses use multiple layers of controls rather than relying on a single safeguard. Here are some additional tips:
- Establish strong internal controls. Develop clear policies for handling money, payments, sensitive information, purchasing, and financial records. Controls should include defined responsibilities and appropriate approval requirements.
- Use segregation of duties. Whenever practical, separate the responsibilities for initiating, approving, recording, and reconciling financial transactions. No single employee should have complete control over a financial process.
- Limit employee access. Provide employees with access only to the systems, information, and financial functions necessary for their job responsibilities. Review access periodically and immediately when an employee changes roles or leaves the organization.
- Implement strong authentication. Require multifactor authentication where available, particularly for email, financial systems, payroll, and other sensitive applications. Employees should use unique passwords and avoid sharing credentials.
- Train employees regularly. Provide ongoing education regarding phishing, social engineering, impersonation, fraudulent requests, cybersecurity threats, and other common fraud techniques. Employees should know how and where to report suspicious activity.
- Maintain strong physical and cybersecurity controls. Protect computers, mobile devices, financial records, customer information, and other sensitive data. Keep software and security systems updated and restrict access to sensitive areas.
- Control sensitive information. Limit access to customer, employee, financial, and business information. Establish procedures for securely storing, transmitting, and disposing of confidential records.
Yakima Federal is here to help!
At Yakima Federal, we’re proud to support the local businesses that help our community thrive. When you open an Advantage Business Checking account, you’ll have access to a suite of business banking services designed to make managing your finances easier while providing additional tools to help protect your business from fraud. Services such as:
Positive Pay: Positive Pay provides businesses with an added layer of protection by helping identify potentially fraudulent checks and ACH transactions before they result in a loss. For check transactions, the business provides information about checks it has issued, allowing exceptions to be identified when a check presented for payment does not match the business’s records. ACH Positive Pay similarly allows businesses to establish criteria for authorized ACH activity and review transactions that fall outside those parameters. When an exception is identified, the business can review the transaction and determine whether it should be paid or returned. By combining transaction monitoring with business-controlled review and decision-making, Positive Pay can help businesses detect unauthorized activity and reduce their exposure to payment fraud.
Account Alerts: Businesses enrolled in online banking can set up account alerts to stay informed about activity affecting their accounts. Alerts can be delivered by text or email and can notify you when your account balance rises above or falls below a specified threshold, a check clears the account, someone logs in to online banking, or other selected account activity occurs. These real-time notifications provide businesses with greater visibility into their account activity and can help identify unusual or unauthorized activity more quickly.
Cash Flow Central: Cash Flow Central provides businesses with a centralized, digital solution for managing payables and receivables while helping streamline everyday financial processes. Businesses can use the service to manage and pay bills electronically, reducing the need to write and mail paper checks and limiting the amount of check stock kept on hand. Moving more payments to a digital process can help reduce opportunities for checks to be lost, stolen, altered, or counterfeited, while also making it easier for businesses to manage and monitor their payment activity. For businesses that continue to issue paper checks, pairing Cash Flow Central with Positive Pay can provide an additional layer of protection against check fraud.
Key takeaways:
- Fraud can take many forms. Businesses should understand the risks associated with ACH fraud, account takeover, business email compromise, vendor fraud, and other types of financial fraud.
- Strong internal controls are the first line of defense. Segregation of duties, dual authorization, appropriate access controls, and independent reviews can help reduce opportunities for fraudulent activity.
- Protect access to financial information. Strong passwords, multifactor authentication, limited user access, and regular access reviews can help protect business accounts and sensitive.
- Monitor account activity. Account alerts, transaction monitoring, and services such as Positive Pay can help businesses identify unusual or potentially fraudulent activity sooner.
Fraud prevention starts with awareness and is strengthened through layers of protection. By combining sound business practices, employee education, account monitoring, and available fraud-prevention services, businesses can better protect their finances and reduce their exposure to fraud.


Banks Never Ask That!

