SardineCon SF/2026

Learn More

What is ACH fraud?

SUBSCRIBE

ACH fraud is theft that moves money over the ACH network, the system US banks use for direct deposits and bill payments. It works because ACH needs only an account and routing number, not a password, and the money takes a day or more to settle, and that slow window is exactly what fraudsters exploit.

What is ACH fraud, in plain English?

ACH stands for Automated Clearing House, the batch network that moves most everyday US bank-to-bank payments: paychecks, bill pay, vendor payments, and subscription debits. ACH fraud is any theft that rides those rails. The defining weakness is that an ACH transaction is authorized with just an account number and a routing number. There is no PIN, no password, and no card-style security code at the moment of the pull or push.

There are two directions. An ACH debit pulls funds from an account, which is how a fraudster with stolen bank details drains money or how an unauthorized company yanks funds it is not owed. An ACH credit pushes funds out, which is how compromised business banking or payroll gets diverted to a mule. Either way, the credentials needed are printed on the bottom of every paper check.

The second weakness is timing. ACH settles in batches over a day or more, not instantly. That lag gives fraudsters a window to move stolen funds before anyone reconciles, and it means unauthorized activity can surface days or weeks after it posts.

How ACH fraud plays out

  1. Obtain — Get bank details. Account and routing numbers come from phishing, data breaches, stolen checks, or account takeover.
  2. Probe — Run test deposits. Tiny credits or debits confirm the account is live and the linkage works before a big move.
  3. Pull or push — Move the money. A large debit drains the account, or a credit pushes funds to a mule the fraudster controls.
  4. Surface — Dispute or return. Days later the return posts or the customer disputes, often long after the funds have moved on.

Who is involved?

Who

Their role

The fraudster

Holds the stolen bank details and initiates the unauthorized debit or credit.

The originating bank (ODFI)

Submits the ACH entry on behalf of an originator, and carries warranty obligations for it.

The receiving bank (RDFI)

Posts the entry to the customer account and handles returns and disputes.

The account holder

The victim whose account is drained, or whose credentials were used to pull funds.

The mule

Receives pushed funds and forwards or withdraws them to break the trail.

What it looks like in practice

In practice

A small business posts a scanned check on social media to celebrate a customer payment, exposing its account and routing numbers. Within a week, two small debits appear from an unfamiliar company name, each under a dollar. Nobody notices, because they look like the kind of micro-verification a real vendor would run.

Those were test deposits. The following Monday a five-figure debit from the same originator hits the account. The business only catches it two days later during reconciliation, files an unauthorized-debit claim, and the bank returns the entry with code R10. The money is recovered this time, but the same details are already being used to attempt debits at other banks.

Why the settlement window matters

ACH is cheap, high-volume, and trusted, which is what makes it a target. Because entries clear in batches rather than in real time, there is a gap between when money moves and when anyone reconciles it. Fraudsters live in that gap: they push funds to a mule and cash out before the debit is even questioned. On the consumer side, an unauthorized debit can be disputed for up to 60 days, so a loss can post cleanly and then reverse weeks later, well after the funds have left.

For operators, the practical work is watching new payees, first-time large debits, and return codes. Codes like R05 (unauthorized consumer debit using a corporate format), R07 (authorization revoked), and R10 (customer says the debit was unauthorized) are the signals that tell you fraud, not a bounced payment, is in play. A spike in these codes, or a burst of small test entries, is your early warning.

What to watch in the data

  • Test deposits. Sub-dollar credits or debits used to confirm stolen bank details work before a larger pull.
  • First-time large debit. A big debit from an originator the account has never transacted with, soon after account details were exposed.
  • Return-code spikes. Rising R05, R07, and R10 returns point to unauthorized activity rather than ordinary payment failures.
  • Fast payee adds. New external accounts or billers linked and used within a very short window, a hallmark of takeover.
  • Unknown company names. Debits from originators that do not match any known biller or vendor relationship.

Quick questions

Why is only an account and routing number enough?

ACH was designed for trusted, batch bank-to-bank transfers, so authorization relies on the originator's warranty rather than a real-time credential check. That is efficient but means anyone with the numbers, which are printed on every check, can attempt an entry.

What do the return codes R05, R07, and R10 mean?

Broadly, they flag unauthorized or revoked debits. R10 is a customer claim that a debit was not authorized, R07 is authorization revoked, and R05 is an unauthorized consumer debit sent in a corporate format. Clusters of these are strong fraud indicators.

How long can an ACH debit be disputed?

A consumer can dispute an unauthorized debit for up to 60 days after the statement, which is why ACH losses can surface long after the payment posts. Business accounts generally have a much shorter return window.

How is ACH fraud different from wire fraud?

Wires settle fast and are close to final with no chargeback right. ACH settles slower in batches and carries dispute and return rights, especially for consumers, so the recovery mechanics and the fraud timing are different.

What are the best defenses?

ACH debit blocks and filters, positive pay, verifying new payees, monitoring for test deposits, and watching return-code trends. Speed of reconciliation matters too, since catching an unauthorized entry early widens your recovery options.

Go deeper

What to know alongside ACH fraud