ACH fraud is the unauthorized use or redirection of payments moving through the Automated Clearing House network — the system that carries direct deposit, vendor payments, and most recurring business transfers in the United States. For employers, it is the mechanism behind payroll diversion, vendor payment fraud, and unauthorized debits against company accounts.
Understanding it matters because ACH has a specific property that shapes the entire risk: once a payment settles and funds are withdrawn, recovery is difficult. Unlike a card transaction, there is no broad chargeback right for a business that authorized a payment to the wrong account.
Credit fraud through altered instructions. The attacker changes where a legitimate payment goes rather than creating a new one. Payroll diversion is the employee-facing version; vendor payment fraud is the supplier-facing version, where an invoice arrives with updated banking details. Because the payment itself is expected and correctly sized, nothing looks unusual until the intended recipient asks where their money is.
Unauthorized debits. An attacker who obtains the employer's account and routing numbers can originate debits against the account. Those numbers appear on every check the business issues, so they are not secret, which is why debit blocks and filters matter more than confidentiality.
Origination compromise. The most severe version, where an attacker gains access to the system used to originate payroll or payment files and submits fraudulent entries directly. This produces the largest losses because it operates at file scale rather than one payment at a time.
Fraudulent accounts are drained almost immediately — funds are withdrawn, moved to other institutions, or converted within hours of settlement. By the time an employee reports a missing paycheck or a vendor asks about an unpaid invoice, several days have usually passed.
Return rights for business ACH entries are narrow and time-bound, and generally do not cover a payment the employer authorized based on fraudulent instructions. The employer authorized it; the instruction was false. That distinction places the loss with the employer in most circumstances.
This is why the entire practical strategy is prevention and fast detection, not remediation. An employer that discovers the fraud within a day may recover something. After that, usually not.
Financial institutions offer protections that many employers either do not know about or decline to reduce friction:
Dual control on origination deserves particular emphasis. It means a compromised credential alone cannot release a payment file, which addresses the highest-severity scenario directly.
Bank controls protect the account. They do not help when the employer authorizes a payment to an account the attacker chose. That requires verification at the point where payment instructions change.
The rule is the same for employees and vendors: any change to banking details is confirmed through a channel already on file, using contact information the employer holds rather than anything supplied in the request. Replying to the requesting email is not verification, and neither is calling a number printed on the new invoice.
Supporting practices include holding banking changes for a defined period before they take effect, requiring two-person approval for such changes, notifying the affected employee or vendor through their existing contact details when a change is made, and reviewing all banking changes as a discrete step before each payment run.
That last item is often the actual detection mechanism. Employees notice missing pay immediately; whether the employer learns about it within hours or days depends entirely on whether reporting is easy and the response is prompt.
Employers frequently assume cyber or crime coverage will absorb the loss. Coverage for fraudulently induced transfers is often limited, sometimes excluded, and commonly subject to conditions requiring specific verification procedures to have been followed. An employer relying on insurance should confirm what is actually covered and what the policy requires of them, before an incident rather than during one.
Employer's Guardian helps employers build verification and reconciliation practices into payment operations through payroll services, covering banking change controls, approval requirements, and pre-run review.
This article provides general educational information, not legal, tax, insurance, or banking advice. Requirements vary by institution, location, and the arrangements your organization maintains.