Electronic Funds Transfer (EFT) Fraud: What Employers Need to Know
August 18, 2026
Electronic funds transfer fraud is the unauthorized movement of money through electronic payment systems. For employers it covers a range of schemes touching payroll, vendor payments, and company accounts — ACH transfers, wire transfers, and real-time payment rails each carrying their own risk characteristics.
The distinctions matter because recovery prospects differ sharply by method, and the controls that protect one rail do not necessarily protect another.
How the rails differ
ACH carries most payroll and recurring business payments. It settles on a delayed basis, which creates a narrow window where a fraudulent entry might still be caught before funds are available. Return rights for business entries are limited and generally do not cover payments the employer authorized on fraudulent instructions.
Wire transfers settle quickly and are effectively final. Once a wire is executed and the receiving bank releases the funds, recovery depends almost entirely on the recipient bank's cooperation and on speed measured in hours. Wires are consequently the preferred method in high-value fraud.
Real-time payment systems combine the worst properties for a victim: immediate settlement and irrevocability. As adoption grows, schemes are migrating toward them precisely because there is no reversal window at all.
The practical implication is that any control depending on catching a fraudulent payment after submission is weak, and becomes weaker as payments get faster. Verification has to happen before authorization.
The schemes employers encounter
Payment instruction fraud is the dominant pattern. The attacker does not create a payment; they change where an expected payment goes. Payroll diversion is the employee-facing form. Vendor payment fraud is the supplier-facing form, where an invoice arrives with updated banking details or a purported supplier emails about a change of account. Because the payment is expected and correctly sized, nothing appears unusual until the intended recipient asks about it.
Business email compromise escalates this by taking over a genuine mailbox — an executive's, a controller's, or a supplier's — so the fraudulent instruction arrives from a legitimate address, often referencing real transactions the attacker has read.
Origination system compromise is the most severe: an attacker with access to the system used to submit payment or payroll files can enter fraudulent transactions directly, at file scale.
Unauthorized debits run in the opposite direction, using the employer's account and routing numbers — which appear on every check the business issues and are therefore not confidential.
Controls at the bank
- Dual control on origination, requiring two people to release any payment file. This directly addresses the highest-severity scenario, since a single compromised credential cannot move money.
- Callback verification for wires, where the bank confirms instructions by phone to a pre-agreed number before executing.
- ACH debit blocks or filters, preventing debits entirely or permitting only pre-authorized originators.
- Positive pay, flagging entries that do not match expected parameters.
- Transaction limits set to operational reality rather than to the maximum the bank permits.
- Segregated accounts holding only funds needed for imminent obligations.
Many employers decline these because they add friction. That trade is worth revisiting against the recovery reality: friction before a payment is inexpensive, and there is often nothing available afterward.
Controls at the instruction layer
Bank controls protect the account. They do not help when the employer knowingly authorizes a payment to an account the attacker selected. That gap is closed only by verifying instruction changes out of band.
The rule is identical for employees and vendors: any change to banking details is confirmed through contact information the organization already holds — not a number on the new invoice, not a reply to the requesting email, not a contact supplied in the request itself. This defeats both lookalike-address attacks and compromised-account attacks, which no sender-based check can catch.
Supporting practices include a waiting period before changes take effect, two-person approval for banking changes, notification to the affected party through existing contact details, and a pre-run review of all changes since the previous cycle.
Detection that compresses the window
Because recovery depends on hours, detection speed is the second-most valuable investment after prevention. Daily account reconciliation rather than monthly, alerts on any banking detail change, comparison of payroll file totals against expectations before release, and an easy, fast route for employees and vendors to report a missing payment all shorten the gap between fraud and discovery.
That last item frequently is the detection mechanism in practice. People notice missing money immediately; whether the employer hears about it within hours or days depends on whether reporting is simple and someone responds.
Insurance is not a substitute
Coverage for fraudulently induced transfers is often limited, sometimes excluded, and commonly conditioned on the insured having followed specific verification procedures. An employer relying on insurance should confirm what is actually covered and what the policy requires — before an incident, not during one.
Employer's Guardian helps employers build verification, approval, and reconciliation practices into payment operations through payroll services.
This article provides general educational information, not legal, tax, insurance, or banking advice. Arrangements vary by institution and by organization.

