By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: RiskifiedPublished September 10, 2026

TL;DR: ACH transactions can carry 2.3 times the fraud risk of card-not-present payments, according to Riskified, and its analysis of dark web discussion plus transaction data shows criminals using bank logs, recent bank-detail changes, and low-value high-velocity purchases to cash out before detection. The real governance issue is not whether to accept ACH, but whether fraud controls are tuned to its delayed settlement and account-access abuse patterns.


At a glance

What this is: This analysis argues that ACH-enabled fraud is being exploited through compromised bank access, delayed settlement, and platform-level blind spots that make suspicious activity look routine until funds are gone.

Why it matters: It matters because payment, fraud, and identity teams need controls that account for account takeover, behavioural spoofing, and settlement lag, not just card-style fraud signals.

By the numbers:

👉 Read Riskified's analysis of ACH fraud risk, cash-out behaviour, and settlement windows


Context

ACH fraud is a payment-governance problem as much as a fraud problem. Once an account and routing number are paired with online account access, criminals can move money repeatedly before the holder or merchant sees the pattern. The key weakness is that ACH often lacks the immediate authorisation signal that card workflows use to stop or challenge suspicious activity.

The article is also about the boundary between identity verification and transaction risk. Fraudsters are not only exploiting payment rails, they are exploiting trusted account access, session continuity, and behavioural mimicry to make stolen bank details look legitimate. That makes this topic relevant to teams responsible for fraud controls, customer authentication, and payout governance, not just payments operations.


Key questions

Q: How should merchants manage ACH fraud without blocking legitimate payments?

A: Use ACH as its own fraud policy tier rather than copying card controls. Weight account age, recent bank-detail changes, session behaviour, and settlement exposure together. Then apply review, hold, or step-up checks before fulfilment when the transaction sits inside a known cash-out pattern. The goal is to reduce loss without treating all ACH activity as suspicious.

Q: Why are recently changed bank details such a strong fraud signal?

A: Because attackers often edit payout details after compromise and before cash-out. A bank-detail change can indicate account takeover, mule setup, or preparation for a low-friction ACH transfer. When that change happens shortly before a transaction, the account may look active and normal while the underlying risk has already shifted materially.

Q: What do fraud teams get wrong about ACH compared with cards?

A: They assume the absence of real-time card authorisation means ACH is lower risk, when the opposite can be true. ACH allows payment initiation before loss is confirmed, so merchants who rely on checkout approval alone miss delayed-failure patterns. The mistake is using card logic for a rail that resolves risk later.

Q: When should ACH transactions be held for manual review?

A: Hold them when recent banking changes, unusual session behaviour, or low-value high-velocity purchasing line up with a possible cash-out pattern. That combination matters because it often indicates a real account being used by the wrong actor. Manual review should happen before fulfilment or payout, while the return window is still open.


Technical breakdown

Why ACH fraud looks legitimate until settlement catches up

ACH is an asynchronous payment rail, which means initiation, clearing, and return do not happen in the same instant. That delay creates a window where a merchant may treat the transaction as normal even though the underlying account access was compromised. Fraudsters exploit that gap by using real bank credentials, ordinary-looking locations, and consumer-style behaviour to avoid immediate suspicion. The issue is not that ACH is inherently unsafe. It is that the control model is weaker when approval, fulfilment, and loss realisation are separated by banking timelines.

Practical implication: align fraud decisions to settlement lag, not just checkout-time signals.

How account access and behavioural spoofing defeat card-style controls

Dark web discussions in the article show fraudsters pairing bank logs with session cookies, expected locations, and browsing patterns to imitate the account holder. That is a different threat than card testing or simple credential theft. The attacker is trying to preserve the appearance of normal account behaviour long enough to move funds or trigger fulfilment. In identity terms, the problem is that the platform trusts a session and an authenticated account without enough proof that the current actor is the real account holder.

Practical implication: add behavioural and session-risk checks around account changes and payout initiation.

Why bank-detail changes and small-dollar bursts are high-signal patterns

Riskified highlights two recurring indicators: recently changed bank details and high-velocity, low-amount purchases. Both suggest an attacker is preparing the account for cash-out while staying below obvious loss thresholds. Bank-detail changes can indicate account takeover or mule setup, while small-dollar bursts exploit the delay between authorization and return processing. These patterns are useful because they are operational, not abstract. They give fraud teams concrete places to apply step-up review, velocity rules, and payout holds before the settlement window closes.

Practical implication: treat bank-detail edits and low-value bursts as review triggers before fulfilment or payout.


Threat narrative

Attacker objective: The attacker wants to move stolen funds through ACH-enabled platforms before detection, return, or account intervention can stop the cash-out.

  1. Entry begins with stolen bank logs, compromised bank credentials, or access to an online account that can be used to initiate ACH payments.
  2. Escalation occurs when the fraudster aligns login geography, session data, and browsing behaviour to look like the legitimate account holder while updating payout details.
  3. Impact follows when the platform fulfils the payment before return windows close, enabling cash-out and NSF losses that are hard to reverse.

NHI Mgmt Group analysis

ACH fraud is increasingly an identity problem disguised as a payments problem. The article shows that fraudsters are not relying on stolen cards alone. They are using bank access, session continuity, and behavioural imitation to make stolen accounts look trustworthy. That means payment teams must treat identity assurance as part of fraud governance, not as a separate upstream concern. The practitioner conclusion is straightforward: if the account is real but the actor is not, traditional payment rules will miss the attack.

Delayed settlement is the structural weakness fraudsters exploit. Card-style authorisation gives merchants a faster signal than ACH, and that difference changes the control model. A payment rail with a 1 to 3 day return window gives attackers time to cash out, especially when fulfilment is faster than reversal. Merchants need to understand that speed asymmetry is itself a risk factor, not just an operational detail. The practitioner conclusion is to design controls around finality, not initiation.

Recent bank-detail changes are a named concept worth treating as a governance signal: bank-detail churn. The article shows that fresh banking updates can precede fraudulent ACH activity by a wide margin. That pattern suggests account takeover, mule setup, or an attacker preparing for low-friction cash-out. This is where identity verification and transaction monitoring intersect. The practitioner conclusion is to elevate bank-detail churn into a monitored risk event, not a routine profile edit.

Behavioural mimicry is now part of ACH fraud tradecraft. Fraudsters are not just abusing credentials. They are trying to match locations, cookies, and browsing patterns so controls see a familiar session rather than a compromised one. That raises the bar for fraud analytics because static identity checks are no longer enough. The practitioner conclusion is to combine session intelligence, device history, and payout controls into one decision path.

ACH acceptance should be governed as a controlled risk tier, not a universal checkout option. The article does not argue for removing ACH. It argues for tuning controls to the fraud profile of the rail. That is the right direction for merchants that want lower costs without higher loss rates. The practitioner conclusion is to treat ACH as a distinct policy domain with its own thresholds, review logic, and loss-management rules.

What this signals

ACH fraud is a reminder that identity assurance and payment authorization are converging control problems. As settlement windows remain slower than attacker decision cycles, merchants will need policy logic that recognises account takeover, session spoofing, and payout manipulation as part of the same risk chain. Bank-detail churn is likely to become a more useful governance signal than raw transaction volume alone.

The next maturity step is to treat payment rails as differentiated trust domains. Teams that still rely on one set of fraud thresholds across cards, ACH, and wallet top-up flows will keep missing the places where attackers exploit delay. Linking policy to settlement finality and account behaviour is the practical way to reduce false confidence.

For identity and fraud programmes, the lesson is to integrate account verification, session telemetry, and transaction controls before the approval point. That is where abuse becomes expensive to reverse, and it is also where the operating model usually has the least cross-functional visibility. A control stack that sees only payment events will remain one step behind the fraudster.


For practitioners

  • Build ACH-specific fraud scoring Separate ACH risk models from card-not-present rules so recent bank-detail edits, return-window exposure, and low-value burst patterns are weighted correctly.
  • Trigger step-up review on bank-detail churn Flag bank-account changes made within a short period before checkout or payout, and route those transactions to review before fulfilment.
  • Hold fulfilment until ACH risk is resolved Delay high-risk orders until bank ownership, transaction behaviour, and account history are consistent enough to reduce cash-out losses.
  • Correlate session and identity signals Join device history, login geography, cookies, and account-update history so fraudulent sessions cannot rely on a single familiar signal to pass.

Key takeaways

  • ACH fraud works because stolen bank access, behavioural mimicry, and delayed settlement can make a bad transaction look routine until the money is gone.
  • Riskified’s data suggests the risk is materially higher than many teams assume, especially when bank details change shortly before a transaction or the payment pattern stays small and fast.
  • Merchants need ACH-specific controls that combine identity, session, and payout governance before fulfilment, not after the return window opens.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4 — Access Permissions and AuthorisationsACH fraud here depends on abusing trusted account access and session legitimacy.
Recommendation — Tighten access permissions around payout changes and review any transaction that follows recent account edits.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeFraud impact grows when compromised accounts can move funds without constraint.
Recommendation — Apply least-privilege limits to payout changes and restrict who can alter bank details.
CIS Controls v8CIS-5 — Account ManagementThe article centres on misuse of active accounts and account detail changes.
Recommendation — Review account lifecycle controls so bank-detail updates and login anomalies trigger reassessment.
GDPRArt.32 — Security of ProcessingFraud monitoring of customer accounts requires appropriate protection of personal and account data.
Recommendation — Protect account and transaction data with controls proportional to the risk of fraudulent access.
MITRE ATT&CKTA0006; TA0009 — Credential Access; CollectionThe fraud chain uses stolen credentials and account data to support cash-out activity.
Recommendation — Map account-compromise patterns to credential access and collection techniques in your detection content.

Key terms

  • ACH Fraud: ACH fraud is the misuse of automated clearing house payments to move money from a compromised or deceptive account relationship. It often relies on delayed settlement, account takeover, and weak behavioural verification so the payment appears legitimate long enough for the attacker to cash out.
  • Bank-Detail Churn: Bank-detail churn is the repeated or recent change of payout or linked bank information within an account. In fraud analysis, it is a useful signal because attackers often update banking details just before initiating transactions, creating a short but meaningful window of elevated risk.
  • Settlement Window: A settlement window is the time between payment initiation and final confirmation or reversal. For ACH, this gap can be long enough for fraudsters to exploit fulfilment before the transaction is returned, which makes timing and hold policies central to loss prevention.
  • Behavioural Mimicry: The deliberate imitation of normal customer actions to reduce suspicion and improve approval odds. In fraud operations, behavioural mimicry can include cart composition, login patterns, timing, and shipping choices that look like established customer behaviour even when the underlying intent is malicious.

What's in the full article

Riskified's full analysis covers the operational detail this post intentionally leaves for the source:

  • Dark web discussion patterns that show how fraudsters talk about bank logs, ACH cash-out, and avoidance of detection.
  • The transaction-level behavioural indicators Riskified used to separate normal ACH activity from suspicious patterns.
  • The practical implications of the 1 to 3 day settlement and return window for fulfilment and loss management.
  • The webinar context and the AML operations perspective that sit behind the analysis.

👉 Riskified's full article covers the dark web signals, transaction patterns, and ACH risk trade-offs in more detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, identity lifecycle, and secrets management. It gives identity and security practitioners a practical baseline for governing trust, access, and accountability across complex programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org