Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

ACH fraud signals: what merchants need to watch now


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20605
Topic starter  

TL;DR: ACH transactions can carry 2.3 times the fraud risk of card-not-present payments, according to Riskified, and its analysis of dark web discussion plus transaction data shows criminals using bank logs, recent bank-detail changes, and low-value high-velocity purchases to cash out before detection. The real governance issue is not whether to accept ACH, but whether fraud controls are tuned to its delayed settlement and account-access abuse patterns.

NHIMG editorial — based on content published by Riskified: an analysis of ACH fraud risk, dark web cash-out behaviour, and transaction patterns

By the numbers:

Questions worth separating out

Q: How should merchants manage ACH fraud without blocking legitimate payments?

A: Use ACH as its own fraud policy tier rather than copying card controls.

Q: Why are recently changed bank details such a strong fraud signal?

A: Because attackers often edit payout details after compromise and before cash-out.

Q: What do fraud teams get wrong about ACH compared with cards?

A: They assume the absence of real-time card authorisation means ACH is lower risk, when the opposite can be true.

Practitioner guidance

  • Build ACH-specific fraud scoring Separate ACH risk models from card-not-present rules so recent bank-detail edits, return-window exposure, and low-value burst patterns are weighted correctly.
  • Trigger step-up review on bank-detail churn Flag bank-account changes made within a short period before checkout or payout, and route those transactions to review before fulfilment.
  • Hold fulfilment until ACH risk is resolved Delay high-risk orders until bank ownership, transaction behaviour, and account history are consistent enough to reduce cash-out losses.

What's in the full article

Riskified's full analysis covers the operational detail this post intentionally leaves for the source:

  • Dark web discussion patterns that show how fraudsters talk about bank logs, ACH cash-out, and avoidance of detection.
  • The transaction-level behavioural indicators Riskified used to separate normal ACH activity from suspicious patterns.
  • The practical implications of the 1 to 3 day settlement and return window for fulfilment and loss management.
  • The webinar context and the AML operations perspective that sit behind the analysis.

👉 Read Riskified's analysis of ACH fraud risk, cash-out behaviour, and settlement windows →

ACH fraud signals: what merchants need to watch now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 20196
 

ACH fraud is increasingly an identity problem disguised as a payments problem. The article shows that fraudsters are not relying on stolen cards alone. They are using bank access, session continuity, and behavioural imitation to make stolen accounts look trustworthy. That means payment teams must treat identity assurance as part of fraud governance, not as a separate upstream concern. The practitioner conclusion is straightforward: if the account is real but the actor is not, traditional payment rules will miss the attack.

A question worth separating out:

Q: When should ACH transactions be held for manual review?

A: Hold them when recent banking changes, unusual session behaviour, or low-value high-velocity purchasing line up with a possible cash-out pattern. That combination matters because it often indicates a real account being used by the wrong actor. Manual review should happen before fulfilment or payout, while the return window is still open.

👉 Read our full editorial: ACH fraud risk is outpacing platform detection on payment rails



   
ReplyQuote
Share: