Outbound ACH & Supplier Payment Fraud
- Inbound ACH is customers paying you. Outbound ACH is you paying suppliers. Different risk, different controls, different liability
- Outbound means your money already left. Recovery runs under 30%. After 24 hours a recall is a polite ask, not a demand
- The top vector is a BEC-driven vendor banking change. Someone talks your AP team into swapping a vendor's bank details
- Prevention is procedural, not technical. Dual authorization, out-of-band verification, segregation of duties, vendor file audits
Outbound ACH fraud is money you sent, landing in the wrong account. Usually because someone changed a vendor's bank details.
Most ACH writing is about inbound. Customers paying you. Our ACH operations and ACH fraud pages do the same, and that's the right place to start. But you also send money out. Suppliers, contractors, landlords, payroll. That's a different risk entirely. The money flows away from you and the recovery window is brutally short.
Inbound vs. Outbound ACH Risk
On paper they're the same rail. The risk profiles aren't close.
| Factor | Inbound ACH (Customer Pays You) | Outbound ACH (You Pay Suppliers) |
|---|---|---|
| Direction | Money flows in | Money flows out |
| Who initiates | You (or your processor) as ODFI | You as originator via your ODFI |
| Primary fraud type | Unauthorized debits, return abuse | Payment redirection, insider theft |
| Your role when fraud hits | Victim (you lose the goods/service) | Liable party (your money is gone) |
| Recovery window | Returns come to you in 2-60 days | You have ~24 hours for a recall |
| Legal framework | Reg E (consumer), UCC (business) | Nacha rules, UCC Article 4A |
| Detection | R10/R29 return codes alert you | You discover it when vendor calls asking where payment is |
| Typical loss per incident | Transaction amount | $10K-$125K+ (often larger payments) |
The difference that matters: inbound fraud announces itself. A return code lands in your file. Outbound fraud tells you nothing. The money leaves, the fraudster moves it, and weeks later your real vendor asks where the payment went.
Attack Vectors
Vendor Banking Change Fraud
This is the top vector, and it's a flavor of Business Email Compromise. The BEC & Phishing page covers BEC in depth. There's no point repeating it here.
Short version: a fraudster impersonates one of your vendors. Compromised email, or a spoofed domain. They ask you to update the banking details. AP updates the vendor master file. The next payment run pays the fraudster.
Why it works so well:
- Vendor banking changes are routine. They happen legitimately
- AP processes dozens of invoices and nobody trained them to be suspicious
- One successful change captures the next payment
- The median loss is $125,000. That's FBI IC3 data
For the full prevention set, see BEC & Phishing.
Payee Account Number Manipulation
Someone changes the account or routing number in your AP system. Or edits the payment file on its way to the bank.
How it happens:
- External access: They get into QuickBooks or NetSuite and edit vendor records
- Batch file tampering: They alter your Nacha file between creation and upload
- Man-in-the-middle: They sit between you and the bank's ACH portal
Detection signals:
- Vendor record changes with no verified change request behind them
- Routing numbers that don't match the vendor's known bank
- Several vendors suddenly moving to the same receiving bank
ACH Origination Abuse
You send payment instructions through your ODFI. That makes you an originator. Abuse of that access is its own risk.
Scenarios:
- Someone uses your origination credentials to pull money from third parties
- Fake entries added to a legitimate payment run
- Credential theft on your bank's ACH origination portal
Your liability: you own every transaction you send. Someone else uses your access? Nacha still puts the returns and the damages on you.
Insider Threats
Your AP clerk, bookkeeper or controller can already move money. That's the whole problem.
Common schemes:
- Ghost vendors: Fake vendor records, payments routed to a personal account
- Payment splitting: A real vendor payment, plus a small second one to themselves
- Check-to-ACH conversion: They convert a check to ACH and redirect it
- Overbilling collusion: Employee and vendor inflate invoices and split the excess
Why it goes undetected: the thief usually reconciles the accounts too. No segregation of duties, no second set of eyes.
Prevention Controls
It's procedural work, nearly all of it. No fraud score catches a clean-looking payment to a fraudster's account.
| Control | What It Prevents | Implementation |
|---|---|---|
| Dual authorization for new payees | Ghost vendors, BEC | Two people must approve any new vendor in the master file |
| Dual authorization for banking changes | BEC, account manipulation | Two people must approve any change to vendor bank details |
| Out-of-band verification | BEC | Call vendor at a known phone number (not from the email) to confirm banking changes |
| Micro-deposit or API verification | Wrong account, manipulation | Verify new bank details with test deposits or bank API before sending real payments |
| ACH Positive Pay | Unauthorized origination | Bank-side control that matches outbound ACH against your authorized payee list |
| Segregation of duties | Insider fraud | Person who enters payments is not the person who approves them |
| Vendor master file audits | Ghost vendors, stale records | Quarterly review of all vendor records - flag dormant vendors, duplicate tax IDs, PO box-only addresses |
| Payment threshold alerts | Large-dollar fraud | Automatic alerts for payments above a set threshold |
The Non-Negotiable Three
If you do nothing else, do these:
- Dual authorization on banking changes. No single person gets to change where payments go. Period.
- Out-of-band verification for new bank details. Call the vendor at a number you already had on file. Never use contact info from the email asking for the change.
- Segregation of duties. Whoever enters the payment doesn't approve it.
ACH Origination Compliance
Originate ACH and the Nacha rules bind you. Whether you know it or not.
Originator Responsibilities
- Authorization: Every transaction needs one, on file
- Return liability: Every return is yours, unauthorized ones included
- Data accuracy: Account numbers, routing numbers and amounts must be right
- ODFI agreement: Your bank's contract spells out your duties. Read it
Entry Class Codes That Matter
| SEC Code | Name | Use Case |
|---|---|---|
| CCD | Corporate Credit or Debit | Business-to-business payments (vendor, supplier) |
| PPD | Prearranged Payment and Deposit | Payroll, employee reimbursements |
| CTX | Corporate Trade Exchange | B2B with addenda records (remittance data) |
Why it matters: the wrong SEC code is compliance exposure. CCD returns and PPD returns run on different clocks. An unauthorized CCD return is due the next business day. An unauthorized PPD return to a consumer-status account gets the longer Reg E window.
Unauthorized Return Exposure
A transaction comes back unauthorized. R29 corporate, R10 consumer. You're on the hook:
- You have to accept the return
- Your ODFI may charge you a fee
- Repeat offenders lose origination privileges
If Outbound ACH Goes Wrong
The First 24 Hours Are Everything
ACH recalls run on a tight clock.
Within 24 hours of settlement:
- Call your bank and request an indemnified recall
- Your ODFI sends the request on to the receiving bank
- That bank must reply within 10 banking days. Returning the money is voluntary
After 24 hours:
- Your recall is a request now, not a demand. They can decline
- If the fraudster already moved the money, there's nothing to return
- Recovery drops under 10% after 72 hours
Response Checklist
Immediate (first hour):
[ ] Call your bank - phone, not email
[ ] Request ACH recall with transaction details
[ ] Freeze any pending payments to the same account
[ ] Preserve all evidence (emails, change requests, approvals)
Within 24 hours:
[ ] File FBI IC3 report at ic3.gov
[ ] Notify your bank's fraud department formally
[ ] Notify your cyber insurance carrier (if applicable)
[ ] Begin internal investigation - who approved, what process was followed
Within 1 week:
[ ] Complete internal investigation
[ ] Identify control failures
[ ] Implement corrective controls
[ ] Consider SAR filing if amount exceeds $5,000
Recovery Odds
| Timeline | Recovery Likelihood |
|---|---|
| Caught before settlement | High - payment can be reversed |
| Within 24 hours of settlement | Medium - recall request has teeth |
| 24-72 hours after settlement | Low - funds likely moved |
| After 72 hours | Very low - legal action is your remaining option |
Most outbound ACH fraud surfaces days or weeks late. The real vendor calls asking where their payment is. By then the money's gone.
Next Steps
Setting up outbound ACH controls?
- Put dual authorization on vendor banking changes. Highest-ROI control you have
- Write the out-of-band verification procedure. See the BEC prevention framework
- Ask your bank about ACH Positive Pay. It matches payments to your approved payee list
Already sending outbound ACH and worried about gaps?
- Audit the vendor master file. Dormant vendors, duplicate tax IDs, PO box addresses
- Check who can change vendor bank details. Segregation of duties matters
- Read your ACH origination agreement. Know what you signed
Dealing with a suspected outbound fraud incident?
- Call your bank and request a recall. Every hour counts
- File with FBI IC3 at ic3.gov, even if recovery looks hopeless
- Work the BEC response playbook
Related Pages
- ACH Operations - Inbound processing and return management
- ACH Fraud - Inbound fraud, return codes, verification tools
- BEC & Phishing - The top vector for outbound payment fraud
- Bank Transfers - ACH, wire and RTP as payment methods
- ACH Return Codes - The full code reference
- Business Banking ATO - When they take your banking logins
- Payout Strategy - Outbound payment timing and risk
- Vendor Management - Operational controls for vendor relationships