Skip to main content

Outbound ACH & Supplier Payment Fraud

TL;DR
  • Inbound ACH is customers paying you. Outbound ACH is you paying suppliers. Different risk, different controls, different liability
  • Outbound means your money already left. Recovery runs under 30%. After 24 hours a recall is a polite ask, not a demand
  • The top vector is a BEC-driven vendor banking change. Someone talks your AP team into swapping a vendor's bank details
  • Prevention is procedural, not technical. Dual authorization, out-of-band verification, segregation of duties, vendor file audits

Outbound ACH fraud is money you sent, landing in the wrong account. Usually because someone changed a vendor's bank details.

Most ACH writing is about inbound. Customers paying you. Our ACH operations and ACH fraud pages do the same, and that's the right place to start. But you also send money out. Suppliers, contractors, landlords, payroll. That's a different risk entirely. The money flows away from you and the recovery window is brutally short.

Inbound vs. Outbound ACH Risk

On paper they're the same rail. The risk profiles aren't close.

FactorInbound ACH (Customer Pays You)Outbound ACH (You Pay Suppliers)
DirectionMoney flows inMoney flows out
Who initiatesYou (or your processor) as ODFIYou as originator via your ODFI
Primary fraud typeUnauthorized debits, return abusePayment redirection, insider theft
Your role when fraud hitsVictim (you lose the goods/service)Liable party (your money is gone)
Recovery windowReturns come to you in 2-60 daysYou have ~24 hours for a recall
Legal frameworkReg E (consumer), UCC (business)Nacha rules, UCC Article 4A
DetectionR10/R29 return codes alert youYou discover it when vendor calls asking where payment is
Typical loss per incidentTransaction amount$10K-$125K+ (often larger payments)

The difference that matters: inbound fraud announces itself. A return code lands in your file. Outbound fraud tells you nothing. The money leaves, the fraudster moves it, and weeks later your real vendor asks where the payment went.


Attack Vectors

Vendor Banking Change Fraud

This is the top vector, and it's a flavor of Business Email Compromise. The BEC & Phishing page covers BEC in depth. There's no point repeating it here.

Short version: a fraudster impersonates one of your vendors. Compromised email, or a spoofed domain. They ask you to update the banking details. AP updates the vendor master file. The next payment run pays the fraudster.

Why it works so well:

  • Vendor banking changes are routine. They happen legitimately
  • AP processes dozens of invoices and nobody trained them to be suspicious
  • One successful change captures the next payment
  • The median loss is $125,000. That's FBI IC3 data

For the full prevention set, see BEC & Phishing.

Payee Account Number Manipulation

Someone changes the account or routing number in your AP system. Or edits the payment file on its way to the bank.

How it happens:

  • External access: They get into QuickBooks or NetSuite and edit vendor records
  • Batch file tampering: They alter your Nacha file between creation and upload
  • Man-in-the-middle: They sit between you and the bank's ACH portal

Detection signals:

  • Vendor record changes with no verified change request behind them
  • Routing numbers that don't match the vendor's known bank
  • Several vendors suddenly moving to the same receiving bank

ACH Origination Abuse

You send payment instructions through your ODFI. That makes you an originator. Abuse of that access is its own risk.

Scenarios:

  • Someone uses your origination credentials to pull money from third parties
  • Fake entries added to a legitimate payment run
  • Credential theft on your bank's ACH origination portal

Your liability: you own every transaction you send. Someone else uses your access? Nacha still puts the returns and the damages on you.

Insider Threats

Your AP clerk, bookkeeper or controller can already move money. That's the whole problem.

Common schemes:

  • Ghost vendors: Fake vendor records, payments routed to a personal account
  • Payment splitting: A real vendor payment, plus a small second one to themselves
  • Check-to-ACH conversion: They convert a check to ACH and redirect it
  • Overbilling collusion: Employee and vendor inflate invoices and split the excess

Why it goes undetected: the thief usually reconciles the accounts too. No segregation of duties, no second set of eyes.


Prevention Controls

It's procedural work, nearly all of it. No fraud score catches a clean-looking payment to a fraudster's account.

ControlWhat It PreventsImplementation
Dual authorization for new payeesGhost vendors, BECTwo people must approve any new vendor in the master file
Dual authorization for banking changesBEC, account manipulationTwo people must approve any change to vendor bank details
Out-of-band verificationBECCall vendor at a known phone number (not from the email) to confirm banking changes
Micro-deposit or API verificationWrong account, manipulationVerify new bank details with test deposits or bank API before sending real payments
ACH Positive PayUnauthorized originationBank-side control that matches outbound ACH against your authorized payee list
Segregation of dutiesInsider fraudPerson who enters payments is not the person who approves them
Vendor master file auditsGhost vendors, stale recordsQuarterly review of all vendor records - flag dormant vendors, duplicate tax IDs, PO box-only addresses
Payment threshold alertsLarge-dollar fraudAutomatic alerts for payments above a set threshold

The Non-Negotiable Three

If you do nothing else, do these:

  1. Dual authorization on banking changes. No single person gets to change where payments go. Period.
  2. Out-of-band verification for new bank details. Call the vendor at a number you already had on file. Never use contact info from the email asking for the change.
  3. Segregation of duties. Whoever enters the payment doesn't approve it.

ACH Origination Compliance

Originate ACH and the Nacha rules bind you. Whether you know it or not.

Originator Responsibilities

  • Authorization: Every transaction needs one, on file
  • Return liability: Every return is yours, unauthorized ones included
  • Data accuracy: Account numbers, routing numbers and amounts must be right
  • ODFI agreement: Your bank's contract spells out your duties. Read it

Entry Class Codes That Matter

SEC CodeNameUse Case
CCDCorporate Credit or DebitBusiness-to-business payments (vendor, supplier)
PPDPrearranged Payment and DepositPayroll, employee reimbursements
CTXCorporate Trade ExchangeB2B with addenda records (remittance data)

Why it matters: the wrong SEC code is compliance exposure. CCD returns and PPD returns run on different clocks. An unauthorized CCD return is due the next business day. An unauthorized PPD return to a consumer-status account gets the longer Reg E window.

Unauthorized Return Exposure

A transaction comes back unauthorized. R29 corporate, R10 consumer. You're on the hook:

  • You have to accept the return
  • Your ODFI may charge you a fee
  • Repeat offenders lose origination privileges

If Outbound ACH Goes Wrong

The First 24 Hours Are Everything

ACH recalls run on a tight clock.

Within 24 hours of settlement:

  • Call your bank and request an indemnified recall
  • Your ODFI sends the request on to the receiving bank
  • That bank must reply within 10 banking days. Returning the money is voluntary

After 24 hours:

  • Your recall is a request now, not a demand. They can decline
  • If the fraudster already moved the money, there's nothing to return
  • Recovery drops under 10% after 72 hours

Response Checklist

Immediate (first hour):
[ ] Call your bank - phone, not email
[ ] Request ACH recall with transaction details
[ ] Freeze any pending payments to the same account
[ ] Preserve all evidence (emails, change requests, approvals)

Within 24 hours:
[ ] File FBI IC3 report at ic3.gov
[ ] Notify your bank's fraud department formally
[ ] Notify your cyber insurance carrier (if applicable)
[ ] Begin internal investigation - who approved, what process was followed

Within 1 week:
[ ] Complete internal investigation
[ ] Identify control failures
[ ] Implement corrective controls
[ ] Consider SAR filing if amount exceeds $5,000

Recovery Odds

TimelineRecovery Likelihood
Caught before settlementHigh - payment can be reversed
Within 24 hours of settlementMedium - recall request has teeth
24-72 hours after settlementLow - funds likely moved
After 72 hoursVery low - legal action is your remaining option

Most outbound ACH fraud surfaces days or weeks late. The real vendor calls asking where their payment is. By then the money's gone.


Next Steps

Setting up outbound ACH controls?

  1. Put dual authorization on vendor banking changes. Highest-ROI control you have
  2. Write the out-of-band verification procedure. See the BEC prevention framework
  3. Ask your bank about ACH Positive Pay. It matches payments to your approved payee list

Already sending outbound ACH and worried about gaps?

  1. Audit the vendor master file. Dormant vendors, duplicate tax IDs, PO box addresses
  2. Check who can change vendor bank details. Segregation of duties matters
  3. Read your ACH origination agreement. Know what you signed

Dealing with a suspected outbound fraud incident?

  1. Call your bank and request a recall. Every hour counts
  2. File with FBI IC3 at ic3.gov, even if recovery looks hopeless
  3. Work the BEC response playbook