You Paid a Fake ACH Vendor Payment and What Your Accounting Team Does First
A fraudulent ACH payment just went out. The first hour for your accounting team: the bank call, the payroll variant, and finding the mailbox that started it.
It is 9:40 on a Tuesday morning and your controller walks into your office holding a printout. A supplier you have paid for six years just called to ask why last month's invoice is still open. Your records say the payment went out three weeks ago by ACH, to the new bank account the supplier asked you to start using in August. The supplier says they never asked. That account belongs to someone else, and the money is gone from yours.
ACH, short for Automated Clearing House, is the network that moves most routine business payments in the United States, from vendor bills to payroll direct deposits. It is cheaper than a wire transfer and a little slower, and that difference matters a great deal in the first hour after you discover a fraudulent payment. Most advice about payment fraud is written around wires. This post is about ACH, because for most accounting teams in McKinney, Plano and across North Texas, ACH is how the money actually leaves the building.
This kind of fraud is a form of business email compromise, usually shortened to BEC. BEC is when a criminal takes over or imitates a real email account and uses that trusted voice to redirect money. It is the most common reason a business owner calls us after something has already gone wrong, and the call almost always starts the same way: "We paid it, and we only just found out." If that is where you are today, this post is written for you, and the order of the steps matters more than any single one of them.
Why an ACH Payment Is a Different Problem Than a Wire
A wire transfer moves money between banks almost immediately and is very hard to pull back once it lands. ACH payments work differently. They travel in batches, they settle on a schedule, and the receiving bank often has some time before the money is posted to the account and becomes available to withdraw. That gap is the reason ACH fraud can sometimes be interrupted when a wire cannot.
The catch is that the gap only helps you if you use it. Criminals know ACH is slower, so they move fast on their end. The account that received your payment is usually a "mule" account, which is a bank account opened or borrowed specifically to receive stolen money and pass it along. Mule accounts are typically emptied within a day or two of the deposit. By the time a supplier calls about a missing payment, as in the example above, weeks have often passed and the money has moved several times.
So recovery on a payment discovered within a day or two is a real possibility, and recovery three weeks later is uncommon. Neither changes what you do in the next hour, because the same steps protect the next payment and build the record your insurance carrier will want.
Business bank accounts also lack the dispute protections that personal accounts carry, so your speed and your documentation are what you have.
The First Hour for Your Accounting Team
The first call goes to your bank, and it goes out before anyone starts investigating email. Not your IT provider, not your attorney, not the supplier. The bank is the only party that can reach the receiving bank, and every hour you spend gathering facts first is an hour the mule account has to empty.
While someone is on the phone with the bank, a second person should freeze anything else that might be in flight. That means every scheduled or pending ACH batch to the same vendor, and every vendor whose banking details changed in the last ninety days. Fraudsters rarely change one record. If they had access long enough to redirect one supplier, assume they looked at others until you can prove they did not.
A third task is to stop the bleeding in email. Whoever administers your Microsoft 365 or Google Workspace account should reset the password for any mailbox involved, sign that account out of every device, and turn on MFA if it was not already on. MFA, short for multi-factor authentication, is the second step after a password, usually a code or an app prompt on a phone. It is important to know that MFA alone does not guarantee the attacker is out, because a criminal can create a hidden mail rule that quietly forwards or deletes messages. Our guide to the first 48 hours after a compromised Microsoft 365 mailbox walks through what to check.
The last task in the first hour is a report to the FBI at the Internet Crime Complaint Center, known as IC3, at ic3.gov. IC3 is the federal intake point for online fraud. Filing a report does not guarantee recovery, but banks and investigators can use it to support a freeze on the receiving account, and your insurance carrier will almost certainly ask whether one was filed. Write down the IC3 complaint number and give it to your bank.
If your business has one internal IT person, this is the moment that person is going to be pulled in four directions at once. That is a common situation for growing companies in Collin County and a good reason to line up outside help before you need it. Co-managed IT means your internal person keeps running the business systems day to day while an outside team takes the incident work, so nobody has to choose between resetting passwords and calling the bank.
What to Say to Your Bank and How to Say It
The words you use with the bank matter. "We think we might have paid the wrong account" sounds like a clerical error and tends to get routed to a general service queue. "We are reporting a fraud-induced ACH credit and we are asking you to request a return from the receiving bank today" tells the bank exactly what kind of problem this is and what you want them to do about it.
Have the details ready before you call, or gather them while you are on hold. The bank will want the date and amount of each payment, the receiving bank's routing number and the account number it was sent to, the trace number for the transaction if your banking portal shows one, and a short description of how you were told to change the account. Ask the bank for a case number and the name of the person you spoke with, and write both down.
The rules that govern the ACH network have recently given banks clearer ways to handle this. Your bank can ask the receiving bank to return a payment that was made under false pretenses, and receiving banks are now expected to watch for suspicious incoming payments. That is useful, but it is not a guarantee. The receiving bank can return only what is still in the account, and it is not required to make you whole out of its own pocket. This is why speed beats everything else in the first hour.
If the payment was discovered quickly, ask whether the bank can also place a hold on the receiving account while the return request is reviewed. If the payment was discovered late, ask the bank what it can still attempt and get the answer in writing. Either way, follow the phone call with an email to your banker summarizing what you asked for and when. That email becomes part of your record.
For a wire payment rather than ACH, the timing and wording are different, and we cover that separately in what to do after paying a fake invoice by wire.
The Payroll Version That Nobody Watches
Vendor payments get most of the attention, but there is a quieter version of ACH fraud that hits payroll. It usually starts with an email to HR or the payroll administrator that appears to come from an employee. It says something simple, such as "I switched banks, can you update my direct deposit before Friday." The message comes from the employee's real address, because the attacker has broken into their mailbox, or from an address that is one letter off.
The change gets made, payroll runs, and the employee's paycheck lands in a mule account. Nobody notices until the employee asks why they were not paid, often a week or two later. By then the next payroll may have gone to the same place.
The dollar amount is usually smaller than a vendor fraud, but the employee is now short on rent through no fault of their own, the business usually covers the missed pay, and the incident tells you the attacker had, or still has, a way into your environment.
The fix in the moment follows the same order as above. Call the bank, freeze any other pending direct deposit changes, reset the affected accounts, and file with IC3. Afterward, the lasting fix is a rule that direct deposit changes are never made from an email request alone. The employee confirms in person or through a call to a phone number already on file, never a number in the email.
Finding the Mailbox That Started It
Once the money calls are made, the next question is which mailbox was actually compromised. There are three possibilities, and they lead to very different conversations. The attacker may have been inside your accounting mailbox, reading invoices and timing their request. They may have been inside your vendor's mailbox, sending a genuine looking message from a genuine address. Or they may never have been inside anyone's mailbox, and simply registered a lookalike domain and copied the vendor's signature.
This is not academic. If your mailbox was the one compromised, other clients and vendors may have received fraudulent messages from you, and you may have notification duties. Our post on what to tell clients when a fraudulent invoice leaves your mailbox covers that conversation. If the vendor's mailbox was compromised, they need to know today, because you are probably not their only customer receiving those emails.
Answering the question properly takes digital forensics, which is the careful, documented examination of sign-in records, mail rules and message headers to establish what happened and when. The record has to be collected before anyone starts cleaning up, because some of the evidence, especially sign-in history, expires after a limited number of days in common business email platforms. If the first instinct is to delete the suspicious rules and move on, the proof of how long the attacker was inside can disappear with them.
Our business email compromise response service is built around exactly this sequence. We help you make the bank call correctly, contain the mailbox without destroying evidence, and then establish which account was used, how long the attacker had access, and what they could see.
What It Costs When the Money Does Not Come Back
The lost payment is the number everyone focuses on, but it is rarely the whole bill. Consider a 25 person distribution company in Frisco that sends one $48,000 supplier payment to a fraudster. If the money is not recovered, the company still owes the real supplier the full $48,000. It has now paid that invoice twice.
On top of that come the hours. The controller and the owner can each easily lose two or three working days to bank calls, insurance paperwork, and conversations with the supplier. If the attacker was in your mailbox, add the cost of investigating it and of reaching out to every client who may have received a fake message. If any of those messages contained customer information, you may face notification obligations under Texas law, which can mean legal review and, in some cases, letters to affected people.
Insurance can help, but read the policy before you count on it. Many cyber insurance policies treat payment fraud as a separate category, often called social engineering or funds transfer fraud coverage, with its own lower limit. Some require that you verified the bank change by phone before paying, and deny the claim if you did not. Call your broker the same day you call your bank, because late notice is one of the most common reasons claims run into trouble.
Stopping the Next One Without Slowing Down Payables
Prevention matters here, but only once the current incident is under control. The single most effective control is simple. Any change to a vendor's or employee's banking details is confirmed with a phone call to a number you already had on file, never a number in the email that requested the change. Pair that with a waiting period of a few business days before the first payment to a new account, and a second person's sign off on that first payment.
Ask your bank about the fraud controls it offers on outgoing ACH, such as alerts on new payees or a review step before a batch is released. Make sure every mailbox in finance, HR and leadership uses MFA, and have someone review the mail rules on those accounts regularly. Email security tools can flag lookalike domains and unusual sign-ins before a fake request reaches your accounts payable inbox, and dark web monitoring can warn you when an employee's password shows up for sale after a breach somewhere else.
None of these controls require you to slow down every payment. They focus friction on the one moment fraud depends on, which is a change to where the money goes.
If a fraudulent ACH payment has already gone out, call us at 512-518-4408 and we will help you work the first hour in the right order. We are based in McKinney and work with businesses across McKinney, Plano and Frisco. If you would rather find out where your payment process is exposed before anything happens, start with a free security assessment or contact our team.
Frequently Asked Questions
Can an ACH payment to a scammer be reversed?
Sometimes, if you act quickly. Your bank can ask the receiving bank to return a payment that was made under false pretenses, but the receiving bank can only send back what is still in the account. Payments discovered within a day or two have a much better chance than payments discovered weeks later.
Who should we call first after paying a fraudulent ACH invoice?
Call your bank first, before you investigate email or contact anyone else. Tell them you are reporting a fraud-induced ACH payment and ask them to request a return from the receiving bank today. Then file a report at ic3.gov and notify your insurance broker the same day.
Is the bank responsible for a fraudulent ACH payment from a business account?
Usually not. The consumer protections that apply to personal accounts generally do not cover business accounts, and if your company authorized the payment, even because it was deceived, the bank is not automatically liable. Your contract with the bank and any fraud controls you agreed to will shape what happens next.
How do we stop fake direct deposit change requests?
Never change direct deposit or vendor banking details based on an email alone. Confirm every change by calling a phone number you already had on file, and have a second person approve the first payment to any new account. Protect HR and payroll mailboxes with multi-factor authentication and review their mail rules regularly.
Need Help With This?
Innovation Network Design helps businesses across McKinney, Dallas, and nationwide with expert cybersecurity services.
Mark Sullivan
Innovation Network Design
With nearly a decade in cybersecurity and IT infrastructure, our team delivers expert insights to help businesses in McKinney, Dallas, and across DFW make informed security decisions. Have a question? Get in touch.
Ready to Secure Your Business?
Get a free security assessment and find out where your organization stands.