As ACH payment becomes more available, it gives fraudsters a route to move funds from compromised bank accounts, a risk that digital platforms may not recognize as fraud until it is too late.

Through dark web intelligence and internal transaction data, Riskified analysts observed fraudsters discussing compromised bank accounts, ACH-accepting platforms, and ways to cash out stolen funds. Separately, Riskified’s transaction data show that ACH transactions carry a significantly higher fraud risk than card-not-present (CNP) transactions and reveal behavioral patterns associated with fraudulent activity.

Why fraudsters are targeting ACH-enabled transactions

Fraudsters prize stolen credit card details. But according to many dark web forums, the real goldmine is in “bank logs” (at minimum, with account and routing numbers), compromised bank accounts with potentially large balances and online access to the account itself. A static set of card details supports one card-not-present (CNP) transaction that may or may not be approved. Online bank access lets a fraudster act repeatedly and adaptively, moving money and controlling the account before the holder takes notice. The ACH system is the legitimate highway for those funds, and a pathway to them for criminals.

As ACH becomes more common as a payment or wallet ‘top-up’ method, fraudsters are exploiting these platforms to move funds from stolen bank accounts. There’s no need for panic and no reason to exclude ACH as a payment rail; it has clear benefits. But it’s time to update the assumption that ACH is always a safer, lower-cost alternative to card payments. Instead, ensure your business has an ACH-appropriate fraud protection strategy in place.

Why ACH fraudsters cash out at checkout

ACH fraud is not new. Across the forums, marketplaces, and guides Riskified reviewed on the dark web, ACH fraud appears to be a mature, established market rather than an emerging one. Fraudster forums describe active marketplaces, and participants share detailed playbooks around ACH fraud.

The discussions outline various ways bad actors can extract funds via ACH once they have access to a bank log. They can move money between banks or use wire transfers for faster action and higher limits. But fraudsters note that these transfers are monitored closely.

Fraudsters increasingly rely on ACH-accepting platforms as preferred cash-out destinations because they can resemble routine consumer behavior, deflecting attention from fraud detection systems. Unlike direct bank transfers, which often raise red flags, ACH-based online transactions create a veil of legitimacy. To exploit this further, fraudsters leverage online account access to rigorously emulate legitimate account holder activity (e.g., aligning login credentials with expected locations, session cookies, and browsing patterns). Advanced operational security (OPSEC) measures enhance this impersonation, replicating behavioral nuances that card data alone cannot achieve.

As the newest Nacha rules take effect, fraud teams must recognize that fraudsters’ growing sophistication is expanding the ACH attack surface and helping them evade detection more effectively.

Is ACH “safer” than credit cards?

The short answer is no. Riskified analysis shows that ACH transactions can actually carry 2.3 times the fraud risk of CNP transactions.

ACH lacks real-time authorization the way cards do, so confirmation can lag, and platforms often fulfill the transaction before knowing whether the payment holds. Payment settlement and return windows run on banking schedules (with a 1-3 day average), but are subject to conditions (e.g., business days only), so a weekend or holiday can stretch the gap by several calendar days. That combination can make ACH particularly attractive to fraudsters.

What’s more, Riskified observations from dark web discussions suggest that stronger fraud detection has made carding harder and less profitable. Fraudsters describe card fraud as effectively “tied by antifraud algorithms,” and, in one guide, claim payouts are capped at around $100 regardless of method. Despite the added effort a bank log requires, ACH fraud may entice fraudsters seeking larger payouts.

What does Riskified data reveal about ACH fraud?

With ACH fraud, the bank account can be real, the customer account can be proven, the IP address can be domestic, yet the transaction can still be fraudulent. Riskified’s transaction data show several patterns that can help distinguish risky ACH transactions from ordinary activity:

  • Recently changed bank details are a risk signal. Among established customer accounts, those with bank details updated less than a week before the transaction were 6 times riskier than the rest of the established-account population. Riskified found that fraudsters update bank details almost twice as often as the broader population.
  • US-based IP addresses are not necessarily lower risk. Transactions associated with US IP addresses were almost 2.5 times riskier than those associated with non-US IP addresses in the analyzed population. Riskified also found that proxy use was identified in fewer than one-third of the fraudulent population associated with US IPs.
  • High-velocity, low-amount ACH purchases can signal NSF abuse. Riskified has observed fraudsters exploiting ACH settlement windows by initiating high-volume purchases (in small-dollar payments to stay below merchant thresholds) from insufficiently funded accounts. If platforms fulfill those orders before the payments are returned, the transactions can generate significant NSF losses.

Learn how to manage ACH risk: Attend the September 24 webinar

Join Riskified’s upcoming webinar to hear directly from the Director of AML Operations at Pangea about their ACH program and practical tips for preserving more of ACH’s upside with fewer trade-offs.