Skip to content
Navanta logo - homepage
  • 877-778-7774
  • Support
    • Our Story
    • Our People
    • Join Our Team
    • View All Solutions
    • Core Banking
    • Managed IT
      • Bankers Private Cloud
      • Bankers Essentials
      • Cybersecurity
      • M365 Management
    • CRM
    • Advisory
      • Virtual CIO
      • Virtual ISO
      • Security Awareness Training
    • View All Resources
    • Articles
    • CEO Update
    • Client Spotlight
      • Core Banking
      • Cyber Attacks
      • Exams & Audits
      • Information Security
      • Managed IT
    • Navanta in the News
    • Upcoming Events
    • Recorded Webinars
  • Brand FAQs
  • Contact Us
      • Our Story
      • Our People
      • Join Our Team
      • View All Solutions
      • Core Banking

        Keep community focus with a core that runs reliably.

      • Managed IT

        Simplify banking IT with one trusted partner.

      • CRM

        Know every customer. Grow every relationship

      • Advisory

        Navigate IT and risk with clarity and confidence.

      • Have something in mind?
        Bankers Private Cloud
      • Bankers Essentials
      • Cybersecurity
      • M365 Management
      • Virtual CIO
      • Virtual ISO
      • Security Awareness Training
      • View All Resources
      • Browse By Type
        Articles
      • CEO Update
      • Client Spotlight
      • Navanta in the News
      • Upcoming Events
      • Recorded Webinars
      • Browse by Topic
        Core Banking
      • Cyber Attacks
      • Exams & Audits
      • Information Security
      • Managed IT
  • Brand FAQs
  • Contact Us
Articles

The Fraud Numbers Bankers Can’t Ignore Anymore

  • EXAMS & AUDITS
  • FRAUD
  • STRATEGIC PLANNING

A federal ACH deadline is now in effect. Imposter scams, ATM attacks, and check fraud all hit record losses in 2025. For community financial institutions, the practical question is not whether fraud is getting worse, it is whether the low-cost defenses already available are being used consistently.

For community financial institutions, the fraud line item rarely shrinks. This year, the pressure is more immediate: Nacha’s June 22 deadline now applies regardless of ACH volume, while 2025 loss data show scammers exploiting the same weak spots over and over—authorized transfers, stolen checks, impersonation calls, and physical ATM access. The issue is not whether fraud risk is rising. It is whether the institution has already turned known defenses into daily practice.

A hard deadline, not a soft one

Nacha’s new fraud monitoring rules rolled out in two phases this year. Phase one took effect March 20, 2026, covering all ODFIs plus any originator, third-party sender, or third-party service provider that moved more than 6 million ACH entries in 2023. Phase two took effect June 22, 2026, removing that volume threshold entirely.

Here’s the detail worth flagging internally: as of June 22, size no longer exempts anyone. If your institution did not clear the 6 million-entry threshold and was waiting on the sidelines, it should already have a documented, risk-based monitoring process in place—not a plan to build one later.

What the 2025 data shows

Imposter scams. The FTC logged imposter scams as the most-reported fraud category for the fifth straight year, at roughly $3.5 billion in losses. Bank impersonation was the single costliest type, nearly $1 billion, ahead of government impersonators. In practice, that means one of the highest-dollar fraud risks facing your customers right now may sound like your own fraud department, not a stranger pretending to be someone else.

ATM jackpotting. The FBI recorded more than 700 jackpotting incidents in 2025, part of roughly 1,900 since 2020, with last year’s losses topping $20 million. Nearly every case starts the same way: someone opens the machine’s cabinet and installs or swaps in malware. That puts the fix back on the physical side, cabinet locks, tamper alerts, camera coverage, not just fraud software.

Check fraud. The American Bankers Association has tracked a roughly 385% rise in check fraud since 2020, most of it starting with stolen mail. FinCEN’s latest analysis counted more than 15,000 suspicious activity reports tied to mail-theft check fraud in a single six-month period, worth over $688 million, and small and mid-sized institutions filed most of them. Paper checks are still a live attack surface even where you’ve moved most customers to digital payments.

Zelle and other real-time transfers. A Federal Reserve Bank of Kansas City review found customers at the three largest U.S. financial institutions on the Zelle network disputed more than $206 million in 2023 transactions as scams, and those customers absorbed more than 80% of the loss themselves. The transactions were technically authorized, the customer clicked send, which is exactly why they’re so hard to reverse and so easy to miss with standard fraud rules.

Where fraud tools still miss

Monitoring software is good at catching a mismatched ACH name or a check that doesn’t match the signature on file. It has no way to catch a customer who reads a one-time passcode over the phone to someone they believe is calling from their financial institution, because by the network’s own rules, that transaction is authorized. This is the gap behind the Zelle numbers above, and it’s the reason customer education still matters even though it consistently underperforms as a standalone fix.

The more realistic goal is putting a small amount of friction, a callback prompt, a hold, a second confirmation, at the exact moment a customer is being talked into something, rather than hoping a warning they read weeks earlier comes to mind at the right second.

The defenses that don’t cost anything

  • Positive pay catches check mismatches before they clear and is worth pairing with a fraud-monitoring platform on commercial accounts.
  • FedDetect, the Federal Reserve’s ACH anomaly and duplicate-check alert service, comes at no added cost to any institution already on FedLine Web or FedLine Advantage.
  • The American Bankers Association’s Fraud Contact Directory is searchable by institution, city, state, or FDIC number, and it’s the fastest way to find the right contact at another institution for a breach-of-warranty claim.
  • The International Association of Financial Crimes Investigators connects fraud and investigations staff directly to contacts at other institutions instead of starting a case cold.

For most community financial institutions, the gap isn’t access to these tools. It’s whether front-line staff use them every time or only remember them once a case has already gone cold.

The takeaway

June 22 is fixed. The record fraud numbers from 2025 are not going to reverse on their own. What is within your control is smaller than that: get ACH monitoring documented before the deadline, treat positive pay and FedDetect as standing practice rather than a backup plan, and build a moment of friction into the transactions that scammers currently talk customers straight through.

Navanta section divider
Sources: Nacha; Federal Trae Commission; Federal Bureau of Investigation; FinCEN; American Bankers Association; Federal Reserve Bank of Kansas City; Federal Reserve Financial Services.

By Eric Jones • July 24, 2026

Join the Navanta Navigators Brief

Insights for community bankers navigating technology, security, and growth.

More in Exams & Audits

  • Pennies
    ARTICLES

    Industry Update: Preparing for Operational Changes Related to Pennies and Cash-Handling Practices

    Read the Post
  • ARTICLES

    Why We Chose to Partner with the Cyber Risk Institute (CRI)

    Read the Post
  • ARTICLES

    A Guide to Selecting the Right Replacement for the FFIEC CAT

    Read the Post
Navanta logo - homepage
  • Linkedin
  • Get to Know Us
    • Our Story
    • Our People
    • Join Our Team
  • Find Your Solution
    • Core Banking
    • Managed IT
    • CRM
    • Advisory
  • Explore Resources
    • Blog Posts
    • Client Experiences
    • Events & Webinars
  • Contact Us
    • 877-778-7774
    • [email protected]

  • 877-778-7774
  • Support
  • Privacy Policy
© 2026 Navanta
Contact Us

Client Login

  • MyBPC

    Previously MyBankonIT. Log in here to access your client portal for Bankers Private Cloud.

    Sign In

  • theSafeTM

    Sign in here to access your account information and resources in theSafe as usual.

    Sign In

  • Navanta CRM

    Previously Quest Analytics IQCRM. Continue to use these existing CRM links:

    Product Updates Technical Requirements CRM Email Support