For community financial institutions, fraud is no longer just a rising line item. It is a compliance, operational, and customer-trust issue that demands daily attention. 2025 loss data shows scammers continuing to exploit familiar weak spots: impersonation scams, stolen checks, ATM access, and authorized transfers customers are tricked into sending.
Now, Nacha’s fraud-monitoring rule is in effect for institutions of every ACH volume, adding regulatory urgency to a problem many institutions are already confronting.
The practical question for bank leaders is not whether fraud risk is growing. It is whether the low-cost defenses already available have become standard practice.
A hard deadline, not a soft one
Nacha’s updated fraud monitoring rules were rolled out in two phases this year. Phase 1 took effect in March 2026, covering all ODFIs plus any originator, third-party sender, or third-party service provider that moved more than 6 million ACH entries in 2023. Phase 2 took effect in June 2026, removing that volume threshold entirely.
The detail worth flagging internally: smaller banks are no longer exempt based on ACH volume. If your institution did not clear the 6 million-entry threshold and was waiting on the sidelines, it should already have a documented, risk-based monitoring process in place—not a plan to build one later.
What the 2025 data shows
Imposter scams. The FTC logged imposter scams as the most-reported fraud category for the fifth straight year, at roughly $3.5 billion in losses. Bank impersonation was the single costliest type, nearly $1 billion, ahead of government impersonators. In practice, that means one of the highest-dollar fraud risks facing your customers right now may sound like your own fraud department, not a stranger pretending to be someone else.
ATM jackpotting. The FBI recorded more than 700 jackpotting incidents in 2025, part of roughly 1,900 since 2020, with last year’s losses topping $20 million. Nearly every case starts the same way: someone opens the machine’s cabinet and installs or swaps in malware. That puts the fix back on the physical side, cabinet locks, tamper alerts, camera coverage—not just fraud software.
Check fraud. The American Bankers Association has tracked a roughly 385% rise in check fraud since 2020, most of it starting with stolen mail. FinCEN’s latest analysis counted more than 15,000 suspicious activity reports tied to mail-theft check fraud in a single six-month period, worth over $688 million, and small and mid-sized institutions filed most of them. Paper checks are still a live attack surface even where you’ve moved most customers to digital payments.
Zelle and other real-time transfers. A Federal Reserve Bank of Kansas City review found customers at the three largest U.S. financial institutions on the Zelle network disputed more than $206 million in 2023 transactions as scams, and those customers absorbed more than 80% of the loss themselves. The transactions were technically authorized, the customer clicked send, which is exactly why they’re so hard to reverse and so easy to miss with standard fraud rules.
Where fraud tools still miss
Monitoring software is good at catching a mismatched ACH name or a check that doesn’t match the signature on file. It has no way to catch a customer who reads a one-time passcode over the phone to someone they believe is calling from their financial institution, because by the network’s own rules, that transaction is authorized. This is the gap behind the Zelle numbers above, and it’s the reason customer education still matters even though it consistently underperforms as a standalone fix.
The more realistic goal is putting a small amount of friction, a callback prompt, a hold, a second confirmation, at the exact moment a customer is being talked into something, rather than hoping a warning they read weeks earlier comes to mind at the right second.
The defenses that don’t cost anything
- Positive pay catches check mismatches before they clear and is worth pairing with a fraud-monitoring platform on commercial accounts.
- FedDetect, the Federal Reserve’s ACH anomaly and duplicate-check alert service, comes at no added cost to any institution already on FedLine Web or FedLine Advantage.
- The American Bankers Association’s Fraud Contact Directory is searchable by institution, city, state, or FDIC number, and it’s the fastest way to find the right contact at another institution for a breach-of-warranty claim.
- The International Association of Financial Crimes Investigators connects fraud and investigations staff directly to contacts at other institutions instead of starting a case cold.
For most community financial institutions, the gap isn’t access to these tools. It’s whether front-line staff uses them consistently or only thinks of them after a case has already gone cold.
The takeaway
The record fraud numbers from 2025 are not going to reverse on their own. What is within your control is smaller than that: ensure ACH monitoring is documented, treat positive pay and FedDetect as standing practice rather than a backup plan, and build a moment of friction into the transactions that scammers currently talk customers straight through.
