EXCLUSIVE – My colleague JJ Hornblass recently commented on the ACH fraud that took place at our company, and how one of its most striking aspects was the casual way in which the bank reacted to it.
This casualness may be due to ACH fraud not being anything new to the industry. What is new is faster payments, and easily built “burner identities,” — synthetic digital identities cobbled together to form credible semblances of customers, steal some money, and disappear. Mary Ann Miller, senior director at the fraud and compliance solutions provider NICE Actimize, described how synthetic identities are typically built. Fraudsters will use a valid social security number (easily and cheaply bought even before the Equifax breach), pair it with a name, and locate the new identity at an actual address located somewhere that won’t raise eyebrows at the risk management department. (123 Fake Street and 666 Fifth Avenue not recommended.)
Then fraudsters will open an account, get assigned a checking account, and send money to it by some faster payment method, and just as quickly move the money along to another account. “And they do this over and over,” Miller said. They start with small amounts via ACH, which itself is the backend of many payment types, such as payroll, billpay, and P2P, then move to larger amounts via wire fraud. They do this, that is, if the ACH account is not carefully monitored, Miller said. “It is hard to calculate the fraud rate across these many uses,” Miller noted.
“In the US, banks have no requirement to report fraud losses centrally in the public domain,” Miller said. “We do see, however, the fraudsters themselves commenting in online forums like Reddit when a product or channel is a so-called ‘money machine.’ Consumers are also becoming more vocal online when they have experienced fraud.” Further, fees are no barrier to keeping fraudsters away from faster payments — they have shown themselves willing to pay.
“Channels like realtime payments or faster payments that are supported under the ACH settlement are seeing an increase in attack rate, which also includes the authentication methods used to support these types of payments,” Miller added.
Another scenario is using the same money more than once by employing check float, the time between the payment being made and the money making its way to the other account. Part of the impetus of creating bitcoin was to prevent the double-spending of digital money.
Convenience for customers can mean headaches for fraud departments. A multitude of channels means many avenues for fraud to travel.
One company that acknowledges the pervasive use of checks in B2B transactions and beyond but provides stronger protection is the startup SnapCheck, an alum of INV Fintech, this site’s sister accelerator. SnapCheck is built to work within a company’s existing accounting system, but relieve the security of managing account numbers. SnapChecks can be sent and received without the sharing of account numbers. The company is gaining significant traction in the billpay and core banking space, having rolled out to Celeriti clients over the past several months.
With traditional ACH, there are few protections. To receive payments, companies must expose their account numbers, thus opening the door to fraudsters. Around the world, many accounts come with two account numbers — one for inbound payments and one for outbound. In the absence of such sensible improvements, the SnapCheck example shows that as customers push for faster payments banks comply, safety and soundness need not be thrown out of the window. Unfortunately, today it appears faster payments and digital account opening are creating a golden age not for the customer experience, but for fraud.






