I have worked in banking for nearly four decades, and I have never seen fraud evolve as quickly as it has over the past few years. What used to be a rare occurrence has become a weekly conversation with business owners. The targets are no longer just big companies or organizations that issue a lot of checks. It’s the two-person architecture firm. It’s the small marketing agency that mails a single vendor payment. It’s the family business that assumes “we’re too small to be interesting.”
Two themes continue to surface: email compromise and check fraud. The good news is there are simple steps that dramatically reduce your risk. None of them are flashy. All of them work.
The “too good to be true” interview
Let me start with a story that shows how convincing fraud can look today. One of our clients recently discovered a fake hiring operation running in their name. Applicants went through real-time video interviews with multiple “staff,” received an offer, and then got a sign-on bonus check drawn on the company’s account. A follow-up message told the new “hire” that the bonus was too high, and they needed to send part of it back.
Several applicants did the right thing and called the bank to verify the check. That call helped us alert the client and stop the damage. The next line of defense was in place as well: Positive Pay. When those counterfeit checks hit the account, the check numbers and payees did not match the file the company had sent the bank, and the items were flagged before funds left the account.
Two lessons from that incident: first, schemes can look legitimate from the outside. Second, basic controls and standard operating procedures do work when you use them.
Why email compromise sits at the center
Almost every fraud case I see starts with email. An accounting inbox receives “updated” wiring instructions. A vendor’s address changes. An employee gets a message that looks like it came from the CEO, asking for a quick payment. The emails are polite, timely, and well formatted. People take them at face value, because we are all busy and want to move on to the next task.
Learn to build a new habit: whenever payment instructions change, pause and make sure the message truly came from who you think it did. Subtle changes in the sender’s address or tone are often the first red flag. Then, verify by phone using a number you already have on file, never the one in the email signature. Pull the file. Call the known contact. Ask two simple questions only they would know, such as the last invoice amount, project name, or another detail you already share. It takes two minutes and can stop a six-figure mistake.
Check fraud is not going away yet
Checks expose two things that fraudsters want – your routing number and your account number. With the right blank stock and a cheap encoder, a criminal can produce believable checks that run through the system. “Check washing” compounds the risk. Someone intercepts your check, chemically removes the payee, inserts a new name, and deposits it before anyone notices.
If you still use checks, adopt these steps:
- Turn on Payee-Match Positive Pay. You send your bank a file of check numbers, amounts, and the intended payees. Anything that does not match becomes an exception for you to approve or return.
- Lock up your check stock. If the person who cuts checks leaves their office, the door should be locked. Do not leave a signed check on a desk “to go out with the mail.”
- Deliver mail securely. Do not leave envelopes on a hallway table. Take outgoing checks to the post office. If you have a history of issues, consider courier services for sensitive payments.
- Move electronic everywhere you can. Every paper check you eliminate is one less opportunity for someone to intercept your account information.
ACH safeguards most businesses overlook
Companies often protect checks and forget about Automated Clearing House (ACH) debits – the electronic network that processes direct payments and withdrawals between accounts. You have options:
- ACH Filters/Blocks. Maintain a short list of approved companies that can debit your account. Anything else becomes an exception for your review.
- Review-every-debit mode. If your transactions are light, choose the setting that requires your approval for any ACH debit before it posts.
- Be careful with “common” payees. It is tempting to approve a broad name like a national card issuer. That can open the door for someone to pay a bill that is not yours. Keep common brands on your exception list and approve specific amounts as they appear.
Daily monitoring and simple alerts
The best safeguards only work when you look at them. Put a second set of eyes on the account each morning – five minutes can save days of cleanup. Turn on text or email alerts for the events that matter like a debit over a set amount, a balance below your comfort level, or any outgoing wire. If something looks off, you have a short window to return items on a business account, so speed matters.
Treat sensitive data like cash
I still see bank details and wiring instructions sent in plain email. That is not secure. Use an encrypted email tool or a portal provided by your bank or accounting software. Share the password through a separate channel, and only with someone you already know. Do not text account numbers and do not post them in a PDF attachment without encryption. Convenience should not outweigh common sense.
Inside your office, assume curious eyes exist. Bank statements, check copies, and deposit records belong in a locked drawer. Shred bins should be locked too. If you hire a shredding service, remember that people change jobs. Do not leave a stack of statements beside the bin and assume they will disappear safely.
Build a short playbook now
You do not need a thick manual for your protocols. You do need a one-page plan that answers these questions:
1. Who approves payments and changes to payment instructions. Name the role, not just the person.
2. How to verify changes. Phone call to a known number, with two questions to authenticate.
3. What to do when something looks wrong. Pause payments, notify the bank officer, review pending exceptions, and consider closing and reopening an account if credentials may be exposed.
4. Where to store and how to send sensitive information. List the approved encrypted tools and who can use them.
5. Who watches the account daily. Even in small shops, pick a backup when the primary person is out.
Share the playbook with your accountant and any trusted vendor who touches your payments. A short conversation now is easier than a long cleanup later.
The mindset shift that unlocks results
The pace of fraud is not slowing down. Technology only makes it easier to mimic emails and create convincing paperwork. But that doesn’t mean you have to stay on the defensive. It means you put a few practical habits in place and stick with them. Verify changes. Limit paper checks. Use Positive Pay and ACH filters. Secure what matters, and look at your accounts every day.
These are not banking buzzwords. They are routines that protect cash, protect relationships, and protect your time.
Tamara Sutton Reed is Senior Vice President of Business Development and Treasury Management at Triad Bank. With more than 35 years in commercial banking, she specializes in helping privately held businesses strengthen cash flow, manage risk, and plan for long-term growth. Since joining Triad in 2010, Tamara has led the bank’s Treasury Management department and championed fraud-prevention initiatives for St. Louis businesses. She was recently recognized by St. Louis Small Business Monthly as one of the city’s Best Bankers of 2025.