Growing threats in commercial banking fraud.
Key takeaways:
- Commercial banking fraud is widespread and growing, with more than three-quarters of U.S. organizations experiencing attempted or actual payments fraud.
- Business email compromise, check fraud, vendor fraud, ACH/wire fraud, and account takeover fraud remain leading threats. Criminals increasingly use AI-powered tactics to create convincing scams and exploit trust.
- Strong internal controls are among the most effective defenses. Dual approvals, vendor verification procedures, multifactor authentication, employee training, transaction monitoring, and fraud mitigation tools can help reduce risk.
Fraud involving business payments and financial accounts is one of the most common threats companies face.
Every payment method carries some risk, but certain methods are more frequently targeted by fraudsters than others. As the tactics that swindlers use become increasingly sophisticated, often with the help of generative AI, companies must be more vigilant than ever about monitoring their financial operations. In this article, you’ll learn about the most common types of commercial banking fraud that companies may experience today and the steps you can take to help better safeguard your business.
The growing threat of commercial banking fraud.
Surveys show that commercial banking fraud has become alarmingly common. According to the Association for Financial Professionals’ (AFP) 2026 Payments Fraud and Control Survey, more than three-quarters of U.S. organizations experienced attempted or actual payments fraud in 2025.
Paper checks were the most targeted in 2025 (cited by 58% of survey respondents), followed by ACH debits (30%) and wire transfers (25%), the survey revealed.
According to the AFP, financial losses were reported by 48% of organizations with revenue under $1 billion and 66% of organizations with revenue exceeding $1 billion. The AFP notes that “while smaller firms face fraud less frequently, they lack the recovery infrastructure of larger firms and are therefore much more likely to absorb the full financial loss of a successful fraud attack.”
Common types of commercial banking fraud and how to mitigate them.
These are some of the most common fraud schemes that businesses encounter today, and the measures you can take to help lower your risk:
Business email compromise.
Business email compromise (BEC) occurs when a fraudster impersonates internal executives or vendors, or otherwise gains access to email accounts to request unauthorized payments or sensitive information. BEC is considered a type of phishing, but the email is usually highly personalized and often involves research into the way a business is structured.
The AFP’s most recent survey revealed that BEC affected 74% of organizations in 2025, which was a significant increase from 2023 and 2024.
Some red flags that can often indicate possible BEC include urgent requests for same-day wire transfers, emails that contain “updated” ACH instructions and last-minute payment redirections.
How to mitigate BEC: Requiring dual approvals for outgoing payments is one way to help combat BEC. Other controls include using verbal callback verifications for any changes to payments, and training employees to always independently verify urgent payment requests.
Check fraud.
Paper checks can be particularly vulnerable to fraud because they contain information that fraudsters can use to attempt unauthorized transactions. Unlike electronic transactions that typically incorporate multiple layers of security protocols, paper checks rely on basic security features that bad actors can easily circumvent. They also contain much of the information that someone would need to try to gain access to your checking account.
Examples of check fraud include mailbox theft, forged signatures, check washing (the chemical removal of legitimate payments information), counterfeit reproduction and fraudulent checks issued to shell companies.
Signs of check fraud to be on the lookout for include checks that clear with altered numbers, duplicate check numbers and missing checks from mailed payments.
How to mitigate check fraud: Switching from paper checks to a digital payment solution can reduce the number of people who see your account information. If you continue to use paper checks, set clear access rules. Decide who can write checks, who approves payments and how records are managed. There are also solutions that enable your bank to verify that a check matches what you issued.
Vendor fraud.
Vendor fraud is a type of financial deception in which a business’s vendors or employees working with vendors intentionally manipulate payments or procurement processes to steal money or overcharge for services and goods. In some cases, the fraudulent activity is carried out by bad actors who are posing as vendors.
The most common signs of possible vendor fraud include emails requesting updated ACH or wire details, slightly altered email domains and urgent requests that involve pending invoices.
How to mitigate vendor fraud: Strong internal controls for vendor payments are one of the most effective fraud mitigation strategies. For example, if payment instructions change, always call the vendor to verify the new information before issuing payment. Also, segregating accounts payable duties so that different employees are responsible for different tasks in the payment process can help make it harder for one person to conceal fraud. It also provides an additional layer of protection if a scammer is attempting to trick someone into issuing an improper payment.
ACH and wire fraud.
Electronic payments are generally less vulnerable to fraud than paper checks. However, ACH and wire payments can still be manipulated by bad actors initiating unauthorized wire transfers, or debits through the Automated Clearing House (ACH) network. Scammers may take advantage of the speed and finality of electronic payments, which can make fraudulent transactions difficult to recover once the funds have been sent.
The most common warning signs of possible ACH or wire fraud include unexpected requests to change payments instructions, messages that create urgency or push for immediate action, email addresses with subtle misspellings or unusual domains and requests that bypass normal approval processes.
How to mitigate ACH and wire fraud: As with vendor fraud, strong internal controls are one of the best defenses against ACH and wire fraud. Using ACH blocks and filters, setting transaction alerts and reconciling accounts daily are other effective ways to mitigate these risks.
Account takeover fraud.
Account takeover fraud occurs when a fraudster uses stolen credentials, phishing, malware or other means to gain unauthorized access to online banking, treasury management or email accounts. They then change the password and contact information associated with the account to lock out the rightful owner and use the account to make fraudulent transactions.
This type of fraud may not be detected quickly because the activity appears to be coming from a trusted source. Signs of possible account takeover fraud include login attempts from unfamiliar devices or locations, changes to user permissions or contact details, and payments initiated outside of normal activity.
How to mitigate account takeover fraud: Companies can lower the risk of account takeover fraud by requiring multifactor authentication for all users, limiting user permissions based on job role and regularly reviewing login and transaction activity.
Other fraud mitigation best practices for your business.
In addition to the strategies outlined above, there are some other tactics that can help build awareness about fraud and foster a culture of ethics and integrity within your organization:
- Educate your employees: Fraud mitigation depends as much on informed employees as it does on technology, and ongoing training is more effective than one-time awareness campaigns. Regularly review policies and procedures for issuing and receiving payments, and train your employees to question urgency and verify requests independently.
- Talk to your staff about social engineering: This is the term for psychologically manipulating someone into taking an action that benefits the scammer. Rather than exploiting a technical vulnerability, a fraudster attempts to persuade someone inside your organization to open the door using trust, urgency and authority. Today, more and more phishing attacks involve voice cloning and AI-enhanced scams that enable attackers to mimic familiar voices or writing styles.
- Maintain documented vendor onboarding procedures: For example, when adding a new vendor to your system, call the vendor using a known phone number rather than a phone number that’s given in an emailed request.
Fraud mitigation solutions from Commerce Bank.
Commerce Bank offers several solutions to help reduce your exposure to various types of fraud:
- Positive Pay: This feature electronically uploads your issued checks into our system, which then compares the amount on file with the check when it’s presented for payment. Any discrepancies trigger an alert for businesses to make a “pay/no pay” decision. Commerce also adds a dual layer of protection so that anything rejected in the first pass is sent for a manual review by an operator. Positive Pay also automates the reconciliation and check storage process for additional security. Additional features include Premium Positive Pay, which verifies the check’s payee information against the provided electronic file, and Reverse Positive Pay, which enables you to review all checks presented on that account through a daily file of paid items.
- ACH Risk Manager: With this feature, you can set criteria for ACH payments, such as vendor, amount, frequency and more. Any transactions that don’t match your set criteria are presented as exceptions for you to review.
- Email alerts: Businesses that are enrolled in Positive Pay, ACH Risk Manager or wire notifications can opt in to email notifications. Depending on the solution, Commerce will notify you of account activity such as unauthorized ACH transactions, check discrepancies, exceptions awaiting decision or wire transfers.
- Payment Hub: This feature validates a vendor’s bank account and routing number against trusted banking data before payments are sent, which helps detect potentially fraudulent or incorrect banking information before payments are issued.
What to do if fraud occurs.
If you suspect that your business has been the victim of fraud, speed and clarity are critical.
- Contact your bank immediately
- Notify your internal finance and leadership teams
- Secure affected systems and reset credentials
- Preserve all related emails, messages and documentation
- File appropriate reports with authorities, if necessary
Having a plan in place before an incident occurs can significantly reduce response time and confusion. Financial institutions can help organizations understand available fraud mitigation tools, establish response protocols and identify controls that align with payment activity.
If you have questions about fraud risks, mitigation strategies or strengthening internal controls, visit our fraud hub for additional resources and guidance.
