Skip to main content

Check Fraud Is Still the #1 Payment Threat in 2026 — Here's What to Do About It

8 min readMike ThriftMike Thrift
Check Fraud Is Still the #1 Payment Threat in 2026 — Here's What to Do About It

If you had to guess which payment method criminals target most in 2026, would you pick a slip of paper that's been around since the 1600s, or a real-time digital wire transfer? The answer, according to the Association for Financial Professionals' (AFP) latest Payments Fraud and Control Survey, is the paper check. Fifty-eight percent of organizations reported fraud involving checks in 2025 — more than ACH debits (30%) and wire transfers (25%) combined don't even catch up.

Overall, 76% of U.S. organizations experienced attempted or actual payments fraud last year. That's not a niche problem affecting a handful of unlucky companies — it's the default operating environment for anyone who moves money. And the businesses least equipped to absorb the hit are exactly the ones most likely to get hurt: small and mid-sized companies without a treasury department, a fraud analyst, or a bank relationship manager on speed dial.

If you run a small business and still write or accept checks — and most businesses do — this is worth 10 minutes of your attention.

Why Checks, of All Things, Are Still the Top Fraud Target

It seems almost backwards. Wire transfers move money instantly and irreversibly, which should make them the more attractive target. But checks have a structural weakness that newer payment rails don't: they carry all the information a fraudster needs — your bank routing number, account number, signature, and business name — printed in plain text on a piece of paper that travels through the mail, sits in an unlocked drawer, or gets photographed on a phone.

"Check washing" — chemically removing the ink from a stolen check and rewriting the payee and amount — has become common enough that the U.S. Postal Inspection Service runs dedicated public-awareness campaigns about it. Add in outright counterfeiting (printing fake checks using your account and routing numbers from an intercepted document) and altered checks (raising a $500 check to $5,000), and you have a fraud vector that's cheap to execute and hard to trace back to a single point of failure.

Here's the part that should give every small business owner pause: despite knowing all this, 72% of check-using organizations told AFP they plan to keep using checks anyway, and 68% cited vendor requirements as the reason. In other words, businesses aren't choosing checks because they think checks are safe — they're stuck with checks because a supplier, landlord, or contractor insists on being paid that way.

The Small Business Vulnerability Gap

The AFP survey highlights a split that matters a lot if you're not running a Fortune 500 finance department. Loss rates differ sharply by company size: 48% of firms under $1 billion in annual revenue reported actual financial losses from fraud, compared to 66% of larger organizations.

At first glance that sounds like good news for small businesses — fewer of them lose money. But read it the other way: larger organizations have layers of controls (dual authorization, dedicated fraud teams, insurance policies built for this exact scenario) that catch fraud attempts before money leaves the building, or that recover funds afterward through bank relationships and legal resources a five-person company simply doesn't have. When fraud does get through at a small business, there's usually no safety net. The loss isn't absorbed by a corporate insurance program — it comes straight out of the owner's cash flow.

That's the real headline buried in this survey: small businesses aren't attacked less because they're less vulnerable. They're often attacked less because they're smaller targets with smaller checks to steal. But when an attack succeeds, a small business has far less room to absorb it.

Business Email Compromise Is Rising Fast, Too

Checks aren't the only story. Business email compromise (BEC) — where a fraudster impersonates a vendor, executive, or client by email and requests a wire transfer or a change to payment banking details — affected 74% of surveyed organizations in 2025, a sharp jump from prior years.

The classic version: someone emailing from what looks like your CFO's address ("quick favor, need you to wire $8,000 to this new vendor account today, I'm in meetings"). The more sophisticated version showing up now: a fraudster who has actually compromised or spoofed a real vendor's email thread, and sends an invoice with "updated" bank details that route your legitimate payment straight into their account. If your bookkeeping process treats every emailed invoice as trustworthy without a verification step, you're exposed to this regardless of company size.

The AFP survey also flagged something newer for the first time this year: AI-generated deepfake audio and video used to impersonate executives on phone or video calls, requesting urgent wire transfers. It's still an emerging threat rather than a widespread one, but it's the direction fraud is heading — and it means "I heard the CEO's voice, so it must be real" is no longer a safe assumption.

The AI Adoption Gap — an Opportunity, Not Just a Warning

Only 17% of surveyed organizations currently use AI tools for fraud mitigation, even though the ones that do report meaningful benefits: 49% saw improved efficiency in fraud reporting, 45% reported better deepfake detection, and 43% saw faster real-time fraud identification.

For a small business, "use AI for fraud detection" doesn't have to mean building anything custom. Most modern business banking platforms and treasury tools now bundle basic anomaly detection — flagging a payment that's unusually large, going to a new payee, or timed oddly compared to your normal patterns — into their standard offering. The gap the AFP survey is describing isn't really an AI gap; it's an adoption gap. The tools exist and are often already included in your bank's business account. Most businesses just haven't turned them on.

A Practical Fraud-Prevention Checklist for Small Businesses

You don't need a treasury department to meaningfully cut your fraud risk. Here's what actually moves the needle, roughly in order of cost-to-benefit:

1. Turn on Positive Pay

Positive Pay is a service most business banks offer (sometimes for a small monthly fee, sometimes free with a business account) that compares every check presented for payment against a list of checks you've actually issued. If the check number, amount, or payee doesn't match what you told the bank you wrote, it gets flagged before it clears instead of after. Given that checks are the single most-targeted payment method, this is the highest-leverage control on this list — and it's often sitting unused in your online banking portal right now.

2. Add ACH Debit Blocks or Filters

If you don't authorize automatic ACH debits from vendors, you can block them entirely at the bank level, or set filters that only allow debits from a pre-approved list of companies and amounts. This closes off the second-most-targeted payment method with a single settings change.

3. Require a Callback for Any Banking-Detail Change

This is free and takes five minutes to implement: if a vendor, contractor, or "executive" emails asking you to send payment to a new bank account, verify it by phone — using a number you already have on file, not one provided in the email — before sending anything. This single habit defeats the majority of BEC attacks, because the fraudster's entire scheme depends on you trusting the email at face value.

4. Separate Who Approves Payments From Who Sends Them

Even in a two- or three-person business, having one person enter a payment and a different person approve it before it goes out creates a natural check (no pun intended) against both outside fraud and internal errors. If you're a true solo operator, the substitute is a mandatory 24-hour delay on any new or unusually large payment, giving you a cooling-off window to double-check it.

5. Reconcile Weekly, Not Monthly

Fraud caught within days is often recoverable; fraud caught after a month usually isn't. If your bookkeeping runs on a monthly cadence, you're giving a fraudulent check or ACH debit up to four weeks to clear, get spent, and become unrecoverable before you even notice it happened. This is where clean, current books stop being a "nice to have" and become your actual fraud detection system — you can't spot an unauthorized transaction in a reconciliation you haven't done yet.

Why Your Bookkeeping Habits Are Your First Line of Defense

Every control on that list — positive pay, ACH filters, callback verification, dual approval — depends on one underlying habit: knowing exactly what should be in your accounts at any given moment, so that anything unexpected stands out immediately. A business that reconciles daily or weekly against a clear, itemized ledger will catch a fraudulent $4,000 check within days. A business that reconciles once a month against a spreadsheet nobody's opened in three weeks might not catch it until the money's long gone.

This is one of the quieter arguments for keeping your books in a format you can actually audit line by line, rather than a black-box app that summarizes your cash position without showing the underlying transaction trail. Beancount.io gives you plain-text, version-controlled accounting — every transaction is a readable, timestamped entry you (or your bookkeeper) can review, diff, and reconcile against your bank feed without hunting through a proprietary interface. When something looks off, you can see exactly what changed and when. Get started for free and see how much easier fraud stands out when your books are actually built to be read.

Share this article