Man using tablet in shop

9 min read

Key takeaways

  • Fraud—including business email compromise, check fraud, account takeover, ACH debit fraud and ransomware—fuels billions in losses each year, with AI making attacks faster and harder to detect.
  • Each type of fraud has distinct warning signs and prevention measures. Guarding against fraud starts with understanding threats your business faces.
  • Technical solutions help, but they’re rarely sufficient on their own. A strong fraud prevention strategy combines these tools with employee training on identifying and responding to attacks.

Fraud drove billions in losses in 2025, according to the FBI Internet Crime Complaint Center’s (IC3) most recent annual report, and artificial intelligence is making attacks faster, cheaper and harder to spot. A key step in managing fraud risk is understanding the threats your business may face. Five types of business fraud account for many threats facing companies today: business email compromise, check fraud, account takeover, ACH debit fraud and ransomware.

John Geronimo, Managing Director, Client Fraud Prevention and Recoveries at J.P. Morgan, breaks down how each type of fraud works and shares steps your team can take to help reduce risk.

Fraud typeHow it worksPrevention control
Business email compromiseFraudster impersonates a contact by email to redirect paymentsVerification callbacks for payment, contact changes
Check fraudCounterfeiting, alteration or forged endorsement of checksMove to electronic payments, Positive Pay with payee verification
Account takeoverFraudster gains access to a protected account and its fundsStrong authentication (passkeys, MFA), employee training
ACH debit fraudUnauthorized electronic withdrawal using routing and account numbersACH blocking and filtering, daily reconciliation
RansomwareMalware that locks files or systems until ransom is paidEmployee training, hardware/software updates, backups, network segmentation

Business email compromise

A Guide to Business Email Compromise Prevention

Your all-in-one guide to business email compromise

Read more

Business email compromise (BEC)—a scheme where fraudsters use email to trick targets into sending funds or sensitive information—is the most common form of business fraud Geronimo sees. It drove more than $3 billion in losses, according to the IC3's most recent annual report.

“With the speed at which we do business and the number of tasks on anyone’s plate, it’s no surprise this is a successful type of business fraud,” Geronimo said. “We’re human. We make mistakes.” 

How BEC works

In a BEC attack, fraudsters pose as a familiar business contact—typically a company executive or vendor. They may use phishing to compromise that person’s real email account, or rely on spoofing or look-alike domains to make their emails appear legitimate.

One common scenario: a fraudster impersonating a vendor intercepts an authentic invoice and forwards it with new payment instructions. The victim pays the invoice, but the funds go to the fraudster, not the vendor.

How to spot BEC

Treat any email requesting changes to payment instructions as suspicious until verified. Fraudulent emails can be hard to spot. Look-alike addresses may use subtle character swaps to mimic legitimate ones. Spoofed emails can be indistinguishable from authentic ones until you hit reply and see the actual address.

AI makes fraudsters more convincing. It can generate polished emails and mimic a person’s writing style. Scammers can also use voice cloning to impersonate an executive or vendor on a follow-up call.

“Anybody can do this for minimal cost,” Geronimo said. “It’s driven an increase in scale and believability.”

BEC prevention strategies

Callbacks—calls to confirm payment instruction changes before sending funds—can help reduce the risk of BEC, but only if done correctly. Avoid these five common callback mistakes:

  1. Relying on an inbound phone call. A scammer may try to circumvent your callback policy by calling first. “Often you’re multitasking, you know you need to confirm the change, and the person is offering to take care of it right then and there,” Geronimo said. Unless your team places the call, they can’t confirm who’s on the other end.  
  2. Using a fraudster’s phone number. When conducting a callback, use a reliable number from your system of record. Any contact information shared by email could have been provided by a bad actor. “We’ve seen criminals provide a company’s legitimate number but add a direct line that goes to a fraudster,” Geronimo said.
  3. Not speaking with the person responsible for the change. A fraudster who has compromised a legitimate email address can intercept verification requests. Confirm with the person who initiated the change—don’t settle for a third party.
  4. Assuming someone else conducted the callback. When one team makes payments and another verifies changes, steps can fall through the cracks. Speak with the person who validated the change and confirm they executed controls as intended.
  5. Not verifying contact changes. A sophisticated BEC attack may start with an email asking to change a vendor’s contact information in your system of record. Later, when you receive a request to update payment instructions and conduct a callback, the number on file will be the fraudster’s. “Contact changes should receive the same level of scrutiny as payment instruction changes,” Geronimo said.

To supplement callbacks, consider account validation services, which verify recipient account details to help prevent payments to fraudulent accounts.

      

Our team can help you strengthen fraud protection. 

Contact a banker

      

Check fraud

Check fraud is the unauthorized use, alteration or counterfeiting of checks to steal funds. Check use has declined, but checks remain the payment method fraudsters target most: 58% of organizations reported check fraud activity in the most recent AFP Payments Fraud and Control Survey Report.

How check fraud works

Checks are vulnerable to fraud in several ways:

  • Counterfeiting. If a scammer intercepts one of your business’s checks, they can use the account number, routing number and signature to produce counterfeits.
  • Alteration. Without indelible ink, a fraudster can alter a legitimate check’s payee name or dollar amount.
  • Endorsement fraud. A scammer deposits an intercepted check with a forged endorsement—or no endorsement at all.

How to spot check fraud

Signs your business may have experienced check fraud include unexpected discrepancies between internal records and bank statements, such as:

  • Checks clearing for amounts different from what was issued
  • Mismatched payee names
  • Duplicate check numbers

Another red flag: vendors reporting non-payment on invoices you’ve already paid, which may indicate checks were intercepted and altered.

Check fraud prevention strategies

One of the most effective ways to reduce check fraud risk is to use alternate payment methods.

“Not only are checks the most expensive payment instrument, they’re the most attacked—and even with the maximum protection available, you can’t entirely eliminate the potential for fraud,” Geronimo said.

If your business needs to use checks, consider fraud protection solutions such as Positive Pay and Check Fraud Detection. Positive Pay helps detect fraud by comparing checks presented for payment to issued checks and flagging discrepancies. Check Fraud Detection adds a layer of defense, using AI to review the entire check image for potential alterations—including changes to the check’s payee name.

For accounts that don’t issue checks, use Post No Check.

Account takeover

In an account takeover (ATO), a fraudster gains unauthorized access to a protected account—such as a bank account—and the funds in it. Though less common than BEC or check fraud, it’s a growing threat. In the first 11 months of 2025, the FBI Internet Crime Complaint Center received more than 5,100 ATO complaints, with losses exceeding $262 million.

“We saw a surge in account takeover in 2025,” Geronimo said. “For businesses, the impact can be devastating.”

How account takeover works

Fraudsters often pose as the target’s bank, using deceptive calls, texts or emails to convince the recipient to share login credentials such as a password or multifactor authentication code. A common pretext: the caller offers to help the target reverse or stop a fraudulent transaction.

Fraudsters may also create phishing websites that closely mimic an authentic bank site, then drive targets to them. They can link to the fake site in legitimate-seeming texts or emails, or manipulate search engine rankings so the phishing site appears at the top of the results.

Sophisticated fraudsters seize control as well as funds, changing the account’s password and contact information to lock legitimate users out.

How to spot account takeover

Warning signs of account takeover include:

  • Unsolicited contact. Even when a call, text or email appears to come from a familiar person or institution, verify it before acting—especially if the message creates alarm or urgency.
  • Unfamiliar account activity. Unexpected login notifications, password reset requests, changes to account contact information, or sign-ins from unknown devices or unusual locations can all signal a fraudster has gained access.

Account takeover prevention strategies

Preventing account takeover requires strong authentication and targeted training.

  • Use strong authentication. Passkeys are a form of authentication that eliminates passwords altogether, but they aren't available on every platform or device. If passkeys aren’t an option, combine passwords with tokens or one-time passcodes. Password managers add a layer of protection: they only autofill credentials on legitimate sites.
  • Train employees to spot threats. Training, including simulated phishing tests, can help your team learn to question unsolicited contact. Employees’ awareness of what information a bank will and won’t request can help reduce the risk of falling victim to fraud. A J.P. Morgan employee, for example, will never ask for your full account number, password, or full token code, nor will they ask you to click a link and enter your credentials.  
  • Manage exposure: Employees should only have access to accounts and payment capabilities necessary for their role. Review access regularly to keep entitlements up to date. Consider setting dollar or payment velocity limits appropriate to each employee’s role or requiring dual approval for changes such as adding a new payee or making a high-dollar payment.

ACH debit fraud

ACH debit fraud is an unauthorized electronic withdrawal from a business’s bank account. About 30% of organizations reported experiencing ACH debit fraud in 2025, according to the AFP survey.

How ACH debit fraud works

Unlike check fraud, which requires access to physical checks, ACH debit fraud takes only two pieces of information: your routing number and account number.

Fraudsters can obtain these details in many ways—from stealing or photographing one of your business’s checks to sending phishing emails to accounts payable staff. They may start with a small withdrawal to test whether the account is active and monitored before debiting larger sums.

How to spot ACH debit fraud

Daily reconciliation is critical: unauthorized corporate debits must be reported within 24 hours.

Signs of fraudulent ACH activity can include:

  • Small, unfamiliar debits that may indicate a fraudster testing your account
  • Debits from unknown originators with no business relationship to your company
  • Duplicate debits, as well as debits from familiar vendors in unexpected amounts or outside the typical billing cycle

ACH debit fraud prevention strategies

ACH transaction blocking can help guard your accounts against fraudulent ACH debits. You can block all ACH debits on an account or use ACH transaction blocking with Positive Pay to specify which companies can initiate debits, cap transaction amounts and adjust your filters as needed. Even with these tools, vigilance matters.

“You can still have unauthorized debits through an allowable company, which is why it’s still important to reconcile and identify anything unauthorized—ideally on a daily basis,” Geronimo said.  

Teams that are familiar with escalation procedures for suspicious transactions—and that use real-time alerts for new payees, changed banking details, first-time ACH recipients or unusual payment activity—are often better positioned to detect unauthorized transactions quickly.

Ransomware

Photo of people in a meeting

Protect your organization against ransomware

Read more

Ransomware is a type of malware that fraudsters use to extort businesses by blocking access to files, systems or networks until a ransom is paid. Fraudsters may also threaten to publish data.

Reported losses topped $32 million in 2025, according to the IC3—but that figure understates the true cost. It doesn’t capture operational disruption, lost files or third-party remediation expenses.  

How ransomware works

Fraudsters often spread ransomware through social engineering—emails or texts that trick recipients into clicking a link, downloading an attachment or scanning a QR code designed to spread malicious software.

Employee impersonation is another increasingly common tactic for spreading ransomware. A cybercriminal might pretend to be an employee to try to convince a call center worker to grant access to a system. Or a fraudster could impersonate tech support to persuade an employee to download malicious software.

Once inside, ransomware moves fast. It can take as little as three days to take hold across a network.

How to spot ransomware

Because ransomware attacks and ATO both start with unauthorized access, warning signs can overlap.

Treat unsolicited calls, texts and emails with skepticism—especially any that encourage you to click links, open attachments or scan QR codes. Unexpected system activity is another early indicator: pay attention to login notifications from unknown devices, new device enrollments or unfamiliar user accounts.  

Ransomware prevention strategies

Protecting your organization against ransomware requires strong cybersecurity hygiene:

  • Train employees to identify suspicious emails, calls and other messages
  • Limit employees’ ability to download unapproved software
  • Update software regularly to address vulnerabilities
  • Back up critical data
  • Segment networks to help contain ransomware if it gets in
  • Shield endpoints—networked devices such as laptops, desktops and mobile devices—with tools such as endpoint detection and response (EDR) or extended detection and response (XDR)

An incident response and recovery plan is equally important. Identifying essential systems and operations in advance—and mapping out workarounds or restoration paths—can help you minimize operational disruption.  

We’re here to help

Fraud threats evolve constantly, and so do our fraud prevention solutions. Whether you’re strengthening authentication, safeguarding payments or educating your team on prevention, J.P. Morgan bankers and industry specialists can help you prepare

© 2026 JPMorgan Chase & Co. All rights reserved. JPMorgan Chase Bank, N.A. Member FDIC. Deposits held in non-U.S. branches are not FDIC insured. Non-deposit products are not FDIC insured. Visit jpmorgan.com/cb-disclaimer for disclosures and disclaimers related to this content. 

Contact us

This field is required.

This field is required.

This field is required.

This field is required.

This field is required.

Please enter a valid business email. This field is required.

Please enter a valid business email. This field is required.

Please enter a valid business email. This field is required.

By checking the box below I consent to JPMorganChase using the information I have provided to send me:

Learn more about our data practices in our privacy policy.