9 min read
Fraud drove billions in losses in 2025, according to the FBI Internet Crime Complaint Center’s (IC3) most recent annual report, and artificial intelligence is making attacks faster, cheaper and harder to spot. A key step in managing fraud risk is understanding the threats your business may face. Five types of business fraud account for many threats facing companies today: business email compromise, check fraud, account takeover, ACH debit fraud and ransomware.
John Geronimo, Managing Director, Client Fraud Prevention and Recoveries at J.P. Morgan, breaks down how each type of fraud works and shares steps your team can take to help reduce risk.
| Fraud type | How it works | Prevention control |
|---|---|---|
| Business email compromise | Fraudster impersonates a contact by email to redirect payments | Verification callbacks for payment, contact changes |
| Check fraud | Counterfeiting, alteration or forged endorsement of checks | Move to electronic payments, Positive Pay with payee verification |
| Account takeover | Fraudster gains access to a protected account and its funds | Strong authentication (passkeys, MFA), employee training |
| ACH debit fraud | Unauthorized electronic withdrawal using routing and account numbers | ACH blocking and filtering, daily reconciliation |
| Ransomware | Malware that locks files or systems until ransom is paid | Employee training, hardware/software updates, backups, network segmentation |
Business email compromise (BEC)—a scheme where fraudsters use email to trick targets into sending funds or sensitive information—is the most common form of business fraud Geronimo sees. It drove more than $3 billion in losses, according to the IC3's most recent annual report.
“With the speed at which we do business and the number of tasks on anyone’s plate, it’s no surprise this is a successful type of business fraud,” Geronimo said. “We’re human. We make mistakes.”
In a BEC attack, fraudsters pose as a familiar business contact—typically a company executive or vendor. They may use phishing to compromise that person’s real email account, or rely on spoofing or look-alike domains to make their emails appear legitimate.
One common scenario: a fraudster impersonating a vendor intercepts an authentic invoice and forwards it with new payment instructions. The victim pays the invoice, but the funds go to the fraudster, not the vendor.
Treat any email requesting changes to payment instructions as suspicious until verified. Fraudulent emails can be hard to spot. Look-alike addresses may use subtle character swaps to mimic legitimate ones. Spoofed emails can be indistinguishable from authentic ones until you hit reply and see the actual address.
AI makes fraudsters more convincing. It can generate polished emails and mimic a person’s writing style. Scammers can also use voice cloning to impersonate an executive or vendor on a follow-up call.
“Anybody can do this for minimal cost,” Geronimo said. “It’s driven an increase in scale and believability.”
Callbacks—calls to confirm payment instruction changes before sending funds—can help reduce the risk of BEC, but only if done correctly. Avoid these five common callback mistakes:
To supplement callbacks, consider account validation services, which verify recipient account details to help prevent payments to fraudulent accounts.
Check fraud is the unauthorized use, alteration or counterfeiting of checks to steal funds. Check use has declined, but checks remain the payment method fraudsters target most: 58% of organizations reported check fraud activity in the most recent AFP Payments Fraud and Control Survey Report.
Checks are vulnerable to fraud in several ways:
Signs your business may have experienced check fraud include unexpected discrepancies between internal records and bank statements, such as:
Another red flag: vendors reporting non-payment on invoices you’ve already paid, which may indicate checks were intercepted and altered.
One of the most effective ways to reduce check fraud risk is to use alternate payment methods.
“Not only are checks the most expensive payment instrument, they’re the most attacked—and even with the maximum protection available, you can’t entirely eliminate the potential for fraud,” Geronimo said.
If your business needs to use checks, consider fraud protection solutions such as Positive Pay and Check Fraud Detection. Positive Pay helps detect fraud by comparing checks presented for payment to issued checks and flagging discrepancies. Check Fraud Detection adds a layer of defense, using AI to review the entire check image for potential alterations—including changes to the check’s payee name.
For accounts that don’t issue checks, use Post No Check.
In an account takeover (ATO), a fraudster gains unauthorized access to a protected account—such as a bank account—and the funds in it. Though less common than BEC or check fraud, it’s a growing threat. In the first 11 months of 2025, the FBI Internet Crime Complaint Center received more than 5,100 ATO complaints, with losses exceeding $262 million.
“We saw a surge in account takeover in 2025,” Geronimo said. “For businesses, the impact can be devastating.”
Fraudsters often pose as the target’s bank, using deceptive calls, texts or emails to convince the recipient to share login credentials such as a password or multifactor authentication code. A common pretext: the caller offers to help the target reverse or stop a fraudulent transaction.
Fraudsters may also create phishing websites that closely mimic an authentic bank site, then drive targets to them. They can link to the fake site in legitimate-seeming texts or emails, or manipulate search engine rankings so the phishing site appears at the top of the results.
Sophisticated fraudsters seize control as well as funds, changing the account’s password and contact information to lock legitimate users out.
Warning signs of account takeover include:
Preventing account takeover requires strong authentication and targeted training.
ACH debit fraud is an unauthorized electronic withdrawal from a business’s bank account. About 30% of organizations reported experiencing ACH debit fraud in 2025, according to the AFP survey.
Unlike check fraud, which requires access to physical checks, ACH debit fraud takes only two pieces of information: your routing number and account number.
Fraudsters can obtain these details in many ways—from stealing or photographing one of your business’s checks to sending phishing emails to accounts payable staff. They may start with a small withdrawal to test whether the account is active and monitored before debiting larger sums.
Daily reconciliation is critical: unauthorized corporate debits must be reported within 24 hours.
Signs of fraudulent ACH activity can include:
ACH transaction blocking can help guard your accounts against fraudulent ACH debits. You can block all ACH debits on an account or use ACH transaction blocking with Positive Pay to specify which companies can initiate debits, cap transaction amounts and adjust your filters as needed. Even with these tools, vigilance matters.
“You can still have unauthorized debits through an allowable company, which is why it’s still important to reconcile and identify anything unauthorized—ideally on a daily basis,” Geronimo said.
Teams that are familiar with escalation procedures for suspicious transactions—and that use real-time alerts for new payees, changed banking details, first-time ACH recipients or unusual payment activity—are often better positioned to detect unauthorized transactions quickly.
Ransomware is a type of malware that fraudsters use to extort businesses by blocking access to files, systems or networks until a ransom is paid. Fraudsters may also threaten to publish data.
Reported losses topped $32 million in 2025, according to the IC3—but that figure understates the true cost. It doesn’t capture operational disruption, lost files or third-party remediation expenses.
Fraudsters often spread ransomware through social engineering—emails or texts that trick recipients into clicking a link, downloading an attachment or scanning a QR code designed to spread malicious software.
Employee impersonation is another increasingly common tactic for spreading ransomware. A cybercriminal might pretend to be an employee to try to convince a call center worker to grant access to a system. Or a fraudster could impersonate tech support to persuade an employee to download malicious software.
Once inside, ransomware moves fast. It can take as little as three days to take hold across a network.
Because ransomware attacks and ATO both start with unauthorized access, warning signs can overlap.
Treat unsolicited calls, texts and emails with skepticism—especially any that encourage you to click links, open attachments or scan QR codes. Unexpected system activity is another early indicator: pay attention to login notifications from unknown devices, new device enrollments or unfamiliar user accounts.
Protecting your organization against ransomware requires strong cybersecurity hygiene:
An incident response and recovery plan is equally important. Identifying essential systems and operations in advance—and mapping out workarounds or restoration paths—can help you minimize operational disruption.
Fraud threats evolve constantly, and so do our fraud prevention solutions. Whether you’re strengthening authentication, safeguarding payments or educating your team on prevention, J.P. Morgan bankers and industry specialists can help you prepare.
© 2026 JPMorgan Chase & Co. All rights reserved. JPMorgan Chase Bank, N.A. Member FDIC. Deposits held in non-U.S. branches are not FDIC insured. Non-deposit products are not FDIC insured. Visit jpmorgan.com/cb-disclaimer for disclosures and disclaimers related to this content.