Financial Fraud Advisory: ACH Change Requests Are the New Phishing Frontier

Fraud Full

Cybercriminals are increasingly shifting their focus from malware‑heavy attacks to social engineering and finance‑process manipulation, especially around ACH change requests. Companies across all industries are reporting six‑figure losses caused by nothing more than a convincing email.

This tactic is now one of the top five causes of business email compromise (BEC) losses reported to the FBI IC3.

How the Scam Works

Attackers send a message pretending to be a vendor, executive, or known partner, requesting that the company update ACH payment details. The email often looks legitimate at first glance, but contains subtle, intentional differences in the sender or CC’d addresses.

Common deception tricks:

1. Replacing letters with lookalike characters

2. Adding or removing punctuation

Attackers also frequently CC an “executive” to make the request appear authorized, but that CC is also a spoofed variation of a real address.

This psychological tactic increases urgency and legitimacy while bypassing normal approval skepticism.

Why Companies Are Losing Money

Because most organizations do not have a formal policy for verifying ACH change requests, accounting teams often rely on email alone.

Cybercriminals know this.

Once the ACH details are changed in the system, money wires go directly to the attacker’s account, and in many cases, the funds are unrecoverable.

Nevtec Recommendation: Implement a Mandatory ACH Change Policy

To combat modern phishing and BEC attacks, every organization should adopt a 3‑step ACH Change Verification Policy:

1. Zero ACH Changes Based Only on Email

No matter how legitimate the message appears.
No exceptions.
No “urgent” pressure overrides the policy.

2. Mandatory Out-of-Band Verification

Require a phone call or live confirmation using a phone number already on file, never one listed in the email requesting the change.

3. Dual Approval for All ACH Updates

One employee enters the change; another validates it.
This alone stops most fraud attempts.

Training Tip for Staff

Instruct teams to zoom in or hover over the sender and CC fields to check for:

  • extra characters
  • substituted characters (1 vs l, o vs 0, rn vs m)
  • additional subdomains
  • punctuation swaps
  • unusual reply‑to addresses

Cybercriminals rely on humans, not noticing.
Nevtec’s job is to make sure they do.

Scroll to Top