Here is a fact about your business checking account that should change how you start every morning: if a fraudster pulls money out of it through the ACH network, you have about two banking days to get it back. A consumer in the same situation gets 60 days. Same banking system, same type of fraudulent debit, wildly different fuse — and yours is the short one.
All it takes to light that fuse is your routing number and your account number, printed together on every paper check you have ever handed out. Anyone holding one of those checks holds everything needed to originate an ACH debit against your account: no password, no signature, no multi-factor prompt. The debit posts, the money moves, and unless you catch it within roughly 48 hours of settlement, the straightforward path to reversing it closes. After that you are negotiating, not disputing.
This is not a rare edge case. The Association for Financial Professionals' 2026 Payments Fraud survey found that 76 percent of organizations experienced attempted or actual payments fraud in 2025, with ACH debits among the most frequently attacked payment types. The good news is that banks already sell the exact tools that stop this particular attack — ACH debit blocks, ACH filters, and ACH Positive Pay — and most of them cost little or nothing on a business account. This post explains how each one works, how to structure your accounts so a single compromised account number cannot reach your payroll or tax money, and what to do in the first hours after a bogus debit posts.
How an Unauthorized ACH Debit Actually Happens
The Automated Clearing House network moves money directly between bank accounts — payroll direct deposits, vendor payments, tax payments. It is governed by Nacha's Operating Rules, which define who can originate entries and how returns work. The network was designed for trusted parties, and its authentication for debits is thin by modern standards: the originator asserts it has your authorization, and the debit flows.
A typical attack chain looks like this. A fraudster gets your account and routing numbers — from a check you mailed to a vendor, a compromised invoice in someone's email, or a data breach. They submit an ACH debit through a bank or payment processor, sometimes one they opened under a fake business identity, sometimes a legitimate account they control. The debit posts against your account on settlement day. If you do not spot it and your bank does not return it within the business return window, the money is effectively gone from the ACH system, even though it started in a real account that investigators could have unwound the transaction from days earlier.
Business email compromise makes this worse. A fraudster posing as your vendor emails new "updated bank details," your bookkeeper updates the vendor record, and your next payment goes to the thief. That payment was authorized by you, which makes recovery far harder — a reminder that payment fraud is often a process failure first and a banking problem second.
The Two-Day Fuse: Business vs. Consumer Return Rights
This asymmetry is the single most important thing in this post, so let it sink in. Under Nacha rules, a consumer who spots an unauthorized ACH debit generally has up to 60 calendar days from the settlement date to dispute it through a Written Statement of Unauthorized Debit. For a non-consumer (business) account, the receiving bank must return an unauthorized debit far faster — the return generally has to be available to the originating bank by the opening of the second banking day after settlement. Practitioners shorthand this as the 24-hour or two-day window, and the practical meaning is the same: miss a couple of mornings of review and your cleanest remedy evaporates.
There is no appeal to a longer clock. Your bank cannot extend a Nacha deadline because you were on vacation. This is why every control in the rest of this post exists: they either prevent the debit from posting at all, or they surface it fast enough that you can still return it.
The daily-reconciliation habit is the free version of all of this. If you or your bookkeeper reviews every debit that posted the previous day — every single business day — you will catch unauthorized entries inside the window. If reconciliation happens weekly or monthly, you are structurally unable to return a fraudulent business debit through the normal channel. Whatever tools you adopt, pair them with daily review.
ACH Debit Blocks: The Nuclear Option (Use It Liberally)
An ACH debit block is exactly what it sounds like: your bank rejects every ACH debit presented against the account, no exceptions, no review queue. Nothing gets through.
Blocks belong on every account that should never have ACH money pulled out of it. Think about your own account roster: a trust or escrow account, a tax reserve account, a savings sweep, a refund account that only ever receives credits. If legitimate business never originates an ACH debit against an account, a block converts the entire category of ACH debit fraud on that account from "detect and return within two days" to "structurally impossible."
Call your bank's treasury or business banking team and ask which accounts carry blocks today. Many businesses discover the answer is none — blocks are rarely default-on, and nobody adds them unprompted. Adding one is usually a one-page form or a few clicks in the treasury portal, and most banks do not charge for it.
ACH Filters: An Allowlist for the Accounts That Must Accept Debits
Some accounts genuinely need to accept ACH debits: the account your payroll provider pulls from, the one your tax payments debit, the one where a few trusted vendors collect recurring payments. For these, the control is an ACH filter — a preauthorization list keyed on the originator's company ID, often with dollar limits attached.
You tell the bank: this account accepts debits only from these company IDs, and optionally only up to these amounts. A debit from an unknown originator, or a known one above its cap, is rejected or held as an exception depending on how your bank implements filters. A fraudster originating a debit under their own company ID sails straight into the wall.
Filters demand maintenance, which is where businesses let them rot. Every new vendor authorized to pull from the account needs to be added before their first debit, and every terminated vendor relationship needs to be removed. Build filter review into your vendor onboarding and offboarding checklists: when you sign the ACH authorization form with a new vendor, add their company ID to the filter the same day; when you cancel a service, remove it. Amount caps deserve the same treatment — set them near the actual expected debit so a compromised-but-authorized originator cannot drain the account in one pull.
ACH Positive Pay: Review Exceptions Before Money Moves
Check Positive Pay has been around for decades: you send the bank your issued-check file, and checks that do not match get flagged. ACH Positive Pay applies the same pay-or-return decisioning to electronic debits, and it closes the gap the old check-only systems left open — historically, forgers learned that Positive Pay systems did not monitor ACH debits at all.
With ACH Positive Pay enabled, debits that match your authorization rules post normally, while anything else lands in an exception queue in your online banking portal. Your team reviews each exception and clicks pay or return before the bank's cutoff — typically mid-morning on the business day after the debit arrives. That cutoff discipline is the whole game: an exception queue nobody checks before cutoff is decoration, not a control. Assign a named human, plus a backup, whose morning routine includes clearing the queue.
Smaller businesses sometimes balk because Positive Pay sounds like a big-company treasury product. It is not anymore. Most business banking platforms include ACH Positive Pay as a standard cash-management feature, often free or a few dollars a month. If your bank does not offer it, that is a legitimate reason to shop banks — the feature gap between institutions on this specific control is enormous.
Structure Your Accounts Like Bulkheads on a Ship
Tools on one big operating account help, but account structure multiplies their power. The goal is quarantine: a compromised account number should expose one pool of money, not all of them. A practical setup for a small business looks like this:
- Operating account. Day-to-day money in and out. Carries a filter or Positive Pay, never a full block, because legitimate debits must flow.
- Payroll account. Funded just in time for each payroll run, often zero-balance. Only the payroll provider's company ID is authorized. A fraudster who gets this account number finds little in it between paydays.
- Tax account. Holds estimated-tax reserves. ACH debits blocked entirely if you always push tax payments rather than letting agencies pull them — and pushing is the safer direction anyway.
- Collections account. Where customer ACH payments land. Debits blocked; money sweeps out to operating on a schedule.
Two principles make this work. First, restrict who knows each account number: the payroll account number should appear in exactly one vendor relationship, not on checks you hand to everyone. Second, keep balances proportional to exposure — large idle balances should sit behind blocks, not in the account with the most authorized debit originators.
This structure also simplifies your books. When each account has one job, every transaction on its statement has one expected shape, and anomalies practically highlight themselves. A debit on the collections account is not just unexpected — it is definitionally unauthorized.
What to Do in the First Hours After a Bogus Debit Posts
Despite every control, assume something will eventually slip through, and have the response rehearsed before you need it:
- Call your business banker immediately — same day, before cutoff if possible. Ask for the debit to be returned as unauthorized. Remember the fuse: your bank needs to get that return to the originating bank by the opening of the second banking day after settlement. A Friday-afternoon discovery handled Monday morning is already at the edge.
- Put it in writing. Follow the call with a written unauthorized-debit claim in whatever form your bank requires. Keep timestamps of every contact.
- Freeze the exposure. If the account number is compromised, ask about closing or restricting the account and moving legitimate activity to a fresh one. Fraudsters who succeed once tend to try again.
- Work backward to the leak. Review who had the account number, which vendor relationships changed recently, and whether any "updated banking details" emails arrived in the preceding weeks. Close the process hole, not just the banking hole.
- File a police report and notify your insurer. Recovery through law enforcement is a long shot for small amounts, but the report supports insurance claims and establishes a paper trail if the same originator hits you again.
Then run a post-mortem with your team within a week. The question is never "who clicked the thing" — it is "which control that we have now described in this post was missing, and who owns installing it by what date."
The 2026 Backdrop: Nacha Now Requires Fraud Monitoring Too
The controls above are yours to adopt, but the network itself tightened in 2026. Nacha's expanded fraud-monitoring rules took effect in two phases — March 20, 2026 for the highest-volume originators and receivers, and June 2026 for everyone else — requiring risk-based processes to spot unauthorized entries and entries authorized under false pretenses, on both the origination and receipt sides. Banks and processors must now monitor for the fraud patterns this post describes, including standardized entry descriptions that make suspicious debits easier to identify.
Treat this as a tailwind, not a substitute. Your bank's monitoring improves the ecosystem's odds; your blocks, filters, and daily review protect your specific account inside your specific two-day window. The liability for a missed return still lands on you.
Make Daily Review Part of Your Bookkeeping Rhythm
Here is where fraud prevention and bookkeeping merge into one habit. The daily review that catches unauthorized debits is the same daily review that keeps your books clean: match each posted debit to an expected payment, investigate the ones with no match, and record everything the same day. Businesses that reconcile daily do not just catch fraud faster — they close their months faster, spot duplicate vendor charges sooner, and walk into tax season with books that are already done.
If daily review sounds like overhead you cannot staff, shrink the surface instead of skipping the habit. Fewer accounts with debit activity, tighter filters, and pushed payments instead of pulled ones all reduce the number of lines a human must eyeball each morning. Ten expected debits across two accounts take minutes to verify; two hundred unexplained lines across six accounts take a morning nobody has. Design the account structure so the daily check is small enough to actually happen.
Your accounting records are also your evidence file. When you dispute a debit, the bank wants to know it was unauthorized — a clean ledger showing every vendor you actually authorized, with amounts and dates, answers that question in one page. Sloppy books do not just slow your tax return; they weaken your fraud claims.
Keep Your Payment Controls and Your Books in One System
Unauthorized ACH debits exploit the gap between what your bank shows and what your books expect — and that gap is smallest when your financial records are complete, current, and entirely under your control. Beancount.io provides plain-text accounting that gives you complete transparency and control over your financial data — no black boxes, no vendor lock-in. Get started for free and see why developers and finance professionals are switching to plain-text accounting.





