RECENTLY, A FELLOW—let’s call him Tom—contacted me with a distressing story of financial fraud. I’ll describe what happened then review steps you might take to prevent this same sort of thing.
Tom first noticed there might be a problem when he spotted a larger-than-average withdrawal from his checking account. The payee was a 529 college savings plan. But because Tom and his wife—let’s call her Jane—have 529 accounts for their children, the transaction almost went unnoticed. Tom assumed it was a transfer into his own family’s account. But when he mentioned it to Jane, she noted that they had stopped contributing to their 529. That prompted them to investigate further.
What they found was that scammers had set up a new 529 account in Tom’s name. They then initiated an electronic funds transfer to move more than $2,000 from Tom and Jane’s checking account into the new 529 set up by the thieves. The intention presumably was to then withdraw the funds from the 529, at which point the theft would become unrecoverable.
How were the thieves able to initiate the transfer from Tom and Jane’s bank? This is the part that’s distressing: They took advantage of the widely-used Automated Clearing House (ACH) system. Unfortunately, this system has key weaknesses that make it susceptible to fraud like this. First, it allows funds to be “pulled” out of an account. That’s in contrast to a wire transfer, which can only be “pushed” out by someone with access to the account. So a thief would only need your name, account number and bank routing number to siphon funds from that account. And unfortunately, that information is printed on the front of every check, making it accessible to someone looking to perpetrate this type of scheme.
Once the thief had the new 529 account set up in Tom’s name, it was just one simple step to initiate a transfer from Tom and Jane’s bank since the accountholder’s name was the same on both accounts. It was so seamless that if Tom hadn’t been reviewing the transactions in his account, he might never have noticed the theft.
According to the FBI, losses due to cybercrime have increased from $1 billion per year to $21 billion over the past 10 years, and ACH theft is a tactic thieves are using more frequently, so it’s worth looking at strategies to help keep your accounts secure. Here are six recommendations.
What if, like Tom and Jane, you spot a fraudulent transaction in your account? Then it’s important to report it as quickly as possible. Regulation E can limit your liability, but the faster you report a suspicious transaction, the more protection it provides. Liability is limited to just $50 if a theft is reported within two business days, but that exposure increases to $500 if it’s reported later. And after 60 days, there are no guarantees.
Thieves, unfortunately, don’t seem to sleep, which means that we need to be more vigilant than in the past, and need to be continuously vigilant. As personal finance author Mike Piper wrote recently, “Cybersecurity should be considered another core area of personal finance—no different from insurance planning, for instance.”
Adam M. Grossman is the founder of Mayport, a fixed-fee wealth management firm. Sign up for Adam’s Daily Ideas email, follow him on X @AdamMGrossman and check out his earlier articles.
So I’m the “Tom” in this article. Adam Grossman is our advisor, and I passed this story on to him. To clarify, and therefore hopefully answer a few of the good questions in the comments below…
My wife and routinely review transactions on our accounts, so we caught it quickly. My wife gets the credit for realizing we had stopped contributing (very recently) to our kids 529s. The amount was very similar to what we typically contributed. ACH transactions were reversed by the bank, as one commenter points out that they can, so we lost no money.
The fraudsters had set up a 529 account with Colorado’s plan, College Invest. We live in North Carolina, and use Virginia’s 529 plans. We’ve never had an account in Colorado. The account was not set up in my name or my wife’s name–it was set up in the fraudster’s name, either real or fabricated. They used a “UGift” link–a link you would send to friends and family so that they can set up an ACH transfer to your kids 529 accounts on a one time basis–to initiate the transfer. So whoever did it obviously had our routing and account number. That could have come from a billion places. We rarely write checks, but we do on occasion. Every bank and financial institution we use, and both our workplaces (direct deposit info), and our CPAs office, and our former advisors office, and on and on and on, ALL of them have this info, or had it at one point. My brother-in-law has a 25 year career with Fidelity in their compliance office. He told me that at Fidelity alone, which employs roughly 80,000 people, several thousand have this info for every client. Multiply that by the several brokerage houses and several banks we do business with. All it takes is one compromised human. I’d love to do business with fewer banks, but with two workplaces that use two different brokerage houses, and two intertwined financial lives, sometimes you can only consolidate up to a certain point. Of note, College Invest had frozen the account, as they had noticed an uptick in this type of fraud using their accounts, and had flagged this one as suspicious. They assured us that the only transfer allowed out of this account would have been back to its source–but they never contacted us–we contacted them to get that info.
One other interesting point…the fraudsters ran a test on the routing and account numbers first, by donating a small amount via ACH to Givewell, a charity we have used in the past. That was either a startling coincidence, or they knew our transaction history going back over a period of years, which is scary. I contacted everyone with our legacy info to let them know, but no one really did anything except to say that their digital protocols and safeguards were secure.
Anyway, we closed that bank account, and now monitor everything else even more closely than before. Per other comments:
ACATS fraud terrifies me. We locked all our accounts. Very easy to do on most platforms. Even if they don’t offer an option online (e.g. Fidelity workplace retirement accounts), call them. They can lock it.
For the person who doesn’t want to gift to a kids 529 via ACH, or write a check, or give bank info over the phone, I’m with you. I just give them cash when I see them. Kids love getting a wad of cash anyway.
I’m sure there were other points to address, but I’m tired of typing. Bottom line, you don’t need to be writing checks–or even own a checkbook– to be at risk for ACH fraud. Fraud should get top billing in personal finance these days. Ignore at your own risk.
ps. My real name is Ty
Besides ChexSystems as mentioned below, this article has also made we wonder, along with GW, why we even have checks.
When we became nomadic almost four years ago, I slipped a checkbook into my backpack. This article makes me wonder if we should shred it. In all that time we have needed to use checks twice (and had to mail them from overseas). Could we have found a way around not having paper checks on those occasions? Probably, with some hassle.
Most of the time we’re outside the U.S., so if someone got hold of my backpack, they would face some difficulty in exploiting our checks, and we’d have time to lock down the account, which doesn’t have much in it anyway.
Another thing to think about. My guess is we hold onto the checkbook.
I learned the hard way about check washing. But in my case it was not a check I had written. It was a paper check issued to me by IRS for my 2023 tax refund. (Now I know better than having an IRS refund processed as a check. It was my first time handling taxes after my husband passed. And now the only option you have for a refund is a direct deposit.). My check was stolen and washed, made payable to someone in Massachusetts. Chase had cashed it. Took me six months and numerous conversations with local police, Treasury Department, Secret Service (who handles mail theft), and the IRS. After six months the check was replaced.
I believe it is incorrect to state that any system designed to protect the user of a given method or system is not hackable (currently). If man created it, someone can corrupt it. It’s when, not if. It sounds “conspiracy theory like” but I’d bet that there are entities out there that collectively know far more about each of us than we’d like to believe.
As for checks, why do they still exist? These days, they are an accident waiting to happen, as many mention herein.
The scam that scares me the most is ACATS transfers where similar to the scam mentioned they withdraw securities or funds from your brokerage account to an identically set up account at another brokerage that they control. Apparently our senators are trying to get brokerage firms to start a system where their customers can lock their accounts to prevent such transfers. Fidelity and vanguard offer this but not Schwab.
I just noticed this feature at Vanguard, and locked accounts for me, my wife and mother, and called a friend.
This type of thing freaks me out. I don’t use monarch but I use something called Lunch Money. This app in a way forces you to approve every transaction. It takes literally seconds, especially when you know what you’ve paid for to approve them but when you see something that doesn’t make sense, it’s something to focus on. I connect all my checking credit cards to this Lunch Money app so I can make sure money that’s going out has been looked at by me.
Having worked in the payments industry, there are some common things people don’t know. ACH transactions can be reversed unlike Wires. You can ask your bank within 60 days of receiving your bank statement, to dispute an unauthorized transaction. This is not the case for wires. The bank does not need debit authority to pull back an ACH unlike a wire. You must send in an WSUD form which is a written statement of an unauthorized debit. The bank must act on it. Also, don’t allow anyone or any entity to pull from your account – like the Electronic Company. What if these entities were hacked and that information was made public. Push your payments and control your money. Happy to answer any questions.
Here is an explanation from AI:
The Anatomy of the Scam
Unlike a wire transfer (where money can only be pushed out by logging directly into your bank account), the Automated Clearing House (ACH) system allows authorized third parties to “pull” money directly from your account using basic details.
Why the Scam Works
Key Takeaways to Protect Yourself
This helped me, hoping it helps others.
Thanks for this article Adam. I am still a little mystified as how they can use the ACH system to pull money from one account to another, when they are not the person on the account, and then empty their new account? Someone please explain more. My counter to this, is that I get notified from my bank any time money goes out or comes in over $50 in an email and a text. I also use Quicken daily, to watch all bank accounts and charge cards. In fact being a numbers guy, I zero out my balance for each payment made. If you just use a credit card in general on Quicken, they just remove the payment, but on the transaction listing, you do not know what group it paid for. For that you have to go to a monthly statement, which is not always correct, as if you have a refund just before a payment is made, it is deducted and will not even agree with that statement. This is why I developed my own system to zero the balance and exactly what group transactions that covers.
I believe the most effective way to avoid ACH scams is to avoid keeping large amounts of money in your transactional account (usually checking). This is the account that is typically exposed to the public (checks, debit cards, etc.). Keep an offline MM or savings account and transfer funds as needed. That way the only monies that are exposed are in small amounts.
I was told this is not so simple. If you have other accounts with the same bank, they may pull from those accounts in the case of an overdraft.
I don’t allow overdrafts. It’s one way to remove a little risk.
From a different concern about ACH withdrawals, I’ve never contributed to a 529 plan and not sure how they are setup (gov’t, bank or brokerage). I’m wanting to help my niece pay off her college school loans in under five years, because right now she’ll be retired before the payments are completed. Her parents and grandparents are deceased, so I’m offering to help. Plus she is divorced with two young children.
She currently makes payments via ACH on the AidVantage website which manages federal student loans on behalf of the U.S. Department of Education. I can add my banking info and authorize ACH payments, but I’m hesitant as sited in Adam’s article even though this is a different purpose as I’m not funding a 529, but paying off a student loan. I want to make lump sum payments to the loans with the highest interest and the options to assist are: mail a check (I use the gel pens) with instructions which loan to apply the payment to; make on over-the-phone payment with my bank check card; or transfer the money to her and let her make the payment. A credit card is not an option offered.
Have other readers been in this situation in paying school loans and what caveats should I be aware of?
Adam, thanks for the great article and excellent advice. I’ve been meaning to buy a gel pen, ever since Jonathan’s article that you referenced. Thanks for the reminder.
Passkeys are an incredible problem for end users because they are tied to devices. If you don’t have the device, you are locked out. And if someone else has the device, let’s say your phone, and the can log in to it, now they have access.
Also, don’t be surprised when AI agents figure out how to access and use or spoof passkeys. We’re being sold a technology that makes our lives more difficult and no more secure.
I wonder if another strategy to limit losses is to keep a low balance in your checking account and don’t pay anyone directly from other accounts.
Question: how many keys are required to authenticate for ACH? This sounds like something an AI agent with infinite patience could work through. AI agents don’t sleep.
Passkeys aren’t the problem you suggest they are.
If you have my phone or laptop, you still have to know my password to log into it, and then you still need either my face or my fingerprint to use the passkey.
If I lose my device, I can still use my passkeys on another device by logging into the account that has my password manager (Google, Apple, etc.).
I don’t understand why unauthenticated pull requests are allowed. Seems like the accounts are completely wide open for this type of fraud.
The issue in this story is that the requests were authenticated.
I seem to recall there’s a way to block opening of new accounts in one’s name. Maybe it was specific to bank accounts and wouldn’t have worked for a 529, but probably still worth doing.
Edit: found it, it’s a freeze with ChexSystems.
https://www.chexsystems.com/security-freeze/information
Yes that’s the one! This behaves just like with initiating “credit freezes” with the “Big 3” CREDIT reporting agencies. It blocks opening savings, checking and other types of accounts.
I highly recommend folks create and ID and submit freezes to ChexSystems to block opening banking accounts such as checking, savings, etc. Parents can even submit for minors with the right docs.
IDK if Fidelity, Vanguard or other investment banks 100% use this but I know my local bank checks this each time you open any sort of account. I have to unlock the “freeze” for the bank to even open CDs.
Highly recommended. This is another easy another defense against Identity Theft but you must stay on top of it with like with the big 3 credit agencies. Peace.
Thanks for the link!
You can lock your accounts with the three credit bureaus. But this only prevents against opening accounts that require credit checks. Not sure if this would hav helped when opening an investment account.
Right, our files with the major credit reporting agencies are frozen. I’m thinking of something specific to opening new accounts.
Great article Adam. I watched Frank Abignale of “Catch Me If You Can” fame on a youtube video a while back. It’s the one where he speaks at Google HQ and in the video he spoke of his personal life, something he rarely does. It’s an incredible speech. Anyway, in that video he explains why he never uses debit cards, just credit cards. I check my bank account and credit cards every day.
Good point. I have to admit that I just use my debit card out of laziness; there’s always money in my checking account, and I don’t have to worry about forgetting the due date on a credit card and getting my FICO score dinged for no reason. That’s one thing I like about American Express — you can set it up so that if you haven’t paid, they’ll automatically take the minimum payment out of your checking account, saving you the FICO ding. At this point in history, a monthly due date on credit cards is stupid anyway, as is a monthly statement — you look up everything online, so I don’t care about a monthly statement, I just want to see a rolling history of all my transactions.
A few years ago, I attended a talk by Harry Markopolos — best known as the guy who busted Bernie Madoff. He said, among other things, that the ACH “pull” was a massive opportunity for fraud, and that we all needed to… keep an eye on it! Thanks for the reminder. I’m amazed that with all the obnoxious security we have to go through these days, that this loophole big enough to drive a Brink’s truck through is still there!
Thank you for this warning.
Free Newsletter
Arrives weekly.