FREE NEWSLETTER

Articles › Abuse

Financial Fraud

Adam M. Grossman

RECENTLY, A FELLOW—let’s call him Tom—contacted me with a distressing story of financial fraud. I’ll describe what happened then review steps you might take to prevent this same sort of thing.

Tom first noticed there might be a problem when he spotted a larger-than-average withdrawal from his checking account. The payee was a 529 college savings plan. But because Tom and his wife—let’s call her Jane—have 529 accounts for their children, the transaction almost went unnoticed. Tom assumed it was a transfer into his own family’s account. But when he mentioned it to Jane, she noted that they had stopped contributing to their 529. That prompted them to investigate further.

What they found was that scammers had set up a new 529 account in Tom’s name. They then initiated an electronic funds transfer to move more than $2,000 from Tom and Jane’s checking account into the new 529 set up by the thieves. The intention presumably was to then withdraw the funds from the 529, at which point the theft would become unrecoverable.

How were the thieves able to initiate the transfer from Tom and Jane’s bank? This is the part that’s distressing: They took advantage of the widely-used Automated Clearing House (ACH) system. Unfortunately, this system has key weaknesses that make it susceptible to fraud like this. First, it allows funds to be “pulled” out of an account. That’s in contrast to a wire transfer, which can only be “pushed” out by someone with access to the account. So a thief would only need your name, account number and bank routing number to siphon funds from that account. And unfortunately, that information is printed on the front of every check, making it accessible to someone looking to perpetrate this type of scheme.

Once the thief had the new 529 account set up in Tom’s name, it was just one simple step to initiate a transfer from Tom and Jane’s bank since the accountholder’s name was the same on both accounts. It was so seamless that if Tom hadn’t been reviewing the transactions in his account, he might never have noticed the theft.

According to the FBI, losses due to cybercrime have increased from $1 billion per year to $21 billion over the past 10 years, and ACH theft is a tactic thieves are using more frequently, so it’s worth looking at strategies to help keep your accounts secure. Here are six recommendations.

  1. Secure the login to your bank account by setting up two-factor authentication. And if your bank supports it, use an authenticator app, rather than text messages, for the authentication codes. Ideally, if your bank supports it, switch to a passkey. This is a newer technology that represents a significant advance over traditional passwords. Most importantly, they aren’t vulnerable to phishing attacks. They’re also easier to use, providing one-click logins, and you can store passkeys in a password manager. For those reasons, more websites are beginning to support passkeys. I’d make the switch as soon as your bank makes them available.
  2. Set up alerts through your bank to monitor activity in your checking account. Every bank is different, but most allow you to set up email- or text-based alerts to let you know when transactions above a specified threshold are processed, or when other types of activity occur.
  3. Monitor your transactions. These days, it can be hard to keep an eye on every account. Households often have one or more bank accounts plus credit cards and electronic payment services like Venmo or Zelle. Most people realistically don’t have the time to review every account in real time. That’s why I recommend a service like Monarch or YNAB, which are web-based versions of traditional budgeting tools like Quicken. These services can pull in transactions from all your accounts and present them in a consolidated list, making review much easier. If you kept Monarch or YNAB open in a browser window on your home computer, you could scroll through recent transactions whenever you have a spare minute.
  4. To narrow the circle of people who have access to your account information, try limiting the number of paper checks you write. Especially with Zelle and Venmo as alternatives for making payments, this is getting easier. If you do write paper checks, be sure to use a gel pen and to avoid freestanding mailboxes. Those steps can help prevent a related type of fraud, as Jonathan Clements explained a few years back.
  5. Pay attention to notifications of data breaches. Unfortunately, breach announcements seem to occur so frequently that we’ve become immune to them. It’s worth paying attention, though, to understand which particular pieces of information have been stolen. If it looks like your banking information is included in a breach, it might be worth opening a new account, inconvenient as that would be.
  6. Have your guard up against unsolicited phone calls, emails or text messages. If someone is contacting you about an “account security issue,” or claims to be calling from your bank or from the IRS, be especially wary. Those are common tactics for creating a sense of urgency that can cause people to let their guard down.

What if, like Tom and Jane, you spot a fraudulent transaction in your account? Then it’s important to report it as quickly as possible. Regulation E can limit your liability, but the faster you report a suspicious transaction, the more protection it provides. Liability is limited to just $50 if a theft is reported within two business days, but that exposure increases to $500 if it’s reported later. And after 60 days, there are no guarantees.

Thieves, unfortunately, don’t seem to sleep, which means that we need to be more vigilant than in the past, and need to be continuously vigilant. As personal finance author Mike Piper wrote recently, “Cybersecurity should be considered another core area of personal finance—no different from insurance planning, for instance.”

Adam M. Grossman is the founder of Mayport, a fixed-fee wealth management firm. Sign up for Adam’s Daily Ideas email, follow him on X @AdamMGrossman and check out his earlier articles.

Subscribe
Notify of
28 Comments
Newest
Oldest Most Voted
honestlyfuzzy806be48fc3

So I’m the “Tom” in this article. Adam Grossman is our advisor, and I passed this story on to him. To clarify, and therefore hopefully answer a few of the good questions in the comments below…

My wife and routinely review transactions on our accounts, so we caught it quickly. My wife gets the credit for realizing we had stopped contributing (very recently) to our kids 529s. The amount was very similar to what we typically contributed. ACH transactions were reversed by the bank, as one commenter points out that they can, so we lost no money.

The fraudsters had set up a 529 account with Colorado’s plan, College Invest. We live in North Carolina, and use Virginia’s 529 plans. We’ve never had an account in Colorado. The account was not set up in my name or my wife’s name–it was set up in the fraudster’s name, either real or fabricated. They used a “UGift” link–a link you would send to friends and family so that they can set up an ACH transfer to your kids 529 accounts on a one time basis–to initiate the transfer. So whoever did it obviously had our routing and account number. That could have come from a billion places. We rarely write checks, but we do on occasion. Every bank and financial institution we use, and both our workplaces (direct deposit info), and our CPAs office, and our former advisors office, and on and on and on, ALL of them have this info, or had it at one point. My brother-in-law has a 25 year career with Fidelity in their compliance office. He told me that at Fidelity alone, which employs roughly 80,000 people, several thousand have this info for every client. Multiply that by the several brokerage houses and several banks we do business with. All it takes is one compromised human. I’d love to do business with fewer banks, but with two workplaces that use two different brokerage houses, and two intertwined financial lives, sometimes you can only consolidate up to a certain point. Of note, College Invest had frozen the account, as they had noticed an uptick in this type of fraud using their accounts, and had flagged this one as suspicious. They assured us that the only transfer allowed out of this account would have been back to its source–but they never contacted us–we contacted them to get that info.

One other interesting point…the fraudsters ran a test on the routing and account numbers first, by donating a small amount via ACH to Givewell, a charity we have used in the past. That was either a startling coincidence, or they knew our transaction history going back over a period of years, which is scary. I contacted everyone with our legacy info to let them know, but no one really did anything except to say that their digital protocols and safeguards were secure.

Anyway, we closed that bank account, and now monitor everything else even more closely than before. Per other comments:

ACATS fraud terrifies me. We locked all our accounts. Very easy to do on most platforms. Even if they don’t offer an option online (e.g. Fidelity workplace retirement accounts), call them. They can lock it.

For the person who doesn’t want to gift to a kids 529 via ACH, or write a check, or give bank info over the phone, I’m with you. I just give them cash when I see them. Kids love getting a wad of cash anyway.

I’m sure there were other points to address, but I’m tired of typing. Bottom line, you don’t need to be writing checks–or even own a checkbook– to be at risk for ACH fraud. Fraud should get top billing in personal finance these days. Ignore at your own risk.

ps. My real name is Ty

Last edited 13 days ago by honestlyfuzzy806be48fc3
Michael1
17 days ago

Besides ChexSystems as mentioned below, this article has also made we wonder, along with GW, why we even have checks.

When we became nomadic almost four years ago, I slipped a checkbook into my backpack. This article makes me wonder if we should shred it. In all that time we have needed to use checks twice (and had to mail them from overseas). Could we have found a way around not having paper checks on those occasions? Probably, with some hassle. 

Most of the time we’re outside the U.S., so if someone got hold of my backpack, they would face some difficulty in exploiting our checks, and we’d have time to lock down the account, which doesn’t have much in it anyway. 

Another thing to think about. My guess is we hold onto the checkbook. 

dana little
17 days ago

I learned the hard way about check washing. But in my case it was not a check I had written. It was a paper check issued to me by IRS for my 2023 tax refund. (Now I know better than having an IRS refund processed as a check. It was my first time handling taxes after my husband passed. And now the only option you have for a refund is a direct deposit.). My check was stolen and washed, made payable to someone in Massachusetts. Chase had cashed it. Took me six months and numerous conversations with local police, Treasury Department, Secret Service (who handles mail theft), and the IRS. After six months the check was replaced.

G W
18 days ago

I believe it is incorrect to state that any system designed to protect the user of a given method or system is not hackable (currently). If man created it, someone can corrupt it. It’s when, not if. It sounds “conspiracy theory like” but I’d bet that there are entities out there that collectively know far more about each of us than we’d like to believe.

As for checks, why do they still exist? These days, they are an accident waiting to happen, as many mention herein.

Nick Politakis
19 days ago

The scam that scares me the most is ACATS transfers where similar to the scam mentioned they withdraw securities or funds from your brokerage account to an identically set up account at another brokerage that they control. Apparently our senators are trying to get brokerage firms to start a system where their customers can lock their accounts to prevent such transfers. Fidelity and vanguard offer this but not Schwab.

Edmund Marsh
19 days ago
Reply to  Nick Politakis

I just noticed this feature at Vanguard, and locked accounts for me, my wife and mother, and called a friend.

Edwin Belen
19 days ago

This type of thing freaks me out. I don’t use monarch but I use something called Lunch Money. This app in a way forces you to approve every transaction. It takes literally seconds, especially when you know what you’ve paid for to approve them but when you see something that doesn’t make sense, it’s something to focus on. I connect all my checking credit cards to this Lunch Money app so I can make sure money that’s going out has been looked at by me.

Jennifer Holme
20 days ago

Having worked in the payments industry, there are some common things people don’t know. ACH transactions can be reversed unlike Wires. You can ask your bank within 60 days of receiving your bank statement, to dispute an unauthorized transaction. This is not the case for wires. The bank does not need debit authority to pull back an ACH unlike a wire. You must send in an WSUD form which is a written statement of an unauthorized debit. The bank must act on it. Also, don’t allow anyone or any entity to pull from your account – like the Electronic Company. What if these entities were hacked and that information was made public. Push your payments and control your money. Happy to answer any questions.

William Dorner
20 days ago

Here is an explanation from AI:

The Anatomy of the Scam
Unlike a wire transfer (where money can only be pushed out by logging directly into your bank account), the Automated Clearing House (ACH) system allows authorized third parties to “pull” money directly from your account using basic details.

Why the Scam Works

  • Exposure of Checking Data: Your bank routing number and account number are printed openly on the bottom of every paper check you write. Anyone who receives a check (or breaches a merchant database storing check images) has the exact key needed to initiate an ACH pull.
  • Identity Spoofing & Name Matching: Scammers open a legitimate-looking account (like a 529 college fund, brokerage, or online savings account) in your real name using leaked personal data (SSN, DOB) from past corporate data breaches.
  • Flawed Automated Trust: When the scammer links your checking account to the newly created 529 account, the financial institution sees that the name on the checking account (Tom) matches the name on the 529 account (Tom). Because the names match, internal fraud algorithms treat it as a routine transfer between your own personal accounts and skip deep security checks.
  • The Exit Strategy: Once the money hits the 529 plan, the scammer initiates a withdrawal out of the 529 into an external, untraceable account or prepaid card, cashing out before you notice the missing checking funds.

Key Takeaways to Protect Yourself

  1. Review Account Activity Weekly: Catching suspicious transactions quickly is critical. Under federal Regulation E, if you report unauthorized electronic fund transfers within 2 business days, your personal liability is capped at $50. If you wait longer than 60 days, you can lose 100% of the stolen money.
  2. Limit Paper Checks: Reduce the physical distribution of your routing and account numbers by using electronic bill pay, Zelle, or credit cards instead of paper checks.
  3. Enable Transaction Alerts: Set up instant push or SMS notifications with your bank for any debit or withdrawal over a low threshold (e.g., $100).

This helped me, hoping it helps others.

William Dorner
20 days ago

Thanks for this article Adam. I am still a little mystified as how they can use the ACH system to pull money from one account to another, when they are not the person on the account, and then empty their new account? Someone please explain more. My counter to this, is that I get notified from my bank any time money goes out or comes in over $50 in an email and a text. I also use Quicken daily, to watch all bank accounts and charge cards. In fact being a numbers guy, I zero out my balance for each payment made. If you just use a credit card in general on Quicken, they just remove the payment, but on the transaction listing, you do not know what group it paid for. For that you have to go to a monthly statement, which is not always correct, as if you have a refund just before a payment is made, it is deducted and will not even agree with that statement. This is why I developed my own system to zero the balance and exactly what group transactions that covers.

Bruce Keller
20 days ago

I believe the most effective way to avoid ACH scams is to avoid keeping large amounts of money in your transactional account (usually checking). This is the account that is typically exposed to the public (checks, debit cards, etc.). Keep an offline MM or savings account and transfer funds as needed. That way the only monies that are exposed are in small amounts.

Last edited 20 days ago by Bruce Keller
Barbara Arendt
20 days ago
Reply to  Bruce Keller

I was told this is not so simple. If you have other accounts with the same bank, they may pull from those accounts in the case of an overdraft.

Edwin Belen
19 days ago
Reply to  Barbara Arendt

I don’t allow overdrafts. It’s one way to remove a little risk.

Olin
20 days ago

From a different concern about ACH withdrawals, I’ve never contributed to a 529 plan and not sure how they are setup (gov’t, bank or brokerage). I’m wanting to help my niece pay off her college school loans in under five years, because right now she’ll be retired before the payments are completed. Her parents and grandparents are deceased, so I’m offering to help. Plus she is divorced with two young children.

She currently makes payments via ACH on the AidVantage website which manages federal student loans on behalf of the U.S. Department of Education. I can add my banking info and authorize ACH payments, but I’m hesitant as sited in Adam’s article even though this is a different purpose as I’m not funding a 529, but paying off a student loan. I want to make lump sum payments to the loans with the highest interest and the options to assist are: mail a check (I use the gel pens) with instructions which loan to apply the payment to; make on over-the-phone payment with my bank check card; or transfer the money to her and let her make the payment. A credit card is not an option offered.

Have other readers been in this situation in paying school loans and what caveats should I be aware of?

Rick Connor
20 days ago

Adam, thanks for the great article and excellent advice. I’ve been meaning to buy a gel pen, ever since Jonathan’s article that you referenced. Thanks for the reminder.

Cammer Michael
20 days ago

Passkeys are an incredible problem for end users because they are tied to devices. If you don’t have the device, you are locked out. And if someone else has the device, let’s say your phone, and the can log in to it, now they have access.

Also, don’t be surprised when AI agents figure out how to access and use or spoof passkeys. We’re being sold a technology that makes our lives more difficult and no more secure.

I wonder if another strategy to limit losses is to keep a low balance in your checking account and don’t pay anyone directly from other accounts.

Question: how many keys are required to authenticate for ACH? This sounds like something an AI agent with infinite patience could work through. AI agents don’t sleep.

Last edited 20 days ago by Cammer Michael
Michael1
20 days ago
Reply to  Cammer Michael

Passkeys aren’t the problem you suggest they are. 

If you have my phone or laptop, you still have to know my password to log into it, and then you still need either my face or my fingerprint to use the passkey. 

If I lose my device, I can still use my passkeys on another device by logging into the account that has my password manager (Google, Apple, etc.).

Jon Daley
20 days ago

I don’t understand why unauthenticated pull requests are allowed. Seems like the accounts are completely wide open for this type of fraud.

Cammer Michael
20 days ago
Reply to  Jon Daley

The issue in this story is that the requests were authenticated.

Michael1
20 days ago

I seem to recall there’s a way to block opening of new accounts in one’s name. Maybe it was specific to bank accounts and wouldn’t have worked for a 529, but probably still worth doing.

Edit: found it, it’s a freeze with ChexSystems.

https://www.chexsystems.com/security-freeze/information

Last edited 20 days ago by Michael1
G Mzz
19 days ago
Reply to  Michael1

Yes that’s the one! This behaves just like with initiating “credit freezes” with the “Big 3” CREDIT reporting agencies. It blocks opening savings, checking and other types of accounts.

I highly recommend folks create and ID and submit freezes to ChexSystems to block opening banking accounts such as checking, savings, etc. Parents can even submit for minors with the right docs.

IDK if Fidelity, Vanguard or other investment banks 100% use this but I know my local bank checks this each time you open any sort of account. I have to unlock the “freeze” for the bank to even open CDs.

Highly recommended. This is another easy another defense against Identity Theft but you must stay on top of it with like with the big 3 credit agencies. Peace.

Last edited 19 days ago by G Mzz
Edmund Marsh
19 days ago
Reply to  G Mzz

Thanks for the link!

Last edited 19 days ago by Edmund Marsh
Bruce Keller
20 days ago
Reply to  Michael1

You can lock your accounts with the three credit bureaus. But this only prevents against opening accounts that require credit checks. Not sure if this would hav helped when opening an investment account.

Michael1
20 days ago
Reply to  Bruce Keller

Right, our files with the major credit reporting agencies are frozen. I’m thinking of something specific to opening new accounts.

Patrick Brennan
20 days ago

Great article Adam. I watched Frank Abignale of “Catch Me If You Can” fame on a youtube video a while back. It’s the one where he speaks at Google HQ and in the video he spoke of his personal life, something he rarely does. It’s an incredible speech. Anyway, in that video he explains why he never uses debit cards, just credit cards. I check my bank account and credit cards every day.

urbie53ca4a2392
20 days ago

Good point. I have to admit that I just use my debit card out of laziness; there’s always money in my checking account, and I don’t have to worry about forgetting the due date on a credit card and getting my FICO score dinged for no reason. That’s one thing I like about American Express — you can set it up so that if you haven’t paid, they’ll automatically take the minimum payment out of your checking account, saving you the FICO ding. At this point in history, a monthly due date on credit cards is stupid anyway, as is a monthly statement — you look up everything online, so I don’t care about a monthly statement, I just want to see a rolling history of all my transactions.

urbie53ca4a2392
20 days ago

A few years ago, I attended a talk by Harry Markopolos — best known as the guy who busted Bernie Madoff. He said, among other things, that the ACH “pull” was a massive opportunity for fraud, and that we all needed to… keep an eye on it! Thanks for the reminder. I’m amazed that with all the obnoxious security we have to go through these days, that this loophole big enough to drive a Brink’s truck through is still there!

Edmund Marsh
20 days ago

Thank you for this warning.

Free Newsletter

Arrives weekly.

Select list(s):
SHARE