WrestlingPayments

Fighting Back Against Credit Push Fraud: New ACH Rules for Originators with Guest Jordan Bennett

Wrestling Payments Podcast: Season 4 - Episode 07

Episode Summary

In this episode of Wrestling Payments, host Joe Casali sits down with Jordan Bennett, AAP, APRP, Senior Director of ACH Network Risk Management at Nacha, to discuss one of the most pressing challenges facing businesses today: payment fraud driven by social engineering.

Jordan explores how fraud tactics have evolved from traditional unauthorized debit schemes to increasingly sophisticated scams involving business email compromise, vendor impersonation, account takeover, and executive impersonation. He explains why fraudsters are shifting their focus away from financial institutions and toward businesses themselves, convincing employees to voluntarily send payments to fraudulent accounts.

The conversation highlights practical steps organizations can take to protect themselves, including callback procedures, dual controls, payment verification processes, and slowing down transactions that appear urgent or unusual. Jordan also emphasizes the importance of having a response plan in place before fraud occurs, noting that speed is critical when attempting to recover funds after a fraudulent payment has been sent.

Joe and Jordan preview the upcoming End-User Payments Fraud Symposium, a unique event designed to bring together both financial institutions and business end users to better understand today's fraud threats, emerging ACH risk rules, and the shared responsibility required to protect payments across all channels.

 

Guest-at-a-Glance

💡 Name: Jordan Bennett, AAP, APRP
💡 What he does: Senior Director, ACH Network Risk Management
💡 Company: Nacha
💡 Noteworthy: Leads ACH network risk initiatives and rule development, helping financial institutions, third-party senders, and originators combat fraud, mitigate risk, and strengthen payment security.
💡 Where to find him: https://www.linkedin.com/in/jordan-bennett-aap-aprp-976b3014

 

Key Insights

Social Engineering Has Become the Fraudster's Weapon of Choice

For years, payment fraud focused heavily on unauthorized debits. Today, fraudsters have largely shifted their strategy. Rather than pulling money directly from accounts, they increasingly target businesses through social engineering schemes that convince employees to voluntarily send payments to fraudulent accounts. Common tactics include vendor impersonation, business email compromise, fake executive requests, and account change scams. Because the payment is technically authorized by the business, these schemes can be particularly effective and difficult to recover from. Organizations must recognize that fraud prevention is no longer just an IT or banking issue. It requires awareness and vigilance from everyone involved in the payment process.

 

Good Friction Can Prevent Costly Mistakes

Payments professionals often strive for speed and efficiency, but Jordan argues that some friction is healthy. A simple pause before changing account information or releasing a payment can stop many fraud attempts. Verifying requests through known contact channels, requiring dual approval for payment changes, and investigating unusual payment instructions create small delays that can prevent significant financial losses. In an era where fraudsters rely on urgency and pressure, slowing down may be one of the most effective security controls available.

 

A Fraud Response Plan Is Just as Important as Prevention

Even organizations with strong controls can become victims of fraud. That's why preparation matters. Jordan stresses that businesses should know exactly who to call, what information to provide, and how to escalate concerns if a fraudulent payment is suspected. Time is critical. Financial institutions can often take action to help recover funds, but the opportunity narrows quickly. The difference between reporting fraud within hours versus days can dramatically impact the likelihood of recovering stolen funds.

 

Episode Highlights

Why New ACH Rules Are Focused on Business End Users

00:01:00 – 00:04:40
Jordan explains how recent ACH rule changes are designed to address modern fraud schemes that target originators directly. While many ACH rules have historically focused on financial institutions, new requirements increasingly ask businesses to participate in fraud prevention efforts as well. The goal is to create a stronger, more coordinated defense throughout the payments ecosystem. 

“We need everybody to pull together. We need the originator. We need your financial institution, everybody in that payment stream to be looking out for the fraud.” 

 

The Simple Vendor Impersonation Scam That Keeps Working

00:05:25 – 00:08:15
One of the most common fraud schemes begins with a seemingly innocent message claiming a vendor has changed banking information. Jordan outlines how fraudsters exploit routine business processes and why callback procedures remain one of the most effective controls. Verifying payment changes through existing contact information can prevent substantial losses. 

“I'm gonna call back the number that I have on file for you.” 

 

Urgency Is Often the Biggest Red Flag

00:08:30 – 00:10:40
Fraudsters frequently create a sense of urgency to prevent employees from validating requests through normal channels. Jordan encourages organizations to slow down, pause when circumstances seem unusual, and verify requests before moving money. 

“If something seems urgent, it's probably an issue, right? And there's probably some sort of fraud in there. Now things can be urgent, but you'll be able to contact whomever it is and verify it. If it's urgent and there's no verification, leave that alone. You know, slow it down, add some friction.” 

 

How Modern Fraudsters Are Using Better Scripts and Better Technology

00:13:50 – 00:16:45
Jordan shares a personal story involving a fraud attempt targeting his wife. The experience underscores just how convincing many modern fraud schemes have become and why employees should never share authentication codes, passwords, or login credentials. 

“The script was fantastic. The only thing that really tripped us up was that they were asking for those codes and asking for the login information. And never, never.” 

 

Why Speed Matters After Fraud Happens

00:16:57 – 00:18:05
Many organizations focus on preventing fraud but fail to prepare for what happens if an incident occurs. Jordan emphasizes that reporting suspected fraud immediately gives financial institutions the best chance to stop, trace, or potentially recover funds. 

“The faster we can stop this, that we can put a hold on it, that we can indicate to the receiving financial institution: hey, this is fraud, stop it, and then they can provide information to each other and hopefully get this returned.” 

 

ACH Controls Should Apply Across Every Payment Type

00:19:10 – 00:21:00
Although the session focuses on ACH payments, Jordan reminds listeners that fraudsters are not loyal to a payment rail. Strong controls, verification procedures, and payment governance should be applied consistently across ACH, wires, checks, and other payment channels. 

“The fraudster's gonna take money however you give it to them.” 

 

Fraud Is Everyone's Problem

00:22:00 – 00:23:35
The episode concludes with a reminder that fraud affects consumers, businesses, and financial institutions alike. Protecting the payments ecosystem requires collaboration, education, and vigilance from everyone involved. 

“The fraudster's job is to take money from you. And they don't care if you're a bank or a consumer or a business. And our job is to help stop it all.”