Trends & Research

Trends & Research

Access the power of data and objective insight. Data from various sources, including NEACH surveys and member interviews, is compiled and made available as white papers, case studies, articles, benchmarking, and industry reports to provide a snapshot of both the current and future payments landscape. 

Published on Thursday, August 27, 2026

Six Ways to Help Your Business Customers/Members Mitigate Social Engineering Fraud

Cyber attacks are getting more sophisticated and drastically impacting the bottom lines of businesses. According to a report from VikingCloud, a cybersecurity firm, 58% of those companies who were attacked in 2025 suspect AI was used, and of those who were hit, 52% lost more than 5% of their total revenue.

 

While these forms of fraud are not new, they are morphing, and in many cases, they are having more dire results: The VikingCloud study also indicated that 55% of small-and-medium-sized businesses (SMBs) would have to close as a result of a cyberattack losses of less than $50,000. In a SMB-dominant landscape, this creates a disconcerting reality and points to an impetus for financial institutions (FIs) to offer guidance and support.

 

To get to the heart of these issues, I recently interviewed Jordan Bennett, Senior Director, ACH Risk Management, at Nacha, on NEACH’s Wrestling Payments podcast. We discussed the latest fraud trends affecting businesses, with a focus on social engineering attacks like business email compromise and vendor impersonation—nuanced attacks that attempt to get company representatives to make a payment voluntarily.

 

Mitigating risks

During our conversation, Bennett pointed out that Nacha’s recent rule changes require ACH Originators, businesses sending on the ACH Network, to implement fraud monitoring and detection. But these requirements can be supported and enhanced through their FI relationship. To help mitigate social engineering fraud risk, Bennett shared some examples of best practices for FIs:

 

  1. Add “good friction” to the payment process. If FIs require dual controls and verification steps as part of business payment protocols, it will help business customers/members protect themselves. This does create a degree of friction in the process, but it also offers a pause point, introducing a veil of protection. While the industry is prioritizing expediency, creating these intentional stop gaps will help safeguard the business, and emphasizing that point will help to ease the experience.

 

“We always think of payments as we want to get frictionless. We want to get there but there should be some good friction in there. Let's slow it down, let's think about it, let's make sure that we are identifying fraud before we are the victim,” Bennett summed up.

 

  1. Look holistically at all payment rails. FIs also want to make sure you have protocols in place to flag potential fraudulent transactions on other rails as well. And if an ACH gets returned for expected fraud, make sure you have the mechanisms in place to keep it from turning up on another payment channel.

 

Apply the reasoning behind ACH safety to your other payment rails. You might want to put similar controls in place. Don't make it easy to send money out by a check or wire or some other form of payment. Have good controls on all your payments and look at them together,” advised Bennett.

 

  1. Encourage business customers/members to use callback verification. We also discussed that by championing a callback with major transactions, you can help businesses introduce a point of good friction as a standard operating procedure. Instituting this routine check-in will build in a layer of security that creates a pause before action that may save the business thousands of dollars.

 

  1. Stress to business customers/members that they should treat urgency as a red flag. Particularly with voice impersonation scenarios, fraudsters want to initiate a scheme that speaks to a sense of urgency, triggers alarm bells, and drives a need for immediate action. By reminding business customers/members to recognize the signs of purposeful panic, they can slow down their reaction time to think critically about the details of the situation.

 

  1. Continue emphasizing that you will never ask for account credentials. FIs are already regularly promoting this message but should continue reiterating its importance. Fraudsters have gotten very good at creating a false sense of urgency as we just noted and having an additional clarity on the details an FI will not request may just trigger enough skepticism to get them to stop before initiating the payment.  

 

  1. Explain to your customers/members the steps to take if they are victimized. While we hope we can thwart the fraudster prior to this point, if the business does get scammed, make sure they know what to do. Chiefly, educate them to alert you to the situation as quickly as possible and to share the information for the receiving financial institution, when it’s feasible.  

 

These tips offer a tangible approach to help your customers/members in today’s complex fraud space; however, as we explore the new paradigm of payments fraud, we will have to continually evolve our game plans.

 

Knowledge is the first step to prevention, so we invite you to join us for upcoming education at our End-User Payments Fraud Symposium, taking place virtually 9:30 am – 12:30 pm ET, on September 22 and 23. We will explore the latest fraud schemes and approaches and ways to mitigate risk in today’s environment, and we’ll address topics from both a business and FI perspective. So, plan to join and invite your business customers/members—they attend free when registered by an FI.

 

For more information on the event or to register, visit NEACH.org


NEACH - New England Automated Clearing House Association is a neutral, member-focused advocate. Our role is to give you the intelligence, context, and connections you need to make informed strategic decisions. We bring together industry leaders, policymakers, and innovators so you can evaluate innovation through the lens of your institution’s mission and market strategy. For more information, visit neach.org.

 

...

AUTHOR: Joe Casali, AAP, AFPP, APRP
Executive Vice President

As the EVP of Payments Innovation for NEACH, Joe focuses on exploring innovative solutions and technologies that will help position members for success, both now and in the future. Connect with Joe to read more of his blogs, articles, and posts.

 

 

 

 

 

 

Rate this article:
No rating
Comments (0)Number of views (38)
Print