# Check Fraud in 2026: How It Works and How to Stop It | RankShield Financial

> Check fraud is rising even as businesses write fewer checks. How mail-theft schemes work, why Positive Pay is essential, and the one gap it cannot close.
>
> Source: https://rankshieldfinancial.com/resources/check-fraud-prevention-business/ · RankShield Financial (verifiable pre-settlement payment security)

RankShield Network · Financial · Payment Fraud
# Check Fraud in 2026: Why It Is Rising, How the Schemes Work, and What Stops It

Businesses write fewer checks every year, yet check fraud keeps climbing, driven by mail theft and check washing. Here is how the schemes actually work, the controls that stop most of them, and the one gap that no check control can close.
   By  Jamie Kloncz  Founder, RankShield Financial    August 18, 2026 · 12 min read               Key takeaways
- Check fraud is rising even as check use declines. The AFP 2026 survey found checks the most-targeted payment method at 58 percent, and FinCEN tied a surge to mail theft, with banks flagging over $688 million in mail-theft-related check fraud in six months of 2023 alone.
- Once a check is stolen from the mail, FinCEN found three main outcomes: 44 percent are altered (check washing) and redeposited, 26 percent are used as templates to print counterfeit checks, and 20 percent are fraudulently signed and deposited.
- The workhorse controls genuinely work against these. Positive Pay matches presented checks to a file you issued; Payee Positive Pay adds payee-name matching to catch washing; ACH debit blocks and filters, secure mail handling, and daily reconciliation close the rest.
- There is one check fraud no check control catches: a real, correctly-drawn check you were deceived into issuing to a fraudulently-changed payee. Positive Pay clears it because you authorized it, which is the same blind spot that vendor-impersonation and BEC exploit.
- The strongest structural move is to shift high-value payments off checks, but onto verified electronic rails, or you simply trade check fraud for wire and ACH fraud. Verifying the payee and approval before settlement is what makes that migration safe, and it is what RankShield Financial does.

Check fraud is the payment crime that refuses to fade, and 2026 is the year the numbers make that undeniable. Even as businesses write fewer paper checks every year, the check remains the single most-targeted payment method: the 2026 AFP Payments Fraud and Control Survey found checks were hit in 58 percent of organizations that faced payments fraud, more than any other method 3 . The engine behind the surge is mail theft: FinCEN reported that banks filed more than 15,000 suspicious activity reports flagging over $688 million in mail-theft-related check fraud in just six months of 2023 1 , after check-fraud reports nearly doubled to roughly 680,000 in 2022. This guide explains why check fraud rises as check volume falls, how the schemes actually work once a check is stolen, the controls that stop most of them, and the one kind of check fraud that no check control catches, which is where verifying the payee before a payment settles comes in.

## Why check fraud rises as check use falls

It looks like a paradox: Americans and American businesses write fewer checks every year, yet check fraud keeps climbing. The explanation is that the checks still being written are exactly the valuable ones, and criminals have industrialized the theft of them. The 2026 AFP survey put checks at the top of the target list, hit in 58 percent of organizations that experienced payments fraud, ahead of ACH debits at 30 percent and wire transfers at 25 percent 3 . A business check carries a real bank account and routing number, a large and often predictable amount, and a physical journey through the mail, which is a combination no electronic payment offers a thief.

The accelerant since 2020 has been mail theft. FinCEN reported that check-fraud suspicious activity reports rose 23 percent in 2021 and nearly doubled in 2022, to about 680,000 2 , and it traced much of the increase to checks stolen from residential mailboxes, collection boxes, and mail carriers. In a six-month window of 2023, financial institutions filed more than 15,000 SARs flagging over $688 million in mail-theft-related check fraud, in every US state. So the honest framing is not that checks are becoming safe as they become rare; it is that the shrinking pool of checks is under more concentrated attack than ever, which makes doing nothing the riskiest option for a business that still writes them.

## How the schemes work once a check is stolen

FinCEN’s analysis of the SAR data gives an unusually clear picture of what happens to a stolen business check, and the three main outcomes each call for a different defense. In 44 percent of cases the check was altered and deposited 1 , most often through check washing, where a chemical bath removes the ink so the payee and amount can be rewritten while the genuine signature remains. In 26 percent, the stolen check was used as a template to print counterfeit checks drawn on the victim’s account. In 20 percent, the check was simply signed with a forged endorsement and deposited or cashed. The remaining cases mix these methods or use the account details for other fraud.

The common thread is that the victim’s real account is the target, reached through a physical document that was never meant to be public. Check washing defeats the eye because the paper, the account, and the signature are all authentic; only the payee and amount changed. Counterfeits defeat casual review because they carry correct account and routing numbers. Forged endorsements exploit deposit channels that do not verify the payee. Understanding which scheme you are defending against matters, because the controls that stop them are not interchangeable: the control that catches a counterfeit is not the same one that catches a washed check, and a business needs the layer that covers all three.

## The controls that genuinely stop most check fraud

The good news is that the workhorse controls are effective and widely available, and this guide will not pretend a business is helpless. Positive Pay is the foundation: you send your bank a file of the checks you issued, with check numbers and amounts, and the bank pays only matching items, flagging everything else for your review. It catches counterfeits and unauthorized checks because they are not on your issued list. Payee Positive Pay adds the payee name to the match, which is what catches check washing, since a washed check has an altered payee that no longer matches your file. Reverse Positive Pay is a lighter version where you review presented items yourself. For the ACH side that check fraud often spills into, ACH debit blocks and filters stop unauthorized electronic debits against your account.

Around those bank controls sit the operational habits that close the gaps: mailing checks from inside a post office rather than an outgoing mailbox, using secure lockbox services for high-volume disbursements, reconciling accounts daily rather than monthly so a fraudulent item is caught inside the return window, and enforcing dual controls on check issuance. None of this is exotic, and most of it a business’s own bank will help set up. The reason check fraud still succeeds at scale is not that these controls do not work; it is that many businesses have not turned them all on, or reconcile too slowly to act inside the short window a returned item allows. The [ACH return-window guide](https://rankshieldfinancial.com/resources/ach-fraud-business-return-window-myth/) explains just how short that window really is.

## The one check fraud no check control catches

Here is the honest limit of every control above, and it is the reason this topic connects to the rest of the site. Positive Pay, Payee Positive Pay, and the operational habits all answer one question: is this presented check one that you actually authorized. They are built to catch a check you did not issue, or one that was altered after you issued it. What none of them can catch is a check you did issue, for the right amount, that you were deceived into sending to the wrong party. If a fraudster impersonates a vendor and convinces your team to cut a legitimate check to a new address or a new account, Positive Pay clears it without a second look, because from the bank’s side nothing is wrong: the check matches your issued file exactly, since you issued it.

This is the same blind spot that vendor-impersonation and business email compromise exploit on electronic rails, and it is documented in depth in the guide on [what Positive Pay cannot catch](https://rankshieldfinancial.com/resources/positive-pay-gap-vendor-impersonation/). The distinction is between an unauthorized payment, which check controls are designed to stop, and an authorized payment to a fraudulently-changed payee, which they are structurally blind to because the deception happened before the check was ever written. Recognizing that a business needs both kinds of defense, one for the checks it did not authorize and one for the payees it was tricked into paying, is the whole point, because closing only the first gap leaves the second wide open.

## The strongest move: get off checks, but onto verified rails

Ask a bank or a fraud examiner how to cut check fraud to near zero and the honest answer is the same: write fewer checks. Electronic payments remove the physical document a thief steals, washes, or copies, which eliminates the entire mail-theft attack surface at once. For high-value and recurring disbursements especially, moving from checks to ACH or wire is the single most effective structural change a business can make against the schemes in this guide. That is real, and this page will not undersell it: the paper check is the vulnerability, and removing it removes the vulnerability.

The catch, and it is a serious one, is that migrating off checks does not eliminate payment fraud; it relocates it. The same criminals who wash checks run vendor-impersonation and business email compromise against ACH and wire payments, which is why the FBI put business email compromise at $3.046 billion in 2025, with 86 percent of the money moving by wire or ACH 4 . Trade a check for an unverified electronic payment and you have swapped check washing for the payee swap. So the honest version of the advice is: move off checks, and verify the payee and the approval on the electronic payments you move to, so you are not solving one fraud by opening another.

## Where RankShield Financial fits, and where it does not

The honest framing matters most on this topic, because RankShield Financial is not a check-fraud product and this guide will not pretend otherwise. It does not inspect physical checks, it does not read your mail, and it does not replace Positive Pay or Payee Positive Pay, which remain the right controls for the checks you still write. If your problem is washed checks and counterfeits, your bank’s Positive Pay is the answer, and you should turn on every tier of it. RankShield operates on the electronic side of the picture, in the payment authorization path, and it never takes custody of funds.

What RankShield does is address the two places check controls run out. First, the authorized-payee-switch gap: it verifies that a payment is going to the payee you actually intended and that a named person approved it, which is the exact fraud Positive Pay clears because the payment is authorized. Second, the migration: when you move high-value payments off checks onto ACH or wire, RankShield verifies those electronic payments before they settle, so the shift does not trade check fraud for BEC. The boundaries stay explicit: it verifies the payee and the approval and seals a checkable record, it does not catch every scam, and it is a design-partner-stage product that claims no network it has not built. If you want that verification in front of the payments you are moving off checks, you can [see how it works](https://rankshieldfinancial.com/how-it-works/) or [request access](https://rankshieldfinancial.com/contact/).

## What to do this quarter

If check fraud is on your list, the practical sequence is short. Turn on Positive Pay and Payee Positive Pay with your bank if you have not, because payee-name matching is what catches the washing that drives most of the losses. Add ACH debit blocks or filters so the same account cannot be drained electronically. Stop mailing checks from unsecured outgoing mailboxes, and reconcile accounts daily so a fraudulent item is caught inside the return window rather than at month-end when it is too late. Then start moving your highest-value and most-repetitive disbursements off checks entirely. Each of these is a control your own bank can help you enable, and together they address the check fraud in the FinCEN data directly.

The one thing that sequence does not cover is the authorized payment to a switched payee, on either a check or the electronic rails you migrate to, and that is the gap worth closing deliberately rather than discovering after a loss. Check fraud is rising because the checks that remain are valuable and exposed, but the deeper lesson in the 2026 data is that fraud follows the money onto whatever rail it travels. A defense that verifies the payee and the approval before the payment settles is the one that keeps working as you change how you pay, which is exactly why it belongs alongside the check controls rather than instead of them.
        Operate it
## Verify a payment before it settles

Compose a payment and the conditions around it, then run the same check the product runs on a live rail. The verdict comes back before the money would move.
      Pay to     Amount (USD)     Conditions around this payment      Bank details changed by email       First-time payee       Amount over approval policy       Approver signature verifies       PRE-SETTLEMENT VERDICT  RANKSHIELD NETWORK
Compose a payment on the left and run the check. The verdict is returned before the money moves, the way the product returns it on a live rail.

Sandbox demo · reproduces the product’s verdict logic and signing metadata · not a live network call
        Downloadable · SVG
FinCEN found that stolen business checks meet three main fates: 44 percent are altered by check washing and redeposited, 26 percent are used as templates to print counterfeit checks, and 20 percent are signed with a forged endorsement and deposited. Positive Pay and Payee Positive Pay catch these because they are checks you did not authorize. The one they cannot catch is a real check you were deceived into issuing to a switched payee.
      FAQ
## Frequently asked questions

Every question buyers ask before they trust a payment-security platform, answered directly.
           JAMIE KLONCZ · RANKSHIELD FINANCIAL           ONLINE
Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.
      REQUEST ACCESS →           Self-check
## How exposed are your payments?

Five controls decide whether an authorized-payment scam gets through on a fast rail. Answer them honestly to see where you stand.

- 01 Do you send payments on instant or same-day rails (RTP, FedNow, same-day ACH)?
- 02 Can one person both change a vendor’s bank details and approve the payment?
- 03 Do you always confirm a bank-detail change on a number from your own files, not the request?
- 04 Is the first payment to a new or changed payee held for verification before it goes out?
- 05 Do you keep a signed record of exactly who approved each payment?

Answer all five to see where you stand · 0/5
        References
- [FinCEN, Financial Trend Analysis: Mail Theft-Related Check Fraud (15,000+ SARs, $688M+ flagged in a six-month 2023 window; alteration 44%, counterfeit 26%, forged 20%)](https://www.fincen.gov/sites/default/files/shared/FTA-Check-Fraud-FINAL508.pdf)
- [FinCEN, In-Depth Analysis of Check Fraud Related to Mail Theft (check-fraud SARs up 23% in 2021, nearly doubled to ~680,000 in 2022)](https://www.fincen.gov/news/news-releases/fincen-issues-depth-analysis-check-fraud-related-mail-theft)
- [Association for Financial Professionals, 2026 AFP Payments Fraud and Control Survey (checks most-targeted method at 58%; ACH debits 30%; wire 25%)](https://www.financialprofessionals.org/training-resources/resources/survey-research-economic-data/details/payments-fraud)
- [FBI IC3, 2025 Internet Crime Report (business email compromise $3.046B; 86% of BEC money moved by wire or ACH)](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf)

         About the author
## [Jamie Kloncz](https://rankshieldfinancial.com/about/) Founder, RankShield Financial

Jamie founded RankShield Financial to verify a payment’s intent and authority before it settles on instant and tokenized rails. These guides are written from building that product and reading the primary sources directly: every statistic here links to its original filing or report, never a secondhand summary.

- Primary sources only: each figure links to the original filing
- Honest boundaries: what verification can and cannot do is stated plainly
- Last verified August 18, 2026

  How RankShield Financial verifies →  Request access →            Verify, then settle
## See your payments verified before they settle.

RankShield Financial is rolling out with design partners on instant and tokenized rails. Request access and we’ll map it to your settlement flow.
  Request access  How it works

## Frequently asked questions

### Why is check fraud increasing if businesses write fewer checks?

Because the checks still being written are the valuable ones, and criminals have industrialized stealing them, mainly through mail theft. A business check carries a real account and routing number, a large and often predictable amount, and a physical journey through the mail, which no electronic payment offers a thief. The 2026 AFP survey found checks were the most-targeted payment method at 58 percent, and FinCEN reported that check-fraud suspicious activity reports nearly doubled to about 680,000 in 2022, with banks flagging more than $688 million in mail-theft-related check fraud in just six months of 2023. So the shrinking pool of checks is under more concentrated attack, not less, which makes leaving check controls off the riskiest choice for a business that still writes them.

### What is check washing and how do you stop it?

Check washing is when a thief uses chemicals to remove the ink from a stolen check so the payee and amount can be rewritten, while the genuine signature stays intact. FinCEN found alteration, mostly washing, was the outcome in 44 percent of mail-theft check-fraud cases. It is hard to catch by eye because the paper, account, and signature are all authentic, and only the payee and amount changed. The control that stops it is Payee Positive Pay: because your bank matches the payee name on the presented check against the file of checks you issued, a washed check with an altered payee fails the match and is flagged before it clears. Standard Positive Pay, which matches only check number and amount, will not catch washing on its own, which is why the payee-name tier matters.

### Does Positive Pay stop all check fraud?

No, and understanding the gap is important. Positive Pay and Payee Positive Pay are highly effective against the checks you did not authorize: counterfeits, altered or washed checks, and forged items all fail the match against your issued-check file. What they cannot catch is a check you did authorize, for the correct amount, that you were deceived into issuing to a fraudulently-changed payee, for example through vendor impersonation. That check matches your file exactly, because you issued it, so Positive Pay clears it. That is the same blind spot vendor-impersonation and business email compromise exploit on electronic rails. A business needs both defenses: Positive Pay for unauthorized checks, and payee verification for the authorized payments it was tricked into sending.

### Should a business stop using paper checks entirely?

Moving high-value and recurring payments off checks is the single most effective structural defense against the schemes in this guide, because it removes the physical document that gets stolen, washed, or copied, and eliminates the mail-theft attack surface. But it does not eliminate payment fraud; it relocates it. The same criminals run vendor-impersonation and business email compromise against ACH and wire, which the FBI put at $3.046 billion in 2025 with 86 percent moving by wire or ACH. So the honest advice is to move off checks and verify the payee and approval on the electronic payments you move to, so you do not solve check fraud by opening the door to BEC. Migration plus verification, not migration alone, is the durable answer.

### What are the fastest check fraud controls to put in place?

Start with your bank: turn on Positive Pay and Payee Positive Pay so presented checks are matched to the checks you issued, including the payee name, and add ACH debit blocks or filters so the same account cannot be drained electronically. Then fix the operational gaps: stop mailing checks from unsecured outgoing mailboxes, use a post office or secure lockbox, enforce dual control on check issuance, and reconcile accounts daily so a fraudulent item is caught inside the short return window rather than at month-end. These are controls your own bank will help you enable, and they address the FinCEN check-fraud data directly. The remaining gap, an authorized payment to a switched payee, is closed by verifying the payee and approval before payment, which is a separate and complementary control.
