Request access
RankShield Network · Financial · Payment Fraud

Check Fraud in 2026: Why It Is Rising, How the Schemes Work, and What Stops It

Businesses write fewer checks every year, yet check fraud keeps climbing, driven by mail theft and check washing. Here is how the schemes actually work, the controls that stop most of them, and the one gap that no check control can close.

A brushed-steel secure deposit slot on a dark console accepting a paper payment, a teal verification light beside it, representing a business check being secured and verified.
Key takeaways
  • Check fraud is rising even as check use declines. The AFP 2026 survey found checks the most-targeted payment method at 58 percent, and FinCEN tied a surge to mail theft, with banks flagging over $688 million in mail-theft-related check fraud in six months of 2023 alone.
  • Once a check is stolen from the mail, FinCEN found three main outcomes: 44 percent are altered (check washing) and redeposited, 26 percent are used as templates to print counterfeit checks, and 20 percent are fraudulently signed and deposited.
  • The workhorse controls genuinely work against these. Positive Pay matches presented checks to a file you issued; Payee Positive Pay adds payee-name matching to catch washing; ACH debit blocks and filters, secure mail handling, and daily reconciliation close the rest.
  • There is one check fraud no check control catches: a real, correctly-drawn check you were deceived into issuing to a fraudulently-changed payee. Positive Pay clears it because you authorized it, which is the same blind spot that vendor-impersonation and BEC exploit.
  • The strongest structural move is to shift high-value payments off checks, but onto verified electronic rails, or you simply trade check fraud for wire and ACH fraud. Verifying the payee and approval before settlement is what makes that migration safe, and it is what RankShield Financial does.

Check fraud is the payment crime that refuses to fade, and 2026 is the year the numbers make that undeniable. Even as businesses write fewer paper checks every year, the check remains the single most-targeted payment method: the 2026 AFP Payments Fraud and Control Survey found checks were hit in 58 percent of organizations that faced payments fraud, more than any other method3. The engine behind the surge is mail theft: FinCEN reported that banks filed more than 15,000 suspicious activity reports flagging over $688 million in mail-theft-related check fraud in just six months of 20231, after check-fraud reports nearly doubled to roughly 680,000 in 2022. This guide explains why check fraud rises as check volume falls, how the schemes actually work once a check is stolen, the controls that stop most of them, and the one kind of check fraud that no check control catches, which is where verifying the payee before a payment settles comes in.

Why check fraud rises as check use falls

It looks like a paradox: Americans and American businesses write fewer checks every year, yet check fraud keeps climbing. The explanation is that the checks still being written are exactly the valuable ones, and criminals have industrialized the theft of them. The 2026 AFP survey put checks at the top of the target list, hit in 58 percent of organizations that experienced payments fraud, ahead of ACH debits at 30 percent and wire transfers at 25 percent3. A business check carries a real bank account and routing number, a large and often predictable amount, and a physical journey through the mail, which is a combination no electronic payment offers a thief.

The accelerant since 2020 has been mail theft. FinCEN reported that check-fraud suspicious activity reports rose 23 percent in 2021 and nearly doubled in 2022, to about 680,0002, and it traced much of the increase to checks stolen from residential mailboxes, collection boxes, and mail carriers. In a six-month window of 2023, financial institutions filed more than 15,000 SARs flagging over $688 million in mail-theft-related check fraud, in every US state. So the honest framing is not that checks are becoming safe as they become rare; it is that the shrinking pool of checks is under more concentrated attack than ever, which makes doing nothing the riskiest option for a business that still writes them.

How the schemes work once a check is stolen

FinCEN’s analysis of the SAR data gives an unusually clear picture of what happens to a stolen business check, and the three main outcomes each call for a different defense. In 44 percent of cases the check was altered and deposited1, most often through check washing, where a chemical bath removes the ink so the payee and amount can be rewritten while the genuine signature remains. In 26 percent, the stolen check was used as a template to print counterfeit checks drawn on the victim’s account. In 20 percent, the check was simply signed with a forged endorsement and deposited or cashed. The remaining cases mix these methods or use the account details for other fraud.

The common thread is that the victim’s real account is the target, reached through a physical document that was never meant to be public. Check washing defeats the eye because the paper, the account, and the signature are all authentic; only the payee and amount changed. Counterfeits defeat casual review because they carry correct account and routing numbers. Forged endorsements exploit deposit channels that do not verify the payee. Understanding which scheme you are defending against matters, because the controls that stop them are not interchangeable: the control that catches a counterfeit is not the same one that catches a washed check, and a business needs the layer that covers all three.

The controls that genuinely stop most check fraud

The good news is that the workhorse controls are effective and widely available, and this guide will not pretend a business is helpless. Positive Pay is the foundation: you send your bank a file of the checks you issued, with check numbers and amounts, and the bank pays only matching items, flagging everything else for your review. It catches counterfeits and unauthorized checks because they are not on your issued list. Payee Positive Pay adds the payee name to the match, which is what catches check washing, since a washed check has an altered payee that no longer matches your file. Reverse Positive Pay is a lighter version where you review presented items yourself. For the ACH side that check fraud often spills into, ACH debit blocks and filters stop unauthorized electronic debits against your account.

Around those bank controls sit the operational habits that close the gaps: mailing checks from inside a post office rather than an outgoing mailbox, using secure lockbox services for high-volume disbursements, reconciling accounts daily rather than monthly so a fraudulent item is caught inside the return window, and enforcing dual controls on check issuance. None of this is exotic, and most of it a business’s own bank will help set up. The reason check fraud still succeeds at scale is not that these controls do not work; it is that many businesses have not turned them all on, or reconcile too slowly to act inside the short window a returned item allows. The ACH return-window guide explains just how short that window really is.

The one check fraud no check control catches

Here is the honest limit of every control above, and it is the reason this topic connects to the rest of the site. Positive Pay, Payee Positive Pay, and the operational habits all answer one question: is this presented check one that you actually authorized. They are built to catch a check you did not issue, or one that was altered after you issued it. What none of them can catch is a check you did issue, for the right amount, that you were deceived into sending to the wrong party. If a fraudster impersonates a vendor and convinces your team to cut a legitimate check to a new address or a new account, Positive Pay clears it without a second look, because from the bank’s side nothing is wrong: the check matches your issued file exactly, since you issued it.

This is the same blind spot that vendor-impersonation and business email compromise exploit on electronic rails, and it is documented in depth in the guide on what Positive Pay cannot catch. The distinction is between an unauthorized payment, which check controls are designed to stop, and an authorized payment to a fraudulently-changed payee, which they are structurally blind to because the deception happened before the check was ever written. Recognizing that a business needs both kinds of defense, one for the checks it did not authorize and one for the payees it was tricked into paying, is the whole point, because closing only the first gap leaves the second wide open.

The strongest move: get off checks, but onto verified rails

Ask a bank or a fraud examiner how to cut check fraud to near zero and the honest answer is the same: write fewer checks. Electronic payments remove the physical document a thief steals, washes, or copies, which eliminates the entire mail-theft attack surface at once. For high-value and recurring disbursements especially, moving from checks to ACH or wire is the single most effective structural change a business can make against the schemes in this guide. That is real, and this page will not undersell it: the paper check is the vulnerability, and removing it removes the vulnerability.

The catch, and it is a serious one, is that migrating off checks does not eliminate payment fraud; it relocates it. The same criminals who wash checks run vendor-impersonation and business email compromise against ACH and wire payments, which is why the FBI put business email compromise at $3.046 billion in 2025, with 86 percent of the money moving by wire or ACH4. Trade a check for an unverified electronic payment and you have swapped check washing for the payee swap. So the honest version of the advice is: move off checks, and verify the payee and the approval on the electronic payments you move to, so you are not solving one fraud by opening another.

Where RankShield Financial fits, and where it does not

The honest framing matters most on this topic, because RankShield Financial is not a check-fraud product and this guide will not pretend otherwise. It does not inspect physical checks, it does not read your mail, and it does not replace Positive Pay or Payee Positive Pay, which remain the right controls for the checks you still write. If your problem is washed checks and counterfeits, your bank’s Positive Pay is the answer, and you should turn on every tier of it. RankShield operates on the electronic side of the picture, in the payment authorization path, and it never takes custody of funds.

What RankShield does is address the two places check controls run out. First, the authorized-payee-switch gap: it verifies that a payment is going to the payee you actually intended and that a named person approved it, which is the exact fraud Positive Pay clears because the payment is authorized. Second, the migration: when you move high-value payments off checks onto ACH or wire, RankShield verifies those electronic payments before they settle, so the shift does not trade check fraud for BEC. The boundaries stay explicit: it verifies the payee and the approval and seals a checkable record, it does not catch every scam, and it is a design-partner-stage product that claims no network it has not built. If you want that verification in front of the payments you are moving off checks, you can see how it works or request access.

What to do this quarter

If check fraud is on your list, the practical sequence is short. Turn on Positive Pay and Payee Positive Pay with your bank if you have not, because payee-name matching is what catches the washing that drives most of the losses. Add ACH debit blocks or filters so the same account cannot be drained electronically. Stop mailing checks from unsecured outgoing mailboxes, and reconcile accounts daily so a fraudulent item is caught inside the return window rather than at month-end when it is too late. Then start moving your highest-value and most-repetitive disbursements off checks entirely. Each of these is a control your own bank can help you enable, and together they address the check fraud in the FinCEN data directly.

The one thing that sequence does not cover is the authorized payment to a switched payee, on either a check or the electronic rails you migrate to, and that is the gap worth closing deliberately rather than discovering after a loss. Check fraud is rising because the checks that remain are valuable and exposed, but the deeper lesson in the 2026 data is that fraud follows the money onto whatever rail it travels. A defense that verifies the payee and the approval before the payment settles is the one that keeps working as you change how you pay, which is exactly why it belongs alongside the check controls rather than instead of them.

Operate it

Verify a payment before it settles

Compose a payment and the conditions around it, then run the same check the product runs on a live rail. The verdict comes back before the money would move.

Conditions around this payment
PRE-SETTLEMENT VERDICTRANKSHIELD NETWORK

Compose a payment on the left and run the check. The verdict is returned before the money moves, the way the product returns it on a live rail.

Sandbox demo · reproduces the product’s verdict logic and signing metadata · not a live network call

Downloadable · SVG
RANKSHIELD FINANCIAL // CHECK FRAUD, BY THE NUMBERS After a business check is stolen from the mail 44% Altered and redeposited Check washing: ink removed, payee and amount rewritten, real signature kept. Caught by Payee Positive Pay (payee-name match) 26% Used as a counterfeit template Stolen check copied to print new checks drawn on your account. Caught by Positive Pay (not on your issued file) 20% Forged signature, deposited Stolen check signed with a forged endorsement and cashed. Caught by Positive Pay and deposit verification The one check fraud no check control catches: a real check you were tricked into issuing to a switchedpayee. Positive Pay clears it, because you authorized it. Verify the payee before the payment settles. rankshieldfinancial.com FINCEN, MAIL-THEFT CHECK FRAUD

FinCEN found that stolen business checks meet three main fates: 44 percent are altered by check washing and redeposited, 26 percent are used as templates to print counterfeit checks, and 20 percent are signed with a forged endorsement and deposited. Positive Pay and Payee Positive Pay catch these because they are checks you did not authorize. The one they cannot catch is a real check you were deceived into issuing to a switched payee.

FAQ

Frequently asked questions

Every question buyers ask before they trust a payment-security platform, answered directly.

JAMIE KLONCZ · RANKSHIELD FINANCIAL ONLINE

Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.

REQUEST ACCESS →
Self-check

How exposed are your payments?

Five controls decide whether an authorized-payment scam gets through on a fast rail. Answer them honestly to see where you stand.

  1. 01Do you send payments on instant or same-day rails (RTP, FedNow, same-day ACH)?
  2. 02Can one person both change a vendor’s bank details and approve the payment?
  3. 03Do you always confirm a bank-detail change on a number from your own files, not the request?
  4. 04Is the first payment to a new or changed payee held for verification before it goes out?
  5. 05Do you keep a signed record of exactly who approved each payment?

Answer all five to see where you stand · 0/5

Jamie Kloncz
About the author

Jamie KlonczFounder, RankShield Financial

Jamie founded RankShield Financial to verify a payment’s intent and authority before it settles on instant and tokenized rails. These guides are written from building that product and reading the primary sources directly: every statistic here links to its original filing or report, never a secondhand summary.

  • Primary sources only: each figure links to the original filing
  • Honest boundaries: what verification can and cannot do is stated plainly
  • Last verified August 18, 2026
Verify, then settle

See your payments verified before they settle.

RankShield Financial is rolling out with design partners on instant and tokenized rails. Request access and we’ll map it to your settlement flow.

Request accessHow it works