The 2026 Treasury Management Fraud Landscape: What Your Business Clients Are Facing Right Now

Digitization

Business meeting in well-lit coffee shop

Why Fraud Conversations Need to Start with the Landscape

If you are a treasury management officer or relationship manager preparing for a fraud review with a business client, the first question you need to answer is "What threats is this specific client actually facing right now?"

Fraud is not static. The tactics and targets are constantly evolving. What worked to protect clients two years ago may be irrelevant today, and what clients assume is protecting them may be leaving gaps they don’t realize exist.

This week, we’re diving into what the treasury management fraud landscape looks like in 2026, from the threats your business clients are encountering to the specific vulnerabilities that fraudsters are exploiting. We’re giving you the confidence to walk into your next fraud review meeting and speak credibly about what is happening in the market and why the controls you are recommending matter right now.


The Four Dominant Fraud Threats in 2026

Threat #1: Business Email Compromise (BEC)

Business Email Compromise occurs when a fraudster gains access to or impersonates a trusted email account, typically that of a bank executive or business partner, and uses that access to fraudulently request or redirect payments.

BEC attacks succeed because they exploit trust and urgency. The email looks legitimate and the employee processing the payment does not have a verification process that would catch the fraud before money moves.

BEC trends in 2026:

·        Fraudsters are increasingly using AI-generated voice cloning in combination with email to add a layer of verification that feels authentic but is completely fabricated

·        Attacks target mid-level employees (e.g., accounts payable clerks, office managers, etc.) who have payment authority but may not have the same level of fraud awareness training as executives

·        The average loss per successful BEC attack against businesses under $1 billion in revenue is over $125,000

Most vulnerable industries: Professional services (e.g., legal or consulting services), real estate, healthcare, construction, and any business that regularly processes wire transfers or large ACH payments to vendors.

Best defenses: Put in place wire callback verifications to a pre-verified phone numbers (not a number from the email) and dual approvals for high-value payments. Also employ regular employee training sessions on how to recognize social engineering tactics.


Threat #2: ACH Debit Fraud

ACH debit fraud occurs when an unauthorized party initiates an ACH debit against a business's account, either by using stolen account information or by exploiting the lack of controls that would block unauthorized companies from debiting the account.

ACH volume continues to grow — according to NACHA, B2B ACH transactions increased nearly 10% in 2025 — and many businesses still don’t have ACH debit filters enabled, which means any company with their account number and routing number can attempt a debit.

ACH fraud trends in 2026:

·        Fraudsters are targeting businesses with high account balances visible through public filings or vendor databases

·        ACH debit fraud is often discovered days after the transaction posts, which reduces recovery rates significantly

·        Businesses that have recently experienced a data breach or had vendor credentials compromised are disproportionately targeted in the 90 days following the breach

Most vulnerable industries: Property management companies (frequent ACH activity with multiple vendors), healthcare practices (high balances, multiple vendor relationships), and any business that publicly lists their bank account information for payment acceptance.

Best defenses: ACH debit filters or blocks that pre-approve which companies are authorized to debit the account. This control alone prevents the vast majority of unauthorized ACH debits from ever clearing.

 

Threat #3: Check Fraud (Altered and Counterfeit Checks)

Check fraud encompasses both altered checks (legitimate checks that are intercepted and modified to change the payee or amount) and counterfeit checks (entirely fabricated checks using stolen account information).

While check volume has declined over the past decade, the dollar value of check fraud has increased. Fraudsters know that fewer checks mean fewer controls, and they are writing larger fraudulent checks to maximize the return on each attempt.

Current trends in 2026:

·        Mail theft targeting business checks is increasing, particularly in areas with centralized mailbox clusters or poorly secured drop boxes

·        Fraudsters are using publicly available business account information (from voided checks on vendor portals or payment remittance stubs) to create convincing counterfeit checks

·        Check washing (chemically altering checks to change payee and amount information) remains a low-tech but highly effective tactic

Most vulnerable industries: Businesses that still issue high-value checks regularly — such as real estate firms, legal practices, and construction or property management companies—and businesses in geographic areas with known mail theft patterns.

Best defenses: Use positive pay, which matches every check presented for payment against a file the business issues. Any check that does not match can be flagged and returned before it clears. Positive pay catches both altered and counterfeit checks before they become losses.


Threat #4: Credential-Based Attacks and Account Takeover

Credential-based attacks occur when fraudsters obtain legitimate login credentials via a variety of malware and phishing tactics and use those credentials to initiate unauthorized transactions through the business's treasury management platform.

When a fraudster uses legitimate credentials, the transaction looks like normal activity from the bank's perspective. Nothing about the login appears suspicious, down to the user and the device.

Current trends in 2026:

·        Phishing campaigns targeting employees with treasury management access have become more sophisticated, using any number of traditionally trusted bank messages to harvest credentials

·        Employees working remotely or using personal devices for business transactions are disproportionately targeted because their security posture is often weaker than on corporate networks

·        Multi-factor authentication (MFA) is becoming a standard control, but many businesses are still not using it. When they are, fraudsters are increasingly using MFA fatigue attacks (repeatedly triggering MFA prompts until the user approves one out of frustration)

Most vulnerable industries: Any business with multiple employees accessing treasury management platforms remotely, particularly during periods of high employee turnover when access management may be less rigorous.

Best defenses: Multi-factor authentication, regular user access reviews to remove stale entitlements, employee training on recognizing phishing attempts, and monitoring for unusual login patterns.


Fraud by Industry: Who Is Being Targeted Most Aggressively

Not all businesses face the same fraud risk profile. Certain industries are targeted more aggressively because of their high rates of transactions or publicly available financial information.

Property Management

Why they are targeted: High transaction volumes, multiple vendor relationships, frequent ACH and check activity, and publicly available property ownership and bank account information.

Primary threats: ACH debit fraud, check fraud (both altered and counterfeit), and BEC targeting vendor payment instructions.

Necessary controls: ACH filters, positive pay, dual approval for high-value payments, and vendor payment verification procedures.


Healthcare Practices

Why they are targeted: Large account balances, frequent insurance reimbursements, multiple staff with payment access, and reliance on legacy payment methods (checks and ACH).

Primary threats: Check and ACH debit fraud, as well as credential-based attacks targeting staff with treasury management access.

Necessary controls: Positive pay, ACH filters, user access reviews (particularly after staff turnover), and MFA for all treasury management platform users.

 

Professional Services (e.g., Legal, Accounting, Consulting, etc.)

Reason for targeting: Client trust accounts, high-value wire transfers, and reliance on email for client and vendor communication.

Primary threats: BEC (especially targeting client fund transfers or vendor payments) and wire and check fraud.

Necessary controls: Wire callback verification, dual approval for wires, positive pay, and regular training on email-based social engineering tactics.

 

Real Estate Firms and Title Companies

Reason for targeting: Large wire transfers associated with closings, high public visibility of transaction activity, time-sensitive payment deadlines, and competition for clients all create a sense of urgency that fraudsters exploit.

Primary threats: BEC targeting closing wire instructions and wire and check fraud (earnest money and commission checks).

Critical controls: Wire callback verification for all closing wire instructions, dual approval, positive pay, and documented procedures for verifying wire instruction changes.

 

Construction and Contractors

Why they are targeted: High-value payments to subcontractors and vendors, frequent check and ACH usage, as well as lean back-office operations that typically lack strong controls.

Primary threats: Check fraud, ACH debit fraud, and BEC targeting vendor payment redirects.

Critical controls: Positive pay, ACH filters, dual approval for payments above a defined threshold, and vendor payment verification procedures.

 

Which Controls Most Businesses Are Missing

When you conduct a fraud review with a business client, you will typically find three categories of controls gaps:

Gap #1: No Preventive Controls on Payment Channels

The business uses ACH and checks regularly but does not have ACH filters or positive pay enabled. They assume the bank is monitoring for fraud, or they believe their internal approval processes are sufficient protection.

Preventive controls like ACH filters and positive pay stop fraud before money moves. Without these controls, the business is relying entirely on detection after the fact, which is far less effective and often results in permanent losses.

Industry data suggests that fewer than 40% of small and mid-sized businesses have ACH filters enabled, and positive pay adoption is only slightly higher, which makes your ideal commercial clients ideal marks for fraud attacks.

 

Gap #2: Inconsistent or Absent Approval Workflows

The business has dual approval enabled for some payment types but not others, or approval thresholds are set so high that the majority of payments bypass the control entirely.

Dual approval is one of the most direct defenses against both external fraud (e.g., BEC and vendor impersonation) and internal errors. If your approval workflows are inconsistent or inaccurate, they will provide a false sense of security without actually protecting your transactions.

Most businesses have some form of approval process, but very few have documented, consistently enforced approval policies that match their actual transaction patterns.


Gap #3: Stale User Entitlements

Employees who have left the company or changed roles still have active access to initiate or approve treasury management transactions. The business does not conduct regular user access reviews, so entitlements accumulate over time.

Stale entitlements create two risks: the risk that a former employee with legitimate credentials initiates unauthorized transactions, and the risk that a fraudster obtains those credentials and uses them without the business realizing the account should have been deactivated.

Research from Verizon shows that 10 to 15 percent of entitlements at businesses not conducting regular reviews are stale. For businesses with high employee turnover, that percentage is even higher.

 

How to Use This Landscape in Your Next Client Conversation

The fraud landscape matters most when you bring it into a specific client conversation. The following outline will help you accomplish this effectively:

Step #1: Tailor the Threat Profile to the Client's Industry

Before the meeting, identify which of the four dominant threats are most relevant to the client's industry and transaction patterns. Don’t present all four; focus on the two or three that matter most to this specific client.

Example for a property management company:

"The two fraud threats we are seeing most frequently in property management right now are ACH debit fraud and check fraud. ACH debit fraud happens when an unauthorized company initiates a debit against your account , and without ACH filters in place, there is no control stopping that transaction before it clears.

 Check fraud is increasing because fraudsters know property management firms like yours issue high-value checks regularly. Let's walk through your current setup and make sure you have controls in place for both."

 

Step #2: Use Current Data to Add Credibility

Reference current fraud statistics and trends from 2025–2026 to establish that the threats you are discussing are relevant right now.

Example:

"BEC attacks are still the most costly fraud type affecting businesses your size. The average loss per successful attack in 2025 was over $125,000. And we are seeing attackers get more sophisticated, using AI-generated voice cloning to add a layer of fake verification. Your best option for a control that will stop most, if not all, these attacks is wire callback verification to a phone number you verified in advance."

 

Step #3: Frame Controls as Aligned with Their Specific Risk Profile

Don’t position fraud controls as generic best practices. Position them as directly responsive to the threats the client is most likely to face based on industry data and their current control gaps.

Example for a healthcare practice:

"Given that you process a high volume of checks and ACH transactions, and you maintain significant balances in your operating account, the two controls I would prioritize are positive pay for your checks and ACH filters for your account.

Both of these prevent unauthorized transactions from clearing before they become losses,  which is far more effective than trying to recover funds after fraud has already occurred."

 

Knowledge of the Landscape Gives You Positioning Power

If you start a fraud review with "You should have these controls because everyone should," you’ll lose momentum before you ever have it. Starting with "Here is what we are seeing in your industry right now and here are the specific controls that address those threats" will position you as a competent, knowledgeable partner who understands the client's actual risk environment.

That positioning builds trust and makes your clients far more likely to act on your advice.


Ready to be an invaluable fraud resource for your clients? Contact us today for a no-obligation conversation about equipping your TM team with the insights to offer industry-relevant solutions every time.

Related Reads for You

Discover more articles that align with your interests and keep exploring.