Check fraud is the payment crime that refuses to fade, and 2026 is the year the numbers make that undeniable. Even as businesses write fewer paper checks every year, the check remains the single most-targeted payment method: the 2026 AFP Payments Fraud and Control Survey found checks were hit in 58 percent of organizations that faced payments fraud, more than any other method3. The engine behind the surge is mail theft: FinCEN reported that banks filed more than 15,000 suspicious activity reports flagging over $688 million in mail-theft-related check fraud in just six months of 20231, after check-fraud reports nearly doubled to roughly 680,000 in 2022. This guide explains why check fraud rises as check volume falls, how the schemes actually work once a check is stolen, the controls that stop most of them, and the one kind of check fraud that no check control catches, which is where verifying the payee before a payment settles comes in.
Why check fraud rises as check use falls
It looks like a paradox: Americans and American businesses write fewer checks every year, yet check fraud keeps climbing. The explanation is that the checks still being written are exactly the valuable ones, and criminals have industrialized the theft of them. The 2026 AFP survey put checks at the top of the target list, hit in 58 percent of organizations that experienced payments fraud, ahead of ACH debits at 30 percent and wire transfers at 25 percent3. A business check carries a real bank account and routing number, a large and often predictable amount, and a physical journey through the mail, which is a combination no electronic payment offers a thief.
The accelerant since 2020 has been mail theft. FinCEN reported that check-fraud suspicious activity reports rose 23 percent in 2021 and nearly doubled in 2022, to about 680,0002, and it traced much of the increase to checks stolen from residential mailboxes, collection boxes, and mail carriers. In a six-month window of 2023, financial institutions filed more than 15,000 SARs flagging over $688 million in mail-theft-related check fraud, in every US state. So the honest framing is not that checks are becoming safe as they become rare; it is that the shrinking pool of checks is under more concentrated attack than ever, which makes doing nothing the riskiest option for a business that still writes them.
How the schemes work once a check is stolen
FinCEN’s analysis of the SAR data gives an unusually clear picture of what happens to a stolen business check, and the three main outcomes each call for a different defense. In 44 percent of cases the check was altered and deposited1, most often through check washing, where a chemical bath removes the ink so the payee and amount can be rewritten while the genuine signature remains. In 26 percent, the stolen check was used as a template to print counterfeit checks drawn on the victim’s account. In 20 percent, the check was simply signed with a forged endorsement and deposited or cashed. The remaining cases mix these methods or use the account details for other fraud.
The common thread is that the victim’s real account is the target, reached through a physical document that was never meant to be public. Check washing defeats the eye because the paper, the account, and the signature are all authentic; only the payee and amount changed. Counterfeits defeat casual review because they carry correct account and routing numbers. Forged endorsements exploit deposit channels that do not verify the payee. Understanding which scheme you are defending against matters, because the controls that stop them are not interchangeable: the control that catches a counterfeit is not the same one that catches a washed check, and a business needs the layer that covers all three.
The controls that genuinely stop most check fraud
The good news is that the workhorse controls are effective and widely available, and this guide will not pretend a business is helpless. Positive Pay is the foundation: you send your bank a file of the checks you issued, with check numbers and amounts, and the bank pays only matching items, flagging everything else for your review. It catches counterfeits and unauthorized checks because they are not on your issued list. Payee Positive Pay adds the payee name to the match, which is what catches check washing, since a washed check has an altered payee that no longer matches your file. Reverse Positive Pay is a lighter version where you review presented items yourself. For the ACH side that check fraud often spills into, ACH debit blocks and filters stop unauthorized electronic debits against your account.
Around those bank controls sit the operational habits that close the gaps: mailing checks from inside a post office rather than an outgoing mailbox, using secure lockbox services for high-volume disbursements, reconciling accounts daily rather than monthly so a fraudulent item is caught inside the return window, and enforcing dual controls on check issuance. None of this is exotic, and most of it a business’s own bank will help set up. The reason check fraud still succeeds at scale is not that these controls do not work; it is that many businesses have not turned them all on, or reconcile too slowly to act inside the short window a returned item allows. The ACH return-window guide explains just how short that window really is.
The one check fraud no check control catches
Here is the honest limit of every control above, and it is the reason this topic connects to the rest of the site. Positive Pay, Payee Positive Pay, and the operational habits all answer one question: is this presented check one that you actually authorized. They are built to catch a check you did not issue, or one that was altered after you issued it. What none of them can catch is a check you did issue, for the right amount, that you were deceived into sending to the wrong party. If a fraudster impersonates a vendor and convinces your team to cut a legitimate check to a new address or a new account, Positive Pay clears it without a second look, because from the bank’s side nothing is wrong: the check matches your issued file exactly, since you issued it.
This is the same blind spot that vendor-impersonation and business email compromise exploit on electronic rails, and it is documented in depth in the guide on what Positive Pay cannot catch. The distinction is between an unauthorized payment, which check controls are designed to stop, and an authorized payment to a fraudulently-changed payee, which they are structurally blind to because the deception happened before the check was ever written. Recognizing that a business needs both kinds of defense, one for the checks it did not authorize and one for the payees it was tricked into paying, is the whole point, because closing only the first gap leaves the second wide open.
The strongest move: get off checks, but onto verified rails
Ask a bank or a fraud examiner how to cut check fraud to near zero and the honest answer is the same: write fewer checks. Electronic payments remove the physical document a thief steals, washes, or copies, which eliminates the entire mail-theft attack surface at once. For high-value and recurring disbursements especially, moving from checks to ACH or wire is the single most effective structural change a business can make against the schemes in this guide. That is real, and this page will not undersell it: the paper check is the vulnerability, and removing it removes the vulnerability.
The catch, and it is a serious one, is that migrating off checks does not eliminate payment fraud; it relocates it. The same criminals who wash checks run vendor-impersonation and business email compromise against ACH and wire payments, which is why the FBI put business email compromise at $3.046 billion in 2025, with 86 percent of the money moving by wire or ACH4. Trade a check for an unverified electronic payment and you have swapped check washing for the payee swap. So the honest version of the advice is: move off checks, and verify the payee and the approval on the electronic payments you move to, so you are not solving one fraud by opening another.
Where RankShield Financial fits, and where it does not
The honest framing matters most on this topic, because RankShield Financial is not a check-fraud product and this guide will not pretend otherwise. It does not inspect physical checks, it does not read your mail, and it does not replace Positive Pay or Payee Positive Pay, which remain the right controls for the checks you still write. If your problem is washed checks and counterfeits, your bank’s Positive Pay is the answer, and you should turn on every tier of it. RankShield operates on the electronic side of the picture, in the payment authorization path, and it never takes custody of funds.
What RankShield does is address the two places check controls run out. First, the authorized-payee-switch gap: it verifies that a payment is going to the payee you actually intended and that a named person approved it, which is the exact fraud Positive Pay clears because the payment is authorized. Second, the migration: when you move high-value payments off checks onto ACH or wire, RankShield verifies those electronic payments before they settle, so the shift does not trade check fraud for BEC. The boundaries stay explicit: it verifies the payee and the approval and seals a checkable record, it does not catch every scam, and it is a design-partner-stage product that claims no network it has not built. If you want that verification in front of the payments you are moving off checks, you can see how it works or request access.
What to do this quarter
If check fraud is on your list, the practical sequence is short. Turn on Positive Pay and Payee Positive Pay with your bank if you have not, because payee-name matching is what catches the washing that drives most of the losses. Add ACH debit blocks or filters so the same account cannot be drained electronically. Stop mailing checks from unsecured outgoing mailboxes, and reconcile accounts daily so a fraudulent item is caught inside the return window rather than at month-end when it is too late. Then start moving your highest-value and most-repetitive disbursements off checks entirely. Each of these is a control your own bank can help you enable, and together they address the check fraud in the FinCEN data directly.
The one thing that sequence does not cover is the authorized payment to a switched payee, on either a check or the electronic rails you migrate to, and that is the gap worth closing deliberately rather than discovering after a loss. Check fraud is rising because the checks that remain are valuable and exposed, but the deeper lesson in the 2026 data is that fraud follows the money onto whatever rail it travels. A defense that verifies the payee and the approval before the payment settles is the one that keeps working as you change how you pay, which is exactly why it belongs alongside the check controls rather than instead of them.
