Why Stolen Checks are Fueling FedNow Scams
Why Stolen Checks are Fueling FedNow Scams
Check fraud is 30x more common than instant payment fraud.
The gap between check fraud rates and instant payment fraud rates is wider than most FIs realize. It also tells you less than it looks like it does.
Stolen check images sold on Telegram channels become the account and routing data used to set up mule accounts. Those mule accounts become the destinations for authorized push payment scams over RTP and FedNow. Each rail moves the money. The fraud follows the data.
Three Things to Track Right Now
- Real-time fraud rates look low because real-time volume is still small
63% of firms experienced check fraud in 2025. 2% reported fraud on real-time rails. The gap is significant, and the trade press has been running with it.
The catch: RTP and FedNow are still early in adoption. As volume climbs, fraud volume tends to follow. The 30x ratio reflects today’s exposure, not the trajectory.
Takeaway: Track your check fraud loss rate as a leading indicator for instant payment exposure. The fraud capability is portable. The rail is incidental.
- Stolen check data does not stop at checks
Visa told PYMNTS in April 2026 that check fraud is spilling into faster-payment scams at a rate it had not seen before. The route is short. A check is stolen from the mail, photographed, and listed on a Telegram marketplace within days. A buyer uses the account and routing data to set up authorized push payment scams targeting the legitimate account holder, or to fund mule accounts that receive scam payments from someone else.
The same compromised data set can run for weeks across multiple rails before the original FI flags it.
Takeaway: If you only score check transactions, you only catch part of the fraud lifecycle. Cross-rail signals catch the second use of the same stolen account.
- ACH fraud is growing five times faster than ACH volume
NICE Actimize’s 2026 Fraud Insights Report found ACH fraud growing at roughly 5x the rate of overall payment growth. The average ACH fraud attempt now exceeds the average ACH payment value. The shape of that data says fraudsters are scaling per-transaction targets rather than running thin and high-volume.
Takeaway: Pre-origination validation reaches every rail that touches the FI. Catch the stolen account data once, and you keep it off all three.
Myth vs. Reality
- Myth: Faster payments are the new fraud frontier.
- Reality: Faster payments are the new fraud exit. The fraud starts on paper, the account data flows through credentials, and the money leaves via whichever rail clears first.
Final Thoughts
The 63% vs 2% number gets cited as a vote of confidence in instant payments. Read it again.
The number that should worry you is the velocity at which compromised check data converts into push-payment scams. Two weeks, in some cases less.
FIs that prevent fraud one rail at a time run three defenses that share nothing. FIs that layer defenses across channels and rails have a better chance at stopping scammers.
The fraud landscape is one piece. Defend it that way.
If your institution is rethinking how it prevents fraud across checks and ACH we’re ready to help.
Sources
- “Reality Check: Fact vs. Fiction in Real-Time Payments Fraud,” PYMNTS Intelligence and The Clearing House, 2026
- “Visa Sees Check Fraud Spilling Into Faster Payment Scams,” PYMNTS, April 2026
- NICE Actimize, 2026 Fraud Insights Report