The history of checks goes back more than two centuries, dating back to the Roman Empire when merchants used written orders to transfer funds instead of transporting large quantities of silver or gold. Then in the 9th century, a system called “sakk” was developed, which is where the word “check” is derived from. A sakk, allowed merchants to deposit funds in one city and withdraw them in another, effectively creating a trust-based system for long-distance commerce. The check that we know today took off in the 1950s when Magnetic Ink Character Recognition (MICR) was introduced and peaked in the 1990s before electronic payments and credit/debit card use became common.
Unfortunately, check fraud has been around almost as long as checks have. Today, it's the number one payment fraud threat facing community financial institutions (CFIs). According to the 2026 AFP Payments Fraud and Control Survey, 58% of organizations said they experienced check fraud in 2025, which was higher than both ACH and wire fraud.
The Federal Reserve's own data confirms that check fraud accounted for 30% of all fraud losses at financial institutions, second only to debit card fraud. During one recent review period, FinCEN received more than 15,000 Bank Secrecy Act (BSA) reports from 841 financial institutions on mail theft-related check fraud alone, amounting to hundreds of millions of dollars in exposure for banks.
Here’s a look at seven different types of check fraud that are threatening CFIs today.
Most Common: New Account Fraud
Fake checks are consistently cited as one of the most common types of check fraud, but the scheme usually starts with fraudsters opening a new account, depositing counterfeit or stolen checks and withdraw funds before the CFI can spot the fraud. This pattern is so widespread that FinCEN and the ABA have both issued repeated warnings about it.
The fake checks are often deposited using remote deposit capture since this technology is limited when it comes to scrutinizing magnetic ink and physical check attributes. The rise of mobile and online account opening has made it even easier for thieves to execute this fraud at scale, which lowers the barrier for entry-level fraudsters.
Most Tricky: Check Kiting
Check kiting is widely regarded as the most technically sophisticated and hard to detect check fraud schemes. It takes advantage of check float by bouncing funds between two or more accounts at different institutions to artificially inflate balances.
What makes check kiting especially insidious is that it can run undetected for days, weeks or even months. The checks being written are often real checks, drawn on real accounts, so they pass basic authentication checks with no obvious red flags. While check kiting incidents have declined somewhat thanks to cooperative industry efforts and faster settlement, the schemes that do occur tend to involve larger dollar amounts and more sophisticated operators.
Most Evolving: Split Deposit Fraud
This is a variation of new account fraud that takes advantage of some institutions’ willingness to provide cash back before large checks have completely cleared. Fraudsters deposit counterfeit checks into newly opened or compromised accounts and then immediately request a portion of the inflated balance back in cash. When the check eventually bounces, the institution usually bears the loss.
This scheme earns the "Most Evolving" label because it is adapting fastest to changes in how customers deposit checks and access funds. Bad players are now blending mobile and remote deposit capture with in‑branch cash withdrawals, using synthetic or mule accounts to spread smaller split deposits across multiple institutions, and continually tweaking timing and amounts to stay just below traditional alert thresholds. As new products, faster funds‑availability policies, and updated core rules roll out, split deposit fraud mutates in response, making it one of the most dynamic and adaptive forms of check fraud your institution will face.
Most Overlooked: Deposit Ticket Fraud
With this under-the-radar fraud, a victim is given a check to deposit to cover taxes on a lottery they supposedly won or some other ruse. The victim cashes the check and deposits the cash into an account controlled by the scammer using bank deposit slips, often pre‑printed or “blank” slips bearing the fraudster’s account number.
The criminal counts on the institution's frontline staff treating those slips as routine paperwork and focus their scrutiny on the check rather than reconciling the names and account numbers, which makes it easy to quietly redirect funds. The fraudster then quickly withdraws the funds from an ATM or through rapid in‑branch transactions before the fake check bounces or is flagged, turning what looks like a normal branch‑level process into a conduit for deposit ticket fraud. This scam targets everyday workflows most staff assume are secure and produces small, easily misattributed losses, which is exactly why it remains one of the most overlooked kinds of check fraud.
Most Targeted: Withdrawal Fraud
This is similar to deposit ticket fraud as it is based on scamming victims directly. Here, fraudsters ask victims to deposit a check that’s for more money than they owe and ask the victim to send some of the money back. There are many potential ruses: Scammers may pretend to hire victims as mystery shoppers or personal assistants, or they may tell victims they’ve won a sweepstakes and need to return some money to pay taxes. The check sent by the fraudster is fake and the victims lose the money they sent back.
In practice, this turns the victim into an unwitting “withdrawal mule." Their legitimate account and good standing with the institution are used to pull funds out quickly via cash withdrawals, P2P transfers, wire, or prepaid cards before the counterfeit check is returned unpaid. Because funds are often made available before the check has fully cleared, victims believe the money is “real,” and when the check eventually bounces, the institution reverses the deposit but cannot reverse the money the victim has already sent, leaving the customer on the hook.
Most Opportunistic: Counter Check Fraud
Counter check fraud exploits easy access to blank checks and busy branch environments to turn small, seemingly routine transactions into quick theft. Counter checks are temporary checks printed on demand by a bank in a branch. Fraudsters frequently request these checks in high traffic settings — Friday afternoons, before holidays, or during payroll rushes — when staff are most vulnerable to cutting corners.
These checks have a high risk of fraud because they’re not numbered and don’t have personal information pre-printed on them. They also lack most of the security measures most checks now have, such as watermarks and color-shifting inks. Counterfeit checks are made to mimic the appearance of the bank’s counter checks and then the fraudster presents them at different branches. They are "banking on" the front-line staff treating it as lower risk because the check appears to be drawn on the institution’s own account base.
Most Invisible: Dormant Account Fraud
This type of check fraud captures account and routing numbers from inactive bank accounts to create fake checks that connect to a real account. Because they look at these accounts infrequently, victims often don't discover the fraud for months. Dormant account fraud is similar to identity theft fraud and account takeover fraud, but it hacks dormant account to commit check fraud.
Criminals typically harvest the account information from old checks, legacy bill‑pay files, or data breaches, then test the dormant account with one or more small‑dollar checks before ramping up the amounts once those transactions slip through unnoticed. In many cases, the account owner may have moved, changed email addresses, or lost regular online access, which means standard alerts never reach them and monthly statements may go unread. Dormant accounts are ideal “quiet” funding sources for counterfeit checks and mule activity.
What CFIs Can Do to Combat Check Fraud
The best way to combat check fraud is to take a layered approach that utilizes a number of different strategies, including the following:
- Positive Pay — Checks presented for payment are compared to the check issued file provided by the business to make sure that key details such as the check number, dollar amount, and payee’s name are a match. If they’re not, the check is returned to the business for a pay or no‑pay decision. ACH Positive Pay works similarly for electronic transactions.
- Teller line validation of on‑us checks — Tellers should always carefully review and validate checks deposited or cashed at the same institution from which they were written, paying particular attention to new accounts, large dollar items, and unusual customer behavior.
- Customer education — Be proactive in educating customers about the risks of check fraud and steps they can take to protect themselves. For example, advise businesses to avoid mailing checks when possible and to use electronic payments instead, and not to use dye‑based pens when writing checks since this makes them easier to alter. Reinforce common scam patterns (overpayment, mystery shopper, “lottery taxes”) so customers recognize red flags before they deposit a check.
- Federal Reserve tools — For example, FedDetect Duplicate Notification flags potential duplicate checks across multiple banks, while FedPayments Reporter gives CFIs early notice (the afternoon before presentment) to review checks for potential alterations and other anomalies.
- Suspicious Activity Reports — Timely filing of SARs, especially for mail theft‑related check fraud, is not just a regulatory obligation; it is a valuable fraud‑intelligence tool that helps law enforcement and peer institutions see emerging patterns and shut down organized rings faster.
How CFIs Can Be Proactive - Not Reactive
More than a quarter of banks have experienced a 50% or higher increase in check fraud, and a significant share of surveyed bankers want regulators to shift liability to the bank of first deposit. Together, those findings underscore the importance of stopping fraudulent checks before they clear.
Now is the time to sit down with your fraud‑detection and operations teams. Consider mapping the specific vulnerabilities in your institution’s check lifecycle - from account opening to deposit channels, teller line, and back‑office review. You can then decide which layered controls you’ll invest in next. The institutions that treat check fraud as a strategic risk, not just a back‑office problem, will be the ones that protect their customers, preserve trust, and avoid being the bank of first and last resort when fraudsters strike.

