IntelliPay is a PCI DSS Level 1 payment processor serving government agencies, healthcare providers, and businesses across the United States. This article examines where payment fraud affects government finance operations in 2026 and practical controls that can reduce exposure. Learn more about government payment solutions.

Quick Read

Government agencies often invest heavily in protecting citizen-facing payments, while fraudsters target a separate risk area: vendor payments, payroll, wires, and ACH credits that move money out of the agency.

Many government agencies have invested in stronger citizen-facing payment controls, including PCI-compliant portals, tokenization, and transaction screening. Those measures are important.

But the risk does not end at the payment portal. Vendor payments, payroll, wires, ACH credits, and other disbursements follow different workflows. If a criminal persuades staff to change a vendor's bank account or approve a payment using fraudulent instructions, the transaction may never touch the citizen-payment platform at all.

The numbers back this up

Business email compromise, or BEC, occurs when a criminal impersonates a vendor, executive, employee, or trusted business contact to redirect a legitimate payment. The FBI's 2025 Internet Crime Report recorded 1,008,597 complaints and $20.877 billion in reported losses across all crime categories. BEC alone accounted for $3.0466 billion in reported losses, making it the second-highest loss category after investment fraud.

Wire transfers and ACH were the most commonly reported payment methods in BEC complaints. The FBI also described a 2025 incident in which a city government office in Oregon was targeted for a fraudulent wire of more than $6 million. The incident illustrates why rapid reporting and coordination with a financial institution and law enforcement can be critical when a payment is suspected to be fraudulent.

The Federal Reserve reports that BEC was a leading cause of fraudulent ACH and wire transfers from business deposit accounts, accounting for 73% of reported cyber incidents in 2024—up from 44% in 2023. Common schemes include changing existing vendor payment information, impersonating an authorized party, and manipulating a legitimate employee into approving a payment. Read the Federal Reserve's ACH and wire fraud guidance.

Government fraud takeaway

A public vendor list, published meeting materials, and a trusted-agency name can give impersonators useful information before they ever send an email.

The strongest protection is a payment-approval process that assumes a banking-detail change may be fraudulent until independently verified.

How it actually happens

A criminal may review an agency website, procurement records, public meeting minutes, or other public information to identify a real vendor. The criminal then sends an email that appears to come from that vendor and requests an update to its banking information. If the change is entered without an independent verification step, the next legitimate payment can be sent to the criminal's account.

The payment can appear ordinary because it may use a real vendor name, a familiar invoice amount, and an otherwise normal approval path. The issue is not necessarily a failure of the payment rail; it is often a failure earlier in the process, when payment instructions were changed or an authorized employee was deceived. The Federal Reserve identifies modification of existing payment information and manipulation of authorized parties as common BEC patterns. See the Federal Reserve's fraud-classification guidance.

Five controls that reduce the risk

Ask your bank about positive pay, payee positive pay, ACH filters, ACH blocks, and ACH debit blocks for each disbursement account. Service names and capabilities vary by bank. Positive pay is commonly associated with check issue verification, while ACH filters and blocks can help control which ACH debits or credits are allowed on an account. Confirm the specific protections your bank offers and how exceptions are reviewed.

Verify every banking-detail change through an independent channel. Call a trusted contact using a phone number already in your vendor-management system or on a previously verified contract—not a number supplied in the email request. Apply the same procedure to urgent wire instructions and email requests that claim an executive has approved an exception.

Separate vendor maintenance from payment approval. The employee who changes a vendor's banking information should not be the only person who can release the next payment. Require a second review, document the verification, and create an escalation path for urgent requests.

Restrict ACH activity to what each account actually needs. For example, where appropriate, use debit blocks or filters to prevent unauthorized ACH debits and authorize known counterparties or transaction types. Work with your bank to configure limits, alerts, and exception-review deadlines that match your agency's operations.

Establish a fraud-response plan before an incident occurs. The Nacha fraud-monitoring rule changes became effective March 20, 2026. They require risk-based fraud-monitoring processes for covered ACH participants, including Originators, certain third parties, ODFIs, and RDFIs. The rules do not create a blanket guarantee that a fraudulent payment will be reimbursed. If fraud is discovered, immediately contact the financial institution, request a recall or other available recovery action, and report the incident to the FBI's Internet Crime Complaint Center.

The good news: many of these controls can be implemented through existing bank treasury-management services and internal procedures. Your agency does not necessarily need to replace its payment platform, but it should confirm which controls are available, who owns them, and how exceptions are handled.

Vendor banking-change checklist

Before changing a vendor's payment instructions, agencies can use a simple, documented verification process:

  1. Flag the request as a payment-information change, even if it appears in a reply to an existing email thread.
  2. Call a verified vendor contact using a phone number already on file, rather than any contact information in the request.
  3. Require a second staff member to review and approve the banking-information change.
  4. Document the date, time, person contacted, and verification outcome in the vendor record.
  5. Place a brief hold or secondary review on the first payment sent to the new account when operationally practical.

Operational note: Adapt this checklist to your agency's purchasing policy, segregation-of-duties requirements, vendor-management process, and bank procedures. It is not a replacement for legal, audit, or financial-institution guidance.

Frequently asked questions

Is positive pay only for checks?

Traditional positive pay is primarily a check-fraud control. Banks may offer related ACH controls, such as ACH filters, ACH blocks, debit blocks, payee validation, and transaction alerts. Ask your bank which options apply to your accounts and payment flows.

Do the 2026 Nacha rules make our bank liable for BEC losses?

Not automatically. The rules require risk-based fraud-monitoring processes for covered ACH participants, but they do not establish a blanket reimbursement obligation for BEC-related losses. Your agency should review its account agreement, bank procedures, insurance coverage, applicable law, and any relevant state or local requirements with appropriate advisors.

How quickly should we act after discovering a fraudulent transfer?

Immediately. Contact your financial institution and request available recovery action as soon as the fraud is discovered. The FBI advises victims to provide complete transaction details when reporting to IC3, because speed can improve the chance that funds can be frozen or recalled.

Do we need new software for these controls?

Not always. Many controls are process changes or bank treasury-management features. The first step is to inventory your current vendor-change workflow, approval roles, bank controls, alerts, and incident-response contacts.

The bottom line

Protecting citizen payments is essential, but government agencies also need strong controls over the vendor, payroll, ACH, and wire processes that move money out.

Independent callback verification, separation of duties, account controls, and a tested bank-escalation process can help reduce exposure to vendor-impersonation and BEC fraud.

To review payment acceptance and security options for your agency, visit IntelliPay Government.

Sources and further reading

Disclaimer: This content is provided for general informational purposes only and does not constitute legal, financial, audit, or banking advice. Fraud-prevention requirements, account terms, and available treasury-management services vary by financial institution, state law, and local policy. Agencies should consult their bank, legal counsel, auditor, and internal security teams before implementing controls or relying on the information above.

author avatar
Dale Erling
Dale Erling is a veteran fintech leader with over 15 years of experience in banking and payment processing. Specializing in PCI compliance and interchange cost reduction, Dale helps organizations navigate complex financial landscapes with transparency and security. He is a recognized voice in utility fee architecture and a former strategist for Prosper Healthcare Lending.