Check Fraud Detection: How Banks Catch Altered and Counterfeit Checks

How banks and credit unions detect altered, counterfeit, forged, and duplicate checks: typologies, detection layers, Reg CC holds, and SAR key terms.
Alexandre Berkovic

TL;DR: Check fraud detection is the set of controls a bank or credit union uses to identify altered, counterfeit, forged, and duplicate checks before funds leave the institution. Checks are a shrinking payment method and still the most attacked one: depository institutions filed 682,276 check fraud SARs in 2024 according to Thomson Reuters Institute analysis of FinCEN data, roughly double the 2021 count. No single control catches it. Image forensics, positive pay, deposit behavior analytics, Regulation CC holds, and 314(b) sharing each close a gap the others leave open.

Why Check Fraud Came Back

Check fraud surged because stolen mail became an industrial input. FinCEN issued FIN-2023-Alert003 in February 2023, in coordination with the U.S. Postal Inspection Service, after check fraud SARs rose from more than 350,000 in 2021 to over 680,000 in 2022. Checks pulled from collection boxes are sold in bulk on encrypted messaging channels, washed or copied, and pushed through deposit accounts controlled by recruited mules.

FinCEN's September 2024 Financial Trend Analysis put numbers on what happens to a stolen check. In the six months after the alert, 841 institutions filed 15,417 BSA reports on mail theft-related check fraud covering more than $688 million in actual and attempted transactions. Forty-four percent of those checks were altered and deposited, 26 percent were used as templates for counterfeits, and 20 percent were fraudulently signed. The median reported amount was $14,215, which says the typical item is a business or escrow check, not a birthday card.

The volume has not receded. The 2026 Federal Reserve Financial Services Risk Officer Survey found 63 percent of institutions experienced check fraud attempts in the prior year, with 32 percent reporting increases in counterfeit checks, 21 percent in check washing, and 18 percent in payee forgery. The 2026 AFP Payments Fraud and Control Survey reports 58 percent of organizations experienced check fraud in 2025, down from 63 percent in 2024, a decline that tracks falling check volume rather than any retreat by attackers.

The economics favor the fraudster because of timing. Regulation CC requires the depositary bank to make funds available on a schedule that often runs ahead of the paying bank's return. Counterfeits and forged signatures must be returned by the paying bank's midnight deadline, while warranty claims for altered checks and forged endorsements can reach the depositary bank months after the money is gone. Either way, a bank is holding a loss on a check nobody physically examined.

Six Typologies, Six Different Signals

Check fraud is not one problem. Each typology changes a different part of the instrument or the process, and each leaves a different trace.

Typology What the fraudster changes Primary detection signal
Altered or washed check Payee, amount, or date on a genuine check, often after solvent washing Ink, font, and alignment inconsistencies; positive pay mismatch
Counterfeit check Whole instrument reproduced from a stolen template with real routing and account numbers Check stock and serial number out of pattern with issuer history
Forged endorsement or signature Stolen check deposited by a non-payee, or drawer signature forged Payee name does not match depositing account; signature deviates from reference
Stolen mail (source) Nothing on the check yet; the item is diverted in transit Drawer and depositor geography mismatch; many unrelated payors into one account
Mobile deposit duplicate presentment Same check imaged via mobile deposit, then the paper deposited or cashed elsewhere Cross-channel duplicate detection; restrictive endorsement check
Check kiting Float between accounts exploited with checks not backed by collected funds Circular deposit and withdrawal timing; rising uncollected balances

Washing dominates because it is cheap. Acetone lifts most ballpoint ink while leaving the printed stock intact, and the payee line is the most frequently altered field according to FinCEN, followed by the amount. Duplicate presentment is the newest typology, and Regulation CC's remote deposit capture indemnity, effective July 2018, shifts that loss to the bank that accepted the image unless the paper carried a restrictive endorsement such as "for mobile deposit only." Kiting is the one typology in genuine decline, because Check 21 image exchange compressed the float it depends on.

Detection Layers and What Each One Misses

Five stacked slabs labeled Image Forensics, Positive Pay, Behavior Analytics, Reg CC Holds, and 314(b) Sharing
Check fraud detection stacks five controls, each covering a blind spot the others leave open.

Effective check fraud detection stacks five controls, each covering a blind spot in the others. Institutions that rely on one or two of them catch the crude cases and absorb the rest.

Image forensics examines the check itself. Systems compare the deposited image against the issuer's historical check stock, signature references, and MICR characteristics, and flag anomalies in font rendering, ink density, and field alignment that indicate alteration or reproduction. This is the same discipline that underpins document fraud detection in banking, applied to one highly standardized document type. Its weakness is the clean forgery: a good counterfeit on matching stock with a traced signature will pass, and so will a skillfully re-inked payee.

Positive pay closes that gap on the paying side. A business customer transmits its issued-check file, and every presented item is matched on serial number, amount, and, with payee positive pay, the payee name. Anything that does not match becomes an exception the customer must approve or return before the midnight deadline. Positive pay is close to decisive for enrolled commercial accounts and useless for everything else: consumer accounts are not covered, small businesses often decline to enroll, and basic positive pay without payee matching clears a washed check whose amount and serial number were left alone.

Behavioral analytics watches the depositor rather than the check. A new account that receives a $9,400 business check from an out-of-state payor and requests an immediate withdrawal is a pattern, and so is an established account that deposits checks from six unrelated companies in a week. This is where check fraud detection and mule account detection converge: the 2026 Federal Reserve survey found check-related fraud was the most common trigger for identifying a mule account, cited by 41 percent of institutions. Behavioral models score the deposit, not the drawer, so they cannot distinguish a legitimate windfall from a stolen payroll check without another signal.

Regulation CC exception holds buy time. Under 12 CFR 229.13(e), a depositary bank may extend availability when it has reasonable cause to doubt collectibility, meaning facts that would create a well-grounded belief in a reasonable person that the check will not be paid. The bank must give written notice stating the reason, cannot base the hold on the class of check or depositor, and must retain the supporting facts for two years. The new-account and large-deposit exceptions, the latter currently covering amounts above $6,725, add room. Holds detect nothing on their own. They convert a suspicious score into a window in which the paying bank can return the item.

Cross-institution sharing under 314(b) closes the last gap. The depositary bank sees the depositor, the paying bank sees the drawer, and neither sees the whole scheme. FinCEN's June 2026 fact sheet confirmed that fraud is explicitly within scope and that sharing can happen in real time; Sphinx's guide to FinCEN 314(b) information sharing covers the mechanics. The constraint is participation. Fewer than 2 percent of BSA filers are registered, so a request often reaches an institution that cannot answer it.

The SAR Obligation and FinCEN's Key Terms

Suspected check fraud triggers the standard SAR analysis. Banks must file when a transaction of $5,000 or more involves an identifiable suspect, or $25,000 or more regardless of suspect, within 30 days of initial detection or 60 days if no suspect is identified. Check fraud has its own activity type on the form, SAR field 34(d), and FinCEN's published SAR statistics are built from that check box.

Where mail theft is suspected, FinCEN asked filers in FIN-2023-Alert003 to include the key term FIN-2023-MAILTHEFT in SAR field 2 (Filing Institution Note to FinCEN) and in the narrative. FinCEN builds its trend analysis from those key terms, and institutions that omit them are invisible in the data that shapes future guidance. The narrative should state which typology was involved, how the item was detected, whether it was paid or returned, the amount actually lost versus attempted, and whether the customer was referred to USPIS. FinCEN noted that numerous filings reported the full face amount even when no transaction occurred, which distorts the loss picture. Sphinx's article on writing a better SAR narrative covers structure.

Two patterns deserve care. The depositor may be a victim rather than a perpetrator, as when an elderly customer deposits a counterfeit check and wires the proceeds to a scammer, and the SAR should say so. And an attempted deposit that was caught and returned is still reportable if it meets the thresholds.

How to Evaluate Check Fraud Detection Tooling

Most platforms demonstrate well on obvious counterfeits. The evaluation should focus on the cases that produce losses: washed payee lines, clean counterfeits on real stock, and duplicate presentments across channels. These criteria separate tooling that reduces losses from tooling that adds alerts.

Institutions evaluating check tooling alongside broader real-time transaction fraud detection should also ask how the two share a customer risk view, since the mule account that receives washed checks is often the same one that receives scam-induced wires.

Where Human Review Stays

Detection produces a queue, and several decisions in that queue resist automation. Confirming an alteration often requires contacting the drawer or the paying bank, because the image shows a discrepancy without proving intent. A payee mismatch may be a stolen check or a mother depositing her son's refund. A large check into a new account may be fraud or a home sale. The analyst gathers the context the model cannot see, decides whether to hold, return, or release, and documents that reasoning for the Regulation CC notice and, if needed, the SAR narrative.

Fraud teams at community banks and credit unions are small, check fraud SAR volume has roughly doubled since 2021, and each alert still takes the same twenty to forty minutes of retrieval and documentation. The bottleneck is not detection. It is the review capacity behind it.

Where Sphinx Fits

Sphinx's compliance agents work the review side of that bottleneck. An agent picks up a check fraud alert, pulls the deposit history, retrieves the drawer's prior paid items for comparison, checks the depositor against mule indicators and shared 314(b) information, and writes up the reasoning in a form an analyst can act on and an examiner can follow. Sphinx Doc Fraud applies the same tamper analysis used on onboarding documents to check images. The hold decision, the customer conversation, and the SAR filing decision stay with the compliance team, with the evidence assembled before they open the case.

Frequently Asked Questions

What is the most common type of check fraud?

Altered checks. FinCEN's September 2024 Financial Trend Analysis of mail theft-related check fraud found that 44 percent of stolen checks were altered and deposited, most often by washing and rewriting the payee line. Counterfeits made from stolen templates accounted for 26 percent and fraudulently signed checks for 20 percent.

Can a bank hold a check it suspects is fraudulent?

Yes, under the reasonable cause to doubt collectibility exception in Regulation CC, 12 CFR 229.13(e). The bank needs facts that would create a well-grounded belief in a reasonable person that the check will not be paid, must give written notice stating the reason, and must keep the supporting facts on record for two years. The hold cannot rest on the type of check or type of depositor alone.

When does check fraud require a SAR?

A bank must file when a suspected check fraud transaction totals $5,000 or more and a suspect can be identified, or $25,000 or more regardless of suspect, within 30 days of detection or 60 days if no suspect is identified. Filers mark SAR field 34(d), and where mail theft is suspected, FinCEN asks for the key term FIN-2023-MAILTHEFT in field 2 and the narrative.

Does positive pay stop check fraud?

Positive pay is highly effective for enrolled business accounts, because every presented check is matched against the customer's issued-check file before payment. It does not protect consumer accounts, businesses that decline to enroll, or, without payee positive pay, checks where only the payee name was altered.

What is duplicate presentment in mobile check deposit?

Duplicate presentment occurs when a check is deposited as an image through a mobile app and the paper original is then deposited or cashed somewhere else. Regulation CC's remote deposit capture indemnity, effective July 2018, generally places the loss on the bank that accepted the image unless the paper carried a restrictive endorsement such as "for mobile deposit only." Cross-channel duplicate detection and enforcement of that endorsement are the two main controls.

Get Your Free AI Compliance Handbook

What compliance leaders need to know about AI-driven fraud, autonomous laundering, and how your team can
fight back.
Submit
Thank you! Your submission has been received!
Something went wrong while submitting the form. Please try again.