[HN Gopher] Ask HN: Why hasn't the ACH system been more abused?
___________________________________________________________________
Ask HN: Why hasn't the ACH system been more abused?
IIUC, the ACH system
https://en.wikipedia.org/wiki/Automated_clearing_house Is utterly
insecure. Anyone with your routing number and account number, 2
numbers printed on every check, can ask your bank for all of your
money and the bank will not confirm anything with you. My first
experience with this was Apple's credit card that can only be paid
via ACH and I was shocked when I typed in my info into the apple
wallet app and then it took my money without the bank confirming
anything with me. Why hasn't this been more of a problem? Are
their mitigations? These numbers can be stolen from data breaches
even easier than passwords as they won't be salted and hashed,
they'll be the actual numbers right? The entire payment regime in
the USA seems to be switching over to ACH. Should I be worried?
Author : gernb
Score : 102 points
Date : 2022-08-29 17:53 UTC (5 hours ago)
| JohnHaugeland wrote:
| It's simple, really
|
| You can't do this. Only a bank officer can.
|
| A bank officer gets tracked doing it.
|
| If it's fraudulent, it gets reversed out of the bank's pocket, so
| they go look at who did it, and act accordingly.
|
| And if it's more than $500, you need a second signature.
|
| Now, as a criminal, all you need to do to fake a wire is to hold
| a five year career.
|
| It's the common sense answer.
|
| "it wouldn't work."
| gernb wrote:
| I not sure I understand. I recently signed up for
| apartments.com to pay my rent which way more than $500. Where
| does a bank officer fit into this? Are you saying the millions
| of transactions go through these services are all hand checked
| and signed by 2 bank officers? Can I view these signatures to
| find out who approved the transfer?
| JohnHaugeland wrote:
| A core cultural competency of programmers is to be willing to
| just go look things up.
|
| My opinion is that HN is losing this rapidly.
| mousetree wrote:
| It's a fair question to ask for clarity on the "bank
| officer" part. I was confused too.
| smsm42 wrote:
| aprtments.com had to do the paperwork to establish ability to
| initiate ACH (most likely, they hired some third-party to
| make the actual ACH for them). That's where it gets checked.
| If the provider screws up, and passes bad ACH, they'd likely
| to lose substantial money, and maybe the whole business if
| they get cut off. So the provider will likely verify what
| apartments.com is a legit business with legit people behind
| it, and will eagerly cooperate with law enforcement if
| anything shady happens. In turn, aparments.com probably has
| some protocol to verify the numbers you put in actually
| yours. Because if they screw up on this, they are left
| holding the bag for the stolen money _and_ likely lose access
| to ACH themselves, which would hurt their business.
| mousetree wrote:
| > they are left holding the bag for the stolen money and
| likely lose access to ACH themselves, which would hurt
| their business.
|
| This is the key part. If they're originating the ACH (i.e.
| pulling funds from your account) and a return is issued
| then apartments.com are liable for sending those funds
| back.
| notatoad wrote:
| > Anyone with your routing number and account number, 2 numbers
| printed on every check, can ask your bank for all of your money
|
| Mostly because this is not true. _Anyone_ can't do it. It's
| relatively easy to get permission to get deposit access. Getting
| withdrawal access is not especially easy. And it's capped at an
| amount relative to your credit rating.
|
| And the people who do have withdrawal access need to have a good
| business reason to do withdrawal, and don't want to lose their
| access.
| mikequinlan wrote:
| You have 30 days after you receive your statement from the bank
| to challenge any transactions.
|
| Always check your bank statements.
| legitster wrote:
| There's a _lot_ going on behind the scenes that we don 't see.
|
| The bank is not wiring your money instantly. As I understand it,
| it takes 2-3 days for your bank to do the actual security
| confirmation. What Apple is probably doing is effectively
| floating you a line of credit assuming that the ACH goes through.
| And your bank is probably passing you along the transaction in a
| "pending" state.
|
| There are a lot of security checks just to be _in_ the ACH
| system. Ask someone who does payroll what it takes to set up
| direct deposit. Just having the numbers ain 't enough even to put
| money into an account.
|
| It's a bit analogous of how TLS/SSL work. Yes, you can just issue
| your own self-signed certificate. But that doesn't mean anyone
| will trust it.
| jopsen wrote:
| > There are a lot of security checks just to be in the ACH
| system.
|
| But most of them depend on the customer reviewing their
| transactions and reporting fraud. Otherwise, it can and will go
| undetected.
|
| I personally don't care to review my transactions, it's a
| hassle, simple 2FA would do away with it.
|
| I live in Denmark, we have similar systems for automatic
| payment, but at-least it now let's me see who has a mandate to
| withdraw money from me on a monthly basis. That said, it still
| a sorry state of affairs. The EU mandated 2FA on all internet
| shopping, this works, it got done, it's ugly and some of the
| 2FA systems look sketchy, but online shopping frequently
| involves an app or a text message for authentication.
| legitster wrote:
| There's a ton of misinformation in this thread - this is not
| at all what ACH is. ACH is specifically how _banks_ move
| money between accounts. It 's not at all analogous to wire
| transfers or more generally payments.
|
| ACH being public information is a bit like nameservers being
| public.
| wiredfool wrote:
| ACH is overnight. Any 2-3 day thing is the bank doing risk
| management. There's a presumption of success, and if there's an
| issue, you'll get a return.
|
| There's no 'pending' state on ACH. It's done in one shot, in as
| little as 94 characters.
| legitster wrote:
| Sure, I was specifically referring to OPs example of adding
| funds to an Apple wallet.
| ejstronge wrote:
| > Just having the numbers ain't enough even to put money into
| an account.
|
| Not sure what you mean by that - having the numbers would seem
| to be the only thing needed to add money into an account.
| somehnguy wrote:
| Yeah - 10+ years ago I saved the routing/account number off
| my last check in my bank provided checkbook into my password
| manager. Whenever I need to pay via ACH for anything I just
| copy and paste those numbers - works fine.
| legitster wrote:
| For the bank, yes.
|
| When I put my ACH details into my Cash app, or Apple pay, or
| whatever - I am not actually directly creating an ACH
| transaction. The two organizations are still going to do the
| transaction on my behalf.
| Tangurena2 wrote:
| It does get abused. With counterfeit checks.
|
| You may have come across the sort of scam where someone wants to
| "buy" something you're selling. But they send you a much larger
| check. "Please send us the extra/surplus", they say. Or, "the
| rest is for shipping, send that to X, they'll pick up the item".
| Then when the check works its way through the system, is found to
| be fraudulent, the transaction gets reversed.
|
| https://www.fdic.gov/consumers/consumer/news/august2019.html
|
| Wiring money is something outside the norm in the US banking
| system. I think if it were more common, then ACH fraud would be
| far more common.
|
| Anecdote: When I wanted to wire money (overseas), the hassle at
| my bank was plenty. Every piece of paper had in huge letters
| "this could be fraud! Once this transaction happens, the money is
| gone! Forever!" (slight exaggeration).
| colechristensen wrote:
| ACH fraud is hard to do because it's reversible over long periods
| and you can't do ACH without being well identified.
|
| Banks do plenty of identification of you (say you're opening a
| credit card or bank account) that you don't necessarily see in
| order to cover their risks.
| devwastaken wrote:
| It is abused, it's called check fraud. However the same as
| automobile accidents, it's old news, and just apart of every day
| life.
|
| People have been doing all forms of check fraud. One popular one
| is where they'll send a check, you cash it, money shows up, and
| it reverses later because it's fraudulent.
| JacobThreeThree wrote:
| There is significant ACH fraud.
|
| https://www.cfo.com/corporate-finance/2019/04/scammers-targe...
| olliej wrote:
| This was the most kind boggling thing I encountered when I first
| moved to the US (that and the signature/nothing at all nature of
| using a card to pay for anything).
|
| I asked about why they didn't at least require any checks to be
| issued on checks that they issued and I was told it was because
| people might not want to use bank provided ones??
|
| But yeah the fact that the way you did a direct deposit is give
| someone your bank account# and then they withdraw however much
| money they want from it, and they can do so in perpetuity, is
| absurd.
|
| In NZ - and I presume most of the rest of the world with such
| systems - the only thing you can do with someone's account
| details is deposit money.
| Apreche wrote:
| Go ahead. Print a personal checkbook with someone else's name,
| account number, and routing number on it. Write yourself a check
| and sign it. Then try to cash it or deposit it. See what happens.
| I double dog dare you.
| smsm42 wrote:
| I had it happen to me once - somebody washed my check (i.e.
| removed the original sum and payee and replaced it with larger
| sum and different payee) and tried to cash it. The bank called
| me, because the check looked weird, I said "huh? never heard of
| those" and they refused to cash. Unfortunately, the fraudster
| promptly run away from the bank - or so they told me - so
| that's where the thing ended.
| Tomte wrote:
| It's why Donald Knuth only issues fantasy checks nowadays. I was
| happy to get mine before he started it.
| throwaway1777 wrote:
| I believe the main mitigation is the settlement time and
| reversibility. You have appx t+2 days to notice the issue and
| report it.
| esotericimpl wrote:
| wiredfool wrote:
| For consumer accounts, it's 60 days.
| throwaway1777 wrote:
| Also every account needs KYC so the authorities will know who
| you are if you try to steal money this way.
| gernb wrote:
| I don't get any notices from my bank so I certainly would not
| notice with in 2 days that someone took my money.
| Turing_Machine wrote:
| It's 60 days (or 2 days, if you are a business) from the
| _date you receive the statement_ with the fraudulent
| transaction, not from the date the transaction occurs.
|
| Within that time, the bank(s) are required to reverse the
| transaction, no questions asked.
|
| I believe you can even get your money back at a later time,
| but if you don't make the deadline there are more hoops to
| jump through.
| wiredfool wrote:
| I'm pretty sure that it's 60 days from origination (+ a few
| days for potential holidays and weekends, like if it hits
| on the 23rd of December as a Saturday and the 24th and 25th
| are holidays), but it's been a few years and I don't have
| my NACHA books any more.
|
| But that's certainly not hard and fast, I think I've seen
| roughly twice that time frame for extraordinary cases.
| tyingq wrote:
| _" Anyone with your routing number and account number, 2 numbers
| printed on every check, can ask your bank for all of your money
| and the bank will not confirm anything with you"_
|
| Well, sort of. A very broad set of people can do ACH deposits
| into your account. A much smaller set of people (though still
| lots of them) can do ACH withdrawals.
|
| Also, some banks offer a way to have a whitelist for entities
| allowed to do ACH debits/withdrawals. Chase calls it "ACH Debit
| Block" for business accounts.
| xd1936 wrote:
| How is this decided?
| nickphx wrote:
| The same as any other banking product? Due diligence, know
| your customer laws, and incredibly high fees.
| tyingq wrote:
| Varies by what company and service you're using. Here's what
| Chase says about adding the ability to ACH debit customer
| accounts to a business account:
|
| https://www.chase.com/business/online-banking/ach-
| collection...
| PeterisP wrote:
| The bank decides arbitrarily but effectively since if you're
| a crook, they lose that money so they limit the ability to
| the degree that they trust you, and once their own money is
| on the line, banks weirdly become much more effective at
| restricting fraud.
|
| In essence, it's just equivalent to any other customer risk
| management by the bank, since allowing you a certain amount
| of ACH withdrawals is in some sense similar to credit risk.
| raxits wrote:
| Money goes from your (Bank) account to verified
| entity(merchant/business, Org etc)'s bank account and they have
| legalities/agreements in place.
| mousetree wrote:
| What I've never understood is why the US system relies so much on
| ACH Pulls rather than Pushes? For example, most banks allow you
| to pull money from an external account (by verifying you own the
| external account using something like Plaid Identity or
| microdeposits) but don't always offer the ability to push funds.
|
| It seems pulling is much more open for abuse than pushing funds.
| Perhaps it has something to do with the originator having
| liability for a potential returns.
|
| In Europe, I've never seen any bank allow customers to pull funds
| (something like a SEPA I guess) but its extremely common to push
| funds very easily to another account just by entering their IBAN
| (not so in the US though).
| smoe wrote:
| At least in Switzerland pretty much all the banks offer a
| service called LSV+ trough which you can authorize a third
| party to pull money from your account. Supposedly (personally I
| don't know anyone using it) it is often used for recurring
| bills like utilities, credit card, internet etc.
|
| But as far as I understanding you have to submit a form with a
| wet signature to the bank for each third party you want to
| authorize before they can withdraw. Also, you have 30 days
| after a transaction to dispute it.
| cybersol wrote:
| Maybe I am missing something, but isn't pushing this way
| usually possible by one-time BillPay?
| mousetree wrote:
| In my experience, some banks offer ACH pushing through Bill
| Pay but often an ACH is only made if the recipient is on a
| master list of known institutions (like for paying your
| electricity) and if the recipient is not on this list then a
| check is sent by mail. YMMV though
| L3viathan wrote:
| SEPA Direct Debit, which works on the pull profile and is very
| similar to ACH, is extremely common at least in Germany.
|
| You can only use it (as the puller, not the pullee) if you're a
| business though.
| mousetree wrote:
| Yeah, that's what I mean, doing a SEPA Direct Debit is not
| really available to an end consumer, at least not in any of
| the banking apps I've used. But in the US, pulling funds from
| another account is fairly common.
| jsmith45 wrote:
| The ACH system was based on older check (cheque) clearing
| systems. In those systems the bank in which the check was
| eventually deposited was basically pulling funds.
|
| The US never had a Giro system. The main push based payments
| have generally been "wire transfers", which have significant
| cost, or ACH-based Direct Deposit, which is pretty much only
| used for payroll situations.
|
| Even payment cards are fundamentally a pull based system.
|
| Only Paypal, Venmo, CashApp, or other similar services have a
| push model, and those pretty much always wrap an under the hood
| ACH pull.
| mousetree wrote:
| Interesting to learn about the history but why aren't they
| pushing funds today? It's technically all possible and
| presumably would have less fraud? Or in other words, why do
| most of the rest of the world favor pushing funds through
| their ACH-equivalent systems?
| RyanCavanaugh wrote:
| It's the same question as why people keep so many valuables in
| houses where you can just break a window, walk in, and take
| stuff: because you go to jail if you do that.
|
| If ACH was different and you could just, say, walk up to an ATM
| and punch in a routing/account number and withdraw cash, it'd be
| a very different situation. You can only interact with the ACH
| system through a regular bank, and regular banks have KYC
| regulations that mean the recipient of those funds has a name,
| address, and SSN. Doing theft via ACH means the funds end up in
| account clearly tied to your identity, and you go to jail.
| gernb wrote:
| This doesn't really answer the question though. People steal
| things all the time. The easier it is to steal the more they do
| it. Bikes, breaking into cars, purses, etc...
|
| We have passwords and two factor to prevent this stuff for lots
| of situations but in this ACH case we seem to have nothing.
| What's special about ACH vs all other situations? Why do I need
| a password and two factor on other accounts but not ACH? It's
| just as illegal to break into those other accounts is it not?
| tyingq wrote:
| You could hack someone's business bank account and ACH debit
| other people, yes.
|
| But then you have to get the money out of that account, and
| into cash in your hands without leaving a trail that leads to
| you. It's possible, but complicated. And if you could do it,
| there was probably already significant money in the account
| you hacked into in the first place. No need to pad it with
| ACH debits that might set off alarm bells.
| [deleted]
| bombcar wrote:
| You can't just take money with the numbers.
|
| You have to be a _bank_ or otherwise registered with the
| clearing house.
|
| So you can ask _your bank_ to pull money from my account, and
| if I object _my bank_ will claw back the money from _your
| bank_ and they will know who you are.
|
| And if it wasn't all a misunderstanding or a typo, then they
| know where to find you.
| sp332 wrote:
| You can just take money with the numbers. A business can
| just ask for ACH account info for payments. That means a
| customer could use someone else's "numbers" to fraudulently
| buy thigs. And maybe that other person wouldn't be liable
| for the fraudulent transaction, but the customer would
| still have the stuff they bought without leaving an ID
| behind.
| Sohcahtoa82 wrote:
| What businesses allow you to pay via ACH?
|
| Off the top of my head, the only ones I can think of are
| utilities, other banks (so you can make loan payments),
| and consumer payment processors like PayPal. In the first
| two, they'll have your ID. In the latter, they do the
| "make two deposits" thing to verify you own (or at least
| have access to) the account.
|
| I can't go to Wal-mart and pay via ACH. Do they even take
| personal checks anymore?
| jrockway wrote:
| > What businesses allow you to pay via ACH?
|
| Pretty much anyone with a Stripe account can accept
| payments via ACH.
|
| https://stripe.com/docs/payments/ach-debit
|
| I worked at an ISP and we definitely appreciated it when
| our customers paid via ACH instead of credit card. (Less
| fees.) We were tiny, too; you don't have to be a giant
| company to get this going.
| jsmith45 wrote:
| Of course they still take personal checks. How else would
| elderly granny that does not trust "plastic" pay? Some
| would do it with cash, but many have paid with checks
| their whole lives, and will not stop until they drop
| dead.
|
| And it certainly used to be common for e-commerce sites
| to accept "electronic checks" by having you type in the
| routing and account numbers, with no additional
| verification. These days, there usually is additional
| verification.
|
| It is still commonly accepted with no verification for
| payment for things like utility bills. This appears to be
| on the assumption that if there is check fraud they
| probably know the guilty party, because who else would be
| trying to pay your power bill?
| awad wrote:
| Happens plenty in B2B but, again, reputational risk is
| involved
| edgyquant wrote:
| This business would run the risk of being cut off from
| the financial system.
| cowtools wrote:
| Okay, but the business has no way of stopping this
| attack, so it is fruitless.
| [deleted]
| olliej wrote:
| The question I think is more "why does someone have to give
| me their account details and so allow me to remove an
| arbitrary amount rather than me providing my account details
| knowing that all you can do is give me money?"
| throwgogog111 wrote:
| > because you go to jail if you do that.
|
| The people involved in money transfer scams are never, ever
| going to jail, ever.
| ryandvm wrote:
| Bingo. This is something the cryptocurrency extremists just
| willfully refuse to acknowledge. It turns out that transaction
| reversibility and the ability (and willingness) of law
| enforcement to get involved are extremely useful tools in most
| commerce scenarios.
| throw101010 wrote:
| If reversibility is needed any "cryptocurrency extremist"
| will tell you that there is no trustless solution to this
| kind of transaction and that a trusted intermediary (usually
| an escrow) is needed.
|
| This is what happens with fiat money anyways, it is just so
| intimately mixed by now (credit cards, ACH, etc.) that you
| figure it's the only kind of transaction that exist or should
| exist.
|
| Crypto is providing an alternative to this point of view, if
| you don't think you need it, don't use it, pretty
| straightforward... and if you want to stop it because you
| want people to think like you, try to stop it, let's have
| fun.
| permo-w wrote:
| I think it's the evangelism of crypto that irritates
| people, not the personal use of it, although there are the
| obvious environmental issues with that too.
| jimcavel888 wrote:
| 29athrowaway wrote:
| 18 U.S. Code SS 1343 - Fraud by wire, radio, or television
|
| https://www.law.cornell.edu/uscode/text/18/1343
|
| ACH fraud is wire fraud
| tibbon wrote:
| Is credit card fraud not?
| rsstack wrote:
| "Credit card fraud frequently involves elements of both
| bank fraud and wire fraud"
|
| https://www.justia.com/criminal/offenses/white-collar-
| crimes...
| ramesh31 wrote:
| This. Same as fraud. I could put up a website right now, point
| some ads to it, and start harvesting thousands of CC numbers to
| sell. But then I would go to jail.
| rosnd wrote:
| Wow, you can't do crime because it's illegal!
|
| How do you explain the widespread availability of "drop"
| accounts in the US? Cybercrime forums are full of people
| offering services to "cash out" illicit bank transfers into
| cryptocurrency.
| RyanCavanaugh wrote:
| It's not that you can't, it's that the risks of getting
| caught doing it and punished for it are too high relative to
| the reward.
|
| If you don't believe that deterrence is a real thing, there
| is a lot more human behavior that needs explanation than just
| the relative lack of ACH fraud.
| SilasX wrote:
| You still don't seem to understand why "it's illegal" is
| not a great insight to lead your example with. Even if
| true, the answer would lead with what makes _this illegal
| thing_ so less prone to violation than other illegal
| things.
| permo-w wrote:
| it is illegal _and_ easily detectable
| SilasX wrote:
| I got that part. Still doesn't justify a comment that
| starts with a paragraph implying that illegal things
| can't happen because deterrent. That doesn't help.
| permo-w wrote:
| no one said they can't, just this is largely why they
| don't. are you going to rob a supermarket where you have
| to hand in ID at the door? or will you find somewhere
| easier?
| rosnd wrote:
| https://www.nbcnews.com/news/world/margaritas-story-how-
| one-...
|
| https://www.ice.gov/news/releases/russian-man-pleads-
| guilty-...
|
| They do this, at giant scale. When you're earning tens of
| thousands of dollars per account, it's worth it to train
| people to go open bank accounts using fake passports.
| rosnd wrote:
| How do you explain the widespread availability of "drop"
| accounts in the US? Cybercrime forums are full of people
| offering services to "cash out" illicit bank transfers
| into cryptocurrency.
| greatjack613 wrote:
| Shhhh, this has been going on for years and is known as wire
| fraud and carries one of the most severe punishments by law. On
| top of that most banks will reverse a payment when someone does
| it without your permission although the time and pain it takes to
| reverse it may vary.
| nope96 wrote:
| Not ACH, but the ACATS system (transfer securities between
| brokerages) has recently seen a number of thefts. It seems like a
| horribly insecure system.
|
| If a scammer knows you own stocks, and can impersonate you, they
| can set up an account at another brokerage and pull your stocks
| away with ACATS. YOUR brokerage is required to send them, and
| does no verification. You probably won't even get a notification.
|
| https://www.bogleheads.org/forum/viewtopic.php?p=6756853
|
| Fidelity seems to be the only brokerage at the moment that lets
| you "lock down" your account and prohibit outbound transfers.
| nimish wrote:
| Regulation E limits liability for fraud. ACH isn't an anonymous
| system either.
| mousetree wrote:
| How does Reg E limit the liability for fraud?
| [deleted]
| belfalas wrote:
| Simple: ACH is the 800-pound gorilla of banking in the United
| States and the established players basically have zero incentive
| to change. It is in fact only a losing proposition for them. The
| banks make great fee-based money from the ACH system and the lag
| times in ACH create lots of juicy arbitrage opportunities.
|
| It is true that the system is insecure and terrible for
| consumers, but this is not an issue for the banks. They have
| insurance.
| mousetree wrote:
| What fees and what arbitrage opportunities?
| gernb wrote:
| > The banks make great fee-based money from the ACH system
|
| Confused. The companies that give me the option of ACH vs
| Credit Card always charge 2-3% to pay via credit card and
| nothing to pay via ACH. Why wouldn't they pass on ACH charges
| to me if they are a "great fee"?
|
| update: I see from another link that Chase charges $0.25 per
| transaction so not such a great fee. But maybe across tons of
| charges it adds up.
| mywittyname wrote:
| Not the OP.
|
| The 2-3% credit cards charge as fees are largely used to deal
| with fraud.
|
| There were 30 billion ACH transactions in 2021, and this
| number has been growing by 8%+ YoY for a while now. $0.25 a
| transaction is solid revenue when you consider that it's
| almost pure profits because fraud isn't a big issue and the
| computational power to manage ~100 million transactions a day
| is pretty modest.
| quesera wrote:
| This is true, and even more so.
|
| Medium and large ACH customers pay much less than $0.25 per
| entry, which reflects the security and low-risk nature of
| the network.
| JohnHaugeland wrote:
| The post is asking about the low rate of fraud
| jmann99999 wrote:
| What people seem to miss in this conversation is that fraudulent
| ACH TRANSACTIONS can be reversed for up to 60 days if I recall.
| This is different from WIRE TRANSFERS that can't be reversed.
|
| So, it is not a fertile ground for fraud.
| mousetree wrote:
| The problem here, for banks at least, is that even if they can
| be reversed, the fraudster is long gone by then and the funds
| have been withdrawn.
| wiredfool wrote:
| That's basically correct, though wire transfers aren't
| completely immutable, it's just _really_ hard to back them out.
| advisedwang wrote:
| It's easy to track where the money has gone, which means this
| type of fraud has high risk of getting caught. You need a rube to
| hold the receiving account and then a money laundering method to
| get it away from them cleanly, which is all a lot harder.
| tyingq wrote:
| This seems like the most relevant answer. The account debiting
| the funds will have had a fair amount of due diligence and real
| people associated with it. Some real person will be left
| holding the bag when the flood of complaints comes in. Timing
| it so that you get a fall-guy to open the account, get ACH
| debit rights, steal the money, and get it out and laundered
| would be non-trivial. And doing all that in some way where the
| fall guy can't identify you.
| ohiovr wrote:
| This explains the package manager scams I see in my inbox. I
| keep fraud, crypto, and purchase scams in folders. It is a bit
| like collecting spores, molds, and fungus.
| [deleted]
| bergenty wrote:
| Interesting so if you manage to gain control of someone else's
| account, you pull up the last check from the richest person you
| know and pull from their account. Then you use that to fund a
| crypto account, buy some crypto that can be exchanged on a
| automated defi exchange and you're good to go.
| pengaru wrote:
| > Are their mitigations?
|
| My approach to this is to use services like e-trade where my
| checking/debit account is linked to a brokerage account, and keep
| most of the funds isolated in the brokerage side. Then transfer
| small amounts as needed for daily life into the checking/debit
| side. It's trivial and instantaneous to move money back and forth
| so it's not terribly inconvenient.
|
| This way the only account people ever get ACH information for
| generally has too small a balance to matter much. Also my debit
| card was skimmed at a gas station once and this approach limited
| what they stole to just a few hundred bucks. After dealing with
| e-trade's fraud department to report the theft they eventually
| made me whole and replaced the skimmed card, still took some time
| and frustration though.
|
| I find it delivers significant peace of mind. But one still needs
| to pay attention in case something happens, such things have time
| limits for reporting and expecting the money back. By keeping the
| balance small it somewhat forces having a current awareness of
| its status, assuming regular use.
|
| Another bonus for e-trade is they offer air-gapped hardware token
| based 2FA.
| salawat wrote:
| In the United States, money transmission is a _regulated_ space.
| I.e. you must meet a minimum set of regulations in order to hold
| that license. That license requires you be able to do things like
| handle fraud, chargebacks, dispute resolution, etc...
|
| Everyone implements these processes, and if you get a money
| transmitter that doesn't, generally, every other money
| transmitter in the space will mark transactions from that actor
| as high-risk, either rejecting tx's from them, or sibjecting them
| to longer holds, or just straight out rejecting them.
|
| If you don't have a license of your own, your on ramp is through
| someone who does. They can underwrite the risk of your membership
| in the financial system as a whole, but if they find out (and
| they will, because their business contracts come with audit, FWA,
| and due diligence clauses) you will find your access cut off, and
| if it's brazen enough, lawsuits getting served.
|
| Now, what does this mean?
|
| If you hand someone a blank check, they can absolutely take you
| the cleaners. However, if someone crafts a malicious ACH payload,
| the origin of that can be traced from your bank, back to the
| clearinghouse, from the clearinghouse, back to the originator,
| who will have their processes scrutinized/investigated.
|
| Generally Accepted Accounting Principles and double-entry
| accounting is the magic glue that ties everything together. If
| you follow the rules, you will have a transparent trail to
| follow.
|
| If you don't, you've entered suspected money laundering land.
|
| As a customer...
|
| If you're deposited somewhere that is FDIC insured... You're
| golden up to $100,000ish.
|
| If they aren't FDIC insured, if there's a dispute department, you
| _should_ be good. You should still treat it as higher risk though
| in that if they get bank run 'd, they do not guarantee at all you
| can get any money back. These are regulatorally speaking, _not
| banks_. They can take deposits, do transactions, dispense
| /administer interst bearing accounts (and do often pay higher
| interest due to the higher risk involved with depositing funds
| there), and do bank like things, but they are _not banks_.
|
| If you can't get in contact with a human being, good luck, and
| godspeed. You are braver than I.
| mousetree wrote:
| FDIC Insurance has nothing to do with ACH fraud - it covers
| cases where the bank itself fails. NACHA has its own process
| for ACH disputes/reversals/returns.
|
| Not sure what GAAP and double entry accounting has to do with
| this.
|
| The fraud here is not from end users "crafting a malicious ACH
| payload". End users don't interact with NACHA in that way. The
| more common case is when users, via their bank, are doing ACH
| Pulls from accounts that they shouldn't be. Most banks that
| offer direct ACH Pulls to their customers use a third party
| like Plaid Identity or microdeposits to prove ownership of an
| external account prior to initiating the ACH Pull. This is not
| 100% effective always - disclosure: I work at a neobank and I
| am directly involved in building systems to prevent/mitigate
| ACH fraud.
| pkrotich wrote:
| ACH is a legacy system that can be easily abused for sure -
| what's saving it is the fact that it's not real-time like it's
| newer counsin RTP. It also helps that withdrawing money via ACH
| requires an account and payment processor willing to clear ACH
| for you and shoulder some of the responsibilty.
|
| Yes, you can copy the numbers and make a fake checks to cash, but
| security features on the check helps with validation and most
| Check Cashing places don't cash big checks - mainly because they
| take on the liabity if the check bounces. It's also the reason
| why most bank requires you to have an account with them to cash a
| check depending on the amount.
|
| So in summary, it's relatively "secure" due to validation & delay
| clearing the check. Scammers know this very well - that's why
| they resort to overpaying invoices/items with fake checks only to
| demand refund from the unsuspecting mules - who end up holding-
| the-bag once they send out the refund, only for the check to
| bounce.
|
| Another similar legacy system that is easily and more abused is
| checks via mail - it's easier to cash a REAL check with a fake ID
| compared to a fake check for reasons I mentioned above. Why some
| companies still insist on paying or being payued via a check is
| beyond me!!
|
| Stolen checks is a bigger issue compared to ACH - in fact it's a
| federal offence to steal mail, post office even have Postal
| Police to deal with the issue.
| anon291 wrote:
| The main service provided by banks is that they sell trust.
|
| Only banks and financial institutions can directly send ACH
| transfers.
|
| Unlike wires, ACH transfers take time to settle.
|
| Banks are tasked with only allowing authorized transfers. Any
| bank that does not take adequate precautions will be kicked out
| of the system.
|
| The profit banks can draw from participating in the financial
| system is much higher than the amount they can steal once before
| they get banned.
|
| That's why most banks ask for verification (logins via plaid,
| micro deposits, etc), before allowing ACH withdrawal requests
| from other accounts.
|
| But the most important reason why people don't do this, is that
| it's very easy to get caught. To actually submit an ACH request
| to a random account, you have to appear somewhere in person
| (unless you do small checks up to your daily bank limit via
| picture, which will quickly have you caught since your phone and
| account is linked to a real person).
|
| Some CCTV tapes later, and you'll be put in jail for a very long
| time.
| mousetree wrote:
| ACH and Wires have similar times to "settle". However, rules
| within Fedwire and NACHA allow banks to hold ACHs for a few
| more days before releasing them to the customer. But
| technically funds are both arriving within 24 hours or so.
| gnicholas wrote:
| My edtech startup was contacted by an English-language school in
| a country where we have never advertised and have zero presence.
| They had a few questions but within 2 hours, they were ready to
| make a several-hundred dollar purchase.
|
| I was a bit suspicious because the sale was so easy (selling to
| schools is normally a slog, even inbound), and because they
| immediately asked for our ACH information. I contacted my bank to
| ask if I give them my ACH info, is there a chance they can do
| anything bad to me?
|
| My bank offered that I could give just the last 4 of my account
| number, which could be matched to my account based on the
| business name that would also be provided.
|
| This seemed like a good solution, but after trying several times
| we gave up. They paid via PayPal instead, and we've never had an
| issue with them. But the experience made me think about how ACH
| works, and the risks involved!
| yieldcrv wrote:
| If there was a headline syndicated internationally every single
| time there was an ACH fraud, you would think crypto was a
| godsend. But right now its the opposite, only headlines when a
| fraud occurs in crypto.
|
| Its all perception. The potential for reversibility improves the
| customer experience, but often times nobody is being prosecuted,
| the thieves often get the money for themselves, and the
| banks/insurance eats the loss.
| tdy721 wrote:
| This system you are calling ACH is also just called an "eCheck".
| If you write a check at say WalMart, they just scan it at the
| register and do an "ACH". Like others here have said: "KYC" know
| your customer rules make it hard to do fraud this way without
| getting caught.
|
| People _do_ abuse this all the time, look for the bad check
| writer program in your county. It 's not switching over to ACH,
| that's how it has worked all along. I recommend Catch Me if you
| Can by Frank Abagnale.
| ejstronge wrote:
| I don't believe eChecks and ACH are the same - eChecks are
| associated with a check number but this isn't the case for the
| many ACH transactions I have seen. Additionally, every eCheck
| I've encountered also had a required consent question ("Do you
| authorize us to...") whereas this isn't the case for ACH
| transactions.
| wiredfool wrote:
| There are a couple of ways this transaction can go, with
| different rules. There is an ACH truncation on checks, with
| follows ACH rules of reversability. In that case, they're only
| sending the MICR line of the check, not capturing an image.
|
| There's also Check21, which is much more likely to be what
| they're doing. That takes a front/back image, and is
| essentially electronic settlement of checks, using check
| settling rules. For true fun, the electronic image can later be
| printed out on a larger piece of paper with it's own MICR, and
| now it's an IRD (image replacement document) and it can go back
| into the legacy paper settlement system.
| happyopossum wrote:
| To understand this, you have to think past step 1 of the evil
| plan to steal all your money. First, in order to do ACH
| withdrawals, one must have a bank account that is strongly tied
| to your identity. So as a criminal, I steal your bank account
| number and force a fraudulent withdrawal - now that money is
| sitting (*not really, that's point 2) in my personal bank
| account, which is easy to trace.
|
| Second item - these transfers take a few days to settle, so I've
| "stolen" your money, but I can't withdraw or transfer it to my
| EvilBank offshore account for a couple of days.
|
| And finally, if you don't notice and tell your bank about this,
| and I can wait past the settlement period and withdraw the money,
| now I've got federal law enforcement after me for wire fraud, and
| they know who I am due to #1, so I'm in a world of hurt.
| smsm42 wrote:
| > a bank account that is strongly tied to your identity
|
| Correction: strongly tied to _some_ identity. For online banks,
| for example, there 's not much they can do to check if it's not
| a stolen identity. You'd need a lot of data - SSN, addresses,
| driver's license, etc. - but it's not out of the question to
| obtain such data from dark markets. Of course, withdrawal still
| be a problem, and this identity package will likely be burned
| once the first fraud notice will happen, so it may not be worth
| it to waste it this way.
| PeterisP wrote:
| Do these online banks even permit their customers to issue
| ACH withdrawals at all?
| wiredfool wrote:
| The simplest explanation is: ACH is reversible. If the consumer
| notifies their bank of an unauthorized debit within 60 days, the
| money gets yanked from the originating bank and put back in your
| account.
|
| The originating bank will then do the same to the merchant who
| debited your account, with feeling and 4 part harmony. If they do
| this too much (>1% unauthed, or >5% overall), then they get cut
| off. (Exact thresholds depend on the bank and their risk
| tolerance and what they've underwritten the merchant for. But
| those are about the highest numbers you'll see, though sometimes
| NSF returns can be higher. )
|
| ACH never settles. There's no security as such. An ACH
| transaction happens overnight, on trust, and may come back (by
| agreement) 60days later, and longer in cases of extreme fraud. So
| any time you're seeing a 2-3 day hold on ACH, it's the bank doing
| risk management decisions, not something in the underlying
| transfer. (note, that may not be strictly true for some
| correspondent small banks in alaska or other odd time zones,
| where there really is a day+ delay on things)
|
| The only thing that's keeping fraud under control is the banks
| doing underwriting on the merchants who can do debits. They're on
| the hook (ultimately) if there's fraud, so it's in their
| interests to keep it clean. They're also not likely to cut and
| run, because banking connections to the ACH network are not
| cheap/easy to come by.
|
| (source, I've worked in this space for 18 years)
| sedeki wrote:
| Unrelated question:
|
| > with feeling and 4 part harmony
|
| What do you mean by this in this context? I tried googling it,
| but only found results on musical theory. I guess you mean this
| as a (funny) metaphore?
| wiredfool wrote:
| It's from Alice's Restaurant.
| rtb wrote:
| Yes, a metaphor for doing it "even more". He means that they
| will be angry and will do more than just reverse the
| transaction: they will punish the merchant who fraudulently
| debited your account. They will levy a fine on them (any
| merchant who is plugged into the ACH system will have signed
| a contract with their bank agreeing to accept such fines and
| possibly put up a bond), or even perhaps ban them from making
| any future transactions, seriously harming their business.
| throwgogog111 wrote:
| > If the consumer notifies their bank of an unauthorized debit
| within 60 days
|
| As if. Ask the tens of thousands of people who have been
| scammed sending ACH payments if the bank has ever fucking
| reversed jack shit for them.
| MuffinFlavored wrote:
| > If the consumer notifies their bank of an unauthorized debit
| within 60 days, the money gets yanked from the originating bank
| and put back in your account.
|
| What if, in this order:
|
| 1. they take $10k from my account to their account
|
| 2. they take the $10k out of their account immediately
|
| 3. I call my bank and ask them to reverse the transaction (aka
| the funds are no longer there to yank back)
| kube-system wrote:
| The second bank will be looking at their security footage to
| find the crook who overdrew their account for $10k
| wiredfool wrote:
| 10k is the limit on most forms of ACH to consumer accounts.
| You're also hitting reporting requirements there, so it's not
| likely to go through in the first place without scrutiny.
| However.
|
| Most likely, the originating bank will release the money to
| the account that requested it a day or two later. 3 business
| days is pretty typical. More if they're high risk.
|
| You complain, make a statement under penalty of perjury that
| it's Unauthorized. Your bank sends a return (R10 or one of
| the other shades) to the Fed. The fed debits the originating
| bank, and sends them the return message. You've got your
| money back, and it's the originating bank's problem.
|
| The originating bank then has a potential problem. They go
| after the company that initiated the debit. Depending on
| things, that might be a company or a 3rd party payment
| processor. If it's a 3pp, then they probably still have money
| from that originator or another, and now it's their problem.
| They may have a reserve or rolling settlement against such
| things.
|
| But generally, it's the fact that there's a trusted third
| party (The Fed) that makes sure that banks pay up on returns
| that makes it not your problem.
| fortran77 wrote:
| I've done ACH for amounts over $1,000,000. I was expecting
| to get a call from the bank, etc, but it just worked. I was
| the owner of both accounts, but they were with different
| institutions.
| Asafp wrote:
| This is why Plaid is so successful, it allows banks/fintech
| companies to validate that the information on the counterparty
| account matches what you claim, that it has sufficient amount,
| name and email matches. The bank can also decide if he wants to
| deny an ACH debit or do a manual review of it, for example
| above a specific amount of if its the 1st ach debit. Also the
| clearing days (when you will see money in your bank) will be
| different depending on different risk factors. You can read
| more here about how to mitigate ACH fraud with tools such as
| Plaid - https://guides.unit.co/fraud-and-disputes/ disclaimer -
| I am an engineer at Unit.
| c7DJTLrn wrote:
| Recently used Plaid to deposit into Kraken and I was amazed,
| it's like magic.
| ipython wrote:
| How reversible is it? I received my first fraud call where the
| scammers were asking for check payment - they wanted the
| routing number and check number to get payment (about $400 or
| so- it was for a "cable refund service").
|
| I was curious if I could track them down by giving them real
| info but wasn't convinced enough about the reversibility of it
| to risk basically my entire checking account.
| jessaustin wrote:
| _...about $400 or so..._
|
| Is there any particular reason to believe that the number the
| scammers said they were going to take was the actual number
| they were going to take?
| horsawlarway wrote:
| This is the best answer here so far (and also a reasonably good
| explanation of why, at least in my opinion, crypto is still
| completely non-viable as a real medium of exchange).
|
| The key is that there is a process for reconciliation. It IS
| NOT ENOUGH to simply have a ledger - you also need a mechanism
| for enforcing that the ledger matches reality. And reality is
| complicated, filled with reasonable disputes over terms and
| deals (in the best case) and outright fraud and theft (in the
| worst case).
|
| A given party may be able to temporarily pull money from you
| with two numbers, but the process around reconciliation makes
| it so that you, the customer, are protected from the actions of
| the mediary (because at the end of the day, they're selling
| this service, and are responsible for their actions in relation
| to providing credit). This incentivizes those institutions to
| be careful, protect their reputation, and avoid taking on
| obvious risks.
|
| Essentially - the system is structured in a way where
| incentives align to prevent abuse. And entry into the playing
| field is expensive and limited enough that institutional
| reputation matters.
| kevin_nisbet wrote:
| > And reality is complicated, filled with reasonable disputes
| over terms and deals (in the best case) and outright fraud
| and theft (in the worst case).
|
| Yep, and also methods to bring forward and rectify those
| disputes, as in the courts. I always wonder how many court
| orders each day need to go through the banks for enforcement,
| through wage garnishment, sheriff's auctions, power of
| attorney, etc.
| theonething wrote:
| What about international ACH transfers? What if an overseas
| bank just claims they didn't receive your transfer when
| they did?
| yuvadam wrote:
| There are valid use cases for both types of transactions:
| those that require an option for chargeback as well as those
| that must be settled with finality.
|
| The difference is that while crypto can do both, the legacy
| finance system cannot.
| blatherard wrote:
| I think wire transfers are generally irreversible.
| oarsinsync wrote:
| How do you do a chargeback with Bitcoin? Or is that a
| different cryptocurrency feature?
| DennisP wrote:
| One way to get something like chargeback is 2-of-3
| multisig. The transaction has to be signed by any two of:
| sender, receiver, and a neutral arbitrator. If sender and
| receiver agree, the arbitrator never has to hear about
| that transaction.
| cowtools wrote:
| There is a feature in bitcoin called replace-by-fee
| (https://en.bitcoin.it/wiki/Replace_by_fee). But that is
| not completely analogous to a refund because vendors will
| wait many blocks before accepting a transaction (to
| prevent finney attack).
|
| If you want to have a third party mediate the exchange,
| you can use a multi-signature transaction
| (https://monerodocs.org/multisignature/). For example you
| send the cryptocurrency to a 2-of-3 address where the
| mediator, the vendor, and the customer each hold a key
| and two of them are needed to move the funds (the
| mediator sides with either vendor or customer, or the
| vendor and customer both side against the mediator). Or
| you can send the cryptocurrency to a 2-of-2 address,
| which allows the customer to permanently withhold the
| funds from the vendor at the cost of withholding some
| funds from themself that they put down ahead of time,
| like an escrow that is locked in case of dispute.
| ch33zer wrote:
| You cannot, which is what grandparent was complaining
| about.
| kube-system wrote:
| Yes, there are valid use cases for irreversible payments,
| like closing on a home. Banks _do_ have solutions for this:
| wire transfers. Which is what you'll use if you buy a house
| in the US.
| Asafp wrote:
| Can you share some examples or use cases of transactions
| that must be settled with finality?
| brewdad wrote:
| Hiring a hitman?
| sp332 wrote:
| If I sell someone a meal and they eat it, I really don't
| want that money to leave my account, because I have no
| recourse on my side.
| tehlike wrote:
| If the meal is bought with stolen funds...
| cowtools wrote:
| then the cook should be left uncompensated for their
| work? There is no "fair" outcome in this situation, so
| you should at least make the system fail in a reliable
| way.
| edgyquant wrote:
| Okay so what if you give them the wrong meal and they
| want money back?
| cowtools wrote:
| Then the dissatisfied customer throws a fit and warns
| their peers that the vendor isn't trustworthy.
|
| There is an asymmetry here because anyone can be a
| customer but not everyone can be a vendor- that requires
| a certain level of reputation and upfront investment. So
| it is more risky for a vendor to scam a customer than the
| other way around.
| josephh wrote:
| Thank goodness that the merchants that I do deals with do
| not force me to pay with cryptocurrency.
| cowtools wrote:
| I don't know, I hear all the time about people buying
| things on amazon or something and when it arrives it's
| just crap and you can't get a refund. At the end of the
| day, getting a refund is not about the payment method, it
| is about your business relationship with the vendor.
|
| Cryptocurrency transactions require high trust in the
| sense that they cannot be refunded, but they also require
| low trust in the sense that the vendor cannot possibly
| steal any more money than what you sign them.
| amerkhalid wrote:
| Happened recently, ordered pizza but they delivered to
| wrong address. Called them they wanted to deliver pizza
| again but it would have been too late. So they refunded
| the transaction, though seemed a little reluctant.
|
| My guess is that if I had no option to do a chargeback,
| it would have been harder to get a refund then.
| grlthng wrote:
| If you are a merchant selling goods and services for
| money, and had the choice between transactions with
| finality and without, you will always chose transactions
| with finality.
| dllthomas wrote:
| Not always. If customer fraud is low and customer
| wariness is high, you might well find that providing
| customers the safety of the option to reverse the charge
| gets you enough more money that it nets you more overall.
| Even more so if "finality" of the technology means that
| users instead turn to the courts to dispute your charges.
|
| There _is_ a narrow sense in which the merchant "always
| prefers finality" but it isn't the relevant sense.
| kube-system wrote:
| If customers demand reversible transactions, you will
| choose reversible transactions or you will not have
| customers.
|
| There are, for instance, no longer many mainstream online
| merchants who accept only irreversible transactions.
| There once was a time when online transactions were
| primarily paid via money order, but PayPal and credit
| card processing has made that obsolete.
| scarface_74 wrote:
| When was this time that online payments were done with
| money orders? Some of the earliest online merchants that
| were associated with AOL and Prodigy accepted credit
| cards. Amazon definitely accepted credit cards from day
| one.
| kube-system wrote:
| In the mid to late 90s many retailers online operated
| like mail-order catalogs with catalogs delivered via
| http. Many of them were mail-order businesses first, and
| so they accepted payments for online purchases the same
| way they did for their majority of their customers.
|
| This was also normal for eBay payments at the time.
|
| There were, of course, a few that did accept credit
| cards, but many people were weary about using those
| features because very little of the web used HTTPS at the
| time. Even Amazon accepted money orders for this reason.
| cowtools wrote:
| The Silk Road.
|
| But in all seriousness, if you are a vendor then any
| purchase by a customer that is not associated with a
| legally accountable entity must be settled with finality,
| because you have no way of preventing charge-back fraud
| yourself.
|
| In cryptocurrency marketplaces, the customers vet the
| vendors, not the other way around. This is because the
| vendors have a higher upfront investment in their
| business and reputation. The customers are not expected
| to maintain a reputation (for sake of their privacy) or
| an investment (outside of an multisig escrow) so any
| attempt to vet them is prone to sybil attack.
|
| The process of vetting customers is usually assumed by
| some monopolistic intermediary like PayPal. These
| companies are able to vet customers by implementing a
| mass surveillance system.
| rlpb wrote:
| Twice I've sold an old car to somebody who answered my
| ad. I wanted cash on collection only, because I was
| selling the car to someone I didn't know, couldn't
| reliably trace and therefore could not trust. If they'd
| reversed the payment afterwards, I'd have been down a
| car.
|
| Both parties to this kind of transaction understand why
| finality is required, and don't have a problem with it.
| It's a second hand "sold as seen" transaction. The buyer
| knows where the seller likely lives. The seller doesn't
| know anything about the buyer. Neither party typically
| carry that kind of cash around, so there are two trips to
| the bank (with their own risks) that could be saved if
| there were some sort of easier digital equivalent.
| sverhagen wrote:
| If they'd have turned the corner to see the engine fall
| out from underneath the car, while you'd have already
| strolled off the scene with the money, they suddenly
| wouldn't be so happy with finality. I think finality in
| transactions is more something about "the nominal case".
| If I'm a transaction processor with significant volume, I
| would like to reach some final state without too much
| intervention, but I can still handle the exceedingly-rare
| exceptions with (expensive) humans. Where that point lies
| differs per application, also dependent on what kind of
| service I'm wanting to deliver.
| theonething wrote:
| What if the fraudulent account is emptied? Then it seems
| there's no money to reverse.
| ohiovr wrote:
| I'd like to know too.
| cronokirby wrote:
| It does sometimes get abused, but such abuses fall under wire
| fraud laws, which carry heavy punishments.
|
| So, the legal system is the prevention mechanism for abuse
| here.
| cududa wrote:
| Also, the accounts that you withdraw from are tied to very
| real identity verification. You'd have to launder the money
| reallllll fast to make off with it
| ohiovr wrote:
| That is kind of scary. If some dug through my trash and found
| a torn up voided check they could withdraw my whole account.
| I don't really have enough money to hire lawyers and I'm not
| sure what police could do and besides I'd be broke.
| HeyLaughingBoy wrote:
| About 15 years ago a company kept taking money out of my
| checking account via ACH every two weeks. It was a large,
| well-known company, but I had never done business with
| them. I contacted them and the only answer I could get was
| "well, if we have your information, you must have
| authorized it, so I can't help you. Besides, you don't have
| an account with us, so I can't stop it."
|
| dafuq?
|
| So I went to my local bank branch during lunch and
| explained the situation. The bank manager told me that she
| could stop it immediately, and reverse all the transactions
| to date, but since it was recurring, the only way she could
| block future transactions (outside a 6-month window) would
| be to close my account and open another one.
|
| We agreed to do that.
|
| Literally as she was going through the process, another of
| these phantom debits showed up. Got all my money back, had
| to change checking account #'s and never found out how it
| happened. I can only assume that the next time PayChex
| tried to debit my account and it bounced, they figured out
| their mistake.
|
| But hey, thanks for the absolutely useless customer
| support! I guess it only works if you're actually a
| customer.
| mousetree wrote:
| IIRC your bank could've returned the ACH with an R07
| return code which would've told the Paychex to suspend
| any recurring transactions.
| smsm42 wrote:
| Not really, they couldn't if you pay attention to what
| happens to your account. First of all, they'd have to gain
| access to ACH initiator - for which criminals do have some,
| but it's not likely those will be easy to access to a
| random trash digger. Those have non-trivial costs to
| establish and easy to burn and get prosecuted. And, ACH
| transactions are reversible for a long time, so unless
| you're in a coma, you keep your money at the cost of some
| inconvenience and some waste of time. You won't need any
| lawyers for that, unless a) you have an extremely shitty
| bank that's not afraid to lose their banking license, or b)
| you want to do more than getting your money back for some
| reason.
|
| If they have access to a very quick and efficient cash out
| system, they might offload the costs onto some chump (see
| various "cashback" scams) but it's not trivial to make this
| scheme work. It _can_ work, so shredding your voided checks
| is highly recommended, but it 's not as trivial as finding
| the check, coming to a bank and saying "I'm that guy it
| says here, give me all my money now, in small bills
| please".
| esotericimpl wrote:
| nemothekid wrote:
| > _I don 't really have enough money to hire lawyers and
| I'm not sure what police could do and besides I'd be
| broke._
|
| You would call your bank and they would reverse it. You
| would have your money back in a business day or two. That's
| why ACH isn't "abused".
|
| What would be more worrying if some multinational company
| accidentally debited your account. That would be harder
| because your bank would likely just side with the
| multinational who inadvertently stole your money. However,
| I don't think that is a weakness that exists solely with
| ACH.
| happyopossum wrote:
| It's wire fraud - the feds would go after the perp, and
| your bank would reverse the transaction.
___________________________________________________________________
(page generated 2022-08-29 23:01 UTC)