Protect Your Business from Payment Fraud and Account Takeover
As spoofing, impersonation scams, business email compromise (BEC), account takeover, and adversary-in-the-middle attacks continue to grow more sophisticated, strong internal controls, awareness, and preparation are more critical than ever.
The Threat
- $20.8 billion in reported US cybercrime losses in 20251
- 74% of surveyed organizations experienced attempted or actual business email compromise in 20251
- AI-empowered tools are enabling increasingly convincing social engineering scams
We continue to invest heavily in fraud prevention and detection tools to keep pace with the changing threat landscape. Effective fraud prevention, however, is a shared responsibility and requires layered defenses.
How to Recognize Impersonation Scams
Fraudsters have become increasingly effective at impersonating, or "spoofing," bank personnel. A typical impersonation scam may involve:
Inbound Contact
- A fraudster calls, texts, or emails claiming to be a bank employee, often from a Treasury Management or fraud team.
- Caller ID information, phone numbers, email addresses, and even linked websites may appear legitimate.
- Before making contact, the fraudster may have gathered convincing information about your organization or accounts from other sources.
Urgency
- The fraudster claims there is an urgent problem, such as suspicious account activity, a frozen account, or an allegedly fraudulent payment.
Sensitive Request
- The fraudster asks for a username, password, secure access code, token-generated code, or similar authentication information.
- The fraudster may also send an email or text message containing a link to a malicious website that closely resembles a legitimate website.
Account Takeover
- The fraudster uses the information obtained to access the account, change settings, add users, or initiate payments.
IMPORTANT REMINDER
United Community will never call, text, or email you to ask for a username, password, secure access code, token-generated code, or similar authentication information.
What to Do If You’ve Been Scammed
Stop and Report
If someone claiming to be from United Community contacts you under these circumstances:
- End the call or message immediately. Do not provide any information, click any links, or follow any instructions.
- Immediately call Treasury Management Support at 1-866-270-6100. Do not redial the number that contacted you or use a contact card or link provided in the call or message.
- Do not share usernames, passwords, secure access codes, token-generated codes, or account information.
- If a transaction may have been initiated, contact United Community immediately. Speed can be critical to recovery efforts.
After-Hours Reporting
If you cannot reach United Community after hours and suspect a fraudulent wire, ACH transaction, or other cyber-enabled crime:
- Complete an IC3 (Internet Crime Complaint Center) complaint as soon as possible at: https://complaint.ic3.gov/
- Filing an IC3 complaint does not replace contacting United Community as soon as possible.
- It does provide important information about the incident to the FBI.
What You Can Do Now
Establish Strong Internal Controls
Dual control and segregation of duties for ACH, wire, and administrative activity are critical tools for fighting fraud.
With dual control, one authorized user initiates a transaction or change, and a different authorized user independently reviews and approves it. This helps:
- Prevent one compromised employee, email account, device, or credential from becoming a single point of failure.
- Create a second opportunity to detect changes to beneficiaries, account numbers, payment amounts, or instructions before funds are released.
- Reinforce accountability by separating payment initiation from approval.
Contact Your Insurance Advisor
Cyber and commercial crime insurance can be important tools for limiting exposure to payment fraud. However, the scope of coverage, exclusions, and notice requirements vary, and your policies may require certain internal controls as conditions of coverage.
Regularly review your policies with a trusted insurance professional and ask:
- What types of payment fraud are covered?
- Does your policy require certain security procedures or controls, such as dual control, training, or security tokens, to qualify for coverage?
- If you are the victim of cybercrime, how and when do you provide required notices?
Follow Agreed Security Procedures
- Use the fraud prevention controls available for your Treasury Management services.
- Failure to follow agreed security procedures or refusal to implement offered security procedures, such as dual control, may result in your organization being financially responsible for losses from payment fraud.
Comply with Nacha's 2026 Fraud Monitoring Rules
All non-consumer ACH originators are required to establish and implement risk-based processes and procedures reasonably intended to identify ACH entries initiated due to fraud, including entries authorized under false pretenses.
These processes and procedures must:
- Be reviewed at least annually.
- Be updated as risks evolve.
For more information, visit: https://www.ucbi.com/2026-nacha-rule-changes
Fraud Readiness Checklist
We strongly encourage every ACH and wire origination customer to:
- Enable dual control for ACH and wire transactions.
- Separate payment initiation and approval responsibilities.
- Independently verify new or changed payment instructions using trusted contact information already on file.
- Establish appropriate transaction limits and review them regularly.
- Review user access promptly when roles change or employees leave.
- Never share passwords, tokens, or authentication codes.
- Monitor account activity and transaction alerts daily.
- Train employees to recognize spoofing, business email compromise, phishing, and other social-engineering tactics.
- Review cyber and fraud insurance requirements with your carrier or advisor.
We’re Here to Help
Contact our Treasury Management team to discuss tools that can help safeguard your accounts, including dual control and other fraud prevention services.
Email: [email protected]
Phone: 1-866-270-6100
Or contact your local banker.
Working together, we can strengthen your organization's defenses and prepare for threats as they evolve.
This information is general in nature and does not constitute legal, tax, accounting, cybersecurity, or insurance advice. You are encouraged to consult with competent legal, tax, accounting, cybersecurity, or insurance professionals based on your specific circumstances.
1Source: https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf