Four ways a check goes bad, and why the difference is not academic.
A forged drawer's signature means the check came off the account holder's own checkbook, or a convincing imitation of it, and was signed by somebody else. Nothing on the face of it is wrong except the one thing that matters.
A forged endorsement leaves the front of the check entirely genuine. The check was written to a real payee for a real amount, and somebody else signed the back and deposited it. FinCEN found this the least common of the three main routes, and noted the range within it: "in some instances, perpetrators forged the intended recipient's signature and other times they simply signed their own name or applied an indecipherable signature and attempted to deposit it."
An alteration takes a genuine, properly signed check and changes it. FinCEN reports that "the payee line was the most frequently altered section, followed by the amount, which is typically made higher than the intended amount."
A counterfeit is manufactured. The stolen check is used as a template, and the routing and account information printed on it is enough to produce more. FinCEN's assessment of why this matters: "if counterfeit checks are not identified during the negotiation process, losses resulting from that initial stolen check can be significantly higher," because one stolen check becomes many.
What the reporting data actually shows. FinCEN's February to August 2023 analysis of mail-theft-related check fraud identified "three primary outcomes from perpetrators after stealing checks from the U.S. Mail: (1) altering and depositing the checks, (2) using the stolen checks to create counterfeit checks, and (3) fraudulently signing and depositing the checks." Measured across that period, "altered checks accounted for approximately 44 percent of the BSA reports, counterfeit accounted for 26 percent, and fraudulently signed checks were 20 percent, according to manual review of BSA reports." Those shares do not sum to a hundred, and FinCEN's own footnote explains why: a single report can describe several deposits using different methods.
The scale, with the years attached, because these are dated measurements rather than a running total. In its 2023 alert FinCEN recorded that "in 2021, financial institutions filed more than 350,000 SARs to FinCEN to report potential check fraud, a 23 percent increase over the number of check fraud-related SARs filed in 2020," and that "this upward trend continued into 2022, when the number of SARs related to check fraud reached over 680,000, nearly double the previous year's amount of filings." Narrowing to mail-theft-related cases in the six months from 27 February 2023, FinCEN "received 15,417 BSA reports related to mail theft-related check fraud associated with more than $688 million in transactions, which may include both actual and attempted transactions." The average amount reported per report over that period was $44,774 and the median was $14,215, a gap that says most incidents are far smaller than the average and a few are very large.
The deposit channel is chosen deliberately, and this is the most useful operational fact in the data. Among FinCEN's key findings was "reliance on avoiding human contact: many perpetrators utilized methods that avoid human contact, including check deposits via remote deposit capture (RDC) or at automated teller machines (ATMs) and opening accounts online rather than in person." A second route in the same report is worth knowing because it explains how a check made out to a company gets deposited at all: perpetrators "opened a new account at a financial institution that had either the same name as the intended recipient or a nearly identical name and deposited the check," and those accounts "were typically opened online with fraudulent or stolen identification information."
Where the checks come from, in the reporting FinCEN examined. That reporting is about the mail specifically. FinCEN records that the Postal Inspection Service "received 299,020 mail theft complaints between March 2020 and February 2021, a 161 percent increase compared with the previous 12 months," and describes criminals targeting "USPS blue collection boxes, unsecured residential mailboxes, and privately owned cluster box units," including through the theft of USPS master keys. Business checks are a particular target, FinCEN notes, "because business accounts are often well-funded and it may take longer for the victim to notice the fraud." The problem is not regional: the reporting "included subjects or branch activity in every U.S. state as well as Washington, D.C., and Puerto Rico."
Why the legal framework matters to a victim more here than elsewhere. Because Regulation E excludes paper checks, none of the federal electronic-transfer machinery is available: no statutory liability ceiling, no federal error-resolution clock, no obligation to provisionally credit an account while the bank investigates. The applicable rules come from state commercial law and from the deposit agreement, and the practical consequence is that the customer's own promptness in reviewing statements carries more weight than it would on a card dispute. The deadlines that follow from examining a statement are set out on the bank statement page and are the ones to read first.