Skip to content

Check Fraud

Check fraud is the use of a check to take money the taker is not entitled to, by forging a signature, altering a genuine check, or manufacturing a fake one. It is a paper-instrument crime, which means the federal electronic-transfer protections do not reach it.

Last reviewed by Steven Fox, CFP®, EA on

Quick Summary

  • There are four basic ways a check goes bad: a forged drawer's signature, a forged endorsement, an alteration of a genuine check, and an outright counterfeit.
  • Alteration is the most common. Across FinCEN's February to August 2023 review of mail-theft-related reports, altered checks accounted for about 44 percent of reports, counterfeits 26 percent and fraudulently signed checks 20 percent.
  • The volume is large and was rising fast. Institutions filed more than 350,000 suspicious activity reports flagging potential check fraud in 2021 and more than 680,000 in 2022.
  • The deposit channel is chosen to avoid a human. FinCEN found perpetrators favoring mobile and ATM deposits and accounts opened online rather than in person.
  • Federal electronic-transfer law does not apply. Regulation E expressly excludes transfers originated by check, so the rules governing a check dispute are state commercial law and the account agreement.

Definition

Check fraud is the use of a check, genuine or fabricated, to obtain money the person presenting it has no right to. It covers four distinct acts that get grouped under one heading, and the distinction between them decides both how the loss is allocated and how it is investigated: forging the signature of the person who wrote the check; forging an endorsement so that someone other than the intended payee can deposit it; altering a genuine check, usually the payee name and the amount; and manufacturing a counterfeit that was never a real check at all.

The federal financial regulator that collects the reporting treats it as a named category. FinCEN asks institutions to mark the "check fraud" box, field 34(d), on a suspicious activity report. Of the mail-theft variety specifically it writes that it "generally pertains to the fraudulent negotiation of checks stolen from the U.S. Mail," and that "generally, mail theft-related check fraud is the combination of two crimes: mail theft and check fraud."

One structural fact shapes everything a victim can do about it. A check is a paper instrument, and Regulation E, the federal rule that governs consumer electronic fund transfers, excludes from its definition of an electronic fund transfer "any transfer of funds originated by check, draft, or similar paper instrument." So the liability caps and error-resolution timetable that apply to a debit card or an unauthorized bank transfer do not apply here at all. What governs instead is state commercial law adopted from the Uniform Commercial Code, as each state enacted it, together with the deposit agreement the customer signed — and the deadlines that come with those sit on the bank statement page.

Advanced Explanation

Four ways a check goes bad, and why the difference is not academic.

A forged drawer's signature means the check came off the account holder's own checkbook, or a convincing imitation of it, and was signed by somebody else. Nothing on the face of it is wrong except the one thing that matters.

A forged endorsement leaves the front of the check entirely genuine. The check was written to a real payee for a real amount, and somebody else signed the back and deposited it. FinCEN found this the least common of the three main routes, and noted the range within it: "in some instances, perpetrators forged the intended recipient's signature and other times they simply signed their own name or applied an indecipherable signature and attempted to deposit it."

An alteration takes a genuine, properly signed check and changes it. FinCEN reports that "the payee line was the most frequently altered section, followed by the amount, which is typically made higher than the intended amount."

A counterfeit is manufactured. The stolen check is used as a template, and the routing and account information printed on it is enough to produce more. FinCEN's assessment of why this matters: "if counterfeit checks are not identified during the negotiation process, losses resulting from that initial stolen check can be significantly higher," because one stolen check becomes many.

What the reporting data actually shows. FinCEN's February to August 2023 analysis of mail-theft-related check fraud identified "three primary outcomes from perpetrators after stealing checks from the U.S. Mail: (1) altering and depositing the checks, (2) using the stolen checks to create counterfeit checks, and (3) fraudulently signing and depositing the checks." Measured across that period, "altered checks accounted for approximately 44 percent of the BSA reports, counterfeit accounted for 26 percent, and fraudulently signed checks were 20 percent, according to manual review of BSA reports." Those shares do not sum to a hundred, and FinCEN's own footnote explains why: a single report can describe several deposits using different methods.

The scale, with the years attached, because these are dated measurements rather than a running total. In its 2023 alert FinCEN recorded that "in 2021, financial institutions filed more than 350,000 SARs to FinCEN to report potential check fraud, a 23 percent increase over the number of check fraud-related SARs filed in 2020," and that "this upward trend continued into 2022, when the number of SARs related to check fraud reached over 680,000, nearly double the previous year's amount of filings." Narrowing to mail-theft-related cases in the six months from 27 February 2023, FinCEN "received 15,417 BSA reports related to mail theft-related check fraud associated with more than $688 million in transactions, which may include both actual and attempted transactions." The average amount reported per report over that period was $44,774 and the median was $14,215, a gap that says most incidents are far smaller than the average and a few are very large.

The deposit channel is chosen deliberately, and this is the most useful operational fact in the data. Among FinCEN's key findings was "reliance on avoiding human contact: many perpetrators utilized methods that avoid human contact, including check deposits via remote deposit capture (RDC) or at automated teller machines (ATMs) and opening accounts online rather than in person." A second route in the same report is worth knowing because it explains how a check made out to a company gets deposited at all: perpetrators "opened a new account at a financial institution that had either the same name as the intended recipient or a nearly identical name and deposited the check," and those accounts "were typically opened online with fraudulent or stolen identification information."

Where the checks come from, in the reporting FinCEN examined. That reporting is about the mail specifically. FinCEN records that the Postal Inspection Service "received 299,020 mail theft complaints between March 2020 and February 2021, a 161 percent increase compared with the previous 12 months," and describes criminals targeting "USPS blue collection boxes, unsecured residential mailboxes, and privately owned cluster box units," including through the theft of USPS master keys. Business checks are a particular target, FinCEN notes, "because business accounts are often well-funded and it may take longer for the victim to notice the fraud." The problem is not regional: the reporting "included subjects or branch activity in every U.S. state as well as Washington, D.C., and Puerto Rico."

Why the legal framework matters to a victim more here than elsewhere. Because Regulation E excludes paper checks, none of the federal electronic-transfer machinery is available: no statutory liability ceiling, no federal error-resolution clock, no obligation to provisionally credit an account while the bank investigates. The applicable rules come from state commercial law and from the deposit agreement, and the practical consequence is that the customer's own promptness in reviewing statements carries more weight than it would on a card dispute. The deadlines that follow from examining a statement are set out on the bank statement page and are the ones to read first.

How to Remember

Ask which part of the check is lying. The signature, the endorsement, the amount and payee, or the whole document. Those are the four kinds of check fraud, and they are investigated differently.

Used in a Sentence

“The bank's check fraud team could see the payee line had been altered, because the name on the check image was not the one in the business's own ledger.”

How It Works

  1. A check is obtained. Most commonly from the mail, but also from an unlocked mailbox, a business's outgoing post, a stolen wallet, or a checkbook taken from a home.

  2. It is made usable. Either by altering the genuine check, by using it as a template for counterfeits, or by simply endorsing and depositing it.

  3. It is deposited into an account the perpetrator controls, frequently by mobile or ATM deposit and often into an account opened online in a name resembling the real payee's.

  4. The funds are moved quickly. FinCEN records that once deposited, "the illicit actors often rapidly withdraw the funds through ATMs or wire them to other accounts that they control."

  5. The account holder discovers it, usually on a statement or when the intended payee reports never being paid, and reports it to the bank. Because this is a paper instrument, the rules that follow come from state commercial law and the deposit agreement rather than from the federal electronic-transfer rules.

A hypothetical, showing how one stolen check becomes several losses. Aurelio mails a check for $480 to his water utility. It is taken from a collection box.

The payee line is changed and the amount is raised to $4,800, then deposited by phone into an account opened online in a similar name. The direct loss on that item is $4,800 − $480 = $4,320 more than Aurelio ever authorized, and the utility is still unpaid, so a late fee follows.

The stolen check also carried Aurelio's account and routing numbers on its face. Three counterfeits are printed from it and negotiated at $2,150, $1,900 and $3,300 at other institutions before the account is closed, so the counterfeits alone total $2,150 + $1,900 + $3,300 = $7,350. Adding the altered item, the account has been hit for $4,800 + $7,350 = $12,150 from a single envelope.

That is why a stolen check is worth raising with the bank as an account problem rather than as one disputed item: the numbers printed on the check keep working until the account does not. All figures are hypothetical.

Pros and Cons

Check fraud has no upside, so what follows is what genuinely reduces exposure and what the protections do not reach.

What reduces exposure

  • Not putting outgoing mail in an unattended box. FinCEN and the Postal Inspection Service both identify collection boxes and residential mailboxes as the primary supply of stolen checks.
  • Writing fewer checks. Electronic payment for recurring bills removes the instrument entirely, and Regulation E does reach an electronic transfer.
  • Reviewing statements promptly and item by item. On a check, the customer's own examination of the statement is doing more work than it would on a card dispute.
  • Positive pay or a similar review service for a business account, where the bank matches presented items against an issued-check file.
  • Treating a stolen check as an account compromise rather than a single bad item, because the routing and account numbers printed on it survive the original theft.

What the protections do not reach

  • Regulation E does not apply to a check at all, so there is no federal liability cap and no federal error-resolution timetable.
  • The rules that do apply come from state commercial law and the deposit agreement, so outcomes vary by state and by the terms the customer signed.
  • Delay is costly. Deadlines run from when statements are made available, not from when the customer happens to look.
  • Nothing prevents a counterfeit being produced from a check that was negotiated normally, because the account details are printed on every check that leaves the house.
  • A business check is a bigger target than a personal one and tends to be noticed later.

People Also Asked

Answers to the most frequently asked questions.

What are the main types of check fraud?
Four. A forged drawer's signature, where someone signs the account holder's name; a forged endorsement, where a genuine check is signed over and deposited by someone other than the payee; an alteration, where a real check is changed, most often in the payee line and the amount; and a counterfeit, where a check is manufactured, often using a stolen genuine check as the template. FinCEN's analysis of mail-theft-related cases found alteration the most common, then counterfeiting, then fraudulent signing.
Does Regulation E cover check fraud?
No. Regulation E excludes from the definition of an electronic fund transfer "any transfer of funds originated by check, draft, or similar paper instrument," so the federal liability tiers and error-resolution deadlines that apply to a debit card or an unauthorized bank transfer do not apply to a check at all. What governs is state commercial law adopted from the Uniform Commercial Code, as each state enacted it, together with the deposit agreement. The bank statement page covers the examination deadlines that follow.
How common is check fraud?
Large and, over the years measured, rising. FinCEN recorded more than 350,000 suspicious activity reports flagging potential check fraud in 2021, a 23 percent increase over 2020, and more than 680,000 in 2022. Narrowing to mail-theft-related cases, it received 15,417 reports between 27 February and 31 August 2023 covering more than $688 million in transactions, a figure it notes "may include both actual and attempted transactions." Those are measurements of particular years rather than a current rate.
Why do criminals deposit stolen checks by phone or at an ATM?
Because those channels avoid a person looking at the document and at the depositor. FinCEN listed "reliance on avoiding human contact" among its key findings, naming remote deposit capture, ATM deposits and accounts opened online rather than in person. The same report describes accounts opened online in a name identical or nearly identical to the intended payee's, using fraudulent or stolen identification, which is how a check written to a business gets deposited by someone else.
Should I close the account if one of my checks was stolen?
It is worth raising with the bank immediately, because a stolen check is an account compromise rather than a single bad item. The account and routing numbers are printed on the face of every check, and FinCEN records that "victim checks are also counterfeited using routing and account information from the original, stolen check." Disputing the one altered item does nothing about the counterfeits that can follow from the same numbers.

Sources

AdviceOnly maintains high editorial standards to improve the quality and accuracy of our educational content. Content is written with the assistance of artificial intelligence tools following a rigorous quality assurance process, and periodically reviewed by credentialed and experienced human financial advisors. References used include government data, academic papers, interviews with industry experts, and reputable primary sources. You can learn more about our efforts to produce accurate content in our editorial policy.

  1. Financial Crimes Enforcement Network. "FinCEN Alert on Nationwide Surge in Mail Theft-Related Check Fraud Schemes Targeting the U.S. Mail" (FIN-2023-Alert003).
  2. Financial Crimes Enforcement Network. "Mail Theft-Related Check Fraud: Threat Pattern & Trend Information, February to August 2023."
  3. Code of Federal Regulations. "12 CFR Part 1005 — Electronic Fund Transfers (Regulation E)."

Have a question a definition can't answer?

Advice-only advisors answer questions like this for a transparent flat fee — no products, no commissions, no asset management.

Find an Advisor