To send ACH information securely, put your routing number, account number, account type, and bank name into an encrypted file or a secure portal, verify the recipient through a channel other than the one that made the request, and share any password by a separate method such as a phone call. Plain email, texted screenshots, and unprotected attachments are the openings fraudsters look for, so the goal at every step is to keep your data unreadable to anyone but the person you intended to reach.
What an ACH Transfer Actually Needs From You
Four pieces of information move an ACH payment: the name of your bank, its nine-digit ABA routing number, your account number, and whether the account is checking or savings. The routing number identifies the bank; the account number identifies you within it.1American Bankers Association. ABA Routing Number
You can pull both numbers from the bottom of a paper check, from your online or mobile banking portal, or from a prefilled direct deposit form many banks let you download after login.2Nacha. Direct Deposit Without a Voided Check? Absolutely! If you can’t find them, call your bank and ask after they verify your identity.
Before you share those numbers, know what the other side plans to do with them. In an ACH credit, the sender pushes money into your account — a paycheck deposit is the common example. In an ACH debit, the other party pulls money out, which is how subscription autopays work. Authorizing a debit is the higher-risk direction because it gives the recipient standing permission to take funds. Federal law requires any recurring preauthorized debit from a consumer account to be authorized in writing or by equivalent electronic signature, and the company must give you a copy.3eCFR. 12 CFR 1005.10 – Preauthorized Transfers A verbal-only setup is a warning sign.
Encrypt the Data Before You Send It
Standard email is not private. Messages travel through multiple servers, and any of them can be a leak point. Encrypting the file itself, not just the connection, is what protects you.
Password-Protected PDF
The simplest approach is to put your account details in a PDF and apply AES password protection through Adobe Acrobat or a free alternative. Send the file one way and the password another. If the PDF goes by email, share the password by phone or text. Someone who intercepts the email cannot open the file without the second channel.
Secure File-Sharing Portals
Many employers, payroll providers, and financial institutions run secure portals or SFTP connections built for exactly this exchange. You get an invitation link, create an account with multi-factor authentication, and upload the document inside the portal. Nothing sensitive touches your inbox. If the party asking for your ACH data offers a portal, use it.
End-to-End Encrypted Email
Services like ProtonMail and Tutanota encrypt messages so that only the sender and recipient hold the decryption keys. If both sides use such a service, this works. Gmail and Outlook do not provide end-to-end encryption by default, so attaching an unprotected document to a regular email is not secure even if the connection uses TLS.
NACHA’s data security rules require large ACH originators and third-party processors handling more than two million entries a year to render stored account numbers unreadable through encryption, truncation, or tokenization; passwords alone don’t meet the standard.4Nacha. Supplementing Data Security Requirements The rule is aimed at high-volume processors, but it’s a reasonable baseline to expect from any company asking you to hand over banking details.
Verify Who Is Actually Asking
Strong encryption doesn’t help if you send the file to an impostor. Business Email Compromise schemes, where a fraudster poses as a vendor, employer, or executive to redirect payments, are one of the most common ways ACH data gets stolen.
Confirm Through a Separate Channel
If a request arrives by email, don’t reply to it with your data. Call the person or company using a number you already have on file — not one printed in the email. For an employer, go through HR or accounts payable directly. This out-of-band step is the single most effective anti-fraud move you can make.
Red Flags in the Request Itself
A 2016 FinCEN advisory developed with the FBI and U.S. Secret Service listed warning signs that an emailed payment request may be fraudulent:5FinCEN. FinCEN Advisory – FIN-2016-A003
- A sender address that closely resembles a known contact but has one character changed, added, or deleted.
- A request to route payment to a familiar name but with new bank account details.
- Messages marked “Urgent,” “Secret,” or “Confidential,” or pressure to act before you can verify.
- A beneficiary you have no prior history with, receiving an amount similar to what you normally pay a known vendor.
- Instructions attributed to an executive or attorney that nobody at the company can independently confirm.
Wire fraud carries federal penalties up to 20 years in prison, or 30 years when the scheme affects a financial institution.6Office of the Law Revision Counsel. 18 USC 1343 – Fraud by Wire, Radio, or Television
If You’re the One Receiving ACH Details
When you’re collecting ACH information from an employee or vendor, ask for a voided check, a bank verification letter, or a screenshot from the account holder’s online banking showing the routing and account numbers. What matters is that the information comes from the bank’s own records, not a free-form message.
Send, Confirm, and Validate
Once the file is encrypted and the recipient is verified, send it through the channel you’ve chosen. For portals, upload the file inside the platform. For encrypted email, check the recipient’s address character by character before you press send. A single typo can drop your banking details in a stranger’s inbox.
After sending, contact the recipient by phone or text to confirm the file arrived and opened correctly. This closes the loop.
Micro-Deposits and Instant Verification
Many companies confirm your account by sending micro-deposits, small credits of less than $1 each, then asking you to report the amounts back to prove you control the account.7Nacha. Nacha Micro-Entry Rule The deposits can take up to five business days to post. NACHA rules require that any offsetting debits used to balance the entries not exceed the credits, so you should never see a net withdrawal during this process.
Instant account verification through a secure API is replacing micro-deposits at many companies. You log in to your bank through the service, and it confirms your routing and account numbers in seconds. If it’s offered, it’s faster and doesn’t require you to keep the account information around waiting for test deposits. NACHA rules require organizations initiating online consumer debits to validate first-use account information through micro-entries, a prenotification transaction, or a commercial validation service.8Nacha. Account Validation Resource Center
If Your ACH Information Is Compromised
Speed matters more than anything else here, because your liability under federal law depends on how quickly you report the problem.
Report Fast to Preserve Your Rights
For unauthorized ACH debits from a consumer account that don’t involve a lost or stolen card or access device, you have zero liability if you notify your bank within 60 days of the date it sent the statement showing the error. Miss that window and you can be responsible for unauthorized transfers that occur afterward.9Consumer Financial Protection Bureau. 12 CFR Part 1005 (Regulation E) – Section 1005.6 Liability of Consumer for Unauthorized Transfers Your bank then has 10 business days to investigate (20 for new accounts) and must provisionally credit your account if it needs longer.10Consumer Financial Protection Bureau. 12 CFR Part 1005 (Regulation E) – Section 1005.11 Procedures for Resolving Errors These consumer protections don’t apply to business accounts, which are governed by UCC Article 4A and the terms of your bank’s commercial agreement.11Legal Information Institute. UCC – Article 4A – Funds Transfer (1989)
Stopping Debits Already Authorized
To stop recurring ACH debits, revoke the authorization in writing with the company and keep a copy. Separately, place a stop payment order with your bank at least three business days before the next scheduled debit. Your bank may take the request orally but can require written confirmation within 14 days; if you don’t send it, the stop order can expire.3eCFR. 12 CFR 1005.10 – Preauthorized Transfers Stop payment fees commonly run $15 to $36. Stopping the payment does not cancel any underlying contract, so notify the company as well.12Consumer Financial Protection Bureau. You Have Protections When It Comes to Automatic Debit Payments From Your Account
Steps After a Suspected Compromise
- Contact your bank immediately and ask about blocking ACH debits or closing and reopening the account under a new number.
- Place a free one-year fraud alert with any one of Equifax, Experian, or TransUnion. The bureau you contact must notify the other two.13Federal Trade Commission. Data Breach Response: A Guide for Business
- Consider a free credit freeze, which blocks creditors from pulling your report at all.
- Review your statements daily for at least 60 days so anything unauthorized gets reported inside the Regulation E window.
- File a report at IdentityTheft.gov for a personalized recovery plan, and file with local police if funds were actually taken.
Financial institutions are required under the Gramm-Leach-Bliley Act to maintain safeguards protecting the security and confidentiality of customer information.14eCFR. 16 CFR Part 314 – Standards for Safeguarding Customer Information If the company that received your ACH data failed to protect it, that failure can matter in any dispute over who absorbs the loss.