Skip to main content
A $38.5 Billion Fraud Problem That Starts Before the TransactionFraud Typologies
5 min readFor Fraud Risk Managers

A $38.5 Billion Fraud Problem That Starts Before the Transaction

The Challenge

Your fraud operations team faces a significant issue: By the time a stolen check reaches your detection systems, the fraud is already underway. The check was stolen weeks earlier, digitized, and possibly sold multiple times on dark web marketplaces. Your institution only sees the endpoint of a chain that began in a compromised mailbox and moved through networks you can't observe.

Check fraud losses are staggering, estimated at $38.5 billion globally in 2025, with $33.6 billion in the United States. A single stolen check, once digitized, can be copied and reused across multiple actors and institutions. One compromise fuels dozens of fraud attempts.

Traditional fraud controls focus on the transaction layer, analyzing check images and flagging unusual deposit patterns. However, stolen check data circulates in underground forums long before it reaches a deposit. Your institution is blind to this upstream activity, reacting to fraud that's already in motion instead of preventing it from reaching accounts.

The Environment and Constraints

Your team operates within a payment ecosystem still reliant on paper checks. Despite digital alternatives, checks remain common for certain transactions, creating a persistent attack surface. The supply of compromised checks continues unabated.

Oversight findings revealed that 86% of audited USPS facilities lacked complete arrow key inventories, which provide access to multiple mail receptacles. Over three years, the Postal Inspection Service received more than 800,000 mail theft complaints. The infrastructure that moves checks is leaking them at scale.

Meanwhile, exploiting stolen checks has become easier. Research from Q6 Cyber shows criminals using AI-assisted tools to modify stolen checks. What once required specialized skills now requires minimal technical knowledge. As Greg Williamson from Nasdaq Verafin noted, checks are "still available, and availability is what swindlers want... AI is driving the ease of ability for criminals to enter that market."

Your existing controls weren't designed for this threat model. Consortium intelligence helps identify patterns across institutions, and behavioral analysis flags anomalies. But these capabilities don't address the fundamental visibility gap: They can't see what's happening in the networks where stolen check data is bought, sold, and prepared for exploitation.

Moving Detection Upstream

To effectively prevent fraud, your institution needs to move detection upstream. If stolen check data circulates on the dark web before reaching a transaction, you need visibility into those environments.

Integrate cyber threat intelligence into your fraud operations. This isn't about replacing existing controls. Consortium intelligence, behavioral analysis, and image analysis remain critical. Cyber threat intelligence adds a new layer: visibility into forums, fraud shops, and networks where compromised data is traded.

This integration requires operational changes. Fraud investigators need access to intelligence feeds that surface compromised check data before it's used. Monitor for specific indicators: account numbers in dark web listings, check stock in fraud shops, or discussions about targeting specific institutions.

Rethink investigation workflows. When cyber threat intelligence surfaces compromised data, proactively flag accounts, alert customers, or adjust monitoring thresholds before fraud attempts occur. The intelligence provides context that strengthens investigations and enables earlier intervention.

Results and Metrics

While specific metrics on fraud reduction aren't provided, the strategic shift is clear: from reactive fraud detection at the transaction layer to proactive risk identification in environments where stolen check data is operationalized.

Nick Pearson from Nasdaq Verafin described the operational value: "If the industry cannot completely stop checks from being stolen, the next best opportunity is to identify them once they appear where criminals buy, sell and operationalize stolen financial data."

This changes your institution's position. Instead of waiting for a fraudulent deposit to trigger alerts, you can identify compromised check data while it's still circulating in criminal networks, gaining lead time to act before fraud reaches accounts.

Continuous Improvement

Integrating cyber threat intelligence isn't a one-time task. It's an ongoing shift that requires continuous refinement.

You need tighter integration between cyber intelligence feeds and fraud case management systems. Manual processes for reviewing dark web intelligence and flagging accounts don't scale. Automation is necessary to surface high-priority indicators efficiently.

Establish clear escalation protocols. When cyber threat intelligence surfaces compromised data, what's the threshold for customer notification? When should you freeze accounts preemptively versus increasing monitoring? These decisions require policy frameworks that balance fraud prevention with customer experience.

Training is crucial. Fraud investigators need different skills to interpret cyber threat intelligence. Understanding how networks operate, how stolen data is packaged and sold, and what indicators signal imminent fraud requires domain knowledge that traditional fraud training doesn't cover.

Takeaways for Your Team

If you're responsible for check fraud prevention, you're operating in an environment where the fraud lifecycle begins long before the transaction. Stolen checks are digitized and distributed through networks you can't observe with transaction-layer controls.

Cyber threat intelligence closes that visibility gap. It won't replace your existing fraud detection capabilities, but it adds a critical upstream layer. You need to see where stolen check data is circulating before it reaches your institution.

Start by identifying intelligence feeds that surface compromised financial data relevant to your customer base. Not all dark web monitoring is equal. You need sources that track specific forums, fraud shops, and networks where stolen check data is traded.

Build integration points between cyber intelligence and your fraud operations. Investigators need actionable alerts when compromised data appears, not weekly reports to review manually. The goal is to flag accounts and adjust monitoring before fraud attempts occur.

Develop response protocols for different threat levels. What do you do when cyber intelligence surfaces a customer's account number in a dark web listing? When do you notify the customer versus silently increasing monitoring? These decisions need clear criteria and escalation paths.

Finally, recognize that this is a layered approach. Cyber threat intelligence complements consortium intelligence, behavioral analysis, and image analysis. As Pearson noted: "Effective check fraud prevention requires a layered approach that combines consortium intelligence, behavioral and image analysis, and investigative expertise. Cyber threat intelligence complements these capabilities by providing visibility into emerging threats on the dark web."

The $38.5 billion check fraud problem won't be solved by better transaction monitoring alone. You need to move fraud detection to where the fraud actually begins: in the networks where stolen check data is bought, sold, and prepared for exploitation.

You Might Also Like