An unauthorized or fraudulent payment came out of my business bank account — what do I do, and how do I record it?

Applies to: United States · Updated 2026-09-30

Call the bank or card issuer now, on a number you already hold, and if money left by transfer, ask on that call for a recall; check whether the item is unauthorized alongside, not first. Stop the card, login or authorization it used, and keep a dated record of every report. Consumer bank-account protections don't cover business accounts, and late reporting can forfeit recovery. Book the debit as posted, as a loss, and record any recovery separately, never early.

What should you do first, and in what order?

Take these steps the day you find the item. Steps 1 and 2 come first; the checks in step 3 run alongside them, never before:

  1. Call now. Phone the bank, or the card issuer for a card, on a number you already hold (the back of the card, your statement or the bank's app), never one from an email, text or caller. Report a suspected unauthorized item you are still checking.

    If money left by wire or online transfer, ask on this call for a recall. The FBI Internet Crime Complaint Center's undated page on account takeover says to request a recall or reversal, with a Hold Harmless Letter or Letter of Indemnity, as soon as fraud is recognized, and to report fraudulent wire transfers to IC3 as well.

  1. Stop the route. On the same call, have a card blocked and replaced, or cancelled outright if an insider holds it. For a login, ask the bank to suspend the users involved and cancel pending transfers you did not set up; save a screenshot or export of each payee and template created without you (name, account and routing numbers, who created it and when), then ask the bank to disable them.

    For an electronic debit, ask how to stop further debits. For a check, ask whether to close the account, and count your unused checks against the last number used, reporting any missing. Ask the bank what blocking does and does not undo; money that has already left is pursued through the recall, the claim or insurance.

  1. Classify it today. Run the checks in the next section. If the item proves legitimate, tell the bank at once.
  1. Make the formal report. Ask what form it must take and by when, what the bank will do with the account meanwhile and how it will confirm the report, then give it in that form.
  1. Change credentials from a clean device. Reset the password and second sign-in factor of every banking, card and payment login that could have been exposed, as the account-takeover page advises. Work from a device not used for the compromised login, and stop banking on any device you suspect until it is checked. Remove recovery phone numbers or emails you don't control, and disable, rather than delete, users who should not have access, so their records survive.
  1. Preserve the evidence. Save the statement showing the item, the item or its image, the statements either side, online-banking activity and user records, the payee, template and vendor records as they stood, and every email, message and document connected with it. Set a suspect device aside without wiping it.
  1. Record every report. Note the date and time, channel, person, reference number and what you were told, and keep copies of what you sent and any acknowledgement: this is how you show you reported in time.
  1. Notify your insurer. If the business has crime, fidelity or cyber cover, read the policy's notice conditions today and follow them.

Is it really unauthorized, or something else?

Search invoices, receipts and email for the amount and date as well as the name shown; ask everyone who holds a business card, checkbook or banking login; and list the business's subscriptions and standing authorizations. Then place the item:

If it turns out to beThen
A legitimate charge under a name nobody recognizedTell the bank, match it to its invoice and record it normally.
The same charge posted twiceAsk the payee to reverse one, or else ask the bank or issuer about a dispute.
A recurring payment the business agreed to and forgotRecord it; to end it, cancel with the payee and ask the bank how to stop further debits.
A payment someone inside the business made within their authorityRecord it normally; if they exceeded it, see the insider section.
A payment the business sent after being deceivedAsk at once for a recall, or a stop-payment order on a check not yet paid, and see below.
A payment nobody in the business made or approvedTreat it as unauthorized and finish the steps above.

Why don't consumer protections apply, and what starts your clock?

The CFPB's Regulation E covers an account "established primarily for personal, family, or household purposes", so an account established primarily for business purposes, even a sole owner's, falls outside it. For checks and funds transfers, the rules come from your state's enactment of the Uniform Commercial Code, which the Uniform Law Commission calls state law, not federal. The sections below are California's, with the uniform code's number in parentheses; check your own state's version and your account agreement.

What if it was a business card?

For a business credit card, Regulation Z's official interpretation of section 1026.3 applies the limits on liability for unauthorized use to all credit cards, even for otherwise exempt business-purpose credit. Section 1026.12 defines unauthorized use as use by someone other than the cardholder "who does not have actual, implied, or apparent authority for such use, and from which the cardholder receives no benefit". It caps your liability for unauthorized use at the lesser of $50 or what was obtained before you notified the issuer, and notice may be given in person, by telephone or in writing. An issuer of 10 or more cards for your employees' use may agree with the business on liability for unauthorized use without regard to these limits; read your card agreement.

A business debit card draws on the deposit account, and section 1026.12's limit is written for credit cards, so that limit does not set a business debit card's position. Read the card and account agreements and ask the bank on the first call what you can recover and by when.

What if it was a transfer ordered in the business's name?

For a wire or other transfer, California's section 11204 (4A-204) requires the bank to refund, with interest, to the extent it is not entitled to enforce payment, a payment order it accepted that was not authorized and not effective as yours under section 11202 (4A-202), or not enforceable against you, in whole or in part, under section 11203 (4A-203). You lose the interest, not the refund, if you fail to exercise ordinary care to determine that the order was not authorized and to notify the bank of the relevant facts within a reasonable time not exceeding 90 days after receiving its notification that it accepted the order or debited your account; your agreement may fix that time, as section 1302 allows. Separately, once the bank has been paid from your account for an accepted order issued in your name and you have received notification reasonably identifying it, section 11505 (4A-505) bars you from disputing its right to keep the payment unless you object within one year after receiving that notification. Both clocks run from the bank's notification, not from your discovery.

What if it was a check?

California's section 4401 (4-401) lets a bank charge your account for an item that is properly payable, meaning authorized by you and in accordance with your agreement with the bank. Section 4406 (4-406) requires you to examine each statement or the returned items with reasonable promptness for payments not authorized because of an alteration or an unauthorized signature and, where you should reasonably have discovered one, to notify the bank promptly of the relevant facts. If the bank proves you did not, you cannot assert that item's unauthorized signature or alteration where it also proves the failure caused it a loss, nor the same wrongdoer's on any other item it paid in good faith before your notice and after you had a reasonable period, not exceeding 30 days, to examine and notify. If you prove the bank's failure to exercise ordinary care in paying contributed to loss, the loss is shared; if you prove it did not pay in good faith, that bar does not apply. Whatever either side's care, an unauthorized signature or alteration you do not discover and report within one year after the statement or items were made available to you is barred. Section 4103 (4-103) lets an agreement vary these rules within limits, so read the period your deposit agreement sets.

What if another company pulled an electronic debit?

For an electronic (ACH) debit a company took under an authorization the business never gave, report it to the bank as unauthorized the day you find it, and on that call ask how long a business account has to report such a debit, from what date that period runs, and what form the report must take; check the answer against your account agreement.

What if the business sent the payment after being deceived?

A payment the business sent because a false invoice, spoofed email or impostor asked for it is not an unauthorized debit. California's section 11202 makes a payment order the authorized order of the person identified as sender if that person authorized it or is otherwise bound by it under the law of agency, so section 11204's refund duty does not reach it. The route is the recall requested in step 1.

To close the route, save a copy of the payee record and any template showing the account details the impostor supplied, then remove those details from them, so no later payment follows them. How to handle a vendor's request to change its bank details is a separate question, listed below.

What if a valid login or someone inside the business made it?

For a transfer sent through the business's own login, California's section 11202 makes an order received under the security procedure agreed with the bank effective as yours, whether or not you authorized it, if the procedure is a commercially reasonable method of providing security against unauthorized orders and the bank proves it accepted the order in good faith and in compliance with its obligations under the procedure and any agreement or instruction of yours, evidenced by a record, restricting acceptance. Section 11203 lets an express agreement with the bank, evidenced by a record, limit how far the bank may enforce or keep the payment, and also lets you shift the loss back by proving the order was not caused, directly or indirectly, by a person entrusted at any time with duties to act for you on payment orders or the security procedure, or by someone who obtained access to your transmitting facilities or obtained from a source you control, without the bank's authority, information facilitating a breach of the procedure, however obtained and whether or not you were at fault. Read your agreement for any such limit. A login taken from the business's own staff or devices can therefore leave the loss with the business.

Regulation Z's official interpretation of section 1026.12 says a cardholder who gives someone a card and authority to use it is liable for their transactions beyond that authority unless it has notified the issuer that the person's use is no longer authorized. So if an insider holds a business credit card, tell the issuer at once and have it cancelled, not reissued to them; do the same for a business debit card, though that comment is written for credit cards.

Where an insider moved the money, end all their access at the same moment: banking and payment-app logins, business cards, shared passwords they knew, their phone or email as a recovery contact or second factor on any business login, and any connected app or key they set up. Save activity records, emails and approvals before any account is deleted, and review bank and card activity through your own login, not reports the person prepared. The bank claim may not be available. If the business holds crime or fidelity cover, check today whether its wording covers the person involved and follow its notice conditions; see the insurance section. Reading the books for theft over a longer period is a separate question.

How do you record the payment while the claim is open?

Record the debit as the bank posted it, at the full amount, to an expense account such as Loss from unauthorized payments, not netted against anything you hope to recover. Never delete it or change its date or amount: the ledger must match the statement, and the claim rests on the recorded outflow.

If the business sent the payment itself, it is already in your books: re-code that entry to Loss from unauthorized payments instead of entering it again. On accrual books, where it paid a vendor's bill, re-coding leaves that bill open in accounts payable; on cash-basis books nothing is recorded for the genuine bill until it is paid. Whether and when the business pays it is for the business and the vendor to settle, not a bookkeeping step. For an altered check you wrote, re-code it the same way if the payee was changed, or, if only the amount was raised, record as the loss what the bank paid above your written amount.

Deloitte's April 2025 On the Radar summary says a gain contingency cannot be recognized before it is realized or realizable, and that recoveries of recognized losses may be recognized when it is probable they will be received and the amount is reasonably estimable, but not in amounts exceeding the recognized losses. So carry no receivable until that test is met; whether a provisional credit or an insurer's acceptance meets it is a judgment for your accountant. Hold a credit the bank calls provisional or temporary in a liability account, Provisional credits held, until the decision is final, and set up Recovery of unauthorized payments and Insurance recovery as other-income accounts, apart from sales and the loss account.

Each entry below is made the day the bank posts a movement or gives its decision, so it is the same on cash-basis and accrual books, except that accrual books may record a recovery earlier once the test above is met. If your software imports bank or card transactions, assign each imported item to the accounts shown instead of posting a separate entry; doing both records the movement twice. On a business credit card, the entries run through the card's liability account instead of Bank. In the books, the loss stays in the year the debit posted; whether and when it counts for tax while a claim is open is a question for your tax adviser before you file.

How do you record each outcome?

In this example, a 4,800.00 transfer nobody in the business made leaves the account on 3 March and is reported that day; on 10 March the bank posts a provisional credit of 4,800.00.

DateAccountDebitCredit
3 MarchLoss from unauthorized payments4,800.00
3 MarchBank4,800.00
10 MarchBank4,800.00
10 MarchProvisional credits held4,800.00

The bank's final decision then takes one of three forms:

OutcomeAccountDebitCredit
A. Credit made final in fullProvisional credits held4,800.00
A. Credit made final in fullRecovery of unauthorized payments4,800.00
B. Part made final, part reversedProvisional credits held4,800.00
B. Part made final, part reversedRecovery of unauthorized payments3,000.00
B. Part made final, part reversedBank1,800.00
C. Claim denied, credit reversedProvisional credits held4,800.00
C. Claim denied, credit reversedBank4,800.00

Where no provisional credit was given, record a final credit as a debit to Bank and a credit to Recovery of unauthorized payments; a denial needs no entry. Loss from unauthorized payments keeps the full 4,800.00 in every outcome; the unrecovered amount, which the business bears, is that loss less Recovery of unauthorized payments: nil in A, 1,800.00 in B and 4,800.00 in C.

How does each stage show in the bank reconciliation?

Booked as each movement posts, the ledger and statement agree at every stage. Starting from 20,000.00 with no other activity:

StageStatement balanceLedger balanceReconciling item
Before 3 March20,000.0020,000.00None
Debit posted and booked15,200.0015,200.00None
Provisional credit posted and booked20,000.0020,000.00None
A. Credit made final20,000.0020,000.00None
B. 1,800.00 reversal booked18,200.0018,200.00None
C. 4,800.00 reversal booked15,200.0015,200.00None
C. Reversal on the statement, not yet booked15,200.0020,000.004,800.00 bank deduction to record

Deleting the debit instead would leave the ledger 4,800.00 above the statement from then on. Finding any other reconciliation difference is a separate question.

Can insurance or a bond pay, and how is that recorded?

Insurance is a separate route that matters most where the bank claim fails, as with a deceived payment, a valid login or an insider. Travelers' undated page on its fidelity and crime insurance, for example, describes cover including losses due to employee dishonesty, and insuring agreements that can protect against funds transfer fraud, computer fraud and social engineering fraud. Whether your own policy responds depends on its wording, and a report to the bank does not notify the insurer.

Record an insurance recovery in Insurance recovery, apart from any bank recovery, under the same Deloitte test; recoveries recognized before they are received cannot together exceed the loss recognized. Deloitte treats any excess as a gain contingency, so record an amount received above the loss, such as interest paid with a bank refund, when received in a separate account (interest in interest income). Hold a bank refund of an amount the insurer has paid apart until the insurer has been told. Continuing outcome C, the insurer pays 3,800.00 after a 1,000.00 deductible:

DateAccountDebitCredit
On paymentBank3,800.00
On paymentInsurance recovery3,800.00

The business then bears 1,000.00.

What should you change so the same route can't be used again?

Close the route the payment used, then the ones beside it:

  • Logins. Turn on multi-factor authentication (MFA) for every banking login, give administrative privileges only to trusted IT staff and key personnel, audit access regularly so former employees are removed, and don't use the computer that processes payments for casual browsing. The SBA's undated cybersecurity guidance advises each of these.
  • Approvals. The same guidance says to work with your bank on its most trusted tools and anti-fraud services. Ask the bank whether its online banking can require a second user, with their own login and second factor, to approve every outgoing transfer, every new or changed payee, and every change to users, their permissions or sign-in factors and the approval settings themselves, and turn all of these on where two or more people work in the business.

    If one login can still add a user or change the approval settings alone, that login can defeat the second approval, so ask the bank how to close that too. Where one person does everything, the checks that fit are a separate question.

  • Screening. Ask the bank which services it offers to screen checks and electronic debits before they post.

This guide is general information, not tax or legal advice. Confirm with a qualified professional before acting.

Sources
  1. Federal Bureau of Investigation, Internet Crime Complaint Center — Account Takeover Fraud (ATO), undated
  2. Consumer Financial Protection Bureau — Regulation E, 12 CFR 1005.2: Definitions, current version, undated
  3. Uniform Law Commission — Uniform Commercial Code, undated
  4. Consumer Financial Protection Bureau — Regulation Z, 12 CFR 1026.3: Exempt transactions, with official interpretation, current version, undated
  5. Consumer Financial Protection Bureau — Regulation Z, 12 CFR 1026.12: Special credit card provisions, with official interpretation, current version, undated
  6. California Legislative Counsel — Commercial Code, Division 11 (Funds Transfers), Chapter 2: Issue and Acceptance of Payment Order, sections 11202 and 11203 as amended by Stats. 2023, Ch. 210, effective January 1, 2024; section 11204 as amended by Stats. 2006, Ch. 254, effective January 1, 2007
  7. Legal Information Institute, Cornell Law School — U.C.C. - Article 4A - Funds Transfer (2012), 2012 text
  8. California Legislative Counsel — Commercial Code section 11505, added by Stats. 1990, Ch. 125
  9. California Legislative Counsel — Commercial Code, Division 4, Chapter 4: Relationship Between Payor Bank and Its Customer, section 4406 as amended by Stats. 2016, Ch. 277, effective January 1, 2017
  10. Legal Information Institute, Cornell Law School — U.C.C. - Article 4 - Bank Deposits and Collections (2002), 2002 text
  11. California Legislative Counsel — Commercial Code section 4103, amended by Stats. 1992, Ch. 914, effective January 1, 1993
  12. Deloitte — On the Radar: Contingencies, Loss Recoveries, and Guarantees, April 2025
  13. Travelers — Fidelity & Crime Insurance, undated
  14. U.S. Small Business Administration — Strengthen your cybersecurity, undated

Machine-readable: markdown · JSON