Most business owners assume their company bank account works like their personal one. If money leaves without permission, you call the bank, you file a dispute, and the bank makes it right. That assumption feels obvious. It is also the single most expensive misunderstanding we run into with clients, and owners usually discover it on the worst possible day.

This post is general information, not legal or financial advice. Account agreements and liability rules vary by bank, by account type, and by transaction type, and the only authoritative answer is the one your bank gives you about your accounts. What we can do is tell you what to ask. The good news: most of the effective defenses here already exist on your account and take one conversation to turn on.

Business Accounts Are Not Consumer Accounts

The consumer protections people have in mind come largely from Regulation E, the federal rule covering electronic fund transfers. Regulation E defines the accounts it covers narrowly. Under 12 CFR 1005.2(b)(1), an account means “a demand deposit (checking), savings, or other consumer asset account held by a financial institution and established primarily for personal, family, or household purposes.”

Read that last clause again. Personal, family, or household purposes. A business operating account is not established for those purposes, so it generally sits outside that definition. In practice, the protections that apply to your commercial account come primarily from the deposit agreement you signed with your bank, not from the consumer rule most people are picturing.

That does not mean you have no recourse. Banks work hard to recover funds, and many have policies that go beyond what is required. It means the answer depends on your agreement, on whether the security procedures your bank offered were in place, and on how fast you reported. Understand that before something happens. Ask your banker directly, and if the stakes are large, have your attorney read the agreement.

The Shape of the Attack

You do not need the technical details to defend against this, and we are not going to publish them. The shape is what matters. It usually starts with email. Someone gets into a mailbox at your company, at a vendor, or at a client. They read quietly for a while. They learn who approves payments, how invoices are worded, when payroll runs, and which vendors you would never question.

From there it goes one of two ways. Either a convincing request arrives asking for payment details to be updated, or the criminal collects enough credential and verification information to reach the banking side directly. Either way, the transfer looks legitimate, because from the bank’s view it was authorized through your normal process by someone who knew your normal process. Nothing trips an alarm.

The scale is real. In a 2024 public service announcement, the FBI’s Internet Crime Complaint Center reported that between October 2013 and December 2023, domestic and international exposed losses from business email compromise totaled more than $55 billion across 305,033 incidents. In a November 2025 announcement on account takeover fraud, the same agency reported more than 5,100 complaints and losses exceeding $262 million since January 2025. Most victims had email security. Very few had banking controls. We covered why the email layer alone keeps failing in understanding the surge in phishing attacks.

The Conversation to Have With Your Bank

Call your business banker and ask about each of these by name. Most are standard commercial banking products. Some are free, some carry a small monthly fee, and all of them are cheaper than one bad Friday.

  • Dual control on transfers. One person sets up a payment, a different person approves it. The FFIEC describes this plainly in its guidance on authentication and access to financial institution services and systems: “Controls are available to business customer to require more than one employee to authorize and approve certain transactions.” Highest value item on the list.
  • Approval limits and thresholds. The same FFIEC guidance points to “transaction controls, such as transaction value limits, restrictions on devices for adding payment recipients, limits on the number of transactions allowed per day.” If you never send a wire over $25,000, cap it there.
  • Positive pay. You send the bank a file of the checks you issued. The bank flags anything that does not match before it clears. Ask whether your bank offers a version for electronic payments as well.
  • ACH debit blocks and filters. A block stops electronic debits from hitting an account entirely. A filter allows only an approved list of originators. Most small businesses have at least one account that should never be debited by anyone.
  • Alerts on every transaction over a threshold. Set it low enough to be slightly annoying. The FBI’s 2024 announcement on business email compromise is direct: “Monitor your personal financial accounts on a regular basis for irregularities, such as missing deposits.” Alerts do that monitoring for you.
  • Who to call, and how fast. Get the direct number for the fraud desk, not the general line. Ask what their reporting window is. Write it somewhere that is not your email.

The FFIEC frames the idea behind all of this well: “Layered security incorporates multiple preventative, detective, and corrective controls, and is designed to compensate for potential weaknesses in any one control.” No single item above is sufficient. Together they are hard to get through.

What to Change on Your Side

Bank controls handle the money. These handle the access.

  • Use a dedicated machine or account for banking. One computer, or at minimum one separate user profile, used only for banking. No web browsing, no email, no software installs. This is old advice because it works.
  • Separate the banking credentials from everyday email. If the email address you use to reset your banking password is the same mailbox an attacker just read for three weeks, your reset process is theirs. Use a different address that is not published anywhere.
  • Turn on strong multi-factor authentication and leave it on. The FBI’s November 2025 public service announcement on account takeover fraud is blunt: “Enable two-factor authentication or MFA on any account possible. Never disable it.” Not all MFA is equal, which we broke down in YubiKey vs passkey vs MFA.
  • Reach banking sites through a saved bookmark. The same FBI announcement recommends you “use Bookmarks or Favorites for navigating to login websites,” warning that “MFA will not protect you if you land on a fraudulent login page.”
  • Verify payment changes by phone, on a number you already had. The FBI’s 2024 business email compromise announcement recommends you “use secondary channels and/or two-factor authentication to verify requests for changes in account information.” Never the number in the email.

If It Happens Anyway

Speed is the whole game. The FBI’s guidance is to “immediately contact your financial institution and request a recall of the funds,” then “file a complaint with www.ic3.gov as soon as possible.” Recoveries do happen. They happen for businesses that called in hours, not days. That is why the fraud desk number belongs on a printed card, not buried in a mailbox you may have just lost access to.

The Bottom Line

Do not assume your business account carries the protections your personal account does. Call your banker this week. Ask about dual control, approval limits, positive pay, ACH blocks and filters, and transaction alerts. Ask what your agreement says about unauthorized transfers and what your reporting window is. Then separate banking access from everyday email. That removes most of the paths this attack actually uses. Confirm the specifics with your bank, because the details differ everywhere.

If you want a second set of eyes on the technical side, we help Denton County businesses separate banking access, harden email against mailbox compromise, and build the verification habits that catch payment change requests before money moves. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).