Loading blog...
Check Fraud in 2026: Types, Red Flags, and How Banks Detect It
Hasan Kanchwala
|
July 31, 2026
|
5 minutes read

Check fraud is the manipulation, alteration, or counterfeiting of a paper or truncated cheque to move money the account holder never authorized. It is the oldest payment fraud still running, and in 2026 it is growing, not shrinking.
If you run fraud operations at a bank or NBFC, you already know the uncomfortable part. Cheque volumes are falling, but cheque fraud losses are rising, and your clearing team still reviews each leaf for a few seconds at best. One washed payee name that clears is a recovery case, a regulator question, and an angry account holder, all at once.
This guide covers the seven types of check fraud, the specific field on the cheque each one attacks, and how modern forensic detection actually works, in both the US and Indian clearing systems.
| Check fraud (definition) Check fraud is any act that manipulates a cheque to obtain funds illegitimately, including altering a genuine cheque’s payee or amount, counterfeiting a cheque from a real account’s details, forging the drawer’s signature, or presenting the same instrument multiple times. It applies to both physical cheques and truncated cheque images processed through systems like CTS in India. |
TL;DR
- Check fraud means altering, counterfeiting, forging, or re-presenting cheques to steal funds
- 63% of organizations faced check fraud in 2024, making cheques the most-attacked payment method
- FinCEN data shows most mail-theft check fraud starts with a genuine cheque, not a fake one
- The seven fraud types each attack a specific field: payee, amounts, signature, MICR, or the image itself
- A washed cheque usually passes signature review, because the signature is the one field left untouched
- Truncation (CTS) moved fraud from paper to pixels: splicing and cloning now beat ink checks
- India adds RBI-specific controls: Positive Pay for cheques of Rs 50,000+, and a strict no-alteration rule
- Detection that works runs field-level forensics on every cheque, not manual spot checks
See how automated cheque forensics works on your own cheques
Check fraud is rising in the one payment channel everyone stopped watching
The assumption is that cheque fraud is dying with the cheque. The reality is the opposite: attack rates have held or risen for five straight years while banks moved their fraud attention to UPI, cards, and wires.
According to the 2025 AFP Payments Fraud and Control Survey, 63% of organizations experienced attempted or actual check fraud in 2024. That keeps cheques the most-targeted payment method, a position they have held every year since 2020.
| 📊 63% of organizations faced check fraud in 2024 For a fraud-ops head at a mid-size bank, this means cheques remain your highest-frequency fraud surface even as they shrink as a share of payment volume. Source: Federal Reserve Financial Services, 2025 AFP Survey highlights |
The economics explain it. A stolen cheque needs no malware, no phishing kit, and no mule network to start. It needs a mailbox, a solvent account, and a clearing desk moving too fast to look closely. The same logic drives document fraud across banking workflows, and cheques are its most liquid target.
Document AI that Eliminates Manual Processing and Compliance Gaps
The seven types of check fraud, and the field each one attacks
Every cheque fraud type is an attack on a specific data-bearing field. Name the field, and you know what to inspect.


Visual 1: Seven types of check fraud, seven targets
Two of these deserve their own reading: check kiting exploits time rather than ink, and signature forgery is the only type most banks have a reference file to catch.
The pattern we see across clearing desks: reviews anchor on the signature because it is the only field with a reference image on record. The other fields have no ground truth on file, and that is precisely where alteration lives.
The Genuine-Leaf Problem: most check fraud starts with a real cheque
Here is the single most useful reframe in this space. Most cheque fraud is not counterfeiting. It is editing.
FinCEN’s 2024 mail-theft analysis found that after cheques were stolen from the mail, 44% were altered and deposited, 26% were used as templates for counterfeits, and 20% were fraudulently signed. About two in three deposited frauds used the genuine leaf itself, and even the counterfeit share was modeled on a stolen genuine cheque.
| 📊 $688 million in mail-theft check fraud in six months FinCEN received 15,417 reports from 841 financial institutions in its review period, averaging about $44,774 per report. The dominant method was alteration of genuine cheques, not counterfeiting. Source: FinCEN Financial Trend Analyses |

Visual 2: The Genuine-Leaf Problem (place inside this section)
This is why signature verification alone fails. A washed cheque passes signature review, because the signature is the one field the fraudster deliberately kept. Detection has to interrogate the fields nobody has a reference for: does the payee handwriting match the date and amount handwriting, do the words and figures agree, does the ink history look continuous.
How banks detect check fraud in 2026: the forensic checklist
Modern detection treats every cheque as a small forensic case, run automatically in seconds. This is the check sequence KlearStack runs on every cheque. If you are at the stage of comparing vendors instead, our guide to check fraud detection tools compares seven platforms side by side.
- Amount parity. The courtesy amount (figures) and legal amount (words) must match exactly.
- Alteration scan. Any correction on the leaf fails the cheque. Under RBI rules, a modified cheque requires a fresh leaf, full stop.
- Pixel forensics. For truncated or mobile-deposited images: splicing, cloning, and digital-edit detection on the file itself, the same discipline behind document tampering detection.
- Signature existence. Confirm a signature is physically present in the signature box before authenticating it.
- Signature authentication. Compare against the account’s master signature card.
- Handwriting consistency. One cheque written by two hands is the classic stolen-and-completed leaf.
- Positive Pay cross-reference. Match the presented date, payee, and amount against issuer-submitted data in real time.
- Washing indicators. Chemical alteration of payee or amount fields.
- Duplicate detection. The same instrument never clears twice.
- Pattern anomalies. With the bank’s transaction feed connected via the KlearStack API, presentation behavior that breaks the account’s history gets routed to review.

Visual 3: The ten forensic checks
Extraction accuracy matters here for one reason: you cannot verify a field you misread. That is why the underlying OCR layer in banking workflows has to hold up to 99% accuracy on handwritten fields before any forensic logic means anything.
Document AI that Eliminates Manual Processing and Compliance Gaps
India: CTS, Positive Pay, and the RBI’s zero-tolerance rule
The Indian clearing system changed the battlefield twice, and both changes moved fraud toward pixels and data.
- Cheque Truncation System (CTS): the physical leaf stops at the presenting bank; only the image travels. Fraud on truncated cheques is image fraud, which is why splicing and clone detection now matter more than ink analysis.
- Positive Pay System (PPS): the RBI mandates cross-checking presented cheques against issuer-submitted details for high-value cheques of Rs 50,000 and above. A payee mismatch surfaces before money moves, but only if the check actually runs on every instrument.
- The no-alteration rule: the RBI permits no corrections on a cheque. Any change means a fresh leaf. Operationally, this converts every detected alteration into an automatic return, with no judgment call needed.
The stakes keep climbing. Indian banks reported frauds worth Rs 48,021 crore in FY2025-26, per the RBI’s annual report data, even as case counts fell. Fewer, larger frauds is exactly the pattern a compliance officer at an NBFC should read as concentration risk.
In audit cycles after a fraud event, the question is never “why did the fraudster succeed.” It is “show me the record of what you checked.” Teams with no per-cheque audit trail fail that question even when they caught the fraud.
What changes when detection is automated
| Before | After |
|---|---|
| Seconds of eyeball review per cheque | Ten forensic checks on every cheque, every time |
| Signature is the only verified field | All data-bearing fields interrogated |
| PPS checked manually for high-value cheques | PPS cross-referenced in real time, every eligible cheque |
| Fraud found after the debit posts | Suspect cheques held before funds move |
| No defensible review record | Field-level audit trail per instrument |
The arithmetic is straightforward. An inward clearing desk reviewing 2,000 cheques a day at 20 seconds each spends over 11 person-hours on review. At a 95% straight-through rate, roughly 100 cheques a day reach a human, each arriving with the specific failed checks highlighted. That is under an hour of focused review, aimed only at the leafs that earned it.

Visual 4: The clearing-desk math
When you need this, and when you honestly do not
If your institution clears fewer than a few hundred cheques a month, or cheques are a legacy channel you are actively sunsetting, trained eyes plus PPS compliance may be proportionate. Automated cheque forensics earns its keep at clearing-desk volumes, in bank statement and instrument verification workflows, and wherever an alteration slipping through means regulatory exposure rather than a single write-off.
Deployment follows the standard KlearStack curve: pilot on your own cheques in under 30 minutes, accuracy hardening through UAT, and 95%+ straight-through processing within 90 days.
The field-level mindset wins
Cheque fraud is not one crime. It is seven distinct attacks on specific fields of a small document, and most of them start with a genuine leaf. Review the whole cheque and you will miss it. Interrogate every field, cross-check PPS, and log every verdict, and the fraudster’s cheapest attack becomes your fastest catch.
For a fraud-ops head, the transformation is concrete: every cheque forensically examined, suspects held before money moves, and a 95%+ straight-through rate that keeps the clearing desk fast while making it defensible.
FAQs
Is check fraud still a thing?
Yes, and it is growing. Checks were the most-attacked payment method in 2024, with 63% of organizations reporting attempted or actual check fraud. Falling cheque volumes have not reduced fraud, because stolen and altered genuine cheques remain cheap, low-skill attacks.
How long does a bank detect a fake check?
A counterfeit or altered cheque can surface anywhere from hours to several weeks after deposit, once it fails clearing or the account holder disputes it. Automated forensic screening moves detection to the moment of presentment, before funds are released.
What happens if a fake check is deposited?
The deposit may initially show as available, but once the cheque fails verification the bank reverses the credit. The depositor is typically liable for the withdrawn amount, and the case may be referred for investigation depending on intent.
Can someone steal money from a check?
Yes. A stolen cheque can be washed and rewritten to a new payee, used as a template for counterfeits, or completed and signed if taken blank. This is why alteration and handwriting checks matter more than signature review alone.