3 Scams Targeting Cincinnati-Area Businesses Right Now

Fraudsters aren't just going after big corporations. Here's what local business owners are seeing — and the simple controls that stop most of it.

Fraud against businesses isn't slowing down — it's professionalizing. The FBI's Internet Crime Complaint Center logged more than $20 billion in reported cybercrime losses in 2025, and the biggest categories weren't sophisticated hacks. They were schemes that manipulate busy, trusting people into sending money to the wrong place.

Small and mid-sized businesses are prime targets precisely because they move real money without the layers of approval a Fortune 500 company has. Here are three schemes hitting companies in our area right now and what you can do about each one.

1. The "Vendor" Who Changed Their Bank Account

How it works: Business email compromise (BEC) is the second-costliest cybercrime in America, with more than $3 billion in reported losses last year and the average incident now costs well into six figures. The scam rarely starts with an obvious red flag. Increasingly, the first email is something harmless like "Are you at your desk?" - a low-effort message designed simply to see who responds. The financial request comes later, once the fraudster has established a rhythm.

The most damaging version targets your accounts payable process. A criminal compromises, or convincingly spoofs, the email account of a vendor, contractor or even your own executive, then sends updated payment instructions: "We've switched banks. Please use this new account for the attached invoice." The invoice is real. The relationship is real. Only the account number is fake. And because the vast majority of BEC losses move by wire or ACH, the money is often gone within hours.

AI has made these emails dramatically better. The typos and awkward phrasing you were trained to spot are largely gone.

What to do:

  • Verify every payment-instruction change by phone using a number you already have on file, never one provided in the email requesting the change.

  • Require dual approval for wires, ACH origination and any new payee setup. One person requests, a different person releases.

  • Slow down urgent requests. Urgency is the scammer's most reliable tool. A legitimate vendor will never be offended by a verification call.

2. Stolen and "Washed" Business Checks

How it works: Check fraud is decidedly low-tech and surging. Checks remain the single most targeted payment method for business fraud, and mail theft is the engine behind it. Criminals target USPS collection boxes and carriers, pull outgoing business checks, and "wash" them with chemicals to change the payee and amount. Your $1,850 check to a supplier becomes a $18,500 check to someone you've never heard of.

It gets worse: stolen checks are no longer used once. Check images are photographed and resold through encrypted messaging channels, meaning a single stolen check can expose your account number, routing number and signature to an entire fraud network. Researchers tracked nearly two million stolen U.S. checks circulating online in a single year.

What to do:

  • Enroll in Positive Pay. You tell the bank which checks you've written — check number, amount, payee and anything that doesn't match gets flagged before it clears. It's the single most effective check-fraud control available. (ACH Positive Pay does the same for electronic debits.)

  • Drop outgoing checks inside the post office, not in outdoor collection boxes.

  • Reduce check usage where you can. Every vendor you move to ACH is one less check in the mail stream.

  • Reconcile accounts frequently. Business accounts operate under different rules than consumer accounts, and prompt review of your statements matters. The window to report unauthorized items is defined by your account agreement, not open-ended.

3. The "Government Official" on the Phone

How it works: Federal prosecutors in Cincinnati issued a warning this spring about scammers impersonating prosecutors and federal law enforcement using real names, titles and badge numbers pulled from public records to build credibility. Victims are told they're the subject of a fraud investigation (or the victim of one) and pressured into "protecting" their money by moving it or handing over banking details.

The local-government version hit businesses during tax season. Earlier this year, Blue Ash officials warned that someone posing as a city tax department employee was calling business owners to collect phony past-due balances. Municipal tax departments in our area don't operate that way. Legitimate balances come by letter with documented payment instructions.

What to do:

  • No government agency will ever call demanding immediate payment, especially by wire, gift card, cryptocurrency or payment app. That demand alone signals a scam.

  • Hang up and call back using a number from the agency's official website, not the one on your caller ID (which can be spoofed).

  • If your business receives one of these calls, report it at ic3.gov and alert your team. These campaigns work in waves. If your bookkeeper got the call, the controller at the business across the street will, too.

The Common Thread

None of these scams breaks into your systems. They break into your routines - the invoice you pay without a second look, the check you drop on the way home, the authoritative voice on the phone. The fix isn't more technology; it's a few deliberate speed bumps in how money leaves your business.

If you'd like help setting up Positive Pay, dual approval on electronic payments, or a review of your payment workflows, schedule a consultation or connect with our local team to protect your business today.