The Official Magazine of the Ohio Bankers League
FALL 2026 ISSUE
THE FRAUD FRONTIER
STAYING AHEAD OF TODAY'S THREATS AND TOMORROW'S RISKS The Fraud Edition
FALL 2026 ISSUE
|1
2 | OHIO BANKERS LEAGUE
The Official Magazine of the Ohio Bankers League
OHIO RECORD The Fraud Edition IN THIS ISSUE | FALL 2026
FEATURED ARTICLES
ARTICLES
6
Over the Horizon
10 A consequential Summer for Ohio Banking Policy 12 Staying Ahead of Evolving Fraud
37 PREPARE YOUR BANK FOR AI-ENABLED FRAUD
15 The Fight Must Move Upstream 18 Fraud, Fraud, Fraud 22 Taking the Fight Against Fraud to Ohio Communities 26 Your Incident Response Plan and the First Sixty Minutes 28 Friendly Fraud 30 Fraud Prevention Starts with Awareness 32 ACH Fraud Trends
6 A CHAIRMAN'S PERSPECTIVE: FRAUD IS EVOLVING. SO MUST WE.
34 Turn Your Attention to Wire Fraud Prevention 40 Banking Calendar 42 Around the Industry
FALL 2026 ISSUE
|3
FRAUD IS EVOLVING. SO MUST WE. A CHAIRMAN’S PERSPECTIVE
Fraud has always been a challenge for banking, but the threat facing our industry today is changing at an unprecedented pace. Familiar schemes such as check fraud, account takeover and wire fraud are becoming more sophisticated, while artificial intelligence is giving criminals new tools to impersonate customers, employees and trusted contacts.
The OBL can also be a partner in educating our employees. Fraud prevention is not simply the responsibility of compliance or security teams. Every employee plays a role in identifying suspicious activity and protecting our customers. Practical, timely fraud education can help ensure our entire organization is prepared to recognize and respond to emerging threats.
The numbers underscore the challenge. A 2026 Federal Reserve survey found that 63% of financial institutions experienced check fraud attempts in the prior year, while 23% reported account takeover activity. Debit card fraud was even more widespread, with 75% of institutions reporting attempts. At the same time, artificial intelligence is making scams more convincing through deepfake voices, synthetic identities and highly personalized phishing attempts.
As community bankers, our relationships with our customers remain one of our greatest strengths. By combining those relationships with strong controls, employee education, technology and the resources available through the OBL, we can better protect the people and communities we serve.
For community banks, staying informed and prepared is essential. Fortunately, we do not have to navigate these challenges alone. The Ohio Bankers League is a valuable resource for keeping Ohio's banking community informed about emerging fraud trends, scams and threats. Through timely communications, programming and industry resources, the OBL helps bankers understand what is happening and how they can respond.
4 | OHIO BANKERS LEAGUE
Fraud will continue to evolve. Our commitment to staying one step ahead must evolve with it.
Tony Davis OBL Chairman, President & CEO, Peoples State Bank
FALL 2026 ISSUE
|5
OVER THE HORIZON Did you know that the telegraph distress signal before SOS was CQD? If you do, it is likely because you are a fan of Jeopardy. This was recently an answer relating to the signal sent by the crew of the Titanic. So, what does CDQ even mean? It stood for "All stations, distress". That message combined the telegraph code "CQ" (calling all stations) with "D" for distress. Yet, it was prone to misinterpretation, and poor radio reception could cause operators to mistake it for a routine "CQ" call. In contrast, SOS does not actually stand for anything. It is arbitrary, but is a continuous sequence of three dots, three dashes, and three dots chosen purely for its distinct pattern. Thus, making it an unmistakable rhythm in Morse code. Ironically, I learned that to ensure absolutely no ship missed the transmission—since some older operators on other vessels still favored the Marconi system—throughout the night, the Titanic’s crew began alternating between both signals. Following the sinking of the Titanic, SOS was more internationally adopted in times of distress.
6 | OHIO BANKERS LEAGUE
OBL Fraud Fighting Partnerships Sadly, in my 60 bank visits so far logged this year, fraud continued to come up in most of these conversations. And it tended to be among the first issues discussed. Some of these conversations have felt like SOS calls for help. Last year, we began talking internally about what OBL could do to be more helpful. Plus, in a meeting last fall with Director of the Federal Housing Finance Agency Bill Pulte and Senator Bernie Moreno, they charged the OBL to collaborate with the Federal Home Loan Bank of Cincinnati to be innovative with financial literacy. Therefore, in 2026, we embarked on an effort to provide more resources to our members to help educate Ohioans and stem the tide of financial fraud. Earlier this year OBL was honored to be invited by Attorney General David Yost to partner with his office, pharmacies and nursing homes in fighting elder abuse and financial exploitation. This is a meaningful
collaboration to educate all Ohioans on the warning signs of elder abuse and prevention. As a part of this, OBL has made educational resources available to Member Banks to increase awareness and provide clear guidance on where victims and families can turn for help. I’m proud of the efforts bankers make every day as a crucial front line of defense, training tellers and staff to recognize sudden behavioral shifts, unusual large cash withdrawals and suspicious wire transfers targeting older adults. Consumer education must be constant and better coordinated to make a material impact. Today’s fraud environment reaches far beyond traditional check fraud, but checks remain a stubborn and costly part of the problem. Criminals continue to exploit paper-based payments through counterfeit checks, altered or washed checks, forged endorsements and coordinated deposit schemes. At the same time, fraudsters are ramping up fraud in digital channels in ways such as business email compromise, account takeover, phishing, identity theft, social engineering, romance scams, fake online advertisements, payment redirection and AI-enabled spoofs to manipulate consumers and businesses into sending money or revealing sensitive information. For Ohio banks, the challenge is twofold: stopping fraud at the transaction level while also helping customers recognize scams before money leaves their accounts. Check fraud still requires strong operational controls, employee training, verification practices and rapid information sharing. I applaud the couple of examples of banks sharing information amongst themselves at the local level and convincing law enforcement to participate in their efforts to thwart the bad guys. Through the OBL’s Ohio Bankers Foundation, we are responding by giving banks practical tools to
educate both employees and customers. Through new community education initiatives, including Financial Success Seminars and Fraud Awareness Seminars, we provide curriculum, instructors, event coordination and marketing support so banks can bring accessible fraud-prevention education directly to customers in their local communities. These seminars are designed to help consumers recognize warning signs, understand common fraud tactics and take concrete steps to protect themselves, their families and their finances. OBL also supports Member Banks through professional development and compliance resources, including training on check fraud awareness, identity theft red flags, suspicious activity reporting, Bank Secrecy Act and anti-money laundering responsibilities, mortgage fraud awareness and elder financial abuse. These resources help banks strengthen internal controls, prepare front-line employees to identify suspicious activity and respond more effectively when customers may be targeted. Please reach out if you seek recommendations on educational programming for your employees. Federal and State Fraud Advocacy Efforts At the federal level, OBL has elevated fraud as a policy issue. Earlier this year, OBL garnered Sen. Moreno’s support in co-sponsoring with Sen. Rueben Gallego (D-AZ) bipartisan legislation - Safeguarding Consumers from Advertising Misconduct (SCAM) Act. This bill calls for stronger national protection against online scam advertisements, including requiring major social media platforms to verify advertisers, remove reported scam ads and face enforcement if they fail to protect users. That advocacy reflects a key shift in the fraud conversation: banks will continue to serve as a critical line of defense, but stopping scams also requires accountability from FALL 2026 ISSUE
|7
the platforms and systems that allow criminals to reach victims in the first place. A key point here is that the banks cannot and should not have to fight fraud alone. We need other industries to join us in the fight to protect Ohioans and others across the country. This is why OBL has also advocated with Vice President J.D. Vance’s policy team on the creation of a White House level fraud task force. Such an initiative was rolled out earlier this year to root out fraud in industries such as home healthcare, and we continue to advocate that the scope of this multi-agency needs to be broader to include financial crimes against consumers. There are also several important bills at the state level that OBL has been hard at work on, including legislation to protect older Ohioans and crack down on cryptocurrency ATMs. Don Boyd discusses these efforts in his column. OBL Innovation in Tokenized Deposits OBL is flexing its innovative muscle this year as an organizer in a nationwide consortium to enable banks of all sizes to safely offer programmable payments services while preserving deposits and local lending and reducing dependence on external vendors. As this goes to print, almost 40 state bankers associations announced the formation of BankChain Alliance, to provide customers across the country with secure, modern banking services that work seamlessly across financial institutions of all sizes and support emerging banking capabilities and lending in local economies. What we are in the middle of is truly historic and it has been exciting. Our overriding goal is to create “network effect”. The participating bankers associations collectively represent thousands of banks serving millions of consumers, businesses and communities nationwide. We are leveraging the credibility each of our organizations has built over our existence. While each association serves its own unique market, this initiative reflects a unified vision: that the future of banking is strongest when built collaboratively, governed by the industry and accessible to all institutions. Our sights are set ensuring no bank is left behind in offering their customers tokenized services. This ubiquity should be attractive to technology providers in achieving scale quicker. Our intent is for this to be an industry-owned, bank-governed network built on a common blockchain platform. BankChain Alliance will provide participating financial institutions with a network offering interoperability and supporting emerging banking capabilities such as smart payment tools, tokenized deposits, stablecoins,
8 | OHIO BANKERS LEAGUE
automated settlement, and other innovations, while maintaining the regulatory standards, security, and trust that customers expect from their banks. Credit Unions OBL is disappointed by the Ohio Division of Financial Institution’s recent determination in the purchase of Hicksville Bank by Interra Credit Union and is actively evaluating all available options to protect the industry and address members’ concerns. At the time of writing this article, our focus remains on ensuring the FDIC fully considers the significant legal and public-interest issues presented by this transaction and that Ohio policymakers understand the precedent this decision creates for Ohio banking law and Ohio state-chartered banks. I’m proud of everything Ohio bankers do each day to detect fraud and protect their customers. OBL is grateful to be a valued partner in this fight. Please contact us if you seek additional resources to strengthen your abilities in this space. You have our continued commitment to look out further over the horizon ensuring your bank has necessary resources to be innovative and strategically adapt.
Michael J. Adelman President & CEO, Ohio Bankers League madelman@ohiobankersleague.com
INSURANCE SOLUTIONS Built for Banks, Backed by Expertise Did you know the Ohio Bankers League has its own insurance agency? OBL Insurance Services Agency, Inc. provides full brokerage services for Medical, Dental, Vision, Life, Disability, and more. As the trusted voice for the Ohio banking community, we understand your unique needs. That’s why we’re uniquely positioned to help you build a benefits strategy that aligns with your bank’s culture—while ensuring you get the most competitive pricing available. Our services include: • Plan design and funding options • Annual market checks and renewal analysis • Compliance assistance and HR resources • Wellness plans, claims monitoring, and more
Contact Gauri today to learn more about how OBL Insurance Services can help your bank thrive! 614.340.7598 gairi@ohiobankersleague.com
ASSOCIATION STAFF
4215 Worth Avenue, Suite 300 Columbus, OH 43219 Fax (614) 340-7596
The Ohio Record is published quarterly by OBL BankServices. POSTMASTER: Send address changes to Ohio Record at the address listed above. Statements and opinions expressed in Ohio Record are not necessarily those of the OBL.
Michael Adelman President & CEO madelman@ohiobankersleague.com (614) 340-7616
Rita Hinkle Administrator, OBBT rhinkle@ohiobankersleague.com (614) 340-7609
Gauri Airi Executive Director, Ohio Bankers Benefits Trust gairi@ohiobankersleague.com (614) 340-7598
Daniel Holstein, CPA Senior Accountant dholstein@ohiobankersleague.com (614) 340-7604
Brenda Arnold Products & Services Manager, OBL BankServices barnold@ohiobankersleague.com (614) 340-7620 Don Boyd Senior Vice President of Government Relations & General Counsel dboyd@ohiobankersleague.com (614) 340-7608 Michelle Crume Senior Vice President, OBL Executive Director, OBL BankServices mcrume@ohiobankersleague.com (614) 340-7622 Stephanie Elam Plan Coordinator & Customer Service Specialist selam@ohiobankersleague.com (614) 340-7591
Paige Houlihan Products and Services Coordinator, OBLBankServices phoulihan@ohiobankersleague.com (614) 340-7613
Anthony Lagunzad Manager, Government Relations & BankPAC alagunzad@ohiobankersleague.com 614.340.7614 Stephen Mentzer Database Manager smentzer@ohiobankersleague.com (614) 340-7607 Jennifer Osburn, CPA CFO, Chief Administrative Officer josburn@ohiobankersleague.com (614) 340-7606
Sarah Husk Education Manager shusk@ohiobankersleague.com (614) 340-7610
Megan Peiffer Education Manager mpeiffer@ohiobankersleague.com (614) 340-7618
Audra Johnson Director of Communications ajohnson@ohiobankersleague.com (614) 340-7621
Emily Schwegman Education Specialist eschwegman@ohiobankersleague.com (614) 340-7602
Julie Kiplinger Education Manager jkiplinger@ohiobankersleague.com (614) 340-7612
Christine Zeek Employee Benefits Manager, OBBT czeek@ohiobankersleague.com (614) 340-7617
Evan Kleymeyer Senior Vice President of Government and External Relations ekleymeyer@ohiobankersleague.com (614) 340-7605 FALL 2026 ISSUE
|9
A CONSEQUENTIAL SUMMER FOR OHIO BANKING POLICY The summer months are often described as a quiet period at the Ohio Statehouse. For Ohio’s banking industry, this summer was anything but quiet. Legislative work continued on several important issues, the Supreme Court of Ohio issued consequential decisions affecting financial institutions, and an unprecedented proposed credit union acquisition of an Ohio bank raised fundamental questions about Ohio banking law.
OBL has opposed the transaction through every available regulatory and policy channel. The Ohio Banking Commission adopted a resolution raising concerns and urging regulators to deny or decline approval. OBL also submitted extensive comments to the FDIC addressing Ohio law, deposit insurance, public deposits, field-ofmembership restrictions, CRA obligations, tax fairness, and the broader effect on Ohio’s banking system.
The most significant development was the proposed sale of substantially all the assets and liabilities of The Hicksville Bank to Interra Credit Union, an Indiana statechartered, privately insured credit union. The transaction would eliminate an Ohio bank charter, move customer deposits from the FDIC insurance system to private share insurance, and remove the affected communities from the Community Reinvestment Act framework.
In August, the Ohio Division of Financial Institutions issued a nonobjection letter allowing the transaction to proceed at the state level. OBL fundamentally disagrees with the Division’s interpretation. Ohio law specifically identifies the types of institutions to which an Ohio state-chartered bank may transfer substantially all its assets and liabilities, and credit unions are not included. The Division instead relied on a broad parity provision to reach a result the General Assembly has never expressly authorized.
10 | OHIO BANKERS LEAGUE
Whatever the ultimate outcome of this particular transaction, the Division’s interpretation creates a precedent that cannot be ignored. It raises broader questions about the integrity of Ohio’s bank charter, the proper limits of regulatory parity authority, and whether major changes to the structure of Ohio’s financial-services marketplace should be made by regulators or elected legislators. These issues will remain a major focus for OBL this fall. Fraud prevention also continues to drive much of the banking-related legislative agenda. House Bill 560, the Protect Our Parents Act, would strengthen the ability of financial institutions to intervene when they reasonably suspect the financial exploitation of an older or vulnerable customer. Committee discussions have focused on giving banks practical tools to delay suspicious transactions, contact trusted individuals, and work with law enforcement while providing appropriate protections for institutions acting in good faith.
House Bill 648 House Bill 648 addresses another rapidly growing fraud channel: digital asset kiosks, commonly known as cryptocurrency or Bitcoin ATMs. These machines are frequently used by criminals to convince victims to convert cash into cryptocurrency that can be transferred almost instantly and is extremely difficult to recover. The legislation would establish registration, disclosure, transaction-limit, identification, and consumer-protection requirements. OBL has supported reasonable safeguards that protect consumers without placing additional obligations on banks that do not own or operate the kiosks.
House Bill 195
2026-Ohio-2268, the Supreme Court of Ohio rejected an expansive theory of securities liability that could have exposed banks and other financial institutions to enormous claims simply for providing routine services later used by a customer engaged in misconduct. OBL participated as an amicus in support of the position ultimately adopted by the Court.
Dollar Bank, FSB v. Harris In Dollar Bank, FSB v. Harris, 2026-Ohio-3069, the Court unanimously upheld Ohio’s Financial Institutions Tax against a dormant Commerce Clause challenge. The Court concluded that the tax is internally consistent, fairly apportioned, and does not improperly discriminate against interstate commerce and banks based outside of Ohio. A contrary ruling could have destabilized the FIT and forced policymakers to reconsider the entire tax structure applicable to banks throughout Ohio. As legislators return to Columbus, the remaining session calendar will be compressed by the election and the end of the General Assembly. Bills that move may do so quickly. OBL will continue working to advance practical fraud protections, preserve a competitive and legally sound banking environment, and ensure that policymakers understand how proposed changes will affect banks, customers, and communities throughout Ohio.
Don Boyd SVP, Government Relations & General Counsel, Ohio Bankers League dboyd@ohiobankersleague.com
Ohio has also taken an important step toward modernizing its commercial law. House Bill 195, which becomes effective in October, adopts the latest amendments to the Uniform Commercial Code, including a new Article 12 governing certain digital assets and “controllable electronic records.” The legislation provides greater legal certainty regarding ownership, transfer, security interests, and priority in emerging forms of electronic property. That certainty is increasingly important as banks evaluate digital assets, tokenization, electronic payments, and new forms of collateral.
Bitounis v. Interactive Brokers, L.L.C. The legal landscape produced two particularly important decisions. In Bitounis v. Interactive Brokers, L.L.C., FALL 2026 ISSUE
| 11
STAYING AHEAD OF EVOLVING FRAUD
OHIO’S COMMITMENT TO PROTECTING OLDER ADULTS Older adults have become an all-too-regular target of scam artists. Elder fraud is evolving so rapidly that the schemes – from romance and cryptocurrency scams to tech support and government impersonation – are becoming increasingly difficult to recognize and prevent. Technological advances allow criminals to employ sophisticated tactics that fuel their success, threatening the financial security, independence and well-being of their older victims. Last year alone, Americans age 60 or older lost an estimated $7.75 billion to scammers – a 59% increase from the previous year, according to the FBI’s Internet Crime Complaint Center. This figure encompasses only cases reported to the center, however, so actual losses are believed to be much higher. Given the scale of the harm, the Ohio Attorney General’s Office has made the fight against elder fraud a high priority, expanding statewide initiatives that promote prevention, awareness, and early intervention. The Elder Abuse Awareness Campaign, launched in 2025, seeks to bring this growing threat out of the shadows and eliminate the shame that older Ohioans often feel when victimized. To that end, a campaign video was shared statewide to shed light on “What’s Done in the Dark” and reinforce the importance of reporting elder exploitation and abuse so that scammers can be held accountable. This effort has drawn the support of the Ohio Pharmacists Association, Ohio Bankers League and Ohio Health Care Association, key community partners whose members often come in contact with older adults and are thus well‑positioned to help identify signs of exploitation or abuse.
12 | OHIO BANKERS LEAGUE
More recently, in July, Ohio Attorney General Andy Wilson took aim at romance scams, an impostor scheme often targeted at older adults in which criminals court their victims online to trick them into sending money. AG Wilson’s Romance Impostor Scams Forensic Initiative is designed to ward off financial losses, increase digital forensic review, help investigators identify patterns and support victims. A key part of this effort is a dedicated statewide hotline – 1-855-961-SCAM – for those who have been victimized or who believe a loved one may be the victim of a romance scam. Hotline users can share information with the attorney general’s Constituent Services Section, which coordinates with experts from across the office, including specialists who try to recoup at least part of any money lost by victims. Information provided to Constituent Services is reviewed by criminal intelligence analysts with the Ohio Bureau of Criminal Investigation (BCI) for indicators of fraud. Cases believed to warrant criminal charges are referred to local law enforcement. Simultaneously, victims and/or their loved ones receive educational resources and guidance from our Consumer Protection Section to help them prevent additional financial losses and better understand available options. “No Ohioan should lose his or her life savings to someone pretending to care about them," AG Wilson said. “These scammers are sophisticated, emotionally manipulative and, sadly, increasingly common. We’re giving families a place to turn when they suspect something isn't right and providing law enforcement with valuable information to investigate these crimes.”
Nearly a‑fifth of Ohioans are 65 or older – a number that is expected to keep rising. These demographic realities heighten the risks, particularly for those managing retirement savings, living on fixed incomes, and/or navigating complex digital environments that scammers exploit. Many factors make older adults vulnerable to exploitation, including social isolation, age‑related cognitive changes, and a reliance on online communication. Criminals use a variety of tactics in seeking to capitalize on these vulnerabilities, often devising personalized schemes that use artificial intelligence to mimic voices, fabricate images, and create convincing messages. Even more unsettling is the fact that many victims are targeted close to home, preyed upon by trusted family members, friends, caregivers and acquaintances who misuse accounts, forge signatures or exploit legal authority. We know why victims, particularly those of a mature age, don’t speak up and report the exploitation. They fear retaliation. They feel embarrassed. They are unaware (either because they have mental or physical limitations that impede their ability to remember and report the crime, or the scam is highly sophisticated). They depend on the perpetrator for their care. They don’t know where to turn for help.
Beyond these initiatives, the attorney general’s Elder Abuse Commission works regularly to educate Ohioans about the devastating effects of elder exploitation, helps develop public policy, and encourages cross-system collaboration, ensuring that professionals across social services, finance, healthcare, and public safety have the tools needed to recognize the exploitation and respond effectively. Within the office, the Elder Justice Unit collaborates closely with other divisions – the Consumer Protection, Crime Victim Services, Health Care Fraud and Special Prosecutions sections, as well as the Ohio Bureau of Criminal Investigation – and helps with investigations and prosecutions. The unit also provides training, victim support, and technical assistance to Adult Protective Services, law enforcement, prosecutors, financial institutions, and healthcare providers.
The Ohio Attorney General’s Office is committed to eradicating the stigma associated with victimization. Failure to report these crimes, after all, only deepens the harm, allowing scammers to continue their deception and financial losses to grow. Safeguarding older adults demands a coordinated statewide strategy encompassing technology, trained professionals, strong reporting pathways, and supportive communities. Fraudsters continue to innovate — and Ohio must stay ahead by strengthening prevention, increasing awareness, and making sure that older adults know that asking for help is a sign of strength, not shame.
Monica Walker Elder Services Coordinator – Elder Justice Unit, Office of the Ohio Attorney General
Ohio has one of the nation’s largest and fastest‑growing elderly populations. The state ranks sixth nationally in number of adults age 60 or older, according to the Scripps Gerontology Center at Miami University in Oxford.
FALL 2026 ISSUE
| 13
MICROSOFT 365 SECURITY AUDIT
YOU MOVED TO MICROSOFT 365. DID YOUR SECURITY COME WITH IT? Microsoft 365 hands you the keys, not the locks. Every new cloud service, identity, endpoint, and third-party connection opens another door, and none of them close until they're properly configured, governed, and monitored.
49%
OF ATTACKS TARGET MICROSOFT 365
OUR AUDIT IS
CRI/FFIEC
SCHEDULE YOUR AUDIT
Brandon Krietemeyer brandon@cbcohio.com 614.429.8823 cbcohio.com
14 | OHIO BANKERS LEAGUE
ALIGNED
THE FIGHT MUST MOVE UPSTREAM
FEDERAL POLICY IS BEGINNING TO RECOGNIZE WHAT BANKS HAVE LONG KNOWN: STOPPING FRAUD REQUIRES EVERY PARTICIPANT IN THE ECOSYSTEM. A fraudulent payment rarely begins at a bank. It may begin with a fake investment advertisement on social media, a spoofed text message, a compromised business email account or a convincing voice clone that sounds exactly like a family member. Yet when the victim finally sends the money, the bank is often expected to identify the deception in seconds and absorb the blame if it cannot. That mismatch is the central challenge on today’s fraud frontier. Criminals operate across platforms, telecommunications networks, email systems, payment rails and borders. Banks remain indispensable to stopping and tracing the money, but no institution at the end of the chain can solve a crime that is engineered across the entire chain.
The next phase of fraud prevention must be built around speed, shared intelligence and shared responsibility.
a series of isolated incidents. It is an industrial-scale business model. Artificial intelligence is accelerating that model. FinCEN has warned that criminals are using deepfake identity documents, images, audio and video to defeat verification and authentication controls. Generative tools can improve the grammar of a phishing email, imitate a familiar voice and create persuasive documents at almost no cost. The quality rises while the price of launching thousands of attacks falls. At the same time, older methods remain profitable. FinCEN identified more than $688 million in suspicious activity associated with mail theft-related check fraud during one six-month period. Fraudsters are combining yesterday’s instruments with today’s data, automation and social engineering. A washed check may be oldfashioned; the stolen identity, mule network and digital reconnaissance behind it are not. Washington is beginning to widen the lens
The scale is changing—and so are the tools The FBI’s 2025 Internet Crime Report recorded nearly 453,000 cyber-enabled fraud complaints and more than $17.7 billion in reported losses. Business email compromise alone accounted for roughly $3 billion. Separate Federal Trade Commission data show consumers reported $15.9 billion in fraud losses in 2025, including $2.1 billion from scams that began on social media. These datasets should not be added together, but they point in the same direction: fraud is no longer
Recent federal action suggests an important change in direction. In March, the White House created a Task Force to Eliminate Fraud and separately ordered a broader federal effort against cybercrime, fraud and transnational scam networks. An August presidential memorandum went further by calling for structured partnerships with vetted private companies to identify and disrupt foreign cyber-enabled criminal organizations. Whatever the politics surrounding individual initiatives, the strategic premise is sound: modern fraud is organized, networked and frequently transnational, so the response must be as well. FALL 2026 ISSUE
| 15
For banks, the most immediately useful development may be FinCEN’s June 2026 guidance on Section 314(b) of the USA PATRIOT Act. The guidance clarifies that eligible financial institutions may voluntarily share information about suspected fraud when the activity may involve money laundering or another specified unlawful activity. FinCEN specifically points to practical intelligence such as IP addresses, video surveillance, shared identifying information, newly added payees followed by large transfers and geographically inconsistent login activity. The Federal Reserve has since highlighted the guidance for its supervised institutions and strongly encouraged participation. This is more than a technical clarification. It recognizes that a single suspicious account or transaction may appear inconclusive inside one institution but become obvious when connected to activity at another. Banks should use this moment to examine whether their fraud, cybersecurity and BSA teams can move information quickly enough; whether their Section 314(b) procedures reflect the new guidance; and whether front-line employees know how to escalate a concern before funds disappear. Participation remains voluntary and must be handled within the program’s requirements, but the federal government is sending a clear signal: useful information should not remain trapped in institutional silos. Responsibility must begin before the payment Information sharing among banks is necessary, but it is not sufficient. A scam that begins with a paid advertisement, moves to an encrypted messaging app and ends with a wire or cryptocurrency transfer should not become solely the bank’s responsibility at the final step. That is why the bipartisan Safeguarding Consumers from Advertising Misconduct Act deserves attention. Introduced by Senators Ruben Gallego and Ohio’s Bernie Moreno, the SCAM Act would require online platforms to take reasonable steps to prevent fraudulent and deceptive advertisements and would strengthen enforcement when platforms fail to do so. Its core principle is straightforward: companies that profit from distributing advertisements should have a duty to keep known scammers from buying access to potential victims. This is the direction OBL will continue to press: accountability across the fraud ecosystem. Banks invest heavily in monitoring, authentication, employee training, customer outreach and reimbursement. Those investments matter, but public policy should also address the platforms that introduce victims to scammers, the communications services that carry impersonation attempts, the mule accounts that move stolen funds and the overseas networks that organize the schemes.
16 | OHIO BANKERS LEAGUE
What staying ahead looks like Technology will remain essential, including behavioral analytics, device intelligence, anomaly detection and carefully governed use of AI. But the strongest fraud program also creates deliberate friction at the moments that matter: an independent callback before a business changes payment instructions; dual approval for high-risk transfers; additional verification after a sudden change in contact information; and a trained employee who is empowered to pause when the customer’s story does not add up. Education is equally important, but it must evolve beyond generic warnings. Customers need to understand that caller ID can be spoofed, voices can be cloned, legitimate-looking ads may not be vetted and no government agency or bank employee will demand secrecy while directing an immediate payment. Small businesses should treat any emailed change in wire instructions as unverified until confirmed through a trusted channel. Families should establish a simple verification phrase before a crisis call arrives. The policy goal should not be another stack of prescriptive checklists. It should be a framework that lets institutions act on risk, share useful information with appropriate safeguards and deploy new defenses as quickly as criminals deploy new attacks. Regulators should provide clear safe harbors for good-faith fraud prevention and collaboration, while Congress should ensure that responsibility follows the conduct that created or facilitated the scam. Banks will continue to be the trusted institutions customers call when something goes wrong. That role is a strength, and Ohio bankers perform it every day with skill and compassion. But trust should not be confused with exclusive responsibility. On the fraud frontier, the winning strategy is not to build one stronger wall around the bank. It is to connect the defenses across the entire system—and stop the scam before a customer is ever asked to send the money.
Evan Kleymeyer Senior Vice President of Government and External Relations, Ohio Bankers League ekleymeyer@ohiobankersleague.com
FALL 2026 ISSUE
| 17
FRAUD, FRAUD, FRAUD
KEEPING UP WITH AN EVER-EVOLVING THREAT Fraud this, fraud that, fraud, fraud, fraud. Are you tired of talking about fraud yet? Probably. Unfortunately, fraud isn’t going anywhere anytime soon. As fraudsters continue to evolve their tactics and find new ways to target financial institutions, staying informed and prepared remains a priority for every bank. While the OBL can’t stop a fraudster from making an attempt, we can provide the education, resources and opportunities for bankers to learn how to recognize, report and prevent fraudulent activity at their institutions. From physical and cybersecurity to emerging fraud schemes and technology, OBL’s educational programs give bankers the opportunity to learn from experts, regulators and – perhaps most importantly – each other.
OBL Security & Technology Conference The Security & Technology Conference is one of OBL’s most highly anticipated conferences each year. In today’s uncertain environment, protecting a bank’s people, facilities, systems and information is critical to its customers, employees and community. The conference features two tracks focused on physical security and cybersecurity, which attendees can attend individually or together. Throughout the program, industry experts address a wide range of fraud and security topics, including emerging threats, tools and resources, implementation strategies and best practices. The conference also provides opportunities to hear directly from regulators and fellow bankers through a regulator panel and open discussion. Being able to ask questions, hear how other institutions are addressing challenges and learn from both successes and lessons learned is invaluable. These conversations give bankers new ideas for strengthening policies and procedures, evaluating products and services, and protecting their institutions against an ever-changing threat landscape.
OBL IT Forum
Visit the OBL website at www.ohiobankersleague.com to view the upcoming programs or scan the QR code below.
The OBL IT Forum extends the conversation beyond the Security & Technology Conference, giving IT professionals an opportunity to stay current on some of the most pressing issues facing the technology world. The forum features experts from Infotex and SBS Cybersecurity, with general sessions and breakout opportunities that allow participants to choose between managerial and technical topics. Like OBL’s other forums, the IT Forum is designed by bankers, for bankers. Before each forum, members help shape the agenda by voting on and submitting the topics they are most interested in discussing. This banker-driven approach ensures the program addresses the issues IT professionals are actually facing.
2027 program dates coming soon! 18 | OHIO BANKERS LEAGUE
The forum also includes an open discussion, giving participants the opportunity to bring their questions and challenges to the group. Hearing how peers are addressing cybersecurity, fraud and other technology-related concerns can provide practical ideas – and sometimes reassurance that your institution is not the only one facing a particular challenge.
KBA Fraud Academy For those looking for a deeper dive into fraud, OBL also partners with the Kentucky Bankers Association on its annual Fraud Academy. While the Security & Technology Conference and IT Forum incorporate fraud into broader security and technology discussions, Fraud Academy is dedicated entirely to the topic. This immersive, three-day program is designed to give attendees the skills, strategies and knowledge needed to identify and combat today’s fraud threats. Each year, the curriculum covers more than 18 types of fraud and features insights from experts representing federal agencies, law enforcement and the financial industry, including the DEA, FBI and U.S. Secret Service. The program received rave reviews in its first year and has continued to grow. More than 20 state banking associations now partner on the program, bringing together bankers from across the country. This national perspective is just one of the program’s strengths, allowing participants to learn not only from industry experts but also from bankers facing fraud challenges in different markets and communities. Fraud Academy is available both virtually and in person in Lexington, Kentucky, giving bankers the flexibility to participate in the format that works best for them.
The fraud conversation may be getting old, but the threats certainly are not. OBL’s security, technology and fraud-focused programs give bankers opportunities to stay informed, learn from experts and peers, and take that knowledge back to their institutions. Because when it comes to fraud, there’s always something new to learn.
Sarah Husk Education Manager, Ohio Bankers League
FALL 2026 ISSUE
| 19
2026 OBL
THE MAIN EVENT take flight: BANKING AT FULL THROTTLE October 26 - 28, 2026 greater columbus convention center the ohio banking industry’s premier professional development & networking event Join industry leaders at this fourth annual event featuring eight learning tracks and networking opportunities, as well as the OBL Annual Business Meeting and OBL BankServices Expo. Plus! The OBL will present the 2026 OBL Industry Awards in categories such as Bank of the Year, Banker of the Year, Next Generation Leadership Award, Exceptional Woman in Banking Award and others – including the OBL Five Pillar Awards!
register yourself and your team today! $695 - Full Event per Member* *Includes all scheduled programming, receptions and events Oct. 26 - 28
$495 - Learning Track Day: Tuesday, October 27 (BANKERS ONLY)** **Includes the Learning Tracks, breakfast and awards lunch on October 27
$295 - Guest of an Attendee (includes meals and receptions only)
questions? For program questions, contact Sarah Husk at shusk@ohiobankersleague.com. For registration assistance, contact Emily Schwegman at eschwegman@ohiobankersleague.com.
20 | OHIO BANKERS LEAGUE
topics you won’t want to miss General Sessions Lessons in Leadership
Opening & Closing Keynotes
The Leadership Blueprint: Using Behavioral Insight to Hire, Coach, and Maximize Productivity
Supersonic Success Building Moments that Matter: From Good to Unforgettable
learning tracks Compliance & Risk Management Risk Assessment: How do we focus on specific risk when it exists in everything that we do? Vendor Management: Are You “Really” Managing Your Vendors or Are You Just “Checking a Box”? How AI Is Changing Cybersecurity for Banks, Businesses, and Bad Actors Regulatory Recap & Outlook: What You Need to Know Now
Executive What Does It Take to Thrive? Hidden in Plain Sight: How Banking Leaders Unlock the Talent They Already Have AI – Hype, Hope or Help? Macroeconomic Outlook
Finance Leveling up on Digital Assets Rates Will Surprise You, Your Balance Sheet Shouldn’t Secrets of Highly Successful ALCOs From Cost Center to Growth Engine: A Modern Payments Strategy for Community Banks
Human Resources AI Developments in The Workplace Recruiting & Retaining Gen Z and Millennials: What the Data Tells Us Strategic Burnout: The HR Leader’s Own Oxygen Mask The HR Advantage: How HR Leaders Build the Skills AI Can't Replace
Legal Managing Unfair Competition and Protecting Confidential Information The Real Value of Cyber Resilience and Recovery Money Moves – How Blockchain Will Change Banking Website Tracking Litigation: Managing Demand Letters, Class Action Risk, and Practical Response Strategies
Lending Innovation Drought, Risk Flood: The Hidden Cost to Credit Quality Economic View from the Farmgate Utilizing Technology and Embracing AI in Credit Decisioning SBA as Strategy: Capital Efficiency, Risk Reduction, Profit & Growth
Marketing Why Your Bank? Defining Differentiation in a Commoditized Market Banking on Autopilot Your Actionable Roadmap to Practical AI Value Looking Into Banking’s Future: AI, Digital Banking and the Instant Gratification Consumer
Retail & Operations Collaborate, Delegate & Engage: Modern Tools for Today’s Workforce Rethinking Retirement: The Future of Saving Beyond the Teller Line: Designing the Next-Gen Banking Experience If Amazon Can Warn Me, Why Can't My Bank? Protecting Teens and Families from Unwanted Transactions in Real Time
continuing education credits Need a few additional continuing education credits to finish out the year? Good news! The OBL can provide CPE or CLE credit letters for Main Event participation.
PLUS! Celebrate the Ohio Banking Industry with the OBL Industry Awards!
FALL 2026 ISSUE
| 21
TAKING THE FIGHT AGAINST FRAUD TO OHIO COMMUNITIES Fraud is not a new challenge for Ohio’s banking industry. What has changed is the speed, sophistication and reach of the criminals behind it. From check fraud and identity theft to phishing emails, business email compromise and scams targeting older Ohioans, fraud continues to evolve. Ohio’s banks are often on the front lines, helping customers recognize suspicious activity, protect their accounts and recover when they have been targeted. For more than 130 years, the Ohio Bankers League has helped Ohio’s banking industry navigate challenges and prepare for what comes next. Founded in 1891, OBL has long been a source of education, advocacy and resources for its member banks. Today, that mission includes helping banks and their communities respond to one of the most persistent challenges facing consumers and financial institutions: fraud.
22 | OHIO BANKERS LEAGUE
Education Is a Powerful Tool The most effective fraud prevention strategy does not begin after a customer has lost money. It begins with awareness. A customer who knows that a bank will never ask them to move their money to a “safe account” is more likely to recognize a scam. An employee who understands the warning signs of unusual account activity may be able to stop a fraudulent transaction before it happens. A family member who recognizes the signs of elder financial exploitation may be able to intervene before a loved one suffers a devastating loss. That is why education matters. Banks have a unique position in their communities. They know their customers, employ people who live in those
INTERESTED IN HOSTING A FRAUD PREVENTION WORKSHOP OR LEARNING MORE ABOUT THE PROGRAM? Contact Audra Johnson at ajohnson@ohiobankersleague.com.
communities and are often trusted sources of financial information. That relationship creates an opportunity to do more than respond to fraud. It creates an opportunity to help prevent it. Listening to Our Members OBL’s latest fraud prevention efforts began by listening to our members. Ohio bankers told us they were seeing the effects of fraud firsthand. They were dealing with increasingly sophisticated scams, concerned about vulnerable customers and looking for better ways to educate their employees and communities. In response, OBL developed Fraud Prevention Workshops that bring together banks, community organizations and local experts to provide timely, practical information about emerging scams.
The response has been encouraging. At a recent workshop hosted by The Killbuck Savings Bank, more than 65 people gathered to learn about current fraud threats, identify warning signs and discuss ways to protect themselves and those around them. The turnout demonstrated something important: people want this information. They want to know what to do when they receive a suspicious text, how to recognize an impersonation scam and how criminals are targeting their parents and grandparents. Educating the First Line of Defense Customer education is only one part of the equation. Employee education is equally important. Bank employees are often the first to notice unusual activity or hear a customer describe circumstances that raise a red flag. As fraud tactics change, employees need ongoing training to recognize new schemes and understand how to respond. FALL 2026 ISSUE
| 23
When knowledgeable employees are paired with informed customers, banks are better positioned to prevent fraud before it becomes a loss. OBL is also partnering with the Ohio Attorney General’s Office to combat elder fraud and financial exploitation. This collaboration reflects an important reality: no single organization can fight fraud alone. Banks, government agencies, law enforcement, community organizations and families all have a role to play. By bringing trusted voices together, OBL’s workshops connect Ohioans with information and resources while addressing the specific concerns communities are experiencing. A Continuing Commitment The fight against fraud will not be won with one workshop, one campaign or one new technology. It will require an ongoing commitment to education, awareness and collaboration.
24 | OHIO BANKERS LEAGUE
For OBL, that work is a natural extension of our mission. For more than 130 years, the League has helped Ohio’s banking industry navigate change, respond to challenges and prepare for the future. Fraud is one of today’s most significant challenges, and OBL is committed to helping our member banks meet it head-on, empowering employees, educating customers and taking fraud prevention directly into the communities they serve. Because stopping fraud starts with awareness, grows through education and becomes stronger when an entire community works together.
Audra Johnson Director of Communications, Ohio Bankers League ajohnson@ohiobankersleague.com
Find Better Leads. Have Better Conversations. Win More Business. You know your market. Now find the best opportunities in it—faster. Commercial Prospecting and Industry Intelligence helps bankers build targeted calling lists, understand a prospect’s industry quickly, and support stronger risk conversations during credit underwriting. Commercial Prospecting Access a comprehensive database of commercial properties and businesses. Target your pipeline by loan amount, lender, owner, industry, maturity date, revenue size, or location—and uncover opportunities your competitors are missing. C&I Liens Intelligence Track which institutions hold C&I liens on businesses in your market. Reveal competitor activity, measure market penetration, and identify the most active lenders in specific industries and geographic areas. Industry-Specific Conversation Prep Walk into every call with focused industry insights and practical problem-solving tools—so you can ask better questions, differentiate your bank, and move from introduction to opportunity faster.
FALL 2026 ISSUE
| 25
YOUR INCIDENT RESPONSE PLAN AND THE FIRST SIXTY MINUTES At 7:42 a.m., an office manager at a 30-person accounting firm opens her email to find a message from IT support she doesn't recognize, sent from an account that looks almost right. By 9:15, half the shared drive is encrypted and a ransom note has replaced the firm's client intake spreadsheet. Nobody in the building knows who is supposed to make the first call, what systems can be safely disconnected, or whether the backups actually work. That gap, the sixty minutes between discovery and organized response, is where most of the damage in a cyber incident actually gets decided. This is not a hypothetical reserved for large enterprises. It is the daily reality for small and mid-sized organizations across every industry, and it is why an incident response plan is no longer optional infrastructure. This piece walks through what actually needs to happen in the first hour after an incident is discovered, and why having that sequence written down in advance changes the outcome more than almost any single security tool. The Clock Doesn't Start When You Think It Does Most conversations about incident response focus on the moment a business realizes something is wrong. But that moment rarely lines up with when the actual compromise began. According to IBM's 2025 Cost of a Data Breach Report, organizations took a mean of 241 days to identify and contain a breach in 2025, the shortest window in nine years of tracking, but still nearly eight months of an attacker having some level of access before the incident was fully resolved. That dwell time matters because it reframes what "the first sixty minutes" really means. It is not the first sixty minutes of the attack. It is the first sixty minutes after detection, when an organization has its best and often only chance to limit how much worse the situation gets.
26 | OHIO BANKERS LEAGUE
IBM's research also found that breaches contained within 200 days cost organizations $1.14 million less on average than those that dragged on longer. Speed of response, not just speed of detection, is what separates a contained incident from a catastrophic one. Small and Mid-Sized Organizations Are Absorbing the Worst of It There is a persistent assumption among smaller businesses that they are not attractive enough targets to justify a formal response plan. The data does not support that assumption. Verizon's 2025 Data Breach Investigations Report found that ransomware was present in 88 percent of breaches involving small and mid-sized businesses, compared with 39 percent of breaches at larger enterprises. Attackers are not choosing SMBs because the payout is bigger. They are choosing them because the defenses, and the response plans, are thinner. That gap shows up most clearly in the first hour after discovery. Larger organizations often have a security operations team and a documented escalation path. Smaller organizations frequently have neither, which means the first sixty minutes are spent figuring out who is in charge rather than executing a plan. What Should Actually Happen in the First Sixty Minutes An incident response plan is only useful if it tells people exactly what to do without requiring them to think it through in real time, while adrenaline and uncertainty are both working against clear judgment. The following sequence reflects the core actions that should occur, in roughly this order, once a potential incident is confirmed.
1 Identify and designate an incident lead. One person,
named in the plan ahead of time, makes the call on next steps. This prevents the common failure mode of five people independently deciding what to unplug.
2 Isolate, don't shut down, affected systems.
Disconnecting a compromised machine from the network preserves evidence that forensic investigators and cyber insurance carriers will need later. Powering it off can destroy that evidence.
3 Activate the communication tree. The plan should
list who gets notified first: IT or the managed service provider, leadership, legal counsel, and cyber insurance carrier, in that order, with phone numbers that don't depend on the compromised email system to deliver them.
4 Do not attempt to negotiate or communicate with an attacker directly. That role belongs to legal counsel or a professional incident response firm, not to whoever found the ransom note.
5 Begin a written timeline. Who found the issue, what
time, what systems appear affected, what actions have been taken. This record becomes essential for insurance claims, regulatory notification, and any later legal review.
6 Verify backup integrity before assuming recovery is
possible. An organization that discovers its backups were also encrypted, or hadn't run successfully in weeks, is in a far worse position than one that confirms clean, isolated backups exist.
7 Determine notification obligations. Depending on
the industry and the data involved, there may be legal requirements to notify clients, patients, or regulators within a specific window. This is where legal counsel and a documented compliance framework matter most.
None of these steps require advanced technical expertise to execute. They require a plan that was written before the incident happened, and a team that has actually seen it. A Plan That Lives in a Binder Is Not a Plan
remembers where it's stored, and the person named as incident lead has since left the company. A functional incident response plan is a living document that gets tested. Tabletop exercises, structured walkthroughs where the team talks through a simulated incident step by step, surface these gaps before a real event does. IBM's 2025 report specifically points to regular incident response testing as one of the more effective cost mitigators available to organizations of any size, because it converts a written procedure into muscle memory. For associations and their member organizations, this is a practical starting point that doesn't require a large budget. A plan can begin as a single page: who is the incident lead, who gets called first, where are the backups, and who verifies them. That page, reviewed twice a year, does more to limit damage in the first hour than most standalone security tools. The First Hour Is a Preparedness Problem, Not a Technology Problem It's worth being direct about what actually determines whether an incident becomes a controlled event or a business-ending one: preparation done in advance, not tools purchased after the fact. Firewalls, endpoint detection, and email filtering all reduce the odds of an incident occurring. But once one does occur, the outcome is shaped almost entirely by whether the organization already knows what to do in the first sixty minutes. Organizations that haven't reviewed their incident response plan recently, or don't have one at all, don't need to wait for an audit deadline to fix that. EasyIT, a Columbus-based managed IT and cybersecurity provider, works with businesses across healthcare, legal, manufacturing, and professional services to build and stress-test incident response plans as part of a broader security posture. For organizations unsure where their current plan, or lack of one, actually stands, a complimentary readiness assessment is a reasonable place to start.
Kurt Hoeft CEO, EasyIT
Many organizations do have some version of an incident response plan, often created for a compliance audit or an insurance application, and then never looked at again. A plan nobody has practiced tends to fail in the same predictable ways: the contact list is outdated, nobody
FALL 2026 ISSUE
| 27
FRIENDLY FRAUD
MORE THAN A MERCHANT PROBLEM What is friendly fraud? For years, financial institutions have focused fraud prevention efforts on external threats such as stolen credentials, account takeovers, and payment scams. While those risks remain significant, another form of fraud is gaining momentum across the payments ecosystem: friendly fraud. Also known as first-party fraud or chargeback fraud, friendly fraud occurs when a consumer disputes a legitimate transaction with their card issuer, often after receiving the goods or services. In some cases, the dispute may stem from confusion or a forgotten purchase. In others, the cardholder knowingly misrepresents the transaction to obtain a refund while retaining the product or service. As digital commerce continues to expand, financial institutions are increasingly finding themselves at the center of this growing challenge. A growing risk Friendly fraud affects far more than just merchants, particularly in terms of chargeback volume. A chargeback occurs when a cardholder disputes a transaction with their card issuer, potentially resulting in funds being
28 | OHIO BANKERS LEAGUE
returned to the customer. Every chargeback requires financial institutions to investigate, review, and resolve the dispute, creating operational costs and increasing pressure on fraud and dispute management teams. According to Mastercard’s 2025 State of Chargebacks Report, approximately 23 percent of all chargebacks are tied to first-party fraud. As dispute volumes continue to rise, financial institutions must balance their responsibility to protect consumers with the need to safeguard the integrity of the payments system. This balance is becoming increasingly difficult as fraudsters learn to exploit consumer protection mechanisms designed to address legitimate unauthorized transactions. Why first-party fraud is different Traditional fraud typically involves a criminal actor using stolen payment credentials or accessing an account without authorization. Friendly fraud is more complex because the transaction itself is often legitimate. The cardholder made the purchase. The product was delivered. The service was provided. What makes first-party fraud challenging is that financial institutions often have limited visibility into events that occur after a transaction is authorized. Determining
whether a dispute stems from confusion, buyer’s remorse, family misuse of a card, or deliberate fraud often requires careful analysis and collaboration across multiple parties. This complexity creates both operational and reputational risks for financial institutions.
method. In these situations, proactive customer education can help reduce unnecessary disputes before they occur. Clear communication about transaction descriptions, recurring payment disclosures, and dispute processes can improve customer understanding while reducing operational burdens for institutions and merchants alike.
Balancing consumer protection and abuse Consumer protections remain one of the most important safeguards in the payments ecosystem. Cardholders need confidence that unauthorized transactions can be resolved quickly and fairly. However, institutions also face growing pressure to identify situations where those protections may be misused. The challenge is not simply detecting fraud. It is distinguishing between legitimate disputes and cases where consumers knowingly abuse the chargeback process. Making that distinction requires more than transaction-level review. It increasingly demands a holistic understanding of customer behavior, dispute patterns, and emerging fraud trends. As first-party fraud evolves, institutions may need to expand their use of behavioral analytics, risk scoring, and historical dispute analysis to identify potentially abusive activity. Data and analytics play a critical role Financial institutions have long relied on analytics to identify suspicious transactions before losses occur. The same approach can help address first-party fraud. Patterns such as repeated disputes, frequent claims involving delivered merchandise, or unusual chargeback behavior may indicate elevated risk. While no single data point proves fraud, combining transaction data with customer history can help institutions make more informed decisions during the dispute process.
The next phase of fraud risk As payment volumes continue to grow and commerce becomes increasingly digital, first-party fraud is likely to remain a significant challenge across the financial services industry. For financial institutions, the issue extends beyond chargeback management. It represents a broader risk management challenge that affects operational efficiency, customer relationships, and the overall integrity of the payments ecosystem. Organizations that invest in data-driven fraud detection, strengthen dispute management processes, and leverage behavioral analytics will be better positioned to navigate this evolving threat. The goal is not to limit consumer protections. It is to ensure those protections remain effective while reducing opportunities for abuse. Friendly fraud may begin with a disputed transaction, but its implications reach far beyond a single chargeback. For financial institutions, understanding and addressing firstparty fraud will be an increasingly important component of modern fraud risk management.
Terri Luttrell CAMS-Audit, CFCS, Abrigo
Advanced fraud monitoring capabilities also enable institutions to identify emerging trends earlier, allowing fraud teams to adapt controls as customer behavior and fraud tactics evolve. Education as part of the solution Many friendly fraud cases begin with misunderstandings rather than malicious intent. Consumers may not recognize a merchant name on their statement, forget about a recurring subscription, or fail to realize a family member made a purchase using a shared payment
FALL 2026 ISSUE
| 29
FRAUD PREVENTION STARTS WITH AWARENESS
WHY CUSTOMER EDUCATION IS YOUR FIRST LINE OF DEFENSE As fraud tactics continue to evolve, banks are investing heavily in technology to protect their customers. Artificial intelligence, behavioral analytics, and advanced authentication tools are becoming essential parts of every fraud prevention strategy. Yet one of the most effective defenses remains surprisingly simple: educating customers. The most sophisticated security systems can still be bypassed if a customer unknowingly shares sensitive information or falls victim to a convincing scam. That's why customer awareness shouldn't be viewed as a oncea-year reminder—it should be an ongoing conversation.
Examples include: • Recognizing phishing emails and text messages • Identifying fake payment requests • Protecting online banking credentials • Knowing when a bank will—or won't—ask for personal information Simple, consistent messaging helps customers feel confident rather than overwhelmed. Reach Customers Where They Already Are
Make Education Easy to Understand Fraudsters constantly change their tactics, making it important for banks to communicate in ways customers can quickly understand and remember. Rather than relying solely on lengthy emails or website updates, consider breaking information into short, digestible messages focused on one topic at a time.
30 | OHIO BANKERS LEAGUE
Educational efforts are most successful when they meet customers in their everyday interactions with your bank. Branch signage, statement inserts, community events, digital displays, social media, and direct mail all provide opportunities to reinforce fraud prevention messages. Even small reminders placed in high-visibility areas can prompt customers to pause before responding to a suspicious text or transferring funds.
Make Your Message Memorable
Small Conversations Can Prevent Big Losses
People are more likely to retain information when they engage with it. Educational campaigns that include helpful reference materials—such as wallet cards with fraud reporting numbers, desktop reminders, calendars featuring monthly security tips, or branded giveaway items with QR codes linking to fraud resources—can keep important information accessible long after a campaign ends.
Technology will continue to play an important role in preventing fraud, but customer education remains one of the most cost-effective investments a bank can make. Every conversation, reminder, and educational resource has the potential to stop fraud before it happens.
The goal isn't simply to distribute promotional products; it's to provide practical tools that encourage customers to think about security throughout the year. Empower Employees to Reinforce the Message Your frontline staff are often the first line of defense when something doesn't seem right. Providing employees with consistent educational materials and conversation starters allows them to confidently answer questions and reinforce fraud prevention best practices during everyday customer interactions.
By combining consistent communication with practical, easy-to-remember educational tools, community banks can strengthen customer trust while helping protect the people and communities they serve. Fraud prevention isn't just about responding to threats— it's about empowering customers with the knowledge to recognize them before they become victims.
Bella Ruscheinski Solutions Project Manager, Spry
When employees and customers receive the same messaging, banks create a stronger culture of awareness across every touchpoint.
Visit www.ohiobankersleague.com for more information.
FALL 2026 ISSUE
| 31
ACH FRAUD TRENDS
WHAT BANKS NEED TO KNOW The Fraud Landscape Is Changing ACH continues to be one of the most efficient and widely used payment methods in the United States, but the tactics used by fraudsters are becoming more sophisticated. Increasingly, the greatest risk is not a compromise of the ACH Network itself. Instead, criminals are exploiting people, credentials, business processes, and payment instructions to convince legitimate users to initiate payments to fraudulent accounts. Business Email Compromise Remains a Major Threat Business Email Compromise (BEC) continues to be a leading concern. According to reporting highlighted by Nacha from the 2026 AFP Payments Fraud and Control Survey, 74% of organizations experienced BEC attempts in 2025, up from 63% the prior year. Spoofed emails were especially prevalent. In a typical BEC scenario, a fraudster impersonates an executive, employee, vendor, or other trusted party and requests that payment instructions be changed. Because the resulting ACH credit may be properly authorized by an employee who believes the request is legitimate, traditional controls focused only on unauthorized transactions may not identify the fraud.
instructions using a trusted contact method—not the phone number or email address contained in the payment-change request itself. 2026 Nacha Rules Expand Fraud Monitoring This year also marks an important change in ACH fraud prevention. Nacha’s new Risk Management Rules expanded fraud-monitoring responsibilities across the ACH ecosystem. Phase 1 became effective March 20, 2026, and Phase 2 became effective in June 2026. The requirements now call for risk-based processes and procedures designed to identify ACH entries suspected of being unauthorized or authorized under “False Pretenses.” The rules affect ODFIs, RDFIs, non-consumer Originators, Third-Party Senders, and applicable ThirdParty Service Providers. For RDFIs, monitoring incoming ACH credits can include factors such as transaction velocity, unusual activity, account age, average balances, SEC Code anomalies, and other account characteristics. Nacha also identifies tools such as anomaly detection, behavioral tolerances, pattern recognition, and velocity checks as potential components of a fraud-monitoring strategy. What Banks Can Do
Credit-Push Fraud Is Driving New Attention Credit-push fraud has become an important focus for the payments industry. Unlike an unauthorized debit, these schemes often manipulate an authorized user into willingly sending funds to an account controlled by a fraudster. Vendor impersonation, payroll redirection, account takeover, and fraudulent changes to beneficiary information are common examples. Banks should encourage commercial customers to independently verify new or changed payment
32 | OHIO BANKERS LEAGUE
Technology is important, but effective fraud prevention requires multiple layers of defense. Banks should review ACH risk assessments and monitoring procedures at least annually, strengthen authentication and access controls, establish procedures for verifying changes to payment instructions, educate commercial customers about social-engineering threats, and ensure that operations, treasury management, compliance, fraud, and relationship teams communicate when suspicious activity is identified.
Customer education is particularly important. Businesses should be encouraged to use dual control for ACH origination, limit user permissions appropriately, review transactions and account activity promptly, and treat unexpected requests to change banking information with caution.
Sources
Staying Ahead of the Threat
• Nacha, “Business Email Compromise Attempts Rose Sharply in 2025, Report Finds,” May 13, 2026.
ACH remains a secure and dependable payment network, but fraud prevention is increasingly a shared responsibility. As criminals become more effective at exploiting trusted relationships and legitimate payment processes, banks and their customers must become equally effective at recognizing unusual behavior before funds leave the account. The strongest defense combines technology, welldesigned controls, employee awareness, customer education, and rapid communication. In today’s environment, preventing ACH fraud is no longer simply about identifying an unauthorized transaction—it is about identifying when an authorized transaction may have been initiated because someone was deceived.
• Nacha, “Risk Management Topics – Fraud Monitoring Phase 1 & Phase 2,” 2026. • Nacha, “Credit-Push Fraud Monitoring Resource Center,” 2026.
• Association for Financial Professionals, Payments Fraud and Control Survey reporting.
Nellie Schlachter Director of Growth & Client Relations, Unity FI Solutions
SINCE 1991 With over three decades of serving lenders and millions of flood certificates issued, why trust just any certification provider when you could hire what many would consider the industry leader in accuracy and customer care.
Ask craig how to experience the Fci difference risk free and learn more about why so many lenders trust floodplain consultants.
Craig callahan | 800.945.0246 ccallahan@floodplain.com FALL 2026 ISSUE
| 33
TURN YOUR ATTENTION TO WIRE FRAUD PREVENTION Picture It: Stanley Jones, a long time bank customer approaches the teller line at your financial institution, some printed emails in hand and a sense of urgency written all over his face. Mr. Jones tells Sara, the young, newly hired teller, that he needs to send a wire transfer and it needs to be done quickly. Sara leans into her training and begins asking Mr. Jones some additional, clarifying questions regarding the nature of the wire. Mr. Jones gets more and more frustrated, finally blurting out, “My grandson is in trouble! Stop asking me questions and help me get this done!” As you read the scenario between Mr. Jones and Sara, red flags were likely popping up in your mind. Is Mr. Jones, the victim of an elder abuse scam? Could this situation be an email account compromise? Is Mr. Jones’s sense of urgency a tactic used by the scammers to get him to act quickly without considering the source of the request for funds? On top of the obvious business red flags, there are the complicating factors of customer dynamics. Is the customer always right? Sara is a young, newly hired teller and Mr. Jones has banked with you for years. Sara is unsure how far she should push Mr. Jones; she doesn’t want to make him upset or make him feel like she is questioning his integrity. In the various payments channels available to consumers today, there are certain safeguards built in to prevent fraud from occurring. The debit and credit card industry has regulations, spending limits, behavioral anomaly detection software and authorization filters among the fraud prevention tools in their toolkit. Similarly, consumers who are sending funds via ACH are protected by NACHA rules and regulations, authorization requirements, transaction limits and more. Who or what is protecting consumers that want to send a wire transfer? We are! Financial service professionals are the FRONT LINE to prevent wire fraud. There are several things we have a responsibility to do to help prevent fraudulent wire transactions from taking place, including: verifying account holder identity, identifying red flags and always reporting suspicious activity. As fraudsters get more sophisticated, we must adapt our approach to verifying our customers’ identity. The old methods of relying on caller ID, the last four digits of an account holder’s social security number or even account history information aren’t enough anymore; this
34 | OHIO BANKERS LEAGUE
information could have already been compromised. We need to be more creative in the ways we verify identity by digging deeper and asking the questions that can’t be easily spoofed by fraudsters. Some ideas include: what’s your safety deposit box number, at which branch did you open your account, or after authenticating a caller or upon an in person visit, you could set-up an account password to use in lieu of verification questions. Asking the “who, what, when, where, why” while initiating a wire transfer can uncover unusual behavior such as if someone is being taken advantage of or sending funds under other false pretenses. Looking for red flags can often help a fraudulent wire from being sent in the first place. Empowering your front line staff to ask questions about relationship details, the purpose of payment, or unusual account activity can head off a potentially devastating loss for the customer. If your staff suspects a wire may be fraudulent, make sure they know it is okay to refuse to send the wire or get the bank’s BSA or compliance officer involved. Sometimes even with the best preventative measures in place, fraud can still happen. The quicker you can get word to the receiving bank that fraud has occurred the better. Follow your bank’s internal policies, file a suspicious activity report with FinCEN, encourage your customer to file a police report, and assure your customer that they are not in this situation alone. To help prepare for what may be requested by the receiving financial institution, gather details and documentation regarding the fraudulent activity. This could include copies of your internal wire transfer request, a timeline of events, nature of the transaction, payment details and any law enforcement documents. Fraud can happen at any financial institution at any time and unfortunately, sometimes we don’t think about enhancing procedures to identify fraud, until after it occurs. United Bankers’ Bank is committed to assisting your bank in any way possible to help mitigate fraud.
United Bankers’ Bank
Stay One Move Ahead of the Competition
Discover® Debit Gives You The Advantage. When it comes to your debit program, you should always have the upper hand. Discover® Debit puts you in control of the board with superior economics, marketing support, and personalized service. Checkmate. Debit that’s here for you.® Find out more at DiscoverDebit.com/Win
FALL 2026 ISSUE
| 35
Mortgage Purchase Program Secondary Mortgage Market Access Built for You
SELL LOANS GAIN LIQUIDITY REDUCE RISK
CONTACT YOUR RELATIONSHIP MANAGER TO GET STARTED
36 | OHIO BANKERS LEAGUE
Bryan Parkhurst AVP, Relationship Manager parkhurstbc@fhlbcin.com 513-432-4632
Montez Shugars AVP, Relationship Manager shugarsmk@fhlbcin.com 513-852-7693
PREPARE YOUR BANK FOR AI-ENABLED FRAUD AI is accelerating bank fraud whether a bank is officially using AI or not: check fraud, account takeovers, and fraudulent account openings are just the start. Fraudsters can now generate fake documents, imitate voices, write convincing phishing emails, create synthetic identities, and automate attacks at machine speed. This means banks face risk not only from online banking systems, vendors, employees, and call centers, but also from AI itself. AI systems can be attacked through prompt injection, data poisoning, model manipulation, and attempts to extract confidential information. Even if a bank has not formally adopted AI, its employees, customers, vendors, and fraudsters are already using it. AI also increases the speed and scale of traditional attacks. Social engineering becomes more personalized. Credential attacks become more sophisticated. Deepfake audio and video can defeat old identity checks. Fraud teams that rely only on legacy rules, manual reviews, or human judgment will increasingly fall behind.
1 Examples of New Risks The list of new risks is extensive – both inside and outside the bank. Here are some new risks: • Shadow AI and accidental data breaches: An employee might take a picture of customer personally identifiable information and upload it into a public ChatGPT account. • Personalized phishing and social engineering: Fraudsters can use AI to create highly customized scams across email, text, phone, chat, and social media. • Deepfake impersonation: AI-generated voices and videos can imitate customers, executives, vendors, or trusted third parties. • Synthetic identity fraud: Fake identities can be supported with AI-generated documents that look increasingly real.
FALL 2026 ISSUE
| 37
The bad guys are already using AI. Banks need AI to fight back.
• Automated account takeover: Criminals can automate and customize attacks using breached passwords, social media, and dark web data.
• Data loss prevention and access controls to prevent employees, vendors, or AI agents from exposing customer PII or confidential bank data.
• Poisoned data and altered instructions: Fraudsters may use fake urgency, altered payment instructions, fraudulent merchants, poisoned data, or impersonation attempts to trick employees, customers, or AI systems.
• Do not use old data as authentication. If criminals can buy it — Social Security numbers, old addresses, breached passwords, account history, or mother’s maiden name — it cannot prove identity.
2 Mitigation and Regulatory Requirements
Banks also need to remember that existing rules still apply. AI does not create an exception to privacy, cybersecurity, consumer protection, or bank regulatory requirements. Customer data must be protected. AI use must be governed. High-risk decisions must be explainable, reviewable, and defensible.
You absolutely must start with employee and customer training. The more they know, the less likely you are to be a victim. Also, banks need private AI, not casual use of public AI tools. Confidential and customer data should stay in controlled environments, preferably inside a private or hybrid cloud. Banks also need clear AI policies, defensible controls, and audit trails that show what data was accessed, what outputs were generated, and who approved high-risk actions. Beyond that, banks need to both use AI safely as well as use AI to defend your bank and your customers. Key action items include: • Employee training on AI-enabled fraud, shadow AI, deepfakes, phishing, data privacy, and what information may never be uploaded to public AI tools. • Private AI at your bank (and not Copilot) so confidential customer data can be used safely inside controlled environments. • Deepfake detection for call centers, video interactions, executive approvals, wire requests, and high-risk customer interactions. • Multifactor authentication for employees and customers, especially for account access, password resets, payment approvals, administrative privileges, and changes to customer information. • Immutable AI audit trails that record prompts, outputs, model versions, approvals, overrides, incidents, and compliance evidence.
38 | OHIO BANKERS LEAGUE
3 Conclusion Copilot is not enough. Banks need private AI, secure data governance, audit trails, deepfake defenses, stronger authentication, and advanced fraud detection. Community banks do not need to build this on their own. Fintech companies have been working on solutions here for years. Find your strategic partners for the brave new world of AI.
Alec Crawford Founder & CEO, Verapath
Turn Your network questions into clear decisions
OptimizeIQSM Delivers Data-Informed Answers Identify your best growth opportunities Determine whether your branches are reaching full market potential Optimize your network to improve efficiency, ROI, and CX
network analysis
Trade Area Study
Requst a demo, sample analysis, or connect with a data expert at www.pwcampbell.com
Expansion Study
FALL 2026 ISSUE
| 39
OBL BANKING CALENDAR
MAIN EVENT
October 26 – 28 | Greater Columbus Convention Center
STEPPING UP TO SUPERVISOR October 1
Take Flight: Banking at Full Throttle
A promotion into leadership is exciting - but it also comes with new challenges.
Join industry leaders at this fourth annual event featuring keynotes, eight learning tracks, executive roundtables, OBL BankServices EXPO, Ohio BankPac Silent Auction, networking opportunities, and the presentation of the OBL Industry Awards.
Stepping Up to Supervisor is a one-day seminar designed to help new and emerging leaders successfully transition into supervisory roles with confidence. Excelling as an individual contributor does not automatically prepare someone to lead a team. Moving from peer to supervisor can be one of the most challenging transitions in a career, requiring new skills in communication, accountability, motivation, and team management. Many supervisors find themselves asking: What makes a great leader? How do I motivate employees? How do I navigate difficult conversations or manage different personalities? This program provides practical tools, realistic expectations, and leadership strategies to help supervisors build confidence, avoid common pitfalls, and lead more effectively from day one.
It is no secret that the world is changing at a rapidly evolving pace. Staying up-to-date on key issues in the banking industry is paramount, and the Main Event is a great opportunity to hear the latest information, regulatory changes, technology, fraud, economic factors and more, all while keeping you connected with those who can help the most – peers and service providers. The eight learning tracks provide educational opportunities for the entire management team at the bank. The tracks featured are Compliance & Risk Management, Executive, Finance, Human Resources, Legal, Lending, Marketing, and Retail & Operations. In addition to the industry specific sessions, attendees will also hear about Supersonic Success from the opening keynote, Jack Becker, and Building Moments that Matter: From Good to Unforgettable from the closing keynote, Nolan Nichols. There is truly something for every member of your team at the OBL Main Event. Don’t wait, register today!
40 | OHIO BANKERS LEAGUE
WOWING THE CLIENT October 28
Our Wowing the Client workshop equips frontline branch professionals with the skills to create exceptional client experiences, build stronger relationships and help clients achieve their financial goals. Participants will explore how technology is transforming banking, how to become a more engaged team member and how to uncover client needs and dreams to recommend the right products and solutions. The program covers client expectations, onboarding, relationship growth, cross-selling, data-driven decision making and streamlined work processes, along with strategies for working with Gen Z and Millennial clients and coworkers. Participants will also learn national best practices from branch professionals across the country, develop leadership skills and create an action plan to bring what they learn back to the job.
FDIC DIRECTORS COLLEGE November 5
Join us for the 2026 FDIC Directors College - an opportunity offered only every other year and not available again until 2028. A strong board is essential to a strong bank, yet many directors come from outside industries and may not have a deep understanding of the regulatory, operational, and strategic complexities of banking. FDIC Directors College provides board members with valuable insights into the issues affecting banks today, including regulatory expectations, current challenges, and emerging trends shaping the industry. Participants hear directly from regulators and gain a broader understanding of the many considerations involved in effective bank oversight and decision-making. Whether your board members are seasoned directors or newly appointed, this program offers valuable education tailored specifically to their responsibilities. Join us in person at the Quest Conference Center for this important learning opportunity.
FALL 2026 ISSUE
| 41
AROUND THE INDUSTRY Spotlight On:
First Federal Savings of Lorain Bill Damm Julia Rutkowski Matt Majher Lorain – Bill Damm joins First Federal Savings of Lorain as VP- Residential Lending. Bill is a results-focused banking and mortgage leader with over 30 years of experience in business management, sales strategy, team development, and strategic marketing. Known for his leadership and people-first approach, his strengths include coaching, training, communication, relationship-building, and recruiting. He has been actively involved in local builder, realtor, and community organizations throughout his career. Julia Rutkowski joins First Federal Savings of Lorain as AVP Residential Lending Operations. Julia brings more than 20 years of experience in mortgage sales, management, and operations. She will play a key role in supporting the bank’s growth while maintaining its strong commitment to the community. Julia has led highperforming teams and complex initiatives with clarity and consistency. She excels at improving processes, technology, and team performance to deliver measurable results. Matt Majher joins First Federal Savings of Lorain as Treasurer. Matt has been a Certified Public Accountant since 1991, he has dedicated his career to serving customer focused organizations, primarily health care and banking. Matt earned his Bachelor of Science in Accountancy from Case Western Reserve University and his Masters in Business Administration from Cleveland State University.
Minerva Consumers National Bank announced the addition of Stephen Karapasha, Chief Risk Officer and Chief Legal Counsel to the executive management team. He reports to President and CEO, Ralph J. Lober II. “Stephen’s experience in risk management, compliance, bank Stephen operations, mergers, and legal at the Karapasha community bank level brings a unique skill set and perspective to this role. I look forward to him elevating Consumers’ risk management programs and practices while maintaining our community and customer focus. As a career community banker, he understands the unique challenges and opportunities that community banks encounter. Additionally, it is nice to bring a local native back to Stark County,” said Lober. Mansfield Mechanics Bank is pleased to announce Lindsay Alton has been promoted to Senior Vice President, Controller.
42 | OHIO BANKERS LEAGUE
Lindsay joined Mechanics in 2018 and served as a Senior Financial Analyst and Strategic Finance Manager prior to her current role. Lindsay has over 20 years of experience in the banking industry and holds a bachelor’s degree from Taylor University.
Lindsay Alton
Sandusky Please join us in congratulating Chuck Parcher on becoming President and CEO of Civista Bank and Civista Bancshares, Inc. With more than 38 years in banking and a proven track record of leadership, Chuck has dedicated his career to helping businesses, customers, and communities thrive. Since joining Civista in 2016, he has been a driving force behind our success and growth.
Chuck Parcher
BRANDING
ARCHITECTURE
INTERIOR DESIGN
GRAPHIC DESIGN
MARKETING
CONSTRUCTION
K4ARCHITECTURE.COM | 513.842.K4K4 | 555 GEST ST, CINCINNATI, OH 45203
Farmers & Merchants Bank - Springboro, OH
THIS DOCUMENT, AND THE IDEAS AND DESIGNS INCORPORATED HEREIN, IS THE PROPERTY OF K4 ARCHITECTURE, L.L.C. AND IS NOT TO BE USED, IN WHOLE OR IN PART, FOR ANY OTHER PROJECT,WITHOUT THE WRITTEN AUTHORIZATION OF K4 ARCHITECTURE, L.L.C. COPYRIGHT 2013: K4 ARCHITECTURE, L.L.C. ALL RIGHTS RESERVED
First Federal Community Bank - Dover, OH
Center Bank - Cincinnati, OH
Sutton Bank - Tiffin, OH
Southern Hills Community Bank -HILLS West Union, OH SOUTHERN BANK DATE: 06/03/2025
The Middlefield Banking Co - Westerville, OH K4 ARCHITECTURE, LLC 555 Gest Street Cincinnati, Ohio 45203 Tel: (513) 455-5005 Fax: (513) 455-5008
WEST UNION, OH
KEEP DESIGN & CONSTRUCTION DOLLARS IN OHIO SHOP LOCAL - BANK LOCAL - BUILD LOCAL
State Bank of Lizton Main Office - Brownsburg, IN
Center Bank - Cincinnati, OH
First Financial Bank - Hamilton, OH
The Union Bank Co. - Columbus Grove, OH
The Apple Creek Banking Co. - Wooster, OH
Center Bank - Cincinnati, OH
Richwood Bank - Bellefontaine, OH
FALL 2026 ISSUE
| 43
Your Partners in BOLI and Benefit Planning 44 | OHIO BANKERS LEAGUE