Security experts warn that fake ACH notification emails, designed to appear legitimate, are increasingly used to steal login credentials and perpetrate broader financial fraud, urging users to remain vigilant and verify through trusted channels.
An email claiming that an ACH payment has been put on hold may look routine at first glance, but security researchers say the message is a phishing lure rather than a genuine payment notice. MalwareTips reported that the campaign borrows the names of Fiserv, Microsoft and Citrix to make the message appear credible, while the real aim is to push recipients towards a counterfeit sign-in page. Similar guidance from the University of California, Berkeley warns that unexpected ACH or electronic funds transfer emails are a common phishing tactic, especially when they ask users to log in through a link instead of checking through a trusted channel. MalwareTips also said one observed version used an urgent three-day expiry to pressure the recipient into acting quickly.
The bogus email typically claims that a merchant credit, refund or settlement cannot be completed until a document is reviewed. That mix of payment jargon, e-signature language and cloud-service branding is deliberate, because it creates the impression of a complicated but legitimate workflow. Legal Clarity, in a separate explainer on ACH notification scams, said one of the clearest warning signs is a message that demands verification through a link, uses generic wording or comes from a sender address that does not match the supposed institution.
In the campaign documented by MalwareTips, the button in the email led to a compromised website that then presented a fake Citrix Cloud login page. That step is central to the scam: the page is designed to capture Microsoft or Citrix credentials, and in some cases a multifactor authentication code as well. Berkeley’s security office has warned that phishing emails often try to steer users to non-official login pages, where stolen passwords can be reused across company email, cloud applications and virtual desktops.
The risk does not end with a single stolen password. Security researchers note that attackers often try the same login on workplace email, VPNs and cloud portals, then search the account for invoices, vendor details and bank information. MalwareTips says a finance mailbox can be especially valuable because it can help criminals prepare follow-on fraud, such as changing bank details or sending fake payment instructions. ScamArchive and PayPal-focused scam warnings describe a similar pattern in “payment on hold” frauds aimed at sellers, where the false delay is used to trigger panic and prompt the victim to take the wrong next step.
The safest response is to ignore the link, verify any suspected payment through a bank portal or accounting system opened from a known bookmark and contact the supposed sender using a trusted phone number or email address already on file. Legal Clarity and Berkeley both advise checking unexpected payment messages through separate channels rather than replying inside the same email thread. If credentials were entered, security teams recommend changing the password immediately, revoking active sessions, reviewing mailbox rules and alerting finance staff in case the attack has moved beyond credential theft.
Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.





