The Price of the Press

By Frank Abagnale, Founder, Abagnale and Associates

In 2025 the payment method American businesses were defrauded through most often was the paper check. Not the wire. Not ACH. The check. That is not nostalgia, it is a warning.

American businesses were asked which payment method exposed them to fraud most often in 2025. The answer was the paper check. Fifty-eight percent named checks, more than ACH debits and more than wire transfers. Those same businesses had instant payments available to them throughout the year. Yet the payment instrument most often associated with fraud was still a piece of paper.

I have spent about twenty years designing security into negotiable instruments, and I think that result is embarrassing rather than quaint. The check survives as one of fraud’s favorite instruments because the industry that replaced paper failed to carry forward what the check industry spent decades learning.

Sentiment has nothing to do with it.

What Paper Got Right

A document is secured by being expensive to reproduce, not by looking official.

That sounds obvious now. It was not obvious at the time, and it took the banking industry decades, and a great deal of money, to learn it. When I designed the SuperBusinessCheck for Safechecks, we put sixteen security features into it. Multi-tonal watermark paper made at the mill rather than printed afterward. Stock that reacts to a range of chemicals, so attempts to lift ink leave a stain a teller can see. Toner anchorage incorporated into the sheet so the printed amount melds into the paper, because an amount that can simply be scraped away is not secure. Multicolored fibers. Even the presses themselves were secured.

Those are the features people photograph and put in brochures.

The feature that matters most is harder to photograph. The stock is never sold completely blank. It is customized before it leaves the manufacturer.

Much of the check stock used in America is uncontrolled. Someone can buy the same blank stock a legitimate company uses, and the only thing separating that person from a convincing instrument may be a printer.

Controlled stock changes the equation. Visible security features increase the cost of producing a forgery. Controlled stock denies the forger the raw material in the first place. That distinction is one of the most important things paper security figured out, and one of the things digital identity largely forgot.

Before the Press Was Free

Forgery once required capital.

Printing convincing checks in the 1960s required serious printing equipment. A commercial press represented an enormous investment, and it took skilled people to operate. Nobody acquired and operated such equipment casually, and that was, in itself, a security control. The check was not secure simply because it was cleverly designed. It benefited from the fact that reproducing it convincingly required equipment most people could not obtain.

I have said for years that fraud is roughly four thousand times easier than it once was. People sometimes hear that as a comment about criminals becoming four thousand times smarter.

It is not.

It is a comment about the price of the press. Human gullibility did not change by a factor of four thousand. The capital required to create a convincing forgery collapsed, and when that capital requirement disappeared, much of the security that depended upon it disappeared as well.

Every meaningful security feature I have designed has been an attempt, in one form or another, to put some of that cost back.

What Digital Did Not Carry Forward

When identity moved online, the industry inherited the check’s confidence without carrying forward enough of its engineering.

A digital identity claim is asserted rather than manufactured. There is no controlled stock, nothing that had to be milled or physically obtained. A name. A date of birth. The last four digits of a number that has appeared in so many breaches that treating it as a secret is increasingly difficult to justify.

The person on one end supplies those facts. The system on the other end compares them with facts it already has. That creates a problem: the attacker may control both the claim and the information being used to substantiate it.

We can see a related weakness in check fraud itself. In mail-theft cases reported by American banks to FinCEN during a six-month period in 2023, altering a stolen check and negotiating it was the most frequently reported outcome, at roughly 44 percent. Using the stolen check as a template for counterfeit checks accounted for about 26 percent, while forging the signature accounted for about 20 percent. In each case, the attacker is not necessarily defeating the verification system. The attacker is supplying what the verification system expects to see.

That is also the weakness at the heart of many digital identity systems.

Sixty percent of American financial institutions reported check fraud last year. Debit card fraud, the most widespread kind, reached seventy-five percent. A paper instrument designed for a pre-digital economy can sit that close to the top in 2026 because digitization did not automatically raise the cost of forgery.

In many cases, it lowered it.

A Forged Document With Better Production Values

I am constantly asked whether deepfakes represent something genuinely new. I understand why people want the answer to be yes. It is more comfortable to be facing an unprecedented problem than an old one you did not solve.

A synthetic voice on a telephone call is, in security terms, a forged document with better production values. The underlying crime has not changed. Someone presents a credential they did not earn to a person or system responsible for inspecting it, using a reproduction convincing enough to survive the inspection being performed.

The reproduction once required a printing press. Now it may require little more than a recording. Yet in many organizations, the inspection has barely changed.

We removed the physical substrate from the credential and then asked a human being to authenticate the claimant by listening to them. No competent bank would have asked a teller to authenticate a check based on how confident the person presenting it sounded. That would have been recognized as virtually no authentication at all. Yet it is remarkably close to what many organizations still ask of the person answering the telephone at a help desk.

What Carries Over

The lesson from paper is not a list of physical security features that should somehow be recreated online. Microprinting does not need a digital equivalent. Neither does watermark paper. What matters is the principle beneath those features, and that principle survives the change in medium:

Verification has to be anchored to something the attacker does not control.

That is what controlled stock accomplished. It was an unglamorous piece of logistics, but it worked whether or not the person at the counter was particularly observant. A necessary component of the crime existed somewhere the criminal could not easily obtain or reproduce. Every effective security feature I have worked with has some version of that property. Weak ones ultimately depend upon something the attacker can get hold of.

So when someone calls your help desk and asks to have access restored, training your employee to recognize a suspicious caller matters less than one question.

What is the employee verifying against?

If the answer is a collection of facts the caller could have bought or taken in a breach, you have effectively handed the attacker uncontrolled stock and asked an employee to identify the forgery by ear. If verification instead depends upon a credential or authoritative record that exists outside the caller’s control, and cannot simply be reproduced by the caller, then you have begun to rebuild the principle that made controlled paper secure.

I spend much of my time now watching companies discover this lesson the expensive way. That is how the check industry learned it too.

The difference is that the check industry had decades to learn.

We do not.

Because now the press is free.

Frank W. Abagnale has worked in fraud prevention and secure document design for more than five decades. He spent about twenty years advising the Standard Register Company and Safechecks on security features for negotiable instruments and designed the Frank Abagnale SuperBusinessCheck. He holds patents on anti-counterfeiting components and has consulted with financial institutions and government agencies internationally.

Sources: 2026 AFP Payments Fraud and Control Survey Report, Association for Financial Professionals, announced 14 April 2026 (paper checks the most targeted payment method in 2025, cited by 58 percent of organizations). Federal Reserve Financial Services 2026 Risk Officer Report, announced 22 April 2026, from a fourth-quarter 2025 survey of more than 400 risk professionals (60 percent of institutions reported check fraud; debit card fraud the most widespread type at 75 percent, accounting for 40 percent of total payments fraud losses). FinCEN Financial Trend Analysis, Mail Theft-Related Check Fraud: Threat Pattern and Trend Information, February to August 2023, from 15,417 BSA reports covering more than $688 million in transactions (altered checks approximately 44 percent of reports, counterfeit 26 percent, fraudulently signed 20 percent). Abagnale Fraud Bulletin, Volume 17, on the SuperBusinessCheck’s 16 safety features, its dual-tone true watermark, toner anchorage, and controlled stock never sold completely blank without first being customized for a specific customer.

Hot Topics

Related Articles