In today’s digital world, financial data is increasingly bought and sold within dark web networks. This includes stolen checks — introducing a new dimension to a traditionally pen-and-paper fraud problem.
Stolen check fraud is increasingly a problem of data proliferation. Once a check is stolen and digitized, it can be copied, distributed, altered and reused across criminal networks, allowing a single compromise to fuel multiple fraud attempts.
For financial institutions, this changes the nature of the challenge. Fraud is no longer limited to the point where a stolen check is deposited or altered. Instead, risk begins much earlier, as stolen check data moves through underground marketplaces and criminal networks long before it reaches the institution, making proactive mitigation critical.
An Underground Marketplace for Stolen Check Data
The dark web now includes networks of forums and fraud shops that enable crimes as a service. Stolen checks are bundled with the infrastructure needed to exploit them, including mule accounts, laundering pathways and step-by-step workflows.
This has significantly lowered the barrier to entry, enabling even low-skill actors to execute sophisticated fraud schemes. As Greg Williamson, Head of Fraud Commercialization Strategy at Nasdaq Verafin recently shared with MarketWatch, checks are “still available, and availability is what swindlers want… [artificial intelligence] is driving the ease of ability for criminals and quasi-criminals to now enter that market and start basically leveraging this paper-check environment to easily make money.” Research from Q6 Cyber, a leading cyber intelligence company, also suggests that criminals are increasingly using AI-assisted tools alongside traditional image-editing techniques to modify stolen checks, further lowering the effort required to operationalize compromised check data.
A Growing Problem Driven by Supply and Scale
The impact of check fraud is significant. Globally, losses reached an estimated $38.5 billion in 2025, with $33.6 billion attributed to the United States alone. This scale is not just a function of how checks are used, but how they are now distributed and reused. Once stolen, checks can be digitized, shared, and resold on the dark web and underground channels, allowing a single compromise to support multiple fraud attempts across actors and institutions.
Ongoing issues within the U.S. mail system also continue to expose large volumes of mail. These include persistent challenges with missing or unaccounted-for master keys — known as “arrow keys” — which can provide access to multiple mail receptacles across delivery routes.
“If the industry cannot completely stop checks from being stolen, the next best opportunity is to identify them once they appear where criminals buy, sell and operationalize stolen financial data.”
– Nick Pearson, AVP, Fraud Product Management, Nasdaq Verafin
Recent oversight findings highlight the extent of these vulnerabilities. A majority of audited United States Postal Service (USPS) facilities (86%) lacked complete arrow key inventories and a portion of keys recorded in official tracking systems (19%) could not be accounted for. Over a recent three-year period, the Postal Inspection Service also received more than 800,000 mail theft complaints. Together, these dynamics reinforce one another. A steady supply of stolen checks, combined with the ability to distribute and reuse them at scale, is amplifying an already significant fraud problem in the United States.
Closing the Visibility Gap in Stolen Check Fraud
Check fraud persists because it exploits a structural vulnerability: The continued reliance on a legacy payment instrument combined with the rapid dissemination of compromised check data across dark web networks. Once a check is stolen, digitized and shared on the dark web, a single compromise can fuel multiple fraud attempts across actors and institutions.
For financial institutions, the challenge is understanding where stolen check fraud originates — and how stolen check data is allowed to scale — before it reaches the account. Closing that gap between where a stolen check is compromised and where fraud is detected is essential to temper the multi-billion-dollar check fraud problem.
“Effective check fraud prevention requires a layered approach that combines consortium intelligence, behavioral and image analysis and investigative expertise. Cyber threat intelligence complements these capabilities by providing visibility into emerging threats on the dark web, helping institutions add valuable context to investigations, better understand risk and make more informed decisions before fraud occurs.”
– Nick Pearson, AVP, Fraud Product Management, Nasdaq Verafin
Increasingly, that requires looking beyond the transaction itself. Stolen checks often move through underground forums, fraud shops and criminal networks long before they are altered, deposited or used in an attempted fraud event. As financial crime and cybercrime continue to converge, cyber threat intelligence can help financial institutions move fraud detection upstream by providing visibility into the environments where compromised financial data is bought, sold and operationalized. By understanding how stolen check data is circulating before it reaches the institution, investigators can gain valuable context, strengthen investigations and identify potential risks earlier in the fraud lifecycle.
For more on using Cyber Threat Intelligence to detect illicit activity earlier, read Nick Pearson’s recent blog Dark Web and Cyber Threat Intelligence: Moving Fraud Detection Upstream.
