Report an ACH Data Breach

Data security is essential to the ACH Network, and Nacha takes any and all data breaches seriously. We rely on your prompt reporting of any such breaches in order to monitor Network trends and weaknesses. If your financial institution has experienced a consumer-level ACH data breach, we provide a standardized form to notify us of the incident.

Our Interim Policy on ACH Data Breach Requirements provides a clear means for ODFIs to report any theft or misuse of consumer-level ACH data. That reporting, in turn, increases the Network’s security and helps Nacha mitigate future data theft.

Requirements for Reporting an ACH Data Breach

If an ODFI suspects that there has been an ACH data breach of consumer-level data, the Interim Policy requires that:

  • The ODFI notify Nacha of the ACH data breach
  • The ODFI notify affected RDFIs of the ACH data breach

To report an ACH data breach, ODFIs should use the form below. A Nacha representative will confirm receipt of your submitted information within 24 hours.

ACH Data Breach Reporting Form