I'm not a cybercrime expert, but AFAIK once the fraudulent ACH goes through it's a matter of cashing out the money (to literal cash or resalable goods) before the ACH is inevitably reverted. This leaves the recipient account with a negative balance so it can basically only be used once.