New York Attorney General Sues Zelle Parent Over Fraud Failures, Raising Stakes for Real-Time Payment Security
None
<p><span data-contrast="none">If Zelle thought it had sidestepped the wrath of the courts over the rampant fraud and a series of scams between 2017-2023, just because the Trump administration dropped a suit filed by the now-severely hobbled Consumer Financial Protection Bureau, then the company was sadly mistaken.</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">Waiting in the wings to avenge Zelle customers left scrambling, at risk and out over a billion dollars, was New Attorney General Letitia James, who doggedly pursued President Trump and who now has </span><a href="https://ag.ny.gov/press-release/2025/attorney-general-james-sues-company-behind-zelle-enabling-widespread-fraud" target="_blank" rel="noopener"><span data-contrast="none">filed a suit against Zelle’s parent Early Warning Services</span></a><span data-contrast="none">, a conglomerate of big banks, for failing to safeguard customers — accusing the company of poor security measures, chiefly failing to patch old vulnerabilities that they knew existed. </span><b><span data-contrast="none"> </span></b><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">“EWS knew from the beginning that key features of the Zelle network made it uniquely susceptible to fraud, and yet it failed to adopt basic safeguards to address these glaring flaws or enforce any meaningful anti-fraud rules on its partner banks,” the AG’s office said in a release.</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><div class="code-block code-block-12 ai-track" data-ai="WzEyLCIiLCJCbG9jayAxMiIsIiIsMV0=" style="margin: 8px 0; clear: both;"> <style> .ai-rotate {position: relative;} .ai-rotate-hidden {visibility: hidden;} .ai-rotate-hidden-2 {position: absolute; top: 0; left: 0; width: 100%; height: 100%;} .ai-list-data, .ai-ip-data, .ai-filter-check, .ai-fallback, .ai-list-block, .ai-list-block-ip, .ai-list-block-filter {visibility: hidden; position: absolute; width: 50%; height: 1px; top: -1000px; z-index: -9999; margin: 0px!important;} .ai-list-data, .ai-ip-data, .ai-filter-check, .ai-fallback {min-width: 1px;} </style> <div class="ai-rotate ai-unprocessed ai-timed-rotation ai-12-1" data-info="WyIxMi0xIiwxXQ==" style="position: relative;"> <div class="ai-rotate-option" style="visibility: hidden;" data-index="1" data-name="VGVjaHN0cm9uZyBHYW5nIFlvdXR1YmU=" data-time="MTA="> <div class="custom-ad"> <div style="margin: auto; text-align: center;"><a href="https://youtu.be/Fojn5NFwaw8" target="_blank"><img src="https://securityboulevard.com/wp-content/uploads/2024/12/Techstrong-Gang-Youtube-PodcastV2-770.png" alt="Techstrong Gang Youtube"></a></div> <div class="clear-custom-ad"></div> </div></div> </div> </div><p><span data-contrast="none">After the CFPB abandoned its efforts, James is seeking to get restitution and damages for the victims, vowing to get justice for “New Yorkers who suffered because of Zelle’s security failures.”</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><strong>The lawsuit brought by James against EWS “raises important questions about the responsibilities of real-time payment platforms in protecting consumers from fraud,” says John Anthony Smith, CSO at Fenix24.</strong><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><div class="code-block code-block-15" style="margin: 8px 0; clear: both;"> <script async src="https://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js?client=ca-pub-2091799172090865" crossorigin="anonymous" type="c25dde860c8c38960e1a144d-text/javascript"></script> <!-- SB In Article Ad 1 --> <ins class="adsbygoogle" style="display:block" data-ad-client="ca-pub-2091799172090865" data-ad-slot="8723094367" data-ad-format="auto" data-full-width-responsive="true"></ins> <script type="c25dde860c8c38960e1a144d-text/javascript"> (adsbygoogle = window.adsbygoogle || []).push({}); </script></div><p><span data-contrast="none">While the longer-term answers are likely complex and require a dialogue between consumer agencies, regulators, banks, technologists and consumers, the short-term answer is “more than what Zelle did,” which, from previous reports, wasn’t much.</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">“I think there’s a reasonable argument that EWS could be doing more to meet basic consumer protection standards,” says Smith, though whether that might align with current legal requirements is for the courts to decide.</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">And how much to award also lands squarely in the court of the judiciary. Quantifying loss in court can be challenging, but it can also be difficult for companies to assess loss — and associated risk — internally. </span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none"><strong>While Randolph Barr, CISO at Cequence, says that translating cyber risks into defensible financial terms requires both technical depth and financial fluency, he notes that is “a rare skill set to find in one person.”</strong> </span></p><p><span data-contrast="none">He explains that most companies struggle because “their risk teams are comfortable with qualitative ‘high/medium/low’ scoring, but lack the actuarial, statistical, and financial modeling experience” demanded by Factor Analysis of Information Risk (FAIR).</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">“The cleanest way is to anchor it in the company’s risk management program and use FAIR,” which “ties security lapses to actual financial impact — the language boards, regulators, and courts care about — by modeling loss frequency and loss magnitude across direct fraud, legal/settlement costs, remediation, downtime, churn, and reputational impact,” he says.</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">To get it right, organizations must pull in “security practitioners who understand the threat landscape, risk analysts who can quantify probabilities, and finance/legal experts who can map losses to real-world costs,” says Barr. “Without the right people developing and validating the model, organizations risk producing numbers that look precise but don’t hold up under scrutiny from regulators, auditors, or in court.</span></p><p><span data-contrast="none">Smith doesn’t believe EWS is solely to blame for the proliferation of scams; he notes the platform could and should do more to protect customers.</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none"><strong>Trey Ford, chief strategy and trust officer at Bugcrowd, says fraud and abuse losses and primary impacts can be organized and quantified than those caused by cybersecurity incidents.</strong> </span></p><p><span data-contrast="none">Noting that fraud and abuse teams “are battling misuse, abuse, malice, and crime, which requires a massive tranche of data and intelligence that is different from, but complimentary to, cybersecurity research, testing, and work,” he says addressing it “is often more complicated than simply changing a computer configuration, or installing a vendor patch” and “requires significant engineering, product feature planning, and adjustments in business strategy.”</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">Fixing requires “significant engineering, product feature planning and adjustments in business strategy,” says Ford.</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">Smith called for stronger identity verification at the point of registration that includes names, email addresses, phone numbers and even geolocation data. “If someone claims a U.S. mailing address but is physically located abroad, that should raise a red flag.”</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">Platforms could also include “a short delay, say 8 to 24 hours, for transfers to new recipients” to give users a window for canceling or reporting “suspicious activity before funds are irreversibly moved,” says Smith. “It’s a small friction that could make a big difference.”</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">For now, all eyes will be on the courts in New York. “Organizations with mature fraud and abuse teams, especially in the B2C space, will be watching this lawsuit closely,” says Ford.</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">In the end, though, Barr believes there are no winners. “Some frame this as political, but controls were delayed for years while workable safeguards existed elsewhere,” he says</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">While a win for New York “would likely result in a fine and perhaps some mandated reforms,” says Smith, it remains to be seen “whether that translates into meaningful change for consumers, especially in terms of recovering lost funds.”</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">Barr notes the implications of a NY win could be vast —”stronger requirements for networkwide fraud controls and reimbursement policies, faster adoption of UK-style protections in U.S. real-time payments, and more board accountability to document why known controls weren’t deployed sooner.”</span></p><p><span data-contrast="none">Unlike cybersecurity, the primary impacts and losses associated with fraud and abuse can be easily organized and quantified. Secondary and tertiary losses (loss of trust, brand impact, and, in this case, lawsuits) are hard to quantify and plan for in risk management and investment decisions.</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">There is a natural (and correct) tension associated with privacy, and the need to de-anonymize users and usage patterns, to identify fraud and abuse, requiring strong alignment and commitment from the business, engineering and legal.</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">Addressing fraud and abuse is often more complicated than simply changing a computer configuration or installing a vendor patch. It requires significant engineering, product feature planning, and adjustments in business strategy. Organizations with mature fraud and abuse teams, especially in the B2C space, will be watching this lawsuit closely.</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">Whether that aligns with current legal requirements is a question for the courts. A win for New York would likely result in a fine and perhaps some mandated reforms. But whether that translates into meaningful change for consumers, especially in terms of recovering lost funds, remains to be seen.</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">Smith calls for stronger identity verification at the point of registration that includes names, email addresses, phone numbers, and even geolocation data. “If someone claims a U.S. mailing address but is physically located abroad, that should raise a red flag.”</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">Platforms could also include “a short delay, say eight to 24 hours, for transfers to new recipients” to give users a window for canceling or reporting “suspicious activity before funds are irreversibly moved,” says Smith. “It’s a small friction that could make a big difference.”</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">That said, user education is just as critical. Many scams succeed not because of technical flaws, but because users are unaware of the risks. Platforms like Zelle should invest more in proactive education and in-app warnings to help users recognize and avoid scams.</span><span data-ccp-props='{"201341983":0,"335557856":16777215,"335559739":0,"335559740":240}'> </span></p><p><span data-contrast="none">As for the lawsuit itself, I think there’s a reasonable argument that EWS could be doing more to meet basic <a href="https://securityboulevard.com/2024/05/ai-regulation-in-finance-steering-the-future-with-consumer-protection-at-the-helm/" target="_blank" rel="noopener">consumer protection standards</a>. Whether that aligns with current legal requirements is a question for the courts. A win for New York would likely result in a fine and perhaps some mandated reforms. But whether that translates into meaningful change for consumers, especially in terms of recovering lost funds, remains to be seen.</span></p><div class="spu-placeholder" style="display:none"></div><div class="addtoany_share_save_container addtoany_content addtoany_content_bottom"><div class="a2a_kit a2a_kit_size_20 addtoany_list" data-a2a-url="https://securityboulevard.com/2025/08/new-york-attorney-general-sues-zelle-parent-over-fraud-failures-raising-stakes-for-real-time-payment-security/" data-a2a-title="New York Attorney General Sues Zelle Parent Over Fraud Failures, Raising Stakes for Real-Time Payment Security"><a class="a2a_button_twitter" href="https://www.addtoany.com/add_to/twitter?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2025%2F08%2Fnew-york-attorney-general-sues-zelle-parent-over-fraud-failures-raising-stakes-for-real-time-payment-security%2F&linkname=New%20York%20Attorney%20General%20Sues%20Zelle%20Parent%20Over%20Fraud%20Failures%2C%20Raising%20Stakes%20for%20Real-Time%20Payment%20Security" title="Twitter" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2025%2F08%2Fnew-york-attorney-general-sues-zelle-parent-over-fraud-failures-raising-stakes-for-real-time-payment-security%2F&linkname=New%20York%20Attorney%20General%20Sues%20Zelle%20Parent%20Over%20Fraud%20Failures%2C%20Raising%20Stakes%20for%20Real-Time%20Payment%20Security" title="LinkedIn" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_facebook" href="https://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2025%2F08%2Fnew-york-attorney-general-sues-zelle-parent-over-fraud-failures-raising-stakes-for-real-time-payment-security%2F&linkname=New%20York%20Attorney%20General%20Sues%20Zelle%20Parent%20Over%20Fraud%20Failures%2C%20Raising%20Stakes%20for%20Real-Time%20Payment%20Security" title="Facebook" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_reddit" href="https://www.addtoany.com/add_to/reddit?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2025%2F08%2Fnew-york-attorney-general-sues-zelle-parent-over-fraud-failures-raising-stakes-for-real-time-payment-security%2F&linkname=New%20York%20Attorney%20General%20Sues%20Zelle%20Parent%20Over%20Fraud%20Failures%2C%20Raising%20Stakes%20for%20Real-Time%20Payment%20Security" title="Reddit" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_email" href="https://www.addtoany.com/add_to/email?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2025%2F08%2Fnew-york-attorney-general-sues-zelle-parent-over-fraud-failures-raising-stakes-for-real-time-payment-security%2F&linkname=New%20York%20Attorney%20General%20Sues%20Zelle%20Parent%20Over%20Fraud%20Failures%2C%20Raising%20Stakes%20for%20Real-Time%20Payment%20Security" title="Email" rel="nofollow noopener" target="_blank"></a><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share"></a></div></div>