Categories: The Verge

New York claims Zelle’s shoddy security enabled a billion dollars in scams

New York Attorney General Letitia James is suing the banks behind Zelle over claims that their payment platform enabled “massive amounts of fraud” that caused customers to lose more than $1 billion between 2017 and 2023. In the lawsuit, James alleges Zelle was rushed to market, resulting in a design that made the platform “an obvious conduit for fraudulent activity.”

Early Warning Services (EWS), a company owned by major institutions including Bank of America, Capital One, JPMorgan Chase, Wells Fargo, and others, launched Zelle in 2017 as a way to let customers send money from their bank account to other users on the platform. However, James claims EWS “knew from the beginning that key features of the Zelle network made it uniquely susceptible to fraud” and still “failed to adopt basic safeguards.”

One of the alleged issues highlighted by James’ lawsuit includes a registration process that ”lacked important verification steps” that enabled scammers to sign up using misleading email addresses, which they could use to pose as a government employee or business to trick Zelle customers into sending them money that they couldn’t get back. Following government pressure, Zelle began paying back victims of imposter scams in 2023.

Additionally, James claims EWS did not ensure that banks reported customer complaints about fraud in a “timely” manner and falsely advertised the service as a “safe” money transfer tool. “Even when EWS did receive reports of fraud, it failed to promptly remove the fraudsters from the Zelle network or require banks to reimburse consumers for certain scams,” James alleges.

The lawsuit touches on many of the same points as the one initially filed by the Consumer Financial Protection Bureau. In March, the CFPB dropped its lawsuit against Zelle amid the Trump administration’s attempt to dismantle the agency and the firing of former head Rohit Chopra, who had taken an aggressive approach to tech regulation. That still hasn’t stopped scrutiny from federal lawmakers — and now, New York’s attorney general.

Zelle spokesperson Eric Blankenbaker pushed back on these claims in a statement to The Verge, saying Zelle “leads the fight to stop fraud and scams” in the US. “This lawsuit is a political stunt to generate press, not progress,” Blankenbaker says. “The Attorney General wants to hand criminals a blueprint for guaranteed payouts with no consequences, opening the floodgates to more scams, not less. That’s bad policy and puts consumers at greater risk.”

Attorney General James claims EWS violated New York law and is asking for restitution and damages for all New Yorkers harmed by scams on Zelle. “I look forward to getting justice for the New Yorkers who suffered because of Zelle’s security failures,” James said in the press release.

rssfeeds-admin

Share
Published by
rssfeeds-admin

Recent Posts

Android 17 Launches Advanced Protection Mode to Stop Malicious Service Exploits

Android 17 is turning Advanced Protection Mode into a far more aggressive defense layer by…

6 minutes ago

Google Looker Studio Vulnerabilities Enable Attackers to Exfiltrate Data from Google Services

Google Looker Studio was affected by nine high‑impact “LeakyLooker” vulnerabilities that could have allowed attackers…

6 minutes ago

Real-Time Phishing Campaigns Use Fake Shipment Alerts To Steal Banking Data In MEA

According to Statista, over 161 billion parcels were shipped worldwide in 2022, cementing courier services…

6 minutes ago

Indirect Prompt Injection Attacks Cause OpenClaw AI Agents to Leak Sensitive Data

OpenClaw AI agents are facing increasing security scrutiny after a warning from China’s National Computer…

7 minutes ago

IBM Links Suspected AI-Generated ‘Slopoly’ Malware To Hive0163 Ransomware Operation

In early 2026, IBM X-Force researchers identified a novel, likely AI-generated malware framework dubbed “Slopoly”.…

7 minutes ago

Microsoft Teams, Quick Assist Exploited To Deliver Stealthy A0Backdoor

Cybersecurity researchers at BlueVoyant have uncovered a sophisticated attack campaign using social engineering to breach…

7 minutes ago

This website uses cookies.