Skip to main content
Judge Lets $1 Billion Zelle Fraud Case ProceedFraud Typologies
5 min readFor Fintech Risk and Compliance Teams

Judge Lets $1 Billion Zelle Fraud Case Proceed

A New York Supreme Court ruling has denied Early Warning Services' motion to dismiss the state's fraud lawsuit over Zelle scams. This decision allows Attorney General Letitia James' argument to move forward, suggesting that a payment network can be liable for authorized fraud, transactions customers approved after being deceived by criminals.

The case now enters the discovery phase, where both parties will review internal records. If James wins, Early Warning and its seven bank owners (Bank of America, Capital One, JPMorgan Chase, PNC, Truist, U.S. Bank, and Wells Fargo) could face reimbursement liability that extends to over 2,200 banks and credit unions on the Zelle network.

Key Points of the Ruling

Justice Phaedra Perry-Bond has allowed two fraud theories to proceed under New York Executive Law, which addresses "persistent fraud" in business.

Theory One: Early Warning marketed Zelle as safe because it was "backed by the banks," despite knowing the network had significant fraud issues. The company claimed this was mere puffery, but the judge disagreed, noting that Zelle's disclaimers weren't prominent enough to counteract the safety message.

Theory Two: Early Warning allegedly created "an atmosphere conducive to fraud." This theory doesn't require a direct link between the network and the criminals. The judge highlighted Early Warning's admission that it "continued to collect and retain transaction fees from those fraudulent transactions" even while aware of the fraud. Profiting from known fraudulent transactions can be seen as endorsing the fraud.

The complaint claims scammers stole over $1 billion from Zelle users between 2017 and 2023. In 2020 alone, Early Warning recorded 150,000 fraud reports with $80 million in losses.

The Liability Challenge

The Electronic Fund Transfer Act and Regulation E require banks to reimburse unauthorized transactions, where criminals move money without the customer's consent. However, when a customer authorizes a payment after being deceived about the recipient, banks typically aren't liable.

This distinction has been longstanding. James is using state law to address this gap.

If successful, the implications extend beyond Early Warning. Your fraud operations team could face reimbursement obligations for scams your transaction monitoring didn't flag as unauthorized. Your compliance program would need controls for fraud that can't be detected through velocity checks or behavioral analytics because the customer authenticated and approved the payment.

Implications for Your Fraud Program

Immediate Impact: If you operate a payment network or connect to one, your legal team should review state-level fraud statutes. New York's executive law is broad, but other states have similar consumer protection laws. The American Bankers Association has warned that holding networks liable could disrupt nationwide payment systems and create moral hazard.

Detection Gap: Your current fraud controls likely focus on unauthorized transaction patterns, unusual device fingerprints, impossible travel, account takeover signals. Authorized fraud appears clean in your logs because the customer completed MFA and approved the payment. You'll need different detection signals: rushed transactions after customer service contact, payments to newly added payees, transfers that drain account balances.

Policy Exposure: Early Warning claims 99.98% of Zelle transactions finish without fraud or scam reports. This figure is hard to contextualize because payment networks don't report fraud rates in standardized ways. Your board will ask how your network compares. You won't have an answer unless you start tracking authorized fraud separately from unauthorized fraud now.

International Approaches

The UK implemented mandatory scam reimbursement in October 2024. Banks must repay most victims of authorized push payment fraud. Australia passed similar legislation last year, holding banks liable when they fail to protect customers from scams.

Neither country's banking system collapsed. Smaller institutions did implement transaction limits and additional friction for high-risk payment types. Your risk committee should model what UK-style reimbursement would cost your institution based on your current scam report volume.

Action Steps

1. Separate authorized fraud from unauthorized fraud in your reporting. Your Suspicious Activity Report metrics already track this for AML purposes. Your fraud operations dashboard should too. If you can't tell your board what percentage of customer losses come from scams versus account takeover, you can't model reimbursement exposure.

2. Review your payment network agreements for liability allocation. If you connect to Zelle or similar networks, your participation agreement likely addresses fraud liability. Early Warning's seven bank owners are directly exposed in this case. If you're a participating institution, determine whether your agreement includes indemnification language that could push liability downstream.

3. Document your fraud prevention controls with state enforcement in mind. The judge noted Early Warning acknowledged collecting fees from fraudulent transactions while knowing about the fraud. Your internal communications about fraud trends, mitigation decisions, and cost-benefit analyses on controls will be discoverable if your state attorney general files a similar case. Write those memos as if opposing counsel will read them.

4. Model UK-style reimbursement costs. Pull your scam report volume for the past three years. Calculate what mandatory reimbursement would have cost. Present that figure to your risk committee alongside current fraud prevention spending. If reimbursement would cost more than enhanced controls, you have a business case for investment.

5. Test customer education effectiveness. Early Warning's defense will likely argue it warned customers about scams. Your current fraud alerts and customer communications should be specific, prominent, and testable. If you send generic "be careful of scams" messages, you're creating the same disclaimer problem the judge identified in Zelle's marketing.

Next Steps

Early Warning has 20 days from the ruling to respond. Both sides must propose a discovery plan by September 8. The company has promised to appeal.

Discovery will reveal what Early Warning knew about fraud rates and when it knew it. Other state attorneys general will watch closely. If internal documents show the network prioritized growth over fraud controls, expect similar cases in states with comparable consumer protection statutes.

A settlement could keep those records private but still return money to New York victims. Full litigation would create a public template for other states to follow.

UK Payment Systems Regulator
Australian Securities and Investments Commission

You Might Also Like