Skip to content
RiskTemplates · The Daily Brief Friday, July 31, 2026
Wire The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs JUL 30

Feature Operational Risk

The Zelle Ruling and What Every P2P Payment Operator Has to Fix in Its Fraud Control Framework

A New York judge let the $1B+ Zelle fraud lawsuit proceed on July 21, 2026. The court found Early Warning Services prioritized speed-to-market over fraud controls it had already designed. If you operate a P2P payment product, this ruling is a blueprint of what state prosecutors will look for in your control gap.

By Rebecca Leung · July 29, 2026 ·
Table of Contents

TL;DR

  • On July 21, 2026, a New York state judge let the $1B+ Zelle fraud lawsuit proceed — finding sufficient evidence that Early Warning Services prioritized growth over fraud controls it had already designed
  • This isn’t a Reg E case: APP fraud (where the consumer authorized the transfer under false pretenses) isn’t covered by EFTA’s unauthorized-transaction reimbursement requirements
  • The seven banks owning Early Warning, plus 2,200+ banks and credit unions on the Zelle network, face cascading exposure if the case produces reimbursement obligations
  • State enforcement is filling the void left by the CFPB’s March 2025 dismissal of its federal Zelle lawsuit — and this ruling is the playbook for what comes next

The Federal Path Closed. A State Court Just Opened a Different One.

The CFPB’s Zelle lawsuit ended in March 2025. The Bureau voluntarily dismissed its case with prejudice — the case filed under Director Rohit Chopra accusing JPMorgan Chase, Bank of America, and Wells Fargo of enabling over $870 million in consumer fraud on the Zelle network. Case closed, no reimbursement, no consent order.

New York’s Attorney General had been watching. Letitia James filed her own suit against Early Warning Services LLC — Zelle’s operator — in August 2025, this time using New York Executive Law Section 63(12), which prohibits repeated fraudulent or deceptive acts. On July 21, 2026, a New York state court denied Early Warning’s motion to dismiss, and the case proceeds to trial.

For every compliance officer at a bank, credit union, or fintech operating a P2P payment product: this ruling is worth studying carefully. Not because of Zelle specifically, but because the court’s reasoning maps directly to the gap most P2P programs haven’t closed.

Why This Isn’t a Regulation E Problem

Regulation E is where most compliance teams start when they think about payment fraud liability. That’s partly correct and mostly insufficient.

Reg E — implementing the Electronic Fund Transfer Act — requires financial institutions to reimburse consumers for unauthorized electronic fund transfers. An unauthorized EFT is one that the account holder didn’t authorize, didn’t benefit from, and wouldn’t have authorized if they’d known the full facts. Classic unauthorized transfers: account takeovers, stolen credentials, fraudulent ACH debits.

Authorized push payment (APP) fraud doesn’t meet that test. In an imposter scam, the consumer did authorize the transfer. They were deceived about who was receiving it — a fake government official demanding a tax payment, a fake bank representative “protecting” the account, a fake utility company threatening disconnection — but they voluntarily initiated the payment. The legal authorization exists. Reg E protections, as currently written, largely don’t apply.

The July 23 post on Reg E and FedNow error resolution covers the authorized vs. unauthorized distinction in detail for instant payment programs. The Zelle case operates in a completely different legal lane.

What the New York AG is arguing — and what the court found viable — is that the network operator created conditions that made APP fraud predictably likely and profitable, knew about it, and failed to implement controls it had already designed. That’s a deceptive acts claim under state consumer protection law, not a regulatory compliance claim under EFTA.

What the Court Said Early Warning Did Wrong

The facts alleged in the complaint — which the court found sufficient to proceed — paint a specific picture of control failure:

Pre-launch identity verification was inadequate. Zelle launched in 2017 without identity verification controls that could prevent scammers from creating accounts impersonating banks, government agencies, and utility companies. The complaint alleges that lookalike accounts — using names like “Wells Fargo Fraud Prevention” — were straightforward to create and used systematically to deceive consumers into sending funds.

Fraud reports were logged, not fixed. Zelle had approximately 150,000 induced fraud reports in 2020, representing $80 million in consumer losses — in a single year. The complaint alleges these reports were tracked and dismissed rather than used to redesign the consumer experience or tighten the network’s anti-fraud architecture.

Controls were designed and shelved. The court found the AG had sufficiently alleged that Early Warning’s own teams had designed anti-fraud safeguards as early as 2019 — and that those safeguards were not deployed, at least initially. A design-but-don’t-implement decision is far more damaging in litigation than a failure to identify the problem at all.

Speed-to-market was explicitly prioritized. The court’s ruling specifically notes the AG’s allegation that Early Warning “prioritized accessibility, convenience, consumer adoption, and market dominance at the expense of consumer safety.” This is the finding that will follow the company through discovery and trial.

For P2P program compliance teams, that last point is the one to internalize. A documented business decision to delay or defer fraud controls in favor of adoption metrics creates discovery exposure in any subsequent enforcement action.

The APP Fraud Gap in U.S. Law — and Where It’s Going

The United Kingdom addressed this problem directly. The Payment Systems Regulator’s mandatory reimbursement regime — effective October 2024 — requires sending and receiving banks to split the cost of APP scam reimbursement, capped at £85,000 per claim. Reimbursement is due within five business days unless gross negligence is proven.

Australia passed its Scams Prevention Framework in November 2024, creating mandatory codes with potential fines of up to $50 million AUD for non-compliant firms.

The European Union’s PSD3 framework is expected to address APP fraud liability through mandatory reimbursement provisions.

The United States has no federal equivalent. What it has instead is the situation the Zelle case describes: state attorneys general using consumer protection statutes to hold network operators accountable when federal regulators step back. As Forbes’ coverage of the ruling noted, “New York is writing America’s Zelle fraud rules one lawsuit at a time.”

States with active consumer protection enforcement — California, New York, Texas, Illinois, Massachusetts — are watching this case. A successful outcome for the NY AG would create a template for analogous actions against other P2P payment operators.

What Your P2P Fraud Control Framework Needs Now

The Zelle ruling gives compliance teams a clear roadmap of what prosecutors will look for in a P2P fraud inquiry. Five areas, specifically:

1. Identity Verification at Registration and Onboarding

The complaint’s first allegation is that Zelle failed to verify identities adequately at onboarding, enabling lookalike accounts. For any P2P platform, the question is whether your registration flow can detect:

  • Account names designed to impersonate regulated entities (banks, government agencies, utilities)
  • Device fingerprints or email addresses associated with known fraud networks
  • Velocity patterns suggesting synthetic identity or mule account creation

Documentation should include: what verification is required at registration, what the rejection criteria are, what happens to flagged accounts, and how the thresholds are updated in response to emerging fraud patterns.

2. Real-Time Transaction-Level Fraud Signals

The complaint alleges Zelle lacked adequate real-time controls to identify suspicious transactions before they completed. For instant payment products, where transactions are irrevocable at settlement, this is the last line of detection.

Pre-transaction signals to evaluate and document: unusual first-payment velocity, recipients with no prior transaction history, payment amounts inconsistent with the sender’s historical behavior, text patterns in memo fields matching known scam scripts, device/location anomalies.

For context on the fraud KRIs that matter most for payment programs, the KRI Library includes pre-built fraud metrics across operational risk domains, including transaction monitoring and payment fraud rate tracking.

3. Fraud Safeguard Decision Documentation

This is the element that distinguishes negligence from recklessness in litigation. If your team has evaluated a fraud control — even if you decided not to implement it, or to defer it — that decision should be documented with:

  • The control evaluated
  • The risk it was designed to address
  • Why it wasn’t implemented or was deferred
  • What compensating controls exist
  • Who made the decision and when

A “we thought about it but decided to wait” decision, documented contemporaneously with business rationale, is a defensible record. An undocumented decision that surfaces in discovery as a design-then-shelve pattern is not.

4. Consumer Warnings at the Point of Payment

P2P platforms that include clear consumer warnings before payment completion — “Once sent, this payment cannot be recalled. Never send money to someone you don’t know.” — create a partial defense. Platforms that don’t have the opposite problem: that a consumer had no friction or warning before being defrauded.

The June 2026 post on Reg E P2P payment scam liability standards covers the investigation standards that apply to authorized payment disputes. The pre-transfer warning piece connects to both Reg E dispute outcomes and state law consumer protection analysis.

5. Known-Bad Actor Network Hygiene

If your platform learns that a recipient account has been used to receive fraud proceeds — through a consumer dispute, a law enforcement referral, or a network intelligence share — how quickly is that account suspended or terminated? The Zelle complaint alleges that known fraudsters remained active on the network after being identified.

The FedNow Network Intelligence API, discussed in the July 22 post on FedNow fraud controls, is specifically designed to address this gap for instant payments. For P2P platforms not on FedNow, the equivalent questions are whether bad actor data from external sources (NACHA return codes, law enforcement referrals, network-shared intelligence) is actually being used to take action, and how quickly.

State Enforcement Is the New Federal Enforcement

The trajectory is clear. The CFPB’s federal enforcement capacity has been significantly reduced — 64% fewer nonbank examinations in 2026 than in 2024, and an active retreat from consumer protection cases that were filed under prior leadership. The vacuum is being filled by state attorneys general with broad consumer protection statutes and the political incentive to pursue cases involving visible consumer harm.

Zelle is the highest-profile example, but it’s not alone. The New York AG’s ability to proceed with this case under Section 63(12) — even after the CFPB dropped its federal case — demonstrates that state enforcement isn’t a fallback for federal inaction. It’s an independent lane with its own procedural advantages and legal theories.

For P2P payment compliance programs that were built around federal regulatory expectations, the practical implication is that the compliance bar isn’t set by what CFPB examiners test for. It’s set by what a state AG can plausibly allege in a complaint that survives a motion to dismiss.

So What?

The Zelle ruling isn’t a problem for Early Warning Services’ lawyers to solve — it’s a problem for every P2P program’s compliance team to learn from.

The specific failure pattern the court found viable: a payment network that tracked its own fraud problem, designed fixes, shelved the fixes, and prioritized adoption over safety. That pattern doesn’t require Zelle’s scale to create liability exposure. It requires a documented design decision to defer controls, combined with fraud losses the company knew about.

The right compliance response isn’t to wait for the case to resolve. It’s to audit your P2P fraud control framework against the five categories above, document what you have and why you made the decisions you made, and close the gaps that exist.

The New York AG’s complaint is available. It’s a detailed blueprint of what “inadequate fraud controls” looks like to a state enforcement office. Read it like a self-assessment.


Related reading: Your Reg E Program Wasn’t Built for FedNow: Error Resolution for Instant Payments | Regulation E P2P Scam Liability and Investigation Standards | Instant Payments Fraud Controls: FedNow and RTP Operational Risk

External sources: Law360 — NY AG Zelle Fraud Suit May Proceed | American Banker — Early Warning Loses Bid to Toss NY Suit | Forbes — New York Is Writing America’s Zelle Fraud Rules | Crowdfund Insider — Judge Rules Zelle Must Confront NY AG Lawsuit | Federal Reserve Kansas City — Combating APP Scams in Fast Payment Systems

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the New York court rule in the Zelle case?
On July 21, 2026, a New York state court denied Early Warning Services' motion to dismiss the New York Attorney General's lawsuit. Justice Phaedra Perry-Bond found that the AG's office sufficiently alleged that Zelle's operator 'prioritized accessibility, convenience, consumer adoption, and market dominance at the expense of consumer safety.' The ruling means the $1B+ lawsuit — filed under New York Executive Law Section 63(12) for repeated fraudulent and deceptive acts — proceeds to discovery and, potentially, trial. Early Warning has indicated it will appeal.
What is authorized push payment (APP) fraud and why doesn't Reg E cover it?
Authorized push payment (APP) fraud occurs when a consumer is deceived into voluntarily initiating a payment to a fraudster — imposter scams posing as government agencies, banks, or utilities; romance scams; business email compromise targeting individuals. The consumer authorized the transfer, which is the key distinction from unauthorized payment fraud covered by Reg E. Under the Electronic Fund Transfer Act, banks must reimburse consumers for unauthorized electronic fund transfers. APP fraud doesn't meet the 'unauthorized' threshold because the consumer consented, even if under false pretenses. Federal law currently has no equivalent requirement for APP reimbursement.
What specific fraud control failures did the court identify in the Zelle case?
The New York AG's complaint (which survived dismissal) alleged that Early Warning: launched Zelle without adequate identity verification at consumer registration; allowed scammers to create lookalike accounts impersonating banks, government agencies, and utilities; had 150,000 fraud reports in 2020 alone ($80M in losses that year); and shelved anti-fraud safeguards its own teams had already designed as early as 2019. The court found these allegations sufficient to support claims that Early Warning knew about the fraud problem and chose not to address it effectively.
What does this ruling mean for banks and credit unions that use Zelle?
The seven banks that own Early Warning Services — JPMorgan Chase, Bank of America, Wells Fargo, Capital One, PNC, US Bank, and Truist — carry direct exposure. But the 2,200+ other banks and credit unions that use Zelle face indirect risk through network liability if the case produces a reimbursement order or settlement that changes how the network handles fraud claims. More broadly, the ruling signals that state attorneys general are prepared to hold payment networks — not just individual member banks — accountable for systematic fraud facilitation under state consumer protection law.
What fraud controls should P2P payment operators have documented before a regulatory inquiry?
The Zelle case's factual record suggests five categories regulators and plaintiffs will examine: (1) identity verification controls at onboarding and registration — specifically whether the system prevented spoofed or lookalike account creation; (2) network-level fraud detection — whether real-time signals (device fingerprint, behavioral analytics, velocity monitoring) were built and deployed before regulatory scrutiny; (3) fraud safeguard decision documentation — whether design decisions about fraud controls were documented and whether shelved controls were preserved with explanation; (4) consumer disclosure controls — whether users received clear warnings about imposter scams at the point of payment; and (5) known-bad actor database hygiene — how quickly confirmed fraudsters were removed from the network.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

KRI Library (132 Key Risk Indicators)

132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.