Feature Operational Risk
The Zelle Ruling and What Every P2P Payment Operator Has to Fix in Its Fraud Control Framework
A New York judge let the $1B+ Zelle fraud lawsuit proceed on July 21, 2026. The court found Early Warning Services prioritized speed-to-market over fraud controls it had already designed. If you operate a P2P payment product, this ruling is a blueprint of what state prosecutors will look for in your control gap.
Table of Contents
TL;DR
- On July 21, 2026, a New York state judge let the $1B+ Zelle fraud lawsuit proceed — finding sufficient evidence that Early Warning Services prioritized growth over fraud controls it had already designed
- This isn’t a Reg E case: APP fraud (where the consumer authorized the transfer under false pretenses) isn’t covered by EFTA’s unauthorized-transaction reimbursement requirements
- The seven banks owning Early Warning, plus 2,200+ banks and credit unions on the Zelle network, face cascading exposure if the case produces reimbursement obligations
- State enforcement is filling the void left by the CFPB’s March 2025 dismissal of its federal Zelle lawsuit — and this ruling is the playbook for what comes next
The Federal Path Closed. A State Court Just Opened a Different One.
The CFPB’s Zelle lawsuit ended in March 2025. The Bureau voluntarily dismissed its case with prejudice — the case filed under Director Rohit Chopra accusing JPMorgan Chase, Bank of America, and Wells Fargo of enabling over $870 million in consumer fraud on the Zelle network. Case closed, no reimbursement, no consent order.
New York’s Attorney General had been watching. Letitia James filed her own suit against Early Warning Services LLC — Zelle’s operator — in August 2025, this time using New York Executive Law Section 63(12), which prohibits repeated fraudulent or deceptive acts. On July 21, 2026, a New York state court denied Early Warning’s motion to dismiss, and the case proceeds to trial.
For every compliance officer at a bank, credit union, or fintech operating a P2P payment product: this ruling is worth studying carefully. Not because of Zelle specifically, but because the court’s reasoning maps directly to the gap most P2P programs haven’t closed.
Why This Isn’t a Regulation E Problem
Regulation E is where most compliance teams start when they think about payment fraud liability. That’s partly correct and mostly insufficient.
Reg E — implementing the Electronic Fund Transfer Act — requires financial institutions to reimburse consumers for unauthorized electronic fund transfers. An unauthorized EFT is one that the account holder didn’t authorize, didn’t benefit from, and wouldn’t have authorized if they’d known the full facts. Classic unauthorized transfers: account takeovers, stolen credentials, fraudulent ACH debits.
Authorized push payment (APP) fraud doesn’t meet that test. In an imposter scam, the consumer did authorize the transfer. They were deceived about who was receiving it — a fake government official demanding a tax payment, a fake bank representative “protecting” the account, a fake utility company threatening disconnection — but they voluntarily initiated the payment. The legal authorization exists. Reg E protections, as currently written, largely don’t apply.
The July 23 post on Reg E and FedNow error resolution covers the authorized vs. unauthorized distinction in detail for instant payment programs. The Zelle case operates in a completely different legal lane.
What the New York AG is arguing — and what the court found viable — is that the network operator created conditions that made APP fraud predictably likely and profitable, knew about it, and failed to implement controls it had already designed. That’s a deceptive acts claim under state consumer protection law, not a regulatory compliance claim under EFTA.
What the Court Said Early Warning Did Wrong
The facts alleged in the complaint — which the court found sufficient to proceed — paint a specific picture of control failure:
Pre-launch identity verification was inadequate. Zelle launched in 2017 without identity verification controls that could prevent scammers from creating accounts impersonating banks, government agencies, and utility companies. The complaint alleges that lookalike accounts — using names like “Wells Fargo Fraud Prevention” — were straightforward to create and used systematically to deceive consumers into sending funds.
Fraud reports were logged, not fixed. Zelle had approximately 150,000 induced fraud reports in 2020, representing $80 million in consumer losses — in a single year. The complaint alleges these reports were tracked and dismissed rather than used to redesign the consumer experience or tighten the network’s anti-fraud architecture.
Controls were designed and shelved. The court found the AG had sufficiently alleged that Early Warning’s own teams had designed anti-fraud safeguards as early as 2019 — and that those safeguards were not deployed, at least initially. A design-but-don’t-implement decision is far more damaging in litigation than a failure to identify the problem at all.
Speed-to-market was explicitly prioritized. The court’s ruling specifically notes the AG’s allegation that Early Warning “prioritized accessibility, convenience, consumer adoption, and market dominance at the expense of consumer safety.” This is the finding that will follow the company through discovery and trial.
For P2P program compliance teams, that last point is the one to internalize. A documented business decision to delay or defer fraud controls in favor of adoption metrics creates discovery exposure in any subsequent enforcement action.
The APP Fraud Gap in U.S. Law — and Where It’s Going
The United Kingdom addressed this problem directly. The Payment Systems Regulator’s mandatory reimbursement regime — effective October 2024 — requires sending and receiving banks to split the cost of APP scam reimbursement, capped at £85,000 per claim. Reimbursement is due within five business days unless gross negligence is proven.
Australia passed its Scams Prevention Framework in November 2024, creating mandatory codes with potential fines of up to $50 million AUD for non-compliant firms.
The European Union’s PSD3 framework is expected to address APP fraud liability through mandatory reimbursement provisions.
The United States has no federal equivalent. What it has instead is the situation the Zelle case describes: state attorneys general using consumer protection statutes to hold network operators accountable when federal regulators step back. As Forbes’ coverage of the ruling noted, “New York is writing America’s Zelle fraud rules one lawsuit at a time.”
States with active consumer protection enforcement — California, New York, Texas, Illinois, Massachusetts — are watching this case. A successful outcome for the NY AG would create a template for analogous actions against other P2P payment operators.
What Your P2P Fraud Control Framework Needs Now
The Zelle ruling gives compliance teams a clear roadmap of what prosecutors will look for in a P2P fraud inquiry. Five areas, specifically:
1. Identity Verification at Registration and Onboarding
The complaint’s first allegation is that Zelle failed to verify identities adequately at onboarding, enabling lookalike accounts. For any P2P platform, the question is whether your registration flow can detect:
- Account names designed to impersonate regulated entities (banks, government agencies, utilities)
- Device fingerprints or email addresses associated with known fraud networks
- Velocity patterns suggesting synthetic identity or mule account creation
Documentation should include: what verification is required at registration, what the rejection criteria are, what happens to flagged accounts, and how the thresholds are updated in response to emerging fraud patterns.
2. Real-Time Transaction-Level Fraud Signals
The complaint alleges Zelle lacked adequate real-time controls to identify suspicious transactions before they completed. For instant payment products, where transactions are irrevocable at settlement, this is the last line of detection.
Pre-transaction signals to evaluate and document: unusual first-payment velocity, recipients with no prior transaction history, payment amounts inconsistent with the sender’s historical behavior, text patterns in memo fields matching known scam scripts, device/location anomalies.
For context on the fraud KRIs that matter most for payment programs, the KRI Library includes pre-built fraud metrics across operational risk domains, including transaction monitoring and payment fraud rate tracking.
3. Fraud Safeguard Decision Documentation
This is the element that distinguishes negligence from recklessness in litigation. If your team has evaluated a fraud control — even if you decided not to implement it, or to defer it — that decision should be documented with:
- The control evaluated
- The risk it was designed to address
- Why it wasn’t implemented or was deferred
- What compensating controls exist
- Who made the decision and when
A “we thought about it but decided to wait” decision, documented contemporaneously with business rationale, is a defensible record. An undocumented decision that surfaces in discovery as a design-then-shelve pattern is not.
4. Consumer Warnings at the Point of Payment
P2P platforms that include clear consumer warnings before payment completion — “Once sent, this payment cannot be recalled. Never send money to someone you don’t know.” — create a partial defense. Platforms that don’t have the opposite problem: that a consumer had no friction or warning before being defrauded.
The June 2026 post on Reg E P2P payment scam liability standards covers the investigation standards that apply to authorized payment disputes. The pre-transfer warning piece connects to both Reg E dispute outcomes and state law consumer protection analysis.
5. Known-Bad Actor Network Hygiene
If your platform learns that a recipient account has been used to receive fraud proceeds — through a consumer dispute, a law enforcement referral, or a network intelligence share — how quickly is that account suspended or terminated? The Zelle complaint alleges that known fraudsters remained active on the network after being identified.
The FedNow Network Intelligence API, discussed in the July 22 post on FedNow fraud controls, is specifically designed to address this gap for instant payments. For P2P platforms not on FedNow, the equivalent questions are whether bad actor data from external sources (NACHA return codes, law enforcement referrals, network-shared intelligence) is actually being used to take action, and how quickly.
State Enforcement Is the New Federal Enforcement
The trajectory is clear. The CFPB’s federal enforcement capacity has been significantly reduced — 64% fewer nonbank examinations in 2026 than in 2024, and an active retreat from consumer protection cases that were filed under prior leadership. The vacuum is being filled by state attorneys general with broad consumer protection statutes and the political incentive to pursue cases involving visible consumer harm.
Zelle is the highest-profile example, but it’s not alone. The New York AG’s ability to proceed with this case under Section 63(12) — even after the CFPB dropped its federal case — demonstrates that state enforcement isn’t a fallback for federal inaction. It’s an independent lane with its own procedural advantages and legal theories.
For P2P payment compliance programs that were built around federal regulatory expectations, the practical implication is that the compliance bar isn’t set by what CFPB examiners test for. It’s set by what a state AG can plausibly allege in a complaint that survives a motion to dismiss.
So What?
The Zelle ruling isn’t a problem for Early Warning Services’ lawyers to solve — it’s a problem for every P2P program’s compliance team to learn from.
The specific failure pattern the court found viable: a payment network that tracked its own fraud problem, designed fixes, shelved the fixes, and prioritized adoption over safety. That pattern doesn’t require Zelle’s scale to create liability exposure. It requires a documented design decision to defer controls, combined with fraud losses the company knew about.
The right compliance response isn’t to wait for the case to resolve. It’s to audit your P2P fraud control framework against the five categories above, document what you have and why you made the decisions you made, and close the gaps that exist.
The New York AG’s complaint is available. It’s a detailed blueprint of what “inadequate fraud controls” looks like to a state enforcement office. Read it like a self-assessment.
Related reading: Your Reg E Program Wasn’t Built for FedNow: Error Resolution for Instant Payments | Regulation E P2P Scam Liability and Investigation Standards | Instant Payments Fraud Controls: FedNow and RTP Operational Risk
External sources: Law360 — NY AG Zelle Fraud Suit May Proceed | American Banker — Early Warning Loses Bid to Toss NY Suit | Forbes — New York Is Writing America’s Zelle Fraud Rules | Crowdfund Insider — Judge Rules Zelle Must Confront NY AG Lawsuit | Federal Reserve Kansas City — Combating APP Scams in Fast Payment Systems
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the New York court rule in the Zelle case?
What is authorized push payment (APP) fraud and why doesn't Reg E cover it?
What specific fraud control failures did the court identify in the Zelle case?
What does this ruling mean for banks and credit unions that use Zelle?
What fraud controls should P2P payment operators have documented before a regulatory inquiry?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Keep reading
Related posts.
Operational Risk
Risk Appetite Breach Playbook: What Happens After a Limit Turns Red
A KRI turning red isn't the problem — not knowing what to do next is. Here's the documented breach response playbook: validation, escalation, remediation, and what the board needs to see.
Jul 27, 2026
Operational Risk
Operational Risk Framework Architecture: How RCSAs, KRIs, Loss Events, Issues, and Scenarios Fit Together
Five operational risk components — RCSA, KRIs, loss events, issues, and scenario analysis — only work when they feed each other. Here's the architecture and the artifact handoffs.
Jul 26, 2026
Operational Risk
RCSA Template in Excel: From Workshop Notes to Owner Sign-Off Without Losing the Challenge Record
The challenge record is what separates a defensible RCSA from a copy-paste exercise. Here's the Excel structure that carries workshop observations through second-line challenge to documented owner sign-off.
Jul 26, 2026