Skip to content
RiskTemplates · The Daily Brief Sunday, July 26, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Incident Response

Account Takeover Incident Response: The Reg E Liability Playbook Financial Institutions Can't Ignore

ATO fraud hit $262 million in losses in 2025. The NY AG v. Citibank ruling changed the liability calculus. Here's the 72-hour incident response playbook and the Reg E obligations your policy needs to document.

By Rebecca Leung · June 9, 2026 ·
Table of Contents

TL;DR:

  • The FBI’s IC3 received 5,100+ ATO fraud complaints in 2025, with losses exceeding $262 million — and independent estimates put true losses 3–5x higher.
  • The CFPB’s January 2025 EFT FAQ update confirmed: ATO-related losses where a fraudster used stolen credentials are unauthorized EFTs under Reg E, triggering bank liability and error resolution obligations regardless of whether the customer was tricked into sharing credentials.
  • The January 2025 SDNY ruling in NY AG v. Citibank found that the EFTA applies to consumer wire transfers, rejecting the categorical exemption banks had relied on — the case is on appeal but has fundamentally shifted the liability framework.
  • Your incident response policy needs a parallel Reg E error resolution workflow, not just a fraud operations track. The two have different timelines, evidence requirements, and regulatory consequences.

The Fraud Type That’s Breaking Financial Institution Response Programs

Account takeover fraud isn’t new. But the regulatory liability framework around it changed in January 2025, and most financial institution incident response policies haven’t caught up.

Here’s the gap: most ATO response programs are built around the fraud operations workflow — freeze the account, investigate the access event, confirm or deny the loss, close the case. That’s the right fraud response. It’s not the complete legal response.

The complete response requires running a parallel track: a Reg E error resolution workflow that has its own timelines, its own documentation requirements, and its own consumer notification obligations. Conflating the two — treating the fraud investigation as equivalent to the Reg E investigation — is where institutions create independent liability.

The FBI’s Internet Crime Complaint Center (IC3) received more than 5,100 ATO fraud complaints in 2025, with losses exceeding $262 million. Independent estimates put the true figure 3–5 times higher because most consumer victims never file a complaint. The financial sector experiences fewer ATO attempts per institution than e-commerce, but the per-incident dollar loss is dramatically higher — averaging around $6,700 per incident by Forter’s ATO benchmarks, and far more for wire transfer events.

The January 2025 regulatory developments are what make this a compliance priority, not just a fraud operations problem.

What Changed in January 2025

The CFPB EFT FAQ Update

On January 15, 2025, the CFPB released Version 3 of its Electronic Fund Transfer FAQs, providing updated guidance on the scope of the EFTA and Regulation E for financial institutions.

The critical clarification for ATO: transfers initiated by fraudsters using stolen credentials or fraudulently obtained access information are considered unauthorized EFTs — even when the account holder was tricked into providing those credentials. The analysis focuses on whether the consumer gave actual authority to the person who initiated the transfer, not whether the consumer made a mistake that facilitated the fraud.

This matters because institutions had sometimes argued that a consumer who shared their credentials — even under social engineering — had implicitly authorized the resulting transfers. The CFPB’s FAQ update closes that interpretation off.

Just as significant: the FAQ clarified that financial institutions cannot consider consumer negligence when determining Reg E liability for unauthorized EFTs. That’s not a balancing test. If the transfer was unauthorized under Reg E, the error resolution obligations apply.

NY AG v. Citibank: Wire Transfers and EFTA

Separately, on January 21, 2025, the United States District Court for the Southern District of New York declined to dismiss the New York Attorney General’s EFTA lawsuit against Citibank, in a 65-page opinion that found the EFTA applies to consumer wire transfers.

Citibank’s central argument had been that consumer wire transfers are categorically exempt from EFTA — a position many banks had relied on when processing ATO-related wire transfer losses. The SDNY rejected it.

The NYAG’s theory breaks wire transfers into three phases: (1) the customer’s instructions to their bank, (2) the bank-to-bank transfer via Fedwire, (3) the payee bank crediting the recipient’s account. Only phase two — the bank-to-bank wire — is exempt from the EFTA as a wholesale funds transfer. Phases one and three involve the consumer directly, and those phases are covered by the EFTA’s unauthorized transfer provisions when fraud is involved.

Citibank was granted interlocutory appeal to the Second Circuit in September 2025, and the American Bankers Association filed an amicus brief in December 2025 urging reversal. The case isn’t decided. But the practical reality is that institutions can no longer rely on the categorical wire transfer exemption as a shield when an ATO event involves a wire transfer. The risk calculus changed in January 2025 regardless of how the Second Circuit ultimately rules.

The Four-Category ATO Anatomy

Understanding ATO requires distinguishing the attack vector — because the liability analysis and the incident response steps differ.

Attack VectorWhat HappensReg E ApplicabilityKey Evidence
Credential stuffingFraudster uses previously breached username/password combinations to access accountsUnauthorized EFTFailed login attempts, successful login from new IP/device, session logs
Phishing / vishingCustomer is socially engineered into providing credentials or OTP codesUnauthorized EFT (CFPB FAQ Jan. 2025)Customer call logs, referrer URLs, malicious domain registration data
SIM swapFraudster ports customer’s phone number to take over SMS-based MFAUnauthorized EFTMobile carrier records, authentication logs
Malware / RATMalicious software captures credentials or intercepts sessionUnauthorized EFTDevice forensics, malware signatures, network logs

In every category, the fraudster is the actor — the consumer did not initiate the transfer with actual authority. The analysis is the same even where the consumer’s behavior (reusing passwords, clicking phishing links) contributed to the compromise.

The 72-Hour Incident Response Playbook

Most ATO events at financial institutions follow a predictable sequence. The response failure isn’t usually in the first few minutes — it’s in the parallel process management over the following 48–72 hours.

Hours 0–4: Detection and Initial Assessment

ATO events typically surface through one of three triggers: a customer complaint, fraud monitoring alerts (unusual login geography, device mismatch, velocity anomalies), or a transfer that failed post-processing review.

What to do in the first four hours:

  1. Confirm the access event. Pull authentication logs: what device, what IP, what time, what authentication method was used for the session that initiated the questioned transaction. Preserve these logs immediately — many authentication systems have retention windows as short as 30–90 days.

  2. Make the account freeze decision. This is a judgment call with real consumer impact. Freezing early preserves assets but creates a customer service event. Criteria for immediate freeze: new device or IP not previously used by this customer, contact information change in the same session as the transfer, transaction value significantly above the customer’s historical pattern. Document the decision and the basis for it.

  3. Open two parallel tracks simultaneously. Track 1: fraud investigation. Track 2: Reg E error resolution. These have different owners, different timelines, and different documentation outputs. Open both from the moment the event is confirmed as suspicious.

  4. Preserve evidence. Session logs, IP geolocation data, device fingerprints, authentication method records, any call recordings if the customer was contacted during the session, email or SMS records if the fraudster changed contact information. This evidence determines both the fraud outcome and any subsequent litigation.

Hours 4–24: Investigation and Preliminary Reg E Assessment

By hour 24, two things need to be complete or in progress:

Reg E preliminary assessment. Does this transfer qualify as an unauthorized EFT under the EFTA? The test: was the transfer initiated by someone without actual authority to initiate it? If yes, the error resolution clock is running. The error resolution timeline is 10 business days for domestic consumer account EFTs — not 10 calendar days, not 10 “banking days.” Document the time the customer notification was received, because that starts the clock.

Provisional credit decision. If your fraud investigation will take more than 10 business days to complete, Reg E requires a provisional credit to the consumer’s account within 5 business days of receiving the error notice. This is not discretionary. Institutions that investigate first and apply provisional credit only if they confirm fraud are creating exposure. The investigative timeline drives the provisional credit requirement, not the outcome.

SAR assessment. ATO events meeting the $5,000 threshold (or $25,000 for non-bank SARs) require a suspicious activity assessment. The 30-calendar-day SAR filing clock runs from the date the institution detects the suspicious transaction, not from the date the customer reports it.

Hours 24–72: Error Resolution and Regulatory Notification

Complete the investigation. For a straightforward ATO event with clear authentication evidence, 10 business days is achievable. Document the evidence, the investigative steps taken, and the conclusion.

Provide written results to the consumer. Within 3 business days of completing the investigation, you must send written notification of the results. If you found the transfer was unauthorized, include the correction amount and how it will be applied. If you’re finding the transfer authorized, document why — and be specific, because this document becomes exhibit A in any subsequent dispute.

Assess the FFIEC 36-hour notification obligation. If the ATO event involved a cyber intrusion affecting a bank notification incident threshold, the FFIEC computer security incident notification rule requires reporting to your primary federal regulator within 36 hours of determining the incident qualifies. ATO events don’t automatically trigger this — but ATO at scale, or ATO that exploited a systemic authentication vulnerability, may. The analysis should happen during the first 24 hours.

Review for pattern. Isolated ATO events often aren’t isolated. The same attack campaign frequently targets multiple customers at the same institution using the same vector. The post-event review should look for similar authentication anomalies in the same 24–72 hour window.

What FFIEC Guidance Actually Requires

The FFIEC’s guidance on Digital Banking Security establishes a layered control framework for institutions offering internet banking. For ATO specifically, the guidance identifies four failure modes that examiners look for:

  1. Inadequate authentication for high-risk transactions. Changing contact information, adding new external payees, or initiating large transfers above a threshold require out-of-band confirmation. If these controls weren’t in place before the ATO event, expect a documentation request about why not.

  2. No anomaly detection for new device or geography access. Legitimate customers don’t typically log in from a new country and immediately initiate a large transfer. Flagging new device access + high-value transaction combinations is a basic control gap that examiners now identify as a finding.

  3. Single-factor authentication for internet banking. SMS OTP is no longer considered adequate — not because it’s useless, but because SIM swap attacks compromise it and it doesn’t satisfy the FFIEC’s layered security requirement. FIDO2/passkeys, authenticator apps with phishing resistance, or out-of-band verification are the current standard.

  4. Insufficient error resolution documentation. Examiners increasingly review error resolution files — not just fraud files — in consumer compliance exams. The two often look different: fraud files contain authentication evidence; error resolution files contain the consumer notification, the timeline of investigation steps, the provisional credit decision, and the final written outcome.

Common Mistakes That Create Independent Liability

Treating fraud denial as error resolution closure. If your fraud team determines the transfer was authorized, that determination doesn’t end your Reg E obligation. You still need to provide written notification of the results within 3 business days. Institutions that close fraud cases without completing the written notification step are creating technical Reg E violations independent of the underlying fraud outcome.

Starting the provisional credit clock at fraud confirmation instead of error notice. The 5-business-day provisional credit deadline runs from the consumer’s notification, not from when your fraud team confirms the event. If a customer calls on Monday and your fraud team doesn’t flag it as ATO until Thursday, you haven’t gained three days — you’ve lost three days.

Failing to preserve authentication logs promptly. Many session authentication systems purge logs on 30–60 day cycles. An ATO complaint filed six weeks after the event may find the original access logs are gone. Evidence preservation as an immediate action in the first hour is not optional.

Wire transfer categorical exemption reliance. Post the SDNY ruling in January 2025, institutions that reflexively deny ATO-related wire transfer claims as “not covered by Reg E” are taking a position that a federal court rejected. The Second Circuit appeal may restore the categorical exemption — but relying on it today, in the face of an adverse district court ruling, creates a consumer complaint and regulatory examination posture problem regardless of the ultimate outcome.

So What? The Policy Gap Most Institutions Have

The vast majority of financial institution ATO response policies are fraud operations documents. They describe the fraud detection process, the account hold procedures, the investigation workflow, and the outcome categories. They don’t describe a parallel Reg E error resolution workflow.

The gap matters because the CFPB examines error resolution independently of fraud investigation quality. A program that correctly identifies ATO fraud and recovers customer funds, but fails to provide the written error resolution notice within 3 business days, fails the compliance exam.

ATO fraud spiked 250% among financial institutions per American Banker. The January 2025 regulatory developments added liability where institutions thought they had protection. The documentation and process gap is now a compliance examination issue, not just a customer service concern.

For a complete incident response framework — including Reg E error resolution templates, regulatory notification checklists, and playbooks for ATO, BEC, ransomware, and insider threat — the Incident Response & Breach Notification Kit includes all four playbooks with documentation artifacts built for examination review.

For the severity classification and materiality assessment framework that determines whether your ATO event triggers the SEC 4-business-day disclosure clock or FFIEC 36-hour bank notification obligation, see Incident Triage Techniques: Severity Classification, Materiality, and the SEC 4-Day Clock. For the full cyber incident response lifecycle, see Cyber Incident Response Playbook: From Detection to Lessons Learned. For the FFIEC’s 36-hour bank notification rule that applies to qualifying ATO events, see FFIEC 36-Hour Incident Notification Rule: What Banking Organizations Must Report, When, and to Whom.


Sources: FBI IC3 PSA — Account Takeover Fraud via Impersonation of Financial Institution Support (November 2025); CFPB Electronic Fund Transfer FAQs Version 3, January 15, 2025; ABA Banking Journal — SDNY declines to dismiss NYAG EFTA lawsuit against Citibank, February 2025; American Banker — Banks face new risks as account takeover fraud spikes 250%; ABA Banking Journal — ABA amicus brief, Second Circuit NYAG v. Citibank, December 2025

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Does Regulation E cover account takeover fraud where the customer was tricked into sharing credentials?
Yes. The CFPB's Electronic Fund Transfer FAQs (updated January 15, 2025) clarify that transfers initiated by fraudsters using stolen or fraudulently obtained credentials are considered unauthorized EFTs under Reg E — even if the customer inadvertently disclosed their login information. The critical distinction is whether the customer initiated the transfer themselves with actual authority, not whether they were deceived into providing access.
What did the NY AG v. Citibank ruling mean for wire transfer ATO liability?
On January 21, 2025, the Southern District of New York ruled that the EFTA applies to consumer wire transfers — rejecting Citibank's argument that wire transfers are categorically exempt. The NYAG's theory breaks the transaction into three phases: (1) customer sends instructions to their bank, (2) bank-to-bank wire transfer, (3) payee bank credits the account. Only the bank-to-bank phase is exempt. The ruling is on interlocutory appeal to the Second Circuit, but it has fundamentally changed how institutions need to think about wire transfer ATO liability.
What are the Reg E error resolution timelines a bank must follow after an ATO event?
Upon receiving notice of an error, a financial institution must: investigate and determine whether an error occurred within 10 business days (or 45 calendar days for point-of-sale transactions and international transfers); provisionally credit the consumer's account within 5 business days if it cannot complete the investigation within 10 days; and provide written notification of the results within 3 business days of completing the investigation. Failure to follow these timelines independently creates liability.
What should be in a financial institution's ATO incident response policy?
At minimum: detection triggers and escalation criteria, immediate containment steps (account freeze decision criteria and who authorizes them), a parallel Reg E error resolution workflow with documented timelines, evidence preservation protocol (session logs, IP data, device fingerprints, authentication logs), a consumer notification template, SAR filing assessment, regulatory notification checklist (FFIEC 36-hour rule for bank notification incidents), and a post-incident review process for pattern identification.
How does ATO fraud differ from business email compromise from an incident response perspective?
ATO involves unauthorized access to the victim's own account — so the Reg E unauthorized EFT framework applies directly to the recovery and reimbursement analysis. BEC typically involves the victim authorizing a transfer themselves based on fraudulent instructions, which triggers a different analysis (not unauthorized, potential UDAAP or negligence claims instead). ATO also typically involves evidence of unauthorized account access that needs to be preserved and analyzed, while BEC is primarily a social engineering event with different forensic requirements.
What authentication controls does FFIEC guidance recommend to prevent ATO?
The FFIEC's Digital Banking Security guidance recommends layered controls: phishing-resistant MFA (FIDO2/passkeys, not SMS OTP), device fingerprinting and behavioral analytics for detecting unusual access patterns, out-of-band verification for high-risk transactions (large transfers, new payee additions, contact information changes), transaction velocity limits, and anomaly detection that flags login from new devices or unusual geographies immediately. Single-factor authentication for consumer accounts is no longer considered adequate under FFIEC standards for any institution deploying internet banking.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Incident Response & Breach Notification Kit

Step-by-step incident response playbooks and breach notification templates for all 50 states.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.