Feature Incident Response
Account Takeover Incident Response: The Reg E Liability Playbook Financial Institutions Can't Ignore
ATO fraud hit $262 million in losses in 2025. The NY AG v. Citibank ruling changed the liability calculus. Here's the 72-hour incident response playbook and the Reg E obligations your policy needs to document.
Table of Contents
TL;DR:
- The FBI’s IC3 received 5,100+ ATO fraud complaints in 2025, with losses exceeding $262 million — and independent estimates put true losses 3–5x higher.
- The CFPB’s January 2025 EFT FAQ update confirmed: ATO-related losses where a fraudster used stolen credentials are unauthorized EFTs under Reg E, triggering bank liability and error resolution obligations regardless of whether the customer was tricked into sharing credentials.
- The January 2025 SDNY ruling in NY AG v. Citibank found that the EFTA applies to consumer wire transfers, rejecting the categorical exemption banks had relied on — the case is on appeal but has fundamentally shifted the liability framework.
- Your incident response policy needs a parallel Reg E error resolution workflow, not just a fraud operations track. The two have different timelines, evidence requirements, and regulatory consequences.
The Fraud Type That’s Breaking Financial Institution Response Programs
Account takeover fraud isn’t new. But the regulatory liability framework around it changed in January 2025, and most financial institution incident response policies haven’t caught up.
Here’s the gap: most ATO response programs are built around the fraud operations workflow — freeze the account, investigate the access event, confirm or deny the loss, close the case. That’s the right fraud response. It’s not the complete legal response.
The complete response requires running a parallel track: a Reg E error resolution workflow that has its own timelines, its own documentation requirements, and its own consumer notification obligations. Conflating the two — treating the fraud investigation as equivalent to the Reg E investigation — is where institutions create independent liability.
The FBI’s Internet Crime Complaint Center (IC3) received more than 5,100 ATO fraud complaints in 2025, with losses exceeding $262 million. Independent estimates put the true figure 3–5 times higher because most consumer victims never file a complaint. The financial sector experiences fewer ATO attempts per institution than e-commerce, but the per-incident dollar loss is dramatically higher — averaging around $6,700 per incident by Forter’s ATO benchmarks, and far more for wire transfer events.
The January 2025 regulatory developments are what make this a compliance priority, not just a fraud operations problem.
What Changed in January 2025
The CFPB EFT FAQ Update
On January 15, 2025, the CFPB released Version 3 of its Electronic Fund Transfer FAQs, providing updated guidance on the scope of the EFTA and Regulation E for financial institutions.
The critical clarification for ATO: transfers initiated by fraudsters using stolen credentials or fraudulently obtained access information are considered unauthorized EFTs — even when the account holder was tricked into providing those credentials. The analysis focuses on whether the consumer gave actual authority to the person who initiated the transfer, not whether the consumer made a mistake that facilitated the fraud.
This matters because institutions had sometimes argued that a consumer who shared their credentials — even under social engineering — had implicitly authorized the resulting transfers. The CFPB’s FAQ update closes that interpretation off.
Just as significant: the FAQ clarified that financial institutions cannot consider consumer negligence when determining Reg E liability for unauthorized EFTs. That’s not a balancing test. If the transfer was unauthorized under Reg E, the error resolution obligations apply.
NY AG v. Citibank: Wire Transfers and EFTA
Separately, on January 21, 2025, the United States District Court for the Southern District of New York declined to dismiss the New York Attorney General’s EFTA lawsuit against Citibank, in a 65-page opinion that found the EFTA applies to consumer wire transfers.
Citibank’s central argument had been that consumer wire transfers are categorically exempt from EFTA — a position many banks had relied on when processing ATO-related wire transfer losses. The SDNY rejected it.
The NYAG’s theory breaks wire transfers into three phases: (1) the customer’s instructions to their bank, (2) the bank-to-bank transfer via Fedwire, (3) the payee bank crediting the recipient’s account. Only phase two — the bank-to-bank wire — is exempt from the EFTA as a wholesale funds transfer. Phases one and three involve the consumer directly, and those phases are covered by the EFTA’s unauthorized transfer provisions when fraud is involved.
Citibank was granted interlocutory appeal to the Second Circuit in September 2025, and the American Bankers Association filed an amicus brief in December 2025 urging reversal. The case isn’t decided. But the practical reality is that institutions can no longer rely on the categorical wire transfer exemption as a shield when an ATO event involves a wire transfer. The risk calculus changed in January 2025 regardless of how the Second Circuit ultimately rules.
The Four-Category ATO Anatomy
Understanding ATO requires distinguishing the attack vector — because the liability analysis and the incident response steps differ.
| Attack Vector | What Happens | Reg E Applicability | Key Evidence |
|---|---|---|---|
| Credential stuffing | Fraudster uses previously breached username/password combinations to access accounts | Unauthorized EFT | Failed login attempts, successful login from new IP/device, session logs |
| Phishing / vishing | Customer is socially engineered into providing credentials or OTP codes | Unauthorized EFT (CFPB FAQ Jan. 2025) | Customer call logs, referrer URLs, malicious domain registration data |
| SIM swap | Fraudster ports customer’s phone number to take over SMS-based MFA | Unauthorized EFT | Mobile carrier records, authentication logs |
| Malware / RAT | Malicious software captures credentials or intercepts session | Unauthorized EFT | Device forensics, malware signatures, network logs |
In every category, the fraudster is the actor — the consumer did not initiate the transfer with actual authority. The analysis is the same even where the consumer’s behavior (reusing passwords, clicking phishing links) contributed to the compromise.
The 72-Hour Incident Response Playbook
Most ATO events at financial institutions follow a predictable sequence. The response failure isn’t usually in the first few minutes — it’s in the parallel process management over the following 48–72 hours.
Hours 0–4: Detection and Initial Assessment
ATO events typically surface through one of three triggers: a customer complaint, fraud monitoring alerts (unusual login geography, device mismatch, velocity anomalies), or a transfer that failed post-processing review.
What to do in the first four hours:
-
Confirm the access event. Pull authentication logs: what device, what IP, what time, what authentication method was used for the session that initiated the questioned transaction. Preserve these logs immediately — many authentication systems have retention windows as short as 30–90 days.
-
Make the account freeze decision. This is a judgment call with real consumer impact. Freezing early preserves assets but creates a customer service event. Criteria for immediate freeze: new device or IP not previously used by this customer, contact information change in the same session as the transfer, transaction value significantly above the customer’s historical pattern. Document the decision and the basis for it.
-
Open two parallel tracks simultaneously. Track 1: fraud investigation. Track 2: Reg E error resolution. These have different owners, different timelines, and different documentation outputs. Open both from the moment the event is confirmed as suspicious.
-
Preserve evidence. Session logs, IP geolocation data, device fingerprints, authentication method records, any call recordings if the customer was contacted during the session, email or SMS records if the fraudster changed contact information. This evidence determines both the fraud outcome and any subsequent litigation.
Hours 4–24: Investigation and Preliminary Reg E Assessment
By hour 24, two things need to be complete or in progress:
Reg E preliminary assessment. Does this transfer qualify as an unauthorized EFT under the EFTA? The test: was the transfer initiated by someone without actual authority to initiate it? If yes, the error resolution clock is running. The error resolution timeline is 10 business days for domestic consumer account EFTs — not 10 calendar days, not 10 “banking days.” Document the time the customer notification was received, because that starts the clock.
Provisional credit decision. If your fraud investigation will take more than 10 business days to complete, Reg E requires a provisional credit to the consumer’s account within 5 business days of receiving the error notice. This is not discretionary. Institutions that investigate first and apply provisional credit only if they confirm fraud are creating exposure. The investigative timeline drives the provisional credit requirement, not the outcome.
SAR assessment. ATO events meeting the $5,000 threshold (or $25,000 for non-bank SARs) require a suspicious activity assessment. The 30-calendar-day SAR filing clock runs from the date the institution detects the suspicious transaction, not from the date the customer reports it.
Hours 24–72: Error Resolution and Regulatory Notification
Complete the investigation. For a straightforward ATO event with clear authentication evidence, 10 business days is achievable. Document the evidence, the investigative steps taken, and the conclusion.
Provide written results to the consumer. Within 3 business days of completing the investigation, you must send written notification of the results. If you found the transfer was unauthorized, include the correction amount and how it will be applied. If you’re finding the transfer authorized, document why — and be specific, because this document becomes exhibit A in any subsequent dispute.
Assess the FFIEC 36-hour notification obligation. If the ATO event involved a cyber intrusion affecting a bank notification incident threshold, the FFIEC computer security incident notification rule requires reporting to your primary federal regulator within 36 hours of determining the incident qualifies. ATO events don’t automatically trigger this — but ATO at scale, or ATO that exploited a systemic authentication vulnerability, may. The analysis should happen during the first 24 hours.
Review for pattern. Isolated ATO events often aren’t isolated. The same attack campaign frequently targets multiple customers at the same institution using the same vector. The post-event review should look for similar authentication anomalies in the same 24–72 hour window.
What FFIEC Guidance Actually Requires
The FFIEC’s guidance on Digital Banking Security establishes a layered control framework for institutions offering internet banking. For ATO specifically, the guidance identifies four failure modes that examiners look for:
-
Inadequate authentication for high-risk transactions. Changing contact information, adding new external payees, or initiating large transfers above a threshold require out-of-band confirmation. If these controls weren’t in place before the ATO event, expect a documentation request about why not.
-
No anomaly detection for new device or geography access. Legitimate customers don’t typically log in from a new country and immediately initiate a large transfer. Flagging new device access + high-value transaction combinations is a basic control gap that examiners now identify as a finding.
-
Single-factor authentication for internet banking. SMS OTP is no longer considered adequate — not because it’s useless, but because SIM swap attacks compromise it and it doesn’t satisfy the FFIEC’s layered security requirement. FIDO2/passkeys, authenticator apps with phishing resistance, or out-of-band verification are the current standard.
-
Insufficient error resolution documentation. Examiners increasingly review error resolution files — not just fraud files — in consumer compliance exams. The two often look different: fraud files contain authentication evidence; error resolution files contain the consumer notification, the timeline of investigation steps, the provisional credit decision, and the final written outcome.
Common Mistakes That Create Independent Liability
Treating fraud denial as error resolution closure. If your fraud team determines the transfer was authorized, that determination doesn’t end your Reg E obligation. You still need to provide written notification of the results within 3 business days. Institutions that close fraud cases without completing the written notification step are creating technical Reg E violations independent of the underlying fraud outcome.
Starting the provisional credit clock at fraud confirmation instead of error notice. The 5-business-day provisional credit deadline runs from the consumer’s notification, not from when your fraud team confirms the event. If a customer calls on Monday and your fraud team doesn’t flag it as ATO until Thursday, you haven’t gained three days — you’ve lost three days.
Failing to preserve authentication logs promptly. Many session authentication systems purge logs on 30–60 day cycles. An ATO complaint filed six weeks after the event may find the original access logs are gone. Evidence preservation as an immediate action in the first hour is not optional.
Wire transfer categorical exemption reliance. Post the SDNY ruling in January 2025, institutions that reflexively deny ATO-related wire transfer claims as “not covered by Reg E” are taking a position that a federal court rejected. The Second Circuit appeal may restore the categorical exemption — but relying on it today, in the face of an adverse district court ruling, creates a consumer complaint and regulatory examination posture problem regardless of the ultimate outcome.
So What? The Policy Gap Most Institutions Have
The vast majority of financial institution ATO response policies are fraud operations documents. They describe the fraud detection process, the account hold procedures, the investigation workflow, and the outcome categories. They don’t describe a parallel Reg E error resolution workflow.
The gap matters because the CFPB examines error resolution independently of fraud investigation quality. A program that correctly identifies ATO fraud and recovers customer funds, but fails to provide the written error resolution notice within 3 business days, fails the compliance exam.
ATO fraud spiked 250% among financial institutions per American Banker. The January 2025 regulatory developments added liability where institutions thought they had protection. The documentation and process gap is now a compliance examination issue, not just a customer service concern.
For a complete incident response framework — including Reg E error resolution templates, regulatory notification checklists, and playbooks for ATO, BEC, ransomware, and insider threat — the Incident Response & Breach Notification Kit includes all four playbooks with documentation artifacts built for examination review.
For the severity classification and materiality assessment framework that determines whether your ATO event triggers the SEC 4-business-day disclosure clock or FFIEC 36-hour bank notification obligation, see Incident Triage Techniques: Severity Classification, Materiality, and the SEC 4-Day Clock. For the full cyber incident response lifecycle, see Cyber Incident Response Playbook: From Detection to Lessons Learned. For the FFIEC’s 36-hour bank notification rule that applies to qualifying ATO events, see FFIEC 36-Hour Incident Notification Rule: What Banking Organizations Must Report, When, and to Whom.
Sources: FBI IC3 PSA — Account Takeover Fraud via Impersonation of Financial Institution Support (November 2025); CFPB Electronic Fund Transfer FAQs Version 3, January 15, 2025; ABA Banking Journal — SDNY declines to dismiss NYAG EFTA lawsuit against Citibank, February 2025; American Banker — Banks face new risks as account takeover fraud spikes 250%; ABA Banking Journal — ABA amicus brief, Second Circuit NYAG v. Citibank, December 2025
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does Regulation E cover account takeover fraud where the customer was tricked into sharing credentials?
What did the NY AG v. Citibank ruling mean for wire transfer ATO liability?
What are the Reg E error resolution timelines a bank must follow after an ATO event?
What should be in a financial institution's ATO incident response policy?
How does ATO fraud differ from business email compromise from an incident response perspective?
What authentication controls does FFIEC guidance recommend to prevent ATO?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Keep reading
Related posts.
Incident Response
Incident Response Decision Log: Document Why a Notification Clock Did—or Did Not—Start
When a cyber event hits, every regulator wants the same thing: proof you made a good-faith materiality determination without unreasonable delay. Here's the decision log structure that creates that proof—whether the clock started or not.
Jul 24, 2026
Incident Response
Four Months Late: What the NYDFS Healthplex $2M Penalty Says About When the Notification Clock Actually Starts
NYDFS fined Healthplex $2 million in August 2025 for notifying 4+ months after a breach. The failure wasn't forensics — it was a misunderstanding of when the 72-hour clock starts. The same mistake trips up banks under the FDIC's 36-hour rule.
Jul 23, 2026
Incident Response
Three Clocks, One Incident: How to Manage the Overlapping Cyber Notification Timelines Under OCC, NYDFS, and SEC Rules
When a cyber incident hits, you're not managing one notification obligation — you're managing six, with different triggers, different recipients, and different clocks. The OCC's 36-hour rule, NYDFS's 72-hour requirement, the SEC's 4-business-day materiality window, GLBA customer notices, FinCEN SAR filing, and bank partner contractual obligations all run simultaneously. Here's how to track them without missing one.
Jul 18, 2026