The Prince and the Principle

by Barry Goldman

Suppose Jones receives a communication from a Nigerian prince. The prince convinces Jones that if he provides access to his checking account, the prince will deposit $5 million ($5,000,000.00 USD) in it. Jones finds this proposition attractive and provides his account number, login credentials and password. Much to Jones’s surprise, however, instead of depositing $5 million ($5,000,000.00 USD) as he promised, the prince uses Jones’s credentials to empty Jones’s account. Now suppose Jones files a complaint against his bank alleging that the bank improperly allowed an unauthorized withdrawal from his account. What should be the result?

I think we can agree that Jones is, to use the technical term, SOL.

Next case. Suppose instead of contacting Jones, the scammer contacts Jones’s bank directly. Jones is not involved at all. The scammer somehow manages to obtain Jones’s credentials and uses them to empty Jones’s account. Jones files a complaint making the same allegation he did in the first case – that the bank improperly allowed an unauthorized withdrawal from his account. Now what result?

Again, I think we can agree. Whatever the particular details may be, the facts speak for themselves. The bank failed to protect its customer and improperly allowed an unauthorized withdrawal. The bank is on the hook.

Now let’s talk about a more difficult case. This time the scammer, instead of pretending to be a Nigerian prince, pretends to be Jones’s bank. Jones receives what he has every reason to believe is a legitimate communication from his bank. Let’s say it’s an email. The email looks just like previous emails from his bank. The logo and the colors match. The sender is a name he recognizes. Jones hovers his mouse over the sender’s email address, and it matches. The email doesn’t ask for his login name or credentials. The sender appears to have all that information. Everything is polite, professional and businesslike. There are no spelling or grammatical mistakes. Everything looks perfectly kosher and strictly routine. The email says all Jones needs to do is click the box marked VERIFY and his account will be updated with the latest security protection and fraud prevention software. Sounds like a good idea. Jones clicks the box, and his account balance immediately goes to zero.

When he finds out what happened, Jones files the same complaint we saw in the first two cases. He says the bank improperly allowed an unauthorized withdrawal from his account.

The bank says Jones did authorize the withdrawal. He clicked VERIFY. It’s all very unfortunate, the bank says, but it has nothing to do with them. They didn’t verify the transaction, he did. There is no reason for the bank to have to reimburse him for his loss. They had no role in it whatsoever.

Jones says he did not authorize any such a damn thing. As far as he was concerned, he verified to his bank that he was who he said he was and his account was his account. He didn’t authorize any transaction at all.

Now what?

As usual, the law is not much help. Code of Federal Regulations Title 12, Chapter X, Part 1005, Subpart A, §1005.2 (m) says:

“Unauthorized electronic fund transfer” means an electronic fund transfer from a consumer’s account initiated by a person other than the consumer without actual authority to initiate the transfer and from which the consumer receives no benefit.

As usual, there is wiggle room here. The bank’s argument is that the transfer in an imposter case like this was not “initiated by a person other than the consumer.” It was initiated by the consumer himself. Or, the bank argues, the scammer did have actual authority to initiate the transfer. The consumer gave it to him. Either way, the transfer does not meet the definition of “Unauthorized electronic fund transfer” and the bank is off the hook.

This issue reached the news recently when JPMorgan’s former head of scam prevention filed a whistleblower complaint. The complaint alleged that JPMorgan systematically misclassified unauthorized EFTs as authorized in order to avoid its reimbursement obligations. And it says Morgan’s own analysis showed it would cost at least $100 million to correct the situation. According to reporting in Tech Times:

A bank that has no compliance problem typically does not estimate the cost of fixing one.

Let’s try to think this through carefully. There are three parties involved in one of these transactions: the customer, the scammer, and the bank. The scammer (and the money) are gone. That leaves only the customer or the bank to bear the loss. We agreed at the start of this piece that if the scammer steals money from the customer’s account without the customer having any involvement, that’s the bank’s fault and the bank should have to reimburse the account. That seems clear, and the principle seems sound.

If the scammer tricks the customer into revealing his credentials and that allows the scammer to steal his money, is that the bank’s fault?

If we agree it is the bank’s fault and that it triggers an obligation to reimburse, what is the principle? If the principle is that the bank should have made that theft impossible, do we have an obligation to suggest how they might do that? Even if we don’t have any such obligation – we are not bankers or experts in electronic fraud after all – what is the principle that distinguishes the bank imposter case from the case of the Nigerian prince? Or romance fraud.

Suppose I get an email with a picture of an adorable, young cutie in a bikini. She says she read some of my 3QD columns and she’s dying to meet me. She just needs enough money for airfare. If I send her an EFT, is it my bank’s fault? But if the same scammer pretends to be my bank, then it’s my bank’s fault? I’m not grasping the principle.

I suppose there is an argument that in the case where the customer clicked on the word VERIFY, he didn’t intend to authorize a transfer. He believed he was updating his contact information or some such thing. But that doesn’t help with the cases where the scammer convinces the customer his account has been targeted by scammers and he needs to move his money to a safe account to protect it. There, he does intend to authorize a transfer. It just doesn’t seem to be a distinction that can bear much weight.

I certainly have no great love for JPMorgan or Wells Fargo or any of the rest of those thieves. As a general matter, I think Jamie Dimon and his friends are dangerous criminals. I agree with Robert Reich on the subject. But I’m not asking about a general matter or a question of politics. I’m asking about real, individual cases. And I’m asking because I think it’s important to decide real cases based on articulable, defensible principles.

The reporting about the whistleblower complaint made the point that the $100 million it would cost JPMorgan to correct the alleged misclassification represents 0.5% of its $21.2 billion second quarter net income in 2026. Perhaps that is the principle. Soak the rich. Make the bosses take the losses. This is the Deep Pocket Theory of Liability. As Willie Sutton said, “That’s where the money is.”

Making the customer bear the loss when he did nothing to encourage the fraud and received no benefit from it is unjust. But making the bank bear the loss when it did nothing to encourage the fraud and received no benefit from it is equally unjust. Isn’t it?

Enjoying the content on 3QD? Help keep us going by donating now.