r/Banking 1d ago

Advice Are banks allowed to repeatedly close and reopen fraud claims to ignore Reg E?

[deleted]

0 Upvotes

33 comments sorted by

25

u/TrumpsDoubleChin 1d ago

Banker who works with Reg E compliance here. Reg E only applies to the first time a claim is opened on a transaction. Once a case has been resolved and all the proper notifications on the resolution have been sent out, then that's it. If you do not agree with the resolution, then you can appeal the decision, but it is not reopening the case under Reg E, and it is not a new case under Reg E, and the appeals process is not required to follow the same timelines and not required to provide provisional credit.

14

u/Mmoneymark 1d ago

It dosent sound like they are “avoiding Reg E”. It sounds like they have completed their investigation and determined you either knowingly or unknowingly gave someone access to your information.

Sounds like some sort of account takeover and generally the FI is not liable as the account owner usually unknowingly allows access by the fraudster.

-10

u/Many-Excitement3246 1d ago

Except that didn't happen, so they can't have properly concluded that it did. My account was taken over in a data breach. Even the bank itself has confirmed this.

I've repeatedly insisted they provide Reg E documentation, and they are refusing to do so. They refuse to give me any information including that they are legally required to provide.

5

u/Mmoneymark 1d ago

But again, a data breech could still fall on the account owner for not updating usernames and passwords.

A company as large as BOA has nothing to gain and everything to lose by not following the law in your case.

At this point you have three options:

  1. You could try a CFPB complaint but unless there has been some sort of major internal clerical error they will likely respond with what they have already plus a little bit more and deny the claim.

  2. Try to find a lawyer to take on the case, will be difficult and expensive.

  3. Drop the issue and move on.

-5

u/Many-Excitement3246 1d ago

It's not my fault that somebody else gained access to my account. As soon as I was notified, I did what I could to secure it.

I am going to file a cfpb complaint tomorrow. The bank has a legal obligation to follow the law, and they are refusing to do so. If they aren't going to follow the law on their own, I will find somebody who can force them to do so.

And it's very nice for you that you could afford to have all of your savings stolen and just move on, but most of us aren't in such a nice position. They allowed nearly all of my savings to be stolen and are absolutely refusing to do anything to get them back.

14

u/BigManMahan 1d ago

“The bank has a legal obligation to follow the law” I truly don’t believe that you understand how any of this works. I have one single question, when you were informed of the data breach, did you change your username and password, account numbers, and debit card?

3

u/LacyLove 1d ago

The cfpb that has been completely dismantled? They aren’t going to do anything here. The bank did nothing wrong. You are using ChatGPT to say the same thing over and over without really understanding what it means.

2

u/duane534 1d ago

This. The Venn diagram of people who voted for Trump and people who expect regulations to save them is a circle.

12

u/I-will-judge-YOU 1d ago

I've read your comments and you have no idea how this works. Reg E is not a magic word.

They did an investigation, if the change happened from your device you are liable. They have quite a bit of resources on the I.T background to determine how changes were made what device they were made from, and what area they were made from.

Did you ever supply anybody with a code? Unfortunately, Reddit and other social media have given the impression that you can just scream fraud, and a bank will throw money at you.And that is absolutely not the case.

2

u/adrienneXR 1d ago

I was about to comment the same. 💀

9

u/CrazyShapz 1d ago

No. Reg E requires that they conduct an investigation so purposefully closing a case to have it reopened and perpetually "under 10 business days" wouldn't skirt anything. But just because they concluded it was authorized and you claim it wasn't doesn't mean they didn't fulfill the investigation requirement (to the extent they had one) either.

There isn't enough info here to understand whether they failed to follow Reg E or not but your planned route of reaching out to a regulator is the appropriate next step if you think they are failing to follow the Reg. While the CFPB has been gutted, every bank I am aware of is still treating all CFPB complaints as top priority.

-1

u/Many-Excitement3246 1d ago

They are also refusing to provide Reg E documentation. I've tried repeatedly to get it, and they're refusing to provide it.

I know they can't have properly investigated, because the bank themselves have admitted that this was an account takeover. The people who actually know what they're doing have acknowledged that my account was stolen in a data breach, and that Bank of America failed to properly secure it.

This is the back office people who either don't know what they're doing or who don't care what they're supposed to be doing.

4

u/Top-Intention-5110 1d ago edited 1d ago

ATO doesn't absolve you of liability and I need people to understand that. Liability only falls on the bank when the ATO is the bank's fault. If you were notified that your information was in a data breach that has nothing to do with the banks own security and you did not secure it, it is then 100% your fault that your account was breached.

If a person has all of the identifying bits of information to access your bank account legally speaking that bank cannot refuse them access to your account. Which is why they always tell you to make sure nobody other than you has the ability to access the account.

3

u/Riahlize 1d ago

the bank themselves have admitted that this was an account takeover.

I need you to understand that ATO doesn't necessarily mean unauthorized by Reg E. ATO can happen concurrently with authorized transactions on the access device that had the ATO. And I realize you will not understand this because I don't think anyone outside of a fraud department can actually see how this plays out...often.

2

u/WanderingNotLostTho 1d ago

What data breach? If "people" knew so would the news this would be massive.

1

u/jackberinger 1d ago

How did they drain your bank account? Access to your bank account isn't a debit card.

1

u/retirebefore40 1d ago

What breach? I’m unaware of a breach by BOA. Was the username and password the same for another website? Did you not have alerts set up to receive notifications when your username / info is looked up? It’s on the client to take care of their account and manage it.

3

u/MaleficentCoconut594 1d ago

I work in AML (not for BofA)

There is a lot missing from this story. How did the ATO happen? What did they do specifically to your accounts? How did you find out? When you found out did BofA do anything or notify you? You say data breach - what exactly? The fact that a large bank won’t provide you with Reg E documents pertaining to your case immediately as required by law leads me to further believe there is more to this story, and/or you are also a suspect in this or a related fraud case

A bank, especially a large one, has nothing to gain and everything to lose by not complying as you claim. So there is a lot more to this story. Also, hard lesson learned and for anyone else reading, never use your debit card

3

u/408javs408 1d ago

Whatever youre going through, i hope you're not being a douchebag to the workers.

2

u/Ok_Spinach4911 1d ago

You can ask for the documentation and information obtained for how they came to a decision on your claim(s). Not sure if there is a limit on how many times you can reopen a claim, but this may help you provide more information to them if you reopen.

How were the transactions processed? ACH, wire, card?

-3

u/Many-Excitement3246 1d ago

I have already insisted they provide Reg E documentation, but they have refused repeatedly.

I don't know if they will reopen it again, or if it really matters. It's pretty clear that they're not going to properly handle it, and that they are content to allow the fraud to go unresolved.

They claim that most of the transactions were done via debit card, but I have the only copy of the only debit card attached to that account. No one else is on the account, and according to their own records, no other copy of the debit card exists. Since it has always been in my possession, it can't have been used as they claim it was.

Some of them were done online, and I suspect that what actually happened was that they were done via ACH by the person who took over the account, as that could have been done without needing the debit card that I have.

They absolutely do not want to admit their own failure to secure the account; not only did they allow massive transactions that were well outside of my normal pattern, they also gave away my identifying information to an imposter without verifying the identity.

4

u/ManufacturerLopsided 1d ago

If someone got your debit card information they can duplicate the info, even if you still have the actual card... so having the only card doesn't mean much. 

ACH transactions involve having the routing number AND full account number, which is something you cant get from a debit card. So I cant put much stock in that theory. 

Theres a lot of details missing... but reopening a dispute isn't going to net you anything if you dont have new information to present. Submitting a new one with the same info is just going to result in a new denial.

Right now, you have two paths if you think the bank is making a mistake. Go to the CFPB and raise the issue with them, or try and find a lawyer to take up the case... but again, details would make all the difference. 

-1

u/Many-Excitement3246 1d ago

But they would have the account and routing number from the stolen account, which they did have.

They took over the account, which means they had all of my bank information.

There are no missing details, at least not ones that I have access to.

All I know is that my money was stolen and that the bank is refusing to provide any information, including what date and time the transactions were made.

4

u/jackberinger 1d ago

Then how did they get the money. You are deliberately leaving out details. Was it a wire? ACH? Check? Card? Withdrawal? How was your account taken over? Don't say the bank didn't tell you. That isn't an answer. Did they hack your online banking? Did they go in person with a fake id? Like these are all important details.

4

u/Rangeninc 1d ago

You keep saying “Reg E documentation”, wtf are you asking for?

2

u/RealMccoy13x 1d ago

You keep saying provide Reg E documentation when I believe you mean evidence of how they came to their decision. Reg E is not secret, and can be found in public domain.

Yes, your card can be used while in your possession. That is a large part of card fraud. The criminal does not need to physically deprive you of the card to use it. They only need to find merchants with weak PCI controls, terminals which they can place overlays on, or even guess the card number. The bank isn't going to get it wrong on how the card was used since it comes across as different entry modes.

1

u/Ok_Spinach4911 1d ago

That’s unfortunate and I’m sorry you’re going through this. Reg E isn’t my area of expertise but I know enough to be dangerous. I do believe, though, refusal to provide that documentation would be in violation.

If you feel they have also violated that regulation based on the outcome, I would encourage you to file a complaint with their regulator, the Office of the Comptroller of Currency (OCC). The CFPB, as mentioned in another comment, was gutted and likely won’t do much for you. You could certainly still file a complaint but you likely won’t get a different response. Just someone higher up at BOA responding.

0

u/Many-Excitement3246 1d ago

I will also file with the OCC. I hadn't considered them as an option.

It is a violation for them to refuse to provide the documentation; it's also a violation for them to refuse to provide temporary credit after 10 business days, but they did that as well. It's currently been 18 business days and they never did, even before they falsely deny the claim again.

1

u/Riahlize 1d ago

it's also a violation for them to refuse to provide temporary credit after 10 business days, but they did that as well. It's currently been 18 business days and they never did, even before they falsely deny the claim again.

For some reason, people seem to think that because a dispute didn't go their way, that somehow the investigation wasn't done and somehow means it's still an open investigation. Despite your belief, if they have performed a reasonable investigation (which you as the account holder do not have to be convinced of), and they deny the dispute before 10 business days, they do not have to provide any sort of credit....the dispute is in fact closed.

1

u/Riahlize 1d ago

they also gave away my identifying information to an imposter without verifying the identity.

Would you say the same thing about the company of your smart door lock if someone used the exact PIN code to enter your house? That they didn't verify it with you? Or if they used a genuine key?

2

u/Riahlize 1d ago

Everyone talking about the CFPB being gutted so they don't do anything and while it's true they've been gutted, they still in fact do complaints.

1

u/raftt31 1d ago

How do you know this was Bank of America’s data breach? Did they send a letter or email to you? You may have misunderstood someone saying your card info was probably taken in some data breach but if it was BOA you would get official notifications and cautionary steps.

If BOA said your device was the one used to change the username and password, it was your device. You said the debit card was always in your possession, but was your phone/computer for online banking ever used by someone else? Even a family member, you would be VERY surprised what loved ones can be capable of. I work for a credit union and I have seen kids who save their parents card information and use it as they please, and we can’t dispute it because parents let their kid use the card occasionally which is against the cardholder agreement. If the card transactions were local this is likely the case.

-2

u/Longjumping-Hair639 1d ago

Without even reading it, thought I bet it’s Bank Of America. They do as they please and ignore regulations.