Skip to content

Menu

LexBlog, Inc. logo
CommunitySub-MenuPublishersChannelsProductsSub-MenuBlog ProBlog PlusBlog PremierMicrositeSyndication PortalsAboutContactResourcesSubscribeSupport
Join
Search
Close

Complaint Dismissed Where Hacker-Induced Wire Transactions Authorized by Bank’s Customer

Cybersecurity_1073242516
By Mary C. Zinsner, Susan Flint, Andrew Buxbaum & Elizabeth Briones on May 3, 2022
Email this postTweet this postLike this postShare this post on LinkedIn

A federal district court in New Jersey recently dismissed a complaint against a bank filed by a commercial customer duped by a business email compromise incident. The case involved four wire transfers totaling $1.4 million dollars. The court found that even though the customer was tricked by a fraudster into initiating the transfers, the wires were authorized by the customer’s account manager who approved and confirmed the transactions. The court concluded that the question of whether the bank complied with commercially reasonable security procedures under Uniform Commercial Code Section 4A-202(2) is not reached if the transfers are authorized.

In Harborview Capital Partners, LLC v. Cross River Bank, the email account of the CEO of Harborview was hacked. The fraudster, purporting to be the CEO, emailed Harborview’s account manager, instructing her to initiate four wires to various accounts at a financial institution in Hong Kong. The account manager complied, and upon receipt of each wire transfer order, the bank contacted the account manager to confirm the details of the transaction.

After the fraud was uncovered, Harborview sued the bank, asserting that it accepted unauthorized wire transfer orders and failed to maintain and/or adhere to commercially reasonable security procedures, seeking to hold the bank liable for the payment of the transfers under the UCC. Harborview further alleged that the bank knew that it did not engage in international business, and claimed that after the first wire transfer failed, the bank should have investigated the reason why. Harborview alleged that had the bank done so, the fraud would have been discovered.

Parsing through the language of Article 4A, the court found that the UCC “provides that a payment order sent by a sender’s representative is authorized and binding ‘if that person authorized the order or is otherwise bound by it under the laws of agency.'” Even though Harborview was tricked into authorizing the transfers by a hacker, the orders were still authorized by the account manager. The court noted that Harborview’s claims might have survived a motion to dismiss if the bank was not entitled to rely on instructions from the account manager, but “[n]o such contention is made here.” The court concluded that “[b]ecause Harborview’s agent, employee, and representative sent, signed, and confirmed the wire transfers — even if she did so because she was misled by a third-party hacker — Article 4 provides no cause of action for Harborview.”

In reaching this conclusion, the district court examined two out-of-jurisdiction opinions, addressing what constitutes an “authorized order” under Article 4A of the UCC — Wellton Int’l Express v. Bank of China (Hong Kong) and Berry v. Regions Bank. In both cases, the courts found that the customer had authorized the funds transfer and dismissed the Article 4A-202 UCC claims. Like the plaintiffs in Wellton and Berry, even though Harborview was tricked into authorizing the transfers, “the disputed wire transfers were undoubtedly authorized by Harborview.”

Although Harborview urged the court to consider whether the bank had commercially reasonable security procedures under UCC Section 4A-202(2), the court concluded that it could not reach the question because the transfers were authorized. The court found that the predicate inquiry under the UCC Section 4A-202(1) is whether the transfer was authorized. If authorized, the inquiry under Section 4A-202 ends. The court found that Section 202(2) “posits a second scenario under which the bank may safely execute a transfer order, even if it turns out to have not been actually authorized by the customer. Under 202(2), even if the transfer was not actually authorized by the customer, the bank may escape liability if it verified the transfer according to commercially reasonable procedures upon which the parties had agreed to beforehand.” The court further found that Harborview’s common law claims were preempted by Article 4A, finding that the allegations that the bank accepted unauthorized payment orders, did not adhere to commercially reasonable security procedures, and failed to take certain actions with respect to funds transfers constituted “the very subject matter covered by Article 4A.”

The facts here are common — especially in business email compromise situations involving a bank and its customer. The decision will be helpful to banks facing claims from customers alleging that the bank failed to verify transfers pursuant to commercially reasonable procedures. Rather than merging Sections 202(1) and 202(2) and evaluating compliance with both, the court did a good job of carefully reviewing relevant caselaw and parsing through the UCC to make clear that the statute entails a two-part inquiry where a customer brings a claim against its own bank for originating a wire transfer induced fraudulently by business email compromise. As the court noted, “whether a payment order is authorized is a threshold inquiry; if the order was authorized in fact by the person who is the designated signatory for the customer, the outcome does not thereafter depend on whether the bank also verified the payment order pursuant to commercially reasonable procedures.” Where the bank does nothing more than execute the wire transfer at the direction of an authorized representative of the customer, there is no liability for failing to detect the fraud pursuant to commercially reasonable procedures.

The Harborview decision should be in the arsenal and cited along with Wellton and Berry when the bank originating the fraudulently induced wire moves to dismiss claims brought under UCC Section 4A-202. The case should not proceed to discovery into the commercial reasonableness of the bank’s security procedures where the facts alleged make clear that the customer, although duped by a hacker via business email compromise, in fact authorized the wire transaction.

Photo of Mary C. Zinsner Mary C. Zinsner

Mary Zinsner is a partner in Troutman Pepper’s Washington, D.C. office who handles high stakes matters for banks nationwide. Mary focuses her practice on litigation and strategy in lender liability, check and bank operation, class action, consumer finance, fiduciary matters, and creditor’s rights…

Mary Zinsner is a partner in Troutman Pepper’s Washington, D.C. office who handles high stakes matters for banks nationwide. Mary focuses her practice on litigation and strategy in lender liability, check and bank operation, class action, consumer finance, fiduciary matters, and creditor’s rights disputes. She has also been accepted into the American Arbitration Association’s (AAA) Roster of Arbitrators. Viewed as leaders in the practice of alternative dispute resolution (ADR), AAA arbitrators are required to receive ongoing education in the art and science of arbitration and demonstrate knowledge, prowess, mastery, and proficiency in a particular field.

Read more about Mary C. ZinsnerEmail
Show more Show less
Photo of Susan Flint Susan Flint

Susan is a partner in the firm’s Consumer Financial Services practice with more than 25 years of experience leading teams responsible for litigation and regulatory enforcement matters. Susan specializes in issues arising in the financial services industry and has experience representing and

…

Susan is a partner in the firm’s Consumer Financial Services practice with more than 25 years of experience leading teams responsible for litigation and regulatory enforcement matters. Susan specializes in issues arising in the financial services industry and has experience representing and providing general and specific legal advice and support for high risk litigation and regulatory issues resulting in favorable results to the client. She has extensive experience defending banking clients in multiple areas including retail and small business banking, complex commercial litigation, third party vendor issues and advising on third party legal process issues.

Susan has significant experience in record retention programs for financial institutions and electronic discovery in complex commercial litigation. Susan has been a panelist on litigation discovery issues and has been a frequent instructor with the Minnesota Bankers Association and the American Institute of Banking on issues related to the handling of third party legal process.

Read more about Susan FlintEmailSusan's Linkedin Profile
Show more Show less
Photo of Andrew Buxbaum Andrew Buxbaum

Andrew specializes in representing clients in the financial services industry (including banks, lenders, mortgage companies, debt collection firms and loan servicers) in consumer litigation, bankruptcy, and regulatory compliance matters.

Read more about Andrew BuxbaumEmailAndrew's Linkedin Profile
Photo of Elizabeth Briones Elizabeth Briones

Elizabeth Briones is an associate in the firm’s Consumer Financial Services practice with a focus on complex litigation, professional liability, and product liability. 

Read more about Elizabeth BrionesEmail
  • Posted in:
    Financial
  • Blog:
    Consumer Financial Services Law Monitor
  • Organization:
    Troutman Pepper Hamilton Sanders LLP
  • Article: View Original Source

LexBlog, Inc. logo
Facebook LinkedIn Twitter RSS
Real Lawyers
99 Park Row
  • About LexBlog
  • Careers
  • Press
  • Contact LexBlog
  • Privacy Policy
  • Editorial Policy
  • Disclaimer
  • Terms of Service
  • RSS Terms of Service
  • Products
  • Blog Pro
  • Blog Plus
  • Blog Premier
  • Microsite
  • Syndication Portals
  • LexBlog Community
  • 1-800-913-0988
  • Submit a Request
  • Support Center
  • System Status
  • Resource Center

New to the Network

  • Pro Policyholder
  • The Way on FDA
  • Crypto Digest
  • Inside Cybersecurity & Privacy Law
  • La Oficina Legal Ayala Hernández
Copyright © 2022, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo