Back to Insights
    Bank Fraud

    The "Authorized" Fiction: Litigating Denied P2P Fraud Claims Under the EFTA

    By Rene McNulty, Esq. February 18, 2026 6 Min Read

    If you logged into your bank app and discovered that funds had been moved out of your account through Zelle, Venmo, Cash App, or another peer-to-peer network — and your bank denied your fraud claim on the grounds that the transfer was "authorized" — federal law may give you a path to recovery. The Electronic Fund Transfer Act and its implementing rule, Regulation E, limit consumer liability for genuinely unauthorized electronic transfers and require banks to conduct a reasonable investigation before denying a claim. The analysis below explains how the EFTA defines "unauthorized," why banks routinely deny claims that should be investigated more carefully, and where the law on consumer-deceived transfers currently stands. For a broader overview of your rights under the EFTA, including the important distinction between account-takeover fraud and consumer-initiated scam transfers, see our Know Your Rights: Unauthorized Bank Transfers page.

    When funds disappear from a consumer's bank account through a P2P network, the consumer expects the institution to investigate and, where appropriate, restore the funds. In many cases, the response is a brief denial letter stating that the transfer was "authorized" because the consumer's credentials were used. That conclusion may be correct in some circumstances and seriously wrong in others — and the distinction matters under federal law.

    The Legal Framework: The EFTA and Regulation E

    The Electronic Fund Transfer Act (EFTA), 15 U.S.C. § 1693 et seq., and its implementing rule, Regulation E (12 C.F.R. § 1005), establish a framework that limits consumer liability for unauthorized electronic transfers and requires financial institutions to investigate consumer fraud claims under specific procedures and timelines.

    Under 15 U.S.C. § 1693g and Regulation E § 1005.6, a consumer's liability for an unauthorized electronic fund transfer is capped at a statutory amount that depends on the timing of the consumer's notification to the institution. Consumers who notify their financial institution promptly are entitled to substantially greater protection than those who delay.

    An "unauthorized electronic fund transfer" is defined at 15 U.S.C. § 1693a(11) and Regulation E § 1005.2(m) as a transfer from a consumer's account initiated by a person other than the consumer without actual authority to initiate the transfer, and from which the consumer receives no benefit. The statutory definition specifically excludes transfers initiated by a person who was furnished access to the account by the consumer, unless the consumer has notified the institution that the person is no longer authorized.

    What Counts as an "Unauthorized" Transfer Under the EFTA?

    The clearest case of an unauthorized transfer under the EFTA is one in which a third party — typically through credential theft, account takeover, malware, or session hijacking — accesses the consumer's account and moves funds without the consumer's knowledge or participation. In these cases, the consumer did not initiate the transfer, did not authorize the recipient, and received no benefit. The statutory definition applies on its terms, and the institution's obligation to investigate and, where appropriate, restore funds is established.

    A more contested category involves consumer-initiated transfers where the consumer was deceived about the identity of the recipient or the purpose of the transfer — for example, romance scams, vendor impersonation, or scams in which the consumer was directed to move funds to what they believed was a legitimate destination. Whether such transfers fall within the EFTA's definition of "unauthorized" is the subject of ongoing legal dispute. The Consumer Financial Protection Bureau has taken enforcement positions on aspects of this question, financial institutions have taken the opposite position, and federal courts have not uniformly resolved the issue. Consumers in this category should not assume the outcome is settled and should evaluate their claims with counsel familiar with the current state of the law in their jurisdiction.

    Why Do Banks Deny Account-Takeover Claims?

    When investigating an unauthorized-transfer claim, banks rely heavily on matching digital footprints. If a fraudulent transfer was initiated from a device on which the consumer's mobile banking app is installed, or from an IP address the consumer has previously used, the institution's automated systems often flag the transfer as "authorized" without further inquiry. This conclusion may overlook circumstances in which a malicious actor bypassed two-factor authentication, deployed malware, or executed a session-hijacking attack — all of which can occur on a device or network the consumer has previously used.

    Regulation E § 1005.11 imposes a duty on financial institutions to conduct a reasonable investigation of consumer claims. Denying a claim based solely on credential or device-ID matching, without examining the surrounding forensic evidence, raises a question whether the institution has satisfied that duty.

    What Evidence Establishes an EFTA Claim?

    Effective EFTA claims rest on a careful evidentiary record. Consumers and their counsel typically focus on:

    • The timeline and timing of the consumer's notification to the institution, which determines the applicable liability cap under § 1693g.
    • The institution's written denial and the stated basis for the denial, which establishes what the institution actually investigated.
    • Forensic data the institution relied on or failed to obtain, including session logs, geolocation data, device fingerprinting, biometric mismatches, and transaction-velocity metrics.
    • Evidence of how the transfer was actually initiated, including any indicators of account takeover, malware, or third-party access.

    The EFTA provides for actual damages, statutory damages, and fee-shifting under 15 U.S.C. § 1693m where a financial institution has failed to comply with its obligations under the statute.

    Midwest Consumer Law PLLC handles EFTA unauthorized-transfer matters in federal court.


    Legal Disclaimer: The insights and analysis provided in this publication are intended for educational and informational purposes only and do not constitute legal advice. Reading this article, or submitting information through this website, does not create an attorney-client relationship with Midwest Consumer Law PLLC. Every legal matter is unique, and prior results do not guarantee a similar outcome. If you believe your rights under the Electronic Fund Transfer Act or other consumer protection statutes have been violated, you should seek the counsel of a qualified attorney to discuss the specific facts of your case.

    Free Case Review