The first question clients often ask when cybercriminals get into a company’s online banking system and transfer money from the account is whether or not the bank should be held responsible for the loss.
The answer is almost never simple since account agreements, the Uniform Commercial Code (“UCC”), and mandatory arbitration clauses are generally drafted in such a way as to protect the bank against all liability.
However, the bank does not automatically prevail in all account takeover (“ATO”) cases cases and recovery in many instances turns on what the bank knew, what its systems picked up, and whether it followed its own security procedures.
The Scale of the Problem
Cyber-enabled financial fraud is still increasing at an alarming rate.
In 2025 the FBI’s Internet Crime Complaint Center (“IC3”) received over one million complaints and the amount of money lost was more than $20.8 billion, which represents a 26 percent rise on the figure from the previous year ([1]).
In 2025, business email compromise (“BEC”), which is often the first step leading to account takeover fraud, resulted in 24,768 complaints and reported losses exceeding $3 billion ([2]).
For a great many businesses, one fraudulent transfer can put their operations, their payroll, or the continued existence of the company at risk.
Why the Law Starts Out Favoring the Bank
The idea is that many business owners think they are entitled to the same level of protection as consumers, but they aren’t.
Regulation E provides protection to individual consumers who use personal banking accounts; it usually does not cover commercial accounts held by corporations, partnerships, or other business entities ([3]).
Commercial wire transfers are mainly regulated by Article 4A of the Uniform Commercial Code and by the agreements between the bank and its customer; these agreements are generally drafted in such a way as to assign risk of loss to the to the business.
User Agreements usually state that the customer must protect the credentials, have control over access to the account, and comply with the agreed security procedures.
Accordingly, the bank’s first response is usually simple in that the transaction has been verified with valid credentials and must therefore be viewed as authorized.
The Key Legal Standard
The section of the law that most banks depend on is UCC § 4A-202 ([4]).
A payment order may be analyzed as the customer’s order under that statute even if it had not been authorized, on the condition that (i) the bank’s security procedure was commercially reasonable and (ii) the bank accepted the payment order in good faith and in accordance with that procedure ([5]).
It is important that the bank should have to prove both of these elements.
Commercial reasonableness cannot be judged in a general or abstract way; instead, the analysis takes into account the customer’s circumstances, such as the character of its business, its usual patterns of transaction, the security features available from the bank, and the practices generally followed by similar institutions and customers ([6]).
Even though the statute presents commercial reasonableness as a legal issue, it is generally determined by referring to technical evidence, transaction records, and expert testimony.
If the payment order has not been authorized and fails to meet the requirements of § 4A-202, the bank is generally obliged to return the money together with interest, and this duty cannot be waived by contract ([7]).
Where These Cases Are Won or Lost
The most important evidence is usually obtained from the bank’s own systems.
The federal banking regulators made it clear that financial institutions should use multiple layers of security controls rather than depending just on passwords or single-factor authentication; the regulatory guidance also stresses the importance of fraud detection, monitoring for anomalies, analyzing transactions, and examining unusual customer behavior ([8]).
Modern attacks often manage to get around passwords and even conventional multi-factor authentication.
The Cybersecurity and Infrastructure Security Agency (“CISA”) cautioned that attackers regularly steal usernames, passwords, and one-time authentication codes by means of phishing and social-engineering attacks ([9]).
A claim brought against a bank usually centers on whether the bank noticed the warning signs and did not take action. For example:
- Logins from locations that are unfamiliar or from IP addresses in foreign countries.
- Access from a device that has never been used on this account before.
- Unexpected changes to contact details.
- The size of the transfers is not in agreement with past activity.
- The addition of new beneficiaries right before the transfer took place.
- The bank’s systems have generated internal fraud alerts.
- Calls that were required to be verified had never been made.
The main issue is typically whether the bank carried out procedures which were commercially reasonable and whether it acted in good faith after it had received signs that something was wrong.
Arbitration Is Usually Required
Mandatory arbitration clauses can be found in the majority of business banking agreements.
Arbitration agreements are usually enforceable under the Federal Arbitration Act; it is for this reason that a large number of business account takeover claims are resolved before organizations such as the American Arbitration Association (“AAA”) or JAMS rather than going to court ([10]).
Arbitration does pose some difficulties since discovery is generally more limited than in the case of traditional litigation.
That said, businesses are still able to get important evidence such as authentication logs, fraud alerts, the results of internal investigations, and documentation relating to security procedures.
With proper preparation and expert analysis, these cases can be successfully pursued.
What To Do Immediately
When it is found that an account has been taken over, time is of the essence.
Start by getting in touch with the bank and asking for the transfer to be recalled or reversed immediately ([11]).
Have the bank speak directly to the institution where the money was received and begin all the possible recovery procedures.
Second, submit a complaint to the FBI’s IC3. The FBI states that its Recovery Asset Team froze about $679 million in fraudulent transfers in 2025, which corresponds to a 58 percent success rate for attempted recovery actions ([12]).
Also, make sure all the evidence is preserved, such as emails, text messages, authentication records, call logs, and the affected devices.
Fourth, send the bank a written notice and ask it to keep all the logs, alerts, and records related to the incident.
Finally, take the time to carefully go through the account agreement and keep record of all the contractual and statutory notice deadlines.
How Dilendorf Law Firm Helps
The Dilendorf Law Firm deals with cases involving account takeovers and cyber-fraud for businesses.
We help our clients with filing reports under IC3, carrying out recovery operations, conducting forensic investigations, preserving evidence, and making claims against financial institutions.
If needed, we initiate arbitration proceedings and collaborate with experienced cybercrime investigators and expert witnesses in order to examine bank security procedures, transaction records, and fraud-detection systems.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Sources
[1] FBI Internet Crime Complaint Center, 2025 Internet Crime Report, p. 6 (total complaints, losses, and year-over-year increase). https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[2] FBI IC3, 2025 Internet Crime Report, pp. 7–8, 25–26 (business email compromise complaints and losses). https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[3] Consumer Financial Protection Bureau, Regulation E, 12 CFR § 1005.2(b)(1), (e) (definitions of “account” and “consumer”). https://www.consumerfinance.gov/rules-policy/regulations/1005/2
[4] Uniform Commercial Code § 4A-202, Authorized and Verified Payment Orders (Legal Information Institute, Cornell Law School). https://www.law.cornell.edu/ucc/4A/4A-202
[5] Uniform Commercial Code § 4A-202(b) (payment order effective as the customer’s order if security procedure commercially reasonable and bank acted in good faith and in compliance with it). https://www.law.cornell.edu/ucc/4A/4A-202
[6] Uniform Commercial Code § 4A-202(c) (factors for commercial reasonableness). https://www.law.cornell.edu/ucc/4A/4A-202
[7] Uniform Commercial Code § 4A-204(a)–(b), Refund of Payment and Duty of Customer to Report (Legal Information Institute, Cornell Law School). https://www.law.cornell.edu/ucc/4A/4A-204
[8] Federal Financial Institutions Examination Council, Authentication and Access to Financial Institution Services and Systems, Interagency Guidance, Aug. 11, 2021, §§ 4–6 and Appendix (as published by the Federal Reserve Board). https://www.federalreserve.gov/frrs/guidance/authentication-and-access-to-financial-institution-services-and-systems-interagency-guidance.htm
[9] Cybersecurity and Infrastructure Security Agency, Phishing Resistant MFA is Key to Peace of Mind, Apr. 12, 2023. https://www.cisa.gov/news-events/news/phishing-resistant-mfa-key-peace-mind
[10] 9 U.S.C. § 2, Validity, irrevocability, and enforcement of agreements to arbitrate (Legal Information Institute, Cornell Law School). https://www.law.cornell.edu/uscode/text/9/2
[11] FBI Internet Crime Complaint Center, Business Email Compromise (What To Do In Case Of A BEC Incident). https://www.ic3.gov/CrimeInfo/BEC
[12] FBI IC3, 2025 Internet Crime Report, p. 17 (Recovery Asset Team / Financial Fraud Kill Chain). https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
