<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ludwig &#38; Robinson PLLC &#187; ACH</title>
	<atom:link href="https://www.ludwigrobinson.com/blog/?feed=rss2&#038;tag=ach" rel="self" type="application/rss+xml" />
	<link>https://www.ludwigrobinson.com/blog</link>
	<description>Blog</description>
	<lastBuildDate>Fri, 29 Jan 2021 20:22:53 +0000</lastBuildDate>
	<language>en-US</language>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=3.8.41</generator>
	<item>
		<title>Virginia Court in Email ACH Funds Transfer Fraud Case Relies on NACHA Rules in Permitting Claims Against Bank</title>
		<link>https://www.ludwigrobinson.com/blog/?p=224</link>
		<comments>https://www.ludwigrobinson.com/blog/?p=224#comments</comments>
		<pubDate>Fri, 29 Jan 2021 20:22:53 +0000</pubDate>
		<dc:creator><![CDATA[Ludwig &#38; Robinson PLLC]]></dc:creator>
				<category><![CDATA[BANKING & FINANCE]]></category>
		<category><![CDATA[CORPORATE]]></category>
		<category><![CDATA[INSURANCE]]></category>
		<category><![CDATA[INTERNATIONAL]]></category>
		<category><![CDATA[LITIGATION]]></category>
		<category><![CDATA[ACH]]></category>
		<category><![CDATA[ACH Fraud]]></category>
		<category><![CDATA[BEC]]></category>
		<category><![CDATA[Business Email Compromise]]></category>
		<category><![CDATA[Credit Union]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Funds Transfer Fraud]]></category>
		<category><![CDATA[NACHA]]></category>
		<category><![CDATA[NACHA Operating Rules]]></category>
		<category><![CDATA[Salvatore Scanio]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[UCC]]></category>
		<category><![CDATA[UCC Article 4A]]></category>
		<category><![CDATA[UCC § 4A-207]]></category>

		<guid isPermaLink="false">http://www.ludwigrobinson.com/blog/?p=224</guid>
		<description><![CDATA[As L&#38;R has showed, careful application of NACHA’s rules can be critical to resolving funds transfers losses involving ACH transfers. See L&#38;R Obtains Prompt Full Recovery for Polish Client in ACH Cybercrime Case. A recent Virginia case illustrates the relevance &#8230; <a href="https://www.ludwigrobinson.com/blog/?p=224">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>As L&amp;R has showed, careful application of NACHA’s rules can be critical to resolving funds transfers losses involving ACH transfers. <i>See</i> <i><a href="http://www.ludwigrobinson.com/blog/?p=207" target="_blank">L&amp;R Obtains Prompt Full Recovery for Polish Client in ACH Cybercrime Case</a></i>. A recent Virginia case illustrates the relevance and utility of NACHA’s rules. <i>Studco Bldg. Sys. United States, LLC v. 1st Advantage Fed. Credit Union</i>, 2020 U.S. Dist. LEXIS 238945 (E.D. Va. Dec. 18, 2020).</p>
<p>In another fairly typical business email compromise/social engineering scheme, a cybercriminal  impersonating a vendor induced a business to send four large ACH transfers totaling  $558,868.17 to the fraudster’s account at a credit union. The plaintiff asserted various claims against the beneficiary’s bank, alleging:</p>
<p style="padding-left: 30px;">● Around August 2018, the credit union opened a personal checking account for an individual, John Doe, but did not verify his identity, address, prior banking history, source of funds, membership eligibility</p>
<p style="padding-left: 30px;">● In October 2018, Doe transmitted fraudulent emails to plaintiff</p>
<p style="padding-left: 30px;">● Plaintiff then sent an ACH transfer of $156,834.55 identifying itself, Studco, as the originator and its vendor Olympic Steel, by corporate address, as the receiver, which did not match any account holder with the credit union</p>
<p style="padding-left: 30px;">● The ACH credit identified Doe’s personal account number, but it was commercially coded as &#8220;CCD,&#8221; i.e., &#8220;Corporate Credit or Debit,&#8221; for business transactions under Rules of the National Automated Clearing House Association (NACHA)</p>
<p style="padding-left: 30px;">● NACHA Rules restrict CCD payments to transactions that involve only businesses, and require that any CCD payments directed to personal accounts be rejected</p>
<p style="padding-left: 30px;">● Shortly thereafter, the credit union accepted three additional high-value commercial ACH credit payments for Doe’s account, totaling $558,868.17</p>
<p style="padding-left: 30px;">● Over a one-month period, Doe then withdrew over $558,868.17 incrementally and in-person at the credit union’s branch with the assistance of the credit union, through 13 cashier checks or wire transfers totaling $558,868.17</p>
<p style="padding-left: 30px;">● Nine (9) of the thirteen (13) withdrawals were made out to an individual or entity that is alleged to be known to the credit union or its employee(s).</p>
<p><i>Id</i>. at *1-4.</p>
<p>While the district court dismissed several claims brought by the plaintiff, it permitted two key counts to go forward, in large measure due to the plaintiff’s reliance on NACHA’s rules.</p>
<p>The first was a claim under UCC § 4A-207 for misdescription of beneficiary, with the court finding: “While it is true that [the credit union] has no duty to proactively discover a conflict, the Complaint alleges that [it] had actual knowledge of the misdescription because the transfers were codified as ‘CCD’ and, thus, that it was automatically required to reject the misdescribed ACH transfers, pursuant to NACHA, but it did not. . . . Therefore, the issue of whether [the credit union] had actual knowledge is a factual determination for the jury.” <i>Id</i>. at 12-13.</p>
<p>The second claim the court permitted was a claim for bailment, concluding, “Although bailment requires a common law duty of care . . . the NACHA Rules and [UCC § 4A-207] establish that 1st Advantage must act in a commercially reasonable manner or that it exercised ordinary care when it has control over ACH transfers.” <i>Id</i>. at 16. Like the UCC claim, the court stated: “the question of whether 1st Advantage acted in a commercially reasonable manner in exercising control over [plaintiff’s] ACH transfers is one that the jury must answer[.]” <i>Id</i>. at 16-17. “Specifically, the Complaint alleges that the NACHA Rules provide that ‘it is not commercially reasonable to deposit commercially-coded ‘CCD’ transfers expressly identified as ‘business transactions’ into a personal checking account. Furthermore, NACHA Rules require that depositing &#8216;CCD&#8217; coded transfers into consumer accounts is not commercially reasonable. . . . Moreover, [plaintiff] has adequately alleged that [the credit union] did not act in a commercially reasonable manner in allowing John Doe to fraudulently withdraw money over a month in-person.” <i>Id</i>. at 17.</p>
<p>This case, like L&amp;R’s recent ACH matter, is an important illustration of how effective application of the NACHA Rules can be critical in resolving such cases.</p>
<p>For further information, contact Salvatore Scanio at sscanio@ludwigrobinson.com or 202-289-7605 or Robert Ludwig at rludwig@ludwigrobinson.com or 202-289-7603.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>https://www.ludwigrobinson.com/blog/?feed=rss2&#038;p=224</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Federal Reserve’s Secure Payments Task Force Seeks Feedback on Payment Use Cases</title>
		<link>https://www.ludwigrobinson.com/blog/?p=104</link>
		<comments>https://www.ludwigrobinson.com/blog/?p=104#comments</comments>
		<pubDate>Fri, 05 May 2017 22:25:12 +0000</pubDate>
		<dc:creator><![CDATA[Ludwig &#38; Robinson PLLC]]></dc:creator>
				<category><![CDATA[BANKING & FINANCE]]></category>
		<category><![CDATA[CORPORATE]]></category>
		<category><![CDATA[INSURANCE]]></category>
		<category><![CDATA[LITIGATION]]></category>
		<category><![CDATA[ACH]]></category>
		<category><![CDATA[ACH Fraud]]></category>
		<category><![CDATA[Card Not Present]]></category>
		<category><![CDATA[Card PIN]]></category>
		<category><![CDATA[Card Signature]]></category>
		<category><![CDATA[Check]]></category>
		<category><![CDATA[Check Fraud]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[EFT Fraud]]></category>
		<category><![CDATA[Federal Reserve Secure Payments Task Force]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Mobile Payment]]></category>
		<category><![CDATA[Online Banking]]></category>
		<category><![CDATA[Payment Card Fraud]]></category>
		<category><![CDATA[Salvatore Scanio]]></category>
		<category><![CDATA[SWIFT Fraud]]></category>
		<category><![CDATA[Wire]]></category>
		<category><![CDATA[Wire Transfer Fraud]]></category>

		<guid isPermaLink="false">http://www.ludwigrobinson.com/blog/?p=104</guid>
		<description><![CDATA[The Secure Payments Task Force, convened by the Federal Reserve to advance the safety, security, and resiliency of the national payment system, is asking for feedback on a set of payment use cases which together map out the lifecycle of a &#8230; <a href="https://www.ludwigrobinson.com/blog/?p=104">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>The Secure Payments Task Force, convened by the Federal Reserve to advance the safety, security, and resiliency of the national payment system, is asking for feedback on a set of <a href="https://fedpaymentsimprovement.org/payments-security/payment-use-cases/?elqTrackId=7A44054A204F10A17F367428C0C9CE54&amp;elq=1941d6ba8c3a473c9317d5b775919801&amp;elqaid=11683&amp;elqat=1&amp;elqCampaignId=" target="_blank">payment use cases</a> which together map out the lifecycle of a payment for eight payment types.  The payments types include ACH, Card Not Present, Card PIN, Card Signature, Check, Contactless, Wallet, and Wire.  The payment use cases are intended to provide a common foundation for the payments industry to understand the landscape as it exists today and the associated risks.  Each use case addresses its respective unique payment flow overview, payment type operation, overview of security methods and associated risks, inventory of sensitive payment data and associated risks, and overview of standards.</p>
<p>As a member of the Fed’s Task Force, Ludwig &amp; Robinson is seeking feedback on these payment use cases, which has created an online <a href="https://www.frbsurveys.org/se/3FD0ADC72413656A">Payment Use Cases Industry Survey</a> for that purpose.</p>
<p>In addition, the Task Force is presenting Payment Use Case webinars to provide an opportunity to gain a high-level overview of each use case as a supplement to the <a title="Review the Payment Use Cases" href="https://fedpaymentsimprovement.org/payments-security/payment-use-cases/?elqTrackId=7A44054A204F10A17F367428C0C9CE54&amp;elq=1941d6ba8c3a473c9317d5b775919801&amp;elqaid=11683&amp;elqat=1&amp;elqCampaignId=">use case documents</a>, as follows:</p>
<p><i>Payment Use Cases Webinar – ACH, Wire and Check</i><br />
Date and Time: Thursday, May 11 from 3:00 – 4:00 p.m. ET<br />
<i><br />
</i><i>Payment Use Cases Webinar – Card Signature, Card PIN and Card Not Present</i><br />
Date and Time: Friday, May 12 from 2:00 – 3:00 p.m. ET<br />
<i><br />
</i><i>Payment Use Cases Webinar – Card Not Present, Contactless and Wallet</i><br />
Date and Time: Monday, May 15 from 2:00 – 3:00 p.m. ET</p>
<p>You may <a title="Register for the Payment Use Cases Webinars" href="https://information.frbcommunications.org/PUCRegistration201705?elqTrackId=F8512D599807A3D31AA60845C6C2F3DE&amp;elq=1941d6ba8c3a473c9317d5b775919801&amp;elqaid=11683&amp;elqat=1&amp;elqCampaignId=">register</a> for one or more of these webinars to learn about each of the payment use cases and provide your input.  This information can also be found on <a href="http://fedpaymentsimprovement.org">FedPaymentsImprovement.org</a>.</p>
<p>For further information, contact Salvatore Scanio at sscanio@ludwigrobinson.com or 202-289-7605.</p>
]]></content:encoded>
			<wfw:commentRss>https://www.ludwigrobinson.com/blog/?feed=rss2&#038;p=104</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
