Consumers defrauded on Zelle are left high and dry by the banks that created it [pdf]
warren.senate.gov
warren.senate.gov
But the core concept is digital cash, so you HAVE to treat it as such.
And really this was the original idea for PayPal, dwolla, and lots of other digital cash payment systems.
I spent three weeks being passed back and forth by one bank being told I needed to speak with they other bank. They confirmed the money had been debited from my account, and confirmed it was not deposited in his, but nobody could tell me where the money went. I called Zelle multiple times, but all they would tell me is I needed to talk to the banks. Eventually after three weeks the money was quietly returned to my account with no explanation. After a bit more digging it appears my transaction triggered some fraud alert, but neither myself, the depositor, or either bank was notified of this.
To add insult to injury, during this process the people in charge of Zelle at my bank (which rhymes with Space) told me I was out of luck, because using the Zelle for any type of commercial transaction, including sending rent or security deposits, is against the terms of service. Looking back over the terms of service I found they were 100% correct.
I also found that Zelle is basically just a front-end for the existing ACH Direct Deposit system. It was created by a consortium of banks to compete with services like Venmo, but it at it's core a very different service. Venmo actually provides value by acting as a middle man: Venmo pays the recipient and collects the money from me. Zelle is just a way to send money directly to someone's checking account, but by using their email address or phone number instead of the account and routing number. This is why there is absolutely no recourse if anything goes wrong.
tl;dr do not ever use Zelle.
You've got a lot of details in there that are definitely not common knowledge and would be of wide interest.
But I do get the sense that of all the payment platforms, Zelle is uniquely risky because of the way it's set up. I do with a journalist would look at it from that angle rather just from the "wow there's a lot of fraud here". It seems to be that the banks are incentivized just to get have this product out here to undercut the competition from digital payment platforms, but have absolutely no incentive to make it a functional or safe platform.
I've used PayPal and Venmo but I don't see their utility now and prefer Apple Pay.
All of these modern tools have their benefits and risks. I got burned for $40 on Zelle for a bike part. It was a $40 lesson.
For me I only use Venmo because that's what most people in social circles use. If they used Cash App or Apple Pay, I'd use those instead.
an employer’s direct deposit system, at a third party payroll company asked me for a voided check
I photoshopped my bank account and routing number on a stock image of a voided check
I get paid no problem. dumb process.
So it’s a good, real requirement because it works more frequently than any other alternatives.
you know what works even better though? copy and paste. banking and technology illiterate wage slaves aren't the only ones that wind up with employment on occassion. payroll companies should offer multiple ways to get this done.
We had so many support tickets and errors from people making errors with entering routing and account numbers. Like 20% of all new payees enters bounced back or went to the wrong place. This worked out because new payees were rare since people typically pay the same people over and over.
I think HR does the cancelled check thing because the risk of error is so great and consequential. If people’s paycheck fails, that’s bad.
Walking people through cutting and pasting is harder than “give me a check.”
I can't figure out how to do ACH transfers to friends with my credit union, and I've been told Zelle is the solution for that. I guess I should stick to Venmo?
Zelle has their own instant transfer system, and banks settle up overnight. My understanding is that there isn't ACH transaction for each transfer. Banks have less visibility into Zelle.
I hope FedNow kills Zelle. That should be better integrated. I think Venmo and other payment apps will stick around cause offer useful app.
It is as though a committee of engineers and consultants sat together and said "How do we create the perfect vehicle for as many different types of scams as possible?"
- Maybe! instant settlement
- No standardized audit trail
- No way to know who's really on the other side
- Send money into the void
- 2FA but not really - No standardized audit trail
- No way to know who's really on the other side
I think these 2 are the biggest ones. You put in someone's phone number / email, and you get maybe an associated name as reassurance. How do I know it's actually associated with an account the person I'm trying to pay has access to?Once you give it, you can't demand it back without courts.
It's also a lot easier to send like $5K to some faceless entity with Zelle than with cash.
This version relies on banks being required to make "funds available" in a timeframe that's often shorter than how long it takes a cheque to actually clear - so you can dig yourself into a hole before the cheque finally bounces.
The zelle version is essentially the same thing. Someone "accidentally" sends you a sum, and being a nice, reasonable person, you return it. The problem is this isn't a rollback; you don't (can't) revert their transaction - you create a second transaction.
So when the source of the original transaction turns out to be fraudulent - and as the parent post says, fraudulent can be reverted, the house always wins - that first transaction is reverted. The second, where you "returned" their overpayment, is an entirely distinct transaction and needs to be fought separately. And it's a much harder fight to win, because it doesn't involve the house winning.
(And yes, this could be almost entirely mitigated by having a user-facing return/revert/refund function that undoes the original transaction instead of creating a second.)
So I called them and sat on hold until someone finally picked up and told me that my order was flagged for some reason. After I confirmed my address (?), they seemed to confirm my order and then hung up. I still haven't gotten any confirmation that my item shipped yet.
In general I try to avoid ordering from Amazon, but if I had done that instead, I would have my item in my hands right now. Instead I had to waste my time playing phone tag, and I'm still wondering whether or when they'll actually ship my item. All because the vendor is apparently super-averse to credit card fraud and would rather push me to Amazon for future purchases than take whatever chance they'd be taking by sending me what they've already charged me for.
I'll have to be calling them again after the weekend to see if they've actually sent it. If they haven't, I'll tell them to cancel my order. And then I'll have to wait for them to refund the charges. If they don't, then I'll have to make another call to my bank to reverse the charges.
All the while, I still don't have my item. So if you don't pay for fraud in lost cash, you're definitely paying the overhead of vendors trying to avoid being "stuck holding the bag" by throwing arbitrary verification processes in your face, introducing delays and possibly leading to you needing to make multiple phone calls to resolve problems while being left without the thing you need.
I'm not sure "vendor is so paranoid about fraud because credit cards are too consumer friendly, thus credit cards aren't payer-friendly" follows from this story more than "vendor is just acting in bad faith."
I accepted credit cards for many years until I was subjected to repeated "carding" attacks. The credit card processor blamed me for them, and was unable to tell me how to avoid such attacks. My solution was to not accept credit cards anymore.
With a credit card, you have the fallback of chargebacking. That's the benefit. You haven't gotten to that stage, although you certainly could have escalated to there by now.
Amazon, to my knowledge, will not charge you and then throw you into a "pending verification" quagmire.
But I would imagine most vendors don't want you ordering from Amazon. My point is that when I make an effort to order from another vendor when I could just order from Amazon, that vendor should introduce exactly zero friction to the process in order to be competitive.
Long live the virtues of credit card payments!
Exactly, but I come to the stellar opposite conclusion than you do in this scenario. I would much rather have used a payment mechanism with this vendor that immediately and finally transferred the funds so that I get my item more quickly without playing 3 days of phone tag. BTW, this is a large and established vendor that I trust. You have likely ordered something from them in the past.
> Are they getting a cut of every dollar I spend?
They aren't.
This is posted somewhere, but I also tested it myself. Previous landlord had stolen my security deposit. I went to my Chase branch and called several different numbers trying to reverse the final month's rent, which had been Zelle'd. After initially getting the half-truth that payments cannot be reversed, I found the right person who asked sternly if the payment was unauthorized, saying I could reverse it if it was. I had to say no. So no dice, I had to go sue the landlord instead.
Sounds to me some big banks and fintech got their lobbyists to stick it to Zelle.
Over time people will be conditioned to wait for the SMS before finishing any transaction
That is how UPI does it anyways
Theat would be a good start.
is Zelle ever its own app?
I only use Zelle from my banks' apps, and banks use TFA with text messages all the time, including from the website, calls to support, and the bank app running on the phone. I'm not saying that TFA texts to your phone are 100% two-factor-valuable from an app on your same phone, but what you're talking about would be a major set of changes to the standard security model everybody follows.
The app is for folks using a domestic United States bank that isn't connected to Zelle. During registration, the Zelle app prompts you for your bank name, your mobile phone number, and email address. Those are all checked: If your bank isn't listed as a Zelle-supporting bank, and your phone number & email aren't already linked in the Zelle system, then you can use the app.
You also need to have a Visa- or MasterCard-based debit card. You did not need to provide your PIN. Zelle uses the same rails as VenMo's Instance Bank Transfer[0] payout option, so Zelle is subject to the same limitations.
IIRC, all logins required either mobile number or email, password, and SMS-based two-factor. I think your login lasted for maybe a day. I used the app in the days before app-based two-factor was a thing, so I don't know if they still use SMS-based two-factor today.
Sending and receiving money worked as advertised. In particular, money received would show up in my bank account fairly quickly (within a few hours, IIRC).
I was not charged any fees—for deposits or withdrawals—for using the Zelle app.
[0]: https://help.venmo.com/hc/en-us/articles/115015844068-Instan...
Debit cards that fall under the Durbin amendment to the Dodd-Frank act only charge 0.05% + $0.21
So I 100% disagree that the " credit card fees actually buy you something" because all they do it push the liability on to the merchant.
Visa and Mastercard is not covering the costs of fraud
When you say it would undermine the entire point of Zelle, I don't think that's the Senate's concern. I think the Senate's concern is that banks have created a money transfer system where they eschew their legal obligation to reimburse all unauthorized payments.
Banks have no legal obligation to refund authorized payments, any more than they have obligations to refund people who took cash out of ATMs that they lost as part of a fraud.
> Banks are not repaying customers who contest “unauthorized” Zelle payments – potentially violating federal law and CFPB rules. Zelle claims to have a “zero liability policy” for cases in which a bad actor gains access to a consumer’s Zelle account and uses it to make unauthorized payments, and the Electronic Fund Transfer Act (EFTA) and the Consumer Financial Protection Bureau’s (CFPB) “Regulation E” require that the banks repay customers when funds are illegally taken out of their account without authorization. But the data provided by the banks revealed that they reimbursed consumers for only 47% of the dollar amount of cases in which customers reported unauthorized payments on Zelle in 2021 and the first half of 2022.
About 4 years ago, I got scammed when I sent a payment to a local preschool and later found out the preschool did not receive those funds. Someone was illicitly reading their emails and and also had control of a discarded email address the school no longer used and routed my Zelle payment to the bank account associated with that. The school suspected a former employee, but nothing ever came of it even though there was a police report and I also filed a complaint with the feds. A police officer called me several months later to say the case had ended up in his lap but he didn't see a way to do anything about it. Chase had multiple meetings with me, and they even knew which bank the funds had been transferred to, so it made no sense to me that there was nothing that could be done to retrieve the funds. Eventually the whole saga just ended with no resolution, and I figured if that person was so desperate they probably needed the money more than me.
Anyone have more insight into the underlying mechanics and why we can't confirm recipient identity/account as a Zelle user?
FedNow is here and live.
It's coming, but it's not really "here and live" fully yet.
[1] https://www.frbservices.org/news/press-releases/072023-fedno...
You asked: "fednow"
We're sorry but we need more details to give you a complete and accurate answer. Can you please rephrase your question?
https://www.jpmorgan.com/payments/solutions/fednow
https://www.latimes.com/business/story/2023-07-29/heres-now-...
I'm not sure if it would be you or the officer.
The banking system is supposed to know who everyone is, which is the point of the KYC regulations. Extracting that information out of them is work.
In your example it seems you did actually send it to the school. The problem was an additional party also had access to school accounts, even if old. To me that's equivalent to a former employee having an illicit copy of keys to the till and stealing cash from it in the off hours. Police would probably treat that crime similarly.
At the end of the day the police have to prioritize their resources too. Technically they could "do" things. But is it worth the cost? When it comes to petty crimes it seems mostly the answer is no, and I have to agree. Even when I had my own phone pick pocketed. It sucks but life goes on.
Really?
My bank was charging me $40/month just to have the service active to use it for occasional payments. I did not even realize that using it once "subscribed" me to the service, and fortunately was able to have months of bogus fees reversed.
Plus, it was not even actually all that convenient.
Just skim the report. It id damning.
One thing I learned a long time ago:
Never mistake a bank (or banker) for a friend, no matter how much they try to market their "friendliness". They may sometimes be necessary or even useful, but they are never your friend when it comes down to it.
I'm somewhat sympathetic with your point as applied to fraudulently induced yet properly authorized payments. But it's utterly untenable when talking about unauthorized payments from someone else gaining access to a bank web interface and things like that - the security posture of banks and the security properties they expose to customers would have to change drastically to change that. And frankly assuming a system already has to deal with the second kind, dealing with the first carries basically the same burden.
Edit: ok this one says it's a survey. But the results are that overall 58% don't have 500 in savings, but young people are actually doing better with only 39% of 18-24 year olds having less than 500. I'm not buying that.
The highest available limit I can find is $5,000 per day, and that's limited to private clients and businesses:
https://www.gobankingrates.com/banking/mobile/zelle-limits/
Common limits vary between $500 and $2,500 as you can see.
I've never heard of anyone being able to use it to send $10K in a single transaction, so it would be very helpful to know where you can do that.