Zelle finally caves after years of refusing to refund scam victims
arstechnica.com
arstechnica.com
Their defense is that they only process two million fraudulent transactions a year?
This is the same reason why a PSP will always give you better fraud protection than rolling your own, they look at so much more data than you ever will that they will be able to better tell friend from foe. Fewer false positives and fewer false negatives. Still too much, but the theory is that in order to be able to detect fraud you will have to have some fraud!
That fails to argue that having any fraud is beneficial; if you have no fraud, there is no value in being able to detect fraud.
That fraud by itself is not beneficial goes without saying.
Just like any classification system a fraud control system has false positives, false negatives, true positives and true negatives. In an ideal version of such a system you have no false positives and false negatives. But that idealized version of that system (the one that perfectly classifies fraudulent transactions and non-fraudulent transactions) is static. It can't adapt to cases of fraud that it hasn't seen yet. Eventually a fraudulent transaction gets through.
And that transaction if not detected timely but after the fact (so now there is some detected fraud, in the interval prior to its detection it was undetected fraud) will result in an update to the fraud detection system (probably it will need more than one example to be able to generalize from). Now the perfect system may start to generate false positives or false negatives on other transactions.
Run the 'perfect' system for long enough and it will be like every other fraud control system, a certain fraction of fraud will get through and a certain fraction of good transactions will be marked as fraud. How low you can do this sustainably is an open question but there is a lot of money to be made by squeezing out the last little bits and so a lot of money is poured into these systems. The nasty bit is that many of the players in this space attempt to off-load their residual risk on others (such as merchants or consumers) and that gives them less of an incentive to do the best job they can.
So that's why all of this is relevant. I hope I'm able to explain it clearly enough.
For example, my partner posted an item for sale in FB marketplace.
The buyer said she couldnt pick up item, but her brother would. She could pay via Zelle, all she needed was an email & phone # . None of that seemed weird, so my partner agreed.
The buyer then said she sent a Zelle payment. My partner got an email from "Zelle Pay" saying money was pending due to my partners account not being a business account.
Luckily, we know zelle and didnt fall for it. The sender was a Gmail account.
My partner must have been talking with a bot.
5 min later, another buyer showed up. She also could not pick up but her brother would. She was to pay via zelle.
Be careful with FB marketplace. It's a mess now.
I'm not sure there's a particular reason to think it's a bot or AI is there? It could just be a script and a call-centre type operation.
In my experience, in a FB marketplace transaction where the buyer picks up the item, the buyer only pays after personally inspecting the item and (often) haggling a bit.
Prepaying using Zelle for an unseen item is very weird.
I did this a few years ago to sell a PS5 in the outskirts of Metro Detroit.
We were in communication with the possible buyers and saw them turn into the lot. As soon as we asked them to meet us inside they got cagey, hung up, and just left.
Now? I think you've missed that by a bit which is understated in the same manner your "now" is.
In contrast, in Craigslist-land I'm interacting with just a phone number or an email.
Anyways, I sold a ton of stuff on FB marketplace before we moved out of our old place, only allowed cash / venmo payments and they had to come pick it up
It's like the people who used to abuse the friends/family policy on paypal to cut out paypals fees and then were surprised when they had no buyer/seller protection, when they had to click through several messages specifically telling them that.
It's tough to do fraud at scale when you have to show up to a police station, give them all your info, and leave a detailed paper trail.
Having a police report is easy if you are in America.
All it takes is a phone call and a story. A police report is super simple to get
https://www.oaklandca.gov/services/report-a-crime-online
https://www.sanfranciscopolice.org/get-service/police-report...
There's apparently even a SaaS for them called Coplogic.
If you provided them an audio (ideally with visuals) recording of the interaction and the identity of the thief, of course they can help. Otherwise, it's up to the courts to figure out in most cases.
As to the point of filing, as the sibling response pointed out, it's more for an official record to be on the books for insurance to act on. They'll then use it in their investigations/civil proceedings.
Sure, but that's like saying there's no preparation for an earthquake being done on houses in London.
If you can show an earthquake is likely to happen, sure people will prepare. Otherwise, why bother? Let the Court/insurance sort it out.
A money transfer system that prohibits reversals doesn't reflect what money needs to do.
Yeah you're SOL if you give cash to someone whose identity you don't know, but that's hard to do unintentionally with cash. Whereas Zelle will shield scammers' identities so your recovery options begin and end with Zelle.
That obviously can't be the entire truth, though – unless there's some mechanism to arbitrate claims, it would effectively make Zelle unusable for many of its current uses.
The obvious conclusion is they'll have to start charging everyone transfer fees to pay for the people that fall for stupid scams.
I think you're being much more optimistic about what banks will actually be doing than me. I hope it's not, but based on the article, it might just be "we'll try to claw back your transfer with no questions asked; if the money is still in the recipient's account, you get it back; otherwise you get nothing".
From the article:
> Zelle simply "implemented a mechanism that allows banks to claw back funds from the recipient's account and return them to the sender."
Does this mean I can get that money back? Who do I talk to/where do I go to do so? My bank? Zelle itself?
Works for businesses or neighbors, sure. But random scammer online--no way.
USA GDP nominal: 26.950T
Canada GDP nominal: 2.118T
All figures USD, 2023 estimates.
Another part of the reason is how "legacy" phone carriers operate... the US up until a year or two ago allowed pretty much everyone and their dog to spoof phone numbers using VoIP, which made life for scammers incredibly easy as they didn't need much of a local presence beyond some money mules. Here in Germany, it's way harder to get access to line trunks that allow caller ID spoofing, and on top of that we have strict regulations on what banks need to do to to verify customer identities so it's harder for scammers to open up bank accounts, and so our scammers have to rely on actual people picking up money from the scam victims (e.g. the "fake policeman" scam).
> Zelle simply "implemented a mechanism that allows banks to claw back funds from the recipient's account and return them to the sender."
I'm curious to see what the prerequisites for such a clawback are, both on the side of the payer (a police report? a signed statement? a click in an app?) and the payee (what happens if the money isn't in their account anymore?).
I wonder if Zelle could be feeling competition from fednow?
If you’re selling items online, meet in person, pay cash. Simple as that.
At least codify what the banks agreed to implement -- otherwise they will just go back on this when it costs them too much money and they think no one is looking.
> Zelle simply "implemented a mechanism that allows banks to claw back funds from the recipient's account and return them to the sender."
I highly doubt that that's true, though. For one thing, this would trivially fail in case the recipient account has already cashed out the funds.
Being banks (not that you can't otherwise, but still) it's also entirely possible for them to overdraw your account to do so.
And then if you don't care about that, close your account and report it to Chex Systems, which will make opening any bank or CU account quite difficult.
(1) Scammer sends check / something like that, showing a larger than expected deposit
(2) Check is cached by victim
(3) Victim is asked to reimburse the difference using Zelle or other "irreversible" method (best being Bitcoin, I guess, but Zelle also works apprently..)
(4) Check bounces
(5) Victim looses the money send by Zelle
Dispute arbitration does cost money, though (especially if banks would step in to make customers whole in case fraudsters are already out of their reach), which is why we're in this mess in the first place.
Other than that, Zelle has one huge advantage over the competition: The money is available in the recipient's bank account immediately. Venmo, Cash App etc. charge quite a bit of money for instant payouts.
Well, here's the problem: Zelle was never intended for this use case (i.e. B2C payments).
I believe they are planning to move into that space, but right now it's just the completely wrong tool for the task, and I've never seen it used for that myself (except for a few otherwise cash-only restaurants, food trucks etc).
Imagine having a concrete business and you bought Miatas instead of concrete mixers. Clearly Miatas are useless vehicles which serve no purpose seeing as how they can't keep a few tons of mixed concrete moving for an hour as it gets delivered.
Having a business set up to use Zelle, well, you're using the wrong tool for the job. We don't need every tool to be able to do every use case. Not every car needs to be a cement mixer.