CU Says Fraudsters Bypassed Fiserv Safeguards, Unlocked Stolen Cards
By CU Today Staff —
TAMPA, Fla.—FiCare Federal Credit Union is seeking an emergency federal court order requiring Fiserv to turn over information about what the credit union alleges is an ongoing fraud scheme in which criminals impersonated members and convinced Fiserv call-center employees to remove fraud restrictions from stolen debit and credit cards.
FiCare filed the emergency motion Sept. 23 in U.S. District Court for the Middle District of Florida as part of its pending lawsuit against Fiserv. The credit union alleges fraudsters have been able to bypass verification procedures at Fiserv's cardholder services call center, resulting in at least 18 fraudulent transactions affecting FiCare in August. FiCare also alleges other financial institutions using Fiserv have reported the same type of exploitation.
According to information supplied to CUToday by FiCare's attorneys, at least five other credit unions have been affected by similar fraud. The court filing says callers posing as cardholders answered Fiserv's verification questions and persuaded agents to remove fraud restrictions and reactivate stolen cards. FiCare alleges the call center relies on knowledge-based authentication, including Social Security numbers and information printed on the cards, rather than multifactor authentication such as requiring a member to approve a prompt through an app.
FiCare contends that approach is vulnerable because a thief possessing a stolen card already has some of the information needed to answer the questions, while Social Security numbers can be available to criminals through previous data breaches. The credit union also alleges fraudsters have used "alert bombing," flooding consumers with text messages so legitimate fraud alerts can be overlooked. FiCare says reports of similar incidents at other institutions could help establish when Fiserv became aware of the alleged vulnerability and what it did in response.
“We are proud to represent the coalition of credit unions taking Fiserv to court. Credit unions deserve answers and accountability when a vendor’s safeguards fail,” Charles Nerko, managing partner of NERKO PLLC, which represents FiCare with Hecht Partners LLP and Stearns Weaver, told CUToday.info.
FiCare served Fiserv with 19 discovery requests Sept. 17 seeking, among other things, call center scripts and training materials; call recordings, logs and authentication results; assessments of weaknesses in verification procedures; complaints and incident reports involving the alleged exploit; and information about fraud alerts and alert-flooding attacks. FiCare alleges Fiserv declined to expedite its responses or schedule a discussion with the credit union's attorneys.
The credit union is asking the court to require Fiserv to produce responsive, nonprivileged materials within seven days of an order and wants a ruling by Sept. 29. FiCare says it needs the information to determine whether to seek an injunction and what additional safeguards might be necessary to stop further fraud.
The call center allegations represent a new element in FiCare's broader lawsuit against Fiserv. The underlying case primarily alleges cybersecurity failures at Fiserv allowed hackers to take over online-banking accounts in 2024 and 2025. FiCare said the more recent attacks involve a different Fiserv service and a newly developed method of fraud.
Originally reported by CU Today.