It’s a crime that usually happens quietly.
Thieves use stolen information to open a brokerage account in your name. Soon after, your savings are siphoned from your real brokerage account into the fraudulent one — then the thieves vanish with your money.
Regulators have warned brokerages in recent years that this type of crime has been on the rise, but they haven’t required financial firms to adopt the strongest preventive measures, only suggesting that companies provide them. That has left many brokerage customers potentially vulnerable, depending on where they do business and what safeguards are offered.
Some large institutions, including Citi, Charles Schwab and Bank of America’s Merrill Edge, do not allow customers to lock their brokerage accounts to protect themselves from these types of unauthorized transfers.
And some, including Wells Fargo and Citi, do not alert customers when their money is redirected into another account, according to a recent analysis of a dozen major brokerage firms by Senators Ron Wyden and Elizabeth Warren, ranking Democrats on the Finance and Banking Committees. The lawmakers are urging regulators to require stricter measures.
The review followed a New York Times article from last fall that shed light on the fraud, which is named after the Automated Customer Account Transfer Service, or ACATS, the behind-the-scenes plumbing system that financial institutions use to move customers’ assets like stocks and bonds from one bank or brokerage to another.
“Bad actors are increasingly exploiting structural weaknesses in the ACATS system to illicitly drain consumers’ brokerage accounts, including retirement funds,” the senators wrote in a letter to Robert W. Cook, chief executive of FINRA, the financial industry’s self-regulatory organization. “A recent review of major brokerage firms conducted by our offices reveals a deeply concerning lack of standardized, consumer-controlled protections across the industry.”
The lawmakers called on FINRA to immediately create rules that would require financial firms to notify customers of any outgoing transfers, and to let customers lock their accounts until firms came up with a process that would require customers to approve such transfer requests.
In October, The Times reported on a case in which a Vanguard customer discovered that holdings in his wife’s Roth individual retirement account had vanished.
An online criminal had opened two accounts in her name at Merrill Edge, another brokerage platform, and requested the transfer from Vanguard. The couple was lucky. The fraudster hadn’t yet run off with the money, so Merrill was able to freeze the account.
The ease with which fraudsters can open accounts — often using stolen data or a combination of stolen and false information, like an email address or a mobile phone number — makes it easier to perpetrate the heist. But to pull it off, criminals need to know the other account’s details.
Fidelity and Vanguard offer self-directed features that let customers block these transfers.
According to the senators’ letter, JPMorgan Chase, Robinhood, Webull and Wells Fargo all said they offered similar account locks, but they can be enabled or disabled only by customer service. E-Trade and Morgan Stanley Wealth Management recently added that capability after the inquiry.
Robinhood told lawmakers that it would install a user-managed locking feature by the end of March, the letter said. Webull said on Wednesday that it had recently enabled the feature ahead of its agreed deadline, and Interactive Brokers confirmed it would add a customer-managed ACATS-locking feature by the end of September.
Once a brokerage customer (or, in this case, an impostor) requests a transfer through the institution receiving the money, the firm that is holding the funds has a day to validate that the assets are available for transfer and that the customer’s identifying information is accurate. Within three days, it must make the transfer.
The legislators have also requested that FINRA strengthen the ACATS transfer process by requiring the account holder — from where the money is being withdrawn — to confirm the transaction in an authenticated session on the outgoing broker’s website or mobile app. Many firms at least alert customers that a transfer has been requested.
Additionally, the senators urged the regulator to require brokerages to secure customer accounts with a newer technology called passkeys, which they said were stronger than traditional multifactor authentication, such as verification codes sent by email or text that fraudsters can easily bypass.
FINRA declined to comment on the letter, but said it was among the first regulators to identify this misconduct and alert its member firms. “We are actively engaged with the wider securities industry,” FINRA said in a statement, “to determine what further actions are necessary to protect investors.”
The post Several Big Brokerages Leave Customer Accounts Open to Theft, Senators Say appeared first on New York Times.




