- Key insight: FiCare alleges the people holding the stolen cards are having controls meant to contain compromised cards removed.
- What's at stake: Fiserv serves roughly 10,000 financial institutions, including more than 3,330 credit unions. The motion does not say how many of them use the call center at issue.
- Forward look: FiCare wants a ruling by Sept. 29. Absent an order, Fiserv's responses are not due until Oct. 19.
Overview bullets generated by AI with editorial review.
A Florida credit union alleged in court this week that fraudsters have been calling the service line Fiserv uses to mitigate card fraud, answering its verification questions and talking agents into turning stolen cards back on.
FiCare Federal Credit Union made the allegation in an
FiCare has been suing Fiserv since January over attacks that took over members' online banking accounts in 2024 and 2025. The most recent motion asks the court to, on an expedited basis, make Fiserv answer questions posed during that case.
No court has ruled on the allegations raised this week, and Fiserv has not answered them in court.
Fiserv did not respond to a request for comment by deadline.
Responding to an earlier credit union lawsuit against Fiserv over alleged security lapses, a company spokesperson
Fiserv serves roughly 10,000 financial institutions, including more than 3,330 credit unions, according to
What FiCare alleges against Fiserv
According to FiCare's motion this week, Fiserv blocks a card when it suspects fraud, and the number listed on the back of those cards is Fiserv's cardholder-services call center; a customer can call that number to lift a block on debit and credit cards.
The credit union says the people using the stolen cards have also been calling the center, and the center workers have been unlocking cards for them.
At least 18 fraudulent transactions hit FiCare cardholders in August after fraudsters called Fiserv's call center and convinced workers to unlock the cards, according to a sworn declaration from Ashley Magill, the credit union's senior vice president for lending and operations.
The declaration does not put a dollar figure on the losses or say who absorbed them.
FiCare and five other institutions have reported this problem to Fiserv, according to Magill's declaration. The motion does not say how many of Fiserv's clients use the call center at issue.
FiCare sent the company those questions and demands for records on Sept. 17, in the pretrial fact-gathering process known as discovery.
The credit union asked Fiserv to admit that its call center requires neither a one-time passcode nor any other form of multifactor authentication before it lifts a fraud block.
Fiserv has not answered the requests, and its responses are not due until Oct. 19. It declined to respond sooner when FiCare asked, according to the motion.
FiCare filed its emergency motion this week because, the credit union argued, the fraud continues in the meantime.
FiCare asked the court to rule by Sept. 29 on whether to shorten the response deadline.
How the callers got through
As far as FiCare knows, Fiserv's call center does not use multifactor authentication, according to the credit union's motion.
Fiserv allegedly verifies callers with knowledge-based questions instead, including a member's Social Security number and information printed on the face of the card, such as the expiration date and the security code.
Anyone holding a stolen card has some of those answers, and Social Security numbers are no longer secret either, the credit union argued.
The motion cites
Five other credit unions say it happened to them
Magill's declaration names five other Fiserv clients that reported the same problem and said they had told Fiserv about it: Choice One Community Federal Credit Union, Galaxy Federal Credit Union, MERCO Credit Union, Somerset Federal Credit Union and Torrington Municipal and Teachers Federal Credit Union.
None of the credit unions responded to requests for comment.
According to Magill, MERCO reported that Fiserv's call center was not sending PINs to verify callers. Magill also said that Choice One asked Fiserv to put multifactor authentication in place in its call center.
Neither the credit unions nor Fiserv has confirmed any of it. Magill said she learned of those incidents through an email listserv of which she is a member.
A Fiserv employee answered those emails on Sept. 16 and wrote that institutions raising these problems "help all of us better understand emerging threats and identify opportunities to further strengthen fraud prevention strategies," according to the declaration.
Read more:
What comes next for banks in a post-CLARITY Congress Warsh: Rising bond yields a sign of strong U.S. economy Borrowing from Federal Home Loan banks jumped 20% in 2Q State bank examiners get a playbook for inspecting AI
Regulators warned about call centers in 2021
Federal banking regulators, through the Federal Financial Institutions Examination Council, gave call centers their own section of a 2021
The section warns that attackers use social engineering to talk call center staff into resetting credentials. Reliable methods of verifying a customer's identity "generally do not depend solely on knowledge-based questions," the guidance said.
The guidance document's appendix lists suggested alternatives: a one-time passcode sent to a device the institution already has on file, an authenticator app, voice recognition (
The council addressed the guidance to credit unions and banks rather than to their vendors. Regulators in recent years have drawn a hard line that financial institutions (such as FiCare)
FiCare's motion this week does not lean on the guidance document. It instead cites the security promises in its contract with Fiserv.
Fiserv has also published a warning about authenticating customers with knowledge-based challenges.
If a customer calls a bank to reset a password and gets asked for a mother's maiden name or the last four digits of a Social Security number, "that's not enough," said Kannan Srinivasan, then Fiserv's vice president of risk strategy and analytics, in an article on the company's website.
"Fraudsters already have that information," he said in the article.
"Criminals often use call centers in their account takeover attempts," the article said, and good practice covers "authenticating users to remove transactions or even suspend accounts."
Fiserv appears to have since
FiCare's motion quotes the page and cites that archived copy. Fiserv took the page offline after it was cited against the company in earlier data-security litigation, according to the motion.
What Fiserv has said, and what happens next
Several other credit unions have
The credit union "was aware of any alleged potential security risk," signed with Fiserv anyway and "chose not to implement additional security features," Fiserv said in that filing.
That response addressed online banking, not the call center, and Fiserv filed it before the allegations this week surfaced.
Fiserv's most recent
Public companies disclose the legal proceedings they treat as material in each quarterly report. The absence of the credit union cases suggests Fiserv does not see the cases as material.











