IT CloudLink Featured in Fintech Bloom: The Fraud Liability Debate Is Asking the Wrong Question

A byline by IT CloudLink founder John (Chris) Rondthaler was published in Fintech Bloom on May 12, 2026 -- arguing that the financial industry's fraud debate is focused on the wrong question.

A byline I wrote was published in Fintech Bloom on May 12, 2026: "The Fraud Liability Debate Is Asking the Wrong Question."

The piece makes a single argument: the financial industry is having an important conversation about who pays when fraud happens. It's the wrong conversation.

Fraud doesn't enter the financial system through the bank. It enters through the businesses connected to it -- the law firm, the medical practice, the mid-market wholesaler. The bank's fraud detection ends at the bank's perimeter. Your office is outside it.

I've worked two of these incidents firsthand. In one, the SMB absorbed the entire loss. In the other, the bank paid. The fraud came through the same undefended endpoint both times. Same attack vector, different legal outcome -- determined entirely by how the attacker chose to complete the transaction.

The piece draws on FBI IC3 data ($2.77 billion in Business Email Compromise losses in 2024), the UK's authorized push payment reimbursement experiment (losses rose 12% in H1 2025 despite mandatory bank reimbursement), and the AFP's 2026 payments fraud survey (74% of organizations experienced BEC in the prior year) to make the case that moving liability doesn't move the attack surface.

The fix isn't liability reform. It's extending the defense perimeter to the endpoint where fraud actually enters -- your email environment, your credentials, your staff.

Read the full byline on Fintech Bloom.