You Are the Entry Point

Fraud doesn't originate inside your bank. It enters through your business -- through email, credentials, and one employee who clicked the wrong thing. Here's what that means for your liability.

A client of mine -- a mid-market wholesaler, Southern California, been in business for over twenty years -- sent nearly half a million dollars to a vendor they'd worked with for years. Except it wasn't the vendor. It was someone who had spent three weeks watching their email, learned their vendor's billing cadence, spoofed the domain close enough to pass a quick scan, and sent an invoice at exactly the right moment.

The bank processed a legitimate payment. The vendor never received it. The wholesaler absorbed the loss in full. Under U.S. law, that's an authorized push payment -- the business instructed the transfer, so Regulation E doesn't apply. The bank owed them nothing.

The fraud didn't originate inside the bank. It originated inside the wholesaler's email.

This matters because the entire architecture of financial fraud defense is built around protecting the bank's perimeter. Transaction monitoring, behavioral anomaly detection, real-time payment screening -- these are sophisticated systems, and the major institutions have spent accordingly on them. What they don't protect is the 50-person law firm or the three-physician practice that sits at the other end of the wire.

A second incident. A small professional services firm, credentials stolen via an infostealer -- a piece of malware that exfiltrated saved passwords from a browser session. The attacker used those credentials to execute a SIM swap, which routed the firm's phone number to a device they controlled. That gave them the MFA codes. They cleared the bank account overnight.

In this case, the bank bore the loss under Regulation E because the transfer was unauthorized -- the firm didn't instruct it. Same attack vector (an undefended SMB endpoint), different legal outcome.

Two incidents. Same entry point. Different liability result depending entirely on how the attacker chose to complete the transaction.

The FBI's Internet Crime Complaint Center reported $16.6 billion in losses across all fraud categories in 2024, with Business Email Compromise alone accounting for $2.77 billion. Those aren't losses the financial system failed to intercept at the bank. They're losses that entered the financial system through endpoints exactly like your office -- through email accounts, through credential databases, through employees who didn't recognize a spoofed domain. My client's loss alone was nearly half a million dollars. One invoice. Three weeks of reconnaissance. One click.

Here's what the financial services industry is starting to understand, slowly: they have extended their revenue surface to the SMB endpoint. Every embedded payment product, every business banking API, every digital treasury tool -- these reach into your operation. Your security posture is now, whether you recognize it or not, a component of their fraud risk model.

What the industry hasn't done yet is extend the defense the same distance.

That's not an accusation. It's a structural gap. The technology to close it exists -- AI-based anomalous payment detection, SIM swap APIs that flag hijacked numbers before a transfer completes, email security tools that catch BEC attempts before the invoice lands. The gap isn't capability. It's perimeter definition.

If your business processes payments, receives wires, manages client funds, or touches financial infrastructure in any form -- you are fintech infrastructure. You are the last mile. And right now, you're the undefended one.

The question isn't whether fraud will try your door. The FBI data answers that. The question is whether your door is the kind that makes them move on to an easier target.


John (Chris) Rondthaler is the founder of IT CloudLink, an IT and cybersecurity consultancy serving healthcare practices, law firms, and compliance-driven SMBs in the Los Angeles area. He has worked two real financial fraud incidents firsthand. His byline "The Fraud Liability Debate Is Asking the Wrong Question" was published in Fintech Bloom in May 2026.