FiCare FCU Files Emergency Motion Seeking Records from Fiserv; Alleges At Least 18 Fraudulent Card Transactions During August

TAMPA, Fla. — FiCare Federal Credit Union is asking a federal judge to order Fiserv to quickly produce records about alleged fraud through its cardholder services call center, saying criminals posing as members persuaded agents to remove restrictions from stolen debit and credit cards.

At least 18 fraudulent transactions affected FiCare in August after callers got fraud restrictions lifted, according to an emergency motion filed Sept. 23 in U.S. District Court for the Middle District of Florida and reviewed by the CU Daily. A statement provided with the filing says at least five other credit unions have been affected by the same type of fraud. The motion itself says other financial institutions using Fiserv have reported similar incidents but does not give a number.

The $77.4-million FiCare, which is one of a half-dozen credit unions that have filed suit against Fiserv over alleged security shortcomings, alleges that Fiserv’s call center relies on questions that can be answered with a caller’s Social Security number and information printed on a card. A thief holding a stolen card would already have some of the information used to verify the caller’s identity, the credit union argues.

The motion says FiCare understands that the call center does not use multifactor authentication, such as asking a cardholder to approve a prompt in an app. It also alleges that fraudsters have flooded consumers with text messages so Fiserv fraud alerts go unnoticed. Those descriptions of the call center’s practices and the alleged attacks are FiCare’s assertions; the court has not made findings on them.

Records Sought Before Possible Injunction

FiCare served 19 discovery requests on Fiserv on Sept. 17: four written questions, seven requests for documents and eight requests for admission. They cover the call center’s authentication requirements, calls in which restrictions were removed from FiCare cards, fraud alert practices and Fiserv’s knowledge of similar incidents elsewhere.

The credit union is seeking call recordings, logs, agent notes, authentication results, scripts and training materials. It also wants assessments of possible weaknesses, complaints and incident reports, and records showing whether Fiserv changed its procedures after learning of the alleged fraud. The written questions and document requests cover the period beginning June 1.

FiCare says those records would help it determine how unauthorized callers passed verification, when Fiserv learned of the problem and what steps it has taken in response. The credit union argues that only Fiserv holds much of that information.

Motions Asks Judge to Require Response

The motion asks the judge to require Fiserv to respond and complete production of responsive, nonprivileged materials within seven days of an order. FiCare also seeks a shortened briefing schedule and a ruling by Sept. 29. Without an agreement or court order accelerating the process, responses are due Oct. 19, according to the filing.

FiCare says it needs the information to decide whether to seek an injunction and, if so, what protections to ask the court to require. The emergency motion seeks faster discovery; it does not ask the court to issue an injunction now. FiCare acknowledges that the requested records could also show that corrective measures have made an injunction unnecessary.

Charles Nerko

“We are proud to represent the coalition of credit unions taking Fiserv to court. Credit unions deserve answers and accountability when a vendor’s safeguards fail,” said Charles Nerko, managing partner of NERKO PLLC. His firm represents FiCare with Hecht Partners LLP and Stearns Weaver.

FiCare cites potential harm to members

In arguing that the request is urgent, FiCare says an unauthorized debit card transaction can immediately drain money from a member’s account. The filing says members rely on those funds for critical payments, including medical procedures and court-ordered fines, and argues that an inability to make such payments could have serious consequences.

Those are examples of potential harm cited by the credit union. The motion does not say that an August transaction caused a medical procedure to be delayed or a member to miss a court-ordered payment. FiCare also argues that fraud against its members could damage its reputation and goodwill.

FiCare’s pending lawsuit principally concerns separate alleged cybersecurity failures at Fiserv that the credit union says enabled hackers to take over online banking accounts in 2024 and 2025. The call center incidents involve a different Fiserv platform and began after FiCare filed its second amended complaint July 2. FiCare argues that the newer incidents are relevant because its lawsuit also concerns Fiserv’s contractual obligations to safeguard the credit union’s information.

Other Cases Cited

The motion cites two other data security cases brought against Fiserv by financial institutions — one involving CenCap Federal Credit Union in Connecticut and another involving Self-Help Credit Union in North Carolina — in which courts ordered expedited discovery. Those orders addressed the timing of evidence production in separate cases; they do not establish FiCare’s allegations.

FiCare says its lawyers asked Fiserv on Sept. 17 and 18 to discuss expedited responses and security measures that could prevent further fraud. According to the motion, Fiserv declined to agree to faster responses and did not provide a time to meet. The filing presents FiCare’s account of those exchanges and allegations. The court has not ruled on the emergency request.

The CU Daily has contacted Fiserv for comment.

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.