The “Just the Rails” Defence: What the Zelle Fraud Case Means for Wero and Europe

Zelle case

The “Just the Rails” Defence: What the Zelle Fraud Case Means for Wero and Europe

On 20 July 2026, the Supreme Court of the State of New York, New York County  refused to dismiss the New York Attorney General’s fraud action against Early Warning Services, LLC (EWS), the operator of Zelle.

Zelle operates as a technical and organisational layer connecting participating financial institutions: the customer accounts remain with the banks, while EWS operates the network infrastructure, maintains network rules and shared services, and performs functions relevant to the routing and fraud control of Zelle payments. The payment itself is executed between the participating financial institutions.

This distinction is important for the case. The Attorney General is therefore not suing the institution that held or transferred the victim’s money, but the entity operating the network layer above the individual banks and alleges that failures at that level contributed to systemic fraud.

The ruling allows an important theory to proceed: that a payment-network operator like EWS may have to answer for its own design, fraud controls, enforcement of network rules and representations about safety, rather than being treated merely as neutral infrastructure.

The oversight run-up. The case followed years of U.S. congressional scrutiny of fraud on Zelle. Senator Elizabeth Warren’s October 2022 report, Facilitating Fraud, found that four banks had recorded more than 190,000 scam cases involving over USD 213 million in 2021 and the first half of 2022. Among the three banks providing complete reimbursement data, consumers were reimbursed in only 9.6% of scam cases. Subsequent congressional scrutiny continued into 2025. These are oversight findings, not judicial findings, and EWS disputes the broader portrayal of fraud on Zelle. Nevertheless, they form part of the factual and political background to the New York Attorney General’s action.

What New York is actually alleging

EWS is owned by Bank of America, Capital One, JPMorgan Chase, PNC, Truist, Wells Fargo and U.S. Bank.

The complaint pleads one cause of action: repeated or persistent fraud under New York Executive Law § 63(12). 

The allegations concern EWS’s own conduct. The Attorney General alleges that EWS knew that weaknesses in Zelle’s design and anti-fraud framework facilitated fraud; identified additional safeguards as early as 2019 but delayed full implementation until 2023; inadequately enforced its rules against participating banks; and nevertheless marketed Zelle as safe and secure.

The complaint characterises this as creating an “atmosphere conducive to fraud.”

The complaint refers to more than USD 1 billion in reported losses across the Zelle network between 2017 and 2023. It does not allege USD 1 billion of losses in New York alone. For New York users, it alleges losses in the “tens of millions, if not hundreds of millions” of dollars.

The July 2026 decision therefore does not establish a general duty of payment-network operators towards users. It means that, at the pleading stage, allegations concerning the operator’s own knowledge, design decisions, controls and marketing are sufficient to proceed to discovery.

Why the Zelle case is of interest for Europe

The case is particularly timely because Europe is currently building, through Wero, a payment system with many of the same structural characteristics as Zelle — before questions of fraud allocation and scheme-level accountability have been fully tested in practice.

Wero is operated by the European Payments Initiative (EPI), currently backed by 18 European banks and financial-services companies. It launched in Germany on 2 July 2024, in France on 30 September 2024, subsequently expanded into Belgium and entered Luxembourg in September 2026 through the migration from Payconiq. Migration of the Dutch iDEAL system to Wero is underway and is currently intended to be completed by 31 December 2027. Wero now reports approximately 59 million users. 

“Like Zelle, Wero is a bank-backed account-to-account payment system built on customers’ existing bank accounts: the scheme does not replace the account-holding banks, while important functions are organised at scheme level. The National Bank of Belgium describes EPI as operating a four-party account-to-account payment scheme layered over the European Payments Council’s SCT Inst scheme. Its infrastructure includes the payment scheme, the Wero front end and a shared technical platform providing functions including fraud prevention, transaction processing and back-office services.

This is precisely why the Zelle case matters for Europe. Where fraud-prevention functions, scheme rules and technical controls are exercised above the level of the individual customer’s bank, potential responsibility should follow function, knowledge and control.

The PSR improves fraud prevention. It still does not solve APP fraud.

 The April 2026 PSR compromise materially strengthens fraud prevention, but it still does not create a general reimbursement right for victims who were fraudulently induced to authorise a payment.

Article 59 PSR provides reimbursement for a narrow category of impersonation fraud, essentially where a fraudster pretends to be the consumer’s own PSP through communication channels attributed to that PSP. It does not generally cover investment scams, romance scams, pig-butchering schemes or fake brokers — the core categories of APP fraud.

Verification of Payee (VoP), already applicable to euro credit transfers under Regulation (EU) 2024/886, and the liability provisions in Article 57 PSR can prevent certain misdirected payments. But VoP confirms whether account identifiers correspond; it does not establish whether the beneficiary itself is legitimate. A correctly named mule account, shell company or fraud-linked beneficiary can pass VoP. EFRI examined these limitations in detail in Payee Verification in EU Payments: Useful Safeguard, Limited Solution.

More significant are Articles 65, 69 and 83 PSR, which strengthen pre-execution transaction monitoring, intervention duties and liability on both the payer and receiving side. Where objectively justified fraud indicators exist, PSPs may be required to suspend or withhold payments; failures can trigger reimbursement consequences and the new rules partly reverse the burden of proof.

Notably, Article 58 of the April 2026 PSR compromise text (Council doc. ST 8221/26) already recognises limited liability of technical service providers and operators of payment schemes for failures to provide services necessary to support strong customer authentication.

These are meaningful improvements, but they remain essentially breach-based rules. If PSPs establish that the required monitoring was performed and that the statutory intervention threshold was not reached, the fact that the consumer was deceived into authorising the payment does not itself create a general reimbursement claim.

EFRI has analysed this problem in detail in Enhanced Transaction Monitoring under the PSR: Old Wine in New Bottles? and EU PSR/PSD3: Empty APP Fraud Protections for Victims. The central problem remains unchanged: the evidence needed to establish a breach is largely controlled by the financial institutions against which the victim must bring the claim.

EFRI therefore continues to advocate a victim-first shared-liability model: prompt reimbursement to the victim, followed by recourse between the professional actors according to which entity controlled and breached the relevant safeguard. The detailed proposal is set out in EFRI’s Shared Liability Framework Proposal for the PSR.

What the Zelle litigation should make Europe examine

The New York case provides Europe with no ready-made cause of action. Executive Law § 63(12) has no direct EU equivalent, and the proceeding is being brought by a state Attorney General rather than an individual victim.

Its significance is structural and evidentiary.

For Wero or another European scheme, the decisive question should not be whether “the network” is generally liable. It should be:

Which entity controlled the safeguard that failed?

That requires evidence concerning:

  • scheme rules and enforcement powers;
  • common fraud-prevention infrastructure;
  • fraud and complaint data available at scheme level;
  • identification of repeat beneficiary accounts or institutions;
  • measures considered but not implemented;
  • information exchanged between participating PSPs; and
  • representations made to consumers about safety.

The Zelle complaint is particularly relevant because it alleges that EWS had identified measures capable of reducing fraud years before fully implementing them and that fraud subsequently declined after the complete safeguards were introduced.

Those allegations remain to be proved. But they illustrate the evidentiary chain that would also matter in Europe:

knowledge — control — failure — causation — loss.

Assessment

New York has not held EWS liable. It has refused to end the case at the pleading stage and allowed the Attorney General’s allegations to proceed to discovery.

With the PSR Europe is moving in the right direction, but — in EFRI’s view — too slowly and too narrowly. Liability should follow the actor or actors that controlled the failed safeguard, had legally relevant knowledge or warning signals, and had the ability to prevent or interrupt the loss.

That may be the payer’s bank, the beneficiary PSP, a payment institution or another intermediary. 

EFRI’s work on Payvision/ING and on Payvision’s cooperation with the Barak and Lenhoff fraud networks illustrates why the liability analysis must follow the payment chain rather than stop at the consumer-facing bank.

Where fraud-relevant rules, data and infrastructure are controlled at scheme level, the network operator should not escape scrutiny merely because it does not hold the victim’s account.

The most important part of the Zelle proceedings may therefore still lie ahead: discovery may reveal what EWS knew about systemic fraud, which safeguards it could implement, and how it responded. For Europe, those facts may ultimately prove more important than New York law itself.

More about this topic.