Michigan firm sues bank over theft of $560,000

Experi-Metal says Comerica Bank's online security practices resulted in theft

A Michigan-based manufacturing firm is suing its bank after online crooks depleted the company's account by $560,000 via a series of unauthorized wire transfers last year.

In a lawsuit filed in December, Experi-Metal Inc. (EMI) of Sterling Heights blamed the loss on its financial institution Comerica Bank's security practices, and on the bank's alleged failure to heed signs that should have alerted it to the fraudulent activity.

The complaint, filed in Macomb County Circuit Court, demanded that Comerica reimburse EMI for the loss, along with interest, attorney's fees and any other damages the court saw fit to impose. News of the lawsuit was reported by Bankinfosecurity.com earlier this week.

The lawsuit is one of several that have been filed over the past few months involving banks and customers victimized by online theft. In this case, the theft occurred after an employee at EMI supplied the crooks with the company's online banking credentials in response to a phishing e-mail that purported to come from the bank.

The credentials were then used to initiate wire transfers totaling $560,000 from EMI's account to numerous accounts in Russia, Estonia, Scotland, Finland, China, and the U.S. Once deposited, the funds were quickly withdrawn.

In its lawsuit, EMI alleged that the phishing scam had worked only because of Comerica's routine practice of sending e-mails to customers asking them to click on a link to update their security information.

EMI said that between 2000 and 2008, Comerica had used digital certificates to authenticate users to its online banking system. During this time, the bank would send e-mails asking customers to click on a link and submit specific information in order to renew their digital certificates, EMI claimed in its suit.

The complaint also alleged that the token-based authentication system that replaced Comerica's digital certificates was not adequate enough to protect against the kind of attack that resulted in the theft.

"Comerica knew or should have known that the technology of the two-factor authentication procedure which it instituted in 2008 was known to be lacking in any reasonable fortification against 'man in the middle' phishing attacks," EMI said.

"[It was in] reality a downgrade as a security measure from the digital certificate technology that was previously used by Comerica," the company said.

The complaint also faulted Comerica for ignoring signs of fraudulent activity on EMI's account. The company said that it had initiated just two wire transfers in total before the unauthorized withdrawals began.

Then, over a three-hour period, 47 wire transfers and 12 transfer-of-fund requests were initiated from EMI's account. The bank did not check with EMI about the unusual activity for several hours, and even after it was asked not to honor any transfers, the bank did not take action until another 38 wire transfers had taken place, the complaint alleged.

In its response, Comerica claimed that EMI's loss was solely its own fault. "Valid credentials assigned to an EMI employee were used to authenticate a logon for purposes of online banking transactions," the bank said. "If some unknown criminals used those credentials, rather than the EMI employee to whom they had been entrusted, this was caused solely by the actions of that EMI employee."

The bank also said it should have been obvious "to any reasonably alert person" that the phishing site where the EMI employee entered the company's banking credentials was not a legitimate site.

Neither EMI nor Comerica responded immediately to a request for comment. The case is not scheduled to go to trail until the end of this year.

The dispute is similar to several other disputes in front of courts around the country. One example is a lawsuit involving Lubbock, TX-based PlainsCapital bank and its customer Hilary Machinery Inc of Plano, which was robbed of over $800,000 in a fashion very similar to EMI. In that case however, it is the bank that has filed a lawsuit asking a federal district court to absolve it of any blame.

In Illinois, a couple whose bank account was robbed has been allowed to sue their bank for its alleged failure to implement the latest security measures designed to prevent such compromises.

Meanwhile, in New York, the Town of Poughkeepsie is slamming its bank, TD Bank NA for failing to notice or stop numerous unauthorized transfers totaling over $500,000 from its account.

Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan or subscribe to Jaikumar's RSS feed . His e-mail address is jvijayan@computerworld.com.

FREE Computerworld Insider Guide: Five IT certifications that won’t break you
Join the discussion
Be the first to comment on this article. Our Commenting Policies