Cybersecurity Policy Report, Financial Regulator Urged to Close Gap Exploited by Cyber Thieves, (Aug 20, 2026)
Organizations Mentioned:Financial Industry Regulatory Authority | Gap
The Financial Industry Regulatory Authority (FINRA) should require the brokerages it oversees to implement cybersecurity protections to prevent cyber thieves from stealing assets from account holders, according to Sens. Ron Wyden (D., Ore.) and Elizabeth Warren (D., Mass.), the ranking members, respectively, of the Senate committees on Financial Services and Banking, Housing, and Urban Affairs.
FINRA should require its member brokerages to prevent fraudsters from exploiting the features of the Automated Customer Account Transfer Service (ACATS), which enables investors to quickly transfer their assets between brokerages, Sens. Wyden and Warren said in a letter sent today to FINRA President and Chief Executive Officer Robert Cook.
ACATS was designed to prevent brokerages from trying to retain departing customers by requiring account transfers to occur within days, but that speed has come at the expense of security, they said. The “hyper-efficient timeline” of ACATS transfers “effectively solved a major consumer-protection issue of the past,” the senators said, but “inadvertently created a massive security vulnerability that fraudsters are exploiting.”
“The ACATS system requires zero notification to or authentication from the actual account holder by the outgoing brokerage firm. Fraudsters exploit this by using stolen personal information to open a fraudulent account in a victim’s name at a separate online brokerage and then submit an ACATS request to pull the victim’s life savings from their legitimate account,” they noted.
In 2023, FINRA recommended—but didn’t require—its member brokerages to notify investors via phone calls, texts, or e-mails that their accounts were being transferred. Several large financial institutions ignored the recommendation, the senators said.
“It is unacceptable that major brokerage firms are putting customers’ life savings at risk of being ripped off by criminals because of inadequate account protections. FINRA must step in to protect consumers. In the short term, FINRA must immediately codify the voluntary guidance from Regulatory Notice 23-06 into a binding rule that would require brokers to send text, email, or push alerts to account holders when an ACATS transfer request is received, several days before the customer’s assets are transferred out of their account,” they said.
“Crucially, to counter modern cyber threats, FINRA must also require brokers to secure customer accounts with phishing-resistant multi-factor authentication (MFA), specifically a technology called passkeys. Traditional MFA—such as verification codes sent by text message or email and mobile push notifications—can be easily bypassed by bad actors,” they added.
Sens. Wyden and Warren asked Mr. Cook to respond to their letter by Sept. 17 and detail “the steps that FINRA intends to take to protect investors.”
News: FederalLegislation DataSecurity