Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • FTC Intends to Police Retailers’ Use of ‘Surveillance Pricing’
    • D. Mass.: Most Meta Pixel, Google Analytics website tracking privacy claims against hospital survive dismissal
    • Financial Regulator Urged to Close Gap Exploited by Cyber Thieves
    • Latvian Regulator Outlines Methodology of Response to Personal Data Leaks
    • Nonprofit Appeals Denial of Cybersecurity Pilot Program Funding
    • Power Inverters Eligible for Clean-Energy Tax Credits Removed From FCC’s Covered List
    • TCPA, Fax, Robocall Petitions Deemed ‘Moot’ by FCC Bureau
    • U.K. Privacy Agency Highlights Parental Concerns About Children’s Online Activities
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    Cybersecurity Policy Report, Financial Regulator Urged to Close Gap Exploited by Cyber Thieves, (Aug 20, 2026)

    Organizations Mentioned:Financial Industry Regulatory Authority | Gap

    By Tom Leithauser

    The Financial Industry Regulatory Authority (FINRA) should require the brokerages it oversees to implement cybersecurity protections to prevent cyber thieves from stealing assets from account holders, according to Sens. Ron Wyden (D., Ore.) and Eliza ...

    By Tom Leithauser

    The Financial Industry Regulatory Authority (FINRA) should require the brokerages it oversees to implement cybersecurity protections to prevent cyber thieves from stealing assets from account holders, according to Sens. Ron Wyden (D., Ore.) and Elizabeth Warren (D., Mass.), the ranking members, respectively, of the Senate committees on Financial Services and Banking, Housing, and Urban Affairs.

    FINRA should require its member brokerages to prevent fraudsters from exploiting the features of the Automated Customer Account Transfer Service (ACATS), which enables investors to quickly transfer their assets between brokerages, Sens. Wyden and Warren said in a letter sent today to FINRA President and Chief Executive Officer Robert Cook.

    ACATS was designed to prevent brokerages from trying to retain departing customers by requiring account transfers to occur within days, but that speed has come at the expense of security, they said. The “hyper-efficient timeline” of ACATS transfers “effectively solved a major consumer-protection issue of the past,” the senators said, but “inadvertently created a massive security vulnerability that fraudsters are exploiting.”

    “The ACATS system requires zero notification to or authentication from the actual account holder by the outgoing brokerage firm. Fraudsters exploit this by using stolen personal information to open a fraudulent account in a victim’s name at a separate online brokerage and then submit an ACATS request to pull the victim’s life savings from their legitimate account,” they noted.

    In 2023, FINRA recommended—but didn’t require—its member brokerages to notify investors via phone calls, texts, or e-mails that their accounts were being transferred. Several large financial institutions ignored the recommendation, the senators said.

    “It is unacceptable that major brokerage firms are putting customers’ life savings at risk of being ripped off by criminals because of inadequate account protections. FINRA must step in to protect consumers. In the short term, FINRA must immediately codify the voluntary guidance from Regulatory Notice 23-06 into a binding rule that would require brokers to send text, email, or push alerts to account holders when an ACATS transfer request is received, several days before the customer’s assets are transferred out of their account,” they said.

    “Crucially, to counter modern cyber threats, FINRA must also require brokers to secure customer accounts with phishing-resistant multi-factor authentication (MFA), specifically a technology called passkeys. Traditional MFA—such as verification codes sent by text message or email and mobile push notifications—can be easily bypassed by bad actors,” they added.

    Sens. Wyden and Warren asked Mr. Cook to respond to their letter by Sept. 17 and detail “the steps that FINRA intends to take to protect investors.”

    News: FederalLegislation DataSecurity

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use