Bank of America to face trial in California pandemic unemployment lawsuit

scanx
Reviewed by
Suketu GScanX News Team
Key Highlights

Judge Gonzalo P. Curiel denied Bank of America's motion for summary judgment in a class action involving over 100,000 Californians who received unemployment benefits via prepaid cards during the pandemic. The lawsuit alleges the bank failed to implement EMV security chips and used an automated fraud filter to deny legitimate claims, leading to frozen accounts and lost benefits. Plaintiffs seek treble and punitive damages for violations of federal and state laws, including the Electronic Funds Transfer Act and California Consumer Privacy Act. This follows a $225 million regulatory fine paid by the bank in 2022.

powered bylight_fuzz_icon
48645015

*this image is generated using AI for illustrative purposes only.

Bank of America will face trial in a long-running multi-district litigation concerning its handling of unemployment benefits for Californians during the COVID-19 pandemic. On August 18, 2026, Judge Gonzalo P. Curiel of the U.S. District Court in San Diego issued a 105-page order denying the bank’s motion for summary judgment in In re Bank of America California Unemployment Benefits Litigation (Case No. 3:21-md-2992-GPC-MSB).

The denial clears the path for plaintiffs, represented by Cotchett, Pitre & McCarthy and Altshuler Berzon LLP, to pursue class-wide damages. The lawsuit alleges that more than 100,000 recipients had their unemployment and disability benefits stolen from prepaid debit cards due to the bank’s failure to implement basic security measures, specifically the omission of industry-standard EMV security chips.

Allegations of Fraud Filter Abuse

Plaintiffs contend that Bank of America violated the federal Electronic Funds Transfer Act by failing to investigate unauthorized transaction claims. Instead of conducting required investigations, the bank allegedly used an automated Claim Fraud Filter to summarily deny all claims alleging unauthorized ATM transactions and freeze accounts. This action deprived cardholders of access to previously paid benefits.

The suit further alleges that the bank compounded the harm by making it nearly impossible for aggrieved cardholders to reach customer service centers, often forcing them to spend hours on hold before disconnection. Plaintiffs seek treble (3x) damages for willful violations of federal statutes and punitive damages for intentional disregard of class members’ rights.

Legal History and Regulatory Context

The litigation originated from a class action filed by Cotchett, Pitre & McCarthy in January 2021 (Yick v. Bank of America, N.A.). In June 2021, a San Francisco district court issued a preliminary injunction, finding that plaintiffs demonstrated a strong likelihood of success. The injunction required the bank to stop using the Claim Fraud Filter, reopen denied claims, reimburse improperly denied cardholders, and improve call center service.

In July 2022, Bank of America entered into Consent Orders with the Consumer Financial Protection Bureau and the Office of the Comptroller of the Currency, agreeing to pay fines totaling $225 million. These orders mirrored many claims in the original complaints. In June 2025, Judge Curiel certified five classes: Claim Denial, Credit Rescission, Account Freeze, Customer Service, and EMV Chip.

What the Numbers Show

The case involves significant potential liability exposure beyond the $225 million in regulatory fines already paid. The court’s certification of five distinct classes suggests a broad scope of alleged misconduct, ranging from technical security failures (EMV chips) to procedural due process violations. The pursuit of treble damages under federal law indicates that plaintiffs are positioning the bank’s conduct as willful rather than negligent, which could substantially increase the final settlement or judgment value if proven at trial.

Claims Proceeding to Trial

Plaintiffs are pursuing several key legal theories against Bank of America:

  • Violations of the federal Electronic Funds Transfer Act by failing to timely investigate and reimburse unauthorized transaction claims.
  • Violations of the California Consumer Privacy Act by issuing EDD debit cards without EMV security chips and failing to ensure confidentiality of personal information.
  • Violations of due process rights by depriving class members of protected property interests without adequate due process.
  • Negligence in failing to include security cards on EDD debit cards and inadequately staffing customer service call centers.
  • Breaches of the implied covenant of good faith and fiduciary duties owed to EDD cardholders.

How might the prospect of treble damages under the Electronic Funds Transfer Act influence Bank of America's settlement negotiations prior to trial?

What impact could a plaintiff victory in this case have on the broader banking industry's adoption of EMV security chips for government-issued prepaid debit cards?

Will the previous $225 million regulatory fines paid to the CFPB and OCC be credited against any potential civil judgment or settlement in this litigation?

like15
dislike

Bank of America to acquire MDSec Consulting in Q4 2026

scanx
Reviewed by
Jubin VScanX News Team
Key Highlights

Bank of America announced the acquisition of MDSec Consulting Limited, an information security specialist based in Macclesfield, England. The transaction, involving approximately 65 cybersecurity professionals, is scheduled to close in Q4 2026 after regulatory clearance, enhancing Bank of America's global cybersecurity capabilities.

powered bylight_fuzz_icon
46994600

*this image is generated using AI for illustrative purposes only.

Bank of America announced on July 30, 2026, that it will acquire MDSec Consulting Limited, a specialist information security consultancy headquartered in Macclesfield, England. The transaction is expected to close during the fourth quarter of 2026, subject to regulatory approvals. This acquisition strengthens Bank of America’s cybersecurity infrastructure by integrating MDSec’s team of approximately 65 highly skilled professionals, enhancing the bank’s defensive capabilities against evolving digital threats.

Deal Overview

The acquisition targets MDSec Consulting Limited, which provides deeply technical information security-related consultancy services. While specific financial terms have not been disclosed, the strategic value lies in talent acquisition and technical expertise. The deal complements Bank of America’s existing presence in the North of England, where the bank employs over 1,400 staff in Chester and operates one of its cyber threat operations centers.

Key Details

Parameter Detail
Acquirer Bank of America
Target MDSec Consulting Limited
Target HQ Macclesfield, England
Workforce ~65 cybersecurity professionals
Expected Closing Q4 2026
Status Pending Regulatory Approvals

Strategic Context

Kris Fador, Chief Information Security Officer at Bank of America, stated that the bank has long admired the exceptional ability of the MDSec team. He noted that the acquisition allows Bank of America and its clients to further benefit from their work, welcoming the team as the bank continues to enhance its leading cybersecurity capabilities in the UK and globally.

Dominic Chell, Co-Founder of MDSec, expressed pride in the team’s achievements and the ambition to build world-class security capabilities. He highlighted that joining a leading financial institution reflects their culture of innovation and technical excellence, providing an opportunity to take their ambition to the next level.

What the Numbers Show

The integration of 65 specialized cybersecurity experts into Bank of America’s existing operations represents a targeted talent acquisition rather than a scale-driven merger. With over 1,400 employees already based in nearby Chester, the acquisition consolidates regional expertise, potentially streamlining operational coordination between the new Macclesfield team and the established Chester cyber threat operations center.

How might the integration of MDSec's specialized talent influence Bank of America's cybersecurity service offerings to its corporate clients in the UK?

What specific regulatory hurdles could delay the Q4 2026 closing, particularly regarding cross-border data security and financial sector compliance?

Will this acquisition signal a broader trend of major US banks acquiring niche European cybersecurity firms to bolster their global defensive infrastructure?

like15
dislike

More News on bank of america