Patco Construction v Peoples United puts burden on wrong party
endif; ?>In this political season we are hearing a lot about how individuals need to take responsibility for their own lives. We don’t want a society that is dependent on the government (or maybe we do, I don’t know) for support. Well, in information security this issue is of critical importance. If you are not responsible for the consequences of your actions around security, why would you ever take them seriously?
The case of Patco Construction v. Peoples United Bank is a great example of security responsibility. My friend Jody Brazil of Firemon and I discussed this case and the issues at hand. You can listen to our discussion below. Jody also wrote a great blog post on the issue here.
For those not familiar with this case, it revolves around the theft of more than a half a million dollars from the bank account of a company called Patco Construction. Their bank account was at Peoples United. It seems that through a successful phishing or other type of attack, the criminals were able to obtain Patco’s online banking credentials. Once in possession of the log-in credentials they logged into the account and made several transfers totaling over $500k in a short period of time. All of the transfers were to accounts at foreign banks. All of these banks then received transfer requests for the funds to other banks and accounts. Within a short time the money had moved from one bank to another, one country to another. By the time Patco and United became aware of the theft, roughly half the money was gone, never to be recovered. The other half was recovered.
Because the cyber thieves had logged on with valid credentials, People’s United took the position that it was not their fault the money was stolen. Patco was at fault for giving up its credentials. While there are rules surrounding consumers’ losses for online banking and credit and debit cards, those don’t apply necessarily to commercial accounts.
Patco said that if the bank had two-factor authentication or other better security measures the crooks would not have been able to so easily log on and steal the money. They also claimed that Peoples United’s own system red flagged the transactions as suspicious and they should have blocked them until further investigation.
The case was recently appealed, where it was sent back down to the lower court. The appeals court seemed to rule against the bank, recommending remediation in an effort to settle this, but clearly they indicated at least some liability with the bank.
What should the bank have done? The criminals logged in with valid credentials. Is the bank supposed to know that they were criminals? If the bank has to look beyond the computer to everyone logging in, is online banking worth the risk to the bank? At what point should Patco be responsible for allowing its log on to be stolen? If they don’t have to pay the price and take responsibility for their own security, can we really expect them to ever bother to take security seriously?
Jody and I have both been in the security industry a long time. Getting organizations to actually budget and take security seriously used to be a very hard sell. Over the years it has gotten easier mainly because of all of the high-profile breaches and compliance regulations. But if there is no penalty for allowing your online banking credentials to be stolen¸ what incentive is there for you to guard it? If the bank is ultimately responsible anyway, why even bother?
What about the bank? If they know they are going to be responsible, shouldn’t they make it more difficult to prove who you are before letting any money or information out? What effect does this have on doing business? Many hail two-factor authentication as the answer here, but is it really? Jody and I think it will help, but there are those who argue to the contrary.
What about you? Do you think the bank should be responsible for this loss? What should Patco’s responsibility be? Aren’t we sending the wrong message by letting Patco off the hook for this?
Listen to Jody and I discuss this and then please let us know your thoughts in the comments.
By way of disclosure, I have done some consulting work for Firemon in the past




