Issues with identity theft and reasonable investigations can be very complicated. Case in point — the forensic analysis detailed in this ruling in which a District Court judge in California partially denied a defendant’s motion for summary judgment in a case alleging violations of both the Fair Credit Reporting Act and the Rosenthal Fair Debt Collection Practices Act, among other claims.
The background: The lawsuit centers on a series of activities involving a personal loan that was taken out in the plaintiff’s name without authorization. On August 23, 2023, the plaintiff received notifications about unauthorized attempts to transfer funds from his checking account with the defendant via Zelle. These were followed by suspicious phone calls that led to the plaintiff providing personal information, under the belief that he was speaking with a representative from the defendant. Shortly thereafter, a loan application for $9,800 was submitted using a non-historic device, and the funds were deposited into the plaintiff’s account. Subsequently, the plaintiff noticed transfers totaling $4,500 to a third-party account and another $4,000 transferred to his Apple Cash account. The fraud was detected after the defendant’s fraud system flagged the suspicious transactions, but a portion of the stolen funds was withdrawn before the defendant could intervene.
- The plaintiff reported the identity theft to the defendant and the police and submitted a fraud claim.
- The defendant denied the claim based on the fact that a historical device was used for some transactions, leaving the plaintiff liable for the full amount. The denial of the fraud claim and the defendant’s subsequent credit reporting of the loan as belonging to the plaintiff sparked this lawsuit, which alleged violations of the FCRA, the RFDCPA, and the California Identity Theft Act.
The ruling: The issue, at least as it relates to the FCRA claims, was the defendant’s “rubber stamping” of subsequent disputes after determining that its first investigation was reasonable. There were a number of potential flags that could have been further investigated after they were brought to the attention of the defendant, noted Judge Michael M. Anello of the District Court for the Southern District of California.
- The court highlighted that the defendant’s initial investigation into the fraud claim was insufficient, particularly given that the defendant had only relied on the fact that a historical device was involved in one of the transactions. Despite other evidence indicating potential fraudulent activity — such as the use of a “fraud cookie” to initiate the loan and transfers — the bank’s investigation was limited in scope. The defendant did not conduct a thorough review of all the transfers, including those to the third-party account, or investigate the circumstances surrounding the $4,000 Apple Cash transfer, which was made using a non-historic device, according to the judge.
- Judge Anello specifically pointed out that the defendant failed to call the plaintiff or thoroughly examine the broader context of the fraudulent activity. Instead, the investigation relied too heavily on the idea that the Apple Cash transaction, which occurred via a historical device, negated the fraud claim.
- The court also emphasized that the defendant’s actions after the initial investigation did not remedy this lack of diligence. When the plaintiff filed a subsequent dispute, the defendant merely affirmed its initial conclusions without addressing new information presented by the plaintiff. Judge Anello noted that a reasonable jury could find that the defendant’s investigation was not as thorough as required by the FCRA and that its failure to conduct a comprehensive review of the fraud allegations could lead to a violation of the law.
- In light of these findings, the court denied the defendant’s motion for summary judgment, allowing the plaintiff’s claims under both the FCRA and the California Consumer Credit Reporting Agencies Act (CCRAA) to proceed.




