October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Bessemer’s lawsuit against Fiserv tested who pays when outsourced banking security fails

The Bessemer-Fiserv lawsuit tested whether a credit union could hold its outsourced banking-technology provider responsible for alleged security weaknesses. The court let contract claims proceed, dismissed negligence theories, and never issued a final finding that Fiserv was liable.
From TheFinanceBase Team6 min to read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When a credit union outsources online banking and account processing, it still answers to members and regulators if security controls fail. The difficult question is who bears the resulting loss: the institution, its technology provider, or both. Bessemer System Federal Credit Union v. Fiserv became an important test of that question, but it did not produce a final ruling that Fiserv was liable.

Bessemer alleged that Fiserv’s Charlotte account-processing platform and Virtual Branch service contained longstanding vulnerabilities and that Fiserv failed to correct them. In a July 14, 2020 ruling, the federal court allowed key contract and trade-secret theories to continue while dismissing negligence and unfair-trade-practices claims. The public docket shows discovery activity through October 2023; the available record does not establish a final judgment, trial verdict, or settlement by August 18, 2026.

What the Bessemer-Fiserv case was

Bessemer filed the lawsuit in Pennsylvania in April 2019. It became federal case 2:19-cv-00624-RJC in the U.S. District Court for the Western District of Pennsylvania on May 28, 2019. The defendants were Fiserv Solutions LLC and Fiserv Inc. CyberScoop’s July 15, 2020 article used the headline “Credit union’s lawsuit against Fiserv is a test for cybersecurity liability.” The underlying case is documented in the federal docket and contemporary coverage of the filing.

Bessemer sought monetary and other relief and said it was moving to another online-banking vendor. Fiserv denied the allegations and said it would respond through the legal process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

What Bessemer alleged

The complaint’s allegations, which were not adjudicated findings, described a series of alleged security and operational failures. Bessemer reportedly claimed that Fiserv:

  • failed to promptly patch known vulnerabilities;
  • continued using allegedly outdated security methods after weaknesses were raised;
  • failed to protect confidential member information and financial records from unauthorized access;
  • operated systems that exposed members to possible identity theft; and
  • had defects that impaired the credit union’s ability to protect member data.

Bessemer also alleged that Fiserv threatened civil or criminal action if the credit union disclosed the alleged security problems to third parties. Credit-union trade coverage described the dispute in similar terms at the time (Credit Union Times; CyberScoop). None of those allegations, by themselves, proves that a vulnerability was exploited, that identity theft occurred, or that Fiserv caused compensable losses.

Rank #2
Liberty Safe - Heavy Duty Concrete Gun Safe Anchoring Kit (10915)
  • ANCHORED DOWN - Keep your safe solid and secure to concrete flooring
  • EASY TO INSTALL - Utilize the pre-drilled holes in your safe for easy installation
  • VALUE - Best security add-on to your Liberty Safe gun safe

What the judge actually decided in 2020

Judge Robert J. Colville’s July 14, 2020 opinion was a motion-to-dismiss decision, not a trial ruling. It screened the legal theories and determined which could proceed under the pleadings.

Claim or issue Result in the 2020 opinion
Breach of the main contract Allowed to proceed
Federal trade-secret theory Allowed to proceed in relevant part
Negligence Dismissed
Unfair or deceptive trade practices Dismissed
Final liability or damages Not decided

The opinion is available through Justia and an official government-hosted PDF. The court’s treatment of negligence is particularly important: the gist-of-the-action doctrine treated the alleged security-performance dispute as fundamentally contractual. Thus, dismissing negligence did not end the case. It made the negotiated agreement, its security commitments, and its remedies more important.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-C Type TrustKey T120
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Why contract language may decide cybersecurity liability

A technology provider can face substantial exposure even when a negligence claim fails if the contract supplies a specific security obligation. Relevant documents may include the master agreement, service schedules, security exhibits, data-protection addenda, implementation statements, and product documentation incorporated into the deal.

Terms that deserve close review

  • Minimum security controls, authentication requirements, encryption, and patching commitments.
  • Incident-notification deadlines, cooperation duties, forensic access, and log availability.
  • Audit, testing, vulnerability-reporting, and independent-assessment rights.
  • Customer configuration responsibilities, including whether multifactor authentication or fraud controls must be activated by the institution.
  • Warranties, disclaimers, service levels, indemnities, liability caps, consequential-damage exclusions, arbitration provisions, and jury waivers.
  • Rules for member reimbursements, stolen funds, vendor replacement, data conversion, and termination assistance.

A statement that a platform is “secure” is not automatically a contractual warranty. Its legal effect depends on where it appeared, whether it was incorporated into the agreement, whether it promised identifiable controls, what disclaimers applied, and whether the customer relied on it.

Rank #4
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

The evidence that would decide the dispute

Cybersecurity allegations become a liability case only when the plaintiff can connect an obligation, a failure, causation, and legally recoverable loss. Discovery would therefore be expected to examine:

  • contracts, security schedules, and representations about controls;
  • vulnerability reports, penetration tests, scans, patch tickets, and remediation histories;
  • communications in which Bessemer reported weaknesses or Fiserv responded;
  • authentication, access, incident, and system logs;
  • evidence that an alleged weakness was known, exploitable, and material;
  • whether Bessemer accepted, rejected, or failed to activate available protections;
  • expert analysis linking the alleged weakness to actual member harm; and
  • loss records for reimbursements, forensics, legal work, notification, lost productivity, and vendor transition.

The docket reflects how difficult that process became. In 2023, the court addressed special-master recommendations and continuing electronic-discovery disputes, then extended discovery and expert-report deadlines on October 13. See the August 8, 2023 discovery order and the October 13, 2023 order. A separate September 15, 2021 opinion addressed Fiserv’s counterclaims.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FEITIAN K39 USB Security Key - Two Factor Authenticator - USB-C with FIDO2 - Help Prevent Account Takeovers
  • FIDO2 + FIDO U2F certified and supported USB security key
  • Supports Computers, Laptops, Tablets, and Mobile Devices with a USB-C port
  • Works without downloading any drivers. Supported OS: Android, Chrome OS, Windows, MacOS, Linux
  • Durable design made to last for a long time with everyday use. Water-resistant (IP67)
  • Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the case did not establish

  • It did not find that Fiserv’s systems were insecure.
  • It did not find that Fiserv caused a compensable data breach or identity theft.
  • It did not create a general cybersecurity duty for every fintech provider.
  • It did not transfer a credit union’s regulatory responsibility for member-information protection to its vendor.
  • It was not a nationwide appellate precedent; it was a federal district-court ruling at the pleading stage.

The practical “test” was narrower: could a financial institution use contract and related statutory theories to hold a major technology provider accountable for alleged security deficiencies? The court allowed that question to be litigated, but did not answer it on the merits.

Why outsourcing does not eliminate the credit union’s responsibility

A credit union generally remains responsible for safeguarding member information and managing service-provider risk even when critical systems are hosted or operated by a third party. Vendor responsibility is a separate question involving contract duties, common-law claims, statutory claims, and allocation of losses. Liability to the institution may also differ from direct liability to individual members.

The central edge case is the boundary between provider infrastructure and customer configuration. A claim may turn on whether a control was included by default, available but not activated, excluded by contract, sold as an upgrade, technically unavailable in the relevant product version, or assigned to the credit union.

How the 2026 FiCare lawsuit differs

FiCare Federal Credit Union’s lawsuit, reported by Payments Dive on January 29, 2026, is a separate case and should not be treated as an outcome in Bessemer. According to reporting about FiCare’s complaint, the alleged intrusions began in 2024 and involved account takeovers through Fiserv’s Virtual Branch Next platform. FiCare alleges customer losses of hundreds of thousands of dollars, reimbursement by the credit union, and a refusal by Fiserv to reimburse it. The complaint also alleges that controls such as multifactor authentication and biometric protections were absent or available only through an additional security charge. Fiserv disputes the allegations and plans to defend the case. Source: Payments Dive.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Bessemer FiCare
Reported focus Alleged vulnerabilities, patching, and exposure of member information Alleged account takeover, authentication controls, and stolen funds
Procedural significance 2020 claims-screening ruling; later discovery activity Separate 2026 lawsuit; allegations remain disputed
What it proves Nothing about ultimate Fiserv liability Nothing about systemic misconduct or the Bessemer outcome

A contract and vendor-risk checklist for credit unions

  1. Define baseline controls. Put MFA, privileged-access safeguards, encryption, logging, patch timelines, and fraud monitoring in the agreement rather than relying on general marketing language.
  2. Assign account-takeover losses. State who investigates, reimburses members, pays response costs, and bears losses when controls fail.
  3. Require usable evidence. Negotiate timely access to logs, vulnerability notices, test results, incident records, and forensic cooperation.
  4. Review remedies. Examine caps, exclusions, indemnities, consequential-loss language, arbitration, jury waivers, and insurance requirements.
  5. Test configuration duties. Document which protections the institution must activate and verify that staff can operate them correctly.
  6. Preserve communications. Keep vendor notices, tickets, security assessments, and decisions about accepting or rejecting controls.
  7. Plan an exit. Test data return, conversion, deconversion, and continuity procedures before a dispute or security event occurs.
  8. Assess independent monitoring. Managed detection, identity tools, penetration testing, and fraud services can reduce operational risk, but they cannot replace contractual access to the vendor’s telemetry or reassign legal responsibility automatically.

The continuing lesson

Bessemer shows why outsourced cybersecurity disputes are often decided less by broad statements about “secure” platforms than by contracts, technical evidence, causation, and damage allocation. The July 2020 ruling kept the core contract dispute alive while rejecting negligence and unfair-trade theories. Years of discovery followed, and the available public record does not establish a final merits result. For institutions choosing or renewing an online-banking provider, the durable lesson is to specify controls, evidence, cooperation, and loss allocation before an incident makes those terms the center of a lawsuit.

Quick Recap

Bestseller No. 2
Liberty Safe - Heavy Duty Concrete Gun Safe Anchoring Kit (10915)
Liberty Safe - Heavy Duty Concrete Gun Safe Anchoring Kit (10915)
ANCHORED DOWN - Keep your safe solid and secure to concrete flooring; EASY TO INSTALL - Utilize the pre-drilled holes in your safe for easy installation
$31.34
Bestseller No. 3
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-C Type TrustKey T120
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-C Type TrustKey T120
For the driver download and user guide, please visit TrustKey Solutions Home support page.
$20.00
Bestseller No. 4
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
For the driver download and user guide, please visit TrustKey Solutions Home support page.
Bestseller No. 5
FEITIAN K39 USB Security Key - Two Factor Authenticator - USB-C with FIDO2 - Help Prevent Account Takeovers
FEITIAN K39 USB Security Key - Two Factor Authenticator - USB-C with FIDO2 - Help Prevent Account Takeovers
FIDO2 + FIDO U2F certified and supported USB security key; Supports Computers, Laptops, Tablets, and Mobile Devices with a USB-C port
$28.50

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.