Free tools Windows power users keep installed
One-click scans. No signup required.
When a credit union outsources online banking and account processing, it still answers to members and regulators if security controls fail. The difficult question is who bears the resulting loss: the institution, its technology provider, or both. Bessemer System Federal Credit Union v. Fiserv became an important test of that question, but it did not produce a final ruling that Fiserv was liable.
Bessemer alleged that Fiserv’s Charlotte account-processing platform and Virtual Branch service contained longstanding vulnerabilities and that Fiserv failed to correct them. In a July 14, 2020 ruling, the federal court allowed key contract and trade-secret theories to continue while dismissing negligence and unfair-trade-practices claims. The public docket shows discovery activity through October 2023; the available record does not establish a final judgment, trial verdict, or settlement by August 18, 2026.
What the Bessemer-Fiserv case was
Bessemer filed the lawsuit in Pennsylvania in April 2019. It became federal case 2:19-cv-00624-RJC in the U.S. District Court for the Western District of Pennsylvania on May 28, 2019. The defendants were Fiserv Solutions LLC and Fiserv Inc. CyberScoop’s July 15, 2020 article used the headline “Credit union’s lawsuit against Fiserv is a test for cybersecurity liability.” The underlying case is documented in the federal docket and contemporary coverage of the filing.
Bessemer sought monetary and other relief and said it was moving to another online-banking vendor. Fiserv denied the allegations and said it would respond through the legal process.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
What Bessemer alleged
The complaint’s allegations, which were not adjudicated findings, described a series of alleged security and operational failures. Bessemer reportedly claimed that Fiserv:
- failed to promptly patch known vulnerabilities;
- continued using allegedly outdated security methods after weaknesses were raised;
- failed to protect confidential member information and financial records from unauthorized access;
- operated systems that exposed members to possible identity theft; and
- had defects that impaired the credit union’s ability to protect member data.
Bessemer also alleged that Fiserv threatened civil or criminal action if the credit union disclosed the alleged security problems to third parties. Credit-union trade coverage described the dispute in similar terms at the time (Credit Union Times; CyberScoop). None of those allegations, by themselves, proves that a vulnerability was exploited, that identity theft occurred, or that Fiserv caused compensable losses.
Rank #2
- ANCHORED DOWN - Keep your safe solid and secure to concrete flooring
- EASY TO INSTALL - Utilize the pre-drilled holes in your safe for easy installation
- VALUE - Best security add-on to your Liberty Safe gun safe
What the judge actually decided in 2020
Judge Robert J. Colville’s July 14, 2020 opinion was a motion-to-dismiss decision, not a trial ruling. It screened the legal theories and determined which could proceed under the pleadings.
| Claim or issue | Result in the 2020 opinion |
|---|---|
| Breach of the main contract | Allowed to proceed |
| Federal trade-secret theory | Allowed to proceed in relevant part |
| Negligence | Dismissed |
| Unfair or deceptive trade practices | Dismissed |
| Final liability or damages | Not decided |
The opinion is available through Justia and an official government-hosted PDF. The court’s treatment of negligence is particularly important: the gist-of-the-action doctrine treated the alleged security-performance dispute as fundamentally contractual. Thus, dismissing negligence did not end the case. It made the negotiated agreement, its security commitments, and its remedies more important.
Recommended Free Tools
Rank #3
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Why contract language may decide cybersecurity liability
A technology provider can face substantial exposure even when a negligence claim fails if the contract supplies a specific security obligation. Relevant documents may include the master agreement, service schedules, security exhibits, data-protection addenda, implementation statements, and product documentation incorporated into the deal.
Terms that deserve close review
- Minimum security controls, authentication requirements, encryption, and patching commitments.
- Incident-notification deadlines, cooperation duties, forensic access, and log availability.
- Audit, testing, vulnerability-reporting, and independent-assessment rights.
- Customer configuration responsibilities, including whether multifactor authentication or fraud controls must be activated by the institution.
- Warranties, disclaimers, service levels, indemnities, liability caps, consequential-damage exclusions, arbitration provisions, and jury waivers.
- Rules for member reimbursements, stolen funds, vendor replacement, data conversion, and termination assistance.
A statement that a platform is “secure” is not automatically a contractual warranty. Its legal effect depends on where it appeared, whether it was incorporated into the agreement, whether it promised identifiable controls, what disclaimers applied, and whether the customer relied on it.
Rank #4
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
The evidence that would decide the dispute
Cybersecurity allegations become a liability case only when the plaintiff can connect an obligation, a failure, causation, and legally recoverable loss. Discovery would therefore be expected to examine:
- contracts, security schedules, and representations about controls;
- vulnerability reports, penetration tests, scans, patch tickets, and remediation histories;
- communications in which Bessemer reported weaknesses or Fiserv responded;
- authentication, access, incident, and system logs;
- evidence that an alleged weakness was known, exploitable, and material;
- whether Bessemer accepted, rejected, or failed to activate available protections;
- expert analysis linking the alleged weakness to actual member harm; and
- loss records for reimbursements, forensics, legal work, notification, lost productivity, and vendor transition.
The docket reflects how difficult that process became. In 2023, the court addressed special-master recommendations and continuing electronic-discovery disputes, then extended discovery and expert-report deadlines on October 13. See the August 8, 2023 discovery order and the October 13, 2023 order. A separate September 15, 2021 opinion addressed Fiserv’s counterclaims.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallBest Value
- FIDO2 + FIDO U2F certified and supported USB security key
- Supports Computers, Laptops, Tablets, and Mobile Devices with a USB-C port
- Works without downloading any drivers. Supported OS: Android, Chrome OS, Windows, MacOS, Linux
- Durable design made to last for a long time with everyday use. Water-resistant (IP67)
- Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.
What the case did not establish
- It did not find that Fiserv’s systems were insecure.
- It did not find that Fiserv caused a compensable data breach or identity theft.
- It did not create a general cybersecurity duty for every fintech provider.
- It did not transfer a credit union’s regulatory responsibility for member-information protection to its vendor.
- It was not a nationwide appellate precedent; it was a federal district-court ruling at the pleading stage.
The practical “test” was narrower: could a financial institution use contract and related statutory theories to hold a major technology provider accountable for alleged security deficiencies? The court allowed that question to be litigated, but did not answer it on the merits.
Why outsourcing does not eliminate the credit union’s responsibility
A credit union generally remains responsible for safeguarding member information and managing service-provider risk even when critical systems are hosted or operated by a third party. Vendor responsibility is a separate question involving contract duties, common-law claims, statutory claims, and allocation of losses. Liability to the institution may also differ from direct liability to individual members.
The central edge case is the boundary between provider infrastructure and customer configuration. A claim may turn on whether a control was included by default, available but not activated, excluded by contract, sold as an upgrade, technically unavailable in the relevant product version, or assigned to the credit union.
How the 2026 FiCare lawsuit differs
FiCare Federal Credit Union’s lawsuit, reported by Payments Dive on January 29, 2026, is a separate case and should not be treated as an outcome in Bessemer. According to reporting about FiCare’s complaint, the alleged intrusions began in 2024 and involved account takeovers through Fiserv’s Virtual Branch Next platform. FiCare alleges customer losses of hundreds of thousands of dollars, reimbursement by the credit union, and a refusal by Fiserv to reimburse it. The complaint also alleges that controls such as multifactor authentication and biometric protections were absent or available only through an additional security charge. Fiserv disputes the allegations and plans to defend the case. Source: Payments Dive.
| Bessemer | FiCare | |
|---|---|---|
| Reported focus | Alleged vulnerabilities, patching, and exposure of member information | Alleged account takeover, authentication controls, and stolen funds |
| Procedural significance | 2020 claims-screening ruling; later discovery activity | Separate 2026 lawsuit; allegations remain disputed |
| What it proves | Nothing about ultimate Fiserv liability | Nothing about systemic misconduct or the Bessemer outcome |
A contract and vendor-risk checklist for credit unions
- Define baseline controls. Put MFA, privileged-access safeguards, encryption, logging, patch timelines, and fraud monitoring in the agreement rather than relying on general marketing language.
- Assign account-takeover losses. State who investigates, reimburses members, pays response costs, and bears losses when controls fail.
- Require usable evidence. Negotiate timely access to logs, vulnerability notices, test results, incident records, and forensic cooperation.
- Review remedies. Examine caps, exclusions, indemnities, consequential-loss language, arbitration, jury waivers, and insurance requirements.
- Test configuration duties. Document which protections the institution must activate and verify that staff can operate them correctly.
- Preserve communications. Keep vendor notices, tickets, security assessments, and decisions about accepting or rejecting controls.
- Plan an exit. Test data return, conversion, deconversion, and continuity procedures before a dispute or security event occurs.
- Assess independent monitoring. Managed detection, identity tools, penetration testing, and fraud services can reduce operational risk, but they cannot replace contractual access to the vendor’s telemetry or reassign legal responsibility automatically.
The continuing lesson
Bessemer shows why outsourced cybersecurity disputes are often decided less by broad statements about “secure” platforms than by contracts, technical evidence, causation, and damage allocation. The July 2020 ruling kept the core contract dispute alive while rejecting negligence and unfair-trade theories. Years of discovery followed, and the available public record does not establish a final merits result. For institutions choosing or renewing an online-banking provider, the durable lesson is to specify controls, evidence, cooperation, and loss allocation before an incident makes those terms the center of a lawsuit.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




