All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to US Politics & Policy

Senators Urge Regulators to Bolster Brokerage Customer Protections

Created at 20 Aug · 3:21 PM1 source↑ Market-relevant
IN SHORT

Senators Ron Wyden and Elizabeth Warren are calling on regulators to mandate stronger protections for brokerage customers, citing an increase in account takeover incidents and theft. FINRA has noted a rise in these attacks, often facilitated by compromised login credentials.

Key Numbers

20firms participating in FINRA roundtables

Who's Involved

Ron Wyden
Ranking Democrat on the Senate Finance Committee
Elizabeth Warren
Ranking Democrat on the Senate Banking Committee
FINRA
Financial Industry Regulatory Authority, which issued a notice on account takeovers
David Kelley
Director at FINRA
Greg Markovich
Senior Principal Risk Specialist at FINRA

↳ Why This Matters

The rise in account takeover incidents at brokerages poses a significant risk to individual investors, potentially leading to financial losses and erosion of trust in the financial system. The senators' call for stronger protections aims to address these vulnerabilities.

Key facts

  • Senators Ron Wyden and Elizabeth Warren are pushing for enhanced customer protections at brokerages.
  • An increase in account takeover (ATO) incidents has been reported to FINRA.
  • Compromised login credentials are a primary method used by bad actors to access brokerage accounts.
  • FINRA has highlighted the issue and shared best practices with firms.
  • Firms have regulatory obligations to protect sensitive customer data.
  • Senators Ron Wyden and Elizabeth Warren have called on financial regulators to implement stronger safeguards for customers of online brokerages, citing a significant rise in account takeover (ATO) incidents. These attacks involve unauthorized access to customer accounts using compromised login credentials, leading to potential theft.

    FINRA, the self-regulatory organization overseeing broker-dealers, has noted an increase in such incidents. In a regulatory notice, FINRA outlined that bad actors are exploiting conditions like the widespread use of mobile devices and the availability of stolen login information on the dark web to perpetrate these attacks. Common methods include phishing emails and social engineering.

    FINRA has engaged with 20 firms of varying sizes to discuss effective strategies for preventing, detecting, and responding to ATOs. The organization reminded member firms of their existing regulatory obligations to protect sensitive customer data and reiterated that its notice does not introduce new legal requirements but rather discusses practices firms may consider for their cybersecurity programs. Practices such as recommending password managers to customers were highlighted as potentially effective mitigation strategies.

    Frequently asked questions

    An account takeover incident occurs when unauthorized individuals gain access to a customer's online brokerage account using compromised login credentials, such as usernames and passwords.

    The increase is attributed to more firms offering online accounts, greater use of mobile devices, and the availability of stolen login credentials on the dark web, along with sophisticated attack methods.

    FINRA is monitoring the rise in ATO incidents, providing guidance to firms on best practices for cybersecurity, and reminding them of their regulatory obligations to protect customer data.

    No, FINRA's guidance does not mandate specific practices. Firms are expected to design cybersecurity programs that are reasonably tailored to their individual risk profiles and operations.

    What Happens Next

    01Regulators are expected to review the senators' recommendations for enhanced customer protections.
    02Brokerage firms may consider implementing additional cybersecurity measures to mitigate ATO risks.

    How It Developed

    Senators Ron Wyden and Elizabeth Warren have urged regulators to require brokerages to provide stronger customer protections.
    FINRA has reported an increasing number of customer account takeover (ATO) incidents.
    Bad actors are using compromised customer information, such as login credentials, to gain unauthorized entry to online brokerage accounts.
    The increase in ATOs is partly attributed to more firms offering online accounts, increased mobile device usage, and the availability of stolen credentials on the dark web.
    FINRA has organized roundtable discussions with firms to discuss approaches to mitigating ATO risks.
    FINRA reminds member firms of their obligations to protect sensitive customer data.

    Sources

    T1
    Several Big Brokerages Leave Customer Accounts Open to Theft, Senators SayThe New York Times
    T2
    Wells Fargo Wire Fraud Letterbanking.senate.gov
    T2
    Brown, Reed Push Big Banks to Protect Consumers from Wire Fraud | United States Committee on Banking, Housing, and Urban Affairsbanking.senate.gov
    T2
    Regulatory Notice 21-18 | FINRA.orgfinra.org

    Related Stories

    Senate Democrats question USDA over data errors, staff losses
    20 Aug · 10:06 AM
    Trump Accounts to initially offer S&P 500 ETFs for simplicity, Robinhood CEO says
    20 Aug · 5:00 AM
    FCA warns investors risk life savings with unregulated services
    20 Aug · 8:51 AM
    Tim Scott: Warren’s Team Wants to ‘Run Crypto Out of the Country’ as CLARITY Act Stalls
    20 Aug · 1:00 PM
    Gallego warns rushed CLARITY Act vote could harm crypto legislation
    20 Aug · 4:41 AM