Quick Answer: A Florida credit union is suing its online banking vendor for alleged security failures—including using email passcodes instead of proper multi-factor authentication. This lawsuit reveals that even the financial institutions we trust are fighting their own battles to keep our money safe. Your job: stay vigilant, monitor your accounts, and don’t assume any institution is impenetrable.
While you’re watching your own accounts for fraud, your bank or credit union is fighting a war you never see—against the very vendors they hired to protect you.
A new federal lawsuit exposes just how messy that fight can get.
The Lawsuit: Credit Union vs. Online Banking Vendor
FiCare Federal Credit Union, a Florida-based institution serving federal employees, has filed suit against Fiserv, one of the largest financial technology companies in the world. The allegations paint a troubling picture of what can happen behind the scenes at financial institutions.
According to the complaint filed January 27, 2026:
The Daily Money Brief — Free, at 10 AM
Money you may be owed, scams to dodge, and the fine print decoded — the consumer money news that affects your wallet, every weekday.
- Fiserv’s online banking platform allegedly used email passcodes instead of proper multi-factor authentication—a security practice experts consider inadequate
- The vendor allegedly misrepresented its security capabilities during the sales process
- When the credit union tried to address security concerns, Fiserv allegedly tried to upsell a “SecureNow” add-on product
- Termination fees reportedly reach into the seven figures—trapping institutions in contracts even when dissatisfied
Important: These are allegations in a lawsuit, not proven facts. Fiserv has not yet responded to the complaint. This article is about what the case reveals about vendor relationships—not a judgment on either party.
Why This Matters to You
You probably don’t think about your bank’s vendors. You shouldn’t have to. But this lawsuit illustrates something important: financial security is a multi-front war.
Your financial institution isn’t a fortress—it’s a network of relationships:
- Online banking platforms (like the one in this lawsuit)
- Payment processors
- Mobile app developers
- Data storage providers
- Security monitoring services
Each relationship is a potential vulnerability. Each vendor makes promises. And sometimes, according to lawsuits like this one, those promises don’t hold up.
The Reality: Your credit union or bank can do everything right internally and still face problems from a vendor’s security gaps. That’s why YOUR vigilance is the last line of defense.
What You Should Do
You can’t control your bank’s vendor relationships. But you can control your own vigilance:
- Monitor your accounts weekly. Don’t wait for monthly statements. Check transactions regularly—ideally through your institution’s app or website, not third-party aggregators.
- Set up transaction alerts. Most banks and credit unions offer text or email alerts for transactions over a certain amount. Use them.
- Use strong, unique passwords. If your bank’s vendor has weak security, at least make sure YOUR access isn’t the weak link.
- Enable real multi-factor authentication. If your institution offers authenticator app-based MFA (not just email or SMS codes), use it.
- Watch for data breach notifications. If your institution notifies you of a security incident, take it seriously. Change passwords, monitor accounts, consider a credit freeze.
The Bigger Picture on Financial Security
This lawsuit is a reminder that financial security isn’t just about watching for Nigerian prince emails or phishing texts. It’s about understanding that the entire system—from your behavior to your bank’s choices to their vendors’ practices—creates your overall protection.
Your bank or credit union is (hopefully) fighting for you. But they’re also locked into contracts, dealing with vendors who may overpromise, and navigating a technology landscape that changes faster than contracts can keep up.
What Financial Institutions Do
- Vet vendors (though clearly not always successfully)
- Monitor for fraud patterns
- Maintain regulatory compliance
- Provide fraud protection and dispute resolution
What They Can’t Control
- Every vendor’s actual security practices
- Data breaches at third parties
- Whether vendor promises match reality
- Your personal security habits
If You’re a Credit Union Member
Credit unions are member-owned, which theoretically gives you more voice than at a big bank. If you’re concerned about your credit union’s security practices:
- Ask about their online banking vendor and security practices
- Attend member meetings where you can raise questions
- Review their annual reports for technology investments
- Consider whether they offer modern security features (biometric login, authenticator app MFA, real-time alerts)
You have a right to know how your money is being protected.
Key Takeaways
- Financial institutions rely on vendors for critical services like online banking
- Vendor security problems can affect you even if your bank does everything right
- A Florida credit union is suing its online banking vendor over alleged security failures
- Your vigilance—monitoring accounts, using strong authentication, watching for breaches—is your best protection
- Credit union members can ask questions and advocate for better security
Sources
- CourtListener — FiCare Federal Credit Union v. Fiserv Solutions, LLC, Case 8:26-cv-00231 (M.D. Fla.)
- FTC — Credit freezes and fraud alerts guidance
FAQ
Is my money safe at my credit union or bank?
Your deposits are federally insured (FDIC for banks, NCUA for credit unions) up to $250,000. This lawsuit is about security practices, not deposit safety. Your money is protected by insurance even if there’s a security incident.
What is Fiserv?
Fiserv is one of the largest financial technology companies in the world, providing services to thousands of banks and credit unions. They process payments, provide online banking platforms, and offer other financial technology services. This lawsuit involves their “Virtual Branch Next” online banking product.
Should I leave my credit union because of this lawsuit?
This lawsuit involves one specific credit union and one specific vendor. It doesn’t mean all credit unions have security problems. Focus on whether YOUR institution offers strong security features and responds appropriately to security concerns.
What is multi-factor authentication and why does it matter?
Multi-factor authentication (MFA) requires two or more verification methods to access your account—typically something you know (password) plus something you have (phone app code) or something you are (fingerprint). Email-based codes are considered weaker because email accounts themselves can be compromised.
How do I know if my bank’s online banking is secure?
Look for: authenticator app-based MFA (not just SMS or email codes), biometric login options, real-time transaction alerts, and quick response when you report suspicious activity. If your institution only offers basic password protection, that’s a concern worth raising with them.
Dealing With Debt? Understanding your options is the first step. See how all your debt relief options compare — including ones most sites won’t tell you about. The Find Your Path quiz gives a recommendation based on your actual numbers, and the Scam-O-Meter checks any company’s complaint history before you sign. Federal Reserve research shows bankruptcy filers recover faster than those who don’t file.