Complaints from Randolph-Brooks Federal Credit Union members who say they were denied reimbursement after impersonation scams are putting a practical fraud-operations question in focus: what evidence proves who actually initiated a transfer?

Credit Union Daily reported on August 4, citing an investigation by San Antonio television station KENS 5, that at least three members said they collectively lost thousands of dollars after callers posing as RBFCU employees prompted them to approve transactions. The report said denial letters reviewed by the station characterized the transactions as authorized because members’ credentials were used.

RBFCU did not disclose the total number of incidents. Its statement to KENS 5 said confirmed impersonation scams increased by an average of 100 additional cases per month during the second quarter, and that its fraud and operations teams were investigating with law enforcement. The credit union had already warned members on June 5 that scammers were spoofing trusted phone numbers and using urgency to move money.

The members’ accounts, the contents of the denial letters and the attorney’s legal position are allegations reported by KENS 5 and Credit Union Daily. CreditUnionAI News has not reviewed the underlying transaction records, and the public evidence does not establish whether each transfer was initiated by a member or by a third party using information obtained through deception. That distinction is central.

Credentials do not answer every authorization question

The Consumer Financial Protection Bureau’s Regulation E FAQs say an electronic fund transfer initiated by a third party using credentials fraudulently obtained from a consumer can meet the definition of an unauthorized EFT. The Bureau gives the specific example of an impersonator who tricks a consumer into providing login information, a texted confirmation code or debit-card data and then uses that information to make a transfer.

The same guidance says consumer negligence cannot be used to impose greater liability than Regulation E permits. It also requires a prompt, reasonable investigation that reviews relevant information in the institution’s own records. The current text of 12 CFR Part 1005 defines an unauthorized EFT around who initiated the transfer and whether that person had actual authority—not simply whether a correct password or one-time code appeared in the process.

That does not mean every scam-induced payment is automatically unauthorized. A member may personally initiate a transfer after being deceived, while a fraudster in another case may initiate it after capturing access information. A member may also approve a security prompt without understanding that it authorizes a new payee or outgoing transfer. Fraud and compliance teams need to reconstruct the event before applying the rule.

A defensible investigation needs an evidence map

A claim file should separate identity evidence from transaction-initiation evidence. Successful credentials, device possession and a completed challenge establish facts, but they do not by themselves show what the member understood or who executed the transfer. Investigators should preserve the login session, device and IP history, payee-creation record, transfer-initiation event, challenge language, delivery channel, call notes, credential-reset activity and the member’s reporting timeline.

Teams should then document the decision path in plain language: who created the recipient, who entered the amount, what the authentication prompt actually said, whether a new device or location was involved, what happened during the call and which evidence supports actual authority. A denial reason based only on credential use risks collapsing several different questions into one.

The operating response also starts before a claim. After-hours reporting should let a member freeze access or a suspicious transfer without waiting for a staffed fraud desk. High-risk changes—new devices, new external recipients and unusually large transfers made during an active inbound call—can trigger a cooling period, independent callback or additional review. Confirmation messages should state the amount, destination and consequence clearly rather than ask for an ambiguous “yes.”

What credit unions should do now

Fraud, payments, contact-center and compliance leaders should sample recent impersonation claims and test whether the case record can answer five questions: who initiated the transfer; how access was obtained; what the member saw and approved; what contradictory signals were reviewed; and how the final Regulation E conclusion follows from those facts. Legal counsel should review the framework against the institution’s products, state law and current regulatory guidance.

Leaders should also track more than gross fraud loss. Useful measures include time from member report to account containment, percentage of cases with complete device and session evidence, reversals after appeal, complaint themes and the false-positive impact of new controls. Those measures connect prevention, investigation quality and member recovery.

The RBFCU reports are a reminder that scam detection and claim resolution are one operating system. Credit unions adding faster response tools, such as those examined in CreditUnionAI News coverage of near-real-time card-fraud controls, should design the evidence trail at the same time. The same principle applies to the AI-enabled identity and mule-account patterns flagged by FinCEN: a risk signal begins the investigation; it does not replace one.