Court filing
Exhibit 2 — In re Bank of America California Unemployment Benefits Litigation (Dkt. 324-5, S.D. Cal. No. 3:21-md-02992)
Filed August 29, 2024 in In re Bank of America California Unemployment Benefits Litigation; one of 1415 filings from this case.
Record facts
| Court | U.S. District Court for the Southern District of California |
|---|---|
| Filed | 2024-08-29 |
U.S. District Court for the Southern District of California · No. 3:21-md-02992-GPC-MSB · Doc. 324-5 · 2024-08-29 · Docket on CourtListener
Full text
Exhibit 2
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6631 Page
1 of 59
1
UNITED STATES DISTRICT COURT
SOUTHERN DISTRICT OF CALIFORNIA
IN RE BANK OF AMERICA CALIFORNIA
UNEMPLOYMENT BENEFITS
LITIGATION
Case No. 3:21-md-02992-GPC-MSB
EXPERT REPORT OF JANE CLONINGER
IN SUPPORT OF PLAINTIFFS’ MOTION FOR CLASS CERTIFICATION
August 29, 2024
REDACTED PUBLIC VERSION
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6632 Page
2 of 59
ii
TABLE OF CONTENTS
I. ASSIGNMENT ............................................................................................................................ 1
II. SUMMARY OF EXPERT QUALIFICATIONS ........................................................................ 4
III. HOURLY RATE ....................................................................................................................... 4
IV. FACTS AND DATA CONSIDERED ....................................................................................... 4
V. SUMMARY OF OPINIONS ...................................................................................................... 5
VI. STATEMENT OF OPINIONS AND BASIS FOR OPINIONS ............................................... 7
A. Mag-Stripe Only Cards Are Highly Vulnerable to Skimming and Card-Present
Counterfeit Fraud .................................................................................................................. 7
B. EMV Chips Prevent Card-Present Counterfeit Fraud ......................................................... 14
C. By 2019, EMV Chips Were the Industry Standard for Credit and Debit Card Security .... 18
D. The Bank’s Failure to Include EMV Chips in its EDD Debit Cards Was
Inconsistent with Industry Standards and Caused EDD Debit Cards to Be
Vulnerable to Counterfeit Card Fraud ................................................................................. 24
E. The Bank’s Decision to Not Include EMV Chips in EDD Debit Cards as of
Early 2020 Was Inconsistent with Other Participants in the Payments Industry ................ 25
F. It Was Highly Foreseeable that the Bank’s Failure to Include EMV Chips in EDD
Debit Cards Would Lead to Counterfeit Fraud Targeting EDD Debit Cardholders
During the Pandemic, Because Fraud Migrates to the Weakest Link ................................. 34
G. Any Financial Institution in the Bank’s Situation Would Have Known that Many
EDD Cardholders Who Reported Unauthorized PIN-Enabled ATM Withdrawals
Were True Victims of Counterfeit Fraud ............................................................................ 40
VII. CONCLUSION ...................................................................................................................... 43
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6633 Page
3 of 59
1
I.
ASSIGNMENT
1.
I have been retained as an expert in this matter by co-lead counsel for Plaintiffs,
Cotchett, Pitre & McCarthy, LLP and Altshuler Berzon LLP (collectively, “Plaintiffs’ Counsel”),
and I submit this Report in support of Plaintiffs’ Motion for Class Certification.
2.
Plaintiffs’ Counsel have informed me that from 2011 to approximately February
15, 2024, the Bank had an exclusive contract with California’s Employment Development
Department (“EDD”) to distribute unemployment insurance (“UI”), disability insurance, and
paid family leave benefits to Californians through Bank-issued prepaid debit cards (“EDD debit
cards”).1 Prior to July 2021, all EDD debit cards were “mag-stripe only” debit cards that did not
contain an “EMV” chip (terms explained below).2
3.
Plaintiffs’ Counsel asked me to provide my expert opinion with respect to certain
issues relevant to this litigation, including but not limited to:
a. Whether Bank of America’s (the “Bank’s”) failure to embed EMV chips in its
EDD debit cards between March 2020 and June 2021 was consistent with industry
standards for debit card security;
b. Whether the Bank’s failure to include EMV chips in its EDD debit cards between
March 2020 and June 2021 foreseeably rendered those cards vulnerable to card
skimming attacks and card-present counterfeit card fraud, including unauthorized
withdrawals at Automated Teller Machines (“ATMs”);
1 Ex. 15 (Depo. Tr. of the Bank’s Rule 30(b)(6) Designee Robert Chestnut (“Chestnut Tr.”))
54:19-24, 75:8-13, 76:3-7, 129:2-13. “Ex. __” in this Report refers to the exhibits attached to the
Declaration of Connie K. Chan in Support of Plaintiffs’ Motion for Class Certification (“Chan
Decl.”).
2 Ex. 16 (Depo. Tr. of the Bank’s Rule 30(b)(6) Designee William Matthew Martin (“Martin
Tr.”)) 65:4-14.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6634 Page
4 of 59
2
c. Whether card skimming results in the unauthorized access and exfiltration, theft,
or disclosure of the cardholder’s personal information;
d. Whether inclusion of EMV chips in EDD debit cards would have prevented EDD
debit cardholders from being subject to card skimming and counterfeit card fraud
between March 2020 and June 2021, including fraud committed through
unauthorized ATM withdrawals; and
e. Whether, between late September 2020 and June 2021, it would have been
reasonable for the Bank to assume that all or almost all EDD debit cardholders
who reported an unauthorized ATM withdrawal were likely fraudsters making
false reports, rather than actual victims of counterfeit card fraud.
II.
SUMMARY OF EXPERT QUALIFICATIONS
4.
I have over 35 years of experience working in financial services, specifically in
the payments industry, which coordinates the exchange of money for goods between customers,
businesses, and financial institutions. My primary focus within the payments sector has been on
product innovation for credit and debit cards, including EMV chips, contactless and mobile
payments.
5.
From 1982 to 1985, I worked for First Interstate Bancorp in its strategic planning
group. In 1985, I joined Edgar, Dunn & Company, a consulting firm with particular expertise in
the payments sector. In 2017, I joined Accenture, a large global technology and strategy
consulting firm, as a Senior Managing Director in its payments industry practice. I largely
retired in February 2019 but continue to work as an independent consultant.
6.
In those capacities, I have gained expertise in the economic and operational
aspects of the payments industry. I have assisted clients in preparing product roadmaps, strategic
plans, and business cases (justifications for proposed projects based on expected commercial
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6635 Page
5 of 59
3
benefit) for new products and technology investments, including EMV chips. I have completed
numerous client projects involving multiple payment methods such as credit, debit, prepaid, and
person-to-person payments. My consulting experience includes advising clients on the use of
mobile payments and contactless cards and conversion to EMV chip cards.
7.
Between approximately 2004 and 2015, my focus was on the business
implications of EMV chip technology. I worked with Interac (Canada’s debit network) to
develop the business case for EMV migration for the debit in Canada. I also worked with
MasterCard and Visa in the U.S. to develop industry-wide business cases for both debit and
credit cards in the U.S. My work involved creating models that captured the costs (including chip
and card production costs, point of sale terminal, and ATM upgrade or replacement costs, and
expenses related to changes to software) and the benefits (primarily reduction of card-present
counterfeit fraud) for each of the major constituents of the payments landscape: issuers,
acquirers, ATM operators, merchants, networks, and processors.3 I also developed fraud
3 An issuer is a financial institution that provides payment cards, credit, debit or pre-paid, to their
consumer customers. Issuer responsibilities include marketing their card products, underwriting
the credit risk of each applicant, processing cardholder purchase requests, and managing the
cardholder account (e.g. maintaining a record of transactions, payments, balance outstanding,
etc.).
An acquirer is a financial institution that provides processing and settlement services to
merchants/businesses. Acquirers enter into contracts with merchants to provide payment
processing services. They maintain the merchant’s account record (including individual
transaction details), submit daily settlement to the network, and process the incoming receipt of
funds to ensure that they are accounted appropriately. Acquirers are also responsible for
underwriting each of their merchant customers.
An ATM operator is the Financial Institution or independent operator responsible for the
management of the ATM, including providing services such as loading cash, ATM maintenance,
ATM ownership and leasing.
Merchants provide goods and services to cardholders and submit card transactions to their
acquirer for payment. Merchants are the customers of the acquirers.
Networks, also known as brands, card networks, or payment schemes, provide the infrastructure,
rules, and standards necessary to process payments. They connect all the players, oversee the
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6636 Page
6 of 59
4
forecasts for the status quo (no EMV chips) and for the transition to the use of EMV chips for
each business case. My work informed my clients’ decisions regarding EMV conversion.
8.
I have spoken at numerous industry conferences on topics related to payment card
innovation including EMV chip technology as well as other developments related to adoption of
contactless and mobile payments.
9.
I have an MBA from UCLA’s Anderson School of Management in Los Angeles
and a BS in Economics from University of Tennessee in Knoxville.
10.
A true and correct copy of my current curriculum vitae (CV), which includes a list
of all publications I have authored or co-authored in the last 10 years and a list of all other cases
in the last four years in which I have testified as an expert at trial or by deposition, is attached as
Appendix A.
III.
HOURLY RATE
11.
I am being compensated at a rate of $450 per hour for my work in this matter. My
compensation is not contingent on the nature of my opinions or on the outcome of this litigation.
IV.
FACTS AND DATA CONSIDERED
12.
In preparing this report and forming the opinions expressed herein, I considered
documents, testimony, and information produced in discovery in this litigation as well as
publicly available documents and information and my general knowledge, training, and
experience from over 30 years in the payments industry. The specific materials I considered are
cited in this report and in the attached Appendix B.
payment processing activity, monitor the settlement of transactions, and regulate and manage the
corresponding compliance policies. The network has commercial relationships only with the
issuer and the acquirer. In this case the network is Visa.
Processors manage the systems that process card transactions on behalf of their customers, either
issuers or acquirers. They handle the technical aspects of authorizing, clearing and settling
transactions between acquirers and issuers, and manage the corresponding compliance.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6637 Page
7 of 59
5
13.
My work on this case is ongoing, and I may review additional materials or
conduct further analysis. I reserve the right to update, refine, or revise my opinions as
appropriate including if additional information becomes available to me.
V.
SUMMARY OF OPINIONS
14.
Based on my general knowledge, training, and over 35 years of industry
experience, my review and analysis of documents produced by the Bank in this litigation and
documents publicly available, and my review of the deposition testimony of the Bank’s Rule
30(b)(6) designees, it is my opinion that:
a. Payment cards that have only a magnetic stripe to hold cardholder information
and not an EMV chip (“mag-stripe only cards”), including the Bank’s EDD debit
cards at issue in this litigation, are highly vulnerable to card skimming and card-
present counterfeit fraud.
b. The EMV standards, released in 1996, were designed to prevent card-present
counterfeit fraud related to mag-stripe only cards, and EMV chips are highly
effective at preventing card-present counterfeit fraud.
c. By 2019, the use of EMV chips was already an industry-standard security
measure throughout the U.S. debit card market, including for debit cards used for
the administration of government benefits.
d. The Bank’s failure to include EMV chips in its EDD debit cards was inconsistent
with industry standard practices and caused those cards to be less secure and more
vulnerable to skimming and card-present counterfeit card fraud (including
unauthorized ATM withdrawals) than debit cards with embedded EMV chips.
e. The Bank’s failure to include EMV chips in its EDD debit cards created an
inferior level of card security for EDD debit cardholders compared to the level of
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6638 Page
8 of 59
6
card security the Bank provided to its non-prepaid consumer and business credit
and debit cardholders, to whom the Bank issued EMV chip cards from 2014
onward.
f. Given the well-known fact that criminals probe for security weaknesses and
exploit vulnerabilities they identify, and that by 2020 it was well documented that
fraud had begun to concentrate on mag-stripe only cards, it was highly
foreseeable that card-present counterfeit fraud (including unauthorized ATM
withdrawals) targeting EMV chip-less Bank-issued EDD debit cards would
continue to increase during 2020. Because prepaid cards with high balances and
low security are particularly attractive to criminals and because the COVID-19
pandemic was projected to result in a large increase of the EDD debit card load, it
was also highly foreseeable that fraud targeting EDD cards would continue to
increase during the pandemic.
g. Card skimming results in the unauthorized access and exfiltration, theft, or
disclosure of the cardholder’s personal information.
h. The addition of EMV chips to the Bank’s EDD debit cards would have prevented
virtually all card-present counterfeit fraud (including unauthorized ATM
withdrawals) for the Bank’s EDD debit cardholders at chip-enabled ATMs and
POS terminals, which were the overwhelming majority of ATMs and POS
terminals by 2020.
i. Any major financial institution in the Bank’s situation in 2020-21 would have
known that many EDD debit cardholders who reported unauthorized ATM
withdrawals during the pandemic were true victims of card skimming and/or card-
present counterfeit card fraud.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6639 Page
9 of 59
7
VI.
STATEMENT OF OPINIONS AND BASIS FOR OPINIONS
A.
Mag-Stripe Only Cards Are Highly Vulnerable to Skimming and Card-
Present Counterfeit Fraud.
15.
Prior to July 2021, all Bank-issued EDD debit cards were mag-stripe only debit
cards.4
16.
IBM created the first mag-stripe card in the 1960s.5 IBM essentially attached
magnetic recording tape, invented in Germany in the 1920s, to a card, which was originally used
for entry control.6 In 1970, American Express was the first to use mag-stripe cards for payments,
using the magnetic recording tape to store personal information regarding the cardholder,
including the cardholder’s name, and credit card number, and data relevant to the payment, such
as the card expiration date.
17.
Mag-stripe payment cards typically have three tracks on the mag-stripe. Tracks 1
and 2 are used to store data specified by the card brand (e.g., Visa) in pre-specified formats,
while Track 3 is used primarily for additional information specified by the issuer.7 The data on
the three tracks does not change from one transaction to the next and is easily readable.8 The
4 Ex. 16 (Martin Tr.) 65:8-14.
5 See The Magnetic Stripe, IBM, https://www.ibm.com/history/magnetic-
stripe#:~:text=Parry%20helped%20develop%20the%20Universal,It%20worked (last accessed
Aug. 7, 2024).
6 See Vicki Hyman, Swiping Left on Magnetic Stripes, VISA Newsroom (Aug. 12, 2021),
https://www.mastercard.com/news/perspectives/2021/magnetic-stripe/.
7 See Jerome Svigals, The Long Life and Imminent Death of the Mag-Stripe Card, IEEE
Spectrum (May 30, 2012), https://spectrum.ieee.org/the-long-life-and-imminent-death-of-the-
magstripe-card.
8 See id.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6640 Page
10 of 59
8
Motley Fool, a private investment advisory firm for individuals, has described the process as
follows:9
Cards […] store all pertinent data on the magnetic stripe on the back of the
card, including the cardholder's name, credit card number, expiration date,
and CVV number. Once the information is written on this stripe, however,
it is forever static, meaning it will never change.
18.
Card-present counterfeit fraud occurs when criminals use a cloned card to make
purchases or ATM withdrawals that are charged to the real cardholder’s account. Criminals
obtain the card data through various scams including a process called “skimming.” Skimming
occurs when criminals use devices that surreptitiously read and store the mag stripe data, which
is static and unencrypted. The individuals later retrieve and use the stolen data to manufacture
counterfeit or “cloned” cards.
19.
Skimming devices are often used in conjunction with pinhole cameras or PIN pad
overlays, which capture the Personal Identification Number (“PIN”) as the unsuspecting
cardholder enters it into the payment terminal or ATM. Using this data, the criminal can
manufacture counterfeit cards to make unauthorized purchases or ATM withdrawals.
20.
The following graphic from the FBI identifies several common skimming devices
and where they would typically be placed on an ATM:10
9 Matthew Cochrane, Why U.S. Counterfeit Credit Card Fraud Is Down 75%, Motley Fool (Sept.
17, 2018, 5:11 PM), https://www.fool.com/investing/2018/09/16/why-us-counterfeit-credit-card-
fraud-is-down-75.aspx.
10 Taking a Trip to the ATM, Beware of ‘Skimmers’, FBI News (July 14, 2011),
https://www.fbi.gov/news/stories/atm-skimming.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6641 Page
11 of 59
9
FBI Overview of ATM Skimming
21.
Pinhole cameras (Item 1 on the FBI’s Overview of ATM Skimming) are very
small and are often disguised in side panels or trim pieces attached to the ATM. Below is an
example of what a pinhole camera looks like:11
11 Photos: How to Detect Skimming Devices on ATM’s [sic], CBS21 News (March 15, 2018,
10:50 AM), https://local21news.com/news/local/photos-how-to-detect-skimming-devices-on-
atms.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6642 Page
12 of 59
10
Pinhole Camera Example:
22.
Item 2 on the FBI’s Overview of ATM Skimming describes a skimmer, the device
that reads the mag stripe and captures the card details for the criminal to gather later after
collecting details from many cards.12 Below is an example of a card skimmer, installed and
partially opened: 13
ATM Card Skimmer, Installed and Partially Opened
Appearance of skimmer from outside
ATM.
The skimmer overlay when
removed.
12 See Taking a Trip to the ATM, Beware of ‘Skimmers’, FBI News (July 14, 2011),
https://www.fbi.gov/news/stories/atm-skimming.
13 See Brian Krebs, Why I Always Tug on the ATM, Krebson Security (March 31, 2017),
https://krebsonsecurity.com/2017/03/why-i-always-tug-on-the-atm/.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6643 Page
13 of 59
11
23.
A PIN pad overlay (Item 3 on the FBI’s Overview of ATM Skimming above)14 is
an alternative to using a pinhole camera. It is inserted over the real PIN pad and captures the
PIN number using the sensors on the back side of the device. Below is an example of a PIN pad
overlay.15
Example of Pin Pad Overlay
24.
The skimmers, PIN pad overlays, and pinhole cameras are very realistic, making
them very hard to spot. The picture below depicts an ATM that is compromised compared to one
that has not been compromised, showing how hard it may be to spot the skimming and PIN
capture devices: 16
14 Taking a Trip to the ATM?: Beware of ‘Skimmers’, FBI News (July 14, 2011),
https://www.fbi.gov/news/stories/atm-skimming.
15 Understanding Card Skimmers and How to Protect Yourself, Los Angeles County Consumer &
Business Affairs (April 17, 2023), https://dcba.lacounty.gov/newsroom/understanding-card-
skimmers-and-how-to-protect-yourself/ (attributing the photo to Sean Cooper, What You Need to
Know About Card Skimming, Engaget (July 28, 2014), https://www.engadget.com/2014-07-28-
credit-card-skimming-explainer.html).
16 ATM Skimming Gets a Tech Upgrade, PYMTS (Sept. 18, 2017),
https://www.pymnts.com/news/security-and-risk/2017/atm-skimming-gets-a-tech-upgrade/.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6644 Page
14 of 59
12
Card Skimmer on ATM
25.
Once the criminal has implanted the skimmer and PIN pad overlay or camera, the
skimmer records the information from the mag-stripe while the PIN pad overlay or camera
captures the PIN.17 The criminal can then use this information to create a counterfeit card, which
functions the same as the original mag-stripe only card and can be used in conjunction with the
stolen PIN to make fraudulent card-present transactions, including unauthorized ATM
withdrawals.18
26.
Counterfeit fraud due to skimming has long been a well-known problem
throughout the payment services industry and law enforcement. Skimmers have been used since
as early as December 2002,19 but “ATM skimming really began to take off globally in 2010 with
the large-scale production of skimming devices, especially the wireless variety.”20 When “3-D
printing came along in 2011, high-quality skimming devices became even simpler to produce,
17 See Taking a Trip to the ATM?: Beware of ‘Skimmers’, FBI News (July 14, 2011),
https://www.fbi.gov/news/stories/atm-skimming.
18 See What Is Credit Card Fraud?, Equifax, https://www.equifax.com/personal/education/credit-
cards/articles/-/learn/credit-card-fraud/.
19 Sue Chan, Is Your Credit Card Being Skimmed?, CBS News (Dec. 6, 2002, 3:46 PM),
https://www.cbsnews.com/news/is-your-credit-card-being-skimmed/.
20 Yossi Geller, ATM Fraud: The Evolution of An Epidemic, ATM Marketplace (Dec. 13, 2016),
https://www.atmmarketplace.com/articles/atm-fraud-the-evolution-of-an-epidemic/.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6645 Page
15 of 59
13
with razor-thin Bluetooth-compatible versions replacing clunky overlays.”21 ATM Marketplace,
an ATM industry news and information website, reported in 2016: “ATM skimming is a growing
epidemic that shows no sign of slowing.”22 Fair Isaac Corporation (“FICO”) reported a six-fold
increase in compromises of ATMs and merchant devices in the United States in 2015 and
predicted continuing increases: “As the last few years have proven, skimming technology and
knowhow have improved and are more accessible to the general population, so we will continue
to see increases in compromises and the speed at which they occur.”23
27.
Counterfeit fraud is a significant problem. In 2015, the Nilson Report, a
payments industry newsletter, estimated total U.S. counterfeit fraud to be $3.89 billion.24 This
number includes data stolen from multiple points of compromise including skimming as well as
data breaches.25 The FBI has estimated that skimming alone “costs financial institutions and
consumers more than $1 billion each year.”26
28.
Through skimming, criminals gain access to all information stored on the
magnetic stripe, including the cardholder’s unencrypted personal information, such as name and
card number. Skimming thus presents one well-documented means of unauthorized access and
theft of unencrypted personal information.
21 Id.
22 Id.
23 FICO Reports a 70 Percent Rise in Debit Cards Compromised at U.S. ATMs and Merchants in
2016, Fraud Protection & Compliance, FICO (Mar. 29, 2017),
https://www.fico.com/en/newsroom/fico-reports-70-percent-rise-debit-cards-compromised-u-s-
atms-and-merchants-2016.
24 Global Card Fraud Losses Reach $16.31 Billion – Will Exceed $35 Billion in 2020 According
to The Nilson Report, Business Wire (Aug. 4, 2015, 7:49 PM),
https://www.businesswire.com/news/home/20150804007054/en/Global-Card-Fraud-Losses-
Reach-16.31-Billion#.VgDIZRFViko; Card Fraud Losses Reach $16.31 Billion, Nilson Report
(August 2015), https://nilsonreport.com/articles/card-fraud-losses-reach-16-31-billion/.
25 Card Fraud Losses Reach $16.31 Billion, Nilson Report (August 2015),
https://nilsonreport.com/articles/card-fraud-losses-reach-16-31-billion/.
26 How We Can Help You, Skimming, FBI, https://www.fbi.gov/how-we-can-help-you/scams-
and-safety/common-scams-and-crimes/skimming (last visited Aug. 1, 2024).
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6646 Page
16 of 59
14
B. EMV Chips Prevent Card-Present Counterfeit Fraud.
29.
EMV chips prevent card-present counterfeit fraud by creating a dynamic code,
often called a dynamic CVV code, that is unique to each transaction.27 The EMV chip uses
information provided by the Point of Sale (“POS”) terminal (for example the terminal
ID/location or amount of purchase) as well as data from the card (for example, the cardholder
name, account number, or expiration date) to create an encrypted code that is unique to each
transaction. The dynamic CVV code is then included in the authorization request cryptogram
created by the card and in the authorization response cryptogram returned from the issuer. EMV
uses public/private key encryption to encrypt and decrypt these message components ensuring
that only the legitimate issuer and legitimate chip can create and validate the data. The dynamic
CVV code provides a means for the issuer to validate the transaction before authorization.28
30.
When the issuer receives the electronic request for authorization from the
terminal, the issuer can immediately confirm based on the codes provided whether the card has
an embedded EMV chip, and whether the data in the authorization request came from that chip
or from the mag-stripe. If use of the mag-stripe is detected, the dynamic CVV code will not be
correct, and the issuer can decline the transaction in order to avoid the losses associated with any
fraud related to that transaction.29 The correct dynamic CVV code cannot be successfully
27 The term “EMV” is derived from the names of the original collaborators who developed the
EMV standards governing all EMV chips—EuroPay, MasterCard and Visa (EuroPay later
merged with MasterCard). EMVCo is the organization responsible for managing the EMV
standards as well as other global payment security standards. EMVCo is governed by the
payment networks and payment industry participants. See generally The Role of the EMV®
Specifications, EMVCo (Mar. 18, 2020), https://www.emvco.com/knowledge-hub/the-role-of-
the-emv-specifications-2/.
28 See generally EMV At a Glance, EMVCo (2022), https://www.emvco.com/wp-
content/uploads/2022/09/EMV%C2%AE-Chip-At-A-Glance-EMVCo-eBook.pdf; A Guide to
EMV Chip Technology, EMVCo (Nov. 2014), https://www.fisglobal.com/-
/media/fisglobal/WorldPay/Docs/Insights/A-Guide-to-EMV-Chip-Technology.pdf.
29 See infra ¶¶ 39-40 (describing liability shift rules).
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6647 Page
17 of 59
15
created without a legitimate EMV chip which is used in conjunction with an EMV capable
terminal to create the proper dynamic CVV code.
31.
EMV chip cards still include the traditional mag stripe, and criminals have
developed methods to try to create a counterfeit mag-stripe only version of EMV chip cards. But
it is virtually impossible to clone the EMV chip itself, and a counterfeit mag-stripe only version
of an EMV chip card cannot be used successfully in any terminal that has a chip reader (which
includes virtually all ATMs and the vast majority of point-of-sale terminals).30 If a counterfeit
mag-stripe only version of an EMV chip card is swiped so that the EMV capable terminal reads
the mag-stripe, the mag-stripe on the card transmits a code to the terminal which indicates that a
chip has been embedded on the card. The terminal will then reject the card and will request that
the cardholder insert the chip into the chip reader to complete the transaction. Without the EMV
chip creating the dynamic CVV, the counterfeit mag-stripe only card cannot be used to make
card-present transactions at chip-enabled terminals.
32.
In April 2018, a study by the ATM Industry Association found that “[t]he vast
majority (91 percent) of U.S. ATMs are now EMV-capable, and fully 86 percent accept chip-on-
chip transactions.”31 Thus, by early 2018, most ATMs in the United States required the use of an
30 The exception is when an ATM owner or merchant allows fallback (use of the mag-stripe on a
chip enabled card) when a chip card cannot be read. In this case the liability shifts back to the
ATM owner or merchant. In order to limit the practice of allowing fallbacks, both Visa and
MasterCard impose fines for excessive fallback transactions. To avoid fallback fees, fallback
rates must be below 2.5% for Visa and 3% for Mastercard. See EMV Implementation Guidance:
Fallback Transactions, US Payments Forum (2016), https://www.uspaymentsforum.org/wp-
content/uploads/2017/03/Fallback-Transaction-Guidance-FINAL-Dec-2016.pdf. See also: ATM
Fallback Fees, and How to Prevent Them, Premier Merchants Group, LLC (Mar. 23, 2021),
https://pmgcom.com/2021/03/23/atm-fallback-fees-and-how-to-prevent-them/.
31 Nearly All US ATMs Now EMV-Capable, Study Finds, ATM Marketplace (April 6, 2018),
https://www.atmmarketplace.com/news/nearly-all-us-atms-now-emv-capable-study-finds/. The
five percent gap between EMV-capable and ATMs prepare to accept chip-on-chip transactions
“represents the lag in certification and testing” required to ready an EMV-capable ATM for chip-
on-chip transactions.” ATM Industry Association, 2018 ATMIA EMV Migration Survey:
Executive Summary (2018), available at https://www.atmmarketplace.com/.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6648 Page
18 of 59
16
EMV chip at an ATM when an EMV chip is present on the card, and even more were to be
certified and tested to do so shortly.
33.
Because EMV chips cannot be successfully counterfeited and are required to
create the correct dynamic CVV, card-present counterfeit fraud can be effectively prevented by
including EMV chips on credit, debit and ATM cards. As Javelin Consulting reports: “Chip
cards have proven to lower fraud at the point of sale as they effectively eliminate
counterfeiting. They cryptographically prevent criminals from forging the plastic and using
those fake cards at merchant locations.”32
34.
The use of EMV chips has successfully and significantly reduced fraud around the
world, as the examples in the chart below show:
Country
Time
Counterfeit Fraud Change
Comments
UK
Debit & Credit
Full
Implementation
(>90%)33
2008 -
2019
↓90%34
“Counterfeit card losses totaled
£16.3 million in 2018, a decrease
of 33 per cent compared to 2017
and 90 per cent lower than the
peak reported in 2008 (£169.8
million).”35
32 From Application to Transaction: Card Fraud Trends, Threats, and Tactics, JAVELIN at 6
(April 2018), https://javelinstrategy.com/sites/default/files/files/reports/18-5006J-FM-
From%20Application%20to%20Transaction-FIS.pdf (emphasis added).
33 Alex Rolfe, US Market Hits 1 Billion EMV Chip Cards Milestone, Payments Cards & Mobile
(June 1, 2020), https://www.paymentscardsandmobile.com/us-market-hits-1-billion-emv-chip-
cards-milestone/.
34 Fraud the Facts 2019, UK Finance at 17 (2019),
https://www.ukfinance.org.uk/system/files/Fraud%20The%20Facts%202019%20-
%20FINAL%20ONLINE.pdf.
35 Id.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6649 Page
19 of 59
17
Country
Time
Counterfeit Fraud Change
Comments
Canada
Debit
Full
Implementation
(>90%)36
2008 -
2015
↓92%37
Canada began its chip-and-PIN
conversion in 2008 and
completed the debit card
conversion in 2012. Debit fraud
losses from skimming peaked at
CA$142.3 million in 2009, but by
2015 are down by 92%.38
US
Partial
Implementation
Debit & Credit
(~80%)
2015 -
2019
↓87% at EMV merchants
↓62% at all US merchants39
Additionally, the Federal Reserve
Bank of Atlanta reported in June
2019 that “counterfeit card fraud
is dropping […] [in] a trend in
that direction that is consistent
with the [other] countries” that
had previously migrated to EMV
chip.40
35.
Even with only 80% of merchant terminals converted in 2019, the U.S. was
already seeing 87% decreases in fraud at merchants that had converted and 62% at all merchants,
36 Alex Rolfe, US Market Hits 1 Billion EMV Chip Cards Milestone, Payments Cards & Mobile
(June 1, 2020), https://www.paymentscardsandmobile.com/us-market-hits-1-billion-emv-chip-
cards-milestone/.
37 Jim Daly, With Its EMV Conversion Nearly Complete, Canada’s POS Debit Fraud Falls to
New Low (Feb. 25, 2016), https://www.digitaltransactions.net/with-its-emv-conversion-nearly-
complete-canadas-pos-debit-fraud-falls-to-new-low/.
38 Id.
39 Visa EMV Chip Cards Help Reduce Counterfeit Fraud by 87 Percent, Visa (Sept. 3, 2019, 3:48
PM), https://usa.visa.com/visa-everywhere/blog/bdp/2019/09/03/visa-emv-chip-
1567530138363.html.
40 Douglas King, The Future of U.S. Fraud in a Post-EMV Environment, Retail Payments Risk
Forum at 22 (June 2019), https://www.atlantafed.org/-
/media/documents/rprf/publications/2019/06/23/future-of-us-fraud-in-post-emv-environment-
king-doug.pdf.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6650 Page
20 of 59
18
including those who had not yet converted, as compared to fraud levels four years earlier.41 As
Helcim, a payment services provider focused on small businesses, reported to its customers:42
When EMV cards were first introduced, they had a significant impact on
payments fraud because of these unique, dynamic data transaction IDs which can
not be replicated. As an example, in the US, it is estimated that from 2015 to
2018, card-present credit card fraud fell by as much as 75% due to the enhanced
security of EMV chip technology.43
C.
By 2019, EMV Chips Were the Industry Standard for Credit and Debit Card
Security.
36.
EMV chip technology standards have existed since 1996. By 2013, EMVCo’s
membership had expanded beyond the original members (Europay, Mastercard and Visa) to
include participation by all major stakeholder groups, including the principal global card
brands44: JCB joined in 2004, American Express joined in 2009, followed by Discover and
UnionPay in 2013. Participation also expanded to include a broad range of interested industry
stakeholders, including merchants, payment processors and other payments industry companies.
37.
The first major payments market to convert to EMV chips was the UK, which in
May 2003 began EMV trials and on February 14, 2006 converted nationwide. Shortly thereafter,
other countries began implementing EMV. By 2019, over 8.8 billion EMV chip cards had been
issued in Europe, Africa and the Middle East, Canada, and Latin America and the Caribbean, and
each of those regions had over 90% of their transactions processed with EMV chips.45
41 Visa EMV Chip Cards Help Reduce Counterfeit Fraud by 87 Percent, Visa (Sept. 3, 2019, 3:48
PM), https://usa.visa.com/visa-everywhere/blog/bdp/2019/09/03/visa-emv-chip-
1567530138363.html.
42 Danny Randell, EMV Chip Cards: Everything You Need to Know, Helcim Blog (Aug. 17,
2022), https://www.helcim.com/guides/emv-chip-card-technology/.
43 A 75% reduction is consistent with Visa data from three months prior, March 2019, as
compared to the data referenced in the chart above.
44 Why EMV?, EMVCO, https://www.emvco.com/why-emv/ Implementation section.
45 Alex Rolfe, US Market Hits 1 Billion EMV Chip Cards Milestone, Payments Cards & Mobile
(June 1, 2020), https://www.paymentscardsandmobile.com/us-market-hits-1-billion-emv-chip-
cards-milestone/.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6651 Page
21 of 59
19
38.
In October 2010, United Nations Federal Credit Union became the first U.S.
issuer to offer EMV cards to its credit customers.46 Other U.S. banks soon followed, issuing
EMV credit cards to selected segments of their customers, including those with frequent
international travel.
39.
By mid 2012, the U.S. payments market committed to migrating to EMV.
MasterCard, Visa, American Express, and Discover each issued “liability-shift” rules that took
effect in October 2015.47 Liability-shift rules were used in many countries to create economic
incentives for issuers and merchants to adopt EMV technology. A liability-shift rule assigns
liability for fraud to whichever party (either the card issuer or the acquirer/merchant) has the
least protection.48 For example, if a mag-stripe only card is presented to an EMV capable
merchant, the issuer of that card bears the cost of any fraud associated with that transaction. The
opposite would be true if an EMV card is presented to a mag-stripe only reader—the merchant
rather than the issuer would be liable for any fraud. If the mag-stripe on an EMV capable card is
used on an EMV capable reader and the merchant has configured its terminal to accept the mag-
stripe rather than forcing use of the chip (as is industry standard practice), the merchant is liable
for any resulting fraud because the merchant allowed the less secure technology to be used.
40.
Shortly after the announcement of liability-shift rules and deadlines, several major
U.S. banks, including Bank of America, announced plans to issue cards with embedded EMV
46 Saurabh Kumar Choudhary, EMV Compliance in the U.S., Capgemini at 17 (2012),
https://www.capgemini.com/wp-content/uploads/2017/07/EMV_Compliance_in_the_U.S..pdf
(citing EMV Resources, Secure Technology Alliance, https://www.securetechalliance.org/smart-
cards-applications-emv/).
47 EMV in the USA: The Story So Far, American Banker (April 5, 2013, 3:27 PM),
https://www.americanbanker.com/payments/slideshow/emv-in-the-usa-the-story-so-far.
For additional information see: Understanding the U.S. EMV Liability Shifts, US Payments
Forum at 4-5 (July 2017), https://www.uspaymentsforum.org/wp-content/uploads/2017/07/EMV-
Fraud-Liability-Shift-WP-FINAL-July-2017.pdf.
48 See id.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6652 Page
22 of 59
20
chips for their credit card portfolios.49 The table below from Capgemini’s report entitled EMV
Compliance in the U.S. provides a timeline for key commitments to EMV in the U.S. announced
in 2010 and 2011.50
Figure 1: EMV Compliance in the U.S.
41.
By 2014-2015, the U.S. debit card industry had begun migration efforts to EMV.
According to the 2014 Debit Issuer study by Celent, a large global research and advisory firm
focused on technology for financial institutions:
49 Saurabh Kumar Choudhary, EMV Compliance in the U.S., Capgemini at 17 (2012),
https://www.capgemini.com/wp-content/uploads/2017/07/EMV_Compliance_in_the_U.S..pdf
(citing EMV Resources, Secure Technology Alliance,
http://www.smartcardalliance.org/pages/smart-cards-applications-emv); Jonathan Camhi, Bank
of America Switches to EMV Chip Credit Cards for Consumers, InformationWeek (July 23,
2012, 3:50 PM), https://www.banktech.com/payments/bank-of-america-switches-to-emv-chip-
credit-cards-for-consumers/d/d-id/1295590d41d.html?.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6653 Page
23 of 59
21
86% of the US debit issuers were planning to start issuing EMV cards in
2014-2015, with most efforts focused on 2015. The EMV Migration
Forum [a cross industry body focused on the U.S. EMV transition]
forecasts that 4.5 million terminals will have been installed by the end of
2014, and over 46% of US merchant terminals will be enabled for EMV
by the end of 2015. In October 2014, President Obama signed an
executive order to use EMV for all government cards. It is estimated that
100 million EMV chip cards will have been issued by the end of 2014. In
September, Bank of America announced that all new debit cards will be
EMV. “The US EMV train has finally left the station and is building
up steam,” said Zilvinas Bareisis, senior analyst at Celent.51
42.
On September 20, 2014, Bank of America announced it was committed to
converting its consumer and commercial debit card portfolio to EMV to provide enhanced
security for its customers, becoming the first major U.S. bank to add EMV chip technology to
debit cards.52 Titi Cole, retail products and underwriting executive for Bank of America, stated
that “[c]hip technology is an important tool in increasing card security, and we want our
customers to have the best possible experience when using their payment cards” and “[t]he new
chip-enabled debit cards will improve security of customers’ transactions when traveling abroad
and at home as more U.S. merchants adopt chip technology.”53 The release noted that existing
Bank customers would receive chip cards when their existing cards were replaced at expiration
or for any other reason and that the Bank expected to complete conversion of its consumer and
small business debit cards to EMV by the end of 2015.54
50 Id.
51 US Shifts to EMV as Obama and Apple Weigh In, FinTech Futures (Dec. 15, 2014),
https://www.fintechfutures.com/2014/12/us-shifts-to-emv-as-obama-and-apple-weigh-in/
(emphasis added).
52 Bank of America Begins Rollout of Chip Debit Cards, BusinessWire (Sept. 30, 2014, 11:10
AM), https://www.businesswire.com/news/home/20140930005292/en/Bank-of-America-Begins-
Rollout-of-Chip-Debit-Cards; Ex. _ (Martin Dep. Ex. 44).
53 Bank of America Begins Rollout of Chip Debit Cards, BusinessWire (Sept. 30, 2014, 11:10
AM), https://www.businesswire.com/news/home/20140930005292/en/Bank-of-America-Begins-
Rollout-of-Chip-Debit-Cards.
54 Id.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6654 Page
24 of 59
22
43.
On October 17, 2014, President Obama signed an Executive Order, Improving the
Security of Consumer Financial Transactions, calling for all government agencies to shift to the
use of chip-and-PIN technology (i.e. EMV) credit, debit, and other payment cards, including
for all prepaid debit cards used to distribute federal government benefits.55 The switch was
needed, the Order explained, to “further strengthen the security of consumer data” and “improve
the security of consumer financial transactions in both the private and public sectors.”56 The
Order mandated that all executive departments and agencies must “transition payment processing
terminals and credit, debit, and other payment cards to employ enhanced security features,
including chip-and-PIN technology.”57 The mandate to transition to EMV chip cards applied to
Direct Express federal programs, which provide prepaid debit cards for monthly deposits of
Social Security, Supplemental Security Income, veterans, and other federal benefits and that are
administered by the Treasury Department,58 as well as credit, debit, and other payment cards
provided through the General Services Administration (GSA).59 The Executive Order directed
both the Treasury Department and GSA to transition covered cards to EMV by no later than
January 1, 2015 The relevant text of the Executive Order states:.60: The relevant text of the
Executive Order states:
Given that identity crimes, including credit, debit, and other payment card
fraud, continue to be a risk to U.S. economic activity, and given the economic
consequences of data breaches, the United States must take further action to
enhance the security of data in the financial marketplace. While the U.S.
Government's credit, debit, and other payment card programs already include
protections against fraud, the Government must further strengthen the security
of consumer data and encourage the adoption of enhanced safeguards
55 Exec. Order No. 13681, 79 F.R. 63491 (Oct. 23, 2014).
56 Id.
57 Id. §1.
58 See Direct Express, Frequently Asked Questions, https://www.usdirectexpress.com/faq.html
(last accessed Aug. 8, 2024).
59 Exec. Order No. 13681, 79 F.R. 63491, §1 (Oct. 23, 2014).
60Id.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6655 Page
25 of 59
23
nationwide in a manner that protects privacy and confidentiality while
maintaining an efficient and innovative financial system.
By the authority vested in me as President by the Constitution and the laws of
the United States of America, and in order to improve the security of
consumer financial transactions in both the private and public sectors, it is
hereby ordered as follows:
Section 1. Secure Government Payments. In order to strengthen data security
and thereby better protect citizens doing business with the Government,
executive departments and agencies (agencies) shall, as soon as possible,
transition payment processing terminals and credit, debit, and other payment
cards to employ enhanced security features, including chip-and-PIN
technology. In determining enhanced security features to employ, agencies
shall consider relevant voluntary consensus standards and specifications, as
appropriate, consistent with the National Technology Transfer and
Advancement Act of 1995 and Office of Management and Budget Circular A-
119.
(a) The Secretary of the Treasury shall take necessary steps to ensure that
payment processing terminals acquired by agencies through the Department of
the Treasury or through alternative means authorized by the Department of the
Treasury have enhanced security features. No later than January 1, 2015, all
new payment processing terminals acquired in these ways shall include
hardware necessary to support such enhanced security features. By January 1,
2015, the Department of the Treasury shall develop a plan for agencies to
install enabling software that supports enhanced security features.
(b) The Administrator of General Services shall take necessary steps to ensure
that credit, debit, and other payment cards provided through General
Services Administration (GSA) contracts have enhanced security
features, and shall begin replacing credit, debit, and other payment cards
without enhanced security features no later than January 1, 2015.
(c) The Secretary of the Treasury shall take necessary steps to ensure that
Direct Express prepaid debit cards for administering Government
benefits have enhanced security features, and by January 1, 2015, the
Department of the Treasury shall develop a plan for the replacement of
Direct Express prepaid debit cards without enhanced security features.
(d) By January 1, 2015, other agencies with credit, debit, and other payment
card programs shall provide to the Office of Management and Budget (OMB)
plans for ensuring that their credit, debit, and other payment cards have
enhanced security features.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6656 Page
26 of 59
24
44.
By early 2018, 91% of all U.S. ATMs had converted to EMV-enabled ATM
terminals to service EMV-enabled debit and credit cards.61 By March 2019, 99% of U.S.
payments volume ($81B) was completed using an EMV chip card.62
45.
In my opinion, based on the above facts and my experience, by 2019, EMV had
become the industry standard for payment card security in the United States.
D.
The Bank’s Failure to Include EMV Chips in its EDD Debit Cards Was
Inconsistent with Industry Standards and Caused EDD Debit Cards to Be
Vulnerable to Counterfeit Card Fraud.
46.
The Bank promised in its contract with EDD to “employ the highest level of
security and fraud safeguards” for EDD debit cardholders.63 However, for many years after the
Bank had converted its consumer and commercial debit cards to EMV chip cards,64 and even
after 2019 when the U.S. market reached the milestone with 99% of U.S. payments volume
being processed as EMV within the U.S.,65 the Bank continued to issue mag-stripe only cards to
its EDD debit cardholders and did not provide EDD debit cardholders the same level of security
it afforded to its commercial customers.66
61 Nearly All US ATMs Now EMV-Capable, Study Finds, ATM Marketplace (April 6, 2018),
https://www.atmmarketplace.com/news/nearly-all-us-atms-now-emv-capable-study-finds/.
62 See Chip Technology Helps Reduce Counterfeit Fraud by 76 Percent, VISA (May 28, 2019,
3:28 PM), https://usa.visa.com/visa-everywhere/blog/bdp/2019/05/28/chip-technology-helps-
1559068467332.html; EMV in the U.S. (2020 Update), Thales (2020),
https://www.thalesgroup.com/en/americas/united-states/digital-identity-and-security/emv; see
also Understanding the U.S. EMV Liability Shifts, US Payments Forum at 4 (July 2017),
https://www.uspaymentsforum.org/wp-content/uploads/2017/07/EMV-Fraud-Liability-Shift-WP-
FINAL-July-2017.pdf.
63 Ex. 22 at 253-54.
64 See Ex. 16 (Martin Tr.) 61:19-23 (Bank has included EMV chips in all consumer and small
business debit cards issued since late 2014).
65 Chip Technology Helps Reduce Counterfeit Fraud by 76 Percent, VISA (May 28, 2019, 3:28
PM), https://usa.visa.com/visa-everywhere/blog/bdp/2019/05/28/chip-technology-helps-
1559068467332.html.
66 Ex. 16 (Martin Tr.) 65:4-14, 65:8-10.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6657 Page
27 of 59
25
47.
By failing to include EMV chips in its EDD debit cards starting at least in the
beginning of 2020, the Bank did not provide EDD debit cardholders the “highest level of security
and fraud safeguards.”67 As described in paragraphs 36-45 and the paragraphs below, by 2019
EMV technology was the industry standard for all credit and debit cards issued in the United
States, including for debit cards used in the administration of government benefits. Even though
EMV chips are considerably more secure than mag-stripe only cards and better protect the
cardholder from card-present counterfeit fraud for the reasons stated above,68 the Bank did not
include its EDD debit cards in its EMV migration in 2014.69 The Bank’s failure to include EMV
chips in its EDD debit cards thus fell below basic industry standards. For all the reasons
discussed above, the lack of EMV chips in EDD debit cards rendered them highly susceptible to
card skimming and card-present counterfeit fraud.70
E. The Bank’s Decision to Not Include EMV Chips in EDD Debit Cards
as of Early 2020 Was Inconsistent with Other Participants in the
Payments Industry.
48.
Documents produced by the Bank in this litigation demonstrate that the Bank
knew as early as January 2020 not only that (1) EMV was already the industry standard for debit
card security, but also that (2) the cost of making a modest investment in EMV chips for the
EDD debit card portfolio would
.71 It is therefore my opinion, based on my industry experience and
expertise, that the Bank’s decision not to include EMV chips in EDD debit cards at least as of
67 Ex. 22 at 253-54.
68 See supra ¶¶29-35.
69 Ex. 16 (Martin Tr.) 65:4-14, 65:8-10.
70 I understand that it was not until July 2021, shortly after a preliminary injunction was issued
against Bank in this lawsuit, that the Bank finally begin issuing EMV cards to new EDD debit
cardholders and to existing cardholders whose cards needed to be replaced. Ex. 16 (Martin Tr.)
65:8-10.
71 See Ex. 27 at -351839–40.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6658 Page
28 of 59
26
January 2020 was highly inconsistent with how I would expect a sophisticated financial
institution in the payments industry to make decisions regarding payment card security.
49.
Bank documents suggest that the Bank did not implement EMV in EDD debit
cards before 2020, despite the well-established benefits of EMV for cardholders, as described
above, due to
.72
50.
By early 2020, however, not only had EMV been the industry standard throughout
the credit and debit card market for at least a year,73 but the Bank’s own internal analyses cited
.
51.
The Bank acknowledged in a presentation dated January 27, 2020, that “
”74 Under the Electronic Funds Transfer
Act (“EFTA”) and EFTA’s implementing Regulation E, the Bank would be liable for card-present
transaction fraud,75 and under the liability shift rules, unauthorized card-present transactions on
EDD debit card accounts would not be recoverable by the Bank where the transaction took place
at an ATM or payment terminal with a chip reader.76
52.
As a result, the Bank’s own pre-pandemic cost-benefit analysis in January 2020,
described below, demonstrated that
.
72 See Ex. 28 at -116001 (“
.”).
73 See supra ¶¶36-45.
74 Ex. 26 at -370154 (emphasis added).
75 See 15 U.S.C. §1693f(b); 12 C.F.R. §1005.11(c)(1).
76 See supra ¶39.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6659 Page
29 of 59
27
53.
.77 In turn,
78
79
54.
The head of the Bank’s EDD debit card product team, Brad Garfield, noted that
.”80 Garfield explained in an email dated January 10, 2020: “
.
77 See Ex. 27 at -351839–40. A
. See Ex. 107 at --104744.
78 Ex. 27 at -351839.
79 Id.
80 Id. Garfield leads card products within the Bank’s Global Transactions Services group. See Ex.
150 at -57850.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6660 Page
30 of 59
28
.”81
55.
Prior to the pandemic, the Bank’s business case alone, regardless of past practice,
should have been clear as to the need to convert EDD debit cards to EMV technology. The Bank
recognized that (1)
”84
56.
Despite
, the Bank continued to ignore industry standards and its
cardholder’s interests by deciding not to include the higher security EMV chips in its EDD debit
cards. In my experience working in EMV transitions across multiple markets, products, and
stakeholders, I have never observed an institution make a similar decision to forego an option
that its own analysis
.
57.
I have known many industry stakeholders to make investments in EMV on far
weaker business cases than the Bank had here, relying instead on a combination of both
quantitative factors (costs and benefits of investment dollars) and qualitative factors (such as
customer experience, ubiquity of acceptance, and trust built on network reliability and security).
In my experience, for many markets, the quantitative analysis predicted 4 or more years to break
even and 6-7 years to reach a positive net present value. Yet those markets moved forward with
conversion to EMV on the strength of the qualitative components. Here, the Bank’s analysis
81 Id. (emphasis added).
82 See Ex. 27 at -351839 (“
.”).
83 Id. at -351839-40.
84 Id. at -351839.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6661 Page
31 of 59
29
showed
Given this analysis, the Bank’s failure to
convert its EDD debit cards to EMV chip cards was highly irregular compared to the behavior of
other participants in the payments sector.
58.
Documents produced by the Bank in this litigation indicate that the Bank
.85 If true, such facts would render the Bank’s decision not to
convert its EDD debit cards to EMV chip cards in early 2020 even more inconsistent with how I
would expect a financial institution to make decisions about payment card security, based on my
industry experience and expertise.
59.
The contract between the Bank and EDD provided that the parties would split the
revenue earned on “float,” i.e. interest earned on EDD debit cardholders’ account balances.86 As
indicated in internal emails exchanged among Bank officials, the Bank
. As one internal Bank email
explained:
.87
85 See Ex. 27 at -351839-40; Ex. 108 at -102937; Ex. Ex. 28 at -116001; Ex. 24 at -123235).
86 Ex. 15 (Chestnut Tr.) 55:21-56:9, 169:1-170:13.
87 Ex. 28 at -116001; see also Ex. 108 at -102937 (“
”); Ex. 30 at -352396 (
).
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6662 Page
32 of 59
30
60.
Another internal email from Brad Garfield, head of the Bank’s EDD debit card
product team, dated March 10, 2020 also explained
88
61.
In an email dated February 25, 2020, Garfield laid out the Bank’s
88 Ex. 27 at -351839 (emphasis added).
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6663 Page
33 of 59
31
89
62.
In March 2020, the Bank created a PowerPoint document entitled “
.90
.91
92 All of those facts and observations are accurate, based on my personal,
expert knowledge and experience, and consistent with the industry reports cited above.93
89 Ex. 24 at -123235 (emphasis added).
90 Ex. 25 at -167019–24.
91 Ex. 25 at -167021.
92 Ex. 25 at -167021.
93 See supra ¶¶29-35 n.32-45.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6664 Page
34 of 59
32
63.
94
95
96
64.
Despite the Bank’s
, the Bank did not adopt EMV in 2020 for its EDD
debit cards.97 Based on the documents the Bank produced, and given the Bank’s
, it is my understanding that
94 Ex. 25 at -167022 (emphasis added).
95 Id.
96 Id.
97 Ex. 16 (Martin Tr.) 65:8-10.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6665 Page
35 of 59
33
.
65.
Based on my review of these Bank documents and my expertise, it is clear that,
before the onset of the pandemic, the Bank understood that
, and that the Bank was aware of
. It is also clear that the Bank had determined as of January 2020 that
. Given these factors, in
my extensive experience building and analyzing business cases for EMV chip migration, I would
have recommended and expected the Bank to migrate the EDD portfolio to EDD no later than
January 2020. The Bank’s decision not to make a minor investment
, which
would have sharply reduced the increasing fraud losses the Bank was experiencing and provided
industry standard card security to cardholders, evidently because the
, was highly irregular and, in my opinion,
irresponsible to EDD cardholders.
66.
Even after witnessing historic fraud on EDD debit cards in 2020 during the
COVID-19 pandemic, the Bank still did not act swiftly to add EMV chips to EDD debit cards.
An Executive Summary on the prepaid unemployment card portfolio presented by the Bank
sometime in mid-to-late 2020 suggests that
98
•
.
•
.
98 Ex. 107 at -104744, -104746.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6666 Page
36 of 59
34
67.
Yet still the Bank did not begin issuing EMV chip cards to new EDD debit
cardholders and to existing cardholders whose cards needed to be replaced until July 2021,
shortly after a preliminary injunction was issued against Bank in this lawsuit.99
68.
The Bank’s failure to meet industry standards for fraud security before July 2021
was particularly egregious, in my opinion, because (1) EMV was industry standard at least a year
before the pandemic; (2) months before the pandemic began, the Bank had
; and, finally, (3) the Bank was aware of the
ability of EMV to prevent the fraud cardholders were experiencing throughout the pandemic. Yet
instead of immediately implementing a switch to EMV at any of those points, the Bank did not
begin conversion until July 2021, thus exposing every EDD debit cardholder to the risk of card-
present counterfeit fraud for no justifiable reason.
F.
It Was Highly Foreseeable that the Bank’s Failure to Include EMV Chips in
EDD Debit Cards Would Lead to Counterfeit Fraud Targeting EDD Debit
Cardholders During the Pandemic, Because Fraud Migrates to the Weakest
Link.
69.
It is well established that fraud migrates to the weakest link. As described in
examples below, long before the pandemic, industry experts had warned that retailers and banks
that lagged in implementing EMV after the liability shift risked increasing their cardholders’
vulnerability to fraud. Indeed, experts had long been raising warnings to smaller programs and
merchants that there was significant risk to further delaying EMV chip implementation.
99 Ex. 16 (Martin Tr.) 65:8-10.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6667 Page
37 of 59
35
70.
The 2016 Community Banking Connection report, a nationwide Federal Reserve
System resource for community banks, identified the risk smaller programs faced related to
becoming the “easiest target” for criminals:100
What is the risk of delaying? Timing is another factor to consider. Migration to
chip cards is a version of “musical chairs” for card issuers: No one wants to
be the last one in a market to convert to chip cards because fraudsters tend
to attack the easiest targets first. Because magnetic stripe cards are easier to
counterfeit, they are generally attractive targets for thieves.
71.
In June 2017, the American Banker similarly warned in an article entitled,
“Crooks Are on the Prowl for Late EMV Converts,” that smaller banks are at risk of being “in
the cross hairs of criminals poised to exploit obvious holes” and may face a major fraud event:101
More than 60% of all U.S. payment cards are now EMV-enabled and just
over half of all merchants are chip-compliant, which has slashed
counterfeit card risk for many operators. But the U.S. has a long way to go
before full conversion to the EMV standard is completely finished, and
those who delay may find themselves in the cross-hairs of criminals
poised to exploit obvious holes in the system. Smaller financial
institutions and merchants in specific categories that have not made the
move to EMV may now be at higher risk for counterfeit card losses
from criminals exploiting account data on the shrinking number of
older magnetic-stripe payment cards not yet equipped with the more
secure EMV chip technology.
A handful of smaller banks still haven’t taken action on EMV, and they
may have to get hit by a significant fraud event before they’re
convinced they need to invest the money and time into finally
converting to chip cards, “says Troy Bernard, director of strategic
marketing and products at CPI Card Group, a card manufacturer.
100 Mary J. Hughes, The U.S. EMV Chip Card Migration: Considerations for Card Issuers,
Community Banking Connections (2016),
https://www.communitybankingconnections.org/articles/2016/i1/emv-chip-card-migration
(emphasis added).
101 Kate Fitzgerald, Crooks Are On the Prowl for Late EMV Converts, American Banker (Jun 23,
2017, 12:01 AM), https://www.americanbanker.com/payments/news/crooks-are-on-the-prowl-
for-late-emv-converts (emphasis added).
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6668 Page
38 of 59
36
72.
In April 2018, Javelin Research reported that criminals were beginning to focus
on mag stripe only debit and prepaid cards, with counterfeit fraud targeting prepaid cards nearly
tripling compared to the previous year:102
Transaction fraud losses are falling because of EMV and a shift in
behavior. As more and more credit cards are meeting the EMV standard,
criminals are focusing their attention on less lucrative debit and
prepaid cards. In 2017, roughly 3.4 million people lost control of their
prepaid cards — nearly three times as many as the previous year. The
average amount per fraudulent transaction is declining. In the same period,
debit card fraud victims rose from 5.2 million to 6.6 million.
73.
Thus, even before the start of the pandemic, the industry was warning that the
lack of EMV chips cards made mag-stripe only debit and prepaid cards targets for skimming
attacks and counterfeit card fraud.
74.
In addition, the pre-pandemic load values (a term for the amount of money being
added to or “loaded” onto the benefit cards) for the EDD program were already large enough to
be an attractive target for counterfeiting.103 The sheer volume of money that the Bank was
administering provided an incentive for criminals to target the program.
75.
Based on my experience, a sophisticated financial institution like Bank of
America would have been aware well before the start of the pandemic of the high risk that
fraudsters would target its EDD debit cardholders because their mag-stripe only cards were
particularly vulnerable to skimming and counterfeit fraud. Indeed, a Bank presentation dated
January 27, 2020 confirms the Bank’s awareness that its EDD debit cards had become an
attractive target for fraud:
102 From Application to Transaction: Card Fraud Trends, Threats, & Tactics at 5 (April 2018),
https://javelinstrategy.com/sites/default/files/files/reports/18-5006J-FM-
From%20Application%20to%20Transaction-FIS.pdf (emphasis added).
103 See Ex. 154 at -154042 (
).
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6669 Page
39 of 59
37
.104
76.
The impact of the pandemic increased both the number of benefit recipients and
the total load value on EDD debit cards, which were reloaded with benefits every two weeks.105
This made the vulnerabilities in the Bank’s administration of the EDD program even more
attractive to criminals.106 Based on my experience, it would have been foreseeable to any
sophisticated financial institution like Bank of America at the onset of the pandemic that the
increase in EDD debit card load, combined with the known security vulnerabilities of mag-
stripe-only EDD debit cards, would make EDD debit cards an even more attractive target for
card skimming and counterfeit fraud during the pandemic, in the absence of EMV chip cards.
77.
Indeed, several documents produced by the Bank in discovery (1) demonstrate the
, (2) confirm
, and (3) demonstrate the
.
104 Ex. 26 at -370154 (emphasis added).
105 Ex. 110 at -59687-88 (
”); Ex. 154 at -154042 (“
).
106 During the pandemic, reports confirmed that EDD debit cardholders were falling victim to
skimming and counterfeit card fraud. For example, on November 13, 2020, NBC Los Angeles
identified three victims of likely skimming fraud who had their EDD funds stolen from their
accounts. See Christine Roher, Thousands Are Being Stolen From Bank of America Accounts,
and EDD May Be Linked. Here’s How to Protect Yourself, NBC Los Angeles (Nov. 14, 2020,
3:07 PM), https://www.nbclosangeles.com/news/local/edd-bank-of-america-fraud-bank-account-
stolen/2462198. On November 20, 2020, CalMatters wrote about five additional victims of
skimming fraud related to EDD accounts. Lauren Helper & Stephen Council, How Bank of
America Helped Fuel California’s Unemployment Meltdown, CalMatters (Nov. 20, 2020),
https://calmatters.org/economy/2020/11/how-bank-of-america-helped-fuel-californias-
unemployment-meltdow.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6670 Page
40 of 59
38
78.
For example, in one email dated April 24, 2020, Bank employees discussed the
“
,” acknowledging “
.”107 The
Bank email explains that “
.”108 While the presence of EMV chips in the Bank’s non-prepaid debit
cards was
.”109
79.
Another email dated April 23, 2020 similarly confirms that “
” (i.e. non-prepaid debit cards, all of which had EMV chips as of 2014), “
”110
80.
In an internal email dated May 22, 2020, the Bank acknowledged that “
”111
81.
In an internal email chain on July 9, 2020, William Martin (current Bank
Management Executive for Prepaid Unemployment Programs and former Senior Fraud Policy
Manager112) asked: “
107 Ex. 32 at -228914 (emphasis added).
108 Id.
109 Id. (emphasis added)
110 Ex. 34 at -297295 (emphasis added).
111 Ex. 111 at -171973.
112 Ex. 16 (Martin Tr.) 26:11-25; see also Ex. 150 at -57844.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6671 Page
41 of 59
39
.”113
Melody Szretter, who oversaw the Bank’s fraud strategies for EDD prepaid debit cards in the
2020-2021 time period,114 replied: “
.”115
82.
In another email dated August 18, 2020, Bank employees discussed seeing an
“
,” explaining that “
,” and that
”116
83.
In an internal email dated September 9, 2020, Brad Garfield, head of the EDD
debit card product team, noted that “
,” and “
….”117
84.
The Bank’s documents show that the Bank understood, consistent with my
opinion, that adding an EMV chip to its cards would provide the best protection against
counterfeit fraud. In an internal email dated November 2, 2020, Melody Szretter, in response to
a question from Brad Garfield about
, wrote: “
”118
113 Ex. 56 at -172471–72.
114 Ex. 16 (Martin Tr.) 37:2-4; see also Ex. 150 at -57844.
115 Ex. 56 at -172471–72 (emphasis added).
116 Ex. 33 at -455617 (emphasis added).
117 Ex. 154 at -154043; see also Ex. 26 at -370154.
118 Ex. 55 at -163307 (emphasis added).
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6672 Page
42 of 59
40
85.
Based on these Bank documents and others, it is evident that the Bank knew its
EDD debit card program was highly attractive to criminals given the high dollar amounts pre-
pandemic and even higher dollar amounts during the pandemic combined with a lack of EMV
chip security, which is consistent with my opinion that EDD debit cards were in fact highly
attractive to criminals during the pandemic and highly susceptible to skimming and counterfeit
fraud because they lacked industry-standard EMV chips. Had the Bank issued its EDD debit
cardholders industry-standard EMV chip cards, just as it had issued its other consumer and small
business debit cardholders EMV chip cards since 2014, EDD debit cardholders would have been
protected from such fraud. Had the Bank begun its migration of the EDD card portfolio to EMV
when the rise in counterfeit fraud became evident in 2019, the Bank would have had EMV chip
cards in place before or at the very least early in the pandemic, which would have prevented
much of the subsequent loss and hardship that EDD cardholders experienced as a result of
skimming and counterfeit fraud. The Bank nonetheless made a deliberate choice not to adopt
EMV chips in EDD debit cards for reasons that are wholly inconsistent with my experience of
how participants in the payment sector make their EMV migration decisions.
G.
Any Financial Institution in the Bank’s Situation Would Have Known that
Many EDD Cardholders Who Reported Unauthorized PIN-Enabled ATM
Withdrawals Were True Victims of Counterfeit Fraud.
86.
Plaintiffs’ Counsel have informed me that from September 28, 2020 until the
preliminary injunction in this case went into effect on June 8, 2021, the Bank ran all incoming
EDD debit cardholder unauthorized-transaction claims through its “Claim Fraud Filter” (“CFF”)
and used the results of that CFF as a basis for automatically denying certain categories of claims
(and, for a period of time, for automatically freezing the cardholders’ EDD debit card accounts).
The Bank’s CFF Indicator 1 applied to all “
,” which the Bank interpreted as any claim involving an
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6673 Page
43 of 59
41
unauthorized ATM withdrawal.119 If a claim involved a claim of an unauthorized ATM
withdrawal (which was necessarily a PIN-enabled ATM withdrawal because all ATMs require the
use of a PIN), Indicator 1 of the CFF was triggered, and the claim was denied on that basis.120
Plaintiffs’ Counsel have also informed me that on or about September 28, 2020, the Bank applied
its CFF retroactively to claims that had been submitted between April 1, 2020 and September 27,
2020 and which the Bank had already resolved by issuing permanent credit.121 For all such
claims that triggered Indicator 1 of the CFF because they had involved a claim of an
unauthorized ATM withdrawal, the Bank rescinded the permanent credit that the Bank had
previously issued.122
87.
For the reasons explained above, it has long been known throughout the payment
services industry that mag-stripe only cards are vulnerable to skimming and card-present
counterfeit fraud. Given that knowledge, and based on the Bank’s own documents discussed
above, it is my opinion that, as a matter of industry practice, it was clear at the time the CFF was
in place that due to the absence of EMV chips in the Bank’s EDD debit cards, legitimate
cardholders were vulnerable to skimming attacks and counterfeiting. It would also have been
clear to industry practitioners that criminals could easily create counterfeit cards (using
cardholder information obtained either through skimming, phishing, data breaches, or other
security attacks) and that, due to the lack of EMV chips in the Bank’s EDD debit cards, the
119 Ex. 49; Ex. 88 at -125177; Ex. 47 at -100649 (describing Indicator 1 as “
”); Ex. 16 (Martin Tr.) 125:18-126:8, 127:8-10 (similar); Ex. 14 (Rule 30(b)(6) Depo.
of Shane Daniels (“Daniels Tr.”)) 285:22-286:13, 289:7-12 (similar). Indicator 1 was also
”). Ex. 17 (Rule 30(b)(6) Depo. of Michael Letson (“Letson
Tr.”)) 92:15-94:5 (agreeing that
”); Ex. __ (Daniels Tr.) 285:25-
286:25; see Ex. 81 at -592328 (describing Indicator 1 as “
”); Ex. 50 at -90640, -90643 (same).
120 Id.
121 Ex. 16 (Martin Tr.) 175:10-14, 178:13-23; Ex. 14 (Daniels Tr.) 234:24-236:5.
122 See id.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6674 Page
44 of 59
42
criminals could use those counterfeit cards to make unauthorized POS transactions and ATM
withdrawals.
88.
The Bank’s cardholder agreement advised cardholders that they “may incur no
liability for unauthorized use of [a] Card” but only “provided [the cardholder] notify [the Bank]
within a reasonable time of the . . . unauthorized use.”123
89.
Industry leaders also knew that innocent cardholders can be the victims of fraud.
Visa, Bank of America’s card network partner, knows that consumers can be innocent victims.
Visa’s Zero Liability Policy is designed to protect consumers from fraudulent activity on their
cards. Visa explains its Zero Liability Policy to consumers on its website, as specifically
protecting fraudulent use of cards offline (meaning card present transactions):124
Visa's Zero Liability Policy* is our guarantee that you won't be held
responsible for unauthorized charges made with your account or account
information. You're protected if your Visa credit or debit card is lost,
stolen or fraudulently used, online or offline.
90.
The Consumer Financial Protection Bureau, known as CFPB, similarly recognizes
that legitimate cardholders can be innocent victims of fraud and provides consumers with advice
regarding their protections under law. The CFPB is the federal agency charged with overseeing
the financial services industry and protecting consumers from unfair, deceptive, or abusive
practices. The CFPB’s website poses several Frequently Asked Questions, including one focused
on unauthorized transactions on a debit card, which is shown below: 125
If the unauthorized transaction was made using a debit card or other
electronic fund transfer, you might have additional protections under
federal law. Electronic fund transfers include ATM transactions, purchases
123 Ex. 76 at -536402.
124 With Zero Liability, You’re Not Responsible for Unauthorized Charges, Visa,
https://usa.visa.com/pay-with-visa/visa-chip-technology-consumers/zero-liability-policy.html
(last accessed Aug. 9, 2024) (emphasis added).
125 How Do I Get My Money Back After I Discover an Unauthorized Transaction or Money
Missing From My Bank Account, Consumer Financial Protection Bureau (Aug. 28, 2023),
https://www.consumerfinance.gov/ask-cfpb/how-do-i-get-my-money-back-after-i-discover-an-
unauthorized-transaction-or-money-missing-from-my-bank-account-en-1017/ (last accessed Aug.
9, 2024).
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6675 Page
45 of 59
43
using your debit card, some online bill payments, and payments you’ve set
up to be deducted from your account automatically . . . .
What if someone charges my account but I have my physical debit card?
If an unauthorized withdrawal appears on your bank statement, but you
did not lose your card, security code, or PIN or had any of them stolen,
you should notify your bank or credit union right away.
91.
In light of everything discussed above, it is my opinion that any financial
institution in the Bank’s situation would have known, and the Bank knew or should have known,
that many of its EDD debit cardholders who reported an unauthorized ATM withdrawal between
April 1, 2020 and June 8, 2021 were in fact victims of counterfeit card fraud that likely resulted
from card skimming. The Bank’s decision to issue mag-stripe only rather than EMV chip cards
to its EDD debit cardholders prior to July 2021 enabled such fraud. It is also my opinion that
any financial institution in the Bank’s situation would have known, and the Bank knew or should
have known, that its “Claim Fraud Filter” strategy would result in the wrongful denial of a
substantial number of valid claims and the wrongful freezing of accounts of innocent EDD debit
cardholders.
VII.
CONCLUSION
92.
It is my opinion that, from January 2020 to July 2021, Bank of America denied its
EDD debit card customers the industry-standard security it had long provided to its commercial
debit and credit card customers. Financial institutions knew, as the Bank confirmed in its own
words, that including EMV chips on its credit and debit cards would be the most effective tool
for fighting counterfeit fraud in a card-present environment. In the years before the pandemic, it
was widely recognized and readily foreseeable to everyone in the industry, including the Bank,
that fraud would move to the remaining less secure mag-stripe only cards that remained in the
market and that card programs that did not convert to EMV would be increasingly targeted by
counterfeit fraud.
93.
In my professional experience, the Bank’s decision to proceed without EMV chips
in its EDD debit cards from January 2020 until July 2021, even after
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6676 Page
46 of 59
44
was highly irregular in the payments industry.
94.
The Bank’s failure to issue EMV chip cards to EDD debit cardholders rendered
EDD debit cardholders particularly vulnerable to counterfeit card fraud (such as unauthorized
ATM withdrawals) that could have been prevented by the presence of an EMV chip on their
debit cards.
95.
As a foreseeable result of the Bank’s decision not to introduce industry-standard
security EMV chips into EDD debit cards, there was significant card-present transaction fraud
targeting the Bank’s EDD debit card portfolio during the pandemic, including unauthorized ATM
withdrawals).
96.
In my opinion any financial institution in the Bank’s situation would have known,
and the Bank did know or should have known, that due to Bank’s decision to issue vulnerable
mag-stripe only rather than EMV chip cards to its EDD debit cardholders prior to July 2021,
many of its EDD debit cardholders who reported an unauthorized ATM withdrawal between
April 1, 2020 and June 8, 2021 were in fact victims of card-present counterfeit fraud that likely
resulted from card skimming. It is also my opinion that any financial institution in the Bank’s
situation would have known, and that the Bank did know or should have known, that its “Claim
Fraud Filter” strategy would result in the wrongful denial of a substantial number of valid claims
and the wrongful freezing of accounts of innocent EDD debit cardholders.
* * *
* * *
Dated: August 29, 2024
___________________________
Jane E. Cloninger
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6677 Page
47 of 59
45
Appendix A: Curriculum Vitae
Appendix B: List of Materials Considered
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6678 Page
48 of 59
APPENDIX A
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6679 Page
49 of 59
Jane.cloninger@gmail.com
Jane E. Cloninger
415.218.7417
JANE E. CLONINGER
San Francisco, CA | jane.cloninger@gmail.com | 415.218.7417 | linkedin.com/in/janecloninger
A senior leader with broad consulting experience in competitive strategy, new product development,
business case development and implementation execution. Primary expertise is electronic payments
systems, particularly emerging products and technologies including mobile, contactless and EMV for both
face to face and online payments and real time payments. Worked in many parts of the card industry
including working with card brands, issuers, merchants, co-brand partners, third party processors, and
major merchant acquirers. Global experience includes Canada, Latin America, UK, and Australia.
1. EDUCATION
University of California at Los Angeles, Anderson Graduate School of Management, Los Angeles,
CA; Master of Business Administration, Strategy and Finance, 1982
University of Tennessee, Knoxville, TN; Bachelor of Science, Economics, 1978 (with honors)
2. EMPLOYMENT HISTORY
Accenture, Senior Managing Director, Accenture Payment Services
San Francisco, CA
2017 – 2019
Edgar, Dunn & Company, Director/Partner
San Francisco
1985 – 2017
First Interstate Bancorp, Assistant Vice President
Los Angeles, CA
1982 – 1985
Wilshire Associates
Los Angeles, CA
1979 – 1980
3. SELECTED LITIGATION SUPPORT EXPERIENCE
Jane has provided expert reports and testimony at depositions, mediation, arbitration, and jury trials.
Selected examples include the following:
Class Size – Analyzed the likelihood that customers who could potentially benefit from the settlement would
have remained customers and that they would have active credit cards on file by which they could receive any
settlement funds.
Bankruptcy Dispute – Provided expert opinion and testified in deposition in a case involving the bankruptcy of
a charter airline. Provided testimony regarding industry risk management practices and the role and
responsibility of the acquirer in underwriting and monitoring their merchant clients.
Securities Litigation – Class Action. In support of a class action lawsuit alleging inappropriate public disclosure
of credit card portfolio performance to investors, prepared expert report based on analysis of portfolio
performance during each quarter of the class period to determine what actual performance was compared to
reported performance. Evaluated loan loss reserves and calculated appropriate reserve levels based on risk
exhibited by the portfolio performance indicators. Testified for mediation and prepared Expert Report for
settlement purposes. Case settled in favor of our client.
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6680 Page
50 of 59
Jane.cloninger@gmail.com
Jane E. Cloninger
415.218.7417
Contract Dispute – Valuation of Co-Brand Credit Card Portfolio. Prepared the damage assessment related to
litigation resulting from the co-brand partner’s refusal to honor an established co-brand agreement. Assessed
the competitive environment and management practices during the interim period to identify any changes in
value related to other factors. Provided expert witness testimony in deposition and in a jury trial that
concluded in favor of damages for our client.
Contract Dispute – Credit Card Program Valuation. Provided expert witness testimony related dispute
between a bank and its former cobrand marketing partner. Developed estimated future earnings potential
and loss forecasts to estimate the probable profitability if the program had been continued
4. OTHER SELECTED PROJECT EXPERIENCE
Jane has been a consultant to the credit card and payments industry since 1985. Below are selected examples
of projects:
De Novo Digital Bank. Responsible for the client relationship and oversight of various client engagement
teams involved in the implementation of a new core banking platform, accounting platform, AML tools and
data strategy development.
Business Case Development for Chip. Developed the business case for the migration of a national PIN debit
scheme from magnetic stripe technology to chip. Developed the industry business cases for migration within
the US considering the costs and benefits to issuers, acquirers/merchants, and processors. Developed the
business case for a large regional issuer which included its retail credit and debit programs as well as
commercial and prepaid portfolios.
Risk Assessment. Led a review how risk was introduced into a global payment services’ core services and how
the client identified and responded to incidents. Scope included working with Treasury and Settlement to
develop an end-to-end view of the process. Areas addressed including client on-boarding, transaction
authorization processing and backend monitoring and settlement. Documented key workflows and made
recommendations to address areas of risk including upstream Treasury dependencies.
Payments Roadmap. Developed a payments roadmap for a large transportation company. Identified and
prioritized over 20 opportunities for near term and long-term implementation based on their ability to meet
management’s objectives.
Payment Strategy. Developed the corporate strategy for a national debit brand. Identified what areas of
investment to pursue and what not to pursue. Reviewed the competitive landscape to identify threats and
opportunities. Assisted client in assessing the impact of changing regulatory and competitive environment on
their business. Developed planning scenarios and related volume projections. Identified various competitive
and regulatory scenarios and likely merchant and consumer reactions under each scenario. Identified the
implications to the client and likely transaction volumes that would result under each competitive scenario.
Product Strategy. Created a Product Roadmap for a national debit brand that outlines the planned product
evolution, including opportunities and investment requirements across eleven proposed products, including:
contactless, mobile, P2P, cross border debit, bill payment, prepaid and online payments. Assessed the
competitive environment, market need, strategic fit, and level of effort and investment required to
implement.
Mobile Payments. Developed an NFC commercialization roadmap for a global payment brand. Analysis
included identifying key requirements for commercialization and assessing six markets’ readiness against
those requirements.
5. SELECTED SPEAKING ENGAGEMENTS
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6681 Page
51 of 59
Jane.cloninger@gmail.com
Jane E. Cloninger
415.218.7417
Card Not Present Expo, Moderator, “Remote Control: Focusing on mobile Web and in-app capability
vs. mPOS”, May 2016
Money 20/20, Moderator “Payment Card Innovation – and the Evolving Role of Issuers, Processors
and Networks”, October 27, 2015
ARC Travel Connect, 2015 (Airlines Reporting Company), Speaker and Panel Moderator, “How Do
New Developments in Payments Impact the Travel Industry”, Washington DC, October 22, 2015
Mobile World Congress, Barcelona. Moderator “Mobile Retail: Delivering Contextual Experiences to
Drive Loyalty and Spend”, March 16, 2015
Money 20/20, Moderator “Payment Security Evolution: EMV, Mobile, CNP & Beyond”, November 3,
2014
Cartes America, “Mobile Payment Ecosystem Views”, May 13, 2014
Payments Summit, Smart Card Alliance, Mobile Payments, the Battle of the Approaches, February 3,
2014
Law Seminars International, Palo Alto, CA, “Mobile Payments, Players, and The Customer Experience
– and the Issues They Raise, November 21, 2013
Money 20/20, Panel Moderator “The Future of the Secure Element and Trusted Execution
Environment”, October 7, 2013
Merchant Risk Council, Webinar, May 23, 2013. Results of survey conducted by EDC and MRC:
“Mobile Commerce and the Merchant Experience”
Law Seminars International, San Francisco, CA, November 15, 2013. “Mobile Payments Ecosystem”
Law Seminars International, Seattle WA, May 13, 2013. “Mobile Payments: Players and Their
Technologies”
Cartes America, Las Vegas, April 23, 2013. “EMV, NFC and Mobile Implementations Based on the US
Business Case”
Merchant Risk Council, Las Vegas, March 28, 2013. Mobile Super Session. “Mobile Commerce”
Smart Card Alliance, Las Vegas, February 4, 2013. Moderator: “Keynote Plenary Panel Session: The
Pressing Issues on EMV Migrations”
6. PUBLICATIONS
2016 Advanced Payments Report, Edgar, Dunn & Company and Cards & Payments Mobile
2015 Advanced Payments Report, Edgar, Dunn & Company and Cards & Payments Mobile
2014 Advanced Payments Report, Edgar, Dunn & Company and Cards & Payments Mobile
2013 Advanced Payments Report, Edgar, Dunn & Company and Cards & Payments Mobile
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6682 Page
52 of 59
APPENDIX B
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6683 Page
53 of 59
Date
Doc Type
Title/Desciption
Bates Range
8/24/2024
10/1/2021
Declaration
2/6/2024
Transcript
2/8/2024
Transcript
2/29/2024
Transcript
1/2/2024
Rog Response
3/17/2021
Letter
BANA_EDD_MDL-00002230-2231
10/14/2015
Document
BANA_EDD_MDL-00002286-2851
3/31/2020
Document
BANA_EDD_MDL-00012962-12972
8/26/2020
PPT
BANA_EDD_MDL-00018397-18403
1/27/2020
Document
BANA_EDD_MDL-00054544-54548
10/30/2020
Email
BANA_EDD_MDL-00057504-57506
10/20/2023
Document
BANA_EDD_MDL-00057837-57878
3/13/2021
Email
BANA_EDD_MDL-00059312-59315
3/13/2021
Document
BANA_EDD_MDL-00059316-59318
3/28/20
Email
BANA_EDD_MDL-00059687-59690
9/2/2020
PPT
BANA_EDD_MDL-00060229-60256
8/25/2020
PPT
BANA_EDD_MDL-00060269-60271
8/25/2020
PPT
BANA_EDD_MDL-00060417-60423
12/9/2020
Email
BANA_EDD_MDL-00061630-61632
12/10/2020
Email
BANA_EDD_MDL-00061638-61640
7/21/2021
Email
BANA_EDD_MDL-00065475-65476
12/22/2020
Email
BANA_EDD_MDL-00068506-68513
4/23/2020
Email
BANA_EDD_MDL-00069065-69066
9/24/2020
PPT
BANA_EDD_MDL-00071516-71524
12/22/2020
Email
BANA_EDD_MDL-00072855-72862
1/21/2021
Email
BANA_EDD_MDL-00073356-73357
2/12/2021
Document
BANA_EDD_MDL-00073529-73531
2/5/2021
PPT
BANA_EDD_MDL-00073892-73896
3/3/2021
Letter
BANA_EDD_MDL-00074102-74103
2/5/2021
PPT
BANA_EDD_MDL-00074200-74204
12/14/2020
Email
BANA_EDD_MDL-00079995-79997
1/21/2021
Email
BANA_EDD_MDL-00086717-86718
3/17/2021
Letter
BANA_EDD_MDL-00087245-87246
4/2/2021
Email
BANA_EDD_MDL-00087364-87366
10/14/2020
Email
BANA_EDD_MDL-00090135-90143
12/29/2020
Email
BANA_EDD_MDL-00090640-90647
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6684 Page
54 of 59
1/12/2021
Email
BANA_EDD_MDL-00090683-90686
1/26/2021
Email and PPT
BANA_EDD_MDL-00090721-90726
4/13/2021
Email
BANA_EDD_MDL-00091195-91196
3/5/2021
Email
102688
2/21/2020
Email
BANA_EDD_MDL-00102937
2/25/2020
Email
102939
9/30/2020
Email
104743
9/30/2020
Email and
Document
BANA_EDD_MDL-00104742-
104746
9/30/2020
Document
BANA_EDD_MDL-00104744-
104746
1/11/2021
Email
BANA_EDD_MDL-00107261-
107266
1/14/2021
Email
107335
7/8/2021
Email
110520
8/10/2021
Email
111230
2/21/2020
Email
BANA_EDD_MDL-00115701
7/21/2020
Email
116002
4/29/2021
Email
118618
12/14/2020
Email
120595
5/12/2021
Email
123034
5/24/2021
Email
123059
2/20/2020
Email
123234
2/26/2020
Email
123236
2/21/2020
Email
BANA_EDD_MDL-00124142
11/2/2020
Email
125465
3/10/2021
Email and
Document
BANA_EDD_MDL-00125919-
125923
9/24/2020
Email
BANA_EDD_MDL-00129437-
129440"
7/2021
Document
130037
5/14/2021
Document
BANA_EDD_MDL-00145891-
145893
9/14/2020
Email
BANA_EDD_MDL-00154146-
154148
3/3/2021
Letter
BANA_EDD_MDL-00155505-
155506
4/29/2021
Email
157708
1/8/2021
Email
159117
11/2/2020
Email
163308
3/9/2020
Email
167015
3/13/2020
Email
BANA_EDD_MDL-00167019
3/13/2020
PPT
167024
2/20/2020
Email
168422
3/9/2020
Email
BANA_EDD_MDL-00168423
5/22/2020
Email
BANA_EDD_MDL-00171972-
171973
7/10/2020
Email
172473
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6685 Page
55 of 59
8/21/2020
Email
BANA_EDD_MDL-00173006
9/1/2021
Email
BANA_EDD_MDL-00179619
9/14/2020
PPT
187060
9/9/2020
Email
188079
4/23/2021
Email
BANA_EDD_MDL-00190491-
190493
2/5/2021
Document
190918
9/9/2021
Email
202449
1/27/2020
PPT
BANA_EDD_MDL-00211359-
211363
3/10/2020
Email
211373
2/26/2020
Email
213310
8/19/2020
Email
BANA_EDD_MDL-00218256
4/24/2020
Email
228915
3/9/2021
Email
233958
1/21/2021
Email
242716
2/5/2021
Document
253657
2/5/2021
Document
253676
Document
BANA_EDD_MDL-00268581
4/8/2021
Email
BANA_EDD_MDL-00273386-
273387
4/9/2021
Chat
BANA_EDD_MDL-00274164-
274167
5/3/2021
Chat
BANA_EDD_MDL-00274236-
274242
5/20/2021
Email
BANA_EDD_MDL-00274652-
274654
9/7/2021
Email
282292
(from parent
email)
PPT
BANA_EDD_MDL-00287946-
287950
6/2020
PPT
292675
4/23/2021
Email
BANA_EDD_MDL-00297295
1/10/2020
Email
351840
3/3/2020
Email
352397
3/4/2020
Email
BANA_EDD_MDL-00352398
3/4/2020
Email
BANA_EDD_MDL-00352410
3/4/2020
PPT
BANA_EDD_MDL-00352411
3/5/2020
Email
BANA_EDD_MDL-00352432-
352448
4/1/2014
Document
BANA_EDD_MDL-00353351-
353352
9/22/20
Email
BANA_EDD_MDL-00355911
10/1/2020
Email and PPT
BANA_EDD_MDL-00356089-
356095
5/17/2021
Email
BANA_EDD_MDL-00362418
5/18/2021
Email
BANA_EDD_MDL-00362461
8/10/2021
Email
367078
2/5/21
PPT
369754
3/17/21
Email
BANA_EDD_MDL-00369760-
369763
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6686 Page
56 of 59
1/28/2020
Email and PPT
BANA_EDD_MDL-00370150-
370155
5/21/2021
Email and
Document
BANA_EDD_MDL-00401305-
401312
2/19/2021
Letter
BANA_EDD_MDL-00439488-
439493
1/29/2021
Email and PPT
BANA_EDD_MDL-00452786-
452802
8/18/2020
Email
455619
10/6/2021
Email
BANA_EDD_MDL-00465067
9/14/2020
Email
BANA_EDD_MDL-00489662-
489664
9/2/2020
PPT
495285
9/14/2020
PPT
495789
(from parent
email)
PPT
BANA_EDD_MDL-00510120-
510124
PPT
529858
10/26/2020
Chat
BANA_EDD_MDL-00531526
3/17/2021
Letter
BANA_EDD_MDL-00535318-
535319
3/23/2021
Email
BANA_EDD_MDL-00539518-
539519
5/3/2021
Chat
BANA_EDD_MDL-00560053-
560061
1/15/2021
Chat
BANA_EDD_MDL-00589043-
589048
3/13/2021
Email and
Document
BANA_EDD_MDL-0059312-59318
2/20/2020
Email
616322
8/11/2020
Document
BANA_EDD_MDL-00630008-
630009
12/17/2020
Email
673344
2/19/2021
Letter
BANA_EDD_MDL-00674368-
674373
(from parent
email)
PPT
BANA_EDD_MDL-00678778-
678782
9/25/2020
PPT
871864
1/14/2021
Chat
BANA_EDD_MDL-0090695-90698
9/30/2014
Article
3/3/2020
Email
7/10/2015
Document
6/27/2024
Document
7/16/2024
Document
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6687 Page
57 of 59
8/15/2024
Document
8/7/24 (last
accessed
date)
Article
8/12/2021
Article
5/30/2012
Article
9/17/2018
Article
7/14/2011
Article
3/15/2018
Article
3/31/2017
Article
4/17/2023
Article
7/28/2014
Article
9/18/2017
Article
Article
12/6/2002
Article
12/13/2016
Article
3/29/2017
Report
8/4/2015
Article
8/2015
Article
8/1/24 (last
accessed
date)
Article
2022
eBook
11/2014
Document
12/2016
Document
4/6/18
Article
4/2018
Report
6/1/20
Article
2019
Report
2/25/16
Article
9/3/19
Article
6/2019
Report
8/17/22
Article
Article
2012
Report
4/5/13
Article
7/2017
Report
2012
Article
7/23/12
Article
12/15/14
Article
9/30/14
Article
10/23/2014
Order
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6688 Page
58 of 59
8/8/24 (last
accessed
date)
Webpage
5/28/2019
Article
2020
Report
6/2/21
Order
2016
Article
6/23/17
Article
4/2018
Report
11/14/20
Article
11/20/20
Article
8/9/24 (last
accessed
date)
Webpage
8/9/24 (last
accessed
date)
Webpage
Case 3:21-md-02992-GPC-MSB Document 324-5 Filed 08/29/24 PageID.6689 Page
59 of 59File and source
- File
- gov.uscourts.casd.709615.324.5.pdf
- Size
- 1,335,981 bytes
- SHA-256
- c6e0a973fcb277378ea1dee22c88b8a93b2d1ef8a0dfabe8605a5dac42a7d666
- Original
- PACER (login required)