How to Challenge a Bank’s Denial of a Fraud Chargeback in New York Under Regulation E (EFTA)
New York consumers generally have **60 days** from the date a bank sends the statement showing an unauthorized electronic transfer to notify the institution under **Regulation E**. When a bank denies a fraud chargeback, the denial can often be challenged by demanding the bank’s investigation file, correcting errors in how it applied the EFTA, and escalating through regulators or litigation. This article explains deadlines, evidence, dispute letters, and New York-focused escalation steps to overturn a denial.
When a bank denies a “fraud chargeback,” the first step is identifying which legal framework actually applies. For debit cards, ATM withdrawals, ACH transfers, and many peer-to-peer transfers that post to a bank account, the controlling law is usually the Electronic Fund Transfer Act (EFTA) and its implementing rule, Regulation E (12 C.F.R. Part 1005). In New York, challenging a denial typically requires a disciplined timeline: (1) confirm the transaction qualifies as an “electronic fund transfer,” (2) preserve your notice deadline, (3) demand and rebut the bank’s investigation rationale, and (4) escalate through regulators or litigation if the bank fails to comply.
1) Confirm the dispute is covered by Regulation E (and not a credit-card chargeback)
Consumers and even bank staff often use “chargeback” as a catch-all term. But Regulation E is most often about bank account debits, not credit card billing disputes (which are typically handled under the Fair Credit Billing Act/Regulation Z). Regulation E commonly covers:
- Debit card purchases where funds are pulled from a checking account
- ATM withdrawals
- ACH transfers (including many online bill-pay or merchant debits)
- Online banking transfers initiated through the bank’s platform
- Some person-to-person (P2P) transfers tied to an account, depending on product structure
It also covers errors beyond pure fraud—e.g., wrong amount, duplicate transfer, transfer to the wrong payee, or a transfer you did not authorize. If the transaction is a credit card transaction (not a debit from a deposit account), a different dispute path applies.
Example: Debit vs. credit matters
If a New York consumer’s debit card is used at a local electronics store without permission, that typically triggers Regulation E investigation duties. If the same purchase was made on a credit card, you’re in a different statutory lane. Attorneys challenging a denial should start by pinning down the rail: debit/ACH (Reg E) or credit (Reg Z).
2) Know the key Regulation E deadlines that can decide the case
Regulation E has strict timing rules that affect liability and whether a bank may deny a claim.
The 60-day statement rule (critical)
In general, the consumer must notify the financial institution of an unauthorized electronic fund transfer or other error within 60 days after the institution sends the periodic statement on which the error appears. Missing this window can dramatically weaken the claim and may increase exposure for subsequent transfers.
The “two business days” and “60 days” liability framework (overview)
For unauthorized transfers involving an access device (e.g., a debit card), consumer liability can depend on how quickly the loss is reported after learning of it. While details can be fact-specific, prompt notice is always advantageous. In practice, counsel should advise clients to report suspected fraud immediately—even while gathering documentation.
Investigation timeline: 10 business days and provisional credit
Once notified, the bank generally must investigate promptly. If it cannot complete the investigation within a short initial period (often discussed as 10 business days), it may need to provide provisional credit (subject to conditions) while continuing its investigation (often up to 45 days, and longer in limited scenarios such as some point-of-sale or foreign transactions). A denial that skips or mishandles this sequence can be challenged.
Practice point: In a denial appeal, one of the most effective lines of attack is procedural: did the bank meet its Regulation E timing, notice, and explanation requirements?
3) Understand common (and challengeable) reasons banks deny fraud disputes
Banks often deny fraud claims based on standardized narratives. Many are rebuttable with targeted evidence.
Denial reason: “You benefited from the transaction”
Institutions may argue the consumer received goods or services or that a household member made the transfer. Regulation E turns on authorization. Receiving a package does not automatically prove authorization if, for example, the order was made using stolen credentials and delivered to a compromised location.
Denial reason: “The transaction was authenticated”
Banks sometimes rely on internal logs suggesting PIN entry, device recognition, IP address matches, or “strong customer authentication.” Authentication signals can be misleading, especially with SIM swaps, malware, social engineering, or compromised devices. A strong challenge requests the underlying logs and methodology, not just conclusions.
Denial reason: “It’s a scam, not fraud”
Some banks draw a line between “unauthorized” and “authorized but regretted” transfers (e.g., romance scams, fake business invoices). While scam scenarios can be harder, they are not automatically outside Regulation E. The question is whether the consumer actually authorized the specific transfer. If authorization was induced through impersonation, account takeover, or spoofing that resulted in an unauthorized transfer, counsel can often frame the dispute as an EFTA error claim with supporting facts.
4) Build the evidence package that wins Regulation E challenges
Successful challenges are evidence-driven. In New York disputes, attorneys should consider assembling a “bank-ready” record that anticipates denial rationales.
Documents and data to collect
- Account statements showing the disputed transfers
- Bank alerts (SMS/email) and screenshots of fraud notifications
- Timeline of when the client learned of the transfer and when notice was given
- Police report (NYPD or local department) and complaint number when appropriate
- FTC Identity Theft Report if identity theft is suspected
- Device evidence: proof of phone loss, SIM swap, malware scans, carrier logs if available
- Location proof: travel records, work logs, GPS history to rebut “you were present” claims
- Merchant communications (for debit card purchases) and delivery details
- Notarized statement/affidavit describing non-authorization (when strategically helpful)
Example: ATM withdrawals denied due to “PIN used”
A bank may deny a claim because the withdrawals show correct PIN usage. A strong rebuttal can include: (1) evidence the card was never lost, (2) evidence of a skimming pattern at the ATM location, (3) police report, (4) proof the consumer was elsewhere, and (5) prior account takeover indicators (password reset emails, new device logins, SIM swap). The goal is to show PIN entry does not equal authorization.
5) Send a Regulation E “error notice” letter that locks in your rights
Although many disputes start by phone or in-app chat, counsel should ensure the bank receives a written error notice that clearly triggers Regulation E duties. Send it to the bank address designated for errors (often on the statement) and keep proof of delivery.
What the letter should include
- Account holder name, address, and last 4 of account number
- Date(s) and amount(s) of the disputed transfer(s)
- A clear statement: “This is a notice of error under Regulation E”
- Why the transfer is unauthorized or incorrect
- When and how the client discovered the issue
- A request for all documents the bank relied on to deny the claim
- A request for the bank’s investigation results and explanation in writing
Tip for New York practitioners: Include a concise, numbered timeline. Bank investigators (and later, regulators) respond well to a clean chronology: discovery date, report date/time, case number, provisional credit dates, denial date, and each follow-up.
6) Demand the bank’s investigation file and challenge defects
Regulation E requires banks to investigate and to report results. When a denial arrives, the dispute is no longer about “what happened” alone—it becomes about whether the bank’s investigation and explanation meet legal standards.
Common investigation defects to look for
- Conclusory denial letters without meaningful explanation
- Failure to address specific disputed transfers
- Ignoring evidence of account takeover (password resets, new payees, new devices)
- Conflating “scam” with authorization without analyzing consent
- Improper requests that shift investigation burden entirely to the consumer
- Failure to handle provisional credit correctly (timing/conditions)
If the bank’s denial references “device match,” “IP match,” or “PIN used,” request the underlying records. If it will not provide them voluntarily, that refusal can become important in a CFPB/NYDFS complaint or litigation discovery.
7) Escalate in New York: CFPB, NYDFS, and internal bank appeals
When a bank refuses to reverse a denial, escalation can be decisive. A structured escalation also shows reasonableness—useful if the case ends up in court























