Fintech Case Files | September 2026

ƒ Regulatory ISSUE TEN I SEPTEMBER 2026 ƒ Litigation

ISSUE 10 | 3 REGULATORY CFPB Advances Reconsideration of Open Banking Rule The Consumer Financial Protection Bureau (CFPB) has proposed a rule revisiting its Section 1033 open banking framework to the White House Office of Information and Regulatory Affairs (OIRA) for review. The submission marks a significant step toward publication of a proposal that could substantially revise the CFPB’s 2024 Personal Financial Data Rights Rule. The CFPB previously announced that it intended to reconsider key aspects of the existing framework, including who may access consumer-authorized financial data, whether financial institutions may charge third parties for data access, and how to address privacy, cybersecurity, and operational concerns associated with data sharing. Industry participants have closely scrutinized the rule because of the costs associated with maintaining data-sharing infrastructure and the obligations imposed on banks, fintech companies, and data aggregators. Although the substance of the proposal has not yet been released publicly, reports indicate the CFPB may permit financial institutions to charge fees for access to consumer-authorized account information, a departure from the 2024 rule, which generally required covered institutions to provide data access without charge. Once OIRA completes its review, the CFPB may publish the proposal and begin a formal notice-and-comment process. OCC Confirms National Bank Act Preempts State MoneyTransmitter Licensing Requirements The Office of the Comptroller of the Currency (OCC) issued Interpretive Letter 1192, concluding that the National Bank Act preempts state money-transmitter licensing requirements applied to national banks. The letter was issued in response to a request from Fidelity Digital Assets, National Association, an OCC-chartered national trust bank that sought confirmation that it could conduct its federally authorized activities nationwide without obtaining state money-transmitter licenses. The request arose after Fidelity Digital Assets converted from a New York–chartered trust company to a national bank in December 2025 and surrendered its Iowa money-transmitter license. Iowa took the position that the institution did not qualify for the state’s exemption from money-transmitter licensing requirements because it did not have federally insured deposits. The OCC nevertheless concluded that state licensing requirements are preempted regardless of whether a national bank qualifies for a particular state-law exemption. Relying on long-standing National Bank Act preemption principles and U.S. Supreme Court precedent, the OCC concluded that states cannot require a national bank to obtain a state money-transmitter license as a condition of exercising federally authorized powers. The OCC further determined that state money-transmitter licensing regimes generally conflict with federal law because they subject national banks to examinations, reporting obligations, and other forms of supervision that constitute impermissible visitorial oversight under 12 U.S.C. § 484. The OCC emphasized that its conclusion extends beyond Iowa and applies to any similar state moneytransmitter licensing regime that purports to apply to national banks, including laws that limit licensing exemptions to only certain categories of national banks. California Court Rejects Regulator’s Challenge to Fintech Lending Model The Los Angeles County Superior Court rejected the California Department of Financial Protection and Innovation’s (DFPI) challenge to the business model of Opportunity Financial LLC (OppFi), a fintech that offers loans through its lending platform in partnership with Utah-chartered FinWise Bank. The court focused on whether the loans were “usurious at inception” and concluded that they were not. Central to that conclusion was the court’s finding that FinWise—not OppFi—was the true lender because it played a substantive role in the lending program. Among other things, FinWise underwrote the loans, funded them with its own money, was identified as the lender on the promissory notes, and bore economic risk on the loans. The court held that the loans offered to California consumers by Utah-chartered FinWise were not usurious under Utah law. The ruling is a setback for the DFPI and a favorable development for fintech companies that operate through bank-partnership lending models involving banks chartered in other states. New York Advances BNPL Regulations The New York Department of Financial Services (NYDFS) has issued proposed regulations implementing the state’s buy now, pay later (BNPL) law, moving New York closer to establishing a comprehensive regulatory framework for BNPL providers. The proposal is the latest step in New York’s effort to regulate a rapidly growing consumer credit product. The proposed regulations broadly define BNPL loans as closed-end credit provided for a consumer’s purchase of goods or services and apply to both interest-free and interest-bearing BNPL products. The proposal also adopts an expansive definition of a BNPL lender that encompasses not only entities that make or acquire BNPL loans but also operators of platforms, software, or systems through which consumers obtain BNPL loans from third parties. The regulations would impose extensive requirements governing disclosures, underwriting, billing practices, payment processing, data privacy, and customer service. If adopted, the regulations would significantly expand oversight of BNPL providers operating in New York and could serve as a model for other states considering similar legislation or regulatory frameworks. The proposal reflects a broader trend of increased state-level scrutiny of BNPL products as regulators continue to evaluate whether existing consumer lending laws adequately address the industry. Illinois Enacts Legislation to Regulate Buy Now Pay Later Lenders Illinois Governor JB Pritzker signed into law the Buy-Now-Pay-Later Loan Consumer Protection Act, which establishes a comprehensive licensing and supervisory framework for BNPL providers operating in Illinois. Among its key protection provisions, the law mandates clear pretransaction disclosures— including total cost, payment schedule, and any applicable fees—and imposes restrictions on late fees, interest charges, and other penalty-based revenue models. The law also provides consumers with a right to cancel a BNPL agreement within a specified period and requires providers to establish dispute resolution procedures. Illinois’s BNPL law reflects a growing state-level trend toward closing a perceived gap in the oversight of short-term, point-of-sale installment credit products. Unlike traditional installment lenders, many BNPL providers have historically operated outside the scope of state lending and licensing statutes, in part because their products are often structured to avoid triggering interest-based regulatory thresholds.

ISSUE 10 | 5 Oregon Proposes BNPL Licensing Guidance The Oregon Department of Consumer and Business Services has proposed a bulletin that would require nonbank BNPL providers and BNPL service providers to obtain either a payday lender license or a consumer finance license before operating in the state. The licensing requirement would depend on the repayment term of the product, with loans of 60 days or less falling under Oregon’s payday lending laws and longer-term products subject to Oregon’s consumer finance laws. The proposal takes the position that BNPL products constitute loans under Oregon law regardless of whether they charge interest or fees and regardless of whether they are marketed as nonrecourse loans. The proposed bulletin also states that licensing requirements may apply not only to BNPL lenders but also to brokers, facilitators, agents, and service providers involved in originating or servicing BNPL products. If adopted, the bulletin would place Oregon among a growing number of states seeking to expand oversight of BNPL products and providers. Multistate Settlement Highlights Oversight Risks in Pointof-Sale Lending A coalition of state attorneys general led by Texas announced a multistate settlement with GreenSky Holdings LLC and GreenSky LLC, resolving allegations that merchants participating in GreenSky’s point-of-sale financing program engaged in deceptive lending practices and that GreenSky failed to maintain adequate oversight of those merchants. The investigation was prompted by consumer complaints alleging that loans were opened without consumers’ knowledge or consent, loan terms were misrepresented, and vulnerable consumers, including elderly individuals and persons with cognitive impairments, were pressured into financing arrangements they did not legally authorize. The settlement requires GreenSky to pay $10 million and includes injunctive provisions designed to strengthen GreenSky’s compliance controls and merchant-monitoring processes going forward. FTC Takes Action Against Payment Processor for Facilitating Sham Merchant Transactions The Federal Trade Commission (FTC) announced that payment processing company Humboldt Merchant Services would pay $12 million and be permanently barred from processing payments for merchants presenting a heightened risk of potential fraud. The FTC filed a complaint and proposed stipulated order in the Eastern District of Michigan. According to the complaint, Humboldt processed payments for more than 1,000 merchants that operated as shell entities or fronts for fraudulent companies engaged in unauthorized billing schemes, including Legion Media, which the FTC shut down in 2024. The FTC alleged that Humboldt opened and processed payments for merchants it knew, or consciously avoided knowing, were shell companies used by undisclosed third parties engaged in fraud. The complaint further alleged that Humboldt ignored red flags indicating that the merchants were shells and typically incurred chargebacks at rates almost 10 times higher than levels credit card brands consider excessive. The FTC also alleged that Humboldt attempted to increase transaction volume through the sham accounts by placing them on a lower-risk bank identification number licensed by an affiliated entity, improving the likelihood that transactions would be approved. Under the proposed order, Humboldt would be prohibited from credit card laundering and processing for four categories of merchants: straw companies; merchants listed in the card networks’ MATCH database for chargebacks, laundering, or fraud; merchants subject to law enforcement action; and ecommerce entities using third-party mailbox providers as their only business location that engage in negative-option billing or lack processing history. The order would also bar Humboldt from providing or assisting in providing false or misleading information to obtain payment processing and from using tactics to avoid fraud and risk monitoring, including load balancing. The deputy director of the FTC’s Bureau of Consumer Protection stated that the case underscored the FTC’s commitment to holding companies accountable for knowingly supporting fraudulent businesses. FTC Settles with Payment Processor over Merchant Fraud Allegations The FTC filed a complaint in the District of Arizona against Canadian payment processor Nuvei Corporation and four subsidiaries, including Nuvei Technologies Inc., a Delaware corporation based in Scottsdale, Arizona. The FTC alleged violations of Section 5(a) of the FTC Act and the Telemarketing Sales Rule, asserting that Nuvei opened and maintained merchant accounts for businesses it knew or should have known were engaged in deceptive conduct, including tech-support scams targeting U.S. consumers. The parties filed a stipulated order the following day. The FTC’s central example involved Reimage, a tech-support scheme for which Nuvei allegedly processed more than $30 million in consumer payments from 2017 through 2023. In 2020, Visa warned Nuvei that Reimage was impersonating Microsoft through fake virus alerts and directing consumers to offshore call centers. The FTC alleged that, despite the warning and a resulting fine, Nuvei increased its processing for Reimage. The complaint also alleged that Nuvei opened accounts for merchants promoting business opportunities with false earnings claims, impersonating government tax authorities, or previously terminated by other processors for excessive chargebacks or fraud. Under the stipulated order, Nuvei agreed to pay a $4.85 million monetary judgment for consumer redress and was permanently barred from processing payments for tech-support telemarketers. The order also requires enhanced screening and monitoring of prospective and existing covered clients, including monthly monitoring, quarterly test calls, and investigations triggered by chargeback rates above 1% when a merchant records more than 75 chargebacks in a month. Nuvei neither admitted nor denied the allegations. FTC Wins Contempt Order Against Payment Processor for Violating Consent Order A Nevada federal court imposed $6.5 million in sanctions against payment processor Cliq for violating multiple provisions of a 2015 FTC consent order. The court, however, declined the FTC’s requests to appoint a receiver, bar Cliq’s executives from the payments industry, or award the approximately $52.9 million in relief sought by the agency. The dispute traces back to a 2014 FTC complaint alleging that Cliq (then known as CardFlex) helped a deceptive merchant, I Works, obtain and maintain payment processing access despite repeated placement on high-risk merchant lists and excessive chargeback activity. The FTC further alleged that Cliq enabled I Works to evade card-network monitoring programs through the use of shell companies and multiple merchant accounts. Under the 2015 consent order, Cliq was required to implement enhanced merchant-risk controls, including restrictions on processing MATCH-listed merchants, facilitating evasion of card-network monitoring programs, and onboarding high-risk merchants without specified underwriting and due diligence. The Nevada federal court found that Cliq violated those requirements by processing transactions for certain prohibited merchants, assisting merchants in evading network risk controls, failing to conduct required reviews, and continuing to process merchants with excessive chargebacks without the investigations and reporting mandated by the order.

ISSUE 10 | 7 UK Regulator’s Digital Wallet Competition Probe The UK Financial Conduct Authority (FCA) announced that it has opened a competition investigation into PayPal, Visa, and Mastercard over contractual arrangements governing the funding and use of PayPal’s digital wallet. The FCA confirmed that it is investigating all three companies under Chapter I of the UK’s Competition Act 1998 and is separately investigating Visa and Mastercard under Chapter II, which addresses potential abuses of a dominant market position. Importantly, the regulator emphasized that it has reached no conclusions and has not found that competition laws were violated. According to public disclosures, the investigation focuses on provisions in PayPal’s agreements with Visa and Mastercard relating to how consumers fund and use the PayPal wallet. While the FCA has not disclosed the specific contractual terms at issue, the probe comes amid growing regulatory scrutiny of digital wallets and payment ecosystems. Digital wallet usage in the UK has increased significantly in recent years, and regulators have expressed concerns that commercial arrangements among major payment providers could affect competition, innovation, and consumer choice. Illinois Enacts Retail Cash Payment Act Requiring Businesses to Accept Cash The Retail Cash Payment Act, signed into law in July, takes effect January 1, 2028. Under the act, covered retail establishments may not refuse cash for in-person sales of less than $500, post signage stating that cash is not accepted, or charge higher prices to customers who pay in cash. Businesses are not required to accept bills larger than $20. Covered establishments include fuel stations, grocery stores, pharmacies, and restaurants that employ an individual to accept in-person payments at a physical location. The act exempts self-service checkout transactions if at least one staffed register at the location accepts cash, sales between 10 p.m. and 6 a.m., a temporary inability to accept cash because of a system failure or insufficient change, membership-model establishments, establishments that provide a mechanism to convert cash into a prepaid card on or within the premises, and transactions conducted by telephone, internet, or mobile application. The statute also allows a business to comply with the self-service exception by maintaining at least one cash-accepting point of sale. Violations are petty offenses subject to fines of $50 for a first violation, $100 for a second violation within 12 months, and $500 for a third or subsequent violation within 12 months, with a $5,000 calendar-year cap. A 30-day cure period is required before a fine may be imposed. The act further declares that it preempts local regulation. Illinois joins a growing list of states addressing cashless commerce; New York prohibits food stores and retail establishments from refusing cash, and Delaware enacted the Consumer Equal Access Protection Act. The Illinois law reflects a broader nationwide effort to preserve cash as a payment option. CFTC Seeks to Unwind Biden-Era Crypto Settlement The Commodity Futures Trading Commission (CFTC) and crypto exchange Gemini jointly asked a New York federal court to vacate portions of a January 2025 consent order that resolved the agency’s long-running case against the crypto exchange. According to the CFTC, a subsequent review of the investigation concluded that the complaint should not have been filed and would not have been brought under the agency’s current enforcement standards. The agency cited concerns about the credibility of a key whistleblower, the strength of the evidence, and aspects of the investigation and litigation process. The underlying case stemmed from allegations that Gemini made false or misleading statements to the CFTC during the process of seeking approval for a bitcoin futures product. Gemini previously agreed to a settlement that included a $5 million civil monetary penalty and injunctive relief. While the parties now seek to vacate the settlement’s prospective provisions, the penalty has already been paid and will not be refunded. New York AG Reaches Settlement with Crypto Platform over Promotion of Crypto Yield Product The New York Attorney General’s Office reached a settlement with cryptocurrency platform Uphold HQ Inc., resolving an investigation into Uphold’s promotion of CredEarn, a cryptocurrency yield product offered by Cred LLC. The assurance of discontinuance required Uphold to pay $5 million to compensate investors. New York claimed that Uphold marketed CredEarn as a safe, savings-like investment product without adequately disclosing that CredEarn’s returns were in fact generated through high-risk microloans. New York further claimed that Uphold misrepresented the availability of insurance protections for investors and engaged in the offer or sale of CredEarn securities and cryptocurrency without registering as a broker or commodity broker-dealer with the state. Without any admission of wrongdoing, the settlement includes requirements that Uphold strengthen its due diligence procedures for third-party investment products and register as a broker with the New York Attorney General’s Office before engaging in similar activities. This case is significant because it represents the first enforcement action by the New York attorney general against a platform that promoted a third-party yield product. California Reaches Settlement with Fintech over Alleged FDIC Insurance Misrepresentations The DFPI announced a settlement with fintech Yotta Technologies Inc., resolving claims of deceptive marketing practices. The DFPI alleged that Yotta marketed customer savings accounts as FDIC insured, but transferred customer funds into accounts maintained through Synapse Brokerage LLC that were not covered by FDIC insurance. When Synapse filed for bankruptcy in April 2024, thousands of consumers lost access to their funds. The consent order requires Yotta to pay a $1 million civil penalty and implement remedial measures designed to assist affected consumers. Foreign Bank Settles with New York After Misleading Fee Disclosures Investigation The North American subsidiary of a foreign bank settled with the NYDFS following an investigation into undisclosed extension fees on automobile loans. According to the NYDFS, the bank advertised to consumers that extensions on automobile loans were available for a single $25 fee but failed to disclose in those advertisements that the $25 fee was monthly. The bank agreed to pay a penalty of $400,000 and return more than $275,000 to affected customers. The settlement underscores the importance of transparent fee disclosures in consumer lending.

ISSUE 10 | 9 LITIGATION Revised Swipe Fee Settlement Receives Initial Court Approval In re Payment Card Interchange Fee and Merchant Discount Antitrust Litigation, No. 1:05-md-01720 (E.D.N.Y.). The Eastern District of New York granted preliminary approval to a revised $38 billion settlement between Visa, Mastercard, and a class of more than 12 million merchants in the long-running interchange fee antitrust litigation that began in 2005. In granting preliminary approval of the revised settlement, the court acknowledged nearly 40 objection letters, but noted it was “too soon to tell” whether the concerns were widespread among the class or “confined to a vocal minority.” The revised settlement includes several notable structural concessions, including most notably that Visa and Mastercard have agreed to reduce average interchange fees by approximately 0.1 percentage point over five years and to cap the standard consumer credit card interchange rate at 1.25% for eight years—a reduction of more than 25% from pre-settlement levels. Under the revised settlement, merchants would also gain expanded surcharging flexibility, including the ability to impose surcharges on certain higher-fee cards or offer discounts for lower-fee payment methods. While the preliminary approval is a significant milestone, the settlement is not yet final and remains subject to further objections and a final approval hearing. Court Approves Settlement Resolving Interchange Fee Classification Claims CAPP Inc. v. Discover Financial Services, No. 1:23-cv-04676 (N.D. Ill.). The Northern District of Illinois granted final approval of the settlement agreement that resolved allegations that Discover improperly classified certain consumer credit card accounts as commercial accounts between 2007 and 2023, resulting in excessive interchange fees across the payment ecosystem. The settlement class includes all end merchants, merchant acquirers, and payment intermediaries that processed or accepted a misclassified card transaction during that period. Under the settlement, Discover will reimburse eligible class members for 100% of their estimated overcharges, plus compounded interest, subject to a minimum fund of $540 million and a maximum recovery of approximately $1.225 billion, excluding additional post-2024 interest. The court additionally awarded $25 million in attorneys’ fees, $307,000 in litigation expenses, and service awards of $7,500 to each class representative. First Circuit Holds Card Waived Arbitration Right by Refusing to Pay Filing Fees 5-Star General Store v. American Express Company, No. 25-1023 (1st Cir.). The First Circuit affirmed the denial of American Express Company’s motion to stay a class action and compel arbitration arising from the company’s swipe-fee policies. Thousands of small merchants had initiated arbitrations before the American Arbitration Association (AAA) in August 2023. The AAA administrator determined the filing fees, and the merchants paid their share. American Express disputed the amount and refused to pay its share. The AAA repeatedly warned the parties that nonpayment would result in administrative closure. When American Express still did not pay, the AAA administratively closed the arbitrations. The merchants then filed a class action in the District of Rhode Island, arguing that American Express’s refusal to pay constituted a default and waiver of its contractual right to compel arbitration under the Federal Arbitration Act (FAA). The district court denied American Express’s motion to stay the litigation and compel arbitration, agreeing with the merchants. The First Circuit affirmed, holding that the district court had authority to determine whether American Express’s conduct amounted to waiver or default under the FAA. The appeals court concluded that American Express’s deliberate refusal to pay the arbitration fees, despite repeated warnings and an opportunity to cure the nonpayment, constituted both waiver and default. The court also found no error in the district court’s rejection of American Express’s unclean-hands defense. The decision underscores that a party that deliberately refuses to pay required arbitration fees after receiving notice and an opportunity to do so may lose its contractual right to compel arbitration. Credit Cards Granted Permission to Appeal Landmark UK Interchange Fee Ruling Earlier this year, the UK Court of Appeal granted Visa and MasterCard permission to challenge a 2025 ruling issued by the UK Competition Appeal Tribunal (CAT) that the default multilateral interchange fees (MIFs) imposed by Visa and Mastercard on retailers during card transactions violated EU and UK competition law. The 2025 ruling was notable because it was the first occasion on which courts found that unregulated interchange fees are considered inherently anticompetitive, even when fees have been subject to regulatory oversight. In granting Visa and MasterCard the right to appeal that ruling, the Court of Appeal appears to be focused on whether the CAT misapplied precedent, including a counterfactual analysis and whether the networks’ “default rule” interchange-fee structure itself restricted competition. UK Competition Appeal Tribunal Imposes Deadline for Additional Claimants to Join Interchange Fee Proceedings The Merchant Interchange Fee Umbrella Proceedings involve thousands of UK merchants alleging that Visa and Mastercard charged unlawfully high card transaction fees in violation of UK and EU competition laws. The claims are being managed together before the UK’s CAT, which is a specialized judicial body that hears competition-law and economic-regulation disputes. The CAT is resolving common issues through coordinated trials. The CAT has already found that Visa’s and Mastercard’s fee arrangements infringed competition law, but will now consider, in Trial 3, whether those arrangements nevertheless qualify for a competitionlaw exemption. In a recent case-management decision, the CAT considered whether additional claimants should be allowed to join the Trial 3 proceedings. The defendants argued that a cutoff date was necessary to protect the integrity of the evidentiary process and ensure fairness. The CAT agreed, emphasizing that the umbrella proceedings are designed to promote efficient case management while remaining fair to all parties. Concerned that unlimited participation could undermine the selected claimant sample and evidentiary record, the CAT imposed a deadline of October 23, 2026 for additional claimants to join Trial 3.

ISSUE 10 | 11 More Than 30 Firms Suing over Interchange Fees Boels Rental Ltd. and others v. Visa Europe Ltd. and others, No. CL-2026-000241 and Boels Rental Limited and others v. Mastercard Incorporated and others, No. CL-2026-000240. More than 30 major businesses—including H&M, Heineken, Eurostar, Patagonia, and Queen’s University of Belfast—have brought competition-law claims against Visa and Mastercard in the United Kingdom. The Boels claims allege that Visa’s and Mastercard’s multilateral interchange fee arrangements and associated rules forced merchants to pay higher service charges and blocked lower-cost alternatives to payment. The claimants are seeking damages and a declaration that the rules were void as breaches of competition law. The claimants successfully transferred the proceedings to the CAT, and the proceedings will now join long-running litigation before the CAT, which created umbrella proceedings in 2022 to manage claims from over 2,100 merchants. The CAT has previously found that pre-2015 interchange fees charged by Visa and Mastercard violated competition law. In the latest development, the CAT’s president ordered that the Boels claims against both Visa and Mastercard be brought within the umbrella proceedings framework. The parties will be bound by future umbrella determinations on common issues while retaining the ability to seek application of earlier trial judgments by agreement or other means. UK Merchants File Competition Claim Challenging Commercial Card Interchange Fees Water Plus Limited and Others v. Visa Incorporated and Others and Mastercard Incorporated and Others, No. 1787/5/7/26 (CAT). A water utility and two hotel companies brought a competition damages action against Visa and Mastercard in the UK CAT. The claimants challenged the card brands’ interchange-fee framework for commercial card transactions, alleging that they violated UK and EU competition law by unlawfully restricting competition in two ways. First, the claimants contended that the card brands’ default interchange fees inflate the cost of accepting commercial cards by establishing a minimum level for the fees acquirers charge merchants. Second, the claimants alleged that the card brands’ acquiring rules impeded competition among acquirers across European markets, allowing interchange fees to remain higher than necessary. The claimants sought damages and compound interest for losses allegedly incurred from July 17, 2020 onward. The proceedings have since been stayed by consent pending resolution of an appeal in the related Commercial and Interregional Card Claims (CICC) collective proceedings. The CICC proceedings are opt-in and opt-out collective actions brought on behalf of UK merchants against Visa and Mastercard, alleging that multilateral interchange fees on commercial and interregional card transactions violate UK and EU competition laws. The appeal arises from the CAT’s March 2026 opt-in application judgment, which held that only a natural or legal person, and not an undertaking or corporate group, may validly opt in to collective proceedings. Under the CAT’s order, the stay will remain in place until 30 days after any appeal of the CICC opt-in application judgment is finally determined, though any party may seek termination of the stay on notice. The action arrives amid a broader wave of UK interchange-fee litigation. If successful, the litigation could increase scrutiny of commercial-card revenue models, affect acquirer pricing practices, and encourage additional merchant claims across industries. D.C. Circuit Denies Government’s Bid to Immediately Slash CFPB Workforce National Treasury Employees Union v. Vought, No. 25-5091 (D.C. Cir.). In an en banc order, the D.C. Circuit Court declined the CFPB’s latest bid to immediately implement a plan to downsize its workforce. The government’s motion would have permitted acting CFPB Director Russell Vought to immediately lay off approximately half the CFPB’s remaining workforce, reducing it to 556 employees. The court denied the government’s motion but granted a limited remand for the district court to decide whether to modify, suspend, or dissolve the preliminary injunction in light of the CFPB’s new plan and other intervening developments. The appeal stems from a case brought by the National Treasury Employees Union and other plaintiffs against Vought for violations of the Administrative Procedure Act. The operative complaint accuses the CFPB of orchestrating a campaign to illegally dismantle the agency. In March 2025, the district court entered a preliminary injunction after finding that CFPB officials had been engaged in a “concerted, expedited effort to shut the agency down entirely” and that they had “absolutely no intention of operating the CFPB at all.” The government appealed and moved to modify the stay pending appeal, arguing that a new proposed workforce reduction plan superseded prior plans and that congressional funding cuts made current staffing levels unsustainable. Ultimately, the D.C. Circuit denied the CFPB’s request for immediate implementation of the workforce reduction plan and granted a limited remand.. Court Rules Former Parent Company Cannot Recover $1.7 Billion from FDIC Receivership SVB Financial Group v. Federal Deposit Insurance Corporation, as Receiver for Silicon Valley Bank, No. 5:24-cv-01321 (N.D. Cal.). Following a bench trial, the Northern District of California ruled that the litigation trust succeeding to SVB Financial Group’s claims was not entitled to recover approximately $1.7 billion from the FDIC as receiver for Silicon Valley Bank. Silicon Valley Bank was closed by the California Department of Financial Protection and Innovation, and the FDIC was appointed receiver. SVB Financial Group was the bank’s parent holding company, and its litigation trust later filed a $1.7 billion claim against the receivership estate. The parties stipulated that the FDIC’s liability would be $1.7 billion, subject to reduction by the trust’s liability for any affirmative defenses on which the FDIC prevailed. The FDIC invoked affirmative defenses under the Federal Deposit Insurance Act, which permits the FDIC as receiver to succeed to the failed bank’s rights and assert offsets against claims on the receivership estate. The court found that SVB Financial Group executives were dual-hatted as officers of both the holding company and the bank and breached their fiduciary duties to the bank. According to the court, they caused the bank to assume excessive interest-rate and liquidity risk for the benefit of the holding company. The court further found that other executives, including members of the finance and risk committees, knew of the breaches. The FDIC established approximately $4.5 billion in damages arising from securities mismanagement, exceeding the trust’s $1.7 billion claim and resulting in a complete offset. The court explained: “The holding company chose to run the bank through holding company officers in accordance with the global, enterprise-wide policies, limits, and metrics that the holding company established. Having made this choice, it must live with the consequences.” The ruling is one of the largest bank-failurerelated judicial decisions in recent years and reinforces the FDIC’s authority to assert affirmative claims against company affiliates whose conduct contributed to a bank’s failure.

ISSUE 10 | 13 Constitutionality of Tennessee Cross-Border Payments Tax Challenged Financial Technology Association v. Gerregano, No. 26-0753-III (Tenn. Ch. Ct., Davidson Cnty.). The Financial Technology Association (FTA) filed a declaratory judgment action in Tennessee Chancery Court challenging the constitutionality of House Bill 2502, a new state law imposing a sales tax on international money transmissions. HB 2502 imposes a $10 tax per transaction on international money transfers originating in Tennessee and transmitted by entities licensed under the state’s Money Transmission Modernization Act, plus an additional 2% tax on any amount exceeding $500. The tax applies only to money transmitted to locations outside the United States—domestic transfers are not subject to the levy. The FTA, which brings the action on behalf of members including PayPal and Remitly, argues that by singling out only foreign-bound transactions for taxation, HB 2502 facially discriminates against foreign commerce in violation of the dormant Commerce Clause and constitutes an unauthorized state impost on exports in violation of the Import-Export Clause. The complaint contends that both provisions reflect the U.S. Constitution’s commitment to ensuring the federal government speaks with one voice on matters of foreign commerce. The complaint seeks a declaration that HB 2502 is unconstitutional and a permanent injunction barring enforcement before the tax’s January 1, 2027 effective date. The FTA asserts that its members must modify transaction-processing systems, compliance software, and customer-facing interfaces to comply with the law’s requirements, and that these costs are unrecoverable due to sovereign immunity. Bank Files Interpleader Action over $144 Million Account Amid Competing Demands from CFPB and Judgment Debtors Merchants Bank of Indiana v. Consumer Financial Protection Bureau, No. 2:26-cv-07259 (C.D. Cal.). A dispute over $144 million in pledged assets prompted Merchants Bank of Indiana to bring an interpleader action in the Central District of California. The underlying controversy stems from a CFPB enforcement action against CashCall Inc. and its owner, which culminated in a judgment exceeding $157 million for allegedly unlawful lending and debt collection practices. While CashCall and related entities pursued appellate review of the judgment, they pledged approximately $144 million in cash, Treasury bills, and other assets as collateral, with Merchants serving as custodian. The U.S. Supreme Court denied certiorari, triggering competing demands on the bank. The CFPB directed Merchants to transfer the collateral to the CFPB, asserting that the judgment was final and the debtors had failed to satisfy their payment obligations. That same day, CashCall’s counsel instructed the bank to hold the funds, arguing that a forthcoming motion to vacate meant the litigation remained unresolved. Caught between these conflicting instructions, Merchants filed its interpleader complaint. It alleged that it has no ownership interest in the account and cannot safely determine which demand is proper without judicial intervention, asking the court to resolve the competing claims, clarify its custodial obligations, and discharge it from potential liability. The case has since been automatically stayed following CashCall’s Chapter 11 bankruptcy filing. Court Declines to Dismiss Buy Now, Pay Later Antitrust Case Sezzle Inc. v. Shopify Inc., No. 0:25-cv-02395 (D. Minn.). The court declined to dismiss Sezzle Inc.’s lawsuit against Shopify Inc., in which Sezzle claims that Shopify violated federal and Minnesota antitrust law. Sezzle contends that Shopify has made it harder for consumers to use Sezzle’s buy now pay later (BNPL) services that allow consumers to purchase goods in interest-free installments on merchant websites. Sezzle alleges that Shopify obscured Sezzle’s checkout option behind a counterintuitive purchase screen, imposed a third-party payment fee on merchants using Sezzle, disabled Sezzle’s real-time inventory-locking feature, and cut off order identification numbers for Sezzle transactions, among other things. Shopify launched its own competing BNPL product, Shop Pay Installments, in June 2021. The court allowed Sezzle’s monopolization and attempted monopolization claims under Section 2 of the Sherman Act to go forward, finding Sezzle plausibly defined a relevant BNPL aftermarket on Shopify platforms distinct from credit cards and personal loans, within a foremarket where Shopify holds at least 70% share. The court found the single-brand aftermarket factors articulated in Epic Games Inc. v. Apple Inc. less important given Shopify’s foremarket dominance but found that Sezzle satisfied them regardless. The court also held that Sezzle’s unlawful contracts claim survived because the contractual third-party payment fee constituted concerted action that plausibly “imposed an unreasonable restraint” given Shopify’s market power. The Minnesota statutory claims also survived to the same extent as federal claims. The court dismissed the tying claims under Section 1 of the Sherman Act and its state-law counterpart because Sezzle failed to allege coercion. Merchants could still enable Sezzle, and 15–25% of BNPL transactions remained separate from Shopify’s in-house BNPL service—too high to establish a de facto tie. Who Owns the Coins? Customer Assets, Trusts, and Unsecured Creditors in UK Crypto Insolvencies When a crypto business fails, one question often matters more than any other for customers: Do they still own their crypto assets, or are they left with only an unsecured claim against the insolvent company? English law now gives a clear starting point. The Property (Digital Assets etc) Act 2025 confirms that digital or electronic assets are capable of being owned and may form part of an insolvent estate. But ownership in this context is closely tied to control. Under Principle 6 of the UNIDROIT Principles on Digital Assets and Private Law, control involves “the exclusive ability to prevent others from obtaining substantially all” the benefit of the asset, to obtain that benefit oneself, and to transfer those powers to another person. That recognition, however, does not answer the practical question of who owns assets held by an insolvent platform. The key issue is whether the company held the crypto assets on trust for its customers. If a valid trust exists, customers are likely to be treated as beneficial owners and may be able to recover the assets, subject to any applicable costs. The assets would not belong beneficially to the company and would not be available for distribution to general unsecured creditors. For that reason, the UK Jurisdiction Taskforce has emphasized the value of clear custody arrangements from the outset. An express trust, requiring certainty of intention, objects, and subject matter, provides the greatest certainty for customers seeking protection against insolvency risk. By contrast, if the contractual arrangements create only a debtor-creditor relationship, customers are unlikely to have proprietary rights in specific assets. Their claim will instead be against the insolvent company, ranking alongside other unsecured creditors. The distinction is especially significant when platforms pool customer assets, rehypothecate them, or reserve broad rights to use deposited digital assets. The starting point is therefore how a crypto asset is held. In a custodial model, the custodian controls the private keys; in a non-custodial model, the user retains that control; and hybrid structures may raise more complex questions. For customers, platforms, and insolvency practitioners alike, the lesson is clear: The legal and operational arrangements should be understood before insolvency occurs, not after. Anna Nolan Partner

ISSUE 10 | 15 Anti-steering Antitrust Suit Dismissed with Prejudice Sabol v. PayPal Holdings Inc., No. 4:23-cv-05100 (N.D. Cal.). The Northern District of California dismissed with prejudice the federal antitrust claims asserted against PayPal challenging the company’s anti-steering rules for online merchants. Consumers alleged that PayPal’s merchant agreements prevented merchants from steering customers toward lower-cost payment methods, resulting in higher processing fees and retail prices. After two prior amendments, the second amended complaint added allegations about PayPal’s market position, payment-processing economics, and the pass-through of transaction fees to consumers. Although the court indicated that the revised allegations may have addressed market-power concerns, it ruled that the plaintiffs still lacked antitrust standing. The alleged injuries remained too indirect and speculative because the complaint did not plausibly link PayPal’s fees to prices paid by particular consumers or show the significance of those fees compared to other ecommerce pricing factors. The court also rejected reliance on a separate ecommerce payment-processing market and dismissed the Sherman Act claim with prejudice and without further leave to amend. The ruling also eliminated the remaining state-law claims. The court had previously allowed the plaintiffs to supplement their allegations over jurisdiction under the Class Action Fairness Act (CAFA), but the amended complaint still did not allege the amount of any plaintiff’s online spending or the magnitude of any overcharge. After dismissing the federal claim and finding CAFA jurisdiction inadequately pleaded, the court declined to exercise jurisdiction over the state-law claims and dismissed them without prejudice. Second Challenge to Acquisition of Discover Stalls as Challengers Given Final Attempt Fry v. Capital One Financial Corp., No. 4:25-cv-03769 (N.D. Cal.). The Northern District of California again dismissed a lawsuit brought by credit card users challenging Capital One’s $35 billion acquisition of Discover, finding the credit card users’ cursory allegations did not establish how they were harmed by the merger and, therefore, did not adequately plead Article III standing to challenge the purchase. Capital One completed the acquisition on May 18, 2026. The dismissal was without prejudice, allowing the credit card users to again amend their complaint to raise adequate factual allegations. Any subsequent amendment, however, would likely be the credit card users’ last chance to bring their challenge—the court indicated it is unlikely to allow further amendments. In particular, the order emphasized that the complaint does not describe what cards the plaintiffs have or how they use them, that the plaintiffs actually participate in the relevant markets, and that the plaintiffs’ allegations are “based on an attenuated chain” of events. The plaintiffs filed a second amended complaint, and the parties have submitted briefing on Capital One’s motion to dismiss. Capital One argues that the plaintiffs still have not established standing to challenge the acquisition of Discover, noting that the allegations that the merger will substantially lessen competition and that the plaintiffs may be harmed are based on the same attenuated chain of inferences the court previously rejected and are too conclusory to show a substantial risk the alleged harm will occur. Court Narrows and Then Denies Class Certification in Website Tracking Action Shah v. Capital One Financial Corporation, No. 3:24-cv-05985 (N.D. Cal.). This action filed in 2024 alleges that Capital One deployed third-party tracking technologies on its website that intercepted and transmitted customer data, including employment information, banking details, citizenship status, credit card application outcomes, and online activity, to entities such as Google, Meta/Facebook, and Adobe. The plaintiffs contended that the data sharing served no purpose other than facilitating targeted marketing and advertising. They sought damages, restitution, disgorgement, injunctive and declaratory relief, and attorneys’ fees on behalf of a nationwide class and California subclass, asserting privacy, consumer protection, contract, and common-law claims under both California and federal law. In May 2026, the court dismissed plaintiff Ingraham for lack of standing but denied Capital One’s motion as to the plaintiff Williams. The court found that Ingraham’s continued use of Capital One’s application process after filing suit undermined his asserted expectation of privacy. In contrast, the court held that Williams adequately alleged that Capital One shared personally identifiable information with third parties without sufficiently disclosing those practices and that factual disputes precluded dismissal. In June 2026, the court denied the plaintiffs’ motion for class certification on commonality and predominance grounds. The court found that though Capital One’s data-sharing practices raised common questions, determining whether and what information was shared for each user would require individualized proof. The court also held that consent, standing, and injury would require userspecific inquiries, including each user’s subjective understanding of Capital One’s privacy policy and their expectations of privacy. The case now proceeds solely on Williams’s individual claims. New Jersey Federal Court Allows Data Privacy Class Action to Proceed Stevens v. TD Bank N.A., No. 1:24-cv-08311 (D.N.J.).. A New Jersey federal court largely denied TD Bank’s motion to dismiss a class action alleging the bank used embedded tracking technology to secretly share customers’ confidential financial data with Meta and Google. TD Bank moved to dismiss the amended complaint on two grounds: (1) that the plaintiff lacks Article III standing because he suffered no concrete injury in fact; and (2) that the plaintiff consented to the challenged disclosures through TD Bank’s terms of use, online privacy code, and privacy notices. The court ruled that the plaintiff plausibly alleged an injury in fact analogous to the injury caused by the tort of intrusion upon seclusion. The court distinguished the Third Circuit’s decision in Cook v. GameStop, which found no standing when only generic online shopping behavior was disclosed, and relied on the more recent In re BPS Direct LLC decision, which held that transmitting sensitive information entered in a secure context bears a close relationship to intrusion upon seclusion injury. The court further ruled that TD Bank’s consent defense—based on its terms of use and privacy notices—could not be adjudicated at the pleadings stage and converted that portion of TD Bank’s motion into one for summary judgment.

ISSUE 10 | 17 Court Dismisses Class Action over Discount-Code Browser Extension Campbell v. Honey Science LLC, No. 5:25-cv-02850 (N.D. Cal.). The Northern District of California dismissed the latest complaint in a class action brought by United Kingdom users of Honey, a browser extension owned by PayPal that applies coupons or discount codes before users purchase an item on a vendor’s website. The plaintiffs alleged that Honey promised to apply the best discount codes but sometimes failed to do so because of vendor agreements and, rather than searching the internet, relied on codes from affiliate networks, websites, or Honey subscribers. Based on these alleged practices, the plaintiffs brought claims for violation of California’s Unfair Competition Law (UCL), unjust enrichment, and common-law invasion of privacy. The court dismissed the UCL and unjust enrichment claims because the requested disgorgement of vendor commissions was not tied to the alleged overpayment theory and the class members received a benefit from their purchases. It also dismissed the invasion of privacy claim, finding that the complaint did not allege what data Honey tracked or why the alleged tracking was highly offensive, particularly given the extension’s commercial purpose. Trump-Affiliated Entities Refile Debanking Suit The Donald J. Trump Revocable Trust v. Capital One N.A., No. 1:25-cv-21596 (S.D. Fla.). The plaintiffs affiliated with President Donald Trump are pursuing claims against Capital One arising from the bank’s closure of approximately 385 accounts in 2021. They allege that Capital One terminated the banking relationships for political reasons following the events of January 6, 2021. After the court dismissed the first amended complaint, the plaintiffs filed a second amended complaint (SAC) that narrowed the case to contract-focused and related theories and abandoned the consumer protection claims. The SAC centers on Capital One’s rules governing deposit accounts. Although the agreement permits Capital One to close accounts “for any or no reason and without notice,” the plaintiffs contend that the bank exercised that discretion in bad faith and for an improper purpose. The SAC also relies on Florida Statute § 655.0323, which identifies discrimination based on political opinions, speech, or affiliations as an “unsafe and unsound practice” for financial institutions, as evidence of limits on Capital One’s contractual discretion. The SAC’s fraudulent concealment claim alleges that Capital One concealed the reasons for closing the accounts despite a duty to disclose them arising from the parties’ confidential banking relationship and Capital One’s exclusive possession of the relevant facts. The plaintiffs contend that the concealment caused harms beyond the account closures themselves. The parties have fully briefed Capital One’s motion to dismiss the SAC and await a decision on the merits. The case illustrates how customers may challenge broad contractual authority to terminate banking relationships as discriminatory or exercised in bad faith. Firearms Retailer Sues over Blocked Payment Platform Access ACEJ Holdings LLC v. Capital One N.A., No. 8:26-cv-02261 (D. Md.). According to its complaint, after ACEJ Holdings LLC, a federally licensed firearms retailer based in Maryland, integrated a Capital One–branded payment platform powered by Melio into its accountspayable workflow, the defendants blocked and ultimately disabled the plaintiff’s access to the platform, despite identifying no transaction-specific fraud, illegality, or misconduct. ACEJ brings consumer protection, defamation, contract, and business tort claims, along with requests for declaratory and injunctive relief, alleging more than $75,000 in damages for disrupted payment operations and alleged reputational harm. The defendants moved to dismiss, advancing different theories of non-liability. Capital One argues that Melio, not Capital One, restricted the plaintiff’s payment functionality and that Capital One merely provided the banking infrastructure the plaintiff used to access Melio’s services. Capital One further notes that the plaintiff’s business checking account was never suspended, restricted, or closed and remains active. Capital One contends that the plaintiff expressly agreed to terms and conditions that bar the claims asserted in the complaint. Melio argues that the plaintiff is not a consumer under the applicable consumer protection statute and that the remaining claims fail as a matter of law because the plaintiff cannot establish the required elements of any cause of action. Specifically, Melio contends that no actionable statement or special damages support the disparagement claim, the parties’ written terms foreclose any implied contract, no false statement or duty supports negligent misrepresentation, no wrongful conduct supports tortious interference, and the request for declaratory and injunctive relief cannot survive without a viable underlying claim. Bank Moves to Dismiss Class Action over Rewards Forfeited After Account Closures NTech Consulting LLC v. Capital One N.A., No. 3:26-cv-00308 (E.D. Va.). Former rewards cardholders brought a class action against Capital One, alleging that the bank improperly closed their accounts and prevented them from receiving or redeeming accumulated cashback rewards, bonuses, and miles. The plaintiffs, who held several types of Capital One rewards cards, contend that the bank’s account closure practices violated their cardholder agreements and state and federal consumer protection laws. Capital One moved to dismiss. The alleged losses varied among plaintiffs. One business cardholder and its owner claimed approximately $10,600 in forfeited cashback rewards and spending bonuses, while two individual cardholders allegedly lost $111.79 in cashback rewards and 86,560 miles, respectively. Capital One identified activity “inconsistent with typical customer account usage” as the basis for the closures. The bank’s motion noted that some claimed rewards related to purchases that posted after account closure and that certain spending bonuses required the account to remain open through its one-year anniversary, a threshold the relevant account did not reach. The bank’s primary defense rested on the governing cardholder agreements. Those agreements permitted Capital One to close or suspend an account “at any time and for any reason permitted by law,” even without cardholder default, and expressly warned that closing an account could result in the loss of unredeemed rewards. Annual spending bonuses were similarly conditioned on the account remaining open through its first anniversary. Because the challenged conduct was expressly addressed by these provisions, Capital One maintained that the plaintiffs could not recharacterize the account closures and rewards forfeitures as breaches of the implied covenant of good faith and fair dealing or as unjust enrichment. Capital One also challenged the state consumer protection claims, arguing that the disclosed forfeiture circumstances did not support viable claims. The bank contended that New York’s 90-day grace period provision for redeeming credit card rewards does not create a private right of action. Capital One argued that its adverse action notices satisfied the Equal Credit Opportunity Act by identifying atypical account activity as the reason for closure, even without further detail about the specific activity at issue.

RkJQdWJsaXNoZXIy MzI4MjIwNg==