Sentinel Vault
← All field notes
Fraud & Crime Trends · May 11, 2026

When the Fed Says Fraud Is a Systemic Risk, Your Bank Is About to Get a Lot Less Patient

When the Fed Says Fraud Is a Systemic Risk, Your Bank Is About to Get a Lot Less Patient

On May 5, Federal Reserve Vice Chair for Supervision Michelle W. Bowman gave a speech at the Women in Housing and Finance Symposium in Washington. Most coverage treated it as another fraud-awareness moment. It wasn't. Bowman put the Fed on record describing consumer fraud as a threat to the integrity and reliability of the financial system itself. That's not consumer-protection language. That's systemic-risk language, and it changes who owns the problem.

The numbers she presented are why.

In 2024, one in five American adults experienced financial fraud or a scam. Non-credit-card fraud losses across the U.S. financial system totaled $84 billion. Banks and investigators recovered only $21 billion of it. Consumers ate the rest: $63 billion gone. More than half of the non-credit-card fraud involved a bank account product, not a credit card. A single regional bank Bowman cited estimated its annual fraud costs at $40 million.

For a household, the median loss was $500 before any recovery. Bowman noted that 13 percent of Americans can't cover a $400 emergency expense, and 30 percent of online scam victims said losing the money damaged their financial condition. The retail-level damage isn't theoretical, and it's now showing up in the same Fed reports that track bank stability.

What "Systemic Risk" Actually Triggers

Words mean things at the Fed. When the Vice Chair for Supervision describes fraud as a threat to financial-system integrity, it does two practical things.

First, it gives examiners license to ask about fraud controls the way they ask about credit risk and liquidity. Bowman announced that she, Treasury Secretary Bessent, and FCC Chair Carr will convene a public-private roundtable on coordinated fraud response. That's a regulatory signal: the agencies expect institutions to act, and to document that they're acting.

Second, it changes how banks treat exposure that used to be tolerated. When the Fed labels something a systemic concern, large institutions stop absorbing the cost and start pushing it back to the source. The accounts that look most expensive to a fraud team are the ones most likely to feel pressure first.

Why Small Businesses Are the Pressure Point

Large enterprises have fraud teams, security budgets, and audit trails that satisfy a compliance reviewer on sight. Small businesses don't. A four-person HVAC company or a family-owned restaurant group processes real wire transfers, holds real payroll accounts, and connects to the same payment rails as everyone else. Often with no MFA on the business banking portal, no written vendor verification procedure, and email running through a domain that hasn't been reviewed since 2019.

From a bank's risk perspective, that SMB account is exposure. If a business email compromise scam drains the account through a fraudulent wire, the institution eats reputational damage and sometimes the loss itself. If that pattern repeats across enough small accounts, it starts to look like a portfolio-level problem.

The response from lenders and processors won't be subtle. Expect tightened onboarding documentation, enhanced transaction monitoring on accounts that can't demonstrate basic controls, and in some cases, relationship reviews that result in account closures. It's already happening in fragments. Bowman's speech says it's going to accelerate.

What "Baseline Anti-Fraud Hygiene" Actually Means

Compliance reviewers aren't expecting small businesses to run a SOC. They're looking for evidence that someone is paying attention. A few things move the needle:

  • Multi-factor authentication on banking and accounting portals. This is the first question. If the answer is no, every other conversation gets harder.
  • A written wire verification procedure. Even one paragraph: before any wire over $X leaves the account, call the recipient at a known number. Not a number from the email. A number from your records.
  • Email domain protections (SPF, DKIM, DMARC). These stop your domain from being spoofed in vendor impersonation attacks. Your IT person or MSP can check current status in about ten minutes.
  • A designated person who owns fraud response. Not a policy document. A name. Someone who knows what to do when a vendor calls saying their bank account changed.

None of these are expensive. All of them are documentable, which is the part that matters when a compliance officer is reviewing your account.

What Law Enforcement Is Watching

For investigators working financial crime in LA, the Inland Empire, and the broader SoCal corridor, the Fed's framing reinforces something that's been building on the case-file level for a while. Business email compromise and account takeover cases that used to look like isolated incidents are starting to cluster. Same mule networks, same spoofed domains, similar target profiles. The systemic-risk language from Bowman is the regulatory version of what LE has been documenting at street level.

It also signals that SARs and fraud referrals from financial institutions are going to increase in volume and specificity. Banks under pressure to show regulators they're monitoring for systemic fraud exposure aren't going to sit on unusual transaction patterns. That means more referrals, more leads, and more cases where the investigation starts with a business owner who had no idea they were a node in something larger.

What Small Businesses Should Do This Week

The window to get ahead of this is narrowing. Where to start:

  1. Log into your business banking portal and turn on MFA today. Every major bank supports it. If yours doesn't, call them and ask why.
  2. Write a one-page wire transfer policy. It doesn't need to be formal. It needs to exist and be followed. Verbal confirmation before any wire. No exceptions.
  3. Ask your IT person or MSP to run a DMARC check on your domain. If you're not protected, spoofing your domain costs an attacker nothing and takes about five minutes.
  4. Review who has access to your accounting software and banking logins. Former employees, old contractors, anyone whose access was never revoked. That's access that can still be used against you.
  5. Document what you've done. Not for anyone in particular right now. But if a bank compliance reviewer asks what controls you have in place, having a one-page summary is the difference between a five-minute conversation and a relationship review.

Bowman's speech is the regulatory community saying out loud that fraud at the small-business level is no longer just your problem. That means your bank's tolerance for accounts that look unprotected is shrinking. The businesses that get ahead of this are the ones that treat basic fraud hygiene the same way they treat keeping their business license current. Not optional. Not complicated. Just done.

About the author
Pete Hish, Sentinel Vault founder
Taught by Pete Hish · Founder

A working cyber-fraud supervisor, not a vendor consultant.

US Army veteran. Active sergeant supervising a cyber and fraud investigations team at a large Southern California law-enforcement agency. Ten-plus years inside the cases that hit small businesses, families, and public-sector agencies first. The training is shaped by what actually goes wrong, not what vendor decks predict.

Certified Cybersecurity SpecialistCertified Cyber Fraud SpecialistCalifornia POST Certified Instructor
Hacked or Hardened? book cover
Prefer the long-form version?

Hacked or Hardened? covers these patterns end-to-end — the four ways small businesses get hit, what to fix first, and how to lead through an incident.

Related field notes
Next step

Want this kind of analysis for your team?

A 2–4 hour cyber risk briefing: the threats specific to your business, the controls that actually pull their weight, and a 90-day action plan.