Wire fraud
Hegira Health Inc. v. Fifth Third Bank N.A.
Date: July 30, 2026
Issue: Under UCC Article 4A, did Fifth Third Bank use commercially reasonable security procedures and act in good faith by not preventing $2 million in fraudulent wire transfers from customers’ accounts?
Case Summary: A Michigan federal court dismissed a lawsuit accusing Fifth Third Bank of violating Uniform Commercial Code (UCC) Article 4A by failing to use commercially reasonable security procedures and act in good faith to prevent more than $2 million in fraudulent wire transfers from customers’ accounts.
In July 2025, Hegira Health Inc. sued Fifth Third Bank, alleging it failed to detect and stop a series of fraudulent wire transfers after an imposter gained access to its accounts. According to Hegira, in May 2025, an imposter posing as a Fifth Third Bank fraud prevention officer obtained Hegira’s login credentials and administrative access to its accounts. Afterward, someone changed Hegira’s wire-transfer settings from dual authorization to single-user approval. Fifth Third Bank then processed 14 wire transfers totaling about $2.09 million to beneficiaries who shared the same Miami address. Hegira claimed that Fifth Third Bank should have flagged the unusual activity, issued fraud alerts or holds, and stopped the transfers before the losses grew. Although Hegira recovered some funds, it alleged that Fifth Third Bank failed to reimburse the remaining losses.
Fifth Third Bank removed the case to the Eastern District of Michigan and moved to dismiss, arguing it acted in good faith and followed the parties’ agreed-upon, commercially reasonable security procedures. Judge Susan DeClercq agreed, ruling that UCC Article 4A governed Hegira’s claims and set the rules for assigning losses from unauthorized wire transfers. Under Article 4A § 202, a bank may treat an unauthorized payment order as effective if the bank and the customer agreed to a security procedure, that procedure was commercially reasonable, and the bank accepted the order in good faith and complied with the agreed security requirements. When those conditions are met, the customer bears the loss from the unauthorized transfer.
After deciding that UCC Article 4A governed Hegira’s claims, the court concluded that Hegira failed to state a claim even without considering the parties’ agreements. Reviewing only the complaint, the court ruled that Hegira did not identify any specific security procedure the parties agreed to use. Instead, Hegira argued that Fifth Third Bank’s fraud engine, risk scoring, alerts, holds, and other fraud-response measures should have detected or stopped the transfers. The court explained, however, that Article 4A recognizes a security procedure only when the bank and customer agree to use it. Because Hegira did not allege that the parties agreed to use those fraud-detection measures as security procedures, the court held that Fifth Third’s failure to use them could not support an Article 4A claim.
Bottom Line: The court refused to hold Fifth Third Bank liable for the wire fraud because Hegira could not identify any agreed-upon security procedure that the bank handled in a commercially unreasonable manner or failed to follow in good faith.
Document: Opinion










