Senators Elizabeth Warren (D-Mass.) and Ron Wyden (D-Ore.) have escalated pressure on the Financial Industry Regulatory Authority to close what they call a critical security gap in the Automated Customer Account Transfer Service (ACATS), the system that moves client assets between brokerages. In a letter to FINRA CEO Robert Cook, the senators argue that ACATS's speed—originally designed to prevent firms from delaying transfers to competitors—has become an exploitable vulnerability.
The letter, dated September 3, 2025, notes that ACATS requires no notification or authentication from the account holder before an outgoing firm processes a transfer. Once a request is submitted, the outgoing brokerage has just one business day to validate or object, then three business days to complete the transfer. Criminals, the senators say, use stolen personal information to open accounts in a victim's name at another brokerage and initiate an ACATS pull, often draining retirement savings before the account owner notices.
Inconsistent safeguards across firms
The senators' offices reviewed practices at major brokerages and found wide inconsistency. Fidelity and Vanguard offer customers a self-managed transfer-block feature, while J.P. Morgan, Robinhood, Webull, and Wells Fargo said similar locks exist but can only be toggled by customer service representatives. Following outreach, Webull and Robinhood have committed to user-managed locks by Q3 2026 and Q1 2027, respectively, and Interactive Brokers has committed to a self-service lock by Q3 2026. Citi, E*TRADE, Merrill Lynch, and Morgan Stanley Wealth Management do not offer comparable mechanisms, and Charles Schwab reportedly declined to provide written commitments.
The letter also flags a gap in transfer notifications. FINRA's Regulatory Notice 23-06, published in March 2023, identified customer alerts as an "effective practice" but stopped short of requiring them. Warren and Wyden argue that voluntary guidance allowed firms like Citi and Wells Fargo to avoid giving customers any warning, eliminating the three-day window for intervention.
Authentication and international precedent
On authentication, the senators want FINRA to require phishing-resistant multi-factor authentication, specifically passkeys. They note that Interactive Brokers, Merrill Lynch, Morgan Stanley Wealth Management, Robinhood, Vanguard, Webull, and Wells Fargo support the technology without mandating it. J.P. Morgan supports passkeys only for web access, not its mobile app, while Fidelity and E*TRADE are still rolling out the feature, with Fidelity targeting September 2026. Charles Schwab and Citi support only weaker methods.
To illustrate what's achievable, the senators point to Japan, where regulators required passkey-based authentication for securities accounts starting July 1, 2026. FINRA has been asked to respond by September 17.
Warren has previously pressed FINRA on enforcement. In 2024, she criticized the decline in enforcement actions and fines, calling it evidence of deregulatory drift. FINRA attributed the drop to membership expulsions and barred individuals.
The ACATS letter arrives as FINRA seeks other anti-fraud measures. Last week, the regulator asked the SEC to approve new Rule 2166, which would allow firms to delay suspicious transactions for up to 10 business days, and proposed extending the maximum hold period for exploited senior investors to 145 business days under amendments to Rule 2165. In that filing, FINRA cited FTC estimates that fraud cost older Americans $81.5 billion in 2024 and FBI data showing $7.7 billion in reported losses among Americans over 60 in 2025.
For advisors, the issue underscores the importance of client education and proactive account protections. As FINRA weighs mandatory rules, firms may need to adapt their systems. Related coverage includes FINRA's proposed fraud hold and rising fraud among cardholders.


