IN THE UNITED STATES DISTRICT COURT FOR THE EASTERN DISTRICT OF PENNSYLVANIA
FRONTLINE FABRICS, INC., et al., CIVIL ACTION
Plaintiff, No. 25-7342-KSM v.
GÜLIPEK KUMAS VE IPLIK VE, et al.,
Defendants.
MEMORANDUM MARSTON, J. August 11, 2026 Plaintiff Frontline Fabrics, Inc. lost $1.4 million when hackers infiltrated one of its foreign vendors, opened a United States bank account in the vendor’s name, and posing as an employee of the vendor, directed Frontline to route payments to the fraudulent account. (Doc. No. 1.) Frontline brings this suit against the foreign vendor, Gülipek Kumas Ve İplik Ve (“Gülipek Tech”); the financial institutions that were used to transfer the money, TD Bank, N.A., and Truist Bank; Frontline’s insurance company, Federal Insurance Company; and the “John Doe” hackers. (Doc. No. 1 at 3–4.) TD Bank has moved to dismiss the claims asserted against it. (Doc. No. 18.) For the reasons discussed below, that motion is granted. I. BACKGROUND Plaintiff Frontline Fabrics, Inc. is a Pennsylvania corporation that manufactures flame- resistant products. (Doc. No. 1 at ¶ 7.) It purchases the flame-retardant yarn used in its products from Defendant Gülipek Tech, which operates a spinning mill in Türkiye. (Id.) On February 21, 2025, Gülipek Tech contacted Frontline because Frontline had failed to pay approximately $291,000 in invoices. (Id. at ¶ 8.) Frontline and Gülipek Tech had an established vendor- purchaser relationship, and Frontline had historically sent its payments to Gülipek Tech’s Turkish bank account. (Id. at ¶ 18.) When Frontline investigated whether it had missed any payments to Gülipek Tech, it found that former Frontline controller Tiffany Lawler had sent multiple payments to an account
recently opened in Gülipek Tech’s name at TD Bank, instead of to the company’s long-used Turkish bank account. (Id. at ¶ 16.) Lawler’s email records showed that she had been instructed to update Gülipek Tech’s banking information by Lonnie Braxton, Frontline’s local contact at Gülipek Tech. (Id. at ¶ 18.) The instructions to modify the payment procedures were sent from Braxton’s official Gülipek Tech email address and were consistent with previous communications between Frontline and Gülipek Tech about the latter company’s intentions to open an American bank account. (Id.) Frontline shared its findings with Gülipek Tech, which acknowledged that it did intend to open an American bank account, but had yet to do so. (Id. at ¶ 19.) Gülipek Tech also noted that it had not received any of the payments issued by Lawler and had not detected any internal
security issues that would explain the inconsistency. (Id.) The next day, however, Frontline management spoke with Braxton, who admitted that his company email address had been breached by a third party. (Id. at ¶ 21.) Braxton also confirmed that the emails Lawler received were sent from his official company email account, but he denied receiving any of Lawler’s recent messages with questions about invoices and payment confirmations. (Id.) Based on these findings, Frontline concluded that Gülipek Tech’s computer systems had been accessed by hackers, who monitored Braxton’s correspondence long enough to note Gülipek Tech’s plans to open a bank account in the United States. (Id. at ¶ 23.) Using this intel and Braxton’s company email address, the hackers then deceived Frontline into sending payments to a TD Bank account opened by the hackers in Gülipek Tech’s name. (Id.) Between January 13, 2025, and February 12, 2025, Frontline released six ACH payments, totaling $1,426,476.86, to that account: $184,372.13 (January 13), $196,322.13 (January 15),
$195,002.70 (January 22), $350,780.00 (January 29), $295,484.90 (February 7), and $204,515.00 (February 12). (Id. at ¶ 25.) The funds were transferred out of the hacker’s TD Bank account to an account in Haiti via Zelle. (Id. at ¶ 39.) At least one of the transfers was flagged as suspicious, but it is unclear when it was flagged, by whom, and whether TD Bank knew about the flag. (See Doc. No. 34-2 at ¶ 38; see also July 8, 2026 Hr’g. Tr. at 65:14 (“We don’t know who flagged it.”); id. at 68:4–5 (same).)1 Regardless, the authorized funds were released by TD Bank to the Haitian account. (Doc. No. 1 at ¶ 40.) The funds were then converted to cryptocurrency, at which point they became virtually impossible to trace. (Id. at ¶ 39; see also id. at ¶ 42 (alleging that the FBI was able to locate only around $100,000 of the stolen funds).)
1 Frontline’s initial Complaint also sued Early Warning Services, LLC (“EWS”), the company that operates Zelle, alleging that the “funds sent by Lawler were transferred out of the TD Bank account to hackers in Haiti using the Zelle network operated by EWS” and “[a]lthough Zelle ‘flagged’ the transfer(s) as suspicious, TD Bank and/or EWS ultimately allowed the transfer to go through.” (Doc. No. 1 at ¶¶ 12, 39.) But Frontline voluntarily dismissed EWS not long after the Complaint was filed (Doc. No. 14), because “after some investigation [Frontline] . . . didn’t feel comfortable continuing to allege that” Zelle was “the organization that flagged the activity” as suspicious (July 8, 2026 Hr’g. Tr. at 65:4–7). On July 15, 2026, Frontline moved to amend its Complaint to remove any reference to EWS and to soften its allegations about the flagged transaction. If amendment is granted, the amended complaint would allege, “The funds sent by Lawler were transferred out of the TD Bank account in several transactions, ultimately to Hackers in Haiti. At least one such transaction was ‘flagged’ as suspicious, yet TD Bank ultimately allowed the transfer to go through.” (Doc. No. 34-2 at ¶ 38.) As with the original Complaint, there are no factual allegations to explain who flagged the transaction as suspicious, when it was flagged, or whether TD Bank knew about the flag. (See generally Doc. No. 34-2.) Given Frontline’s representations at oral argument and in the pending motion to amend, the Court does not consider Frontline’s initial allegation that EWS flagged the Zelle transfer as suspicious in this Memorandum. On December 26, 2025, Frontline filed this action against Gülipek Tech, TD Bank, Truist Bank (Frontline’s bank), Federal Insurance Company (Frontline’s insurance company), and the “John Doe” hackers. (Doc. No. 1.) It brings claims for negligence, breach of contract, violations of the Uniform Commercial Code (“UCC”), conversion, and identity theft. (Id. at 11–17.) TD
Bank has moved to dismiss the negligence and UCC claims asserted against it. (Doc. No. 18.) Frontline opposes the motion. (Doc. No. 20.)2 The Court held oral argument on July 8, 2025, and the motion is now ripe for resolution. II. LEGAL STANDARD “To survive a motion to dismiss, a complaint must contain sufficient factual matter, accepted as true, to state a claim to relief that is plausible on its face.” Ashcroft v. Iqbal, 556 U.S. 662, 678 (2009) (quotation marks omitted). “A claim has facial plausibility when the plaintiff pleads factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged.” Id. Although a plaintiff does not need to include “detailed factual allegations” to survive a Rule 12(b)(6) motion to dismiss, the plaintiff must “provide the grounds of his entitlement to relief” which “requires more than labels and
conclusions, and a formulaic recitation of the elements of a cause of action.” Bell Atl. Corp. v. Twombly, 550 U.S. 544, 555 (2007) (quotation marks omitted).
2 TD Bank asks the Court to strike Frontline’s response brief because it was filed more than two weeks after the deadline. (See Doc. No. 21 at 5–6; see also July 8, 2026 Hr’g. Tr. at 41:18–24.) Frontline did not seek an extension of the deadline before filing its brief, and although TD Bank identified the late filing in its reply brief, Frontline did not seek an extension nunc pro tunc. Indeed, it did not acknowledge the mistake at all until oral argument when the Court questioned counsel about the late filing, and he explained that the filing was dilatory because of a calendaring error. (July 8, 2026 Hr’g. Tr. at 53:15–21.) When pressed about his failure to seek an extension once the error was pointed out to him, counsel responded that he did not file a motion because although he “could have certainly done that,” he “chose not to do that.” (Id. at 53:25–54:1.) This response is insufficient. Counsel is warned that the Court expects all future filings by Frontline to be made in a timely manner. Continued failure to meet deadlines or seek appropriate extensions may result in documents being stricken from the record. In ruling on a motion to dismiss, the court must accept as true the factual allegations in the complaint and all reasonable inferences that can be drawn from those allegations. Phillips v. County of Allegheny, 515 F.3d 224, 228 (3d Cir. 2008). “As a general matter,” the court “may not consider matters extraneous to the pleadings.” In re Burlington Coat Factory Secs. Litig.,
114 F.3d 1410, 1426 (3d Cir. 1997). “However an exception to the general rule is that a document integral to or explicitly relied upon in the complaint may be considered without converting the motion to dismiss into one for summary judgment.” Id. (quotation marks omitted and alterations accepted). III. DISCUSSION Frontline asserts two counts against TD Bank: negligence (Count I) and declaratory judgment for violation of Article 4A of the UCC (Count III). (Doc. No. 1 at ¶¶ 45–55, 63–66.) TD Bank moves to dismiss both counts. (See generally Doc. No. 18-1.) The Court addresses its arguments as to each count in turn. A. Count I: Negligence To state a claim for negligence in Pennsylvania, a plaintiff must allege “that the
defendant had a duty to conform to a certain standard of conduct; that the defendant breached that duty; that such breach caused the injury in question; and actual loss or damage.” Chemalloy Co., LLC v. Citibank, N.A., 606 F. Supp. 3d 370, 376 (E.D. Pa. 2022) (citing Wisniski v. Brown & Brown Ins. Co., 906 A.2d 571, 575 (Pa. Super. Ct. 2006)). Here, the issue is whether TD Bank owed Frontline a duty of care. And “[t]he question of whether a duty exists is a question of law for the court to decide.” Shooter Pops LLC v. Wells Fargo Bank, N.A., 649 F. Supp. 3d 62, 68 (E.D. Pa. 2023) (quotation marks omitted). TD Bank argues that Frontline’s negligence claim fails as a matter of law because banks do not owe a duty of care to noncustomers, and no duty should be imposed on TD Bank here. (Doc. No. 18-1 at 9–18.) Frontline responds that TD Bank was subject to the common law duty to use reasonable care when taking affirmative action, and that if this preexisting duty does not govern the case, the Court should recognize a new duty in the context presented here. (Doc. No. 20 at 4–11.) The Court addresses each of TD Bank’s arguments in turn.
1. Preexisting Duty TD Bank is correct that banks generally do not owe a duty of care to noncustomers. See, e.g., Chemalloy Co., LLC, 609 F. Supp. 3d at 377 (“There is a substantial lack of precedent acknowledging a bank’s obligation or duty to noncustomers. Quite the opposite, precedent supports the principle that banks do not owe any duty of care to noncustomers and/or third parties.”); Fragale v. Wells Fargo Bank, N.A., 780 F. Supp. 3d 653, 661 (E.D. Pa. 2020) (“[D]ecisions across the country, including within Pennsylvania, have held that banks do not owe any duty of care to noncustomers and/or third parties.”); see also Adkins v. Sogliuzzo, 625 F. App’x 565, 569 (3d. Cir. 2015) (finding as a matter of New Jersey law that “[a]bsent a special relationship, courts will typically bar claims of non-customers against banks.” (quotation marks omitted)). This rule ensures that banks, which are the conduits for virtually every financial
exchange, are not subjected to limitless liability. Despite this case law, there is some basis for finding, as a matter of Pennsylvania law, that a duty of care can arise even in the absence of a special relationship, contract, or statutory obligation. See Dittman v. UPMC, 196 A.3d 1036, 1044 (2018). In Dittman, a group of employees filed a putative class action against their employers, the University of Pittsburgh Medical Center (“UPMC”) and UPMC McKeesport (collectively, “UPMC”). Id. at 500. The employees alleged that UPMC’s computer system had been breached, allowing hackers to access and steal the “personal and financial information, including names, birth dates, social security numbers, addresses, tax forms, and bank account information of all 62,000 UPMC employees and former employees.” Id. at 500. They brought negligence claims against UPMC, arguing that it owed them a duty to exercise reasonable care when it took the affirmative steps of “collecting Employees’ sensitive personal data and storing it on [UPMC] internet-accessible computer systems.” Id. at 509. This duty, according to the employees, included implementing
“measures to protect them from the foreseeable risk that third parties would attempt to access and pilfer that information.” Id. UPMC moved for dismissal of the complaint, arguing that the employees were proposing “a radical reconstruction of duty,” which would impose liability on UPMC for its nonfeasance. Id. at 511–12. The Pennsylvania Supreme Court disagreed with UPMC. Id. at 513–15. The court began by noting that “in scenarios involving an actor’s affirmative conduct, [the actor] is generally under a duty to others to exercise the care of a reasonable man to protect them against an unreasonable risk of harm to them arising out of the act.” Id. at 513 (quoting Seebold v. Prison Health Servs., Inc., 57 A.3d 1232, 1246 (Pa. 2012)). The court noted that this duty was recognized at common law and “appropriately undergirds the vast expanse of tort claims in
which a defendant’s affirmative, risk-causing conduct is in issue.” Id. (quoting Seebold, 57 A.3d at 1246); see also Restatement (Second) of Torts § 302, cmt. a (1965) (“Anyone who does an affirmative act is under a duty to others to exercise the care of a reasonable man to protect them against an unreasonable risk of harm to them arising out of the act.”). In the case before the court, UPMC’s affirmative conduct included requiring employees to provide “sensitive personal data” and storing that data on its systems. Dittman, 196 A.3d at 515; see also id. at 513–14 (“[A]s a condition of employment, UPMC required [its employees] to provide certain personal and financial information, which UPMC collected and stored on its internet-accessible computer system without use of adequate security measures, including proper encryption, adequate firewalls, and an adequate authentication protocol. These factual assertions plainly constitute affirmative conduct on the part of UPMC.”). And because it was foreseeable that a “cybercriminal might take advantage of the vulnerabilities in UPMC’s computer system and steal Employees’ information,” UPMC had a duty to implement “adequate security measures to
protect against data breaches.” Id. Since Dittman, district courts in this Circuit have disagreed about the extent to which that case can be read as imposing on banks a duty of care to noncustomers. Compare Fragale, 480 F. Supp. 3d at 669 (predicting the Pennsylvania Supreme Court would not “impose a duty on a bank to a noncustomer” for the opening of an account and subsequent transfer of funds), with Elkin Valley Baptist Church v. PNC Bank, N.A., 748 F. Supp. 3d 293, 352 (W.D. Pa. 2024) (concluding that the “Supreme Court of Pennsylvania would most likely hold that a bank owes a duty to users of the banking system, including noncustomers, to refrain from opening or administering accounts in an unreasonable manner which serves to create or increase the risk that such users of the banking system will be injured by cybercrime or other fraud”). Cf. Gemstone
Foods, LLC v. JPMorgan Chase Bank, Nat’l Assoc., No. 26cv60049, 2026 WL 1507876, at *3 (5th Cir. May 29, 2026) (recognizing the lack of “consensus authority” in the Third Circuit on this issue). Unsurprisingly, TD Bank urges the Court to follow Fragale, and Frontline urges us to follow Elkin Valley. Thus, further discussion of these two cases is necessary. Beginning with Fragale, the plaintiff in that case alleged that he received a fraudulent email while trying to close on a retirement property. 480 F. Supp. 3d at 657. The email was from an entity claiming to be a title company, and it provided instructions to wire settlement funds in the amount of $166,054.96 to an account at Wells Fargo. Id. The plaintiff completed the wire and Wells Fargo credited the funds, which were immediately withdrawn from the account. Id. at 657. When the plaintiff learned that he had sent the funds to a fraudulent account, he sued Wells Fargo, bringing a claim for negligence premised on “Wells Fargo’s (1) failure to properly verify the identity of the individual opening the [a]ccount under a purportedly false name and (2) failure to undertake reasonable, preventative steps before
permitting the withdrawal of a large amount of funds when such funds had just been wired into the [a]ccount, which itself was recently opened.” Id. at 658. The Fragale court considered whether the plaintiff had “pled facts sufficient to show that Wells Fargo owed [him] a duty of care” under Dittman. Id. at 661–64. The court found it significant that unlike the parties in Dittman, there was no employer-employee relationship (or any other type of relationship) between the plaintiff and Wells Fargo. Id. at 662. In addition, the court found that the plaintiff had failed to “allege that Wells Fargo engaged in any conduct similar to that of the Dittman employer; there are no allegations in the complaint that Wells Fargo required Plaintiff to submit any personal information, stored any of Plaintiff’s information, or took any affirmative action toward Plaintiff that could be conceived as creating a special
relationship with and an increased risk of harm to Plaintiff.” Id. (cleaned up). Accordingly, the court concluded that the plaintiff had failed to allege Wells Fargo owed him a duty of care, a conclusion that the court noted was “consistent with the prevailing general rule that banks do not owe a duty of care to noncustomers.” Id. at 664.3
3 In addition to discussing Dittman, the Fragale court also distinguished a second Pennsylvania Supreme Court opinion, Anderson v. Bushong Pontiac Co., 171 A.2d 771 (1961). See Fragale, 480 F. Supp. 3d at 662–64. Unlike Dittman, which adopts the definition of negligence in the Second Restatement of Torts, Anderson focuses on the First Restatement of Torts. See Anderson, 171 A.2d at 773. Section 302(b) of that Restatement provides, “A negligent act may be one which creates a situation which involves an unreasonable risk to another because of the expectable action of the other, a third person, an animal or a force of nature.” Id. The Anderson court explained that reasonable foreseeability is key to determining whether a duty exists under this section. Id. There, the plaintiff was injured when a teenager stole a car from the defendant’s car lot and drove it onto a public sidewalk. Id. at 772. The Pennsylvania Supreme Court noted that the defendant knew the keys to the car had been stolen and that In Frontline’s primary case, Elkin Valley, the court distinguished Fragale, finding that the Fragale court’s emphasis on the employer-employee relationship was a misreading of Dittman. See 748 F. Supp. 3d at 351 (“This Court must respectfully adhere to an alternate reading of Dittman. Although the defendant hospital system in Dittman was indeed the employer of the
plaintiff class, the opinion’s imposition of a duty was not predicated on that relationship, but on the hospital’s affirmative, risk-creating conduct.”). The Elkin Valley court reasoned that the appropriate inquiry was not the nature of the parties’ relationship, but instead, whether the defendant engaged in “affirmative, risk-creating conduct” such that it was obligated to act with reasonable care. Id. With that distinction in mind, the court turned to the facts before it. There, the plaintiff alleged that an unknown cybercriminal tricked the plaintiff into wiring $793,876.10 into a fraudulent PNC Bank account opened by an unidentified individual. Id. at 304. The plaintiff claimed that PNC allowed the cybercriminal to open and maintain an account at the bank, even though PNC’s internal systems should have warned it that the account was potentially fraudulent. Id. at 304–05; see also id. at 303 (finding the name on the account
was unknown but noting that either way the account should have been flagged as suspicious because (1) if the account was opened in the name of the plaintiff’s contractor, the bank should have caught “discrepancies (such as registered address or Internal Revenue Service (IRS) tax identification number)” and (2) if the account was opened in another name, the bank should have
they were likely taken by a teenager, yet he did not move the car or take any other precaution to prevent its operation. Id. Based on these facts, the court concluded that it was “reasonably foreseeable that a teenager might steal the car and that the plaintiff, a pedestrian, was within the class of persons endangered by the defendant’s negligence.” Id. at 775. Fragale considered Anderson and found it did not provide a basis for imposing a duty on Wells Fargo because the plaintiff had failed to “show that Wells Fargo was on notice of the likelihood that the [a]ccount was part of a fraudulent scheme to which a noncustomer like [p]laintiff would fall victim.” Fragale, 480 F. Supp. 3d at 664. Neither party has discussed Anderson or Fragale’s discussion of that case, so this Court need not consider it further here. caught that the fictitious business entity was not a “legal entity of record in any jurisdiction and/or the individual opening the account lacked authority [and] corporate records/documentation and/or personal identification”). The plaintiff also alleged that once the account was open, PNC should have closed it, stopped the plaintiff’s transferred funds from
being withdrawn, and/or alerted law enforcement after they were withdrawn, because PNC’s own “automated monitoring of the [a]ccount identified suspicious activity before and after the fraud on Plaintiff was perfected.” Id. at 303–04 (quotation marks omitted). The court agreed with the plaintiff, finding that it “plausibly alleged circumstances suggesting that irregularities in the particular account at issue marked it as suspicious, and therefore risky, from the start.” Id. at 351. And on that basis, the court held that the “plaintiff has plausibly alleged that PNC, in breach of its common law duties: (a) failed to exercise reasonable care in its account opening and administration and (b) permitted withdrawal of the diverted funds transfer in the face of actual or constructive knowledge of beneficiary misidentification.” Id. at 354.4 Here, Frontline has alleged some facts that suggest TD Bank, like the bank in Elkin
Valley, knew or should have known that the account was suspicious when opened and that each transfer was potentially fraudulent. (See, e.g., Doc. No. 1 at ¶ 38 (“TD Bank allowed the Hackers and/or others working at the behest of the Hackers to open a bank account in Gülipek Tech’s name, despite the lack of legitimate, appropriate, and/or credible credentials.”); id. at ¶ 47
4 The parties present Fragale and Elkin Valley as reaching diametrically opposed conclusions, but their interpretations of Dittman are largely consistent. Tellingly, Fragale, like Elkin Valley, reads Dittman as finding a duty arises when a defendant takes “affirmative action toward Plaintiff.” Fragale, 480 F. Supp. 3d at 662; see also Elkin Valley, 748 F. Supp. 3d at 351 (explaining that Dittman’s holding was predicated “on the hospital’s affirmative, risk-creating conduct”). The two courts diverge when it comes to applying that rule to the facts before them. In Fragale, the court finds that merely opening an account and allowing withdrawals, without more, is not the type of “affirmative action” that can give rise to a duty. In Elkin Valley, by contrast, the court finds that such actions are “affirmative, risk-creating conduct,” because there, the bank opened and maintained the account in the face of circumstances that the bank knew or should have known suggested the account was suspicious and potentially fraudulent. (alleging that TD Bank failed to follow “state and federal laws and regulations applicable to account opening . . . including “Know Your Customer (‘KYC’) and Anti-Money Laundering (‘AML’) regulations”)); see also Elkin Valley, 748 F. Supp. 3d at 303–04, 351–54. Nevertheless, this Court does not agree with Elkin Valley that these facts transform the opening and
maintenance of a bank account into the type of “affirmative, risk-creating conduct” that results in banks owing a duty of care to noncustomers who become the victims of fraud. Unlike Dittman, where the employer required its employees to provide the personal information and stored that information on its systems, TD Bank’s actions cannot be said to have directly led to Frontline’s injury. TD Bank did not, for example, direct Frontline to wire the payments to the fraudulent account. See Seebold, 57 A.3d at 1246 (explaining that there is generally no duty to “protect or rescue someone who is at risk on account of circumstances the defendant had no role in creating”). Moreover, this Court has found no case other than Elkin Valley that reads Dittman in such a way that its discussion of duty encompasses the type of conduct at issue here. See, e.g., Fragale, 480 F. Supp. 3d at 660–64; Chemalloy Co., 609 F. Supp. 3d at 374 (rejecting the
plaintiff’s argument that bank owed a noncustomer a duty of care once it “was informed of the potential fraud and allegedly agreed to prevent the funds from withdrawal after funds had been transferred and received by the bank account owner”); Zhejiang Matrix SCM Co. v. PNC Bank Nat’l Ass’n, No. 23cv0979, 2024 WL 1096534, at *4 (E.D. Pa. Mar. 13, 2024) (citing Fragale and finding no duty).5
5 When Plaintiff’s counsel was asked by the Court whether he could identify any case “holding that knowledge of suspicious activity and release of funds by a bank” is “affirmative risk-causing conduct,” he responded, that he was “not sure that we have a case exactly on point there.” (July 8, 2026 Hr’g. Tr. at 56:6–11.) In sum, the Court finds that TD Bank did not owe Frontline a duty of care in these circumstances under the principles outlined in Dittman. 2. New Duty In the alternative, Frontline argues that the Court should recognize a new duty in this context pursuant to the principles outlined in Althaus ex rel. Althaus v. Cohen. In Althaus, the
Pennsylvania Supreme Court identified five factors that courts should consider before identifying a previously unrecognized duty: (1) the relationship between the parties; (2) the social utility of the actor’s conduct; (3) the nature of the risk imposed and foreseeability of the harm incurred; (4) the consequences of imposing a duty upon the actor; and (5) the overall public interest in the proposed solution.” 756 A.2d 1166, 1169 (Pa. 2000). “While no individual factor is dispositive, ‘a duty will be found to exist where the balance of these factors weighs in favor of placing such a burden on a defendant.’” Citizens Bank of Pa. v. Reimbursement Techs., Inc., 609 F. App’x 88, 92 (3d Cir. 2015) (quoting Phillips v. Cricket Lighters, 841 A.2d 1000, 1008–09 (Pa. 2003)); cf. Feleccia v. Lackawanna Coll., 215 A.3d 3, 13 (Pa. 2019) (“Courts should not enter into the creation of new common law duties lightly . . . . The Court has previously adopted the default
position that, unless the justifications for and consequences of judicial policymaking are reasonably clear with the balance of factors favorably predominating, we will not impose new affirmative duties.” (quotation marks omitted)). Unsurprisingly, Fragale and Elkin Valley also disagree about the application of these factors in cases involving banks and noncustomers. Compare Fragale, 609 F. Supp. at 664–69 (“Here, this Court has found that only the second factor weighs in favor of imposing the duties sought by Plaintiff, while the remaining four factors weigh heavily in favor of not establishing such duties. As such, it cannot be said that the balance of factors favorably predominate in favor of imposing the requested duties.” (quotation marks omitted)), with Elkin Valley,748 F. Supp. 3d at 351 n.129 (noting that Fragale and Chemalloy “concluded that on balance the factors weigh against recognizing a duty,” and stating that “[t]his Court would be inclined to weigh several of the factors differently (or would predict that the Pennsylvania Supreme Court would weigh such factors differently)”). Once again, the Court agrees with Fragale.
Factor 1: The first factor considers the “relationship between the parties.” Althaus, 756 A.2d at 553. “Typically, whether the defendant owes a duty to the plaintiff arises from the relationship between those parties . . . .” Walters v. UPMC Presbyterian Shadyside, 187 A.3d 214, 232 (Pa. 2018); see also Fragale, 480 F. Supp. 3d at 665 (“Duty is predicated on the relationship that exists between the parties at the relevant time.” (quoting R.W. v. Manzek, 888 A.2d 740, 746 (Pa. 2005))). Here, TD Bank has no relationship with Frontline,6 and thus, the first factor weighs significantly against imposition of a duty. See Fragale, 480 F. Supp. 3d at 665; Chemalloy Co., 609 F. Supp. 3d at 378; Commerce Bank/Pa. v. First Nat’l Bank, 911 A.2d 133, 139 (Pa. 2006) (“Because the parties were essentially strangers to each other at the relevant time, this factor does not support a finding of duty.”); see also Citizens Bank of Pa. v.
Reimbursement Techs., Inc., 609 F. App’x 88, 92 (3d Cir. 2015) (finding the lack of a relationship is a “significant factor that weighs against the existence of a duty”).
6 Instead, TD Bank has a relationship with the hackers. The Pennsylvania Supreme Court has found that even when there is no “direct relationship” between the parties, this factor may weigh in favor of imposing a duty where “the defendant stands in some special relationship with the person whose conduct needs to be controlled.” Walters, 187 A.3d at 232 (quoting Restatement (Second) of Torts § 315); see also id. (explaining that a “special relationship may include a master’s duty to control a servant”); Emerich v. Phila. Ctr. for Human Dvlpt, Inc., 720 A.2d 1032, 1040 (Pa. 1998) (finding “that the special relationship between a mental health professional and his patient may, in certain circumstances, give rise to an affirmative duty to warn for the benefit of an intended victim”). Frontline has not argued that such a special relationship existed here. And such an argument likely would be unavailing as a bank does not exert the same type of control over its customers’ actions as an employer does over its employees or a mental health professional does over their patient. Factor 2: For the second factor, the Court considers “the social utility of the actor’s conduct.” Althaus, 756 A.2d at 553. “In the context of this factor, courts generally examine whether imposing a duty would confer a benefit upon society.” Fragale, 480 F. Supp. 3d at 665. And in similar contexts, courts have recognized that “there is obvious social utility in banks
taking action to prevent fraudulent banking activity.” Id.; Commerce Bank/Pa., 911 A.2d at 139 (“There is high social utility in a bank taking action against a client’s account when it suspects fraud or check-kiting. Such action could discourage the client from continuing this conduct, and thereby help to protect third parties and minimize losses. This factor supports a finding of a duty.”); cf. Chemalloy Co., 609 F. Supp. 3d at 378 (acknowledging that “[t]here is social utility in requiring banks to take action to address fraud by [their] own customers,” but ultimately finding this factor neutral because imposing such a duty “would open banks to liability both from the customer, who may or may not have obtained the funds fraudulently and is entitled to those funds absent a court order, and also a noncustomer who requested a freeze and fraud review”). TD Bank does not dispute that this factor “likely cuts in favor of finding a duty” (Doc. No. 18 at
9), and the Court finds as much here. Factor 3: The third factor considers “the nature of the risk imposed and foreseeability of the harm incurred.” Althaus, 756 A.2d at 553. Beginning with the nature of the risk, courts generally distinguish “economic loss” from “non-monetary risks such as loss of human life or physical harm.” Chemalloy Co., 609 F. Supp. 3d at 378 (quotation marks omitted); accord Fragale, 480 F. Supp. 3d at 666. Because the risk at issue here is purely financial, the “nature of the risk” would seem to weigh against imposition of a duty. Cf. Walters, 187 A.3d at 236 (“It would be difficult to overstate the risk to public health that this case presents, and we need not do so; the sheer number of exposed patients and the potentially severe consequences of infection with hepatitis C speak for themselves.”). Moreover, as the court noted in Fragale, the type of financial risk at issue here—the risk that criminals will open fraudulent bank accounts and use them to funnel stolen funds—is “speculative” without data on the extent to which bank accounts are opened for fraudulent purposes as compared to proper purposes. See Fragale, 480 F. Supp.
3d at 666 (“Plaintiff does not provide sufficient factual context to assess the degree of financial risk when measured against the number of similar financial transactions that are not part of fraudulent schemes. In the absence of this information, any assessment by this Court of the nature of the risk would be speculative.”). As for foreseeability, “in the context of duty, ‘the concept of foreseeability means the likelihood of the occurrence of a general type of risk rather than the likelihood of the occurrence of the precise chain of events leading to the injury.’” Citizens Bank of Pa., 609 F. App’x at 92 (quoting Kleinknecht v. Gettysburg Coll., 989 F.2d 1360, 1369 (3d Cir. 1993)); see also Commerce Bank/Pa., 911 A.2d at 139 (“As noted above, in general, taking action against a client’s account may prevent some types of harm to third parties. On the other hand, the nature
of the risk and the foreseeability of harm in this specific case are vague and attenuated. While it may be easy in hindsight to trace Appellant’s losses back to some act or omission by First Union, this is not the test. The test is whether the harm to Appellant was foreseeable in the first instance.”). Courts are leery of reading the concept of foreseeability too broadly, recognizing a general “reluctan[ce] to impose a duty to protect a member of the general public from the harmful acts of third parties, in the absence of special circumstances.” Commerce Bank/Pa., 911 A.2d at 139; accord Fragale, 480 F. Supp. 3d at 666. Although Frontline alleges that at some point the withdrawals from the fraudulent account were flagged as suspicious, it has not alleged that TD Bank knew about that flag. Cf. Chemalloy Co., 609 F. Supp. 3d at 378–79 (finding “third factor weighs slightly in favor of a duty” where the bank was “notified of potential fraud” by the plaintiff and “it was foreseeable at that point that fraudulently obtained funds would be withdrawn from the bank account”). And even if it had, that flag did not render the harm foreseeable when TD Bank opened the account.
As for the withdrawals, the Court can do little more than speculate as to the injury’s foreseeability without additional allegations about when each withdrawal was flagged, why it was flagged, and how often such flags generally occur. On balance, we find that the third factor also weighs against imposing a duty. Factor 4: Fourth, the Court must consider “the consequences of imposing a duty upon the actor.” Althaus, 756 A.2d at 553. Frontline argues that the “consequences of imposing [a] limited duty” on banks when opening accounts and responding to suspicious activity is not “unmanageable.” (Doc. No. 20 at 11.) TD Bank disagrees, arguing that “imposing upon banks a duty of care to noncustomers would be significant, as it could ‘impose broad liability on banks to noncustomers and create the perverse incentive for banks to’” avoid flagging actions as
suspicious in the first place. (Doc. No. 18-1 at 16.) The truth appears to lie somewhere in the middle. Frontline’s suggested duty is not the unfettered liability that TD Bank suggests. As to opening accounts in particular, Frontline is merely suggesting that banks take the most minimal steps to verify the opening party’s identity and confirm the account isn’t fraudulent on its face. See Fragale, 480 F. Supp. 3d at 667 (finding “minimal” burden on banks “to verify the identity of persons opening and withdrawing money from an account”). Similarly, Frontline is not advocating that banks have a duty to investigate every withdrawal, but instead, that they respond to flags of suspicious activity when known. Cf. id. (finding “significant” burden on banks to “pause and consider before permitting such withdrawal of future untraceable funds, merely because a withdrawal is large and was preceded by a funds transfer to a new account”). Despite these limitations, the Court cannot ignore that Frontline essentially asks us to make banks “the guarantors of their clients’ trustworthiness”—something courts have been disinclined to do. See, e.g., Commerce Bank/Pa., 911 A.2d at 139–40 (“We decline to make banks the guarantors of
their clients’ trustworthiness. Moreover, imposing liability would inevitably force banks to close or restrict the clients’ accounts on the least degree of suspicion, thereby alienating their customers, in order to avoid unspecified liability”). In addition to considering the consequences to TD Bank of imposing a duty here, “[u]nder this factor, courts also assess whether the defendant is in the best position to prevent the harm” that the plaintiff suffered. Fragale, 480 F. Supp. 3d at 667 (collecting cases). Frontline provides no argument on this issue, and the Court has little trouble finding that Frontline, as the company that wired the funds to the hacker’s account, was in the best position to prevent their loss. For example, before the initial wire, Lawler could have called Braxton to confirm the new account belonged to Gülipek Tech. See Chemalloy Co., 609 F. Supp. 3d at 378 (finding the
fourth factor weighed against creating a duty because “Chemalloy was in the best position to prevent the harm allegedly suffered by simply confirming the invoice was accurate, verifying the email received was in fact from the CFO, verifying that the account was the same account used for prior payments to this vendor, or by obtaining a court order mandating that Citibank freeze the funds. Chemalloy made no effort to confirm that the account receiving three separate wire transfers in fact belonged to their vendor.”); Fragale, 480 F. Supp. 3d at 667–68 (finding fourth factor weighed against imposing a duty where “[b]ased on the facts alleged, it is at least arguable that Plaintiff, rather than Wells Fargo, was in the best position to prevent the harm he allegedly suffered”). Considering all these issues together, the Court finds that, on balance, the fourth factor also weighs against imposition of a duty here. Factor 5: Last, the Court considers “the overall public interest in the proposed solution.” Althaus, 756 A.2d at 553. When considering this factor, courts often “look[ ] at other court’s
decisions in different jurisdictions as persuasive authority as to where the public interest lies.” Fragale, 480 F. Supp. 3d at 668 (quoting Gillen v. Boeing Co., 40 F. Supp. 3d 534, 541 (E.D. Pa. 2014)). Here, with the exception of Elkin Valley, the parties have identified no cases that find banks owe duties to noncustomers. See Fragale, 480 F. Supp. 3d at 668 (“This Court finds the consistent, prevailing, nationwide caselaw persuasive as indicating that there is minimal public interest in imposing the requested duties on banks like Wells Fargo under these circumstances.”); cf. Chemalloy Co., 609 F. Supp. 3d at 379 (“Finally, as to the public interest in a proposed solution, the public has an interest in preventing fraudulently obtained funds from being withdrawn once suspicious behavior has been identified. The public likewise has an interest in being able to access funds from their own bank account. That is why the Pennsylvania Banking
Code requires a court order to freeze funds. If the noncustomer follows that established protocol it protects both the noncustomer’s interest in the funds and the bank’s obligation to its customers. Since there is already recourse for entities like Chemalloy to freeze funds and undertake a fraud review, it does not further serve the public interest to create new duties between a bank and noncustomer.”). As such, the fifth factor also weighs against imposition of a duty in these circumstances. Balancing: In sum, one factor weighs in favor of imposing a duty and the other four weigh against. On balance, this Court finds the Althaus factors weigh against imposition of a duty here. See Citizens Bank of Pa., 609 F. App’x at 93 (“On balance here, the scales tip heavily against the existence of a duty. No relationship exists between the Bank and RTI, and the public interest in holding companies like RTI liable for data breaches to financial institutions with which it has no connection is negligible. Notwithstanding that the harm to the Bank was reasonably foreseeable, the consequences of imposing a duty on RTI would effectively excuse
the Bank’s own failure to ensure that withdrawals from its branches are legitimate. In sum, the District Court's decision that no duty exists was correct.”). * * * Because TD Bank did not owe a duty of care to Frontline, Frontline’s negligence claim fails as a matter of law. TD Bank’s motion to dismiss is granted as to Count I. B. Count III: Declaratory Judgment for Violation of UCC Article 4A That leaves Frontline’s claim that TD Bank violated Article 4A of the Uniform Commercial Code (UCC) by “handling Frontline’s funds and transmitting them to [the] Hackers.” (Doc. No. 1 at ¶¶ 63–66; see also July 8, 2026 H’rg. Tr. at 61:17–18 (“The UCC claim has to do with transfer of ACH payments.”).) Apart from that allegation, Frontline does not identify the facts that give rise to the Article 4A violation, nor does it identify the specific
section of Article 4A anchoring its violation. However, in its entirety, “Article 4A of the UCC applies to claims arising out of wire transfers.” Chemalloy Co., LLC, 609 F. Supp. 3d at 347; see also Organic Leasing, LLC v. Branch Banking & Tr., No. 18-1421, 2018 U.S. Dist. LEXIS 164229, at *5 (E.D. Pa. Sep. 24, 2018) (“Article 4A governs funds transfers.”). “The scope of 4A is determined by the definition of ‘payment order’ and ‘funds transfer’ found in Section 4A- 103 and Section 4A-104.” 13 Pa. Stat. & Cons. Stat. § 4A102, cmt.; accord Fragale, 480 F. Supp. 3d at 659. The phrase “funds transfer” is defined as: the series of transactions, beginning with the originator’s payment order, made for the purpose of making payment to the beneficiary of the order. The term includes any payment order issued by the originator's bank or an intermediary bank intended to carry out the originator's payment order. A funds transfer is completed by acceptance by the beneficiary's bank of a payment order for the benefit of the beneficiary of the originator's payment order. 13 Pa. Stat. & Cons. Stat. § 4A104(a). And the phrase “payment order” is defined as: An instruction of a sender to a receiving bank, transmitted orally, electronically or in writing, to pay, or to cause another bank to pay, a fixed or determinable amount of money to a beneficiary if: (i) the instruction does not state a condition to payment to the beneficiary other than time of payment; (ii) the receiving bank is to be reimbursed by debiting an account of, or otherwise receiving payment from, the sender; and (iii) the instruction is transmitted by the sender directly to the receiving bank or to an agent, funds-transfer system or communication system for transmittal to the receiving bank. Id. § 4A103. This Court agrees with TD Bank that these definitions limit Article 4A, such that it governs “only those actions occurring between the originator’s wire fund instruction (‘beginning with the originator’s payment order’) and the beneficiary bank’s acceptance of the wire transferred funds (‘completed by acceptance by the beneficiary’s bank of a payment order’).” (Doc. No. 18-1 at 15 (quoting Fragale, 480 F. Supp. 3d at 659).) In other words, claims premised on pre- and post-transfer conduct fall outside the scope of Article 4A and fail as a matter of law. Here, Frontline’s UCC claim has been a moving target. In the Complaint, Frontline states only that TD Bank violated the UCC when it “handl[ed] the funds and transmit[ed] them to [the] Hackers.” (Doc. No. 1 at ¶ 65.) The Complaint does not clarify what is meant by “handling the funds.” And regardless, the withdrawal of funds by the hackers falls outside the scope of Article 4A. See Fragale, 480 F. Supp. 3d at 660 (“It is equally apparent that the challenged withdrawal of the funds occurred at a point in time after the beneficiary bank (Wells Fargo) ‘accepted’ the wire transferred funds [from the plaintiff].”). Accordingly, the motion to dismiss Count III is granted. That does not end the matter, however. In its response brief, Frontline shifted gears,
arguing that the UCC claim is actually about the six ACH transfers from Frontline’s bank (Truist) into the fraudulent TD Bank account. (See Doc. No. 20 at 13 (“Frontline can amend to identify the particular statutory provisions implicated by the alleged misdescription of the beneficiary and by the legal consequences of TD Bank’s alleged acceptance and handling of the payment orders.”); see also July 8, 2026 Hr’g. Tr. at 64:12 (“The Court: So you are not looking at [sic] from TD Bank to the Hackers? [Frontline’s counsel]: In the U.C.C. provision— The Court: Right. [Frontline’s counsel]: That’s correct on the U.C.C. count. The Court: So you are only looking from Truist to TD Bank? [Frontline’s counsel]: Correct.”).) And Frontline requests leave to amend its UCC claim to clarify the scope of Count III in this regard. (Id.) TD Bank argues that amendment would be futile (Doc. No. 21 at 14–16), but the Court cannot say that for
certain at this stage. Recognizing that amendment should be freely given “when justice so requires,” Fed. R. Civ. P. 15(a)(2), the Court will grant Frontline the opportunity to amend Count III to the extent it can in good faith cure the deficiencies identified in this Memorandum. Any amendment must identify the provisions of Article 4A that TD Bank is alleged to have violated and describe the facts that support those violations.7
7 The Court is extremely concerned about how Frontline’s counsel has handled the UCC claim to date. As noted above, the Complaint fails to identify the specific provisions of Article 4A that TD Bank allegedly violated, and although the Complaint seems to focus on the withdrawals from the TD Bank account, counsel’s briefing and oral argument suggested that Frontline is actually challenging the transfers from Frontline into the TD Bank account. Adding to our concern, during oral argument, counsel attempted to argue around these concerns by claiming that he is “not an expert in UCC.” (July 8, 2026 Hr’g. Tr. at 60:20.) Against this backdrop, the Court warns Frontline that before amending Count III, IV. CONCLUSION For the reasons discussed above, the motion to dismiss is granted. Frontline will, however, be given an opportunity to amend Count III if it can do so in good faith. An appropriate order follows.
counsel is expected to thoroughly research whether Frontline can put forth a viable UCC claim that survives the arguments raised by TD Bank’s counsel in the reply brief (see Doc. No. 21 at 14–16).