UNITED STATES DISTRICT COURT EASTERN DISTRICT OF MICHIGAN SOUTHERN DIVISION
HEGIRA HEALTH, INC.,
Plaintiff, Case No. 2:25-cv-12481
v. Honorable Susan K. DeClercq United States District Judge FIFTH THIRD BANK NA,
Defendant. _____________________________/
OPINION AND ORDER GRANTING DEFENDANT’S MOTION TO DISMISS (ECF No. 6) AND DISMISSING THE CASE
In this case, Plaintiff Hegira Health, Inc. (Hegira) lost a large sum of money because of a third-party fraudulently posing, ironically, as a fraud prevention officer. Hegira seeks to hold its bank, Defendant Fifth Third Bank NA (Fifth Third), liable under the Uniform Commercial Code (UCC) for not responding adequately to stop the wire transfers in the 33 minutes that the third-party initiated the transfers. But because Hegira did not sufficiently plead that Fifth Third’s response was the result of the failure of particular, agreed upon security procedures, this Court will grant Fifth Third’s motion and dismiss this case. I. BACKGROUND The following factual allegations come from Hegira’s complaint, and they are largely undisputed. ECF No. 1-2. At the motion-to-dismiss stage, these facts must be accepted as true with all reasonable inferences drawn in Hegira’s favor. See Lambert v. Hartman, 517 F.3d 433, 439 (6th Cir. 2008). Beyond the pleadings, this
Court may also consider documents that are public record or that are referred to and integral to the claims. See Com. Money Ctr., Inc. v. Ill. Union Ins. Co., 508 F.3d 327, 335–36 (6th Cir. 2007).
Hegira is a non-profit provider of “mental health and substance abuse use disorder treatment services” and is “one of Michigan’s largest freestanding, integrated behavioral health care organizations.” ECF No. 1-2 at PageID.14. Fifth Third is a national bank with its main office in Cincinnati, Ohio. Id.; see also ECF
No. 1 at PageID.4. Since at least January 2022, Hegira had a bank account at Fifth Third. ECF No. 1-2 at PageID.16–17. According to Fifth Third, all bank customers, including
Hegira, enter into a Master Treasury Management Agreement (MTMA) and Online Channel Access Agreement (OCAA) (collectively “the Agreements”) that govern the contours of the parties’ relationships. ECF No. 6 at PageID.47–48 (referring to ECF Nos. 6-1; 6-2); see also ECF No. 8 at PageID.124 (“Hegira acknowledges that
agreements exist between Hegira and Bank[.]”). On about May 13, 2025, an individual “identifying herself as a fraud prevention officer of [Fifth Third] was able to obtain login credentials to Hegira’s account . . . . [which] also granted administrative rights over such accounts.”1 ECF No. 1-2 at PageID.15. Hegira alleges that when the individual obtained the login
credentials, Hegira was not aware that the individual “was an imposter.” Id. In the next two days, Hegira’s authorization settings changed from requiring dual authorization to single user authorization for wire transfers. Id. at PageID.16.
Two days later, on May 15, 2025, “between 4:29 P.M. and 5:02 P.M.,” Fifth Third processed 14 wire transfers from Hegira’s accounts totaling $2,089,194.00. Id. at PageID.15. The transfers were sent to the bank accounts of 14 different beneficiaries with distinctive names but with the same address in Miami, Florida. Id.
at PageID.16. Each transfer was approximately $150,000.00. Id. But one wire transfer for $167,750.00 “was not completed[] because the beneficiary account was closed.” Id. at PageID.16 n.1.
Fifth Third “notified Hegira after 5:00 P.M.” of the transfers, and Hegira conveyed that the transfers “were fraudulent and unauthorized.” Id. at PageID.17. According to Hegira, “[s]ome funds were later recovered.” Id. at PageID.16 n.1. But when Hegira demanded full restitution from the bank, Fifth Third “did not respond
to Hegira’s demand.” Id. at PageID.18.
1 Hegira does not elaborate as to how the individual got access to the account but does not accuse Fifth Third of providing the information. So, on July 14, 2025, Hegira filed a complaint in Wayne County Circuit Court (“the Complaint”), bringing one count under Article 4A of the UCC. Id. Hegira
alleges that Fifth Third violated UCC Article 4A § 202 by not acting in good faith or compliance with commercially reasonable security procedures to flag and prevent the fraudulent wire transfers from Hegira’s account. Id. at PageID.14–18.
On August 11, 2025, Fifth Third removed the case to this Court. See ECF No. 1. And on September 3, 2025, Fifth Third moved to dismiss Hegira’s complaint under Civil Rule 12(b)(6), arguing that Fifth Third cannot be liable because it acted in good faith and followed the security procedures to which both Parties agreed and
which are commercially reasonable. ECF No. 6. Later that month, Hegira responded, ECF No. 8, and then Fifth Third replied, ECF No. 9. This Court has determined that a hearing on the motion is not necessary and will decide it on the papers. See E.D.
Mich. LR 7.1(f)(2). II. LEGAL STANDARD Under Civil Rule 12(b)(6), a pleading fails to state a claim if its allegations do not support recovery under any recognizable legal theory. Ashcroft v. Iqbal, 556 U.S.
662, 678 (2009). When considering a Rule 12(b)(6) motion, the court accepts the complaint’s factual allegations as true and draws all reasonable inferences in the plaintiff’s favor. See Lambert v. Hartman, 517 F.3d 433, 439 (6th Cir. 2008). The
plaintiff need not provide “detailed factual allegations” but must provide “more than labels and conclusions.” Bell Atl. Corp. v. Twombly, 550 U.S. 544, 555 (2007) (“[A] formulaic recitation of the elements of a cause of action will not do.”). The complaint
is facially plausible if it “pleads factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged.” Iqbal, 556 U.S. at 678; see also 16630 Southfield Ltd. v. Flagstar Bank, F.S.B., 727 F.3d
502, 503 (6th Cir. 2013). Otherwise, the Court must grant the motion to dismiss. See Twombly, 550 U.S. at 570. III. DISCUSSION Hegira argues that Fifth Third violated the UCC by having commercially
unreasonable fraud response security procedures and—or, alternatively—did not act in good faith or compliance with its security procedures when the 14 wire transfers occurred. ECF No. 1-2 at PageID.15–17. Fifth Third responds that Hegira has not
pleaded a violation of the UCC because Hegira’s critiques are of Fifth Third’s internal fraud response mechanisms, not the agreed-upon security procedures subject to the UCC. ECF No. 6 at PageID.54–57. As explained below, this Court finds that Hegira has not raised allegations about specific, agreed-upon security procedures
within the UCC’s purview, so this Court will grant Fifth Third’s motion and dismiss the Complaint. A. Substantive Law As a threshold matter, this Court must determine which substantive law
applies to Hegira’s claims. Because this is a diversity action removed from a Michigan state court to the Eastern District of Michigan, typically Michigan’s substantive law applies. Allied Indus. Scap, Inc. v. OmniSource Corp., 776 F.3d 452,
Free access — add to your briefcase to read the full text and ask questions with AI
UNITED STATES DISTRICT COURT EASTERN DISTRICT OF MICHIGAN SOUTHERN DIVISION
HEGIRA HEALTH, INC.,
Plaintiff, Case No. 2:25-cv-12481
v. Honorable Susan K. DeClercq United States District Judge FIFTH THIRD BANK NA,
Defendant. _____________________________/
OPINION AND ORDER GRANTING DEFENDANT’S MOTION TO DISMISS (ECF No. 6) AND DISMISSING THE CASE
In this case, Plaintiff Hegira Health, Inc. (Hegira) lost a large sum of money because of a third-party fraudulently posing, ironically, as a fraud prevention officer. Hegira seeks to hold its bank, Defendant Fifth Third Bank NA (Fifth Third), liable under the Uniform Commercial Code (UCC) for not responding adequately to stop the wire transfers in the 33 minutes that the third-party initiated the transfers. But because Hegira did not sufficiently plead that Fifth Third’s response was the result of the failure of particular, agreed upon security procedures, this Court will grant Fifth Third’s motion and dismiss this case. I. BACKGROUND The following factual allegations come from Hegira’s complaint, and they are largely undisputed. ECF No. 1-2. At the motion-to-dismiss stage, these facts must be accepted as true with all reasonable inferences drawn in Hegira’s favor. See Lambert v. Hartman, 517 F.3d 433, 439 (6th Cir. 2008). Beyond the pleadings, this
Court may also consider documents that are public record or that are referred to and integral to the claims. See Com. Money Ctr., Inc. v. Ill. Union Ins. Co., 508 F.3d 327, 335–36 (6th Cir. 2007).
Hegira is a non-profit provider of “mental health and substance abuse use disorder treatment services” and is “one of Michigan’s largest freestanding, integrated behavioral health care organizations.” ECF No. 1-2 at PageID.14. Fifth Third is a national bank with its main office in Cincinnati, Ohio. Id.; see also ECF
No. 1 at PageID.4. Since at least January 2022, Hegira had a bank account at Fifth Third. ECF No. 1-2 at PageID.16–17. According to Fifth Third, all bank customers, including
Hegira, enter into a Master Treasury Management Agreement (MTMA) and Online Channel Access Agreement (OCAA) (collectively “the Agreements”) that govern the contours of the parties’ relationships. ECF No. 6 at PageID.47–48 (referring to ECF Nos. 6-1; 6-2); see also ECF No. 8 at PageID.124 (“Hegira acknowledges that
agreements exist between Hegira and Bank[.]”). On about May 13, 2025, an individual “identifying herself as a fraud prevention officer of [Fifth Third] was able to obtain login credentials to Hegira’s account . . . . [which] also granted administrative rights over such accounts.”1 ECF No. 1-2 at PageID.15. Hegira alleges that when the individual obtained the login
credentials, Hegira was not aware that the individual “was an imposter.” Id. In the next two days, Hegira’s authorization settings changed from requiring dual authorization to single user authorization for wire transfers. Id. at PageID.16.
Two days later, on May 15, 2025, “between 4:29 P.M. and 5:02 P.M.,” Fifth Third processed 14 wire transfers from Hegira’s accounts totaling $2,089,194.00. Id. at PageID.15. The transfers were sent to the bank accounts of 14 different beneficiaries with distinctive names but with the same address in Miami, Florida. Id.
at PageID.16. Each transfer was approximately $150,000.00. Id. But one wire transfer for $167,750.00 “was not completed[] because the beneficiary account was closed.” Id. at PageID.16 n.1.
Fifth Third “notified Hegira after 5:00 P.M.” of the transfers, and Hegira conveyed that the transfers “were fraudulent and unauthorized.” Id. at PageID.17. According to Hegira, “[s]ome funds were later recovered.” Id. at PageID.16 n.1. But when Hegira demanded full restitution from the bank, Fifth Third “did not respond
to Hegira’s demand.” Id. at PageID.18.
1 Hegira does not elaborate as to how the individual got access to the account but does not accuse Fifth Third of providing the information. So, on July 14, 2025, Hegira filed a complaint in Wayne County Circuit Court (“the Complaint”), bringing one count under Article 4A of the UCC. Id. Hegira
alleges that Fifth Third violated UCC Article 4A § 202 by not acting in good faith or compliance with commercially reasonable security procedures to flag and prevent the fraudulent wire transfers from Hegira’s account. Id. at PageID.14–18.
On August 11, 2025, Fifth Third removed the case to this Court. See ECF No. 1. And on September 3, 2025, Fifth Third moved to dismiss Hegira’s complaint under Civil Rule 12(b)(6), arguing that Fifth Third cannot be liable because it acted in good faith and followed the security procedures to which both Parties agreed and
which are commercially reasonable. ECF No. 6. Later that month, Hegira responded, ECF No. 8, and then Fifth Third replied, ECF No. 9. This Court has determined that a hearing on the motion is not necessary and will decide it on the papers. See E.D.
Mich. LR 7.1(f)(2). II. LEGAL STANDARD Under Civil Rule 12(b)(6), a pleading fails to state a claim if its allegations do not support recovery under any recognizable legal theory. Ashcroft v. Iqbal, 556 U.S.
662, 678 (2009). When considering a Rule 12(b)(6) motion, the court accepts the complaint’s factual allegations as true and draws all reasonable inferences in the plaintiff’s favor. See Lambert v. Hartman, 517 F.3d 433, 439 (6th Cir. 2008). The
plaintiff need not provide “detailed factual allegations” but must provide “more than labels and conclusions.” Bell Atl. Corp. v. Twombly, 550 U.S. 544, 555 (2007) (“[A] formulaic recitation of the elements of a cause of action will not do.”). The complaint
is facially plausible if it “pleads factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged.” Iqbal, 556 U.S. at 678; see also 16630 Southfield Ltd. v. Flagstar Bank, F.S.B., 727 F.3d
502, 503 (6th Cir. 2013). Otherwise, the Court must grant the motion to dismiss. See Twombly, 550 U.S. at 570. III. DISCUSSION Hegira argues that Fifth Third violated the UCC by having commercially
unreasonable fraud response security procedures and—or, alternatively—did not act in good faith or compliance with its security procedures when the 14 wire transfers occurred. ECF No. 1-2 at PageID.15–17. Fifth Third responds that Hegira has not
pleaded a violation of the UCC because Hegira’s critiques are of Fifth Third’s internal fraud response mechanisms, not the agreed-upon security procedures subject to the UCC. ECF No. 6 at PageID.54–57. As explained below, this Court finds that Hegira has not raised allegations about specific, agreed-upon security procedures
within the UCC’s purview, so this Court will grant Fifth Third’s motion and dismiss the Complaint. A. Substantive Law As a threshold matter, this Court must determine which substantive law
applies to Hegira’s claims. Because this is a diversity action removed from a Michigan state court to the Eastern District of Michigan, typically Michigan’s substantive law applies. Allied Indus. Scap, Inc. v. OmniSource Corp., 776 F.3d 452,
453 (6th Cir. 2015). However, Fifth Third argues that Ohio law applies as provided in the MTMA. ECF No. 6 at PageID.53 n.3 (citing ECF No. 6-1 at PageID.76–77). Hegira acknowledges this argument and appears to concede that Ohio law applies by citing it. ECF No. 8 at PageID.125 n.3, 128 (“Section 202 [of UCC Article 4A]
is codified in Ohio at OH Rev Code § 1304.57”). But Hegira contests—and reserves the right to argue over—whether the Agreements attached to Fifth Third’s motion are binding or operative, thereby rendering Michigan law applicable. Id. at
PageID.124 n.2. Fortunately, §§ 201–202 of UCC Article 4A has been adopted by Ohio and Michigan in identical fashion, barring minor formatting differences. See OHIO REV. CODE § 1304.56–57 and MICH. COMP. LAWS § 440.4701–02; see also Experi-Metal,
Inc. v. Comercia Bank, No. 09-14890, 2010 WL 2720914, at *3 (E.D. Mich. July 8, 2010); Fed. Ins. Co. v. Benchmark Bank, No. 2:17-cv-135, 2018 WL 527285, at *6 (S.D. Ohio Jan. 24, 2018) (applying “Michigan’s identically-worded UCC provision”). Accordingly, this Court need not distinguish among them for its analysis at this time.
“Article 4A of the UCC governs fund transfers.” Imperium Logistics, LLC v. Truist Fin. Corp., 686 F. Supp. 3d 600, 603 (E.D. Mich. 2023). “Whether the risk of loss for an unauthorized wire transfer order falls upon the bank or its customer is
governed by” § 202 of UCC Article 4A, as adopted in Ohio and Michigan. Experi- Metal, 2010 WL 2720914, at *3; McLaughlin v. Comerica Bank, No. 21-12661, 2022 WL 16040109, at *5 (E.D. Mich. Apr. 18, 2022) (“Electronic fund transfers are governed by Article 4A of the [UCC], that is codified in Michigan at MICH. COMP.
LAWS § 440.4601 et seq.); Fed. Ins. Co. v. Benchmark Bank, No. 2:17-cv-135, 2018 WL 527285, at *6 (S.D. Ohio Jan. 24, 2018) (applying “Michigan’s identically- worded UCC provision”).
Under OHIO REV. CODE § 1304.57 and MICH. COMP. LAWS § 440.4702, a wire transfer is considered a customer’s effective order even if the customer did not authorize it where: (1) the bank and customer agreed that the authenticity of payment orders would be verified pursuant to a security procedure; (2) the security procedure is commercially reasonable; and (3) the bank proves that it accepted the orders in good faith and in compliance with the security procedure and any written agreement or instruction of the customer. Experi-Metal, Inc., 2010 WL 2720914, at *3 (citing MICH. COMP. LAWS § 440.4702(2)). And where the transfer is considered effective under these
circumstances, the risk of loss from the transfer lies with the customer. See id. B. Security Procedure At the core of this motion to dismiss is a dispute over the first factor regarding
the definition of a security procedure. Thus, before this Court is the question of whether Hegira raised allegations about actual, agreed-upon security procedures for which Fifth Third can be held liable under the UCC. According to Article 4A § 201, a “security procedure” is defined as a
procedure that is “established by agreement of the customer and a receiving bank for the purpose of (i) verifying that a payment order or communication amending or cancelling a payment order is that of the customer, or (ii) detecting error in the
transmission or the content of the payment order or communication.” Art. 4A § 201; see also OHIO REV. CODE § 1304.56; MICH. COMP. LAWS § 440.4701. Comparing signatures on payment orders with that of the customer “is not by itself a security procedure.” Id. But a security procedure may use “algorithms or other codes,
identifying words or numbers, encryption, callback procedures, or similar security devices.” Id. Here, the Parties both acknowledge that they established security procedures
through some agreements. See ECF Nos. 6 at PageID.54–55; 6-1; 6-2; 8 at PageID.124–25, 124 n.2. But Hegira contends that Fifth Third did not prove that the Agreements attached to Fifth Third’s motion are operative and binding to Hegira,
thereby reserving Hegira’s “right to argue” that the Agreements are not binding. ECF No. 8 at PageID.124 n.2. Yet in the same breath, Hegira attached a copy of the OCAA to its response brief and cites to both Agreements therein. ECF No. 8 at PageID.118,
124–25 (identifying ECF No. 6-2 as Exhibit 2 to its response Brief and citing to ECF Nos. 6-1 and 6-2 throughout). Notably, both Agreements contain the signature of Hegira’s Chief Financial Officer. See ECF Nos. 6-1 at PageID.82; 6-2 at PageID.103. In light of the signatures and Parties’ engagement with the Agreements, this Court
struggles to see how Fifth Third has not proven that the Agreements are operative and binding. But regardless of whether this Court considers the Agreements, this Court finds that Hegira’s complaint is insufficient because Hegira did not refer to
specific security procedures that Fifth Third and Hegira Health agreed to use but that were commercially unreasonable or with which Fifth Third failed to comply. 1. Without Consideration of the Agreements If this Court does not consider the Agreements, looking only at the “four
corners of the complaint,” then the Complaint lacks specific allegations that Fifth Third’s response efforts were “security procedures” that the Parties agreed to use. Instead, Hegira gestures broadly to Fifth Third’s “fraud engine” failing to flag the
wire transfers. ECF No. 1-2 at PageID.15–17 (describing that Fifth Third’s “fraud engine should have flagged a number of anomalies”; “[b]ased on those anomalies, [Fifth Third] should have immediately issued a fraud alert and/or soft hold”; and
“[n]o later than the fourth or fifth wire, and perhaps earlier, these patterns should have progressed from soft holds and fraud alerts to trigger a complete system block” with a fraud analyst and securities group). But the UCC makes clear that security
procedures are “established by agreement of the customer and a receiving bank.” See Art. 4A § 201 (emphasis added); see also OHIO REV. CODE § 1304.56; MICH. COMP. LAWS § 440.4701. And here, Hegira does not allege that there was any agreement to use the “fraud engine” or “risk scoring” as security procedures. See GN
Pro Grp., LLC v. Well Done ASAP, LLC, 764 F. Supp. 3d 757, 762 (N.D. Ill. 2025) (dismissing UCC claims against a bank for an imposter defrauding the plaintiff because the complaint did “not allege that [the Parties] agreed on any security
procedure in connection with the wire transfer”). Accordingly, the security-related actions for which Hegira seeks to hold Fifth Third liable are not related to “security procedures” as contemplated in the UCC. See Art. 4A §§ 201–02; see also Experi- Metal, Inc., 2010 WL 2720914, at *3 (citing MICH. COMP. LAWS § 440.4702(2)).
Thus, Hegira has not stated a claim upon which relief can be granted. See Iqbal, 556 U.S. at 678. 2. With Consideration of the Agreements Even if this Court considers the Agreements as “integral to the complaint,”2
Hegira did not specifically identify security procedures in the Agreements that are allegedly commercially unreasonable or were not acted upon in good faith. The MTMA defines “security procedures” as “the Credentials, call-back protocols, and
other systems, software and procedures provided by [Fifth Third], its Processors or any payment network for authenticating instructions, transactions and use of the Services.” ECF No. 6-1 at PageID.81. And the OCAA defines “Credentials” as “the username, personal identification numbers, identification codes, passwords and
other identifying and authentication inputs, security token or authentication device, equipment or software, that the Channel Administrator and Users use or apply in order to access the Channel Services.” ECF No. 6-2 at PageID.100. But as stated,
the Complaint simply describes the fraud response procedures that it alleges Fifth Third should have had or acted on, but without identifying where in the Agreements the Parties agreed to use a “fraud engine” or risk scoring response system.3 See ECF No. 1-2 at PageID.15–18.
2 “[T]he court may also consider other materials that are integral to the complaint, are public records, or are otherwise appropriate for the taking of judicial notice.” Hodges v. City of Grand Rapids, 139 F.4th 495, 511 (6th Cir. 2025) (citation modified).
3 In the cases relied upon by Hegira, the plaintiffs raised allegations about specific security procedures to which the parties had agreed to use for authentication. See In its response brief, Hegira argues that it “pleaded that banks employ information security risk management processes, including risk scoring systems, that
evaluate individual transactions for fraud and provide controls to prevent it. Defendant [Fifth Third’s] agreements include such systems within its definition of ‘security procedures.’” ECF No. 8 at PageID.118. Hegira elaborates that Fifth
Third’s “automated fraud engine, risk scoring, hold and call-back procedures,[4] as set out in the Complaint, and other such ‘systems, software, and procedures provided by [Fifth Third]’ are part of the Article 4A security procedures under the parties’ agreements.” Id. at PageID.125.
Experi-Metal, 2010 WL 2720914, at *4–5 (identifying the secure token technology); Experi-Metal, Inc. v. Comerica Bank, No. 09-14890, 2011 WL 2433383, at * 6–7 (same). Indeed, Hegira acknowledges that in Patco Construction Company v. People’s United Bank, the First Circuit assessed the reasonableness of specific, agreed upon security procedures such as “user IDs and passwords, the placement of ‘cookies’ on customer devices, challenge questions, and risk profiling.” ECF No. 8 at PageID.131 (citing 684 F.3d 197, 202–03 (1st Cir. 2012)). In fact, the First Circuit held that the bank’s security procedures were commercially unreasonable by analyzing the specific security procedures that the plaintiff identified as problematic (e.g., the new $1 threshold trigger for security questions, in the context of the bank’s lack of any additional security measures like tokens to shore up the new low threshold). See Patco, 684 F.3d at 210–13. In contrast, Hegira does not identify any specific security procedures contemplated in the Agreements akin to the security procedures in these cases that could then lead this Court to assess the allegations about commercial reasonableness and good faith.
4 The Agreements make no mention of a “hold procedure,” and Hegira does not raise any allegations in the complaint about Fifth Third not having a commercial reasonable “call-back procedure[]” or failing to act in compliance or good faith with such a procedure. But a plain reading of the Agreements does not support Hegira’s claim. See Andrews v. Colum. Gas Trans. Corp., 544 F.3d 618, 632 (6th Cir. 2008) (relying on
the plain meaning of an agreement and finding that [t]he plain and ordinary meaning of [the agreement’s] words is clear”). The Agreements do not mention an “automated fraud engine” or a “risk scoring system.” See ECF Nos. 6-1 at PageID.81; 6-2 at
PageID.100. And to the extent that Hegira construes these as “other systems, software and procedures,” Hegira misses the crucial end of that phrase: “for authenticating instructions, transactions and use of the Services.”5 ECF No. 6-1 at PageID.81. Indeed, security procedures are agreed upon protocols like “identifying
words or numbers, [and] encryption” to verify that service activity or transactions are those of the customer. See Art. 4A § 201; see also OHIO REV. CODE § 1304.56; MICH. COMP. LAWS § 440.4701. In other words, security procedures under the UCC
are typically proactive measures to authenticate customer identity and prevent errors. See generally Art. 4A § 201; OHIO REV. CODE § 1304.56; MICH. COMP. LAWS § 440.4701.
5 Furthermore, this general allegation in a response brief cannot save the defective complaint. See Geller v. Michigan, No. CV-17-13233, 2019 WL 2150393 at *7 n.5 (E.D. Mich. Apr. 26, 2019) (“Courts have recognized that a plaintiff cannot use his response to a motion to dismiss as a vehicle to cure the defects in an operative complaint.”), report and recommendation adopted Boucher v. Michigan, No. 17- 13233, 2019 WL 2143203 (E.D. Mich. May 16, 2019); see also Bates v. Green Farms Condo. Ass’n, 958 F.3d 470, 483 (6th Cir. 2020) (“Plaintiffs cannot . . . amend their complaint in an opposition brief or ask the court to consider new allegations (or evidence) not contained in the complaint.”). But Hegira appears to take issue with Fifth Third’s systemic response to the fraudulent wire transfers, which are reactive measures not clearly contemplated in
the “other systems” language of the Agreements. Compare ECF No. 1-2 at PageID.18 (alleging that because Fifth “continued to process the wires despite their multiple flags and anomalies[, this] is evidence of a systemic failure [where Fifth
Third’s] fraud engine failed and does not meet commercially reasonable standards”) with ECF No. 6-1 at PageID.81 and GN Pro Grp., 764 F. Supp. 3d at 762–63 (finding that the complaint alleged that the defendant bank had a security procedure for wire transfer errors but that the bank’s “potential violation of its internal procedure was
not a violation of a security procedure” under the UCC) (cleaned up). Therefore, Hegira has not met its burden of pleading enough factual content about the Parties’ actual, agreed upon security procedures to allow this Court “to draw the reasonable
inference that [Fifth Third] is liable” under UCC Article 4A § 202. See Iqbal, 556 U.S. at 678. At bottom, Hegira’s situation is unfortunate. A third-party defrauded Hegira of a significant sum. But Hegira does not allege that the third-party obtained access
to Hegira’s accounts as the result of a failure on Fifth Third’s part. Instead, it takes issue with Hegira’s responses after the third-party began initiating transactions— none of which were the subject of any agreement between Hegira and Fifth Third.
In so doing, Hegira aims to hold Fifth Third liable for certain procedural failures outside of the UCC.6 Therefore, this Court will grant the motion to dismiss and dismiss the case.
IV. CONCLUSION Accordingly, it is ORDERED that Defendant’s Motion to Dismiss, ECF No. 6, is GRANTED, hereby CLOSING THE CASE.
This is a final order and closes the above-captioned case. /s/Susan K. DeClercq SUSAN K. DeCLERCQ United States District Judge Dated: July 30, 2026
6 To hold otherwise would invite the kind of chaos contemplated in Jajati v. JPMorgan Chase Bank, N.A.: Plaintiff is asking the Court to find, in effect, that a bank that receives an authorized wire transfer instruction and follows that instruction precisely, but learns a month later from the customer that he had been tricked by a third-party to wire the funds, can be liable for executing the instructions. Such a farfetched standard would toss bank payment systems into chaos because the risk of loss from Plaintiff’s own actions (or inactions) would be unreasonably shifted to the bank. That is not what the contracts here provide for, and, as discussed below, is certainly not what the drafters of the U.C.C. had in mind when they drafted Article 4-A. 711 F. Supp. 3d 169, 175 (E.D. N.Y. 2024).