Lack of notifications on password changes and slow customer service put Venmo users at risk for fraud
Context & Ripple Effects
Alison Griswold's Slate report lands at the start of a decade-long accountability arc for Venmo. Within weeks of publication, Venmo announced multi-factor authentication and email notifications — a direct response to exactly the gaps she flagged around silent password changes and hard-to-reach support.
The story didn't stop there: PayPal's SEC filing later revealed an FTC investigation into deceptive or unfair practices, which ended in an FTC settlement with the chairwoman citing 'real harm' to consumers. The through-line from this article to those outcomes makes it the origin point for how regulators and users began judging peer-to-peer payment apps on security and service quality.
First-order effects
- Venmo users whose accounts are taken over have no email alert when their password changes, so attackers can lock out owners before any fraud is noticed — and with customer service slow to respond, victims' recourse in the moment is effectively none.
Second-order effects
- The public scrutiny forces Venmo into remediation within weeks, shipping multi-factor authentication and notification emails, while handing the FTC a documented record of security complaints that feeds its later investigation of the company.
Third-order effects
- Fraud costs follow Venmo for years — internal docs show a ~$40M Q1 2018 operating loss driven largely by fraud — and by 2020 reviewers describe rising fraud rates across payments apps from PayPal, Square, and Zelle with thin support (per the New York Times), pushing the industry toward privacy-by-default designs like Venmo's later friends-only onboarding default.
The trend: Peer-to-peer payment apps are being pushed from growth-first frictionlessness toward security- and privacy-by-default, with regulators and fraud losses forcing each step.