Forensic Analysis Brief

ROYER V. FINTECH

Exposing the Dispute Suppression Machine: How Capital One, Mission Lane, and Sezzle weaponize automated logic to bury consumer identity theft.

Total Disputed Fraud
$2,892.44
Combined unauthorized BNPL charges across Capital One and Mission Lane accounts.
OpenLoop Breach Scale
716,000
Individuals impacted by the data breach that exposed the credential vectors used in this fraud.
Withheld Evidence Rate
100%
Rate at which Sezzle withheld the fraudulent state investigator email from Capital One denial packets.

1. The Data Disconnect: Falsified Regulatory Documents

The foundation of this dispute suppression relies on structurally inaccurate documentation. A forensic audit of 38 Truth in Lending Disclosures (TILDs) generated by Sezzle and WebBank revealed that over 53% overstated the "Amount Financed." These federal documents are generated statically at checkout and never updated to reflect actual settlement amounts, allowing platforms to lock consumers into ghost debts.

TILD Disclosed Amount vs. Actual Settled Charge

Case Study 'bihlg': The TILD claims $125.47 was disbursed, but the actual Amazon charge was $67.06. WebBank never issued a correction.

2. The Three-Legged Liability Shield

The core mechanical flaw in FinTech dispute resolution is the intentional fragmentation of the transaction. The consumer's bank relies entirely on the FinTech processor for verification. When fraud occurs, the FinTech asserts authorization based on a shipping receipt (Leg 1), and the consumer's bank rubber-stamps this assertion to authorize the debit (Leg 3), skipping the mandatory investigation of the actual credit agreement (Leg 2).

The Dispute Deflection Loop

Leg 1: Fulfillment Fraudster → Merchant (MEDVi)
Item shipped to a drop address. Used as false proof of authorization.
Leg 2: Credit Agreement Sezzle Inc. / WebBank
Generates Flawed Chargeback Packet
Leg 3: Repayment Capital One / Mission Lane
Denies Reg E claim based solely on Leg 2 input.

3. Institutional Absurdity: The Explicit Failures

The reliance on Leg 2 FinTech logic breaks down entirely under forensic scrutiny. The formal legal demands directed at Capital One and Mission Lane expose a complete abdication of their duty to conduct a "reasonable investigation" under Regulation E.

Mission Lane / TAB Bank

The "[redacted]@wisconsin.gov" Absurdity

Mission Lane denied the consumer's fraud claim by citing evidence provided by Sezzle. In their official denial packet, Mission Lane included a screenshot of the fraudulent Sezzle account's "Personal Information" panel.

The screenshot explicitly listed the account's VERIFIED email credential as [redacted]@wisconsin.gov.

This email belongs to the actual Wisconsin state consumer-protection investigator assigned to Dr. Royer's complaint against Sezzle. Mission Lane accepted this as proof that Dr. Royer authorized the loan, meaning they either believed Dr. Royer was illegally using a state investigator's government email to buy shoes, or that the state investigator was committing identity theft against Dr. Royer. Instead of recognizing a massive flaw in Sezzle's authentication architecture, Mission Lane simply rubber-stamped the denial.

Capital One

Denying a Claim on a Deleted Account

Capital One's failure highlights the complete breakdown of temporal and factual logic in automated dispute systems.

  • On May 18, 2026, Sezzle officially concluded its relationship with Dr. Royer, waived the entire outstanding balance to zero, permanently closed the account, and deleted the tradeline from all credit bureaus.
  • Weeks later, Capital One issued a final denial of Dr. Royer's Regulation E dispute.
To deny the claim, Capital One relied exclusively on rebuttal evidence forwarded by Sezzle—evidence generated after Sezzle had already admitted the account was closed and the balance waived.

Capital One utilized a 216-page package of boilerplate terms from a FinTech partner to enforce a debt that the originating FinTech had already formally extinguished.

WebBank / FDIC

The "Paper Lender" Paradox

When the FDIC required WebBank to answer for the systematic TILD inaccuracies, WebBank did not act as an independent, regulated creditor auditing its vendor. Instead, WebBank adopted Sezzle's voice and defended the FinTech's technical platform limitations.

WebBank claimed there was no financial regulatory requirement to update the TILD post-consummation, effectively arguing that BNPL disclosures are exempt from standard Regulation Z accuracy updates.

This is a massive risk red flag. A federally insured, state-chartered bank theoretically has nothing to do with the day-to-day software architecture of its platform partner. By defending Sezzle's code limitations and claiming regulatory exemption, WebBank inadvertently proved it exercises zero independent oversight, functioning purely as a "paper lender" shielding the FinTech from compliance.

4. Evidence Suppression & Regulatory Liability

Capital One 216-Page Packet Composition

Evidence Tendered vs. Withheld

Regulatory Exposure Map

Capital One's reliance on Sezzle's unverified annotations constitutes a failure to conduct a reasonable investigation, triggering potential treble damages under 15 U.S.C. § 1693f(e).