Workweek Newsletter {beacon}

3 news stories, 2 reading recommendations, & 1 question.  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌
Fintech Takes
Alex Johnson
Sep 21st, 2026
{cta_url_read_in_browser = community_base_url + "/library/" + article_id + "?utm_source=newsletter&utm_medium=email&utm_campaign=" + edition_slug + "&utm_content=read_in_browser"}{cta_url_read_in_app = community_base_url + "/library/" + article_id + "?utm_source=newsletter&utm_medium=email&utm_campaign=" + edition_slug + "&utm_content=read_in_app"}{cta_url_join_conversation = community_base_url + "/library/" + article_id + "?utm_source=newsletter&utm_medium=email&utm_campaign=" + edition_slug + "&utm_content=join_conversation" + "#comments"} {if profile.vars.member_status == "lead" || profile.vars.member_status == "unfit"} {else}{if profile.vars.member_status == "fit"} {else}{if profile.vars.member_status == "member"} {else} {/if}{/if}{/if}

In partnership with


Happy Monday, Fintech Takers!

I trust you had a good weekend and I hope that your week is off to a productive start!

I have a rare non-travel week this week and I will be in Salt Lake City next week for the AI-Native Banking and Fintech Conference, followed by my virtual event on the science and fiction of friction (register to join us!)

Then we start gearing up for Money20/20 (we still have some room on Sunday morning, if you want to join us for 3x3 basketball!)

In short, it’s all about the fun here at Fintech Takes!

- Alex

Was this email forwarded to you?


Sponsored by Middesk

On paper, Orchard Crest was the applicant every risk team hopes for. Active registration, good standing, application details that matched the record, clean watchlist screens. Nothing obvious suggested a problem.

Every standard check also evaluates a business as a single entity.

The risk was in its relationships, and that’s what Middesk’s entity graph uncovers.

Middesk found one person tied to 10 other companies. Seven more businesses surfaced behind those.

One connected company had submitted 15 applications across 10 institutions, and Orchard Crest's registration number turned up in an archived shelf-company listing.

Would your existing process have caught this?

That's not even everything the entity graph found.


View of Toledo (1599–1600) by El Greco.

3 FINTECH NEWS STORIES

#1: Amazon’s War Against Agentic AI Continues

What happened?

Amazon is mad! Very Mad! GeekWire reports:

Amazon says it has cut off Meta’s new Muse personal AI agent from shopping on Amazon.com on behalf of customers, after attempting unsuccessfully to get the Facebook parent company to voluntarily exclude the e-commerce site from the experience.

The problem, Amazon says, is that it never agreed to any of it. Meta didn’t tell Amazon that Muse would access its store, the agent doesn’t identify itself when it browses, and it appears to capture and store customer credentials, which the company says could create privacy and security risks.

So what?

I wrote about Amazon vs. Perplexity in Friday’s newsletter, which is roughly the same issue (an AI agent accessing Amazon customers’ accounts with their permission and using their credentials). The big difference in that case is that Amazon accused Perplexity of violating the Computer Fraud and Abuse Act (i.e., accusing Perplexity of hacking), which is an argument that the Ninth Circuit Court of Appeals rejected.

In this case, Amazon is merely attempting to block Muse from accessing its website, and returning a message that tells users that using Muse to access Amazon is a violation of Amazon’s conditions of use. The fact that Amazon had to take this step is interesting, by itself, as Meta apparently refused to voluntarily exclude them from the activities that Muse can take on behalf of users.

I imagine that this specific fight between Amazon and Meta may end up getting resolved, without either party turning to litigation, given the larger commercial relationship that exists between the two companies (e.g., Meta signed a multibillion-dollar deal earlier this year to run agentic AI workloads on Amazon’s cloud). Meta may even agree to pay Amazon for direct (and controlled) access for Muse to Amazon customers’ accounts (with their permission).

However, there is no reason to think that similar fights between Amazon and other providers of agentic AI assistants will be resolved quickly or pleasantly. The company’s fight with Perplexity continues and, as Elon Musk points out, there’s no sure-fire way for Amazon to block all AI agents from accessing its site:

This is what distinguishes the 2026 fight over screen scraping in agentic AI from the 2000s/2010s fight over screen scraping in open banking.

Back then, it was expensive to build and maintain scrapers for every bank’s website, and such scrapers were fairly easy to identify and block, since they came from a small number of centralized IP addresses. Modern agentic screen scraping is cost-effective and decentralized. From the perspective of the company getting scraped, it’s not dissimilar to a DDOS attack.  

The reality is that companies won’t be able to stop AI agents, acting under the direction of those companies’ customers, from accessing their websites and taking actions. And, unfortunately, when those actions result in harm to the customers, those companies will not be shielded from the fallout. Just ask banks how many customer service calls they get when an open banking integration doesn’t work, or how quick Senator Warren is to send them a letter when a high-profile consumer problem relating to open banking is reported.

You have to find a way to deal with the pressure that agentic AI is going to put on your website. And, more fundamentally, you have to ensure — long term — that you aren’t making money by artificially imposing friction, cost, or information asymmetry on your customers. Because agentic AI will cut right through that shit.

I don’t think it’s an accident that Shopify — one of Amazon’s largest, most orthogonal competitors — has already integrated with Muse, while Amazon’s own sellers are finding ways to use AI to automate the company’s obtuse return reimbursement process.   

#2: B2B Banking Bundling … At Two Different Speeds

What happened?

Mercury launched an accounting product, embedded directly within its core banking app:

Mercury … launched Mercury Books, double-entry accounting software built directly into Mercury. Mercury Books uses AI to categorize and reconcile banking, card, invoicing, and bill pay activity the moment it happens, finally giving founders a real-time view of their business with no imports, exports, or manual entry required.

Most accounting software predates AI that can read a transaction and understand it, so the category was built to record activity rather than interpret it: a ledger you fill in, reconcile by hand, and hand off to an accountant to verify. Mercury Books treats a business's banking data and its books as one dataset, not two systems a person has to keep in sync.

Mercury Books pulls in activity from Mercury banking, cards, invoicing, and bill pay and automatically categorizes and reconciles it all as customers build their business. Customers can also connect to thousands of external platforms like Stripe, Gusto, and PayPal, for their full financial picture. Everything is categorized and reconciled using full double-entry accounting, supporting both accrual and cash basis.

And AmEx launched a high-yield savings account for businesses and is planning offerings around business checking rewards and payroll as well:

American Express announced the launch of the new high-yield American Express Business Savings account, designed to help businesses earn more on their deposits and manage more of their finances in one place. Later this year, the company will introduce a new way for Graphite Business Cash Unlimited Card Members to redeem Reward Dollars for deposits into their American Express Business Checking accounts, followed by a new payroll solution powered by Gusto with AI-powered insights coming early next year.

So what?

Well, if this doesn’t illustrate the differences between a 9-year-old company and a 176-year-old company, I’m not sure what does.

AmEx launched checking accounts for small businesses in 2021, following its acquisition of Kabbage. By itself, that seems a bit strange given that AmEx launched its first small business credit card in 1988 and officially became a bank in 2008. But whatever. It got a late start in small business banking. Fine.

But how could it take them FIVE YEARS to bolt a high-yield savings account onto that checking account? Did they not realize that small business owners might want a place to earn a little interest on their excess deposits? Do they not realize that this statement — lifted directly from the press release quoted above — was table stakes back in 2019, when Mercury launched it:

Business Checking and Business Savings will now come together under American Express Business Banking, creating a more connected banking experience for businesses. Customers can apply for Business Checking, Business Savings or both through one application and manage their banking alongside their American Express Card products online or in the Amex App.

You can apply for both in one application!

Why are we bragging about that? Why, realistically, are we even thinking of these products — checking and savings — as separate things, given that every small business would naturally want both and think of them more as a package deal?

Meanwhile, Mercury is launching its own embedded accounting product, which, from a scope perspective, puts it even further outside the reach of traditional B2B payments and banking providers like AmEx, and more into the realm of full-service B2B operating systems like Intuit QuickBooks.

These two companies — both banks — are building B2B banking bundles, but they are doing so at radically different speeds.

#3: Revolut Got Scammed

What happened?

Revolut has informed some of its customers that their data has been compromised:

A group operating under the name IAmNotAVillain [is] threatening to sell identity information and account balances and transaction histories, including crypto, of about 680 Revolut users.

So what?

As Jason Mikula’s excellent reporting illuminates, there are a couple of weird things about this incident.

First, it targeted crypto “whales”:

The users whose data were compromised appear to have been targeted because they are crypto “whales,” an industry term used for those who own significant amounts of cryptocurrencies. People known to hold large amounts of crypto have increasingly become targets of kidnapping, extortion, and other threats, owing at least in part to the perceived ease of stealing, moving, and laundering crypto vs. traditional bank deposits or other assets.

The person or group demanded a ransom of 6,000 XMR, a decentralized, privacy-focused cryptocurrency; 6,000 XMR equates to approximately $3,000,000.

IAmNotAVillain said that, if the ransom demand was not met, they would sell the data — potentially compromising the physical safety of the users — and warned “the blood will be on your hands.”

Second, the perpetrator didn’t hack Revolut. It hacked an Italian government email system and then used its access to that system to impersonate law enforcement and convince Revolut to hand over a ton of personal information about the victims:

Documents, screen captures, and a video shared by the hacker appear to indicate that they exploited an official Italian government email system to send forged legal requests to Revolut requesting users’ data.

The system, La Posta Elettronica Certificata (abbreviated PEC), is a secure email network overseen by the Italian government and used by government agencies, companies, and individuals to exchange official or legal correspondence. It is roughly the electronic equivalent of registered/certified mail.

The hacker appears to have then used forged European Investigation Orders, sent from the compromised Italian Ministry of the Interior email address, to request account and transaction information associated with the specified wallet addresses.

Make sure to read Jason’s entire newsletter from yesterday, as he goes into a great deal more detail. I just have a few quick thoughts to add in:

  • In banking, we draw a very hard line between fraud and scams. Fraud is when your account is compromised and the perpetrator initiates transactions that you did not authorize. Scams, by contrast, are when you are tricked into authorizing transactions that you should not have authorized. Generally speaking, we tend to treat fraud as a problem that the company that provided your compromised system or account is responsible for, while scams are treated as something you (the authorizing party) are responsible for. In this case, Revolut was scammed.

  • As Jason’s reporting details, Revolut should not have fallen for this scam. Normally, in Europe, these types of government requests are issued by a judge, court, investigating judge, or public prosecutor and executed by the government agency or office designated to handle such matters in the country where the financial institution is based (Lithuania, in the case of Revolut). In this case, the email address that the perpetrator sent the request from was not associated with a judge, court, or public prosecutor in Italy and it was not transmitted to Revolut through the General Prosecutor's Office of Lithuania. Whoops!

  • It’s absolutely awful that 680 people are now, potentially, in physical danger because they entrusted their crypto fortunes to Revolut. However, this is one of the fundamental tensions in crypto. Most people don’t want to manage their own self-custody wallets for buying, selling, and holding crypto. However, because the buying, selling, and holding of crypto is an inherently public activity (it’s recorded on the blockchain), it can be tracked by interested external parties, including people who are planning to illegally obtain access to government email systems and run impersonation scams. In this specific case, the perpetrator told FT that they used blockchain analytics to identify Revolut users with significant crypto holdings, so that they could specifically target those users in their scam messages to Revolut. Yikes!

  • Revolut recently got preliminary conditional approval to start a full-service national bank in the U.S. As I noted in this article, Revolut has had its share of problems over the years, including losing $23M to fraudsters and not noticing! This is obviously another black eye for the company, and it comes at an inauspicious time. Revolut still needs to get sign off from the FDIC and the Fed for its U.S. bank, and this incident won’t be helpful in that regard. This administration doesn’t love European companies to begin with and not falling for scams like this is exactly the kind of thing that regulators reasonably expect banks to do.


Sponsored by Brico

Charter, sponsor bank, or state licenses? Now that the OCC is answering the phone again, every fintech company with a payments or lending product has to pick.

But before you do, hear from someone who sat on the other side.

Donna Murphy, the OCC's former Deputy Comptroller for Compliance Risk Policy, has read the denial letters. She knows what examiners look for.

On September 22, Donna joins Snigdha Kumar, CEO of Brico, the compliance and licensing platform for regulated fintech companies, for a live conversation on what it takes to get a charter.

Free, 45 minutes, live Q&A.


2 READING RECOMMENDATIONS

#1: Winding Down Banks’ Free Money Machine (by Kiah Haslett, Fintech Takes Banking) 📚

Kiah’s series on deposits continues!

I’ve learned a lot about this side of banks’ business, and how it has changed over the last couple of years, by reading her coverage.

#2: Crypto Blew Its Big Moment—and the Blame Game Has Begun (Wall Street Journal) 📚

An interesting accounting of the aftermath of Clarity’s failure.

To be honest, I’m not sure how you can not assign at least a little of the blame to Coinbase and Brian Armstrong. It feels like they overplayed their hand significantly.

*Bonus: Stop Competing For Your Own Customer (by me, with Method) 📚

Most lenders pay to acquire a borrower, then pay again to reacquire that same borrower when their next need hits. Part of the problem is that bureau data lags a borrower's actual life by 22 days on average, so lenders often learn a borrower's situation has changed after the window to act has closed. Read how permissioned liability data changes the cross-sell math.

*This rec is brought to you by one of our fantastic brand partners.


1 QUESTION FROM FINITY

There are a TON of interesting questions being asked in Finity (our digital community for fintech and banking nerds). I’ll share one question, sourced from the community, each week. However, if you’d like to join the conversation, please apply to join!

What motivation does Amazon have to allow any agentic AI assistant/bot customer-permissioned access to its website?
I’ve heard some folks compare the predicted outcome here to what we saw in open banking, where JPMC relented once it got paid. However, the incentives in that case seem completely different. Amazon has A LOT of leverage and no mandate (legal or otherwise) to play nicely.

If you have any thoughts on this question, reply to this email or DM me in Finity!


Thanks for the read! Let me know what you thought by replying back to this email.

— Alex  

LinkedIn Twitter Instagram Podcast

@Alex Johnson

Unsubscribe
Community Logo