{"id":283692,"date":"2025-11-10T18:16:07","date_gmt":"2025-11-10T18:16:07","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/283692\/"},"modified":"2025-11-10T18:16:07","modified_gmt":"2025-11-10T18:16:07","slug":"schwab-joins-fidelity-in-credential-sharing-crackdown-pontera-escalates-fidelity-blame","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/283692\/","title":{"rendered":"Schwab joins Fidelity in credential-sharing crackdown; Pontera escalates Fidelity blame"},"content":{"rendered":"<p>\n                As Schwab forces clients to reset credentials to curb third-party access, the 401(k) fintech Pontera maintains &#8220;Fidelity stands alone in its decision to lock out thousands of consumers from their own accounts.&#8221;\n            <\/p>\n<p style=\"line-height:1.656\">Schwab has asked clients to reset their login credentials, a request coming shortly after Fidelity took similar action to limit third-party vendor access to 401(k) and other customer accounts.<\/p>\n<p>Like Fidelity, Schwab has cited protecting client data in their attempts to limit credential sharing of a client\u2019s username and password. Third party fintech firms such as Pontera have adopted credential-sharing technology to connect selected outside advisors with held-away assets such as\u00a0 401(k) accounts from retirement plan providers.<\/p>\n<p>\u201cAs part of our security processes, we determined that some clients provided login access to third-party data vendors which may void policies we have in place to protect clients through our Schwab security guarantee,\u201d a <a href=\"https:\/\/www.investmentnews.com\/companies\/charles-schwab\/257314\" rel=\"nofollow noopener\" target=\"_blank\">Charles Schwab <\/a>spokesperson said Thursday, according to<a href=\"https:\/\/citywire.com\/ria\/news\/schwab-asked-clients-to-reset-login-credentials-citing-data-security\/a2477885\" rel=\"nofollow noopener\" target=\"_blank\"> Citywire<\/a>. \u201cAs part of our data security policy, we required these clients to update their account information.\u201d<\/p>\n<p>Anticompetitive assertions<br \/>&#13;<br \/>\n\u00a0<\/p>\n<p>Pontera previously described Fidelity\u2019s actions as &#8220;anticompetitive&#8221; in a campaign last month that included coverage in <a href=\"https:\/\/www.nytimes.com\/2025\/10\/10\/your-money\/401-k-fintech-advisers-fidelity.html\" rel=\"nofollow noopener\" target=\"_blank\">the New York Times<\/a>. In a statement to InvestmentNews on Friday following Citywire\u2019s reporting on Schwab, a spokesperson for Pontera maintained that \u201cFidelity stands alone\u201d in its reaction to clamping down on credential sharing.\u00a0<\/p>\n<p>\u201cFidelity stands alone in its decision to lock out thousands of consumers from their own accounts. We should all care about protecting consumers \u2013 this is why Pontera took a public stance against Fidelity locking consumers out of their accounts, which actually created risk for consumers by eliminating their digital access to their own money,\u201d a Pontera spokesperson told InvestmentNews on Friday.\u00a0<\/p>\n<p>Platforms like Pontera \u201cuse &#8216;screen scraping&#8217; technology that gives them access to a lot more client information than what&#8217;s needed for the tool to perform its function,\u201d Ben Henry-Moreland, a certified financial planner with <a href=\"http:\/\/kitces.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Kitces.com<\/a>, explained to\u00a0InvestmentNews.<\/p>\n<p>Moreland warned that third-party vendors can potentially collect and monetize client data by selling it to other parties without the client\u2019s permission. He added it is problematic for Schwab and Fidelity\u2019s approach to not distinguish between &#8220;tools that have a legitimate purpose and strong data protection policies with the potential bad actors,\u201d Moreland said.<\/p>\n<p>&#8220;Shaky account connections and frequent re-logins have long been part of screen-scraping tools, which has accelerated the push towards API connections in recent years,\u201d Moreland said. &#8220;Hence it&#8217;s frustrating that Fidelity, if reporting is true, hasn&#8217;t worked with Pontera to establish an API connection.&#8221;<\/p>\n<p>Last month, Pontera\u2019s CEO <a href=\"https:\/\/www.investmentnews.com\/retirement-planning\/pontera-cries-anti-competitive-fidelity-cites-cyber-safety-in-credential-sharing-showdown\/262572\" rel=\"nofollow noopener\" target=\"_blank\">Yoav Zurel told InvestmentNews <\/a>that his company supplied API-based integrations with 401GO, which markets itself as a \u201ctech-forward 401(k) retirement plan provider.\u201d\u00a0<\/p>\n<p>&#8220;<a href=\"https:\/\/www.investmentnews.com\/retirement-planning\/pontera-deepens-advice-access-in-401k-plans-with-401go\/257259\" rel=\"nofollow noopener\" target=\"_blank\">We have a partnership with 401GO<\/a>, which is a much smaller competitor to Fidelity. That entire partnership is all API-based,&#8221; Zurel said. &#8220;If Fidelity wants to do that, we&#8217;re open to it &#8230; It&#8217;s really up to them. [But] they&#8217;re not answering our phone calls [or suggestions for] different solutions that we&#8217;ve provided them.&#8221;<\/p>\n<p>A spokesperson for Fidelity <a href=\"https:\/\/www.investmentnews.com\/retirement-planning\/pontera-cries-anti-competitive-fidelity-cites-cyber-safety-in-credential-sharing-showdown\/262572\" rel=\"nofollow noopener\" target=\"_blank\">said last month<\/a> that\u00a0Pontera&#8217;s claim of anticompetitive behavior lacks merit. The spokesperson added that Fidelity works &#8220;closely to support many RIAs who securely advise on employer-sponsored retirement accounts with plan sponsor oversight.&#8221; A person close to the matter confirmed Fidelity has met with Pontera multiple times, and that,\u00a0&#8220;we can confirm that the fintechs created their business models and service offerings without consulting with Fidelity,&#8221; said the spokesperson.\u00a0<\/p>\n<p>Andrew Herzog, an advisor with Texas-based RIA The Watchman Group, says Schwab and Fidelity are right to prioritize protecting their customers&#8217; data above third-party convenience. His RIA has not been impacted by Schwab and Fidelity\u2019s recent moves to restrict third-party access.<\/p>\n<p>Safeguarding client data<br \/>&#13;<br \/>\n\u00a0<\/p>\n<p>&#8220;Third-party services are convenient &#8211; I use them myself. However, when those connections break my financial life is not upended. I care more about safeguarding my data\/credentials than ease-of-use,\u201d Herzog said. &#8220;This has not affected our firm, since we jump on video calls with clients to rebalance\/evaluate their employer-sponsored retirement accounts.\u201d<\/p>\n<p>Absolute Capital Management works similarly to Pontera, as both provide outside advisors with access to their client\u2019s 401(k) and other retirement assets. However, Absolute Capital is an SEC-registered RIA so it is regulated differently than fintechs like Pontera.<\/p>\n<p>\u201cI thought how Fidelity handled it was appropriate and balanced. They were doing the job they were hired to do by the plan sponsor,\u201d <a href=\"https:\/\/www.investmentnews.com\/retirement-planning\/absolute-capital-pontera-401k\/262777\" rel=\"nofollow noopener\" target=\"_blank\">Absolute Capital CEO Brenden Gebben<\/a> told\u00a0InvestmentNews at this week\u2019s Schwab IMPACT conference in Denver. \u201cThere&#8217;s this notion going around the industry that say Fidelity or these custodians are doing it for their own greedy purposes, somehow they&#8217;re making more money out of the deal. And that&#8217;s just a false narrative because what these custodians are doing is enforcing the rules of the plan.\u201d<\/p>\n<p>About 350 advisor firms are utilizing Absolute Capital, Gebben said. He added that Absolute Capital can connect with about 55% of all 401(k) participants nationwide, and the remaining 45% are retirement plans with documented mandates to not allow third-party access.<\/p>\n<p>Lori Weston, head of compliance at STP Investment Services, stresses advisors must prioritize \u201congoing cyber risk assessments\u201d of third-party vendors that access client information.<\/p>\n<p>\u201cConducting ongoing due diligence on third-party vendors is essential to protecting sensitive client information,\u201d Weston said. \u201cWhile advisers often focus on their OMS and CRM systems, intermediary credential-sharing platforms that use actual client login credentials can pose even greater risks \u2014 enabling potential impersonation of account holders themselves and all permissions that go with account holder access.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"As Schwab forces clients to reset credentials to curb third-party access, the 401(k) fintech Pontera maintains &#8220;Fidelity stands&hellip;\n","protected":false},"author":2,"featured_media":283693,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[39],"tags":[28,147,530],"class_list":{"0":"post-283692","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-personal-finance","8":"tag-business","9":"tag-personal-finance","10":"tag-personalfinance"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/283692","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=283692"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/283692\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/283693"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=283692"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=283692"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=283692"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}