Participant Distribution Fraud in the “New Normal”

The Coronavirus pandemic, without a doubt, has changed the way we do business. It has also created some unanticipated vulnerabilities. For instance, since the start of the “new normal,” there has been an increase of cyberattacks on retirement plans and participant accounts through unauthorized distributions. How did this happen? In March of 2020, Congress passed the CARES Act legislation that increased access to retirement funds for those affected by the COVID-19 pandemic. At the same time, many employees started to work from home, many on personal devices and in unsecure environments. The heightened level of plan distributions together with the security risks associated with electronic communications and working remotely, may have created the perfect storm for exposure of participants’ confidential and personal data to cybercriminals. Why would these sophisticated criminals target retirement plans? To quote the famous bank robber, Willie Sutton, when asked why he robbed banks, “because that’s where the money is.” With $6.7 trillion of total assets in 401(k) plans, it seems that Willie would agree that it’s where the money is.

Participant distributions have become a particular focus for fraudsters. Retirement accounts typically have higher balances than checking or savings accounts and they also tend to be less monitored by the participant. Participants are typically encouraged NOT to change their investment selections too frequently, so many only view their statements on a quarterly basis. Though cases of distribution fraud were detected by the FBI as early as 2017, the instances of attacks against retirement accounts have skyrocketed during the pandemic. Additionally, retirement plans tend to have many service providers, like TPAs, recordkeepers, and financial advisors. Some even contract with an outside trustee or trust company to facilitate participant distributions. So, in the unfortunate case that a data breach or fraudulent distribution occurs, who is the responsible party? The answer is not as clear as one might think given that ERISA, the main body of law governing retirement plans, was passed into law in 1976, long before the use of the internet or electronic processing. So, with so many parties involved, the courts have many times indicated shared liability between the plan sponsor and other service providers.

 

How can the chance of cyberattacks be mitigated?

Monitor the Plan’s service providers

Some plan sponsors believe that the hiring of external experts like trust companies and other fiduciaries will protect them in the case of fraud. Under ERISA, the employer/plan sponsor has the fiduciary duty to not only protect participant data but to also select and monitor plan service providers. Service providers, like recordkeepers and trust companies, say they are constantly upgrading their cybersecurity systems, but plan sponsors should be asking questions about their cyber policies as well as improvements to their systems. Mid Atlantic Trust Company, which provides trust and custody services to over 125,000 retirement plans, has taken steps to guard against distribution fraud in its paying agent services, a solution that can be used by recordkeepers, TPAs or even directly by the plan sponsor to process participant distributions. Michele Coletti, who serves as Mid Atlantic’s Chief Operating Officer, states that when processing distributions, “Mid Atlantic includes several layers of review at pre-set release levels determined by the clients, as well as confirming distributions against an industry-leading fraud prevention service.” Additionally, Mid Atlantic looks for distribution red flags in its processes, such as transfers to newly opened bank accounts or funds being transferred to accounts where the registrations don’t match.

Transmit all plan data securely

Although it may take a few more clicks and the creation of another password protected account, plan sponsors and participants should always use a secure portal or encrypted email to send personally identifiable information (PII). That means not using company or personal email to send census information, distribution forms or other communications containing PII in an unsecure fashion.

Learn, learn, learn

Like most things involving cybersecurity, education is key. Educating staff members and participants about phishing emails and click bait schemes that are used to trick the recipient into revealing personal information is a highly effective way to stop fraud. Fraudsters use catchy subject lines like “Approve Changes to your 401(k) Account” or “Click here to update your information” to get participants to reveal information to them. This type of education isn’t once and done but should be repeated on at least an annual basis and as part of employee orientation.

Establish online access

Though it may sound counter intuitive, encourage all participants to set up their online account access and check them regularly even if they prefer to receive paper statements. Unclaimed online accounts are easier for hackers to access and take control. Participants should also choose strong passwords and set up multifactor authentication (MFA) which sends codes to multiple devices to verify the account holder’s identity. Avoiding the use of public Wi-Fi to access retirement accounts greatly decreases the potential of being hacked.

Good policies and procedures go a long way

It’s important to note that not all fraud will be electronic. There are reported cases where fraudsters have used fax, phone and even paper documents by mail to perpetrate distribution fraud. Plan sponsors should follow strict procedures, and ensure that their service providers do as well, to reduce the chance of a fraudulent withdrawal from a participant’s account.

Will retirement accounts ever be 100% secure? Though we may wish so, account theft will continue to evolve as fraudsters find ways of mining personal information whether it be from social media sites, like LinkedIn and Facebook, or by hacking email accounts or passwords. Maintaining good administrative practices as a participant or plan sponsor and selecting service providers who remain vigilant in upgrading their cyber security systems will be key to protecting plan data and assets from cyberattacks.

 

©2021 Benefit Insights, LLC All rights reserved.

This newsletter is intended to provide general information on matters of interest in the area of qualified retirement plans and is distributed with the understanding that the publisher and distributor are not rendering legal, tax or other professional advice. Readers should not act or rely on any information in this newsletter without first seeking the advice of an independent tax advisor such as an attorney or CPA.

We’re leaders in retirement plan administration.
How can we help you get where you want to go?

Serving Clients for 40 Years

Spring will arrive soon, promising new growth and a fresh beginning. It could also be the perfect time to do some spring cleaning for your plan. Let’s look at some areas that you might consider reviewing to ensure your retirement plan is operating efficiently.

Document your processes and procedures to make certain that plan tasks can be handled in case of any absences during an enrollment or pay period. Having a backup in place can prevent errors and delays that could lead to penalties.

Make sure to have a process in place to notify all new enrollments of their eligibility, regardless of whether the plan has automatic enrollment. Depending on the timing for plan entry, including the plan enrollment paperwork with the new hire paperwork could make entry easier for you. Please reach out with any questions regarding when an employee enters the plan.

Deposits of employee deferrals and loan repayments must be submitted to the plan as soon as possible to avoid penalties and corrections. For plans with less than 100 participants, a safe harbor rule allows deposits to be made within seven business days. For larger plans, the expectation is that the money will be deposited more quickly. Depositing these funds on the pay date will avoid the possibility of being late.

Monitoring deferral contribution limits during the calendar year will avoid refunds after year end. Make sure that your payroll is set up to stop deferrals once the limit is reached, including any catch-up contributions for those who have reached age 50.

To keep the plan in compliance, employer contributions must be deposited timely. Due dates are impacted by the type of contributions, required status and tax deductibility. If you have questions on when to deposit your employer contribution or even whether to make an employer contribution, please contact us.

Most plans must be covered by a fidelity bond. The minimum coverage is 10% of plan assets (rounded up to the next $1,000) and the maximum coverage is $500,000. Additional requirements apply to plans with employer securities or non-publicly traded assets. If your fidelity bond is insufficient, now is the time to raise the coverage. Inflation clauses that increase the bond amount as the plan assets increase can ensure that your bond coverage is always adequate. Contact us or your insurance provider if you don’t have a fidelity bond.

Another area to review is communication with participants. Helping your employees understand and trust the plan can increase their contributions. Be sure that your procedures include distributing any plan-related communications—including required participant notices.

Distributions also involve communication, including some of the aforementioned notices. Discussing distribution options with terminated participants, possibly as part of an exit interview, can help to reduce risk of lost participants. We’ll provide instruction on distributions for force-out distributions for small balances, testing corrections and required minimum distributions.

Your plan document is the legal source on how the plan should be administered; operating within its parameters is critical. It’s always worth taking time to review the plan document to ensure that you fully understand and are following its provisions. We’ll cover more details about the plan document later in this newsletter. We’re here to support you in keeping your plan in compliance. Please feel free to reach out with any questions.

Addressing the Challenge of Uncashed Distribution Checks

Uncashed distribution checks present a persistent and often overlooked challenge for retirement plan sponsors. Despite the best efforts of plan administrators, some participants fail to cash their distribution checks, leading to administrative burdens, fiduciary concerns and potential compliance issues. A recent publication by Retirement Management Services (RMS) sheds light on this issue and offers practical guidance for employers seeking to manage and mitigate the risks associated with uncashed checks.

Uncashed checks can arise for various reasons. Participants may have moved without updating their contact information, may not recognize the check as legitimate or may simply forget to deposit it. Regardless of the cause, the responsibility for addressing these uncashed funds ultimately falls on the plan sponsor. This creates a fiduciary obligation to act in the best interest of the participant while ensuring compliance with IRS and Department of Labor (DOL) regulations.

Sponsors are encouraged to maintain up-to-date contact information for all plan participants and to follow up promptly when checks remain uncashed. This may involve sending reminder letters, making phone calls or using certified mail to confirm receipt. In some cases, plan sponsors may also consider using electronic payment methods to reduce the likelihood of checks going uncashed in the first place.

The IRS and DOL have issued guidance on how to handle these situations, including the use of forfeiture accounts and escheatment to state unclaimed property programs. However, these options come with their own set of rules and potential pitfalls. For example, using a forfeiture account may require the plan document to explicitly allow for such treatment. Escheatment laws, which allow the government to assume control of unclaimed property, vary by state. As such, plan sponsors must carefully evaluate their options and consult with legal or compliance experts as needed.

Another important consideration is the documentation of all the efforts made to contact participants and resolve uncashed checks. Maintaining a clear audit trail can help demonstrate fiduciary prudence and protect the plan sponsor in the event of an audit or legal challenge. It is extremely important to have a written policy in place that outlines the steps to be taken when a check remains uncashed beyond a certain period.

By taking a proactive, well-documented and compliant approach, employers can fulfill their fiduciary duties, reduce administrative burdens and ensure that participants receive the benefits they are entitled to.

Source: Retirement Management Services – “Uncashed Distribution Checks” https://www.consultrms.com/Resources/59/Plan-Sponsor-Tips-and-Help/212/Uncashed-Distribution-Checks

Divorce and the Retirement Plan

When a participant in a qualified retirement plan undergoes a divorce, the participant’s account balance may be an asset that is split with the former spouse. As the plan exists for the exclusive benefit of its participants, a court order is required to transfer the participant’s benefits to the ex-spouse. Once approved by the plan administrator, this court order is called a Qualified Domestic Relations Order (QDRO).

The QDRO is a judgment, decree or order that must be issued by a state authority (usually a court). It can be part of the divorce settlement or it may be a separate document. Because of the serious nature of separating the participant’s account balance, the QDRO is more than just an agreement made by both parties — it must also be signed by a judge.

A QDRO will describe how to divide the participant’s account balance between the participant and the ex-spouse, referred to as the alternate payee. In some cases, a set dollar amount will be allocated; in others, a percentage of the account may be designated. In the latter case, the amount assigned to the alternate payee represents the given percentage of the participant’s total vested account balance as of a specified valuation date. This percentage will apply to all sources — such as deferrals, matching or profit sharing — unless specified by the QDRO. Any interest and investment gains/losses that accrue between this valuation date and the date the funds are separated into an account for the alternate payee are often factored into this final calculation. If the participant has outstanding loans, the QDRO will usually indicate how the loans are handled.

Contributions such as deferrals and employer matching made after the valuation date are credited to the participant’s account. Earnings and losses are applied to the account balances. Once the division is complete, the alternate payee’s portion (either dollars or shares) is transferred to an account in the alternate payee’s name.

If the plan allows, the alternate payee may be paid out in a cash or rollover distribution. Not all plan documents allow the alternate payee to receive a distribution before reaching normal retirement age, so it’s important to follow the terms of the plan. In addition, the QDRO cannot violate the provisions of the plan document by requiring a plan to provide an alternate payee or participant with any type or form of benefit not otherwise provided under the plan.

Although the most common situation for a QDRO is a divorce, it can be issued in other situations, such as to a dependent in the case of child support. If the alternate payee is a minor child or legally incompetent, the order can also require payment to the individual with legal responsibility for the alternate payee. If a participant or their attorney provides you with a copy of a divorce decree that references the plan or a QDRO, please contact us immediately, and we will work with you to ensure it meets the requirements of the plan.

Important note for defined benefit plans: For 2025 plan years, PBGC premiums are due one month earlier than usual, specifically on the 15th day of the ninth month after the beginning of the plan year. For calendar year plans, this means the premium is due on September 15, 2025, instead of the usual October 15. This accelerated deadline is due to a provision in the Bipartisan Budget Act of 2015.

Upcoming Compliance Deadlines for Calendar-Year Plans

 

Top of Page

© 2025 Benefit Insights, LLC. All Rights Reserved.

© 2026 Red Bank Pension Services. All rights reserved. Website by GSM Marketing