What's documented
Pindrop was founded in Atlanta in 2011 by Vijay Balasubramaniyan, Paul Judge, and Mustaque Ahamad, all Georgia Tech PhDs — Balasubramaniyan first built the anti-fraud system as a student working with Ahamad and professor Patrick Traynor. The company raised roughly $235 million in venture capital through its last priced equity round — a $90 million Series D in December 2018 that valued it at $925 million — and added a $100 million debt facility from Hercules Capital in July 2024 to fund expansion into AI-deepfake detection. No newer equity round or updated valuation has been made public since. By its own account, Pindrop's technology now runs inside call centers at seven of the top ten U.S. banks, along with insurers and healthcare providers, "handling billions of high-risk interactions annually."
Pindrop doesn't work with one company at a time in isolation. It operates what it calls the Pindrop Intelligence Network, described in its own materials as the largest fraudster consortium in the U.S. — built from more than 5 billion monitored calls and containing over 2.5 million known fraudster phone numbers, available to every Pindrop customer. In practice, that means a fraud signal detected on a call to one bank can follow a caller to a different bank, insurer, or healthcare company that also uses Pindrop. Nothing in Pindrop's public materials describes a caller being told which company first flagged them, or why. (What moves through that shared network, by every public description Pindrop has given of it, is fraud signals and phone numbers — not a caller's raw voice recording itself.)
Pindrop's own published terms state how long it keeps what it extracts from your voice: "voice features" — the company's term for the data points it pulls from call audio — "are retained by Pindrop for up to three (3) years and deleted thereafter." Pindrop's language draws a distinction between that and a "voiceprint," which it says it does not itself retain. The three-year figure has a real carve-out, too: when a bank or other client runs Pindrop's software on its own servers rather than Pindrop's, that data "may be retained on the customer's premises for varying periods of time, depending on the customer" — no fixed limit at all. And if you want to stop it: Pindrop's privacy policy tells you to take the complaint to the bank, not to Pindrop. "Our customer's privacy policy... will dictate the scope and manner of processing, not this Policy," it states, and directs consumer inquiries about voice data "to the customer organization" — the company you actually called. There is no consumer-facing way to opt out of Pindrop's voice analysis directly.
Since at least 2019, according to court filings in the case, John Hancock routed calls about customers' retirement accounts through Amazon's Connect call-center platform, which used Pindrop's technology to analyze each caller's voice and authenticate their identity. Callers were told they no longer needed a PIN — their voice alone was enough to confirm who they were.
Government agencies use Pindrop's fraud-screening tools too. In April 2025, the Social Security Administration installed a new anti-fraud check on phone claims, using Pindrop alongside TransUnion, as part of a policy shift pushed by the Department of Government Efficiency, then headed by Elon Musk. The result, according to an internal SSA document from that May: out of more than 110,000 claims screened, only two were found to have a "high probability" of being fraudulent — no confirmed fraud among them. Flagged claims were held for three days while the check ran, which the same internal document said slowed retirement-claim processing by 25% and caused a "degradation of public service," delaying payments "despite an extremely low risk of fraud." SSA later narrowed the tool to retirement, survivor, and auxiliary claims only, pulling disability claims out of the screening after internal pushback — reporting on the decision didn't specify exactly what that pushback was. Whether the tool is still running at SSA in its original form as of this writing isn't confirmed by any source more recent than that May 2025 reporting. Separately, Virginia's state unemployment agency deployed Pindrop's fraud-detection product in April 2024 across both its automated phone system and its live agents, after finding its prior identity-check process let more than half of fraudulent callers through, according to Pindrop's own case study on the deployment.
Separately, in Bank of the West's customer support line, plaintiff Diana Packbiers alleged Pindrop examined her voice and voice print without her consent — not only to confirm her identity, but, in the words of her own complaint, to "determine the truth or falsity of her statements" — language that tracks the exact wording of the California statute she sued under, not necessarily a factual description of what the software does. That statutory phrase happens to be the same one California law uses for voice-stress analysis, a category of technology with a genuinely bad scientific track record: federally sponsored research has found "little or no scientific evidence" that voice-stress analysis reliably detects lying, controlled studies put its accuracy near chance, and courts have rejected voice-stress-analyzer results as unreliable evidence since the early 2000s. That research is about the category of technology generally, not a specific finding about Pindrop's own product, and this piece isn't claiming otherwise.
Two lawsuits, one very different outcome
Both suits accused Pindrop of collecting and analyzing voiceprints without the written consent Illinois and California privacy law require. They ended up in very different places.
McGoveran v. Amazon Web Services started in Illinois state court in 2019, brought by customers who'd called John Hancock and had their voices authenticated through Amazon Connect and Pindrop. It took seven years and multiple courts to resolve. A federal court in Illinois dismissed it in 2020 for lack of personal jurisdiction over Amazon; refiled in Delaware, a 2021 ruling dismissed it again, on the theory that the actual data collection happened outside Illinois; an amended complaint followed, and in 2023 the Delaware court sided with Pindrop entirely, ruling it qualified for BIPA's financial-institution exemption — while letting a narrower claim against Amazon continue. By 2024 that remaining claim against Amazon was gone too, on summary judgment. On May 12, 2026, the Third Circuit Court of Appeals affirmed all of it, in a precedential opinion (No. 24-3215, written by Judge Porter).
The core of the ruling: Illinois's biometric privacy law exempts "financial institutions," and it borrows that term's definition from the federal Gramm-Leach-Bliley Act. Federal Reserve regulations classify authenticating people's identity for financial transactions as a "financial activity." The plaintiffs themselves had alleged that Pindrop authenticated John Hancock customers — which was, legally, enough to make Pindrop's own conduct a financial activity, and Pindrop itself a financial institution, exempt from BIPA on its own terms. The court separately found the underlying data collection happened mostly outside Illinois anyway — Amazon's servers were in Virginia, Pindrop processed the calls from Georgia, and reports went to a Massachusetts company — giving it a second, independent reason to end the case.
The exemption doesn't just excuse Pindrop from the consent-and-disclosure rules BIPA is best known for. It also excuses this specific work from a real deadline the law otherwise sets: BIPA requires any company it covers to destroy someone's biometric data within three years of that person's last interaction with the company, or sooner if the original purpose for collecting it has already been met, whichever comes first. For a bank-authentication vendor ruled exempt from BIPA altogether, that clock simply doesn't apply.
That exemption isn't a gap in the law — it's built into the statute's own design. BIPA exempts "a financial institution that is subject to Title V of the federal Gramm-Leach-Bliley Act," meaning the law assumes GLBA's own privacy framework picks up where BIPA leaves off. On paper, it does something: GLBA's Privacy Rule and Safeguards Rule require covered companies to give privacy notices and run a data-security program, and the FTC's version of the Safeguards Rule reaches a broad set of businesses "significantly engaged" in financial activities — a voice-authentication vendor for banks plausibly among them. What it doesn't do is give an individual caller any way to enforce it. Federal courts have held flatly that GLBA carries no private right of action — "no private right of action exists for an alleged violation of the GLBA," the Eighth Circuit wrote in Dunmire v. Morgan Stanley DW, Inc., 475 F.3d 956, 960 (2007), a holding other courts have repeated since. Enforcement is up to the FTC, the CFPB, and banking regulators alone. So the actual trade isn't one privacy law for a comparable one. BIPA let Packbiers and the McGoveran plaintiffs sue directly, for $1,000 to $5,000 a violation. The law that exempts Pindrop's bank work from BIPA gives an individual caller nothing to sue with at all.
Pindrop's own chief legal officer, Clarissa Cerda, has defended exactly this arrangement on the record: "Pindrop operates under GLBA's comprehensive privacy and security standards — the same standards our financial institution customers are bound by," she said after the ruling. "For the compliance and legal teams at financial institutions making infrastructure decisions, that alignment is not incidental. That is the point." Whether GLBA's regulator-only enforcement model actually delivers comparable protection to BIPA's private right of action is the specific question this piece has just laid out — Cerda's position is that it does; the case law on who can enforce it says an individual caller can't test that claim in court either way.
How far the exemption actually reaches is genuinely unsettled — and it may reach further than "banking" implies. The specific federal rule the court relied on doesn't say "financial transactions." It says authenticating identity for "financial and nonfinancial transactions" both count as the same protected activity. The court didn't have to test that second half, because John Hancock's retirement-account calls were financial transactions on their face — an easy case. Whether the same exemption would cover Pindrop authenticating an Illinois resident's identity on a call to the Social Security Administration, or a healthcare provider, is an open question nobody has litigated. The rule's own text leaves real room for either answer. Pindrop markets the same voice-authentication technology to insurers, healthcare providers, and — as the SSA deployment shows — government agencies. If a future court reads "nonfinancial transactions" the way it's written, none of that work would need BIPA's consent rules at all. If a future court instead confines the exemption to genuinely financial transactions, all of it would remain fully covered, with BIPA's private right of action intact. No case has decided which. That's not a documented gap or a documented protection — it's an open question this ruling created and did not answer.
Packbiers v. Pindrop Security took a narrower legal shot: not BIPA, but California's wiretapping-and-privacy law, the California Invasion of Privacy Act. Packbiers alleged Pindrop examined her voice and voice print — without consent — when she called Bank of the West, seeking $1,000 for every violation of Penal Code §637.3 on behalf of a class of California residents whose voices had been recorded or examined by Pindrop the same way. Bank of the West had roughly 1.8 million customers at the time.
The case then took an unusual procedural turn. Filed in San Bernardino Superior Court in June 2022 and removed to federal court in Los Angeles that August, Packbiers voluntarily dismissed it herself just 18 days later — and the same day, refiled an identical suit against Pindrop in a different federal court, the Northern District of California, before Judge Haywood Gilliam. That second case did not produce the same kind of appellate rule. On March 1, 2023, Judge Gilliam approved a stipulated dismissal: Packbiers' individual claims were dismissed with prejudice, each side bore its own fees and costs, and absent putative class members were not affected. So the case did not simply vanish — it moved courts, then ended for the named plaintiff without resolving the broader class theory in a public merits ruling.
What this piece is not saying
This isn't saying Pindrop's SSA deployment caught nothing real — the two flagged claims may well have been genuine fraud attempts. The point is narrower: a system that held up 110,000-plus legitimate claims to catch two, at a documented 25% processing cost, is a real tradeoff worth naming, not evidence the whole idea of phone fraud screening is fake.
This isn't saying the Third Circuit got the law wrong, or that Pindrop broke any rule. On the one case that reached a full appellate ruling on the merits, the court sided with Pindrop twice over — the exemption, and the geography. That's the actual, current state of federal law on this question, not a contested claim.
This isn't saying Packbiers lost on the merits, either. Her individual claims were dismissed with prejudice by stipulation; the public order does not resolve whether Pindrop's alleged use of voice analysis violated California law for any broader class.
This also isn't accusing any named SSA or Pindrop employee of misconduct. It's about what a system did, and what a court ruled — not what anyone specifically intended.
This isn't claiming Pindrop's specific product functions as literal lie-detection. The scientific critique of voice-stress analysis cited above is about that category of technology generally — no independent technical audit of Pindrop's own product was found for this piece.
This isn't claiming Pindrop's healthcare or government-agency work has violated BIPA, or that it's definitely exempt either. Both are genuinely open questions under the same rule the McGoveran court used — this piece lays out why, not a settled answer either direction.
What can I do
If you're in Illinois: BIPA still protects you against any company doing this kind of voice analysis that isn't covered by the financial-institution exemption McGoveran just confirmed. You can sue directly — no need to prove actual harm happened — for $1,000 per negligent violation or $5,000 per intentional/reckless one, with a five-year window to file. One caveat: a 2024 amendment caps recovery at one damages award per person per collection method, not a separate award for every individual scan — so the total isn't as simple as multiplying every call by $1,000 or $5,000.
If you're in California: the same idea, a different statute. Penal Code §637.3 — the provision Packbiers herself invoked — allows $1,000 per violation when someone uses an electronic system to examine or record a voice print or voice-stress pattern to determine the truth or falsity of a person's statements without that person's advance express written consent. California has separate all-party consent rules for recording confidential communications, but the Packbiers theory was the narrower voice-analysis claim.
On any call, in any state, right now: ask directly for a non-biometric way to verify your identity — a PIN, a one-time text code, an app confirmation. If the representative says no or can't offer one, write down what they said and when. That refusal is itself worth having on record.
If this is about Social Security specifically: congressional casework is a real, live channel — SSA policy allows it to share information with a congressional office at a beneficiary's own request, and a caseworker can push on a specific claim in a way an individual calling the 1-800 line generally can't. One real limit: the SSA staff who support that congressional-casework channel were reportedly cut sharply during 2025 workforce reductions — the channel still exists, but it may move slower than it used to.
Know the limit, going forward: as of May 12, 2026, a federal appeals court has held that if a company's voice-authentication work supports a financial transaction, it can count as a "financial institution" exempt from Illinois's law entirely — regardless of whether you consented. Don't assume BIPA automatically covers every voice-biometric vendor your bank or insurer uses; check what the company actually does before counting on the law that's supposed to protect you. And don't assume the reverse, either — the exact rule involved covers authenticating identity for "financial and nonfinancial transactions" alike, so whether a call to a government agency, hospital, or insurer gets the same exemption is untested. If a voice biometric vendor analyzed your voice on a non-bank call, that's not automatically covered by BIPA — but it's not automatically exempt from it either.
The Receipts
- McGoveran v. Amazon Web Services, Inc., No. 24-3215 (3d Cir. May 12, 2026) — the Third Circuit's own opinion
- Third Circuit affirms dismissal of BIPA claims against Amazon and Pindrop — ABA Banking Journal
- Pindrop biometric authentication exempt from BIPA as core financial infrastructure — Biometric Update
- Navigating the Financial-Institution Exemption under the Illinois Biometric Information Privacy Act — Dorsey client alert
- Packbiers v. Pindrop Security, Inc. — Notice of Removal, Case No. 5:22-cv-01427 (C.D. Cal.) — quotes the Complaint's allegations and CIPA claim directly
- Packbiers v. Pindrop Security, Inc. — Order Granting Stipulated Dismissal, Case No. 4:22-cv-04926 (N.D. Cal.) — dismisses Packbiers' individual claims with prejudice and leaves absent putative class members unaffected
- California Penal Code §637.3 — voice print / voice-stress analysis consent provision
- Pindrop Security, Inc. — ClassAction.org lawsuit news — original filing coverage
- DOGE went looking for phone fraud at SSA — and found almost none — Nextgov/FCW
- Social Security Faces Blowback As Fraud Detection Flags Just 2 Claims — While Retirement Backlog Nears 600,000 — Yahoo Finance
- DOGE went looking for phone fraud at SSA — and found almost none — Government Executive, May 2025
- Company profile: Pindrop Security — Georgia Tech
- Restoring Trust in Real-Time Communications — Pindrop's own company page (self-reported figures, cited as such)
- Pindrop Brings Real-Time Fraud Intelligence to FICO Marketplace as AI Scams Surge — Pindrop's own press release, on the Intelligence Network/Consortium's scale (5B+ monitored calls, 2.5M known fraudster ANIs, available to all Pindrop customers)
- Avoiding Liability Under the Illinois Biometric Information Privacy Act — Quinn Emanuel, quoting 740 ILCS 14/15(a) directly on the 3-year destruction requirement
- McGoveran v. Amazon Web Services, Inc., No. 24-3215 (3d Cir. May 12, 2026), slip op. at 5-6 — the opinion's own language quoting BIPA's exemption text, "a financial institution that is subject to Title V of the federal Gramm-Leach-Bliley Act" (740 ILCS 14/25(c)), read directly page-by-page, not summarized secondhand
- Dunmire v. Morgan Stanley DW, Inc., 475 F.3d 956, 960 (8th Cir. 2007) — "no private right of action exists for an alleged violation of the GLBA"
- Whoa, My Business is a "Financial Institution" under the FTC's Safeguards Rule? Now What? — Spencer Fane, on the Safeguards Rule's broad reach to businesses "significantly engaged" in financial activities
- Pindrop Solutions — legal/data-handling terms — Pindrop's own stated retention period for "voice features" (up to 3 years), the self-hosted-deployment carve-out, and the language directing consumer inquiries about voice data "to the customer organization," not Pindrop
- Pindrop Privacy Policy — states "our customer's privacy policy... will dictate the scope and manner of processing, not this Policy"
- Third Circuit Rules It Official: Pindrop Qualifies as a Financial Institution Under the Illinois Biometric Privacy Act — Biometric Update, Aug. 20, 2026, source of Chief Legal Officer Clarissa Cerda's on-record quote
- Study Casts Doubt On Accuracy Of Voice Stress Analysis Lie Detection — ScienceDaily, summarizing federally sponsored research on voice-stress-analysis reliability
- Virginia Employment Commission Reduced Fraud Within Months — Pindrop's own case study on its VEC deployment (vendor-authored figures, cited as such)



