---
title: HB 1034. Georgia Tech Support Impersonation and Remote Access Protection Act; enact
collection: bills
id: 2025-2026/hb1034
cite_as: HB 1034, 2025-2026 Regular Session (Ga.)
canonical_url: https://georgiacommons.org/bills/2025-2026/hb1034
md_url: https://georgiacommons.org/bills/2025-2026/hb1034.md
text_url: https://georgiacommons.org/bills/2025-2026/hb1034/text
source_url: https://www.legis.ga.gov/legislation/72364
date: 2026-01-29
status: introduced
corpus_version: bills-2026-09-13
license: Public record of the Georgia General Assembly, via LegiScan; see about.md
publisher: Georgia Commons, an independent project of Georgia Civic Data. Not the State of Georgia. Not legal advice.
up: https://georgiacommons.org/bills/2025-2026.md
previous: https://georgiacommons.org/bills/2025-2026/hb1033.md
next: https://georgiacommons.org/bills/2025-2026/hb1035.md
index: https://georgiacommons.org/bills/index.md
omitted: votes and history
omitted_chars: 129
omitted_url: https://georgiacommons.org/bills/2025-2026/hb1034.md?full=1
bill_number: HB 1034
session: 2025-2026 Regular Session
session_slug: 2025-2026
chamber: House
bill_type: bill
status_date: 2026-01-27
last_action: House Second Readers
sponsors:
  - Sandra Scott
  - Kim Schofield
  - Viola Davis
text_version: Introduced
has_text: true
legiscan_url: https://legiscan.com/GA/bill/HB1034/2025
upstream_id: 2095282
summaries_model: claude-sonnet-5
topic_tags:
  - consumer fraud
  - financial scams
  - elder fraud protection
  - banking regulation
  - identity theft
---

# HB 1034. Georgia Tech Support Impersonation and Remote Access Protection Act; enact

## Text

House Bill 1034
By: Representatives Scott of the 76th, Schofield of the 63rd, and Davis of the 87th
A BILL TO BE ENTITLED
AN ACT
To amend Chapter 1 of Title 7 of the Official Code of Georgia Annotated, relating to
financial institutions, so as to require that financial institutions provide customers the ability
to place emergency holds on suspected fraudulent transactions; to amend Chapter 1 of Title
10 of the Official Code of Georgia Annotated, relating to selling and other trade practices,
so as to add internet and email fraud to the list of crimes constituting unfair or deceptive
practices in consumer transactions; to amend Chapter 9 of Title 16 of the Official Code of
Georgia Annotated, relating to forgery and fraudulent practices, so as to criminalize
electronic and voice communications intended to fraudulently solicit identifying information
and gain remote access to electronic devices and accounts; to provide a short title; to amend
Chapter 15 of Title 17 of the Official Code of Georgia Annotated, relating to victim
compensation, so as to provide victim relief fund access to victims of certain financial
crimes; to amend Chapter 15 of Title 45 of the Official Code of Georgia Annotated, relating
to general provisions relative to the attorney general, so as to require that the Attorney
General create public awareness and training initiatives regarding certain financial crimes;
to provide for definitions; to provide for a short title; to provide for related matters; to repeal
conflicting laws; and for other purposes.
BE IT ENACTED BY THE GENERAL ASSEMBLY OF GEORGIA:
SECTION 1.
This Act shall be known and may be cited as the "Georgia Tech Support Impersonation and
Remote Access Protection Act."
SECTION 2.
Chapter 1 of Title 7 of the Official Code of Georgia Annotated, relating to financial
institutions, is amended in Article 9, relating to criminal and related provisions, by adding
a new Code section to read as follows:
<ins>"7-1-847.
(a) As used in this Code section, the term:
(1) 'Authorized push payment scam' means a process of falsely representing affiliation
with a business or government entity to induce an individual to electronically convey
money or information.
(2) 'Financial institution' means a bank, credit union, trust company, or money
transmitter licensed or operating in this state.
(3) 'Covered transfer' means an electronic funds transfer under 12 C.F.R. Part 1005, an
automated clearing house entry, or a peer-to-peer transfer initiated through a covered
financial institution. Such term shall not include a payment order accepted under Article
4A of Title 11 or a transfer over a federal reserve wire system after acceptance.
(b) Financial institutions shall make available to all customers, at no charge, an account
safety lock accessible by telephone and online. When activated, the institution shall block
creation of new payees, set outbound covered transfer limits to zero, and terminate active
online sessions until the customer reauthenticates his or her identity by in-person
verification, notarized written instructions, or a verified callback number on file. Financial
institutions shall offer customers the option to designate a trusted contact whom the
institution may contact solely to confirm the customer's safety and intent when fraud is
suspected.
</ins>
<ins>(c) If a financial institution detects an active remote access session or remote
administration software operating during initiation of a covered transfer, such institution
shall pause the transaction and require high assurance reauthentication or in-person
verification.
(d) Financial institutions shall implement measures reasonably designed to deter
authorized push payment scams. Upon receiving a customer report of suspected fraudulent
activity, a financial institution shall implement a temporary emergency hold on a covered
transfer prior to final posting or settlement. Such hold may be maintained for up to 72
hours, unless sooner released upon completion of risk review. A single 72 hour extension
may be granted upon a written request from law enforcement or upon the customer's
submission of a police report.
(e) A financial institution may place a temporary emergency hold on a customer account
when fraud indicators are present, including, but not limited to, first-time or high-risk
payees, anomalous device or geolocation data, detection of an active remote access session,
or a beneficiary name or identifier mismatch.
(f) A financial institution shall notify the customer within one business day after placing
a hold on his or her account and provide an outcome within three business days after
release of such hold, including whether funds were released, reversed, or recalled.
(g) All financial institutions shall retain records of account holds for five years and
annually report to the department the number of holds, aggregate dollar amounts paused,
reversals, recalls, and releases. The department shall publish an annual Georgia Financial
Fraud Report summarizing this information state wide."
</ins> SECTION 3.
Chapter 1 of Title 10 of the Official Code of Georgia Annotated, relating to selling and other
trade practices, is amended in subsection (b) of Code Section 10-1-393, relating to unfair or
deceptive practices in consumer transactions unlawful and examples, by striking "and" at the
end of subparagraph (D) of paragraph 36, by replacing the period at the end of paragraph
(37) with "; and", and by adding a new paragraph to read as follows:
<ins>"(38)(A) Any violation of Code Section 16-9-109.1.
(B) In addition to any criminal penalties, the Attorney General may bring a civil action
for injunctive relief, civil penalties, restitution, and other appropriate relief."
</ins> SECTION 4.
Chapter 9 of Title 16 of the Official Code of Georgia Annotated, relating to forgery and
fraudulent practices, is amended by revising Code Section 16-9-109.1, relating to fraudulent
business practices using internet or e-mail, definitions, penalties, sanctions, and immunity,
as follows:
"(a) As used in this part, the term:
<ins>(0.1) 'Electronic communication' means any message sent by short message service,
multimedia message service, or internet based messaging platform, including links or
codes that route a user to a web page or remote access session.
</ins> (1) <del>'E-mail</del> <ins>Email</ins> message' means a message sent to a unique destination, commonly
expressed as a string of characters, consisting of a unique user name or mailbox,
commonly referred to as the 'local part,' and a reference to an <del>Internet</del> <ins>internet</ins> domain,
commonly referred to as the 'domain part,' whether or not displayed, to which an
electronic message can be sent or delivered.
(2) 'Employer' includes a business entity's officers, directors, parent corporation,
subsidiaries, affiliates, and other corporate entities under common ownership or control
within a business enterprise.
(3) 'Identifying information' means, with respect to an individual, any of the following:
(A) Social security number;
(B) Driver's license number;
(C) Bank account number;
(D) Credit card or debit card number;
(E) Personal identification number or PIN;
(F) Automated or electronic signature;
(G) Unique biometric data;
(H) Account password; or
(I) Any other piece of information that can be used to access an individual's financial
accounts or to obtain goods or services.
(4) 'Internet' shall have the meaning set forth in paragraph (10) of Code Section
16-9-151.
<ins>(4.1) 'Voice communication' means the conveyance of any message through human
speech, including live speech, prerecorded or stored human speech, and simulated or
artificially generated human speech produced by software or artificial intelligence.
</ins> (5) 'Web page' means a location that has a single uniform resource locator or other single
location with respect to the <del>Internet</del> <ins>internet.
</ins> (b)(1) It shall be unlawful for any person with intent to defraud, by means of a web page,
<del>e-mail</del> <ins>email</ins> message, <ins>voice communication, electronic communication,</ins> or otherwise
through use of the <del>Internet</del> <ins>internet,</ins> to solicit, request, or take any action to induce
another person to provide identifying information <ins>or remote access to an electronic device
or account</ins> by representing himself, herself, or itself to be a business without the authority
or approval of such business.
(2) It shall be unlawful for any person, with actual knowledge, conscious avoidance of
actual knowledge, or willfully, to possess with intent to use in a fraudulent manner, sell,
or distribute any identifying information obtained in violation of paragraph (1) of this
subsection.
(c) Any person who intentionally violates subsection (b) of this Code section shall be
guilty of a felony and shall be punished by imprisonment for not less than one nor more
than 20 years, a fine of not less than $1,000.00 nor more than $500,000.00, or both.
(d)(1) No employer shall be held criminally liable under this Code section as a result of
any actions taken:
(A) With respect to computer equipment used by its employees, contractors,
subcontractors, agents, leased employees, or other staff which the employer owns,
leases, or otherwise makes available or allows to be connected to the employer's
network or other computer facilities when such equipment is used for an illegal purpose
without the employer's knowledge, consent, or approval; or
(B) By employees, contractors, subcontractors, agents, leased employees, or other staff
who misuse an employer's computer equipment for an illegal purpose without the
employer's knowledge, consent, or approval.
(2) No person shall be held criminally liable under this Code section when its protected
computers, computer equipment, or software product has been used by unauthorized
users to violate this Code section without such person's knowledge, consent, or approval.
(e) This Code section shall not apply to a telecommunications provider's or <del>Internet
</del> <ins>internet</ins> service provider's good faith transmission or routing of, or intermediate temporary
storing or caching of, identifying information.
(f) No provider of an interactive computer service may be held liable in a civil action
under any law of this state, or any of its political subdivisions, for removing or disabling
access to content on <del>an Internet</del> <ins>a</ins> website or other online location controlled or operated
by such provider, when such provider believes in good faith that such content has been
used to engage in a violation of this part."
SECTION 5.
Chapter 15 of Title 17 of the Official Code of Georgia Annotated, relating to victim
compensation, is amended by adding a new Code section to read as follows:
<ins>"17-15-18.
(a) This Code section shall be known and may be cited as the 'Georgia Financial Fraud
Victims Relief Fund.'
(b) As used in this Code section, the term:
(1) 'Eligible financial fraud' means a violation of Code Section 16-9-109.1 or other fraud
resulting in a covered transfer, as such term is defined in Code Section 7-1-847, where
funds are not otherwise reimbursable under federal or state law or by a financial
institution.
(2) 'Eligible victim' means a person residing in this state who promptly reports suspected
fraud to a financial institution, cooperates in any investigation or recovery efforts, and has
not received reimbursement from any other source for the loss.
(c) There is created the Georgia Financial Fraud Victims Relief Fund, to be administered
by the Criminal Justice Coordinating Council. The fund shall consist of moneys
appropriated by the General Assembly; civil penalties and settlement proceeds recovered
by the state for violations of Code Section 16-9-109.1; and gifts, grants, and donations.
The council shall promulgate rules necessary to implement this Code section.
(d) Awards shall reimburse uncompensated pecuniary loss up to $10,000.00 per incident
and $20,000.00 per claimant per calendar year, subject to available funds. Any amounts
recovered by the victim after such reimbursement shall be repaid to the fund to the extent
of the award. No award shall duplicate compensation available from any other source.
(e) An eligible victim shall apply within one year of discovery of the fraud, subject to
equitable tolling for good cause.
(f) The council shall issue an eligibility determination within 90 days of receipt of a
complete application.
(g) The council shall publish an annual report on claims received, awards granted or
denied, and aggregate losses and recoveries."
</ins>
SECTION 6.
Chapter 15 of Title 45 of the Official Code of Georgia Annotated, relating to general
provisions relative to the attorney general, is amended by adding a new Code section to read
as follows:
<ins>"45-15-21.
(a) The Attorney General shall create and maintain a centralized web portal and a toll-free
hotline dedicated to violations of Code Section 16-9-109.1 integrated with existing
consumer complaint systems and capable of referral to applicable federal portals.
(b) All reports shall receive an acknowledgment within 48 hours and a status update within
ten business days. The Attorney General shall coordinate referrals with the Georgia
Bureau of Investigation, the Department of Banking and Finance, and applicable federal
agencies.
(c) The Attorney General shall conduct an annual public awareness campaign focused on
recognizing fraudulent electronic solicitations, authorized push payment scams, and remote
access fraud.
(d) The Attorney General shall develop training programs for state and local law
enforcement agencies and district attorneys regarding technology enabled fraud, including
artificial intelligence generated voice impersonation, deceptive remote access, and
investigative best practices.
(e) The Attorney General may promulgate rules and enter into memoranda of
understanding necessary to implement this Code section."
</ins> SECTION 7.
All laws and parts of laws in conflict with this Act are repealed.

## Summaries written by Georgia Commons

The following was written by claude-sonnet-5 from the text above and is not part of the bill. Quote the text, not the summary.

House Bill 1034 would create new Georgia laws against tech support and remote access scams, require banks to offer emergency fraud holds, set up a victims relief fund, and direct the Attorney General to run fraud awareness and training programs.

### Plain-language summary

Georgia currently has a law against using the internet or email to trick people into handing over personal information by pretending to be a business. This bill, called the Georgia Tech Support Impersonation and Remote Access Protection Act, expands that law to cover phone calls, text messages, and voice communications, including AI generated voices, and adds tricking someone into giving remote access to their device or accounts. It keeps the existing felony penalty of 1 to 20 years in prison and a fine between $1,000 and $500,000.
The bill also requires banks, credit unions, and money transmitters to give customers a free way to lock their accounts during suspected fraud, pause suspicious transfers for up to 72 hours, and report annual fraud statistics to the state. It adds a new violation category to Georgia's consumer protection law, creates a Georgia Financial Fraud Victims Relief Fund administered by the Criminal Justice Coordinating Council to reimburse victims up to $10,000 per incident, and requires the Attorney General to build a fraud reporting hotline and run public training and awareness campaigns. The bill does not state a specific effective date beyond standard enactment.

### What it does

- Expands Georgia's internet and email fraud law (O.C.G.A. § 16-9-109.1) to also cover phone calls, text messages, and voice communications, including AI generated voice impersonation, and to cover tricking someone into giving remote access to a device or account.
- Requires financial institutions to offer customers a free account safety lock that blocks new payees, zeroes out transfer limits, and ends active sessions until identity is reverified.
- Lets financial institutions place temporary holds of up to 72 hours (extendable once) on suspicious transfers when fraud is suspected or a remote access session is detected during a transfer.
- Adds violations of the fraud law to the list of unfair or deceptive practices under Georgia's consumer protection law (O.C.G.A. § 10-1-393), allowing the Attorney General to seek civil penalties and restitution.
- Creates the Georgia Financial Fraud Victims Relief Fund to reimburse eligible fraud victims up to $10,000 per incident and $20,000 per year, administered by the Criminal Justice Coordinating Council.
- Requires the Attorney General to run a fraud reporting hotline and web portal, coordinate with law enforcement, and provide annual public awareness campaigns and law enforcement training on tech enabled fraud.

### Who it affects

Banks, credit unions, and other financial institutions operating in Georgia; consumers and fraud victims, especially older adults targeted by tech support and impersonation scams; the Attorney General's office, the Georgia Bureau of Investigation, the Department of Banking and Finance, and the Criminal Justice Coordinating Council; and businesses whose names are impersonated in fraud schemes.

### Why it matters

Georgians who fall victim to phone or online impersonation scams, including fake tech support calls or remote access tricks, would gain new tools: bank account locks, transaction holds, a state hotline, and a relief fund covering losses up to $10,000. Financial institutions would face new operational and reporting duties.

### Key provisions

- Section 1 gives the bill its short title, the Georgia Tech Support Impersonation and Remote Access Protection Act.
- Section 2 adds O.C.G.A. § 7-1-847, requiring financial institutions to offer free account safety locks, honor customer trusted contacts, and place emergency holds of up to 72 hours on suspicious transfers, with annual reporting to the state.
- Section 3 amends O.C.G.A. § 10-1-393 to make violations of the fraud statute an unfair or deceptive trade practice, letting the Attorney General pursue civil penalties and restitution.
- Section 4 rewrites O.C.G.A. § 16-9-109.1 to add voice and electronic communications and remote device access to the crimes of fraudulent impersonation, keeping the existing felony penalty of 1 to 20 years and a $1,000 to $500,000 fine.
- Section 5 creates O.C.G.A. § 17-15-18, establishing the Georgia Financial Fraud Victims Relief Fund with awards capped at $10,000 per incident and $20,000 per claimant per year, and a 90-day decision deadline.
- Section 6 creates O.C.G.A. § 45-15-21, requiring the Attorney General to run a fraud hotline, web portal, annual public awareness campaign, and law enforcement training on technology enabled fraud.

## Status

- Status: Introduced (2026-01-27)
- Last action: House Second Readers (2026-01-29)
- Sponsors: Sandra Scott, Kim Schofield, Viola Davis
- Official page: https://www.legis.ga.gov/legislation/72364

> The history, votes, and amendments (129 characters) are at https://georgiacommons.org/bills/2025-2026/hb1034.md?full=1
