The Morning After the Merger, Nobody Knew Who the Customers Were
You can buy a company’s customers. That is not the same as being able to say who, or how many, they are.
The Morning After the Merger, Nobody Knew Who the Customers Were
You can buy a company’s customers. That is not the same as being able to say who, or how many, they are.
Over the Labor Day weekend of 2022, a lawyer in Woodstock, Vermont, called Elizabeth Kruska sat down to log into her bank. She was not really changing banks. Her bank had been bought. M&T Bank had paid roughly seven and a half billion dollars for People’s United, and over that long weekend it moved about a million former People’s United customers, and their 1.7 million accounts, onto its own systems. Kruska typed in her details and the system did not know her. It did not recognise her Social Security number. It did not recognise her date of birth. It did not recognise her debit card. By every identifier a bank normally uses to be sure you are you, she did not exist.

She was not alone. A graphic designer in South Londonderry named Georgianne Mora was locked out for more than a day and told, in the flat grammar of software, that her information did not match their records. Other customers were informed that their account simply did not exist. By the Wednesday after the cutover, M&T later conceded, only about forty percent of its new customers had managed to activate their online accounts. The bank had acquired these people. It had paid for them. And on the Tuesday morning it could not confirm that most of them were who they said they were.
The plainest and most awkward question underneath every acquisition is the one my work exists to answer, so mergers hold a grim fascination for me. When one company buys another, the announcement always talks about the combined customer base as if it were a simple sum. Two million here, three million there, five million together. But that arithmetic hides the only interesting question in the whole exercise. Is your customer already my customer? Until somebody can answer that, one human being at a time, across two databases built by two different companies that never once coordinated, the merged firm does not actually know how many customers it has. It knows how many customer records it has, which is a different and much larger number.
Two ledgers, no shared spine
The reason this is genuinely hard, rather than a weekend of copying files, is that the two companies never agreed on who anyone was. Each minted its own internal customer numbers. Bank A’s customer 4471 and Bank B’s customer 9982 might be the same person, and nothing anywhere in either system says so. There is no shared key to join them on. The only way to work out that they are the same is to infer it from the soft, human identifiers each side happens to hold: a name, a date of birth, an address, a phone number, an email, sometimes a national identifier. And those are exactly the fields that drift. People move. They marry and change their names. A middle initial appears on one file and not the other, a maiden name lingers in one system for a decade, a digit is transposed on a form in 2009 and never corrected.
Matching on the parts that agree exactly, the deterministic approach, is precise and easy to explain, and it silently misses every case where the data has drifted even slightly. To catch the rest you need probabilistic matching, the fuzzy sort, which weighs partial evidence and produces a score for how likely two records are the same person rather than a flat yes or no. Serious systems run both, deterministic rules for the clean cases and probabilistic scoring for the messy majority, because a merger is nothing but messy majority. And when the system does decide two records are one person, it then has to choose which version of the truth survives: whose address, whose phone number, whose spelling of the name goes onto the single combined record. Get that judgement wrong at scale, a million times over a weekend, and you get a Tuesday morning in Vermont.
The two ways to be wrong, and both cost money
There are only ever two ways to get this wrong, and a merger manages to produce both at once.
The first is to leave one person as two. The system fails to connect Bank A’s record with Bank B’s, and a single customer walks into the combined company as two strangers. This is the quiet one, and it is the one that makes the announced numbers a fiction. The same people, counted twice, inflate the customer base that justified the deal, and the promised savings that were supposed to come from serving one larger set of customers turn out to be spread across a set that was never as large or as separate as the spreadsheet claimed. It is worth remembering how often the spreadsheet is the problem. Bain, reviewing its own deal work, found that almost sixty percent of executives blamed failed acquisitions on due diligence that did not surface the critical issues. Not knowing who you are actually buying is a fairly critical issue.
The second way is louder and worse. Instead of splitting one person into two, the system fuses two people into one. It decides, on the strength of a shared name or a reused piece of data, that two different customers are the same, and merges their records. In 2018, when the British bank TSB moved five and a bit million customers onto a new platform after its own change of ownership, this is precisely what some of them experienced: they logged in and found themselves looking at other people’s accounts. Some forty thousand complaints arrived in the first ten days, the great majority of them caused by the meltdown rather than the ordinary run of banking. The Financial Conduct Authority and the Prudential Regulation Authority later fined the bank a little over forty-eight and a half million pounds, and the regulator’s account was blunt, that the firm had failed to plan the migration properly and that the governance of the project was not robust enough. A false merge is not a data-quality footnote. It is a stranger reading your balance.
None of this is confined to one unlucky bank. When BB&T and SunTrust combined to form Truist, a company quite literally created by merging two customer bases, the strain surfaced at the same place, the conversion. In the month customers were moved across, complaints to the US consumer regulator spiked, and a bigger share of them than usual were the most serious kind, the proportion in the highest-severity category climbing from about one in ten to roughly one in six. The pattern repeats because the underlying task is always the same, and it is always underestimated: not moving data, but deciding, person by person, who in the first pile is who in the second.
The regulators already decided this was not optional
Here is the part that should end the argument about whether identity resolution is a luxury. In the United Kingdom, a bank is required by law to be able to produce, within twenty four hours of its own failure, a single de-duplicated view of every depositor it has, so that savers can be paid back correctly and quickly. The rule, run by the Financial Services Compensation Scheme and the Prudential Regulation Authority, has been mandatory since the end of 2010, and it says in as many words that firms must identify and rectify the duplicated records that pile up from legacy systems and separate points of data entry. Read that again with a merger in mind. The regulator has taken the question I started with, how many customers do you actually have, and turned it into a legal deadline measured in hours. A bank that cannot resolve its own customers is not merely inefficient. It is out of compliance.
That is the quiet scandal of the merger morning. The failure looks like an IT problem, a bad weekend, a call centre overwhelmed. Underneath it is something more basic that no amount of integration budget makes go away on its own. Two companies spent years each building a careful, private idea of who their customers were, and the deal assumed those two ideas could be added together like sums of money. They cannot. They have to be reconciled, one resolved person at a time, and if that work is treated as a file transfer to be done over a bank holiday, the customers find out first.
Elizabeth Kruska eventually got back into her account. The senators who represent Vermont wrote to the bank demanding that it compensate the people it had locked out, and complained, accurately, that the episode showed a severe lack of due diligence and of resources devoted to doing the thing properly. The bank’s chief executive said he took full responsibility and apologised to customers whose expectations had not been met. All of that is the correct and decent response to the symptom. But the disease was older and simpler than the weekend it surfaced on. A company had bought several million people and had not yet done the unglamorous work of deciding which of them it already knew. You can put two customer bases under one logo in an afternoon. Turning them into one honest answer to the question who are our customers is the actual acquisition, and it is the part everyone budgets last.
Author
Steven Renwick is the co-founder and CEO of Tilores (tilores.io), which provides real-time entity resolution through an API for AI and data teams. He works with engineering and data leaders on resolving customer, supplier, and account identity across fragmented systems.
Sources
- Juliet Schulman-Hall, “Banking transfer is bumpy for some new M&T Bank customers,” VTDigger, 8 September 2022. https://vtdigger.org/2022/09/08/banking-transfer-is-bumpy-for-some-new-mt-bank-customers/
- Banking Dive, “M&T pledges to rectify People’s United account access issues,” 3 October 2022 (deal size, conversion scale, CEO statement, complaint figure). https://www.bankingdive.com/news/mt-pledges-to-rectify-peoples-united-account-access-issues/633185/
- Office of US Senator Edward Markey, “Senators Markey, Blumenthal, Colleagues Demand M&T Bank Compensate Customers Affected by Conversion Failures,” 23 September 2022. https://www.markey.senate.gov/news/press-releases/senators-markey-blumenthal-colleagues-demand-mandt-bank-compensate-customers-affected-by-conversion-failure
- Financial Conduct Authority, “TSB fined £48.65m for operational resilience failings,” 20 December 2022. https://www.fca.org.uk/news/press-releases/tsb-fined-48m-operational-resilience-failings
- Allissa Kline, “Truist reckons with customer backlash after integration snags,” American Banker, 11 May 2022. https://www.americanbanker.com/news/truist-reckons-with-customer-backlash-after-integration-snags
- Financial Services Compensation Scheme, “Single Customer View,” and Prudential Regulation Authority Supervisory Statement SS18/15, “Depositor Protection” (24-hour de-duplicated depositor file, mandatory since 31 December 2010). https://www.fscs.org.uk/industry-resources/single-customer-view/
- Bain & Company, “Due Diligence: Evolving Approaches Boost the Odds of Success,” Global Corporate M&A Report 2020. https://www.bain.com/insights/due-diligence-global-ma-report-2020/
- Tilores, “Reconciling Customer Identities After a Merger or Acquisition” (the entity-resolution mechanics of post-merger customer reconciliation). https://tilores.io/content/reconciling-customer-identities-after-merger-acquisition
메타데이터
- post_id
- 3892cd2d6476
- slug
- the-morning-after-the-merger-nobody-knew-who-the-customers-were-3892cd2d6476
- url
- https://medium.com/@major-grooves/the-morning-after-the-merger-nobody-knew-who-the-customers-were-3892cd2d6476
- canonical_url
- https://medium.com/@major-grooves/the-morning-after-the-merger-nobody-knew-who-the-customers-were-3892cd2d6476
- author_url
- https://medium.com/@major-grooves
- status
- ok
- fetched_at
- 2026-07-08 18:29:56