- enforcement actions and breaches
- 32 enforcement actions and breaches
- in penalties, approximate US dollars
- $7.6B in penalties, approximate US dollars
- jurisdictions covered
- 10 jurisdictions covered
- identity-data breaches
- 7 identity-data breaches
Actions from 2023 to 2026. Every record links its source: 25 cite the authority’s own announcement or decision, 4 the company’s own disclosure, 1 the researchers who found the exposure and 2 a press report. Dataset last updated ; the most recent action in it is dated . Change history.
Database
Browse enforcement actions and breaches
Search by entity, regulator, or keyword. Filter by action type, jurisdiction, and year. Sort any column to compare penalties and dates.
Showing 32 of 32 actions
| Jurisdiction | Analysis | |||||
|---|---|---|---|---|---|---|
Tren de Aragua ATM jackpotting network OFAC designated alleged facilitators of a Tren de Aragua ATM jackpotting scheme, two Mexican companies and a Tren de Aragua leader tied to illegal gold mining. Seven of the SDN entries list a TRON address that Treasury links to laundering the stolen cash. Treasury puts reported US losses from alleged jackpotting at 40.73 million dollars across over 1,500 attacks as of August 2025. Source: home.treasury.gov for Tren de Aragua ATM jackpotting network (opens in a new tab) | OFAC | US | — | Sanctions violation | Read analysis about Tren de Aragua ATM jackpotting network | |
Revolut Revolut confirmed that it disclosed customer data to a fraudster who sent requests for information from a legitimate government agency email domain. Affected customers were told the data included dates of birth, addresses, phone numbers and copies of passports and driving licences, and may have included verification selfies, statements and transaction histories. Revolut said a limited number of customers were affected and that its systems and customer funds were unaffected. Source: techcrunch.com (press report) for Revolut (opens in a new tab) | — | Global | — | Data breach | Read analysis about Revolut | |
Xinbi Guarantee OFAC designated Xinbi Guarantee, a Telegram-based marketplace serving Southeast Asian scam centres, as a transnational criminal organization, together with two app developers. Its SDN entry lists 52 TRON addresses. Treasury says the marketplace processed the equivalent of over 24 billion dollars in digital assets and fiat currency since around 2022. Source: home.treasury.gov for Xinbi Guarantee (opens in a new tab) | OFAC | US | — | Sanctions violation | Read analysis about Xinbi Guarantee | |
IDScan.net IDScan.net said that on or around 1 September 2026 it received information indicating that certain data may have been accessed without authorization, and that it secured its systems and engaged outside experts. It has not confirmed the scale. A dark web service had advertised more than 153 million US and Canadian driver’s license scans, and nine class actions were filed against the company in the Eastern District of Louisiana between 2 and 4 September. Source: idscan.net (company disclosure) for IDScan.net (opens in a new tab) | — | US | — | Data breach | Read analysis about IDScan.net | |
Citibank, N.A., London Branch OFSI imposed a penalty of 4,732,830.58 pounds on 11 August 2026, published on 2 September, for 970 payments worth 19,720,127.43 pounds that breached UK sanctions. The notice traces the breaches to screening gaps, alert backlogs and an ownership determination OFSI found unreasonable. Source: assets.publishing.service.gov.uk for Citibank, N.A., London Branch (opens in a new tab) | OFSI | UK | £4.73M | Sanctions violation | Read analysis about Citibank, N.A., London Branch | |
QuinnBet (Gibraltar) QuinnBet agreed to pay 609,104 pounds, including 193,118 pounds of disgorgement, after the Gambling Commission found its anti-money laundering and customer interaction controls were not effective in practice for 29 months. A platform migration had switched off working limits. Source: gamblingcommission.gov.uk for QuinnBet (Gibraltar) (opens in a new tab) | Gambling Commission | UK | £609,104 | AML/BSA fine | Read analysis about QuinnBet (Gibraltar) | |
Rice Lake Weighing Systems OFAC settled eight apparent violations covering roughly 121,527 dollars of goods, after the company’s Italian subsidiary shipped to Iran through a distributor in the United Arab Emirates. Source: ofac.treasury.gov for Rice Lake Weighing Systems (opens in a new tab) | OFAC | US | $60,764 | Sanctions violation | Read analysis about Rice Lake Weighing Systems | |
UBS Financial Services FinCEN imposed a 125 million dollar penalty, its largest ever on a broker-dealer, after more than 61,500 foreign currency wires worth over 10.5 billion dollars went unmonitored between January 2019 and June 2023. The firm admitted it never closed the gaps a 2018 consent order required it to fix. Source: fincen.gov for UBS Financial Services (opens in a new tab) | FinCEN | US | $125M | AML/BSA fine | Read analysis about UBS Financial Services | |
Wise US Holdings The OCC denied Wise a national trust bank charter, ruling it could not confirm an effective anti-money laundering programme while a 2025 multistate order over late suspicious activity reports and transaction monitoring data integrity remained unresolved. Source: occ.gov for Wise US Holdings (opens in a new tab) | OCC | US | — | KYC failure | Read analysis about Wise US Holdings | |
Landesbank Hessen-Thüringen (Helaba) BaFin ordered Helaba to remedy customer due diligence failures spanning customer identification, verification, updating of customer data, risk analysis and transaction monitoring. It is the second BaFin money laundering measure against the bank in seven months. Source: bafin.de for Landesbank Hessen-Thüringen (Helaba) (opens in a new tab) | BaFin | Germany | — | KYC failure | Read analysis about Landesbank Hessen-Thüringen (Helaba) | |
Swedbank New York’s Department of Financial Services secured a 50 million dollar penalty from Swedbank and its New York branch for withholding information about its Baltic subsidiaries’ links to the Panama Papers, across responses spanning 2016 to 2019. Source: dfs.ny.gov for Swedbank (opens in a new tab) | NYDFS | US | $50M | AML/BSA fine | Read analysis about Swedbank | |
CCV Group De Nederlandsche Bank fined the payment institution 2,656,250 euros after roughly 4,200 merchants sat outside its transaction monitoring system for 23 months, with alerts closed in bulk and no recorded justification. The penalty was raised because CCV had breached the same rule before. Source: dnb.nl for CCV Group (opens in a new tab) | DNB | Netherlands | €2.66M | AML/BSA fine | Read analysis about CCV Group | |
AssuranceAmerica The Atlanta auto insurer disclosed a breach affecting 6,998,886 people, exposing names, contact details and driver’s license numbers after an employee’s credentials were compromised. Source: techcrunch.com (press report) for AssuranceAmerica (opens in a new tab) | — | US | — | Data breach | Read analysis about AssuranceAmerica | |
ABN AMRO De Nederlandsche Bank fined ABN AMRO 8.5 million euros for inadequate due diligence on high-risk customers, finding monitoring insufficiently critical and customer explanations accepted without verification. It follows a 480 million euro criminal settlement five years earlier. Source: dnb.nl for ABN AMRO (opens in a new tab) | DNB | Netherlands | €8.5M | AML/BSA fine | Read analysis about ABN AMRO | |
PCC money laundering network OFAC blocked a network that moved more than 30 million dollars of US drug proceeds through cryptocurrency for Brazil’s PCC, designating two Brazilian nationals and four companies. Brazil then froze roughly 2 billion dollars in related assets. Source: home.treasury.gov for PCC money laundering network (opens in a new tab) | OFAC | US | — | Sanctions violation | Read analysis about PCC money laundering network | |
EagleBank EagleBank agreed to pay 9,057,821 dollars in fines plus 736,515 dollars in forfeiture under a non-prosecution agreement, admitting it wilfully failed to run an anti-money laundering programme from 2010 to 2021 while executives overrode compliance staff. Source: justice.gov for EagleBank (opens in a new tab) | DOJ | US | $9.79M | AML/BSA fine | Read analysis about EagleBank | |
Merrill Lynch The SEC fined Merrill 7.5 million dollars because its transaction monitoring system only investigated alerts scoring 20 or higher, after Merrill’s own analysis showed lower-scoring events would have produced suspicious activity reports. It took about three years to fix. Source: sec.gov for Merrill Lynch (opens in a new tab) | SEC | US | $7.5M | AML/BSA fine | Read analysis about Merrill Lynch | |
CACEIS UK The FCA publicly censured CACEIS UK for weak financial crime controls that let the collapsed wealth manager WealthTek hold client assets it was never permitted to hold. It avoided a financial penalty that the FCA put at about 23.1 million pounds after a 30 percent settlement discount, and agreed a voluntary payment of 31,714,068 pounds to affected clients. Source: fca.org.uk for CACEIS UK (opens in a new tab) | FCA | UK | £31.7M redress | Integrity/governance | Read analysis about CACEIS UK | |
Foreign bank branch (unnamed) and its head of compliance The Central Bank of the UAE fined a foreign bank branch 20 million dirhams for repeated anti-money laundering and sanctions control failures, and separately fined its head of compliance 300,000 dirhams. Source: centralbank.ae for Foreign bank branch (unnamed) and its head of compliance (opens in a new tab) | CBUAE | UAE | AED 20M | AML/BSA fine | Read analysis about Foreign bank branch (unnamed) and its head of compliance | |
Prince Group Treasury widened its action against the Cambodian scam conglomerate, adding 9 individuals and 26 entities, while FinCEN moved to sever the renamed Huione affiliate H-Pay from the US financial system. Source: home.treasury.gov for Prince Group (opens in a new tab) | OFAC, FinCEN | US | — | Sanctions violation | Read analysis about Prince Group | |
Ikano Bank Sweden’s financial supervisor fined Ikano Bank 140 million kronor and issued a formal remark for failing to assess how its corporate products could be used to fund crime. No laundering case was alleged. Source: fi.se for Ikano Bank (opens in a new tab) | Finansinspektionen | Sweden | SEK 140M | AML/BSA fine | Read analysis about Ikano Bank | |
Poste Italiane and Postepay Italy’s data protection authority fined Poste Italiane 6,624,000 euros and Postepay 5,877,000 euros for embedding device-surveillance software in banking apps and making consent to it a condition of account access. Source: garanteprivacy.it for Poste Italiane and Postepay (opens in a new tab) | Garante per la protezione dei dati personali | Italy | €12.5M | GDPR enforcement | Read analysis about Poste Italiane and Postepay | |
Bank of London Group The PRA fined Bank of London Group £2 million for integrity failings and inadequate cooperation over misrepresenting its capital position. Source: bankofengland.co.uk for Bank of London Group (opens in a new tab) | PRA | UK | £2M | Integrity/governance | Read analysis about Bank of London Group | |
Ranson Houghton LLP The SRA fined Ranson Houghton LLP for AML failures, signalling AML enforcement expanding beyond banks into legal services. Source: sra.org.uk for Ranson Houghton LLP (opens in a new tab) | SRA | UK | £10,283 | AML/BSA fine | Read analysis about Ranson Houghton LLP | |
EU GDPR Transparency Sweep (EDPB) 25 EU regulators launched a coordinated GDPR transparency enforcement sweep affecting how KYC flows present data processing. Source: edpb.europa.eu for EU GDPR Transparency Sweep (EDPB) (opens in a new tab) | EDPB / 25 EU DPAs | EU | — | GDPR enforcement | Read analysis about EU GDPR Transparency Sweep (EDPB) | |
Canaccord Genuity FinCEN assessed an 80 million dollar penalty, its largest ever against a broker-dealer, for years of gamed trade surveillance and at least 160 suspicious activity reports that were never filed. Source: fincen.gov for Canaccord Genuity (opens in a new tab) | FinCEN | US | $80M | AML/BSA fine | Read analysis about Canaccord Genuity | |
IDMerit Cybernews reported an unsecured database it linked to IDMerit that exposed about one billion personal records across 26 countries, over 203 million of them from the United States. IDMerit told Cybernews it does not own, control or store the underlying data. The database was found on 11 November 2025 and secured the next day. Source: cybernews.com (researchers) for IDMerit (opens in a new tab) | — | US | — | Data breach | Read analysis about IDMerit | |
Sumsub A breach via a malicious attachment on a third-party support platform went undetected for 18 months (Jul 2024–Jan 2026). Source: sumsub.com (company disclosure) for Sumsub (opens in a new tab) | — | Global | — | Data breach | Read analysis about Sumsub | |
Discord A third-party customer service vendor was compromised, exposing roughly 70,000 government ID photos that the vendor held to review age-related appeals. Source: discord.com (company disclosure) for Discord (opens in a new tab) | — | Global | — | Data breach | Read analysis about Discord | |
Coinbase Coinbase disclosed that a threat actor had paid contractors or employees in support roles outside the United States to collect customer data from internal systems, including names, contact details, masked Social Security and bank account numbers, government ID images and balance snapshots, then demanded money not to publish it. Coinbase refused to pay and estimated the cost at about 180 million to 400 million dollars. Source: sec.gov (company disclosure) for Coinbase (opens in a new tab) | — | US | $180M to $400M est. cost | Data breach | Read analysis about Coinbase | |
TD Bank TD Bank pleaded guilty and paid about $3 billion for Bank Secrecy Act and money-laundering failures — the largest bank ever to plead guilty to conspiracy to commit money laundering. ~$1.8B DOJ, $1.3B FinCEN, $450M OCC, $123.5M Federal Reserve. Source: justice.gov for TD Bank (opens in a new tab) | DOJ, FinCEN, OCC, Federal Reserve | US | $3B | AML/BSA fine | Read analysis about TD Bank | |
Binance Binance agreed to pay more than $4.3 billion to US authorities; founder CZ pleaded guilty, paid a $50M personal fine and stepped down. FinCEN $3.4B civil penalty + 5-year monitorship; OFAC $968M. Source: justice.gov for Binance (opens in a new tab) | DOJ, FinCEN, OFAC, CFTC | Global/US | $4.3B | AML/BSA fine | Read analysis about Binance |
Tren de Aragua ATM jackpotting network
—Sanctions violationUSOFAC
OFAC designated alleged facilitators of a Tren de Aragua ATM jackpotting scheme, two Mexican companies and a Tren de Aragua leader tied to illegal gold mining. Seven of the SDN entries list a TRON address that Treasury links to laundering the stolen cash. Treasury puts reported US losses from alleged jackpotting at 40.73 million dollars across over 1,500 attacks as of August 2025.
Takeaway: A designation that lists wallet addresses is a screening rule you can run today, on crypto rails as well as on names.
Source: home.treasury.govRead analysis about Tren de Aragua ATM jackpotting networkRevolut
—Data breachGlobal—
Revolut confirmed that it disclosed customer data to a fraudster who sent requests for information from a legitimate government agency email domain. Affected customers were told the data included dates of birth, addresses, phone numbers and copies of passports and driving licences, and may have included verification selfies, statements and transaction histories. Revolut said a limited number of customers were affected and that its systems and customer funds were unaffected.
Takeaway: A request from a real government email domain is not proof of a real government request; disclosure to authorities needs its own verification step.
Source: techcrunch.com (press report)Read analysis about RevolutXinbi Guarantee
—Sanctions violationUSOFAC
OFAC designated Xinbi Guarantee, a Telegram-based marketplace serving Southeast Asian scam centres, as a transnational criminal organization, together with two app developers. Its SDN entry lists 52 TRON addresses. Treasury says the marketplace processed the equivalent of over 24 billion dollars in digital assets and fiat currency since around 2022.
Takeaway: Scam-centre marketplaces settle in stablecoins on public chains; the listed wallet addresses are the part of a designation a crypto platform can actually screen.
Source: home.treasury.govRead analysis about Xinbi GuaranteeIDScan.net
—Data breachUS—
IDScan.net said that on or around 1 September 2026 it received information indicating that certain data may have been accessed without authorization, and that it secured its systems and engaged outside experts. It has not confirmed the scale. A dark web service had advertised more than 153 million US and Canadian driver’s license scans, and nine class actions were filed against the company in the Eastern District of Louisiana between 2 and 4 September.
Takeaway: An ID scanning vendor that keeps the scans holds every customer’s identity documents at once; retention is the exposure.
Source: idscan.net (company disclosure)Read analysis about IDScan.netCitibank, N.A., London Branch
£4.73MSanctions violationUKOFSI
OFSI imposed a penalty of 4,732,830.58 pounds on 11 August 2026, published on 2 September, for 970 payments worth 19,720,127.43 pounds that breached UK sanctions. The notice traces the breaches to screening gaps, alert backlogs and an ownership determination OFSI found unreasonable.
Takeaway: Screening that ignores a corporate legal-form prefix misses the sanctioned company it is looking at.
Source: assets.publishing.service.gov.ukRead analysis about Citibank, N.A., London BranchQuinnBet (Gibraltar)
£609,104AML/BSA fineUKGambling Commission
QuinnBet agreed to pay 609,104 pounds, including 193,118 pounds of disgorgement, after the Gambling Commission found its anti-money laundering and customer interaction controls were not effective in practice for 29 months. A platform migration had switched off working limits.
Takeaway: A migration that silently drops a control is a control failure from the day it ships.
Source: gamblingcommission.gov.ukRead analysis about QuinnBet (Gibraltar)Rice Lake Weighing Systems
$60,764Sanctions violationUSOFAC
OFAC settled eight apparent violations covering roughly 121,527 dollars of goods, after the company’s Italian subsidiary shipped to Iran through a distributor in the United Arab Emirates.
Takeaway: Sanctions rules bind entities that US persons own or control almost as tightly as the parent itself.
Source: ofac.treasury.govRead analysis about Rice Lake Weighing SystemsUBS Financial Services
$125MAML/BSA fineUSFinCEN
FinCEN imposed a 125 million dollar penalty, its largest ever on a broker-dealer, after more than 61,500 foreign currency wires worth over 10.5 billion dollars went unmonitored between January 2019 and June 2023. The firm admitted it never closed the gaps a 2018 consent order required it to fix.
Takeaway: An unremediated consent order compounds: the second penalty prices in the first.
Source: fincen.govRead analysis about UBS Financial ServicesWise US Holdings
—KYC failureUSOCC
The OCC denied Wise a national trust bank charter, ruling it could not confirm an effective anti-money laundering programme while a 2025 multistate order over late suspicious activity reports and transaction monitoring data integrity remained unresolved.
Takeaway: An open AML order is a licensing blocker, not just a remediation project.
Source: occ.govRead analysis about Wise US HoldingsLandesbank Hessen-Thüringen (Helaba)
—KYC failureGermanyBaFin
BaFin ordered Helaba to remedy customer due diligence failures spanning customer identification, verification, updating of customer data, risk analysis and transaction monitoring. It is the second BaFin money laundering measure against the bank in seven months.
Takeaway: A remediation order with no fine still creates a supervisory record that the next measure builds on.
Source: bafin.deRead analysis about Landesbank Hessen-Thüringen (Helaba)Swedbank
$50MAML/BSA fineUSNYDFS
New York’s Department of Financial Services secured a 50 million dollar penalty from Swedbank and its New York branch for withholding information about its Baltic subsidiaries’ links to the Panama Papers, across responses spanning 2016 to 2019.
Takeaway: The concealment was punished on its own, separately from the underlying money laundering.
Source: dfs.ny.govRead analysis about SwedbankCCV Group
€2.66MAML/BSA fineNetherlandsDNB
De Nederlandsche Bank fined the payment institution 2,656,250 euros after roughly 4,200 merchants sat outside its transaction monitoring system for 23 months, with alerts closed in bulk and no recorded justification. The penalty was raised because CCV had breached the same rule before.
Takeaway: Coverage gaps outrank tuning: a merchant outside the system generates no alerts to calibrate.
Source: dnb.nlRead analysis about CCV GroupAssuranceAmerica
—Data breachUS—
The Atlanta auto insurer disclosed a breach affecting 6,998,886 people, exposing names, contact details and driver’s license numbers after an employee’s credentials were compromised.
Takeaway: Driver’s license numbers retained after a verification check are a standing liability, not a record.
Source: techcrunch.com (press report)Read analysis about AssuranceAmericaABN AMRO
€8.5MAML/BSA fineNetherlandsDNB
De Nederlandsche Bank fined ABN AMRO 8.5 million euros for inadequate due diligence on high-risk customers, finding monitoring insufficiently critical and customer explanations accepted without verification. It follows a 480 million euro criminal settlement five years earlier.
Takeaway: Accepting a customer explanation without verifying it is not ongoing monitoring.
Source: dnb.nlRead analysis about ABN AMROPCC money laundering network
—Sanctions violationUSOFAC
OFAC blocked a network that moved more than 30 million dollars of US drug proceeds through cryptocurrency for Brazil’s PCC, designating two Brazilian nationals and four companies. Brazil then froze roughly 2 billion dollars in related assets.
Takeaway: Crypto rails do not remove the sanctions nexus; they only change which intermediary sees the transaction.
Source: home.treasury.govRead analysis about PCC money laundering networkEagleBank
$9.79MAML/BSA fineUSDOJ
EagleBank agreed to pay 9,057,821 dollars in fines plus 736,515 dollars in forfeiture under a non-prosecution agreement, admitting it wilfully failed to run an anti-money laundering programme from 2010 to 2021 while executives overrode compliance staff.
Takeaway: Where senior management overrides compliance, the programme on paper counts for nothing.
Source: justice.govRead analysis about EagleBankMerrill Lynch
$7.5MAML/BSA fineUSSEC
The SEC fined Merrill 7.5 million dollars because its transaction monitoring system only investigated alerts scoring 20 or higher, after Merrill’s own analysis showed lower-scoring events would have produced suspicious activity reports. It took about three years to fix.
Takeaway: A monitoring threshold you know is miscalibrated is a documented failure, not a tuning decision.
Source: sec.govRead analysis about Merrill LynchCACEIS UK
£31.7M redressIntegrity/governanceUKFCA
The FCA publicly censured CACEIS UK for weak financial crime controls that let the collapsed wealth manager WealthTek hold client assets it was never permitted to hold. It avoided a financial penalty that the FCA put at about 23.1 million pounds after a 30 percent settlement discount, and agreed a voluntary payment of 31,714,068 pounds to affected clients.
Takeaway: Redress paid to clients is not a penalty, but the permission-scope check that failed is exactly what onboarding due diligence exists to catch.
Source: fca.org.ukRead analysis about CACEIS UKForeign bank branch (unnamed) and its head of compliance
AED 20MAML/BSA fineUAECBUAE
The Central Bank of the UAE fined a foreign bank branch 20 million dirhams for repeated anti-money laundering and sanctions control failures, and separately fined its head of compliance 300,000 dirhams.
Takeaway: Personal liability for the compliance officer is now a live tool, not a theoretical one.
Source: centralbank.aeRead analysis about Foreign bank branch (unnamed) and its head of compliancePrince Group
—Sanctions violationUSOFAC, FinCEN
Treasury widened its action against the Cambodian scam conglomerate, adding 9 individuals and 26 entities, while FinCEN moved to sever the renamed Huione affiliate H-Pay from the US financial system.
Takeaway: Designated networks rename and re-form. Screening against a static entity list misses the successor.
Source: home.treasury.govRead analysis about Prince GroupIkano Bank
SEK 140MAML/BSA fineSwedenFinansinspektionen
Sweden’s financial supervisor fined Ikano Bank 140 million kronor and issued a formal remark for failing to assess how its corporate products could be used to fund crime. No laundering case was alleged.
Takeaway: The general risk assessment is itself an enforceable obligation, independent of whether any transaction went wrong.
Source: fi.seRead analysis about Ikano BankPoste Italiane and Postepay
€12.5MGDPR enforcementItalyGarante per la protezione dei dati personali
Italy’s data protection authority fined Poste Italiane 6,624,000 euros and Postepay 5,877,000 euros for embedding device-surveillance software in banking apps and making consent to it a condition of account access.
Takeaway: A fraud-prevention purpose does not by itself satisfy the GDPR necessity test if a less intrusive control would have worked.
Source: garanteprivacy.itRead analysis about Poste Italiane and PostepayBank of London Group
£2MIntegrity/governanceUKPRA
The PRA fined Bank of London Group £2 million for integrity failings and inadequate cooperation over misrepresenting its capital position.
Takeaway: Regulators want the data trail behind the numbers: source, calculation, sign-off, validation date.
Source: bankofengland.co.ukRead analysis about Bank of London GroupRanson Houghton LLP
£10,283AML/BSA fineUKSRA
The SRA fined Ranson Houghton LLP for AML failures, signalling AML enforcement expanding beyond banks into legal services.
Takeaway: AML obligations now bite professional-services firms, not just financial institutions.
Source: sra.org.ukRead analysis about Ranson Houghton LLPEU GDPR Transparency Sweep (EDPB)
—GDPR enforcementEUEDPB / 25 EU DPAs
25 EU regulators launched a coordinated GDPR transparency enforcement sweep affecting how KYC flows present data processing.
Takeaway: KYC data-collection transparency is now a coordinated enforcement priority.
Source: edpb.europa.euRead analysis about EU GDPR Transparency Sweep (EDPB)Canaccord Genuity
$80MAML/BSA fineUSFinCEN
FinCEN assessed an 80 million dollar penalty, its largest ever against a broker-dealer, for years of gamed trade surveillance and at least 160 suspicious activity reports that were never filed.
Takeaway: Regulators judge an AML programme by what it catches, not by what the written policy says it should catch.
Source: fincen.govRead analysis about Canaccord GenuityIDMerit
—Data breachUS—
Cybernews reported an unsecured database it linked to IDMerit that exposed about one billion personal records across 26 countries, over 203 million of them from the United States. IDMerit told Cybernews it does not own, control or store the underlying data. The database was found on 11 November 2025 and secured the next day.
Takeaway: A large central store of identity records is a target in itself; Cybernews describes this one as unprotected rather than broken into.
Source: cybernews.com (researchers)Read analysis about IDMeritSumsub
—Data breachGlobal—
A breach via a malicious attachment on a third-party support platform went undetected for 18 months (Jul 2024–Jan 2026).
Takeaway: A centralised KYC provider is only as secure as its weakest integration; 18-month dwell time is a monitoring failure.
Source: sumsub.com (company disclosure)Read analysis about SumsubDiscord
—Data breachGlobal—
A third-party customer service vendor was compromised, exposing roughly 70,000 government ID photos that the vendor held to review age-related appeals.
Takeaway: Age assurance built on stored ID images moves the honeypot to whichever vendor reviews the appeals.
Source: discord.com (company disclosure)Read analysis about DiscordCoinbase
$180M to $400M est. costData breachUS—
Coinbase disclosed that a threat actor had paid contractors or employees in support roles outside the United States to collect customer data from internal systems, including names, contact details, masked Social Security and bank account numbers, government ID images and balance snapshots, then demanded money not to publish it. Coinbase refused to pay and estimated the cost at about 180 million to 400 million dollars.
Takeaway: An insider/controls failure, not a hack. Privileged access to a central PII store is the attack surface.
Source: sec.gov (company disclosure)Read analysis about CoinbaseTD Bank
$3BAML/BSA fineUSDOJ, FinCEN, OCC, Federal Reserve
TD Bank pleaded guilty and paid about $3 billion for Bank Secrecy Act and money-laundering failures — the largest bank ever to plead guilty to conspiracy to commit money laundering. ~$1.8B DOJ, $1.3B FinCEN, $450M OCC, $123.5M Federal Reserve.
Takeaway: More than 90% of transaction volume was never fed into automated monitoring — a coverage gap, not a tuning problem.
Source: justice.govRead analysis about TD BankBinance
$4.3BAML/BSA fineGlobal/USDOJ, FinCEN, OFAC, CFTC
Binance agreed to pay more than $4.3 billion to US authorities; founder CZ pleaded guilty, paid a $50M personal fine and stepped down. FinCEN $3.4B civil penalty + 5-year monitorship; OFAC $968M.
Takeaway: Compliance-light by design is now treated as a federal crime, not a growth tactic.
Source: justice.govRead analysis about Binance
Several of these penalties, among them TD Bank, UBS, Canaccord Genuity, Merrill Lynch and CCV, turn on transaction monitoring that did not cover, or did not escalate, what it should have. If you are checking your own rules against these cases, our AML software lets you dry-run a rule against your own transaction history before it goes live, and our transaction monitoring alert triage desk drafts the disposition of each alert for your investigators to decide.
Open data
Download it, cite it, keep it
The full dataset is free to use under CC BY 4.0. Take the file, not a screenshot.
- enforcement.csv CSV · 32 rows · spreadsheet-ready
- enforcement.json JSON · records plus licence, fields and change history
- enforcement.xml RSS · new actions as they land
- breaches.csv CSV · the 7 identity-data breaches only
The files are UTF-8 with one header row, and every column is defined in the
data dictionary. Every record has a
permanent id and its own link: append the id to the tracker URL, for example
#td-bank,
and the link resolves to that row. The id does not change when a record is corrected.
How to cite
Zyphe (2026). AML Enforcement Tracker [dataset], version of 1 October 2026. https://www.zyphe.com/resources/aml-enforcement-tracker. Licensed under CC BY 4.0.
To cite one record, quote the figure as announced, link the record’s permanent URL and, where you can, the source it links to. The version date tells readers which state of the data you used.
Licensed under CC BY 4.0. Reuse the figures, charts and rows in reporting, research or internal training, including commercially, as long as you credit Zyphe and link back to this page.
Writing about one of these actions and want the underlying detail, or a comment on what it changes for compliance teams? Email hello@zyphe.com.
Methodology
How this tracker is sourced
What counts as a record, where each one comes from, and how the figures are stated.
What counts as a record
A record is an enforcement action, sanctions action or supervisory measure that an authority has announced, or an identity-data breach that has been publicly disclosed, where the failure concerns anti-money laundering, sanctions, customer due diligence or the handling of identity data. The tracker is a curated selection, not a census of every action an authority takes: every record links to Zyphe’s own analysis of it.
There is no minimum amount. The smallest penalty in the file is £10,283 (Ranson Houghton LLP). In all, 15 of the 32 records carry no penalty, such as breaches, sanctions designations and supervisory orders. The file holds no proposed rules, consultations or guidance.
The 20 authorities that appear in it are 25 EU DPAs, BaFin, CBUAE, CFTC, DNB, DOJ, EDPB, FCA, Federal Reserve, Finansinspektionen, FinCEN, Gambling Commission, Garante per la protezione dei dati personali, NYDFS, OCC, OFAC, OFSI, PRA, SEC, SRA.
Where each record comes from
Every record links one source and says what kind of source it is. The authority’s own announcement or decision is used wherever one exists. Breaches rarely have one, so their records link the company’s own disclosure where there is one, otherwise the researchers who found the exposure or a named news outlet. In the table, any source that is not the authority’s own is labelled next to its link.
| Source type | What it is | Records |
|---|---|---|
| authority Authority | The regulator’s, prosecutor’s or court’s own announcement, order or decision. | 25 |
| company Company disclosure | The company’s own advisory, press release or regulatory filing about the incident. | 4 |
| researcher Researchers | The security researchers who found the exposure, publishing their own findings. | 1 |
| press Press report | A named news outlet’s report, used only where no authority or company source is linked. | 2 |
The summary is a factual account written by Zyphe from the source. The takeaway is Zyphe’s editorial view and is not part of the source.
How amounts and dates are stated
The amount column shows the figure as announced, in its original currency. A second, approximate US dollar figure sorts the column and adds up to the headline total; for penalties announced in another currency it is a rounded conversion, and the dataset does not record the rate or date used, so quote the figure as announced. Where several authorities or companies share one resolution, the record carries the combined figure and the summary gives the split. Redress, voluntary payments and estimated breach costs are not penalties: they appear in the amount column but count as zero in the total. A dash means there is no figure.
The date is the day the authority announced the action or, for a breach, the day it was first publicly disclosed or reported. That can be months after the conduct or the intrusion; the summary gives those dates where they matter. The jurisdiction is where the authority sits, or for a breach the jurisdiction most affected, or Global.
Action types
- AML/BSA fine.
- A monetary penalty or settlement over anti-money laundering or counter-terrorist financing failures, in any country.
- Sanctions violation.
- A sanctions action: a settlement of apparent violations, or designations that block a network.
- KYC failure.
- A supervisory measure over customer due diligence that carries no fine, such as a remediation order or a refused charter.
- GDPR enforcement.
- A data protection authority’s fine or coordinated enforcement action.
- Integrity/governance.
- An action over integrity, governance or financial crime controls that fits none of the above, such as a censure.
- Data breach.
- A publicly disclosed exposure of identity data. No penalty is recorded unless one was separately imposed.
Updates and corrections
Records are added by hand from actions Zyphe has analysed, with no fixed schedule, so check the date the dataset was last updated, shown above and in the JSON and RSS files. A corrected record keeps its id and permanent link, its record_updated date changes, and the correction is listed in the change history. Substantive corrections are also logged on our sitewide corrections page.
Spotted an error, or have a source to add? Email hello@zyphe.com with the record’s link and, if you have it, the primary source.
Data dictionary
What each column means
The same fields in every export: CSV column names on the left, JSON field names beside them.
| CSV column | JSON field | Meaning |
|---|---|---|
| entity | entity | The firm, network or institution the action concerns, or the company that disclosed the breach. |
| regulator | regulator | The authority or authorities that acted, abbreviated. Empty for a breach with no regulatory action recorded. |
| jurisdiction | jurisdiction | Where the authority sits. For a breach, the jurisdiction most affected, or Global. |
| action_type | actionType | One of six categories, defined in the methodology. |
| amount_usd | amountUsd | The monetary penalty in approximate US dollars, used to sort the table and compute the total. 0 when there is no penalty, including redress, voluntary payments and breach costs. |
| amount_display | amountDisplay | The figure as announced, in its original currency, or the redress or estimated cost when that is the only figure. Empty when there is none. |
| date | date | The date the authority announced the action, or the date the breach was first publicly disclosed or reported (YYYY-MM-DD). |
| year | year | The year of date. |
| summary | summary | A factual summary written by Zyphe from the source. |
| lesson | lesson | Zyphe’s compliance takeaway. Editorial opinion, not part of the source. |
| source_url | sourceUrl | Link to the source the record is built on. |
| zyphe_analysis_url | zypheAnalysisUrl | Zyphe’s article on the action or breach. |
| record_url | recordUrl | Permanent link to the record on the tracker page. |
| id | id | The record’s permanent identifier, also the fragment of record_url. It does not change when the record is corrected. |
| source_type | sourceType | Where the source comes from: authority, company, researcher or press. |
| record_updated | recordUpdated | The date the record was last changed (YYYY-MM-DD). |
breaches.csv carries the identity-data breach records with the columns that apply to them, the same id to join on, and a tracker_post_url pointing at the KYC breach tracker. enforcement.json adds the licence, the suggested citation, these definitions and the change history.
Change history
What changed, and when
Every addition, correction, source change and format change to the dataset, newest first.
-
· Correction
The summary stated as fact that IDMerit left the records exposed. It now attributes the finding to Cybernews, the cited source, and records IDMerit's statement to Cybernews that it does not own, control or store the underlying data.
-
· Correction
The record put the estimated cost at about 400 million dollars and cited a press report. It now cites Coinbase's Form 8-K of 15 May 2025, gives the filing's estimate of 180 million to 400 million dollars, and describes the incident in the filing's terms. A count of about 70,000 affected users and the name of a support contractor were removed because the filing does not state them.
-
· Correction
The summary said CACEIS UK avoided a 33 million pound fine, which is the penalty before the settlement discount. The FCA's announcement, the cited source, puts the penalty it would have imposed at about 23.1 million pounds after the 30 percent discount, and the summary now uses that figure.
-
· Source link
The source link pointed at BaFin's rolling list of measures, which no longer shows the July 2026 order. It now points at BaFin's notice of 20 July 2026 itself.
-
· Source link
Source links moved to the addresses at which the Department of Justice and the EDPB now publish the same announcements.
-
· Format
Every record now states its source type, one of the authority's own announcement or decision, a company disclosure, a researchers' disclosure or a press report. The CSV and JSON files gain three fields, id, source_type and record_updated, and a breach with no regulator has an empty regulator field instead of a dash. RSS items analysed in a news article now link to it; they had pointed at a blog address that does not exist.
-
· Added
5 records added.
Tren de Aragua ATM jackpotting network , Revolut , Xinbi Guarantee , IDScan.net , Citibank, N.A., London Branch
-
· Format
Added breaches.csv, the identity-data breach records as a file of their own, linked from the KYC breach tracker.
-
· Correction
None of the 8 original records linked a source, and five carried a placeholder date of 1 January 2026. All 8 now link their source and carry the date the action or breach was announced.
Binance , TD Bank , Coinbase , Sumsub , IDMerit , EU GDPR Transparency Sweep (EDPB) , Ranson Houghton LLP , Bank of London Group
-
· Format
Added enforcement.csv and enforcement.json, and a permanent link to every record.
-
· Added
19 records added.
QuinnBet (Gibraltar) , Rice Lake Weighing Systems , UBS Financial Services , Wise US Holdings , Landesbank Hessen-Thüringen (Helaba) , Swedbank , CCV Group , AssuranceAmerica , ABN AMRO , PCC money laundering network , EagleBank , Merrill Lynch , CACEIS UK , Foreign bank branch (unnamed) and its head of compliance , Prince Group , Ikano Bank , Poste Italiane and Postepay , Canaccord Genuity , Discord
-
· Format
Added the RSS feed, enforcement.xml.
-
· Added
8 records added.
Bank of London Group , Ranson Houghton LLP , EU GDPR Transparency Sweep (EDPB) , IDMerit , Sumsub , Coinbase , TD Bank , Binance
Book a demo
Eliminate risk and work smarter with Zyphe AI
Book a demo with our team. See agents triage L1 alerts, complete EDD cases, and run KYB reviews against your real workflows.