AML enforcement in 2026 so far, from Zyphe's open dataset: 23 actions, about $324 million in penalties, three fines carrying 79 percent, and what repeats.
Table of contents
- Zyphe's open AML enforcement dataset holds 23 actions dated in 2026 as of 18 September, with about 324 million US dollars in recorded penalties across 14 of them. Nine actions carried no monetary penalty: charter denials, remediation orders, censures, sanctions designations and identity-data breaches.
- Three fines account for 79 percent of the year's total: FinCEN's 125 million dollar penalty against UBS Financial Services, FinCEN's 80 million dollar penalty against Canaccord Genuity, and the New York Department of Financial Services' 50 million dollar penalty against Swedbank.
- FinCEN alone accounts for 205 million dollars, or 63 percent of the 2026 total, from two broker-dealer cases.
- The median penalty among actions with a recorded amount is about 8.6 million dollars, which is where most of the year's supervisory activity actually sits.
- Eleven of the 23 actions were classic AML or Bank Secrecy Act fines. The rest split between identity-data breaches, sanctions actions, customer due diligence orders with no fine, governance findings and GDPR enforcement aimed at KYC data.
- The third quarter to date logged 10 actions and about 189 million dollars, most of it the UBS and Swedbank penalties in a five-week window in July and August.
AML enforcement is the set of penalties, orders, censures and public actions that regulators and prosecutors take against firms for failures in anti-money laundering controls, including customer due diligence, transaction monitoring, suspicious activity reporting and sanctions screening. This edition counts the actions Zyphe has logged with a primary source for 2026 so far.
TL;DR
As of 18 September 2026 the dataset behind our AML enforcement tracker holds 23 actions dated this year, about 324 million dollars in penalties, and three fines that make up 79 percent of that total. FinCEN drove 63 percent of the money from two cases. The typical action, once the three outliers are set aside, is a single-digit-million penalty for monitoring that did not produce reports or due diligence that was not refreshed. Identity-data breaches, sanctions designations and orders with no fine attached are a third of the year's entries, which is why counting only fines undercounts the year. Every number below links to its row and its primary source.
How much did AML enforcement cost in 2026 so far?
| Measure | Value as of 18 September 2026 |
|---|---|
| Actions logged, dated 2026 | 23 |
| Actions with a recorded monetary penalty | 14 |
| Penalties recorded, converted to US dollars at the rate on the record | about 324 million dollars |
| Largest single penalty | 125 million dollars, UBS Financial Services, FinCEN |
| Median penalty among the 14 with an amount | about 8.6 million dollars |
| Smallest recorded penalty | 10,283 pounds, Ranson Houghton LLP, Solicitors Regulation Authority |
| Actions with no monetary penalty | 9 |
| Records in the whole dataset since November 2023 | 27 |
The total is dominated by three cases and the median tells the truer story. Half of the penalised firms paid less than 8.6 million dollars, and the actions with no penalty attached, a denied bank charter for Wise, a supervisory order for Helaba, a censure with 31.7 million pounds of client redress for CACEIS UK, two OFAC designations, an EU-wide GDPR sweep and three breaches, are the ones compliance teams should read most carefully, because they show what regulators act on before the fine arrives.
Which AML enforcement actions were the largest of 2026?
| Rank | Firm | Regulator | Penalty | Date | What the record says |
|---|---|---|---|---|---|
| 1 | UBS Financial Services | FinCEN | 125 million dollars | 3 August 2026 | Second penalty for a broker-dealer AML programme under an unremediated consent order |
| 2 | Canaccord Genuity | FinCEN | 80 million dollars | 6 March 2026 | AML programme judged by what it caught, not what the written policy said |
| 3 | Swedbank | NYDFS | 50 million dollars | 16 July 2026 | Concealment from the supervisor punished separately from the underlying laundering |
| 4 | Ikano Bank | Finansinspektionen | 140 million Swedish kronor | 17 June 2026 | The general risk assessment treated as an enforceable obligation on its own |
| 5 | Poste Italiane and Postepay | Garante | 12.5 million euros | 17 April 2026 | GDPR necessity test applied to fraud-prevention device surveillance |
The three largest together are 255 million dollars, 79 percent of the year. Our analyses of each sit behind the tracker rows: the UBS penalty, the Canaccord penalty and the Swedbank penalty. The two FinCEN cases are both broker-dealers, and both records turn on the gap between the programme on paper and the alerts it generated, which is the same finding FinCEN made against TD Bank in 2024 at twenty-four times the size.
Which regulators drove AML enforcement in 2026?
| Regulator | Actions | Penalties recorded |
|---|---|---|
| FinCEN (United States) | 2 | 205 million dollars |
| NYDFS (New York) | 1 | 50 million dollars |
| Finansinspektionen (Sweden) | 1 | 140 million kronor, about 15.1 million dollars |
| Garante (Italy) | 1 | 12.5 million euros, about 14.6 million dollars |
| De Nederlandsche Bank (Netherlands) | 2 | 11.16 million euros combined, about 13 million dollars |
| Department of Justice (United States) | 1 | 9.79 million dollars |
| SEC (United States) | 1 | 7.5 million dollars |
| Central Bank of the UAE | 1 | 20 million dirhams, about 5.4 million dollars |
| PRA (United Kingdom) | 1 | 2 million pounds |
| UK Gambling Commission | 1 | 609,104 pounds |
| OFAC (United States) | 3 | 60,764 dollars in one settlement, two designations with no penalty |
| OCC, BaFin, FCA, SRA, EDPB | 5 | one small fine, four actions with no penalty or with redress instead |
FinCEN's two cases are 63 percent of the year's money. Dutch enforcement is the most frequent European source, with DNB fining both ABN AMRO and the payment processor CCV within a week in July. The UK appears four times but for small or non-monetary actions, and the FCA's action was a censure with client redress rather than a fine.
What did AML enforcement look like by type and jurisdiction?
By type of action, 2026 to date:
- AML or Bank Secrecy Act fines: 11
- Identity-data breaches: 3
- Sanctions actions: 3 (one OFAC settlement, two designations)
- Customer due diligence orders with no fine: 2 (Wise, Helaba)
- Integrity and governance findings: 2 (CACEIS UK, Bank of London)
- GDPR enforcement aimed at KYC or customer data: 2 (Poste Italiane, the EDPB transparency sweep)
By jurisdiction: United States 11, United Kingdom 4, Netherlands 2, and one each for Germany, Sweden, Italy, the UAE, an EU-wide action and a global vendor incident. The US share is inflated by the three sanctions entries and two of the three breaches; on the eleven classic AML fines alone the split is US 5, Europe 5 (two UK, two Dutch, one Swedish), UAE 1.
What happened in AML enforcement in the third quarter of 2026?
The quarter to 18 September logged 10 actions and about 189 million dollars. July produced seven of them: the OCC's denial of Wise's bank charter over an open AML order, BaFin's customer due diligence order against Helaba, the Swedbank penalty, the two DNB fines, the AssuranceAmerica breach and OFAC's designation of a PCC laundering network using crypto rails. August produced three: the UBS penalty, the Gambling Commission's 609,104 pound settlement with QuinnBet after a platform migration silently dropped a control, and OFAC's 60,764 dollar settlement with Rice Lake Weighing Systems over a foreign subsidiary. Nothing meeting the inclusion criteria had been logged for September by the 18th.
What do the 2026 AML enforcement findings have in common?
Each row carries a one-line lesson drawn from the regulator's own findings. Grouped, the year reads like this.
- Monitoring that did not produce reports. Merrill Lynch knew a threshold was miscalibrated and left it; CCV had merchants outside the monitored population, so no alerts existed to tune; ABN AMRO accepted customer explanations without verifying them; UBS was penalised a second time under an order it had not remediated. Four of the eleven fines are, at root, transaction monitoring that existed on paper.
- Due diligence not completed or not refreshed. Helaba and ABN AMRO were both acted on for customer due diligence on high-risk or existing customers rather than onboarding, and Wise was refused a bank charter over an unresolved AML order, which is the ongoing half of customer due diligence that budgets tend to forget.
- Governance over the programme. EagleBank's senior management overrode compliance; the Bank of London could not show the data trail behind its numbers; the CBUAE imposed personal liability on a compliance officer; Ikano was fined for the quality of its risk assessment itself.
- The perimeter keeps widening. A solicitors' firm, a payment processor, a gambling operator, an auto insurer holding driver's licence numbers and a weighing-equipment maker's foreign subsidiary all appear. AML enforcement in 2026 is not a banking story.
- Concealment is punished on its own. Swedbank's penalty record separates what was hidden from the supervisor from the underlying failure, and prices the hiding.
How many identity-data breaches were logged in 2026?
Three: the database attributed to IDMerit with roughly one billion records, an attribution the vendor disputes; Sumsub's intrusion through a third-party support platform, undetected for about 18 months; and AssuranceAmerica's breach affecting 6,998,886 people including driver's licence numbers. The dataset holds five breaches in total since May 2025 and publishes them as a separate file, and the narrative log with per-incident analysis is the KYC breach tracker. None of the five involved a cryptographic break; each came through a credential, a misconfiguration, an exposed artefact or a person, which is the argument for not holding the documents at all once the check is done.
How is this AML enforcement dataset compiled?
Inclusion. An action is logged when a regulator, prosecutor or court publishes a penalty, order, censure, designation or denial for an AML, sanctions, KYC or customer-data control failure, or when an identity-data breach is confirmed by the holder, a regulator or two independent named publications. Each row carries the primary source URL, the regulator, the jurisdiction, the type, the date, the amount in the original currency and in US dollars at the rate on the record, a two-sentence summary and a one-line lesson.
Exclusion. Private litigation, unconfirmed press reports, actions with no public record, and ordinary supervisory findings that were not published as enforcement.
Cadence. Rows are added as our daily regulatory news review confirms them, usually within a week of publication. This by-the-numbers edition is published monthly; the figures are as of the date in the title and the tracker page recalculates its headline statistics on every build.
Access. The full dataset is downloadable as CSV, JSON and RSS from the tracker page, which publishes Dataset schema markup and a suggested citation. Each row has a permanent anchor. Corrections are recorded on our corrections page.
How can you use the numbers?
Quote them with the as-of date and link the row. Benchmark your own control failures against the lesson column rather than the amount: the amount reflects the firm's size and history, the lesson reflects the control. Use the no-penalty rows to argue for budget before the fine, since a charter denial or a remediation order costs more than most of this year's fines. And if the pattern in section six describes your monitoring, our AML software evaluates every payment against deterministic rules before it settles and lets you backtest any rule for free on stored transactions, which is the cheapest way to find out whether your thresholds would have caught what the regulators found.
The bottom line
Twenty-three actions, about 324 million dollars, three fines carrying 79 percent of it, and a median under nine million. The headline number will always be set by whichever large institution was under an old order when the year began. The useful signal is in the other twenty rows: the orders with no fine, the small penalties on firms that never thought of themselves as regulated for money laundering, and the same three findings repeating under different regulators' letterheads.
This post is a summary of public records and Zyphe's own dataset, not legal advice. Where a regulator's record and this summary differ, the record is right and we would like to hear about it.
Related resources
- AML enforcement tracker
- KYC and identity verification breach tracker
- FinCEN's 125 million dollar UBS penalty
- FinCEN's 80 million dollar Canaccord penalty
- Swedbank's 50 million dollar NYDFS penalty
- TD Bank's 3 billion dollar AML lesson
- Transaction monitoring
- Customer due diligence
- AML software
Cited sources
- FinCEN, FinCEN assesses historic 125 million dollar penalty against UBS Financial Services Inc.
- FinCEN, FinCEN assesses historic 80 million dollar penalty against Canaccord Genuity LLC
- New York Department of Financial Services, press release of 16 July 2026 on Swedbank
- Finansinspektionen, Ikano Bank receives a remark and an administrative fine
- De Nederlandsche Bank, fine for ABN AMRO Bank N.V. for inadequate customer due diligence for high-risk customers
- Department of Justice, EagleBank agrees to pay more than 9.7 million dollars to resolve Bank Secrecy Act investigation
- SEC, order against Merrill Lynch, Release No. 34-105790
- OCC, decision on Wise US Holdings charter application, CD 1381
- UK Gambling Commission, QuinnBet (Gibraltar) Limited to pay 609,104 pounds for regulatory failures
- TechCrunch, another massive data breach exposed millions of driver's license numbers
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.