Learn more about the latest security and privacy threats
Back

Swedbank NYDFS penalty: 50 million dollars for hiding Panama Papers links

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published July 20, 2026 Reviewed by Charlene Wang
Editorial illustration for the article "Swedbank NYDFS penalty: 50 million dollars for hiding Panama Papers links".

New York's DFS hit Swedbank with a 50 million dollar penalty for withholding Baltic subsidiary and Panama Papers data from its regulators. What it means.

Table of contents

The Swedbank NYDFS penalty is a 50 million dollar settlement, signed on 15 July 2026 and approved by New York's financial regulator on 16 July 2026, over the bank withholding information about its Baltic subsidiaries' links to the Panama Papers. The regulator punished the concealment itself, not the underlying money laundering, across responses spanning 2016 to 2019.

  • New York's Department of Financial Services (DFS) secured a 50 million dollar civil penalty from Swedbank AB and its New York Branch for failing to produce responsive information to three special-report requests.
  • The violation is not money laundering. It is the deliberate carve-out of the bank's Estonia, Latvia and Lithuania subsidiaries from what DFS asked for.
  • A compliance officer wrote, in an internal message quoted in the consent order, that removing the Baltics from scope was the point.
  • The order cites New York Banking Law section 125(3), the transparency duty that a foreign bank branch owes its host regulator.
  • It is the third public enforcement action against Swedbank tied to its Baltic operations, after a 2020 Swedish fine and a 2023 OFAC settlement.

What did the Swedbank NYDFS penalty actually punish?

The Swedbank NYDFS penalty punishes a failure to cooperate, not a failure to detect crime. DFS found that when it asked Swedbank about its exposure to the Panama Papers, the bank answered as if only its New York Branch mattered and quietly excluded its Baltic subsidiaries, where the real connections sat.

The Panama Papers, roughly 11.5 million records leaked from the law firm Mossack Fonseca on 3 April 2016, named Swedbank customers. Within days, the bank's own compliance chief told the board that Swedbank Estonia had identified clients using Mossack Fonseca as a registered agent, and that a 2015 payment by a Lithuanian customer traced to a politically exposed person. DFS opened its inquiry on 19 April 2016.

The bank's New York Branch replied on 27 April 2016 that it was unaware of relevant connections. That answer was narrowly true for the branch and materially incomplete for the group. The most damaging evidence is an internal line from the bank's then chief compliance officer, quoted in the consent order, explaining why the Baltic units were cut from a later production: "That's why I wanted to remove them out of the scope". DFS treated that as intent, not oversight.

FactDetail
Penalty50,000,000 dollars
Order signed15 July 2026, approved 16 July 2026
RegulatorNew York State Department of Financial Services
Legal basisNew York Banking Law sections 37, 39, 44 and 125(3)
ConductWithholding responsive information across 2016 to 2019

How did Swedbank withhold the information?

Swedbank withheld information through three regulatory cycles, each time reading the Baltic subsidiaries out of a request that plainly covered them. The pattern matters because it turns a single lapse into a documented course of conduct, which is what elevated the Swedbank NYDFS penalty from a technical finding to a 50 million dollar settlement.

In 2018, external counsel told DFS the request covered the bank's "global operations" and that Swedbank would search its head office and global branch network. It did not. On 24 March 2018 a staffer flagged that a prior Baltic search returned many Mossack Fonseca matches, and the compliance officer replied that this was exactly why she wanted them out of scope. The March and April 2018 responses omitted the Baltics entirely and mis-stated a Swedish supervisory review as clean, when in fact the regulator had issued three improvement recommendations.

DateEvent
3 April 2016Mossack Fonseca leak names Swedbank customers
19 April 2016DFS issues its first special-report request
27 April 2016New York Branch replies, omits group exposure
21 February 2018DFS issues a follow-up request
March to April 2018Bank responses exclude the Baltic subsidiaries
20 February 2019DFS issues a third request after media reports
6 March 2019First substantive Baltic documents produced

What does the Swedbank NYDFS penalty change for your obligations?

The Swedbank NYDFS penalty sharpens a duty many teams treat as procedural: when a regulator requests information, the response must be complete, accurate and truthful across the whole regulated group, not just the entity that received the letter. The order rests on New York Banking Law section 125(3), the reporting-accuracy duty for foreign branches, and section 37, the Superintendent's power to demand special reports.

For customer due diligence and enhanced due diligence, the case is a reminder that adverse findings do not stay local, a point that also runs through recent broker-dealer actions such as Canaccord's record FinCEN penalty. Swedbank held knowledge of Mossack Fonseca links, politically exposed persons and foreign supervisory inquiries at head office while its branch pleaded ignorance. Under a group-wide programme, that knowledge should have surfaced to the regulator. Firms should map which entity holds which record and confirm that a request to one unit triggers a search across affiliates that share customers and compliance systems.

For record-keeping and disclosure, the lesson is to evidence scope. DFS could reconstruct exactly what Swedbank searched, what it found and what it chose not to send. Compliance teams should be able to show the same audit trail in reverse: the request, the search parameters, the responsive material and the sign-off. Characterising a foreign regulator's review as free of "adverse findings" when it carried recommendations was itself treated as a misstatement, so how you summarise other supervisors' conclusions is now a live risk.

What is still uncertain after the Swedbank NYDFS penalty?

Three things remain unresolved: whether DFS pursues the underlying Baltic money laundering, whether any individual faces personal sanction, and how firms reconcile a United States production demand with European bank-secrecy law. The consent order expressly reserves DFS's right to act on transactions or conduct that Swedbank did not disclose, so the Swedbank NYDFS penalty may not close the file. Other agencies are not bound by this settlement either.

Individual accountability is the sharpest uncertainty. The bank dismissed the compliance officer and its former chief executive, and most of the board was replaced, yet the order itself names no individuals and imposes no personal bars. Regulators increasingly pursue named compliance leaders, and the quoted internal messages are the kind of evidence that supports that. Whether any authority follows the paper trail to a person is unresolved.

There is also a genuine scope tension for honest firms. A regulator's request can be ambiguous, and reading it narrowly is sometimes defensible rather than evasive. The safe reading after this case is to raise scope questions with the regulator in writing rather than resolve them unilaterally and silently. Cross-border data and bank-secrecy rules complicate that, because producing Baltic subsidiary records to a United States regulator can collide with local privacy law, and the order offers no guidance on squaring the two.

How does the Swedbank NYDFS penalty compare with past fines?

The Swedbank NYDFS penalty is smaller in dollars than the bank's earlier sanctions but distinct in kind, because it targets candour toward a regulator rather than transaction monitoring. Set against precedent, 50 million dollars for withholding information is a substantial figure, and it lands on a bank that has already paid heavily for the same Baltic operations.

DateAuthorityAmountBasis
March 2020Swedish FSA (Finansinspektionen)SEK 4 billion (around 390 million dollars)AML control failures in Baltic operations, 2007 to 2019
June 2023OFAC (US Treasury)3,430,900 dollars386 apparent Crimea sanctions breaches via the Latvian unit
July 2026NYDFS50,000,000 dollarsWithholding responsive information from the regulator

The through-line across all three is the same set of Baltic subsidiaries and the same underlying problem: a group that treated non-resident, offshore-heavy business as someone else's risk, the same failure mode behind older bank cases like the EagleBank BSA settlement. Reducing how much sensitive customer data any single entity holds, and how much of it must be handed around during an inquiry, is one structural way to shrink that surface.

How should compliance teams respond?

Treat every regulatory request as group-wide by default, and confirm scope in writing before you narrow it. Build a defensible audit trail that records the request, the entities searched, the responsive material and the approver. Reconcile how you describe other supervisors' findings, because understating a foreign regulator's recommendations was itself penalised here. Escalate any decision to exclude an affiliate to senior legal, not to a compliance inbox.

Structurally, the exposure grows with how much personal and KYC data each entity hoards. Zyphe takes a different route: identity is verified once across a distributed network of 60,000 plus nodes, personal data is sharded so no single node holds a complete record, and the customer keeps the key, so there is no central honeypot to withhold, leak or misreport. That model, explained in how Zyphe works and applied in our KYB software, means verification results carry a per-region audit trail you can hand a regulator without shipping raw customer files across borders. To see how that maps to your onboarding stack, book a demo.

The bottom line

The Swedbank NYDFS penalty is a warning about candour, not detection. A bank can pass its transaction-monitoring reviews and still face a heavy penalty for how it answers a regulator. For teams running KYC and AML programmes, the takeaways are to treat requests as group-wide, to evidence exactly what was searched and sent, and to raise scope disputes openly. The less sensitive data any single entity holds, the smaller the temptation, and the risk, of getting that answer wrong.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

It is a 50 million dollar civil penalty imposed by the New York State Department of Financial Services, signed on 15 July 2026 and approved on 16 July 2026. Swedbank failed to produce responsive information to three special-report requests, deliberately excluding its Baltic subsidiaries and their Panama Papers connections from what it sent the regulator.

No. This action punishes the withholding of information from a regulator, not the underlying money laundering. DFS reserved the right to pursue undisclosed conduct separately, so the underlying Baltic exposure is not necessarily resolved by this settlement.

The consent order cites New York Banking Law section 125(3), the reporting-accuracy duty owed by a foreign bank branch, alongside section 37, which lets the Superintendent demand special reports, and sections 39 and 44, which provide the penalty authority.

Yes. Sweden's Finansinspektionen fined Swedbank SEK 4 billion in 2020 for anti-money laundering control failures, and OFAC settled with Swedbank Latvia for about 3.4 million dollars in 2023 over Crimea sanctions breaches. This is the third public action tied to the same operations.

When a regulator asks for information, answer for the whole regulated group, confirm scope in writing before narrowing it, and keep an audit trail of what you searched and produced. Reading a request narrowly and silently is the behaviour that turned a data problem into a 50 million dollar penalty.

See privacy-first KYC in action

Verify identity without storing a single document. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo