- enforcement actions and breaches
- 27 enforcement actions and breaches
- in penalties recorded
- $7.6B in penalties recorded
- jurisdictions covered
- 10 jurisdictions covered
- identity-data breaches
- 5 identity-data breaches
Covering 2023 to 2026. 27 of 27 records link directly to a primary source. Last updated 2026-08-20.
Database
Browse enforcement actions and breaches
Search by entity, regulator, or keyword. Filter by action type, jurisdiction, and year. Sort any column to compare penalties and dates.
Showing 27 of 27 actions
| Jurisdiction | Analysis | |||||
|---|---|---|---|---|---|---|
QuinnBet (Gibraltar) QuinnBet agreed to pay 609,104 pounds, including 193,118 pounds of disgorgement, after the Gambling Commission found its anti-money laundering and customer interaction controls were not effective in practice for 29 months. A platform migration had switched off working limits. Source: gamblingcommission.gov.uk for QuinnBet (Gibraltar) (opens in a new tab) | Gambling Commission | UK | £609,104 | AML/BSA fine | Read analysis about QuinnBet (Gibraltar) | |
Rice Lake Weighing Systems OFAC settled eight apparent violations covering roughly 121,527 dollars of goods, after the company’s Italian subsidiary shipped to Iran through a distributor in the United Arab Emirates. Source: ofac.treasury.gov for Rice Lake Weighing Systems (opens in a new tab) | OFAC | US | $60,764 | Sanctions violation | Read analysis about Rice Lake Weighing Systems | |
UBS Financial Services FinCEN imposed a 125 million dollar penalty, its largest ever on a broker-dealer, after more than 61,500 foreign currency wires worth over 10.5 billion dollars went unmonitored between January 2019 and June 2023. The firm admitted it never closed the gaps a 2018 consent order required it to fix. Source: fincen.gov for UBS Financial Services (opens in a new tab) | FinCEN | US | $125M | AML/BSA fine | Read analysis about UBS Financial Services | |
Wise US Holdings The OCC denied Wise a national trust bank charter, ruling it could not confirm an effective anti-money laundering programme while a 2025 multistate order over late suspicious activity reports and transaction monitoring data integrity remained unresolved. Source: occ.gov for Wise US Holdings (opens in a new tab) | OCC | US | — | KYC failure | Read analysis about Wise US Holdings | |
Landesbank Hessen-Thüringen (Helaba) BaFin ordered Helaba to remedy customer due diligence failures spanning customer identification, verification, updating of customer data, risk analysis and transaction monitoring. It is the second BaFin money laundering measure against the bank in seven months. Source: bafin.de for Landesbank Hessen-Thüringen (Helaba) (opens in a new tab) | BaFin | Germany | — | KYC failure | Read analysis about Landesbank Hessen-Thüringen (Helaba) | |
Swedbank New York’s Department of Financial Services secured a 50 million dollar penalty from Swedbank and its New York branch for withholding information about its Baltic subsidiaries’ links to the Panama Papers, across responses spanning 2016 to 2019. Source: dfs.ny.gov for Swedbank (opens in a new tab) | NYDFS | US | $50M | AML/BSA fine | Read analysis about Swedbank | |
CCV Group De Nederlandsche Bank fined the payment institution 2,656,250 euros after roughly 4,200 merchants sat outside its transaction monitoring system for 23 months, with alerts closed in bulk and no recorded justification. The penalty was raised because CCV had breached the same rule before. Source: dnb.nl for CCV Group (opens in a new tab) | DNB | Netherlands | €2.66M | AML/BSA fine | Read analysis about CCV Group | |
AssuranceAmerica The Atlanta auto insurer disclosed a breach affecting 6,998,886 people, exposing names, contact details and driver’s license numbers after an employee’s credentials were compromised. Source: techcrunch.com for AssuranceAmerica (opens in a new tab) | — | US | — | Data breach | Read analysis about AssuranceAmerica | |
ABN AMRO De Nederlandsche Bank fined ABN AMRO 8.5 million euros for inadequate due diligence on high-risk customers, finding monitoring insufficiently critical and customer explanations accepted without verification. It follows a 480 million euro criminal settlement five years earlier. Source: dnb.nl for ABN AMRO (opens in a new tab) | DNB | Netherlands | €8.5M | AML/BSA fine | Read analysis about ABN AMRO | |
PCC money laundering network OFAC blocked a network that moved more than 30 million dollars of US drug proceeds through cryptocurrency for Brazil’s PCC, designating two Brazilian nationals and four companies. Brazil then froze roughly 2 billion dollars in related assets. Source: home.treasury.gov for PCC money laundering network (opens in a new tab) | OFAC | US | — | Sanctions violation | Read analysis about PCC money laundering network | |
EagleBank EagleBank agreed to pay 9,057,821 dollars in fines plus 736,515 dollars in forfeiture under a non-prosecution agreement, admitting it wilfully failed to run an anti-money laundering programme from 2010 to 2021 while executives overrode compliance staff. Source: justice.gov for EagleBank (opens in a new tab) | DOJ | US | $9.79M | AML/BSA fine | Read analysis about EagleBank | |
Merrill Lynch The SEC fined Merrill 7.5 million dollars because its transaction monitoring system only investigated alerts scoring 20 or higher, after Merrill’s own analysis showed lower-scoring events would have produced suspicious activity reports. It took about three years to fix. Source: sec.gov for Merrill Lynch (opens in a new tab) | SEC | US | $7.5M | AML/BSA fine | Read analysis about Merrill Lynch | |
CACEIS UK The FCA publicly censured CACEIS UK for weak financial crime controls that let the collapsed wealth manager WealthTek hold client assets it was never permitted to hold. It avoided a 33 million pound fine and agreed a voluntary payment of 31,714,068 pounds to affected clients. Source: fca.org.uk for CACEIS UK (opens in a new tab) | FCA | UK | £31.7M redress | Integrity/governance | Read analysis about CACEIS UK | |
Foreign bank branch (unnamed) and its head of compliance The Central Bank of the UAE fined a foreign bank branch 20 million dirhams for repeated anti-money laundering and sanctions control failures, and separately fined its head of compliance 300,000 dirhams. Source: centralbank.ae for Foreign bank branch (unnamed) and its head of compliance (opens in a new tab) | CBUAE | UAE | AED 20M | AML/BSA fine | Read analysis about Foreign bank branch (unnamed) and its head of compliance | |
Prince Group Treasury widened its action against the Cambodian scam conglomerate, adding 9 individuals and 26 entities, while FinCEN moved to sever the renamed Huione affiliate H-Pay from the US financial system. Source: home.treasury.gov for Prince Group (opens in a new tab) | OFAC, FinCEN | US | — | Sanctions violation | Read analysis about Prince Group | |
Ikano Bank Sweden’s financial supervisor fined Ikano Bank 140 million kronor and issued a formal remark for failing to assess how its corporate products could be used to fund crime. No laundering case was alleged. Source: fi.se for Ikano Bank (opens in a new tab) | Finansinspektionen | Sweden | SEK 140M | AML/BSA fine | Read analysis about Ikano Bank | |
Poste Italiane and Postepay Italy’s data protection authority fined Poste Italiane 6,624,000 euros and Postepay 5,877,000 euros for embedding device-surveillance software in banking apps and making consent to it a condition of account access. Source: garanteprivacy.it for Poste Italiane and Postepay (opens in a new tab) | Garante per la protezione dei dati personali | Italy | €12.5M | GDPR enforcement | Read analysis about Poste Italiane and Postepay | |
Bank of London Group The PRA fined Bank of London Group £2 million for integrity failings and inadequate cooperation over misrepresenting its capital position. Source: bankofengland.co.uk for Bank of London Group (opens in a new tab) | PRA | UK | £2M | Integrity/governance | Read analysis about Bank of London Group | |
Ranson Houghton LLP The SRA fined Ranson Houghton LLP for AML failures, signalling AML enforcement expanding beyond banks into legal services. Source: sra.org.uk for Ranson Houghton LLP (opens in a new tab) | SRA | UK | £10,283 | AML/BSA fine | Read analysis about Ranson Houghton LLP | |
EU GDPR Transparency Sweep (EDPB) 25 EU regulators launched a coordinated GDPR transparency enforcement sweep affecting how KYC flows present data processing. Source: edpb.europa.eu for EU GDPR Transparency Sweep (EDPB) (opens in a new tab) | EDPB / 25 EU DPAs | EU | — | GDPR enforcement | Read analysis about EU GDPR Transparency Sweep (EDPB) | |
Canaccord Genuity FinCEN assessed an 80 million dollar penalty, its largest ever against a broker-dealer, for years of gamed trade surveillance and at least 160 suspicious activity reports that were never filed. Source: fincen.gov for Canaccord Genuity (opens in a new tab) | FinCEN | US | $80M | AML/BSA fine | Read analysis about Canaccord Genuity | |
IDMerit IDMerit left roughly one billion identity records (203M tied to US residents) in a database with no authentication, access control or encryption — downloadable by anyone with the URL. Source: cybernews.com for IDMerit (opens in a new tab) | — | US | — | Data breach | Read analysis about IDMerit | |
Sumsub A breach via a malicious attachment on a third-party support platform went undetected for 18 months (Jul 2024–Jan 2026). Source: sumsub.com for Sumsub (opens in a new tab) | — | Global | — | Data breach | Read analysis about Sumsub | |
Discord A third-party customer service vendor was compromised, exposing roughly 70,000 government ID photos that the vendor held to review age-related appeals. Source: discord.com for Discord (opens in a new tab) | — | Global | — | Data breach | Read analysis about Discord | |
Coinbase Overseas support agents (contracted via TaskUs) were bribed to abuse privileged access, exfiltrating data on ~70,000 users (~1% of customers), including masked SSNs, government IDs and balances. Source: reuters.com for Coinbase (opens in a new tab) | — | US | ~$400M est. impact | Data breach | Read analysis about Coinbase | |
TD Bank TD Bank pleaded guilty and paid about $3 billion for Bank Secrecy Act and money-laundering failures — the largest bank ever to plead guilty to conspiracy to commit money laundering. ~$1.8B DOJ, $1.3B FinCEN, $450M OCC, $123.5M Federal Reserve. Source: justice.gov for TD Bank (opens in a new tab) | DOJ, FinCEN, OCC, Federal Reserve | US | $3B | AML/BSA fine | Read analysis about TD Bank | |
Binance Binance agreed to pay more than $4.3 billion to US authorities; founder CZ pleaded guilty, paid a $50M personal fine and stepped down. FinCEN $3.4B civil penalty + 5-year monitorship; OFAC $968M. Source: justice.gov for Binance (opens in a new tab) | DOJ, FinCEN, OFAC, CFTC | Global/US | $4.3B | AML/BSA fine | Read analysis about Binance |
QuinnBet (Gibraltar)
£609,104AML/BSA fineUKGambling Commission
QuinnBet agreed to pay 609,104 pounds, including 193,118 pounds of disgorgement, after the Gambling Commission found its anti-money laundering and customer interaction controls were not effective in practice for 29 months. A platform migration had switched off working limits.
Takeaway: A migration that silently drops a control is a control failure from the day it ships.
Source: gamblingcommission.gov.ukRead analysis about QuinnBet (Gibraltar)Rice Lake Weighing Systems
$60,764Sanctions violationUSOFAC
OFAC settled eight apparent violations covering roughly 121,527 dollars of goods, after the company’s Italian subsidiary shipped to Iran through a distributor in the United Arab Emirates.
Takeaway: Sanctions rules bind entities that US persons own or control almost as tightly as the parent itself.
Source: ofac.treasury.govRead analysis about Rice Lake Weighing SystemsUBS Financial Services
$125MAML/BSA fineUSFinCEN
FinCEN imposed a 125 million dollar penalty, its largest ever on a broker-dealer, after more than 61,500 foreign currency wires worth over 10.5 billion dollars went unmonitored between January 2019 and June 2023. The firm admitted it never closed the gaps a 2018 consent order required it to fix.
Takeaway: An unremediated consent order compounds: the second penalty prices in the first.
Source: fincen.govRead analysis about UBS Financial ServicesWise US Holdings
—KYC failureUSOCC
The OCC denied Wise a national trust bank charter, ruling it could not confirm an effective anti-money laundering programme while a 2025 multistate order over late suspicious activity reports and transaction monitoring data integrity remained unresolved.
Takeaway: An open AML order is a licensing blocker, not just a remediation project.
Source: occ.govRead analysis about Wise US HoldingsLandesbank Hessen-Thüringen (Helaba)
—KYC failureGermanyBaFin
BaFin ordered Helaba to remedy customer due diligence failures spanning customer identification, verification, updating of customer data, risk analysis and transaction monitoring. It is the second BaFin money laundering measure against the bank in seven months.
Takeaway: A remediation order with no fine still creates a supervisory record that the next measure builds on.
Source: bafin.deRead analysis about Landesbank Hessen-Thüringen (Helaba)Swedbank
$50MAML/BSA fineUSNYDFS
New York’s Department of Financial Services secured a 50 million dollar penalty from Swedbank and its New York branch for withholding information about its Baltic subsidiaries’ links to the Panama Papers, across responses spanning 2016 to 2019.
Takeaway: The concealment was punished on its own, separately from the underlying money laundering.
Source: dfs.ny.govRead analysis about SwedbankCCV Group
€2.66MAML/BSA fineNetherlandsDNB
De Nederlandsche Bank fined the payment institution 2,656,250 euros after roughly 4,200 merchants sat outside its transaction monitoring system for 23 months, with alerts closed in bulk and no recorded justification. The penalty was raised because CCV had breached the same rule before.
Takeaway: Coverage gaps outrank tuning: a merchant outside the system generates no alerts to calibrate.
Source: dnb.nlRead analysis about CCV GroupAssuranceAmerica
—Data breachUS—
The Atlanta auto insurer disclosed a breach affecting 6,998,886 people, exposing names, contact details and driver’s license numbers after an employee’s credentials were compromised.
Takeaway: Driver’s license numbers retained after a verification check are a standing liability, not a record.
Source: techcrunch.comRead analysis about AssuranceAmericaABN AMRO
€8.5MAML/BSA fineNetherlandsDNB
De Nederlandsche Bank fined ABN AMRO 8.5 million euros for inadequate due diligence on high-risk customers, finding monitoring insufficiently critical and customer explanations accepted without verification. It follows a 480 million euro criminal settlement five years earlier.
Takeaway: Accepting a customer explanation without verifying it is not ongoing monitoring.
Source: dnb.nlRead analysis about ABN AMROPCC money laundering network
—Sanctions violationUSOFAC
OFAC blocked a network that moved more than 30 million dollars of US drug proceeds through cryptocurrency for Brazil’s PCC, designating two Brazilian nationals and four companies. Brazil then froze roughly 2 billion dollars in related assets.
Takeaway: Crypto rails do not remove the sanctions nexus; they only change which intermediary sees the transaction.
Source: home.treasury.govRead analysis about PCC money laundering networkEagleBank
$9.79MAML/BSA fineUSDOJ
EagleBank agreed to pay 9,057,821 dollars in fines plus 736,515 dollars in forfeiture under a non-prosecution agreement, admitting it wilfully failed to run an anti-money laundering programme from 2010 to 2021 while executives overrode compliance staff.
Takeaway: Where senior management overrides compliance, the programme on paper counts for nothing.
Source: justice.govRead analysis about EagleBankMerrill Lynch
$7.5MAML/BSA fineUSSEC
The SEC fined Merrill 7.5 million dollars because its transaction monitoring system only investigated alerts scoring 20 or higher, after Merrill’s own analysis showed lower-scoring events would have produced suspicious activity reports. It took about three years to fix.
Takeaway: A monitoring threshold you know is miscalibrated is a documented failure, not a tuning decision.
Source: sec.govRead analysis about Merrill LynchCACEIS UK
£31.7M redressIntegrity/governanceUKFCA
The FCA publicly censured CACEIS UK for weak financial crime controls that let the collapsed wealth manager WealthTek hold client assets it was never permitted to hold. It avoided a 33 million pound fine and agreed a voluntary payment of 31,714,068 pounds to affected clients.
Takeaway: Redress paid to clients is not a penalty, but the permission-scope check that failed is exactly what onboarding due diligence exists to catch.
Source: fca.org.ukRead analysis about CACEIS UKForeign bank branch (unnamed) and its head of compliance
AED 20MAML/BSA fineUAECBUAE
The Central Bank of the UAE fined a foreign bank branch 20 million dirhams for repeated anti-money laundering and sanctions control failures, and separately fined its head of compliance 300,000 dirhams.
Takeaway: Personal liability for the compliance officer is now a live tool, not a theoretical one.
Source: centralbank.aeRead analysis about Foreign bank branch (unnamed) and its head of compliancePrince Group
—Sanctions violationUSOFAC, FinCEN
Treasury widened its action against the Cambodian scam conglomerate, adding 9 individuals and 26 entities, while FinCEN moved to sever the renamed Huione affiliate H-Pay from the US financial system.
Takeaway: Designated networks rename and re-form. Screening against a static entity list misses the successor.
Source: home.treasury.govRead analysis about Prince GroupIkano Bank
SEK 140MAML/BSA fineSwedenFinansinspektionen
Sweden’s financial supervisor fined Ikano Bank 140 million kronor and issued a formal remark for failing to assess how its corporate products could be used to fund crime. No laundering case was alleged.
Takeaway: The general risk assessment is itself an enforceable obligation, independent of whether any transaction went wrong.
Source: fi.seRead analysis about Ikano BankPoste Italiane and Postepay
€12.5MGDPR enforcementItalyGarante per la protezione dei dati personali
Italy’s data protection authority fined Poste Italiane 6,624,000 euros and Postepay 5,877,000 euros for embedding device-surveillance software in banking apps and making consent to it a condition of account access.
Takeaway: A fraud-prevention purpose does not by itself satisfy the GDPR necessity test if a less intrusive control would have worked.
Source: garanteprivacy.itRead analysis about Poste Italiane and PostepayBank of London Group
£2MIntegrity/governanceUKPRA
The PRA fined Bank of London Group £2 million for integrity failings and inadequate cooperation over misrepresenting its capital position.
Takeaway: Regulators want the data trail behind the numbers: source, calculation, sign-off, validation date.
Source: bankofengland.co.ukRead analysis about Bank of London GroupRanson Houghton LLP
£10,283AML/BSA fineUKSRA
The SRA fined Ranson Houghton LLP for AML failures, signalling AML enforcement expanding beyond banks into legal services.
Takeaway: AML obligations now bite professional-services firms, not just financial institutions.
Source: sra.org.ukRead analysis about Ranson Houghton LLPEU GDPR Transparency Sweep (EDPB)
—GDPR enforcementEUEDPB / 25 EU DPAs
25 EU regulators launched a coordinated GDPR transparency enforcement sweep affecting how KYC flows present data processing.
Takeaway: KYC data-collection transparency is now a coordinated enforcement priority.
Source: edpb.europa.euRead analysis about EU GDPR Transparency Sweep (EDPB)Canaccord Genuity
$80MAML/BSA fineUSFinCEN
FinCEN assessed an 80 million dollar penalty, its largest ever against a broker-dealer, for years of gamed trade surveillance and at least 160 suspicious activity reports that were never filed.
Takeaway: Regulators judge an AML programme by what it catches, not by what the written policy says it should catch.
Source: fincen.govRead analysis about Canaccord GenuityIDMerit
—Data breachUS—
IDMerit left roughly one billion identity records (203M tied to US residents) in a database with no authentication, access control or encryption — downloadable by anyone with the URL.
Takeaway: Centralised identity databases are honeypots; the breach needed no sophistication.
Source: cybernews.comRead analysis about IDMeritSumsub
—Data breachGlobal—
A breach via a malicious attachment on a third-party support platform went undetected for 18 months (Jul 2024–Jan 2026).
Takeaway: A centralised KYC provider is only as secure as its weakest integration; 18-month dwell time is a monitoring failure.
Source: sumsub.comRead analysis about SumsubDiscord
—Data breachGlobal—
A third-party customer service vendor was compromised, exposing roughly 70,000 government ID photos that the vendor held to review age-related appeals.
Takeaway: Age assurance built on stored ID images moves the honeypot to whichever vendor reviews the appeals.
Source: discord.comRead analysis about DiscordCoinbase
~$400M est. impactData breachUS—
Overseas support agents (contracted via TaskUs) were bribed to abuse privileged access, exfiltrating data on ~70,000 users (~1% of customers), including masked SSNs, government IDs and balances.
Takeaway: An insider/controls failure, not a hack. Privileged access to a central PII store is the attack surface.
Source: reuters.comRead analysis about CoinbaseTD Bank
$3BAML/BSA fineUSDOJ, FinCEN, OCC, Federal Reserve
TD Bank pleaded guilty and paid about $3 billion for Bank Secrecy Act and money-laundering failures — the largest bank ever to plead guilty to conspiracy to commit money laundering. ~$1.8B DOJ, $1.3B FinCEN, $450M OCC, $123.5M Federal Reserve.
Takeaway: More than 90% of transaction volume was never fed into automated monitoring — a coverage gap, not a tuning problem.
Source: justice.govRead analysis about TD BankBinance
$4.3BAML/BSA fineGlobal/USDOJ, FinCEN, OFAC, CFTC
Binance agreed to pay more than $4.3 billion to US authorities; founder CZ pleaded guilty, paid a $50M personal fine and stepped down. FinCEN $3.4B civil penalty + 5-year monitorship; OFAC $968M.
Takeaway: Compliance-light by design is now treated as a federal crime, not a growth tactic.
Source: justice.govRead analysis about Binance
Open data
Download it, cite it, keep it
The full dataset is free to use under CC BY 4.0. Take the file, not a screenshot.
- enforcement.csv CSV · 27 rows · spreadsheet-ready
- enforcement.json JSON · one object per record
- enforcement.xml RSS · new actions as they land
Every row also has its own permanent link. Append the record id to the tracker URL, for example
#td-bank,
and the link resolves to that row.
Cite this dataset
Zyphe (2026). AML Enforcement Tracker. Retrieved from https://www.zyphe.com/resources/aml-enforcement-tracker
Licensed under CC BY 4.0. Reuse the figures, charts and rows in reporting, research or internal training, including commercially, as long as you credit Zyphe and link back to this page.
Writing about one of these actions and want the underlying detail, or a comment on what it changes for compliance teams? Email hello@zyphe.com.
Methodology
How this tracker is sourced
Accuracy first — every entry is built to be cited.
Entries are compiled from public regulator announcements and primary reporting — including the US Department of Justice, FinCEN, OCC, Federal Reserve, OFAC and CFTC; the UK PRA and SRA; and the EDPB together with national EU data-protection authorities. Figures reflect the headline penalties as announced.
Penalty amounts are shown in their originally announced currency; a single USD value is used internally for numeric sorting. A dash (“—”) indicates a breach or action with no associated monetary penalty. Data-breach entries record the disclosed scope rather than a fine.
Every record carries a link to its own primary source, so any figure here can be checked at the issuing authority rather than taken on trust. Where no primary announcement is public, the record links to the original disclosure or first reporting instead, and the source field is left empty rather than filled with a guess.
This is a living dataset, updated as new actions are announced. Spotted an error or have a correction or source to add? Email hello@zyphe.com.
Book a demo
Eliminate risk and work smarter with Zyphe AI
Book a demo with our team. See agents triage L1 alerts, complete EDD cases, and run KYB reviews against your real workflows.