Free guide: How to use AI in compliance

Resources

AML Enforcement Tracker

A searchable, sortable record of major AML/BSA fines, sanctions actions, and identity-data breaches affecting banks, crypto platforms, and identity-verification providers. Each entry links the headline penalty to the underlying compliance failure.

enforcement actions and breaches
27 enforcement actions and breaches
in penalties recorded
$7.6B in penalties recorded
jurisdictions covered
10 jurisdictions covered
identity-data breaches
5 identity-data breaches

Covering 2023 to 2026. 27 of 27 records link directly to a primary source. Last updated 2026-08-20.

Database

Browse enforcement actions and breaches

Search by entity, regulator, or keyword. Filter by action type, jurisdiction, and year. Sort any column to compare penalties and dates.

Showing 27 of 27 actions

  • QuinnBet (Gibraltar)

    £609,104
    AML/BSA fineUK

    Gambling Commission

    QuinnBet agreed to pay 609,104 pounds, including 193,118 pounds of disgorgement, after the Gambling Commission found its anti-money laundering and customer interaction controls were not effective in practice for 29 months. A platform migration had switched off working limits.

    Takeaway: A migration that silently drops a control is a control failure from the day it ships.

    Source: gamblingcommission.gov.ukRead analysis about QuinnBet (Gibraltar)
  • Rice Lake Weighing Systems

    $60,764
    Sanctions violationUS

    OFAC

    OFAC settled eight apparent violations covering roughly 121,527 dollars of goods, after the company’s Italian subsidiary shipped to Iran through a distributor in the United Arab Emirates.

    Takeaway: Sanctions rules bind entities that US persons own or control almost as tightly as the parent itself.

    Source: ofac.treasury.govRead analysis about Rice Lake Weighing Systems
  • UBS Financial Services

    $125M
    AML/BSA fineUS

    FinCEN

    FinCEN imposed a 125 million dollar penalty, its largest ever on a broker-dealer, after more than 61,500 foreign currency wires worth over 10.5 billion dollars went unmonitored between January 2019 and June 2023. The firm admitted it never closed the gaps a 2018 consent order required it to fix.

    Takeaway: An unremediated consent order compounds: the second penalty prices in the first.

    Source: fincen.govRead analysis about UBS Financial Services
  • Wise US Holdings

    KYC failureUS

    OCC

    The OCC denied Wise a national trust bank charter, ruling it could not confirm an effective anti-money laundering programme while a 2025 multistate order over late suspicious activity reports and transaction monitoring data integrity remained unresolved.

    Takeaway: An open AML order is a licensing blocker, not just a remediation project.

    Source: occ.govRead analysis about Wise US Holdings
  • Landesbank Hessen-Thüringen (Helaba)

    KYC failureGermany

    BaFin

    BaFin ordered Helaba to remedy customer due diligence failures spanning customer identification, verification, updating of customer data, risk analysis and transaction monitoring. It is the second BaFin money laundering measure against the bank in seven months.

    Takeaway: A remediation order with no fine still creates a supervisory record that the next measure builds on.

    Source: bafin.deRead analysis about Landesbank Hessen-Thüringen (Helaba)
  • Swedbank

    $50M
    AML/BSA fineUS

    NYDFS

    New York’s Department of Financial Services secured a 50 million dollar penalty from Swedbank and its New York branch for withholding information about its Baltic subsidiaries’ links to the Panama Papers, across responses spanning 2016 to 2019.

    Takeaway: The concealment was punished on its own, separately from the underlying money laundering.

    Source: dfs.ny.govRead analysis about Swedbank
  • CCV Group

    €2.66M
    AML/BSA fineNetherlands

    DNB

    De Nederlandsche Bank fined the payment institution 2,656,250 euros after roughly 4,200 merchants sat outside its transaction monitoring system for 23 months, with alerts closed in bulk and no recorded justification. The penalty was raised because CCV had breached the same rule before.

    Takeaway: Coverage gaps outrank tuning: a merchant outside the system generates no alerts to calibrate.

    Source: dnb.nlRead analysis about CCV Group
  • AssuranceAmerica

    Data breachUS

    The Atlanta auto insurer disclosed a breach affecting 6,998,886 people, exposing names, contact details and driver’s license numbers after an employee’s credentials were compromised.

    Takeaway: Driver’s license numbers retained after a verification check are a standing liability, not a record.

    Source: techcrunch.comRead analysis about AssuranceAmerica
  • ABN AMRO

    €8.5M
    AML/BSA fineNetherlands

    DNB

    De Nederlandsche Bank fined ABN AMRO 8.5 million euros for inadequate due diligence on high-risk customers, finding monitoring insufficiently critical and customer explanations accepted without verification. It follows a 480 million euro criminal settlement five years earlier.

    Takeaway: Accepting a customer explanation without verifying it is not ongoing monitoring.

    Source: dnb.nlRead analysis about ABN AMRO
  • PCC money laundering network

    Sanctions violationUS

    OFAC

    OFAC blocked a network that moved more than 30 million dollars of US drug proceeds through cryptocurrency for Brazil’s PCC, designating two Brazilian nationals and four companies. Brazil then froze roughly 2 billion dollars in related assets.

    Takeaway: Crypto rails do not remove the sanctions nexus; they only change which intermediary sees the transaction.

    Source: home.treasury.govRead analysis about PCC money laundering network
  • EagleBank

    $9.79M
    AML/BSA fineUS

    DOJ

    EagleBank agreed to pay 9,057,821 dollars in fines plus 736,515 dollars in forfeiture under a non-prosecution agreement, admitting it wilfully failed to run an anti-money laundering programme from 2010 to 2021 while executives overrode compliance staff.

    Takeaway: Where senior management overrides compliance, the programme on paper counts for nothing.

    Source: justice.govRead analysis about EagleBank
  • Merrill Lynch

    $7.5M
    AML/BSA fineUS

    SEC

    The SEC fined Merrill 7.5 million dollars because its transaction monitoring system only investigated alerts scoring 20 or higher, after Merrill’s own analysis showed lower-scoring events would have produced suspicious activity reports. It took about three years to fix.

    Takeaway: A monitoring threshold you know is miscalibrated is a documented failure, not a tuning decision.

    Source: sec.govRead analysis about Merrill Lynch
  • CACEIS UK

    £31.7M redress
    Integrity/governanceUK

    FCA

    The FCA publicly censured CACEIS UK for weak financial crime controls that let the collapsed wealth manager WealthTek hold client assets it was never permitted to hold. It avoided a 33 million pound fine and agreed a voluntary payment of 31,714,068 pounds to affected clients.

    Takeaway: Redress paid to clients is not a penalty, but the permission-scope check that failed is exactly what onboarding due diligence exists to catch.

    Source: fca.org.ukRead analysis about CACEIS UK
  • Foreign bank branch (unnamed) and its head of compliance

    AED 20M
    AML/BSA fineUAE

    CBUAE

    The Central Bank of the UAE fined a foreign bank branch 20 million dirhams for repeated anti-money laundering and sanctions control failures, and separately fined its head of compliance 300,000 dirhams.

    Takeaway: Personal liability for the compliance officer is now a live tool, not a theoretical one.

    Source: centralbank.aeRead analysis about Foreign bank branch (unnamed) and its head of compliance
  • Prince Group

    Sanctions violationUS

    OFAC, FinCEN

    Treasury widened its action against the Cambodian scam conglomerate, adding 9 individuals and 26 entities, while FinCEN moved to sever the renamed Huione affiliate H-Pay from the US financial system.

    Takeaway: Designated networks rename and re-form. Screening against a static entity list misses the successor.

    Source: home.treasury.govRead analysis about Prince Group
  • Ikano Bank

    SEK 140M
    AML/BSA fineSweden

    Finansinspektionen

    Sweden’s financial supervisor fined Ikano Bank 140 million kronor and issued a formal remark for failing to assess how its corporate products could be used to fund crime. No laundering case was alleged.

    Takeaway: The general risk assessment is itself an enforceable obligation, independent of whether any transaction went wrong.

    Source: fi.seRead analysis about Ikano Bank
  • Poste Italiane and Postepay

    €12.5M
    GDPR enforcementItaly

    Garante per la protezione dei dati personali

    Italy’s data protection authority fined Poste Italiane 6,624,000 euros and Postepay 5,877,000 euros for embedding device-surveillance software in banking apps and making consent to it a condition of account access.

    Takeaway: A fraud-prevention purpose does not by itself satisfy the GDPR necessity test if a less intrusive control would have worked.

    Source: garanteprivacy.itRead analysis about Poste Italiane and Postepay
  • Bank of London Group

    £2M
    Integrity/governanceUK

    PRA

    The PRA fined Bank of London Group £2 million for integrity failings and inadequate cooperation over misrepresenting its capital position.

    Takeaway: Regulators want the data trail behind the numbers: source, calculation, sign-off, validation date.

    Source: bankofengland.co.ukRead analysis about Bank of London Group
  • Ranson Houghton LLP

    £10,283
    AML/BSA fineUK

    SRA

    The SRA fined Ranson Houghton LLP for AML failures, signalling AML enforcement expanding beyond banks into legal services.

    Takeaway: AML obligations now bite professional-services firms, not just financial institutions.

    Source: sra.org.ukRead analysis about Ranson Houghton LLP
  • EU GDPR Transparency Sweep (EDPB)

    GDPR enforcementEU

    EDPB / 25 EU DPAs

    25 EU regulators launched a coordinated GDPR transparency enforcement sweep affecting how KYC flows present data processing.

    Takeaway: KYC data-collection transparency is now a coordinated enforcement priority.

    Source: edpb.europa.euRead analysis about EU GDPR Transparency Sweep (EDPB)
  • Canaccord Genuity

    $80M
    AML/BSA fineUS

    FinCEN

    FinCEN assessed an 80 million dollar penalty, its largest ever against a broker-dealer, for years of gamed trade surveillance and at least 160 suspicious activity reports that were never filed.

    Takeaway: Regulators judge an AML programme by what it catches, not by what the written policy says it should catch.

    Source: fincen.govRead analysis about Canaccord Genuity
  • IDMerit

    Data breachUS

    IDMerit left roughly one billion identity records (203M tied to US residents) in a database with no authentication, access control or encryption — downloadable by anyone with the URL.

    Takeaway: Centralised identity databases are honeypots; the breach needed no sophistication.

    Source: cybernews.comRead analysis about IDMerit
  • Sumsub

    Data breachGlobal

    A breach via a malicious attachment on a third-party support platform went undetected for 18 months (Jul 2024–Jan 2026).

    Takeaway: A centralised KYC provider is only as secure as its weakest integration; 18-month dwell time is a monitoring failure.

    Source: sumsub.comRead analysis about Sumsub
  • Discord

    Data breachGlobal

    A third-party customer service vendor was compromised, exposing roughly 70,000 government ID photos that the vendor held to review age-related appeals.

    Takeaway: Age assurance built on stored ID images moves the honeypot to whichever vendor reviews the appeals.

    Source: discord.comRead analysis about Discord
  • Coinbase

    ~$400M est. impact
    Data breachUS

    Overseas support agents (contracted via TaskUs) were bribed to abuse privileged access, exfiltrating data on ~70,000 users (~1% of customers), including masked SSNs, government IDs and balances.

    Takeaway: An insider/controls failure, not a hack. Privileged access to a central PII store is the attack surface.

    Source: reuters.comRead analysis about Coinbase
  • TD Bank

    $3B
    AML/BSA fineUS

    DOJ, FinCEN, OCC, Federal Reserve

    TD Bank pleaded guilty and paid about $3 billion for Bank Secrecy Act and money-laundering failures — the largest bank ever to plead guilty to conspiracy to commit money laundering. ~$1.8B DOJ, $1.3B FinCEN, $450M OCC, $123.5M Federal Reserve.

    Takeaway: More than 90% of transaction volume was never fed into automated monitoring — a coverage gap, not a tuning problem.

    Source: justice.govRead analysis about TD Bank
  • Binance

    $4.3B
    AML/BSA fineGlobal/US

    DOJ, FinCEN, OFAC, CFTC

    Binance agreed to pay more than $4.3 billion to US authorities; founder CZ pleaded guilty, paid a $50M personal fine and stepped down. FinCEN $3.4B civil penalty + 5-year monitorship; OFAC $968M.

    Takeaway: Compliance-light by design is now treated as a federal crime, not a growth tactic.

    Source: justice.govRead analysis about Binance

Open data

Download it, cite it, keep it

The full dataset is free to use under CC BY 4.0. Take the file, not a screenshot.

Every row also has its own permanent link. Append the record id to the tracker URL, for example #td-bank, and the link resolves to that row.

Cite this dataset

Zyphe (2026). AML Enforcement Tracker. Retrieved from https://www.zyphe.com/resources/aml-enforcement-tracker

Licensed under CC BY 4.0. Reuse the figures, charts and rows in reporting, research or internal training, including commercially, as long as you credit Zyphe and link back to this page.

Writing about one of these actions and want the underlying detail, or a comment on what it changes for compliance teams? Email hello@zyphe.com.

Methodology

How this tracker is sourced

Accuracy first — every entry is built to be cited.

Entries are compiled from public regulator announcements and primary reporting — including the US Department of Justice, FinCEN, OCC, Federal Reserve, OFAC and CFTC; the UK PRA and SRA; and the EDPB together with national EU data-protection authorities. Figures reflect the headline penalties as announced.

Penalty amounts are shown in their originally announced currency; a single USD value is used internally for numeric sorting. A dash (“—”) indicates a breach or action with no associated monetary penalty. Data-breach entries record the disclosed scope rather than a fine.

Every record carries a link to its own primary source, so any figure here can be checked at the issuing authority rather than taken on trust. Where no primary announcement is public, the record links to the original disclosure or first reporting instead, and the source field is left empty rather than filled with a guess.

This is a living dataset, updated as new actions are announced. Spotted an error or have a correction or source to add? Email hello@zyphe.com.

Book a demo

Eliminate risk and work smarter with Zyphe AI

Book a demo with our team. See agents triage L1 alerts, complete EDD cases, and run KYB reviews against your real workflows.