Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

3cases from 1 jurisdiction
€10.5mTotal of monetary amounts
€789,284Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. U.S. Securities and Exchange Commission (SEC) €9.74m 93 % · 2 cases
  2. Commodity Futures Trading Commission (CFTC) €789,284 7 % · 1 case

What for?

by topic
  1. Incident reporting obligations €9.23m 88 % · 1 case
  2. Critical infrastructure €1.29m 12 % · 2 cases

Who?

by sector

All sectors

  1. Financial services and insurance €10.5m 100 % · 3 cases

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20241€9.23m
Q3 20240—
Q4 20241€789,284
Q1 20250—
Q2 20250—
Q3 20250—
Q4 20250—
Q1 20260—
Q2 20260—
Q3 20261€501,614

3 cases

22 Sep 2026 OTC Link LLCOTC Link: 575,000 USD – security policies never completed despite examination findings USACritical infrastructure €501,614

From 2016 to 2025, the operator of the OTC Link ATS trading system lacked complete policies on systems security, access control and vulnerability management as required under Regulation SCI. Although the examiners of the U.S. Securities and Exchange Commission (SEC) had criticised the gaps in several examinations, drafts remained unfinished; the SEC issued a censure and imposed 575,000 USD.

What organisations can take from it

Track supervisory examination findings with a deadline and a responsible person – points that remain open repeatedly become expensive.

Authority / court
U.S. Securities and Exchange Commission (SEC)
Area of law
Information security and cyber · Critical infrastructure
Legal basis
Regulation SCI, Rule 1001(a)(1)–(3)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Repeat case
yes

Original amount 575,000 USD, converted at the ECB reference rate of 22 Sep 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

1 Oct 2024 Tradition SEF LLCTradition SEF: 875,000 USD – emergency and security tests not brought before the board USACritical infrastructure €789,284

The swap trading platform did not fully inform its board of the results of emergency, technology risk and penetration tests, did not regularly test its business continuity and disaster recovery capabilities and had no adequate risk management. It also failed to produce documents requested during an examination on time despite extensions of deadlines; the Commodity Futures Trading Commission (CFTC) imposed 875,000 USD.

What organisations can take from it

Contingency plans only count if they are tested regularly and the results are noted by the entire governing body.

Authority / court
Commodity Futures Trading Commission (CFTC)
Area of law
Information security and cyber · Critical infrastructure
Legal basis
Commodity Exchange Act; CFTC-Regeln zu System Safeguards für Swap Execution Facilities
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance

Original amount 875,000 USD, converted at the ECB reference rate of 1 Oct 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 May 2024 Intercontinental Exchange, Inc. (ICE) und neun Tochtergesellschaften, u. a. New York Stock Exchange LLCIntercontinental Exchange/NYSE: 10 million USD – cyber attack not reported to the SEC USAIncident reporting obligations €9.23m

In April 2021, a third party alerted ICE to a vulnerability in its VPN; ICE found malicious code that had been inserted but did not inform the legal and compliance officers of its exchange and clearing subsidiaries for days. As a result, the subsidiaries, including the New York Stock Exchange, did not immediately report the incident to the U.S. Securities and Exchange Commission (SEC) as required under Regulation SCI; ICE paid 10 million USD.

What organisations can take from it

Operators of critical market infrastructure need internal reporting channels that pass cyber incidents on to all entities subject to reporting obligations within hours.

Relevance to training and awareness

Internal escalation of cyber incidents to compliance

Authority / court
U.S. Securities and Exchange Commission (SEC)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Regulation Systems Compliance and Integrity (Regulation SCI), Meldepflichten
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Employees
10,000 or more
Repeat case
yes

Original amount 10,000,000 USD, converted at the ECB reference rate of 22 May 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial