Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by stateWhat for?
by topicWho?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 1 | €913,159 |
| Q1 2024 | 0 | — |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 1 | €1.92m |
| Q2 2025 | 0 | — |
| Q3 2025 | 1 | €1.71m |
| Q4 2025 | 2 | €4.35m |
| Q1 2026 | 0 | — |
| Q2 2026 | 1 | €1.92m |
| Q3 2026 | 1 | €216,375 |
7 cases
5 Aug 2026 Order Express, Inc.NYDFS: $250,000 against money transmitter Order Express over cyber deficiencies €216,375
The licensed money transmitter had no adequate policies for system updates and insufficient risk assessments under New York's cybersecurity regulation, as found by the New York State Department of Financial Services (NYDFS). The company has already remedied the deficiencies.
Even small financial service providers must keep documented patch policies and regular risk assessments.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Mitigating circumstances
- Because of its low turnover, the company was exempt from many Part 500 obligations; deficiencies already remedied.
- Published
- 5 Aug 2026
Original amount 250,000 USD, converted at the ECB reference rate of 5 Aug 2026.
- New York State Department of Financial Services Secures Cybersecurity Settlement with Order Express, Inc. Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
29 Apr 2026 Delta Dental Insurance Company und Delta Dental of New York, Inc.NYDFS: $2.25 million against Delta Dental after MOVEit attack and late notification €1.92m
In 2023, attackers exploited a zero-day vulnerability in MOVEit Transfer to steal files containing social security, driving licence, account and health data. The New York State Department of Financial Services (NYDFS) criticised inadequate retention settings, policies and controls as well as the late notification of the cybersecurity incidents to the supervisory authority.
Keep data in transfer tools only for as long as necessary – and report security incidents to the supervisory authority on time.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
- Published
- 30 Apr 2026
Original amount 2,250,000 USD, converted at the ECB reference rate of 29 Apr 2026.
- DFS Secures $2.25 Million Cybersecurity Settlement with Delta Dental Press release of an authority
- Consent Order to Delta Dental 2026 Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Oct 2025 Farmers Insurance ExchangeNYDFS: $2.775 million against Farmers over unprotected online quoting tools €2.4m
Attackers harvested driving licence numbers and dates of birth via inadequately secured online quoting tools and agent portals. According to the New York State Department of Financial Services (NYDFS), Farmers infringed the cybersecurity regulation and did not report the incident in time; the penalty is part of a package totalling $19 million against eight motor insurers.
Automatically pre-filled forms containing customer data are a point of entry – scrutinise public-facing applications for the data they disclose.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
- Published
- 14 Oct 2025
Original amount 2,775,000 USD, converted at the ECB reference rate of 14 Oct 2025.
- DFS Secures More than $19 Million from Auto Insurance Companies over Data Breaches Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Oct 2025 Infinity Insurance CompanyInfinity Insurance: 2.25 million USD – data leak via quoting tool reported too late €1.95m
Attackers extracted driver’s licence numbers in plain text via the motor insurer’s instant quote applications. Infinity discovered the anomalies on 9 February 2021 but only reported the cybersecurity event to the New York State Department of Financial Services (NYDFS) on 14 April 2021; the supervisor also criticised the lack of MFA and insecure development practices.
Misuse of publicly accessible customer applications is also a reportable incident – warnings from the supervisor should trigger an immediate reporting assessment.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- 23 NYCRR § 500.17(a), § 500.12(a) u. a.
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 2,250,000 USD, converted at the ECB reference rate of 14 Oct 2025.
- NYDFS Consent Order to Infinity Insurance Company (14.10.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Aug 2025 Healthplex, Inc.Healthplex: 2 million USD – phishing incident not reported to supervisor for months €1.71m
An employee of the dental insurance service provider disclosed his login credentials via a phishing e-mail; the mailbox containing over 100,000 e-mails with health and social security data was accessible. Healthplex had known about the incident since November 2021 but only reported it to the New York State Department of Financial Services (NYDFS) in April 2022 instead of within 72 hours; in addition, there was no MFA for web access and no data retention and deletion policy.
Security incidents require a fixed reporting process with deadline control – the 72-hour clock starts when the incident is identified, not when forensics is completed.
Recognising phishing; reporting channels for security incidents
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- 23 NYCRR § 500.17(a), § 500.12(b), § 500.13, § 500.17(b)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 2,000,000 USD, converted at the ECB reference rate of 14 Aug 2025.
- NYDFS Consent Order to Healthplex, Inc. (14.08.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
23 Jan 2025 PayPal, Inc.NYDFS: $2 million against PayPal over untrained teams and missing MFA €1.92m
When changing data flows for 1099-K tax forms, insufficiently trained teams bypassed security processes; criminals with compromised credentials were able to retrieve forms containing social security numbers. According to the New York State Department of Financial Services (NYDFS), qualified personnel, training, access policies as well as MFA, CAPTCHA and rate limiting were lacking.
Anyone changing data flows must know the security processes – training development teams is part of cyber defence.
Secure software development and change processes
Missing or inadequate training played a role in the decision.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR Part 500 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Culpability
- negligent
- Mitigating circumstances
- PayPal has since remedied the deficiencies.
- Published
- 23 Jan 2025
Original amount 2,000,000 USD, converted at the ECB reference rate of 23 Jan 2025.
- DFS-Pressemitteilung vom 23.01.2025: Cybersecurity-Vergleich mit PayPal, Inc. (2 Mio. $) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
27 Nov 2023 First American Title Insurance CompanyNYDFS: $1 million against First American over open document links €913,159
The EaglePro application generated links to transaction documents without login and without an expiry date; according to a journalist, by changing the sequential document number, 885 million documents containing, among other things, social security and bank data could be retrieved. Users were told not to send sensitive data, but there were no technical barriers. The penalty was imposed by the New York State Department of Financial Services (NYDFS).
Instructions to users do not replace technical controls – sharing links need authentication and an expiry date.
Classification and sending of sensitive documents
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- 23 NYCRR §§ 500.3, 500.7 (Cybersecurity Regulation)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 1,000,000 USD, converted at the ECB reference rate of 27 Nov 2023.
- Consent Order to First American Title Insurance Company Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link