Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America and Asia-Pacific: 1,838 cases from 37 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Federal Court of Australia (auf Antrag der Australian Securities and Investments Commission, ASIC) €1.48m 100 % · 1 case
What for?
by action- Fine €1.48m 100 % · 1 case
Who?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 0 | – |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 0 | – |
| Q1 2026 | 1 | €1.48m |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
1 case
9 Feb 2026 FIIG Securities LimitedFIIG Securities: 2.5 million AUD for inadequate cyber security ahead of data theft €1.48m
The Federal Court of Australia, on application by the Australian Securities and Investments Commission (ASIC, Australia's corporate, markets and financial services regulator), imposed a penalty of 2.5 million AUD on the fixed-income specialist because between March 2019 and June 2023 it lacked adequate cyber security measures, resources and risk management systems – among other things, there was no multi-factor authentication for remote access, no regular penetration testing and no mandatory security awareness training. In a 2023 attack around 385 GB of confidential data were stolen and some 18,000 clients were notified; the court also ordered a compliance programme with an independent expert.
For licensed financial services firms, cyber security is part of their licence obligations: basic measures such as MFA, patching, monitoring, training and a tested incident response plan must be funded and actually implemented.
Cyber security basics: multi-factor authentication, patch management, security awareness training, tested incident response plan
Missing or inadequate training played a role in the decision.
- Authority / court
- Federal Court of Australia (auf Antrag der Australian Securities and Investments Commission, ASIC)
- Area of law
- Information security and cyber · Security measures and risk management
- Legal basis
- Corporations Act 2001 (Cth) s 912A(1)(a), (d) und (h) i. V. m. s 912A(5A)
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Repeat case
- no
- Mitigating circumstances
- Full cooperation, admissions and an agreed statement of facts; no previous contraventions; the known financial losses (remediation costs of around 1.5 million AUD) were largely borne by the company itself.
- Published
- 9 Feb 2026
Original amount 2,500,000 AUD, converted at the ECB reference rate of 9 Feb 2026.
Checked against the official source on 3 Oct 2026 · Direct link