Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by levelWhat for?
by action- Fine €12.9m 100 % · 3 cases
Who?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 0 | — |
| Q2 2024 | 1 | €9.23m |
| Q3 2024 | 0 | — |
| Q4 2024 | 0 | — |
| Q1 2025 | 0 | — |
| Q2 2025 | 0 | — |
| Q3 2025 | 1 | €1.71m |
| Q4 2025 | 1 | €1.95m |
| Q1 2026 | 0 | — |
| Q2 2026 | 0 | — |
| Q3 2026 | 0 | — |
3 cases
14 Oct 2025 Infinity Insurance CompanyInfinity Insurance: 2.25 million USD – data leak via quoting tool reported too late €1.95m
Attackers extracted driver’s licence numbers in plain text via the motor insurer’s instant quote applications. Infinity discovered the anomalies on 9 February 2021 but only reported the cybersecurity event to the New York State Department of Financial Services (NYDFS) on 14 April 2021; the supervisor also criticised the lack of MFA and insecure development practices.
Misuse of publicly accessible customer applications is also a reportable incident – warnings from the supervisor should trigger an immediate reporting assessment.
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- 23 NYCRR § 500.17(a), § 500.12(a) u. a.
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 2,250,000 USD, converted at the ECB reference rate of 14 Oct 2025.
- NYDFS Consent Order to Infinity Insurance Company (14.10.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
14 Aug 2025 Healthplex, Inc.Healthplex: 2 million USD – phishing incident not reported to supervisor for months €1.71m
An employee of the dental insurance service provider disclosed his login credentials via a phishing e-mail; the mailbox containing over 100,000 e-mails with health and social security data was accessible. Healthplex had known about the incident since November 2021 but only reported it to the New York State Department of Financial Services (NYDFS) in April 2022 instead of within 72 hours; in addition, there was no MFA for web access and no data retention and deletion policy.
Security incidents require a fixed reporting process with deadline control – the 72-hour clock starts when the incident is identified, not when forensics is completed.
Recognising phishing; reporting channels for security incidents
- Authority / court
- New York State Department of Financial Services (NYDFS)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- 23 NYCRR § 500.17(a), § 500.12(b), § 500.13, § 500.17(b)
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Culpability
- negligent
Original amount 2,000,000 USD, converted at the ECB reference rate of 14 Aug 2025.
- NYDFS Consent Order to Healthplex, Inc. (14.08.2025) Decision of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
22 May 2024 Intercontinental Exchange, Inc. (ICE) und neun Tochtergesellschaften, u. a. New York Stock Exchange LLCIntercontinental Exchange/NYSE: 10 million USD – cyber attack not reported to the SEC €9.23m
In April 2021, a third party alerted ICE to a vulnerability in its VPN; ICE found malicious code that had been inserted but did not inform the legal and compliance officers of its exchange and clearing subsidiaries for days. As a result, the subsidiaries, including the New York Stock Exchange, did not immediately report the incident to the U.S. Securities and Exchange Commission (SEC) as required under Regulation SCI; ICE paid 10 million USD.
Operators of critical market infrastructure need internal reporting channels that pass cyber incidents on to all entities subject to reporting obligations within hours.
Internal escalation of cyber incidents to compliance
- Authority / court
- U.S. Securities and Exchange Commission (SEC)
- Area of law
- Information security and cyber · Incident reporting obligations
- Legal basis
- Regulation Systems Compliance and Integrity (Regulation SCI), Meldepflichten
- Action
- Fine
- Status of proceedings
- final
- Sector
- Financial services and insurance
- Employees
- 10,000 or more
- Repeat case
- yes
Original amount 10,000,000 USD, converted at the ECB reference rate of 22 May 2024.
Checked against the official source on 25 Sep 2026 · Direct link