Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

3cases from 1 jurisdiction
€12.9mTotal of monetary amounts
€1.95mMedian per case with an amount

Click a bar to drill down one level.

Where?

by level
  1. Federal level €9.23m 72 % · 1 case
  2. States €3.66m 28 % · 2 cases

What for?

by action
  1. Fine €12.9m 100 % · 3 cases

Who?

by sector

All sectors

  1. Financial services and insurance €12.9m 100 % · 3 cases

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20241€9.23m
Q3 20240—
Q4 20240—
Q1 20250—
Q2 20250—
Q3 20251€1.71m
Q4 20251€1.95m
Q1 20260—
Q2 20260—
Q3 20260—

3 cases

14 Oct 2025 Infinity Insurance CompanyInfinity Insurance: 2.25 million USD – data leak via quoting tool reported too late USA, NYIncident reporting obligations €1.95m

Attackers extracted driver’s licence numbers in plain text via the motor insurer’s instant quote applications. Infinity discovered the anomalies on 9 February 2021 but only reported the cybersecurity event to the New York State Department of Financial Services (NYDFS) on 14 April 2021; the supervisor also criticised the lack of MFA and insecure development practices.

What organisations can take from it

Misuse of publicly accessible customer applications is also a reportable incident – warnings from the supervisor should trigger an immediate reporting assessment.

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
23 NYCRR § 500.17(a), § 500.12(a) u. a.
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Culpability
negligent

Original amount 2,250,000 USD, converted at the ECB reference rate of 14 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Aug 2025 Healthplex, Inc.Healthplex: 2 million USD – phishing incident not reported to supervisor for months USA, NYIncident reporting obligations €1.71m

An employee of the dental insurance service provider disclosed his login credentials via a phishing e-mail; the mailbox containing over 100,000 e-mails with health and social security data was accessible. Healthplex had known about the incident since November 2021 but only reported it to the New York State Department of Financial Services (NYDFS) in April 2022 instead of within 72 hours; in addition, there was no MFA for web access and no data retention and deletion policy.

What organisations can take from it

Security incidents require a fixed reporting process with deadline control – the 72-hour clock starts when the incident is identified, not when forensics is completed.

Relevance to training and awareness

Recognising phishing; reporting channels for security incidents

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
23 NYCRR § 500.17(a), § 500.12(b), § 500.13, § 500.17(b)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Culpability
negligent

Original amount 2,000,000 USD, converted at the ECB reference rate of 14 Aug 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 May 2024 Intercontinental Exchange, Inc. (ICE) und neun Tochtergesellschaften, u. a. New York Stock Exchange LLCIntercontinental Exchange/NYSE: 10 million USD – cyber attack not reported to the SEC USAIncident reporting obligations €9.23m

In April 2021, a third party alerted ICE to a vulnerability in its VPN; ICE found malicious code that had been inserted but did not inform the legal and compliance officers of its exchange and clearing subsidiaries for days. As a result, the subsidiaries, including the New York Stock Exchange, did not immediately report the incident to the U.S. Securities and Exchange Commission (SEC) as required under Regulation SCI; ICE paid 10 million USD.

What organisations can take from it

Operators of critical market infrastructure need internal reporting channels that pass cyber incidents on to all entities subject to reporting obligations within hours.

Relevance to training and awareness

Internal escalation of cyber incidents to compliance

Authority / court
U.S. Securities and Exchange Commission (SEC)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
Regulation Systems Compliance and Integrity (Regulation SCI), Meldepflichten
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Employees
10,000 or more
Repeat case
yes

Original amount 10,000,000 USD, converted at the ECB reference rate of 22 May 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial