Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

4cases from 3 jurisdictions
€6.11mTotal of monetary amounts
€3.7mLargest single case: Unisys Corp.
€1.09mMedian per case with an amount

Click a bar to drill down one level.

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20241€420,000
Q4 20241€3.7m
Q1 20250—
Q2 20251€1.75m
Q3 20250—
Q4 20250—
Q1 20260—
Q2 20260—
Q3 20261€240,000

4 cases

22 Oct 2024 Unisys Corp.SEC: $4 million against Unisys for downplaying cyber incidents after SolarWinds USADisclosure and reporting obligations €3.7m

In mandatory disclosures, Unisys presented cyber risks as hypothetical, although it had suffered two intrusions with data exfiltration connected with the SolarWinds compromise. On the same day, the US Securities and Exchange Commission (SEC) also imposed penalties on Avaya ($1 million), Check Point ($995,000) and Mimecast ($990,000).

What organisations can take from it

Do not describe cyber incidents that have occurred as a mere risk in investor information – disclosure processes must involve IT security.

Authority / court
U.S. Securities and Exchange Commission (SEC)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Securities Act of 1933, Securities Exchange Act of 1934 (inkl. Disclosure Controls)
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Culpability
negligent
Mitigating circumstances
Cooperation in the proceedings and improvement of cybersecurity controls.
Published
22 Oct 2024

Original amount 4,000,000 USD, converted at the ECB reference rate of 22 Oct 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

16 Jul 2026 TeamViewer SETeamViewer: cyberattack not disclosed as inside information without delay GermanyDisclosure and reporting obligations €240,000

Germany's Federal Financial Supervisory Authority (Bundesanstalt für Finanzdienstleistungsaufsicht, BaFin) imposed a fine of 240,000 EUR on the software company because it had not disclosed the information about a cyberattack it had suffered as inside information without delay. The fine notice is final.

What organisations can take from it

Put serious IT security incidents immediately before the ad hoc disclosure committee as well – the incident response process must take capital market disclosure into account.

Relevance to training and awareness

Recognising security incidents as potential inside information and reporting them to the ad hoc disclosure committee

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Art. 17 Abs. 1 UAbs. 1 MAR (EU) Nr. 596/2014
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Published
20 Jul 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 May 2025 SAP SESAP: failure to publish notice on the 2022 annual financial report GermanyDisclosure and reporting obligations €1.75m

SAP had not published an announcement stating from when and at which internet address the 2022 annual financial report was publicly available in addition to the company register (Hinweisbekanntmachung). BaFin imposed a fine of 1.75 million EUR; the notice is final.

What organisations can take from it

Even seemingly formal disclosure steps such as the notice announcement need a fixed place in the financial calendar – the range of fines extends up to five per cent of total turnover.

Authority / court
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
§ 114 Abs. 1 Satz 2 WpHG
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Published
27 May 2025

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Jul 2024 Parrot SAParrot: misleading half-yearly report and insider dealing ahead of a takeover bid FranceMarket abuse and insider dealing €420,000

In its 2018 half-yearly report, the drone manufacturer disseminated misleading information on the absence of impairment indicators for the drone division, on goodwill and on earnings; in addition, the deputy managing director used inside information about a planned takeover bid. Sanctions: Parrot 150,000 EUR, CEO Henri Seydoux 60,000 EUR, Gilles Labossière 210,000 EUR.

What organisations can take from it

Impairment tests for loss-making divisions and trading bans for management are particularly sensitive in a takeover context.

Relevance to training and awareness

Insider dealing ban for executives in connection with takeover plans

Authority / court
Autorité des marchés financiers (AMF), Commission des sanctions
Area of law
Capital markets and financial supervision · Market abuse and insider dealing
Legal basis
Art. 12 Abs. 1 lit. c, Art. 15 MAR; Art. 8 und 14 MAR
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Liability of senior managers
Henri Seydoux (Président-directeur général): 60,000 EUR; Gilles Labossière (directeur général délégué): 210,000 EUR, including for insider dealing
Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial