Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

6cases from 1 jurisdiction
€232.9mTotal of monetary amounts (5 cases with an amount)
€120.1mLargest single case: Cadence Design Systems Inc.
€6.35mMedian per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. U.S. Department of Justice; Bureau of Industry and Security (BIS) €120.1m 52 % · 1 case
  2. U.S. Department of Justice (Criminal Division, Fraud Section; USAO Southern District of Florida) €102.1m 44 % · 1 case
  3. Federal Trade Commission (FTC) €6.35m 3 % · 2 cases
  4. U.S. Securities and Exchange Commission (SEC) €3.7m 2 % · 1 case
  5. U.S. Securities and Exchange Commission €626,868 0 % · 1 case

What for?

by area of law

All areas of law

  1. Sanctions and export control €120.1m 52 % · 1 case
  2. Bribery and corruption €102.1m 44 % · 1 case
  3. Consumer protection and online retail €6.35m 3 % · 1 case
  4. Capital markets and financial supervision €3.7m 2 % · 1 case
  5. Whistleblower protection €626,868 0 % · 1 case
  6. Data protection — 0 % · 1 case

Who?

by company
  1. Cadence Design Systems Inc. €120.1m 52 % · 1 case
  2. Comunicaciones Celulares S.A. (TIGO Guatemala) €102.1m 44 % · 1 case
  3. Chegg Inc. €6.35m 3 % · 1 case
  4. Unisys Corp. €3.7m 2 % · 1 case
  5. AppFolio, Inc. €626,868 0 % · 1 case
  6. Illuminate Education Inc. — 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20240—
Q2 20240—
Q3 20241€626,868
Q4 20241€3.7m
Q1 20250—
Q2 20250—
Q3 20252€126.5m
Q4 20251€102.1m
Q1 20260—
Q2 20261—
Q3 20260—

6 cases

5 Jun 2026 Illuminate Education Inc.FTC: final order against education software provider Illuminate after data leak affecting 10.1 million students USAData breaches and data security Order

According to the complaint by the US Federal Trade Commission (FTC), Illuminate promised schools data security but did not adequately protect its cloud databases, even though a service provider had pointed out vulnerabilities almost two years earlier; a hacker accessed data on 10.1 million students, including health information. The order requires an information security programme, data minimisation and a public deletion schedule, and prohibits misrepresentations about security and notification deadlines.

What organisations can take from it

Do not leave known vulnerabilities unaddressed for years – security promises to customers are measured as binding commitments.

Authority / court
Federal Trade Commission (FTC)
Area of law
Data protection · Data breaches and data security
Legal basis
FTC Act (Verbot unlauterer und irreführender Praktiken)
Action
Order
Status of proceedings
final
Sector
Telecoms, IT and software
Culpability
negligent
Published
5 Jun 2026

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Nov 2025 Comunicaciones Celulares S.A. (TIGO Guatemala)TIGO Guatemala pays more than 118 million USD for bribing members of Congress USABribery of public officials €102.1m

From 2012 to 2018, the Guatemalan mobile network operator made monthly cash payments to members of Congress or their security staff in order to obtain legislative support; part of the funds came from laundered drug money. Two-year Deferred Prosecution Agreement with a criminal penalty of 60 million USD and administrative forfeiture of 58,198,343 USD.

What organisations can take from it

In joint ventures with local partners, the parent company needs genuine control over cash flows and contacts with public officials – an early voluntary self-disclosure is no substitute for a full investigation.

Relevance to training and awareness

Bribery of public officials, cash payments, integrity of co-shareholders

Authority / court
U.S. Department of Justice (Criminal Division, Fraud Section; USAO Southern District of Florida)
Area of law
Bribery and corruption · Bribery of public officials
Legal basis
FCPA, 15 U.S.C. § 78dd-3 (Verschwörung, 18 U.S.C. § 371); Deferred Prosecution Agreement
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Culpability
intentional
Mitigating circumstances
Voluntary self-disclosure by the parent company Millicom in 2015; subsequently extensive cooperation and remediation (including dismissals of staff and an 800 % increase in compliance personnel).
Liability of senior managers
According to the DOJ, the scheme was directed by the then Guatemalan shareholder and other senior individuals; four individuals had already been charged (not named).
Published
12 Dec 2025

Original amount 118,198,343 USD, converted at the ECB reference rate of 12 Nov 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

18 Sep 2025 Chegg Inc.Chegg pays 7.5 million USD in FTC settlement over allegations of obstructed subscription cancellation USAInformation duties in online retail €6.35m

According to the FTC complaint, the education provider hid the cancellation option for its automatically renewing subscriptions on its website and, since October 2020, continued to charge almost 200,000 customers even after they had cancelled. Under the settlement, Chegg is paying 7.5 million USD for refunds and must offer simple cancellation.

What organisations can take from it

Cancellations received must be reliably implemented in the systems – continuing to charge customers is a separate violation.

Relevance to training and awareness

Cancellation processes and customer service for subscriptions

Authority / court
Federal Trade Commission (FTC)
Area of law
Consumer protection and online retail · Information duties in online retail
Legal basis
Restore Online Shoppers' Confidence Act (ROSCA); Section 5 FTC Act
Action
Disgorgement of profits
Status of proceedings
final
Sector
Telecoms, IT and software
Repeat case
yes
Published
15 Sep 2025

Original amount 7,500,000 USD, converted at the ECB reference rate of 18 Sep 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

28 Jul 2025 Cadence Design Systems Inc.Cadence pleads guilty: chip design software for Chinese military university USAExport control and dual-use goods €120.1m

From 2015 to 2021, the San José provider of chip design software supplied hardware, software and semiconductor IP at least 59 times to the National University of Defense Technology (NUDT), a military university on the Entity List, disguised under the alias Central South CAD Center. Cadence pleaded guilty before the US Department of Justice to conspiracy to commit export control violations; criminal penalties of almost 118 million USD and civil penalties of more than 95 million USD imposed by the Bureau of Industry and Security (BIS) result, after crediting, in a net total of more than 140 million USD.

What organisations can take from it

Include cover names and known aliases of listed customers in screening; sales and compliance must escalate indications of military end users.

Relevance to training and awareness

Recognising aliases and cover names of listed customers

Authority / court
U.S. Department of Justice; Bureau of Industry and Security (BIS)
Area of law
Sanctions and export control · Export control and dual-use goods
Legal basis
Export Administration Regulations (Entity List); ECRA; Verschwörung zu Exportkontrollverstößen
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Employees
10,000 or more
Culpability
intentional
Published
28 Jul 2025

Original amount 140,000,000 USD, converted at the ECB reference rate of 28 Jul 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

22 Oct 2024 Unisys Corp.SEC: $4 million against Unisys for downplaying cyber incidents after SolarWinds USADisclosure and reporting obligations €3.7m

In mandatory disclosures, Unisys presented cyber risks as hypothetical, although it had suffered two intrusions with data exfiltration connected with the SolarWinds compromise. On the same day, the US Securities and Exchange Commission (SEC) also imposed penalties on Avaya ($1 million), Check Point ($995,000) and Mimecast ($990,000).

What organisations can take from it

Do not describe cyber incidents that have occurred as a mere risk in investor information – disclosure processes must involve IT security.

Authority / court
U.S. Securities and Exchange Commission (SEC)
Area of law
Capital markets and financial supervision · Disclosure and reporting obligations
Legal basis
Securities Act of 1933, Securities Exchange Act of 1934 (inkl. Disclosure Controls)
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Culpability
negligent
Mitigating circumstances
Cooperation in the proceedings and improvement of cybersecurity controls.
Published
22 Oct 2024

Original amount 4,000,000 USD, converted at the ECB reference rate of 22 Oct 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Sep 2024 AppFolio, Inc.SEC: AppFolio pays 692,250 US dollars over waivers of whistleblower awards USARetaliation against whistleblowers €626,868

The provider of property management software had employees waive potential awards for reports to authorities in two employment agreements and one settlement agreement; 68 consulting agreements (January 2020 to October 2023) prohibited voluntary disclosures to authorities. As part of a sweep against seven listed companies, AppFolio paid 692,250 US dollars to the U.S. Securities and Exchange Commission (SEC); the contract templates were amended.

What organisations can take from it

Separation and employment agreements must restrict neither reports to authorities nor the entitlement to whistleblower awards.

Relevance to training and awareness

Whistleblower protection in contract templates (HR/Legal)

Authority / court
U.S. Securities and Exchange Commission
Area of law
Whistleblower protection · Retaliation against whistleblowers
Legal basis
Securities Exchange Act of 1934, Rule 21F-17(a)
Action
Fine
Status of proceedings
final
Sector
Telecoms, IT and software
Mitigating circumstances
Amendment of the templates after contact by the SEC, information provided to those affected, and cooperation
Published
9 Sep 2024

Original amount 692,250 USD, converted at the ECB reference rate of 9 Sep 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial