Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 756 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

USAStatesNY Clear all filters
10cases from 1 jurisdiction
€73.5mTotal of monetary amounts
€36.1mLargest single case: Block, Inc.
€1.93mMedian per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. New York State Department of Financial Services (NYDFS) €69.9m 95 % · 9 cases
  2. New York State Department of Financial Services (NYDFS) mit den Aufsichtsbehörden von CA, MN, NE, TX und MA €3.59m 5 % · 1 case

What for?

by area of law

All areas of law

  1. Money laundering and terrorist financing €62.4m 85 % · 3 cases
  2. Information security and cyber €11m 15 % · 7 cases

Who?

by sector

All sectors

  1. Financial services and insurance €73.5m 100 % · 10 cases

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20231€913,159
Q1 20240—
Q2 20240—
Q3 20240—
Q4 20240—
Q1 20251€1.92m
Q2 20251€36.1m
Q3 20253€28.1m
Q4 20252€4.35m
Q1 20260—
Q2 20261€1.92m
Q3 20261€216,375

10 cases

5 Aug 2026 Order Express, Inc.NYDFS: $250,000 against money transmitter Order Express over cyber deficiencies USA, NYSecurity measures and risk management €216,375

The licensed money transmitter had no adequate policies for system updates and insufficient risk assessments under New York's cybersecurity regulation, as found by the New York State Department of Financial Services (NYDFS). The company has already remedied the deficiencies.

What organisations can take from it

Even small financial service providers must keep documented patch policies and regular risk assessments.

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Information security and cyber · Security measures and risk management
Legal basis
23 NYCRR Part 500 (Cybersecurity Regulation)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Because of its low turnover, the company was exempt from many Part 500 obligations; deficiencies already remedied.
Published
5 Aug 2026

Original amount 250,000 USD, converted at the ECB reference rate of 5 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

29 Apr 2026 Delta Dental Insurance Company und Delta Dental of New York, Inc.NYDFS: $2.25 million against Delta Dental after MOVEit attack and late notification USA, NYSecurity measures and risk management €1.92m

In 2023, attackers exploited a zero-day vulnerability in MOVEit Transfer to steal files containing social security, driving licence, account and health data. The New York State Department of Financial Services (NYDFS) criticised inadequate retention settings, policies and controls as well as the late notification of the cybersecurity incidents to the supervisory authority.

What organisations can take from it

Keep data in transfer tools only for as long as necessary – and report security incidents to the supervisory authority on time.

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Information security and cyber · Security measures and risk management
Legal basis
23 NYCRR Part 500 (Cybersecurity Regulation)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Culpability
negligent
Published
30 Apr 2026

Original amount 2,250,000 USD, converted at the ECB reference rate of 29 Apr 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Oct 2025 Farmers Insurance ExchangeNYDFS: $2.775 million against Farmers over unprotected online quoting tools USA, NYSecurity measures and risk management €2.4m

Attackers harvested driving licence numbers and dates of birth via inadequately secured online quoting tools and agent portals. According to the New York State Department of Financial Services (NYDFS), Farmers infringed the cybersecurity regulation and did not report the incident in time; the penalty is part of a package totalling $19 million against eight motor insurers.

What organisations can take from it

Automatically pre-filled forms containing customer data are a point of entry – scrutinise public-facing applications for the data they disclose.

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Information security and cyber · Security measures and risk management
Legal basis
23 NYCRR Part 500 (Cybersecurity Regulation)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Culpability
negligent
Published
14 Oct 2025

Original amount 2,775,000 USD, converted at the ECB reference rate of 14 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Oct 2025 Infinity Insurance CompanyInfinity Insurance: 2.25 million USD – data leak via quoting tool reported too late USA, NYIncident reporting obligations €1.95m

Attackers extracted driver’s licence numbers in plain text via the motor insurer’s instant quote applications. Infinity discovered the anomalies on 9 February 2021 but only reported the cybersecurity event to the New York State Department of Financial Services (NYDFS) on 14 April 2021; the supervisor also criticised the lack of MFA and insecure development practices.

What organisations can take from it

Misuse of publicly accessible customer applications is also a reportable incident – warnings from the supervisor should trigger an immediate reporting assessment.

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
23 NYCRR § 500.17(a), § 500.12(a) u. a.
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Culpability
negligent

Original amount 2,250,000 USD, converted at the ECB reference rate of 14 Oct 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

14 Aug 2025 Healthplex, Inc.Healthplex: 2 million USD – phishing incident not reported to supervisor for months USA, NYIncident reporting obligations €1.71m

An employee of the dental insurance service provider disclosed his login credentials via a phishing e-mail; the mailbox containing over 100,000 e-mails with health and social security data was accessible. Healthplex had known about the incident since November 2021 but only reported it to the New York State Department of Financial Services (NYDFS) in April 2022 instead of within 72 hours; in addition, there was no MFA for web access and no data retention and deletion policy.

What organisations can take from it

Security incidents require a fixed reporting process with deadline control – the 72-hour clock starts when the incident is identified, not when forensics is completed.

Relevance to training and awareness

Recognising phishing; reporting channels for security incidents

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Information security and cyber · Incident reporting obligations
Legal basis
23 NYCRR § 500.17(a), § 500.12(b), § 500.13, § 500.17(b)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Culpability
negligent

Original amount 2,000,000 USD, converted at the ECB reference rate of 14 Aug 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

7 Aug 2025 Paxos Trust Company, LLCNYDFS: 26.5 million USD against Paxos over AML deficiencies in Binance business USA, NYCustomer due diligence €22.8m

The New York State Department of Financial Services (NYDFS) imposed a penalty of 26.5 million USD on the crypto trust company because Paxos did not maintain an effective BSA/AML programme before 2023: KYC checks and risk ratings were inadequate, and transaction monitoring and suspicious activity reporting procedures had gaps, including in connection with the business relationship with Binance, contrary to a 2020 agreement. In addition, Paxos must invest at least 22 million USD in its compliance programme.

What organisations can take from it

Companies that distribute products via partner platforms must include those platforms' customer and transaction risks in their own AML programme.

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
New York Banking Law §§ 39, 44; AML-Vorschriften des NYDFS und Bank Secrecy Act
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Published
7 Aug 2025

Original amount 26,500,000 USD, converted at the ECB reference rate of 7 Aug 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

9 Jul 2025 Wise US, Inc.Six US states: 4.2 million USD against Wise US over AML programme deficiencies USA, NYSuspicious activity reports €3.59m

In a coordinated multistate proceeding brought by six states – the New York State Department of Financial Services (NYDFS) with the supervisory authorities of CA, MN, NE, TX and MA – the money transmitter must pay 4.2 million USD. An examination (July 2022 to September 2023) found, among other things, a lack of independent AML reviews at an appropriate frequency, late suspicious activity reports, data quality problems in transaction monitoring and unremedied earlier findings; Wise does not admit any legal infringements and must conduct a lookback.

What organisations can take from it

Remedy findings from earlier examinations and audits on time – otherwise they become a ground for sanctions in their own right.

Authority / court
New York State Department of Financial Services (NYDFS) mit den Aufsichtsbehörden von CA, MN, NE, TX und MA
Area of law
Money laundering and terrorist financing · Suspicious activity reports
Legal basis
Bundes- und einzelstaatliches Recht zu Geldtransfer und BSA/AML (u. a. 31 CFR 1022.320)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Mitigating circumstances
Remedial measures already initiated and lookback
Published
9 Jul 2025

Original amount 4,200,000 USD, converted at the ECB reference rate of 9 Jul 2025.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

10 Apr 2025 Block, Inc.NYDFS: 40 million USD against Block (Cash App) over AML deficiencies USA, NYCustomer due diligence €36.1m

The New York State Department of Financial Services (NYDFS) imposed 40 million USD on the operator of Cash App for serious gaps in its BSA/AML programme, including insufficient customer due diligence, a lack of risk-based controls and untimely transaction monitoring. Rapid growth in 2019/2020 led to a considerable backlog of alerts; an independent monitor is being appointed.

What organisations can take from it

Scale compliance capacity with growth – a backlog of alerts is a supervisory infringement in its own right.

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Money laundering and terrorist financing · Customer due diligence
Legal basis
BSA/AML-, Geldtransfer- und Virtual-Currency-Vorschriften des NYDFS
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Employees
10,000 or more
Mitigating circumstances
Cooperation and remedial measures already initiated
Published
10 Apr 2025

Original amount 40,000,000 USD, converted at the ECB reference rate of 10 Apr 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

23 Jan 2025 PayPal, Inc.NYDFS: $2 million against PayPal over untrained teams and missing MFA USA, NYSecurity measures and risk management €1.92m

When changing data flows for 1099-K tax forms, insufficiently trained teams bypassed security processes; criminals with compromised credentials were able to retrieve forms containing social security numbers. According to the New York State Department of Financial Services (NYDFS), qualified personnel, training, access policies as well as MFA, CAPTCHA and rate limiting were lacking.

What organisations can take from it

Anyone changing data flows must know the security processes – training development teams is part of cyber defence.

Relevance to training and awareness

Secure software development and change processes

Missing or inadequate training played a role in the decision.

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Information security and cyber · Security measures and risk management
Legal basis
23 NYCRR Part 500 (Cybersecurity Regulation)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Employees
10,000 or more
Culpability
negligent
Mitigating circumstances
PayPal has since remedied the deficiencies.
Published
23 Jan 2025

Original amount 2,000,000 USD, converted at the ECB reference rate of 23 Jan 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

27 Nov 2023 First American Title Insurance CompanyNYDFS: $1 million against First American over open document links USA, NYSecurity measures and risk management €913,159

The EaglePro application generated links to transaction documents without login and without an expiry date; according to a journalist, by changing the sequential document number, 885 million documents containing, among other things, social security and bank data could be retrieved. Users were told not to send sensitive data, but there were no technical barriers. The penalty was imposed by the New York State Department of Financial Services (NYDFS).

What organisations can take from it

Instructions to users do not replace technical controls – sharing links need authentication and an expiry date.

Relevance to training and awareness

Classification and sending of sensitive documents

Authority / court
New York State Department of Financial Services (NYDFS)
Area of law
Information security and cyber · Security measures and risk management
Legal basis
23 NYCRR §§ 500.3, 500.7 (Cybersecurity Regulation)
Action
Fine
Status of proceedings
final
Sector
Financial services and insurance
Culpability
negligent

Original amount 1,000,000 USD, converted at the ECB reference rate of 27 Nov 2023.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial