
Sanctions Evasion Service Moved $6.9bn Through Global Banks
A leak of internal files shows a Russian payments group moved more than $6.9bn through global banks using front companies and forged trade documents.
Original write-ups of the governance, risk, compliance, privacy, and regulatory enforcement stories that matter. Published daily, rewritten in our own words, with every claim traced back to its source.

A leak of internal files shows a Russian payments group moved more than $6.9bn through global banks using front companies and forged trade documents.

RUSI says the EU needs one shared way to judge vendor risk in critical infrastructure technology, instead of leaving decisions to member states.

The SEC proposed rules for how investment advisers and regulated funds may custody crypto assets, including self custody and state trust company custodians.

The Information Commission replaced the Information Commissioner as the UK's data protection regulator, moving statutory powers from one person to a board.

ESMA will make AI and tokenisation a Union Strategic Supervisory Priority from 2027, directing national supervisors to scrutinise how firms use both.

The SEC says Beyond Alpha raised $8.7 million from 35 investors on false claims of pre-IPO holdings and returns, with criminal charges filed in parallel.

The SEC alleges Meyer Global Management and its CEO misused client fund assets in funds holding SpaceX and other pre-IPO stakes and inflated investor statements.

The SEC proposed amendments to expand retail access to private markets and asked whether professional credentials should confer accredited investor status.

The FRC revised ISA (UK) 620 and ISAE (UK) 3000 to align with the IESBA ethics code on using external experts, effective 15 December 2026.

GAO finds critical infrastructure sectors face conflicting federal cyber reporting rules, with CISA and SEC requirements named by every participant.

AI agents need their own identity, a named owner, scoped and expiring authority, and runtime telemetry that shows what they actually executed.

The SEC says two overseas-linked groups used WhatsApp and falsified Form D filings to pose as regulated firms, taking over $15 million from retail investors.

New categories on the FCC Covered List block equipment authorization for foreign-produced robots and inverters, reaching well beyond Chinese manufacturers.

New research finds nearly 16% of MCP server hostnames resolve outside the US, and one always-allow permission was enough to hand over sensitive files.

Mandiant says ShinyHunters bypassed string-based WAF rules by URL-encoding one character in the path, reaching an endpoint teams believed was mitigated.

The SEC says Zoe Financial's adviser-matching algorithm and its own Zoe Wealth service created conflicts that went undisclosed until December 2024.

Since 11 September 2026, manufacturers selling digital products in the EU must report exploited vulnerabilities and severe incidents in 24 hours.

Kiteworks asked customers to switch off its platform for six hours after US intelligence agencies warned of a possible attack.

A record US settlement forces Meta to change how Facebook and Instagram are designed, with lessons for UK and EU obligations.

OpenAI says its AI agents interacted with SEC and Census Bureau sites in unexpected ways, and an outside lab found more activity.

Three Agentforce flaws let a poisoned Web-to-Lead form make an AI agent leak CRM data and send phishing messages through Slack.

A new Senate bill would establish an independent Cybersecurity and AI Board of Investigations to review hacks carried out by AI agents.

CISA's 2026 election security plan warns that certification rules slow patching and that voter registration databases remain a prime target.

From 1 September 2026, around 37,000 more UK financial firms can face regulatory action for bullying, harassment and violence at work.

A DHS inspector general report found most federal agencies missed the CISA cloud security deadline, and that CISA cannot compel compliance.

The US and China agreed to set up a channel for handling AI related incidents, with a dedicated AI dialogue scheduled for November.

A US appeals court ruled border officers may scroll through travelers' phones without suspicion, deepening a split over digital privacy at the border.

A joint advisory says attackers used a US industrial automation company's network as a roadmap for later attacks on power and transport customers.

The EDPB adopted guidelines giving data protection authorities a five-step method for deciding whether to fine, and opened them for comment until November 13.

The Federal Reserve proposed reserve, capital and risk management standards for stablecoin issuers under the GENIUS Act, opening a 60-day comment period.

Forty-four state attorneys general settled with Labcorp over a 2019 breach traced to a debt collector, requiring audits and vendor security terms.

Deloitte UK found almost a third of generative AI users run tools at work without their employer knowing, and nearly half had no safety training.

ShareGate's survey of nearly 1,800 IT professionals found 77% of organisations had a Microsoft 365 governance incident in the past year.

US prosecutors allege Oxygen Forensics masked Russian ownership to win millions in government contracts for its mobile forensics software.

The SEC's enforcement director says the division will aggressively pursue fraud and compliance failures, and will judge itself on quality, not case counts.

A UK Civil Service deputy CISO says mandates alone failed across 465 public bodies, so government is building central services that teams actually adopt.

A $100 million CISA pilot proposed in the House would give small water and power operators free access to frontier AI models for defence.

The EU Court of Auditors found unclear roles and slow NIS2 transposition are limiting how fast the bloc can detect and respond to major cyber incidents.

Ofcom opened an investigation into Aylo over whether its Apple based age assurance was properly tested before it was offered to UK users.

The SEC charged CMI Capital and its founder with raising $860,000 from investors, many of them current or retired South Florida law enforcement officers.

A cybercrime group defaced the FBI's recruitment site, says it holds data on agents and job applicants, and wants a federal advisory withdrawn.

Abbott agreed to pay $384,999,040 to settle claims that it sold infant formula produced in unsanitary conditions at two of its plants.

Governor Newsom's executive order asks for options including kill switches for frontier models and independent verifiers placed inside AI labs.

China's new AI Safety Governance Framework focuses on agentic systems, loss of control and countermeasures for AI-driven cyberattacks.

Justice Manual revisions limit what sub-regulatory guidance can require and push DOJ toward dismissing meritless qui tam cases.

The SEC censured broker-dealer OTC Link and fined it $575,000 after examiners flagged the same missing trading system policies for years.

HHS settled a HIPAA case with Ambry Genetics over a 2020 phishing breach affecting 225,370 people, citing a missing risk analysis and access control gaps.

The CFTC proposed codifying CPO and CTA registration exemptions that firms have relied on through a no action letter, with comments open until October 5.

The Upper Tribunal upheld Crispin Odey's lifetime ban and a reduced fine, and the FCA said it will not tolerate a slapdash approach to ethics.

Ireland's data protection regulator fined Google €403 million over how three features handled location data, and ordered fixes within six months.

California's privacy agency says incorrect data broker registration filings draw the same $200-per-day penalty as not registering at all, intent is not the test.

CISA will stop publishing its weekly vulnerability roundup at the end of September, replacing cadence and severity scores with risk-based prioritization.

A UN sanctions monitoring report prompted investigations in Argentina and Pakistan, and confirmed sanctions against enablers in Vietnam and Laos, over North Korean IT workers.

Both Reg S-P compliance deadlines are behind us. The SEC's exam division will now test whether firms actually operate the incident response and vendor oversight programs they wrote.

Spain's data protection agency described a breach where a hacker used a language model to find credentials, enter a corporate system and modify personal data records.

Bills passed in California's final session weeks would curb website tracking lawsuits, expand CCPA deletion rights and tighten AI content disclosure.

The Conference of State Bank Supervisors released a voluntary framework that tells examiners how to assess AI use at the banks they supervise.

Delaware HB 381 requires Attorney General notice within 60 days when affected residents cannot be identified, and narrows the GLBA and HIPAA safe harbor.

Helpfeel says an attacker exploited a flaw in its image upload server and reached a database holding roughly 23.6 million Gyazo user records.

A Texas judge found TikTok liable for misrepresenting its content moderation and the availability of explicit material to minors using Restricted Mode.

FBI data shows nearly 61,000 impersonation complaints and $1.6 billion in losses since January 2025, averaging over $26,000 per case.

A compliance veteran's account of the July 4, 2025 Guadalupe River flood turns five hard lessons into a case for better risk planning.

EO 14412 sets 2030 and 2031 deadlines for federal post-quantum migration and turns cryptographic inventory into an audit question.

The Coast Guard and FBI boarded two US-bound tankers in the Gulf of Mexico after indications that the vessels' networks had been compromised.

Ofcom has fined 11 service providers more than £7 million under the Online Safety Act, yet its enforcement chief says most penalties remain unpaid.

Compliance teams are being urged to extend employee trading surveillance to prediction market contracts that sit outside existing broker feeds.

The SEC gave tokenized securities venues conditional five-year relief from exchange registration to trade tokenized NMS stock via permissioned pools.

DSIT's new AI Risk Management Toolkit gives multidisciplinary teams a workbook, a monitoring dashboard and probing questions to assess AI risk.

CVS Health and Criteo agreed to a $20.5 million settlement over claims that tracking code on CVS sites shared patient health information with an ad firm.

UK court staff accessed the files of Southport victims without authorization, and the Information Commissioner's Office has been notified.

NIST and CISA published final guidance for agencies and cloud providers on stopping token theft, forgery and misuse in single sign-on and API access.

A New Jersey court transferred radaris.com and 13 other domains to a privacy plaintiff after the data broker failed to defend claims under Daniel's Law.

The SEC proposed rescinding Rule 14a-8, which would move shareholder proposals to state law, and separately proposed modernizing proxy solicitation rules.

A review of sovereign digital currency pilots finds adoption fails on anti-money laundering, sanctions screening and supervisory capacity, not on blockchain.

Experts say the FCA's principles-based approach to AI can still work, provided the UK framework is reviewed regularly as the technology changes.

Southern Glazer's agreed to pay $12.5 million under a DOJ non-prosecution agreement over improper payments to retail buyers and false invoices.

A UK parliamentary committee found no regulator can block or compel a frontier AI model, and called for a risk-tiered AI bill with a single watchdog.

Manufacturers selling digital products in the EU must now report actively exploited vulnerabilities within 24 hours under the Cyber Resilience Act.

The UK fined Citibank's London branch £4.7 million after 970 payments worth nearly £19.7 million breached Russian sanctions rules.

The PCAOB adopted amendments to its QC 1000 quality control standard to cut compliance costs, keeping the December 15, 2026 effective date.

FBI officials said AI is accelerating adversary operations, while stressing security fundamentals and continuous, risk-based patching.

Humboldt Merchant Services will pay $12 million and stop processing payments for high-risk merchants after the FTC said it enabled fraud.

The Treasury sanctioned Xinbi Guarantee, a Chinese-language marketplace that processed more than $24 billion in support of Southeast Asian scam centers.

The SEC charged Ernest Ossei Boateng and two companies he controls with raising about $16 million from more than 200 inexperienced investors.

A US watchdog found that every CBP network user could run privileged service accounts, exposing the border agency to serious attack risk.

The FBI's new cyber strategy formalizes adversary takedowns and aims to rebuild company trust in reporting attacks to the bureau.

The FTC withdrew its 2021 policy that treated health and fitness apps as covered vendors under federal breach notification rules.

Lawmakers asked the Treasury to sanction three India-based hack-for-hire groups behind years of espionage against Americans.

Dutch regulators fined Uber about EUR 825 million for using fully automated decisions to deactivate drivers over poor reviews.

Grindr will pay £26m to settle a UK group action over allegations it shared HIV status and other sensitive data with third parties before 2020.

Researchers say LG smart TVs captured audio transcripts and mapped nearby devices even in standby, raising fresh questions about consent and disclosure.

The UK government's corporate reporting reform consultation promises simpler rules and says the changes could save companies more than £450 million a year.

At least four class actions target IDScan.net after reports tied the company to a breach exposing more than 153 million driver's license records.

Moody's research finds most banks now embed compliance at the start of AI projects, with only 17 percent treating it as a final approval gate.

Natural Resources Wales published staff diversity data in a 2021 FoI response and only found out five years later that it was still exposed.

European Parliament members want Serbia's EU accession slowed until it investigates Pegasus and NoviSpy infections of student activists.

Compliance Week says the reach of DOJ's new National Fraud Enforcement Division is still unclear, eight months after its announcement.

Banking agencies said banks may discuss suspicious transactions with customers without breaking SAR confidentiality, as long as no filing is revealed.

The FCC proposed a consumer scorecard rating telecoms on robocall prevention and removed 14 providers from U.S. networks.

The DOJ charged a Russian national with using fake freelance accounts to spread Excel malware to about 80,000 platform users.

The SEC proposed rescinding the rule that bars investment advisers from government work for two years after political donations.

Unit 42 says ransomware attackers used AI agents to breach an enterprise network in under 10 hours and left an 80-page security audit.

Ireland's Data Protection Commission fined the HSE €645,000 after paper psychiatric records were found decaying in disused hospital buildings.

The U.K.'s Data (Use and Access) Act is now fully in force, reshaping consent, subject access requests, and automated decision-making.

The FBI warned that attackers are tricking executives and officials into granting malicious app access that bypasses passwords and multifactor authentication.

The FBI is investigating a dark web service selling more than 153 million drivers license scans, reportedly tied to an identity verification vendor.

As EU member states shift to NIS2 enforcement, access management and credential hygiene offer the fastest auditable compliance wins.

The SEC charged two former Pacific Private Money Group executives with an offering fraud that raised over $80 million from about 190 retail investors.

The SEC proposed modernizing rules for registered transfer agents, the first substantive update since the late 1970s and early 1980s.

Anthropic's new Compliance API for Claude Code shows why governing AI agents needs local visibility, identity mapping and audit trails.

The DoJ revised its statement on Chinese state-sponsored hacking, saying US agencies were targeted rather than victims of intrusion.

The FCA says UK financial services firms still show serious gaps in KYC and financial crime controls despite claiming they have strengthened checks.

The SEC proposed covering European Union debt under Exchange Act Rule 3a12-8, giving the CFTC exclusive oversight of EU debt futures.

Treasury sanctioned five Mabna Institute hackers and tied 30 crypto wallets to their campaigns, a concrete checklist for sanctions screening.

Australia's Scams Prevention Framework fines banks heavily but leaves dating apps and crypto exchanges outside its scope.

Chubb's 2026 report shows average cyber insurance claim costs surging for large firms even as the number of claims dropped.

The UK's ICO fined Elderly Aids £190,000 for making 758,000 unsolicited marketing calls to TPS-registered numbers.

Meta agreed to pay up to $18 billion and overhaul teen safety features to settle child safety claims with nearly every US state.

Australian police charged two men linked to TeamPCP, the group behind the March 2026 compromise of Trivy, KICS and LiteLLM.

Medical device maker Boston Scientific disclosed a cyberattack that hit its IT network and disrupted global operations, including customer order processing and shipping.

The FBI and DOJ disrupted two hacking platforms used by Chinese state-sponsored group QTFY to target U.S. critical infrastructure and government agencies.

NIST identified 23 security and compliance challenges unique to multi-cloud environments in a new report.

OpenAI shut down Russian ChatGPT accounts that ran a covert influence campaign promoting a fake think tank and a 'sovereignty' index favoring Russia.

The FTC and five states settled antitrust claims against Zillow and Redfin over a deal that paid Redfin to exit the rental advertising market.

ETSI has published 17 draft cybersecurity standards to underpin the EU Cyber Resilience Act. What this means for product manufacturers compliance timelines and the harmonized standards route to presumption of conformity.

The UK ICO has called on police forces to strengthen data governance around live facial recognition deployments. What this means for biometric data compliance and public sector accountability.

The Solicitors Regulation Authority has warned law firms about AI misuse risks. What this signals for professional services governance and the compliance obligations around generative AI in regulated sectors.

California's AI transparency law is now enforceable, but detection tools to verify compliance are missing. What this gap means for GRC teams building AI governance programs.

US authorities unsealed charges against 17 Iranians tied to Mabna Institute, expanding the 2018 case over a university cybertheft campaign.

ETSI has published 17 draft standards to operationalize the EU Cyber Resilience Act. Manufacturers of connected products now have a concrete path to compliance, but the technical lift is significant.

The SEC charged three former Tricolor executives with fraud over double pledged subprime auto loans tied to the lender's bankruptcy.

The SEC unveiled a proposed regulatory framework for crypto assets that could bring tokens, platforms, and intermediaries under federal securities law. What GRC teams at crypto-adjacent firms need to prepare for.

The SEC proposed Regulation Crypto Assets, a tailored securities regime with two offering exemptions and a safe harbor for crypto issuers.

The SRA warned UK law firms that AI hallucinations in court filings and client data entered into public AI tools can breach their regulatory duties.

The FCC may add Chinese-made optical transceivers to its Covered List, barring new models from US data centers. A third-party risk story for every AI operator.

FinCEN levied a historic AML penalty against UBS stemming from long-running compliance failures. The case shows how sustained regulatory pressure builds toward enforcement that reshapes an institution.

Wiz found a GitHub Actions workflow injection in Snowflake's public repo that exposed internal Jira credentials. What it teaches GRC teams about CI/CD risk.

OFAC designated Shelbit, an Iranian crypto exchange processing $6 billion in volume, for facilitating sanctions evasion. The action signals expanding enforcement into digital asset intermediaries.

NIST is asking for public comment on modernizing the National Vulnerability Database to support AI-driven vulnerability management. What this means for compliance programs that rely on CVE data.

ETSI published 17 draft standards supporting the EU Cyber Resilience Act, now open for public comment. What the CRA standards pipeline means for anyone building or buying connected products.

The UK ICO issued a reprimand over a 2023 breach at the ACRO Criminal Records Office. What this says about data protection oversight of public bodies, and what GRC teams should take from it.

The US Department of Defense suspended Phase II of the Cybersecurity Maturity Model Certification. What the pause means for contractors, assessors, and anyone running a compliance roadmap.

Over 120 tech organizations back the Shared AI Findings Exchange, a framework for confidentially sharing AI security incidents and translating them into defensive guidance.
Every article links to its original reporting for attribution. Original analysis by Zabez; not affiliated with the sources. Illustrations original to ZABEZ.com.