Skip to content

Compliance News | September 2026

19 minute read

Compliance News
Last updated: September 22, 2026

This month's key compliance news includes Citi's sanctions failings, Samsung's trademark infringement, data breaches at Revolut and an NHS trust, and more.

Our pick of compliance stories this month

Citibank London fined £4.7m for sanctions failures

Citibank has been fined £4.7 million for sanctions failures at its London branch, the UK's Office of Financial Sanctions Implementation (OFSI) said.

Between February and November 2022, Citibank's London office processed 970 prohibited payments worth £19.72 million involving designated Russian individuals and entities. Around £4.3 million of those payments were processed within 24 hours of the designation.

The regulator acknowledged that Citibank faced increased exposure due to its Russian client base, correspondent banking operations with Russian financial institutions and payments relating to its Russian affiliate, AO Citibank.

The introduction of sanctions put a "significant strain on the bank's alert handling and investigation processes", leading to delays in reviewing and escalating sanctions alerts. Human error also contributed to some breaches.

OFSI was especially concerned about a temporary change to internal guidance that was designed to manage the backlog of alerts. Staff no longer needed to request restrictions for every account potentially connected to a designated person, unless there was evidence that the person owned 50% of the entity. This change increased the risk of accounts being unrestricted for long periods due to the delays in processing alerts.

The bank voluntarily disclosed most of the breaches. But other breaches worth around £6.9 million came to light only after OFSI made enquiries, and some of the bank's self-disclosures were incomplete.

"OFSI does not consider there to have been any intent by CBNA London to breach sanctions. However, the errors and failings referred to above were, in aggregate, material and significant and they occurred across a wide range of business areas ⁠and systems within the bank."

-Office of Financial Sanctions Implementation (OFSI)

Key takeaways:

  • Conduct adequate sanctions screening - on existing customers, especially those in high-risk places or with links to sanctioned countries

     

  • Be vigilant and alert to potential screening defects - for example, Citibank's KYC records referred to 'PAO Sovcomflot' whereas the OFSI list used 'Sovcomflot'. The bank's screening system could not handle PAO (the Russian equivalent of a PLC) so no alert was generated. As a result, Citibank processed 328 transactions worth £5.4 million through accounts held or controlled by the shipping company PJSC Sovcomflot

     

  • Conduct proportionate due diligence - with enhanced due diligence on high-risk customers and activities. Conduct accurate assessments of the control and ownership of entities, and document the results

     

  • Keep full records - Citibank's internal records did not include the bank-identification codes (BICs) of designated Russian banks. This meant payments involving designated banks (eg Alfa-Bank, Gazprombank and Amsterdam Trade Bank) were not identified

     

  • Screen the entire chain - Citibank's payment system screened transactions upfront before a correspondent bank was automatically selected to route the payment. This resulted in designated entities being involved in the chain without generating sanctions alerts. Similarly, the designated ultimate beneficiary was not identified when Citibank was asked to return payments to Rosbank and Gazprombank

  • Make timely reports - Citibank failed to report frozen assets promptly on 53 occasions, with delays of more than six weeks. The average time taken between suspecting the bank held frozen funds and filing the report was 274 days

  • Don't use 'workarounds' to bypass controls or evade sanctions restrictions - eg accepting payments via intermediaries

  • Stress test different scenarios - to ensure screening processes are resilient and adapt to rapid and unexpected changes.

Explore our Compliance Essentials Library

Time's up? Samsung ordered to pay Swatch $11.6m for trademark infringements

Samsung Electronics has been ordered to pay Swatch Group $11.6 million in damages for trademark infringements.

Samsung hosted smartwatch apps with designs that imitated the Swiss company's luxury brands such as Breguet, Longines, Blancpain, Tissot and Omega on its Galaxy app store between 2015 and 2019, a UK court heard.

The apps, which were created by third parties, had been downloaded around 160,000 times and were described by Swatch as "knock-offs" that amounted to "large-scale appropriation" of its "valuable and carefully protected" trademarks. Samsung was held liable for failing to control the review process.

"Use of the Swatch Group brands on Samsung's supermarket shelves, downloadable for nothing or for little money, is to my mind very damaging. The low price is demeaning of the brands the Swatch Group seek to promulgate ."

-Judge Marcus Smith 

The ruling is far below the $170 million damages originally sought by Swatch, which claimed the electronics giant had "repeatedly attempted to downplay the scale and significance of the infringements by trivializing the compensation owed to the Swatch Group's well-known brands". Separate proceedings have been brought by the 10 brands in the US.

A Samsung spokesperson confirmed it was examining the judgment and may now appeal. Its lawyers had earlier described the demand as "extravagant". It had claimed that Swatch had suffered no damage and only a trivial sum of $300 was owed.

Start your free trial

Revolut confirms data breach after fake government request 

Revolut has confirmed that it was targeted in a "sophisticated external impersonation scam". The London-based fintech disclosed personal data of 680 customers after it received a fake information request from an email that used a legitimate government agency domain.

The data included customers' identity documents (including passports and drivers' licences), post and email addresses, verification selfies, as well as account information and transaction histories (including Bitcoin).

"Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators."

-Revolut 

The fintech stressed that the company's systems and customer funds were not affected. 

Hackers abused the trust associated with a government agency to trick Revolut into sharing unauthorised information. They have threatened to publish information "every day" unless the challenger bank pays a ransom of 10,000 Bitcoins. 

The incident appeared to target high-net-worth customers. The affected customers were alerted by email. 

Speaking to Computing magazine, experts said that the breach raises questions about how financial firms deal with requests for sensitive information. 

"No malware. No stolen credentials. Just a request that looked legitimate and a process built to comply once it did. This is the gap most security programs still don't close."

-Patricia Titus, Abnormal AI

"The question isn't why an attacker tried this. It's why a regulated financial institution handling highly sensitive data didn't have sufficiently rigorous verification controls to catch it."

-Muhammad Yahya Patel, Huntress 

Key Takeaways:

  • Train your team to recognise threats - including social engineering attacks and the different forms they may take, such as phishing, vishing and smishing

  • Look out for sophisticated attacks - such as the use of AI-enabled or deepfake approaches

  • Be careful with requests from recognised government agencies or brands - criminal groups try to exploit relationships with people we trust including high-street names (eg banks, mobile providers, utilities, etc) by impersonating them. They may use fake emails or domains and send malicious requests for financial information

  • Slow down - scammers create pressure or urgency to force you to act quickly. Stop and think first - is the request genuine?

  • If in doubt, verify - contact the requestor using details you already hold to confirm that the request is legitimate

  • Promptly report suspicious activity - including to IT, the Data Protection team or Compliance so they can liaise with the relevant authorities. 

Discover Aida by Skillcast

Airport hackers publish data on 8.7m customers

Hackers have posted the personal data of 8.7 million people online following the cyberattack on Manchester Airports Group (MAG). 

Experts are warning people to be vigilant because the data may include past and future travel plans and they could be targeted in secondary attacks. 

Hackers accessed the personal data of customers of Manchester, East Midlands and London Stansted airports last month and demanded a ransom. The data related to "car park, lounge and fast-track bookings and in-airport wifi sign-ups". 

At the time, MAG also confirmed that email addresses, phone numbers, vehicle registration numbers and postcodes had been accessed. However, MAG stressed that this did not affect passenger safety or aviation security. No bank and payment details were stored on the hacked system. 

In a statement, the company said:

"MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support."

The Information Commissioner's Office (ICO) has reminded customers to report stolen documents, check bank statements for unusual activity, be alert to suspicious emails, phone calls and messages, and use strong passwords or multi-factor authentication. 

Last year, flights were delayed at European airports, including Heathrow, following an attack on the company that provided check-in and boarding software.

See our Cybersecurity Training Package

NHS trust apologises after hospital worker shared screenshot with partner 

Somerset NHS Foundation Trust has apologised to patients after a hospital worker accessed over 200 patient records inappropriately between August 2017 and October 2023. The Musgrove Park hospital worker shared a screenshot of a patient's medical record without permission and contacted another patient using a phone number taken from hospital records. 

The breach was reported to the Information Commissioner's Office in October 2023, but the worker resigned before disciplinary action could be taken. She received a police caution for "unlawful obtaining of personal data" as her actions were not malicious and were not done for financial gain. 

The worker accessed the records of patients and people she knew, including colleagues, friends, family members and partners. One victim said, "She didn't just breach data, she violated families, vulnerable people, and even the records of those who aren't alive to defend themselves… Where's the justice?" 

There have been over 1,400 serious patient data breaches across the NHS, according to the Health Service Journal. There have been breaches related to victims of the Southport murder, the Nottingham attacks and the boy attacked by a crocodile.

Sam Smith from privacy campaign group Med Confidential says the case raises wider concerns about access to health records and transparency. He would like patients to receive automated notifications via the NHS App if someone accesses their records. 

"We apologise unreservedly to every person whose hospital record has been inappropriately accessed in this way. Many NHS professionals need access to confidential information in order to do their jobs effectively... Very sadly, this was not respected in this case. "

-Phil Brice, Somerset NHS Foundation Trust

Key Takeaways:

  • Train your team so they recognise personal data - ensure they know what rules apply and how to handle it

  • Check access rights are appropriate - access should only be granted to those with a legitimate business need and information should be kept to a minimum

  • Meet the data protection principles - ensure there is a valid reason for data processing, and data is secure and protected

  • Implement effective control measures - ensure access is removed right away when someone leaves, moves or changes their job

  • Take extra care when dealing with sensitive or special category data, such as health or medical information - as extra provisions and safeguards apply

  • Be clear about the rules on information sharing - ensure sharing is lawful, especially for confidential and sensitive information

  • If there is a serious data breach, inform the Information Commissioner's Office within 72 hours - affected individuals must be notified without undue delay if there is a high risk of the breach adversely affecting their rights and freedoms. 

See our GDPR Training Course

Automotive parts company starts settling €20m fine for cartel 

Romanian battery maker Rombat has paid the first instalment to settle its €20.218 million fine imposed by the European Commission for its involvement in a European cartel. 

A South African listed automotive parts group and parent of the Romanian subsidiary, Metair, is jointly liable for €11.6 million of the fine. 

Although both companies are challenging the decision, a European court refused to overturn the fine or suspend payment pending their appeal. 

The European Commission fined automotive starter battery manufacturers around €72 million after finding that Rombat, Exide and FET had used a pricing mechanism that increased the cost of batteries.  

The companies coordinated their approach and imposed a surcharge linked to the price of lead, one of the main battery inputs. They passed on the additional costs to customers. 

Rombat will pay the penalty over 51 months, rather than as a single payment. 

See our Competition Law Course

Adviser fined and banned for unauthorised pension transfer advice 

Financial adviser and director of DPT Financial Solutions Limited, Daniel Thomas, has been fined £742,700 and banned from the financial services industry by the Financial Conduct Authority. 

The FCA claimed that, over five years, Mr Thomas advised 53 clients about 63 transfers out of defined benefit pension schemes without being qualified or authorised to do so, earning around £173,000 in fee income. 

DPT Financial Solutions Limited was an appointed representative (AR), requiring another firm (as principal) to oversee its actions. However, Mr Thomas repeatedly gave misleading information to the principal firm about the extent of his involvement in pension transfer cases. 

The FCA said Mr Thomas also repeatedly misled clients and pension providers about his professional qualifications, destroyed client records and failed to cooperate with its investigation. 

It is not usually in an individual's best interests to transfer out of defined benefits pension (DBP) schemes because they often provide valuable, guaranteed benefits that increase each year in line with inflation. 

The FCA's Conduct of Business Sourcebook (COBS) allows only advisers with specialist qualifications and the correct permissions to advise consumers to transfer out. 

In addition, the FCA said that Mr Thomas breached its Statement of Principles, including Principle 1 (integrity), Principle 2 (due skill, care, and diligence) and Principle 4 (cooperation).

Mr Thomas is appealing the decision. 

"When you advise someone on their pension, you hold their future in your hands. Mr Thomas recklessly betrayed that responsibility. We will not stop acting against those ignoring our rules and unfairly putting people and their hard-earned money at risk." 

-Therese Chambers, the FCA's Executive Director of Enforcement and Market Oversight  

See our FCA Handbook Training Package

Odey loses appeal to overturn financial services industry ban 

Former hedge fund manager Crispin Odey has failed to overturn a ban on working in the UK financial services industry following an appeal heard by the Upper Tribunal. 

Mr Odey was the founder and owner of Odey Asset Management (OAM). Odey was fined £1.84 million and banned from the industry after claims were made in the Financial Times that he sexually harassed or assaulted women "for decades".

Odey threatened and dismissed the Executive Committee (ExCo) when directors refused to give in to pressure. 

The Tribunal agreed with the FCA's findings that Mr Odey showed "reckless disregard" for the governance of Odey Asset Management and instead sought to protect his own interests. It also upheld findings that Mr Odey's dealings with OAM, its clients, investors and the FCA lacked candour.

"During the hearing he [Odey] reinvented history, painted himself as a victim and displayed no contrition. That arrogant entitlement and the resulting complete disregard for proper governance means Mr Odey is unfit to work in financial services."
-Therese Chambers, the FCA's Executive Director of Enforcement and Market Oversight 

The new rule COCON 1.1.7FR, to tackle non-financial misconduct, came into effect on 1 September 2026 and extends the scope of conduct rules to non-banking regulated firms, including hedge funds, insurers and pension funds. It covers bullying, harassment and violence, where there is a work-related link. 

While the new COCON rule focuses on conduct where there is a work-related link, the new FIT guidance includes a wider range of NFM that firms should take into account when assessing individuals. Under the new rules, firms are required to pass on reports of misconduct, such as sexual harassment, racism, violence and intimidation, to prospective future employers to stop so-called "rolling bad apples".

Key takeaways:

  • Arrange training - so your employees and managers know what NFM is, are aware of the changes and how they'll affect them

  • Recognise what "serious" misconduct means - for example, conduct in private life (including social media) is relevant if there's a material risk of the individual breaching regulatory standards or it could damage confidence in financial services

  • Avoid overreaching into individuals' private lives - don't look into past rule breaches, revise past FIT assessments, monitor employees' private lives or social media, investigate trivial or irrelevant allegations about their private lives, or do anything contrary to privacy or employment laws

  • Provide role-specific training so managers and decision makers take reasonable steps to prevent and address NFM (in line with the new Worker Protection legislation) - remember, failure to prevent and address NFM may be a breach of Conduct Rule 2

  • Strengthen fit and proper assessments - to ensure individuals make appropriate disclosures about their private lives (including convictions) where this affect fitness and propriety assessments

  • Improve documentation - ensuring there are adequate records of NFM along with the action that was taken, particularly where there are regulatory impacts

  • Review our regulatory references process - so our overall approach to NFM is consistent and lawful, with clear justification about what is and isn't disclosed in references to prospective employers

  • Strengthen reporting mechanisms - including speak up channels. Encourage psychological safety so colleagues feel confident speaking up if they experience or witness misconduct, such as bullying or harassment, and have faith that their concerns will be assessed independently and fairly, without fear of retaliation

  • Improve governance and oversight - to ensure NFM is escalated. Make sure senior managers and the board receive regular risk reports on culture, including NFM metrics and whistleblowing reports  

See our Financial Crime Training Package

US Treasury flags $13 billion linked to digital asset scams 

The US Treasury's Financial Crimes Enforcement Network (FINCEN) has warned financial institutions to be vigilant to digital asset investment scams being carried out via overseas scam centres. 

Digital asset investment scams are sophisticated fraud schemes that are also known as "pig butchering", "romance baiting" or "cryptocurrency confidence schemes". Criminals use social engineering tactics and fake personas to trick victims into transferring funds to fraudulent investments.  

Such scams are often masterminded by criminal gangs operating in South East Asia from vast compounds and exploit vast networks to manipulate victims and profit from them. 

FINCEN analysed 33,904 Bank Secrecy Act (BSA) reports involving suspected digital asset investment scam activity that were filed between September 2023 and December 2025. It identified $12.7 billion in financial activity linked to scams. 

  • Individuals of all ages were targeted

  • Well-known fraud tactics were used, with illicit actors often using assumed names or identities to pose as romantic partners, new friends or potential business partners to target victims

  • Scammers often created websites or mobile apps to imitate legitimate investment services 

  • Professional money launderers were used to set up financial accounts and shell companies, as well as for moving funds

  • Proceeds were integrated into the financial system through networks of money mules and via stablecoin transfers to digital asset exchanges around the world 


FINCEN also identifies 16 red flags to help financial institutions detect and report suspicious activity related to scam centres, including: 

Victim payments

  • Customers are directed by a supposed representative of law enforcement or a government agency to make a payment using digital assets, to conduct an international wire transfer, or to purchase precious metals or gift cards.
  • Customers say that a payment is intended to retain a law firm or other entity to recover funds lost to fraud but lack documentation demonstrating that the service is legitimate.

  • Customers withdraw funds from an investment or retirement account to purchase gold from a precious metals dealer and indicate that they have been instructed to hand the gold to a courier.

  • Open-source information shows that an MSB receiving customer funds has claimed to be "approved by FinCEN" or a digital asset exchange is advertising services "with no KYC".

Guarantee Marketplaces 

  • Customers conduct transactions involving a digital asset token associated with a guarantee marketplace and fail to provide source-of-funds documentation.

  • A payment service provider operating a guarantee marketplace changes its name, branding, website or other features to mask its association with a marketplace linked to law enforcement action, takedowns or negative news.

  • Customers transact with a cluster of digital asset addresses which blockchain analysis flags as sharing blockchain infrastructure with a known guarantee marketplace.

  • Customers transact with a digital asset address linked to a guarantee market and transactions have no apparent economic, business or lawful purpose.

  • A payment service provider offering digital asset exchange services operates in Burma, Cambodia or Laos and hides its location or corporate structure.

Laundering techniques 

  • Customers of a DeFi service receive deposits from wallets that aggregate suspected scam proceeds and use the DeFi service to move proceeds into a different digital asset or blockchain.

  • Customers conduct substantial transactions using a stablecoin whose issuer advertises that it does not cooperate with law enforcement or its stablecoin cannot be seized or frozen.

  • Customers appear to use liquidity to execute large numbers of offsetting transactions consistent with operation as an OTC broker or P2P exchanger.

  • Customers receive stablecoin deposits from a DeFi service lacking AML/CTF controls, converts the funds to fiat currency and withdraws the proceeds. 

Explore our Compliance Bites Library

 

France imposes levy to slow fast fashion 

France has introduced fees on fast-fashion clothing to reduce sales of cheap clothing sold on e-commerce sites.

The levy, which could reach almost €20 per item by 2030, was introduced after a law was passed in June to regulate "ultra-fast fashion".

Ultra-fast fashion is determined by the volume of clothing placed on the market and the cost of repairing garments in relation to their purchase price.

E-commerce sites, such as Shein, Temu and AliExpress, have been criticised by French officials for driving the demand for cheap clothing.

"The harmful effects of ultra-fast fashion on our environment and our economy are well known and documented"

French minister Mathieu Lefevre. 

The levy has been criticised because it doesn't apply to European and French companies, such as H&M and Zara.

China has described the regulation as "discriminatory" and has warned of potential retaliation.

Related articles