Court Rules

Financial Services Enforcement Actions

Privacy and consumer protection enforcement actions against financial services companies.

66

Total Actions

$1.3B

Total Fines

FTC

Humboldt Merchant Services

The FTC alleged that payment processor Humboldt Merchant Services knowingly processed payments for more than 1,000 shell merchant entities serving as fronts for fraudulent companies engaged in unauthorized billing scams, despite red flags including chargeback rates nearly 10 times higher than card-brand thresholds. Under the proposed stipulated order filed in the U.S. District Court for the Eastern District of Michigan, Humboldt will pay $12 million for consumer redress and is permanently banned from processing payments for merchants with a heightened risk of potential fraud.

Consent Failure

$12.0M

FTC

Nuvei Corporation

The FTC charged Canada-based payment processor Nuvei Corporation and its subsidiaries with knowingly processing payments for fraudulent merchants, including more than $30 million in payments for the Reimage tech support scam from 2017 to 2023, as well as merchants making false earnings claims and impersonating government tax authorities. Under the stipulated order filed in the U.S. District Court for the District of Arizona, Nuvei will pay $4.85 million for consumer redress, is banned from serving tech support telemarketers, and must implement robust merchant screening and chargeback monitoring practices. Note: this is a payments-fraud facilitation action under the FTC Act and Telemarketing Sales Rule, not a data privacy violation.

$4.8M

CT

Hyperliquid

Attorney General William Tong issued a consumer alert warning Connecticut residents about unregulated, offshore decentralized finance (DeFi) cryptocurrency exchanges, naming GMX, Gains Network, dYdX, Aevo, Drift Protocol, Vertex Protocol, and Hyperliquid. The alert highlights risks including bypassing U.S. law via VPNs, predatory leverage up to 250x, misleading synthetic asset products, and lack of KYC protections. No enforcement action or penalty was imposed; at least one Connecticut consumer reportedly lost $200,000 deposited with an unregulated DeFi exchange.

Dark PatternsSecurity Failure
NY

Unidentified student loan scammers (no specific entity named)

New York Attorney General Letitia James issued a consumer alert warning borrowers about scammers exploiting recent federal changes to student loan repayment programs, including the elimination of the SAVE plan and phase-out of income-based plans. The alert provides tips for borrowers, including refusing upfront fees, never granting powers of attorney to unknown parties, and never sharing Federal Student Aid login credentials. No specific company was named and no penalties or remedies were imposed; this is an advisory alert, not an enforcement action.

CT

TaxAct

Connecticut Attorney General William Tong announced a $275,000 settlement with TaxAct, an online tax preparation company, over allegations that between January 2018 and December 2022, TaxAct improperly disclosed detailed customer financial information to Meta and Google through third-party tracking technologies without notifying taxpayers. The settlement requires TaxAct to pay $275,000 and implement new third-party tracking compliance measures, including a review committee, written policies, a tag monitoring system, and two independent third-party audits.

Unauthorized Data SharingNotice Failure

$275K

NY

The Western Union Company

New York Attorney General Letitia James and the NY Department of Financial Services secured commitments from Western Union to maintain its physical locations and cap fee increases for three years after acquiring Intermex, ensuring continued access to remittance services for New Yorkers. The agreement requires Western Union to maintain at least the same physical presence in ZIP codes where Intermex locations operate, offer retail remittance services to six countries, and limit price increases to inflation, with reporting and audit requirements.

OR

Office of the Comptroller of the Currency

Oregon Attorney General Dan Rayfield co-led a coalition of 10 states in a federal lawsuit against the Office of the Comptroller of the Currency (OCC) to block a rule that invalidates state laws requiring mortgage lenders to pay interest on escrow accounts. The lawsuit argues the OCC's rule oversteps federal authority, gives national banks a competitive advantage over state-chartered banks, and takes money away from homeowners.

NY

Office of the Comptroller of the Currency

Nine state attorneys general, led by New York AG Letitia James, sued the U.S. Office of the Comptroller of the Currency (OCC) to stop two rules that preempt state laws requiring banks to pay interest on escrow accounts. The coalition argues the rules exceed OCC's authority under Dodd-Frank and the Administrative Procedure Act. The suit seeks a court order declaring the rules illegal and preventing their implementation.

CT

Office of the Comptroller of the Currency

Attorney General William Tong and a coalition of 10 attorneys general filed a lawsuit challenging a new OCC rule that preempts state laws requiring national banks to pay interest on homeowners' mortgage escrow accounts. The lawsuit argues the OCC ignored federal court decisions and bypassed safeguards, and seeks to block the rule.

FTC

Credit Glory LLC

The FTC filed a complaint against Credit Glory LLC and related entities for deceptive credit repair practices, including false promises, impersonating debt collectors, charging illegal upfront fees, and using negative option billing without consent. A federal court temporarily halted the operation.

Consent FailureNotice FailureDark Patterns
MN

Unlock Partnership Solutions, Inc.

Minnesota Attorney General Keith Ellison filed a settlement with Unlock Partnership Solutions, Inc. over allegations that its 'home equity agreements' were actually unlawful mortgage loans that violated Minnesota's predatory interest rate caps and disclosure requirements. Unlock agreed to pay $944,626 in monetary and debt relief, cease lending unless licensed, and comply with Minnesota mortgage laws.

Notice Failure

$945K

CT

Opportunity Financial, LLC

Attorney General Tong joined a coalition of 17 attorneys general in sending letters to the Office of the Comptroller of the Currency and the Federal Reserve Board, urging them to deny Opportunity Financial's application to acquire BNC National Bank. The merger would grant OppFi a national bank charter, allowing it to circumvent state lending laws and charge triple-digit interest rates, posing risks to consumers and the banking system.

NJ

Opportunity Financials, LLC

Attorney General Jennifer Davenport joined a coalition of 17 attorneys general in sending comment letters to the Office of the Comptroller of the Currency and the Federal Reserve Board, urging them to deny OppFi's application to acquire BNC National Bank and obtain a national bank charter. The coalition argues that the charter would allow OppFi to circumvent state usury laws and offer high-cost loans with APRs up to 200%, harming consumers.

CO

Domuso, Inc.

Domuso, Inc., a rent payment processor, settled with the Colorado Attorney General for charging illegal surcharges on credit/debit card rent payments. The settlement requires Domuso to cap fees at 2%, end fee-sharing with properties, provide cost-free payment options, and pay $100,000. The company must also comply with Colorado's surcharge and junk fees laws.

Notice Failure

$100K

NY

New York Attorney General's Office

New York Attorney General Letitia James submitted testimony to the Senate Committee on Homeland Security and Governmental Affairs' Permanent Subcommittee on Investigations, calling for stronger regulations on cryptocurrency platforms to protect consumers and investors from scams. The testimony details the flood of cryptocurrency scams costing Americans billions annually and criticizes the Digital Asset Market Clarity Act for undermining state enforcement efforts.

Security Failure
FTC

Dennise Merdjanian

The FTC permanently banned Dennise Merdjanian from the debt relief industry and telemarketing after she and Superior Servicing LLC allegedly ran a student loan forgiveness scam that took more than $45.9 million from consumers. The proposed stipulated order imposes a partially suspended monetary judgment and resolves the FTC's litigation against the remaining defendants.

Notice Failure

$45.9M

FTC

Alexander Mashinsky, Shlomi Daniel Leon, and Hanoch Goldstein

The FTC charged the founders of Celsius Network with deceiving consumers by falsely promising that cryptocurrency deposits were safe and always available. The founders agreed to pay $16.5 million and are banned from marketing or selling products that can be used to deposit or withdraw assets, among other restrictions.

Consent FailureNotice Failure

$16.5M

MN

Block, Inc.

Attorney General Keith Ellison announced a $45 million multistate settlement with Block, Inc., the company behind Cash App. The settlement resolves allegations that Block misled consumers about the safety of Cash App, failed to protect users from fraud, and did not provide promised fraud protection and resolution. Block agreed to implement responsible practices including maintaining customer support, offering live support, stopping misleading claims, and fulfilling legal obligations to investigate fraud and reimburse users.

Security FailureNotice FailureConsent Failure

$45.0M

CO

Block, Inc.

Attorney General Phil Weiser announced a $45 million multistate settlement with Block, Inc., the company behind Cash App, for misleading consumers about the safety of the platform and failing to protect users from fraud. The settlement requires Block to implement antifraud measures, provide customer support, and stop deceptive marketing practices.

Security FailureNotice FailureConsent Failure

$45.0M

CO

Unlock Partnership Solutions, Inc.

The Colorado Attorney General settled with Unlock Partnership Solutions, Inc., which marketed home equity agreements that were determined to be consumer credit transactions subject to Colorado's Uniform Consumer Credit Code and Consumer Equity Protection Act. The company must comply with lending laws, rate caps, disclosures, and licensing, and pay $283,375 in restitution to 125 consumers, with additional payments expected.

Notice FailureConsent Failure
MN

Bridge It, Inc.

Minnesota Attorney General Keith Ellison filed a lawsuit against Bridge It, Inc. (doing business as Brigit) for violating Minnesota's payday lending laws. The lawsuit alleges Brigit operates as an unlicensed lender making short-term loans with APRs exceeding 300%, without disclosing rates or complying with state interest caps and disclosure requirements.

Notice FailureConsent Failure
FTC

Golden Home Services

The FTC is returning nearly $3 million to consumers deceived by the Golden Home Services mortgage relief scheme, which falsely promised to reduce homeowners' mortgage payments and prevent foreclosures. A federal court banned the companies and their operators from telemarketing and debt relief businesses and required them to pay millions. The refunds are being mailed to 1,821 affected homeowners.

Consent Failure

$3.0M

NJ

New Jersey Bureau of Securities

The New Jersey Bureau of Securities announced its 2026 annual investment adviser examination, with a particular focus on firms' use of artificial intelligence and cybersecurity protocols. The examination requires nearly 800 registered investment adviser firms to answer questions about AI use in portfolio management, data protection policies, and third-party vendor due diligence. Failure to comply may result in administrative action.

Security FailureAI/Automated Decisions
FTC

National Amendment Assistance

The FTC filed a complaint against National Amendment Assistance and related entities for allegedly deceiving homeowners into paying unlawful upfront fees for mortgage relief services falsely associated with the CARES Act. The court granted a temporary restraining order, and the FTC seeks redress for affected consumers.

Consent FailureNotice Failure
TX

Institutional Shareholder Services, Inc.

Texas Attorney General Ken Paxton filed a lawsuit against proxy advisory firm Institutional Shareholder Services, Inc. (ISS) alleging violations of the Texas Deceptive Trade Practices Act by prioritizing political agendas over sound financial guidance in voting recommendations. The lawsuit seeks an injunction to stop deceptive practices and civil penalties of up to $10,000 per DTPA violation. This action follows a 2025 investigation into ISS and peer firm Glass Lewis & Co.

FTC

Chris Terry, Isis Terry, IM Mastery Academy, IYOVIA, iMarketsLive, IM Academy

The FTC and State of Nevada settled charges with lead defendants of the IM Mastery Academy MLM scheme, including Chris and Isis Terry and their affiliated companies, over false earnings claims used to promote financial training programs and a multi-level marketing venture. The stipulated order imposes a $795.8 million judgment, with defendants surrendering nearly $90 million in assets including luxury real estate, vehicles, jewelry, and a yacht, totaling over $100 million with prior judgments from other involved defendants. The order also bans defendants from selling trading-training services, prohibits false earnings claims, and restricts deceptive practices including negative-option misrepresentations and telemarketing violations.

$795.8M

FTC

Cliq Inc.

A federal court held Cliq Inc. and its executives Andrew Phillips and John Blaugrund in civil contempt for multiple violations of a 2015 FTC order requiring the payment processor to prevent enabling consumer fraud. The court found the defendants facilitated fraud by processing transactions for high-risk merchants, avoiding fraud monitoring, failing to conduct required underwriting, and ignoring chargeback thresholds. The court imposed $6.5 million in civil contempt sanctions against the defendants.

$6.5M

NJ

Titan Macro Finance

The New Jersey Bureau of Securities issued a Cease and Desist Order on April 30, 2026, against Titan Macro Finance for operating an investment fraud scheme via WhatsApp and Instagram that defrauded at least one New Jersey investor of $64,000. The scheme involved unregistered broker-dealer activity, fake trading profits, and undisclosed fees to access investor funds. The action was coordinated with the California Department of Financial Protection and Innovation, which issued a similar order against the entity for violating California’s Commodity Code.

NY

Uphold HQ, Inc.

New York Attorney General Letitia James secured a $5 million settlement from cryptocurrency platform Uphold HQ, Inc. for promoting Cred’s fraudulent CredEarn investment product as safe and reliable, when Cred was making risky loans to uncreditworthy borrowers in China. Uphold also falsely claimed Cred had comprehensive insurance and promoted the product without registering as a broker or commodity broker-dealer under New York law. As part of the settlement, Uphold will pay $5 million to harmed investors, remit $545,189 from Cred’s bankruptcy to customers, improve due diligence policies for third-party products, and register as a broker with the OAG.

$5.0M

CT

American Express, Capital One, Citi Group, Mastercard, Visa, PayPal, Stripe, Sezzle, Block (operator of Square, Cash App, and Afterpay)

On April 28, 2026, Connecticut Attorney General William Tong joined a bipartisan coalition of 24 other attorneys general and New York City in sending letters to major credit card companies and payment processors urging them to block transactions facilitating sales of illegal vaping products. The coalition, led by New York, Pennsylvania, California, and NYC, called for collaboration to stop unlawful sales of unauthorized e-cigarettes that violate federal FDA premarket authorization requirements and the PACT Act. The letters request a meeting to discuss prohibiting noncompliant merchants from using the payment networks, citing past successful government-private sector collaboration in reducing illegal tobacco sales.

NY

American Express, Capital One, Citi Group, Mastercard, Visa, PayPal, Stripe, Sezzle, Block (operator of Square, Cash App, and Afterpay)

New York Attorney General Letitia James led a bipartisan coalition of 24 state attorneys general, Puerto Rico, and New York City in sending letters to nine major credit card companies and payment processors urging them to block transactions facilitating illegal vaping product sales. The coalition cites federal and state laws prohibiting unauthorized e-cigarette sales, particularly to youth, and requests collaboration to prevent payment networks from processing such transactions. No enforcement penalties or actions were imposed as part of this initiative.

NY

Miles Burton Marshall

New York Attorney General Letitia James announced the conviction of tax preparer and insurance agent Miles Burton Marshall for operating a decades-long Ponzi scheme that defrauded 988 investors out of more than $50 million. Marshall pleaded guilty to Grand Larceny in the Second Degree, Securities Fraud under the Martin Act, and Scheme to Defraud in the First Degree, and faces four to 12 years in prison plus approximately $90 million in restitution to victims.

VA

Wall & Associates, Inc.

The Virginia Attorney General issued a consumer warning about predatory practices by tax debt settlement companies, referencing a past successful enforcement action against Wall & Associates, Inc. and CEO P. Mark Yates for violating the Virginia Consumer Protection Act. The Fauquier County Circuit Court ordered the company and CEO to pay over $1.6 million in civil penalties, with additional restitution to consumers pending determination.

$1.7M

FTC

NERD Solutions Inc., ED REF Inc., Natalie Rodriguez, Pablo Ortiz

The FTC obtained a temporary restraining order against NERD Solutions Inc., ED REF Inc., and their operators Natalie Rodriguez and Pablo Ortiz, alleging they operated a deceptive student loan debt relief scheme that impersonated U.S. Department of Education officials and loan servicers to collect illegal upfront fees from consumers. The defendants are accused of violating the FTC Act, Telemarketing Sales Rule, Impersonation Rule, and Gramm-Leach-Bliley Act, having collected at least $8.8 million from affected consumers. The case is pending in the U.S. District Court for the Central District of California.

Student Data
FTC

PayPal Holdings, Inc., Stripe, Inc., Visa Inc., Mastercard Inc.

FTC Chairman Andrew N. Ferguson issued warning letters to the CEOs of four major payment and financial infrastructure providers regarding concerns about debanking law-abiding customers based on political or religious views. The letters remind the companies of their obligations to customers under the FTC Act, warn that inconsistent denials of service could trigger investigations and enforcement, and reference President Trump’s 2025 executive order prohibiting debanking due to political affiliations, religious beliefs, or lawful business activities.

NJ

OneMain Financial, Inc.

New Jersey Attorney General Jennifer Davenport, joined by a bipartisan coalition of 12 other state attorneys general, filed a multistate lawsuit against OneMain Financial, Inc. for allegedly hiding junk fees for add-on loan products in dense fine print, pressuring borrowers to accept unwanted products, and violating state consumer protection laws. The coalition seeks consumer refunds, civil penalties, disgorgement of profits, and a court order halting the illegal practices, correcting credit reports, and dropping collection actions related to the add-ons.

FTC

Growth Cave, LLC

Consumer fraud case where the FTC settled with Growth Cave defendants for operating a deceptive business opportunity and credit repair scheme that cost consumers nearly $50 million. The settlement permanently bans them from such activities, requires asset liquidation to pay a $48.6 million judgment, and prohibits misleading earnings claims and AI use.

$48.6M

FTC

Cliq, Inc., Andrew Phillips, John Blaugrund

The FTC filed a motion in federal court seeking to hold payment processor Cliq, Inc. and its operators in contempt for systematically violating a 2015 consent order. The defendants are accused of processing payments for high-risk and prohibited merchants, failing to screen for deceptive practices, and facilitating fraud avoidance tactics. The FTC is requesting at least $52.9 million in consumer relief, a permanent ban on the individuals from payment processing, and appointment of a receiver.

Consent FailureSecurity Failure

$52.9M

CT

Affirm, Afterpay, Klarna, PayPal, Sezzle, Zip

Connecticut Attorney General William Tong led a multistate coalition in sending inquiry letters to six major BNPL providers—Affirm, Afterpay, Klarna, PayPal, Sezzle, and Zip—seeking detailed information on their pricing, fees, disclosures, and consumer assessment practices to evaluate compliance with consumer protection laws, following the rescission of federal Truth in Lending Act rules for BNPL.

Notice Failure
NY

Wojeski & Company

New York Attorney General Letitia James settled with public accounting firm Wojeski & Company over two data breaches in 2023 and 2024 that exposed personal information of over 4,700 New York residents, including social security numbers and medical benefits. The firm failed to implement adequate data security measures, did not encrypt sensitive data, and delayed notifying affected consumers of the breaches for over a year. Wojeski must pay $60,000 in penalties and implement enhanced cybersecurity measures including encryption, incident response plans, and employee training.

Data BreachSecurity FailureBreach Notification Delay

$60K

NY

American Family Mutual Insurance Company/Midvale Indemnity Company, Farmers Insurance, Hagerty Insurance Agency, The Hartford Insurance Group, Infinity Insurance Company, Liberty Mutual Insurance, Metromile, State Auto Mutual Insurance Company

New York Attorney General Letitia James secured $14.2 million in settlements from eight car insurance companies for failing to protect consumers' personal information. The companies' inadequate cybersecurity allowed hackers to steal driver's license numbers and other data through online quoting tools, impacting over 825,000 New Yorkers. The settlements require the companies to pay penalties and implement enhanced data security measures.

Security FailureData Breach

$14.2M

MA

Earnest Operations LLC

Massachusetts Attorney General settled with Earnest Operations LLC for $2.5 million over allegations that the student loan lender's use of AI underwriting models led to disparate impact on Black, Hispanic, and non-citizen applicants. The company failed to test its AI models for bias, used discriminatory variables like Cohort Default Rate, and sent inaccurate adverse action notices. Earnest must pay the fine, discontinue problematic practices, and implement compliance measures.

AI/Automated DecisionsNotice Failure

$2.5M

FL

Robinhood Crypto, LLC.

Florida Attorney General James Uthmeier launched an investigation into Robinhood Crypto, LLC for allegedly deceptive practices regarding trading costs. The AG issued a subpoena seeking internal documents to determine if Robinhood violated Florida's Deceptive and Unfair Practices Act by falsely claiming to offer the lowest crypto trading costs. Robinhood must respond by July 31, 2025.

FTC

Paddle

The FTC entered into a settlement with U.K.-based payment processor Paddle to resolve allegations that its unfair payment processing practices facilitated tech support scammers operating in Cyprus. Paddle agreed to pay a $5 million monetary penalty as part of the settlement.

$5.0M

CT

Treasury Department

Connecticut Attorney General William Tong joined a coalition of 19 attorneys general in suing President Trump and the U.S. Treasury to stop DOGE's unauthorized access to the Treasury's central payment system and confidential records, calling it the largest data breach in American history. The lawsuit seeks an injunction to block the expanded access policy and a declaration that it is unlawful.

Unauthorized Data SharingData Breach
NY

Equifax Information Services, LLC

New York Attorney General Letitia James announced a settlement with Equifax Information Services, LLC for inaccurately reporting credit scores to lenders due to a coding error, which lowered consumers' scores and inflated costs for loans and insurance between March and April 2022. Equifax will pay $725,000 and implement safeguards to prevent future errors, with restitution for affected consumers.

Data Broker Non-Compliance

$725K

NY

Government Employees Insurance Company (GEICO) and The Travelers Indemnity Company

GEICO and Travelers were fined $11.3 million for data breaches that exposed personal information of over 120,000 New Yorkers due to inadequate cybersecurity. The breaches involved driver's license numbers being stolen and used in fraudulent unemployment claims. The settlements mandate enhanced security measures and penalties.

Data BreachSecurity Failure

$11.3M

FTC

Financial Education Services (FES) d/b/a United Wealth Education, United Credit Education Services, Youth Financial Literacy Foundation

The FTC is distributing over $10.9 million in refunds to 443,048 consumers harmed by Financial Education Services (FES), a credit repair pyramid scheme that defrauded consumers through false promises of credit score fixes and illegal pyramid recruitment. The refunds follow a 2024 settlement with FES and its owners that banned them from fraudulent practices and required turnover of funds for consumer restitution.

FTC

Financial Education Services

Consumer fraud enforcement against Financial Education Services for operating a credit repair pyramid scheme that defrauded consumers with false promises of easy credit fixes. The FTC secured a settlement in 2024 requiring $10.9 million in refunds to over 443,000 consumers and permanent bans on the operators.

$10.9M

NY

Morgan Stanley Smith Barney LLC

Morgan Stanley failed to properly decommission computer devices containing unencrypted customer data, leading to the sale of devices with personal information at auction and missing servers with potential data. A multistate coalition secured a $6.5 million settlement requiring Morgan Stanley to implement enhanced data security measures.

Security FailureData Breach

$6.5M

NJ

Morgan Stanley Smith Barney, LLC

New Jersey Attorney General Matthew Platkin announced a multistate settlement where Morgan Stanley will pay $1.27 million to NJ over data security incidents that compromised personal information of over 755,000 NJ residents and millions nationwide. The incidents involved improper decommissioning of devices and a software flaw, leading to unauthorized access. The settlement requires Morgan Stanley to strengthen its data security and disposal procedures.

Security FailureData Breach

$1.3M

FTC

Five tax preparation companies

The FTC issued warnings to five tax preparation companies against using or disclosing consumer tax data for unrelated purposes like advertising without explicit consent. The agency cites its penalty offense authority, referencing a previous case against Beneficial Corp, and warns that such practices violate the FTC Act and could incur penalties up to $50,120 per violation. The notices highlight that using tracking technologies for data collection without consent is also prohibited.

Consent Failure
FTC

Experian Consumer Services

The FTC settled charges against Experian Consumer Services for violating the CAN-SPAM Act by sending marketing emails to consumers who signed up for credit management accounts without providing an opt-out mechanism. The emails promoted products like Experian Boost and Dark Web scans but lacked unsubscribe links. Experian must pay $650,000 and is prohibited from future violations.

Opt-Out FailureNotice Failure

$650K

NJ

Horatiu Charlie Caragaceanu, The Shark of Wall Street, and Hedge4.ai

The New Jersey Bureau of Securities issued a Cease and Desist Order against Horatiu Charlie Caragaceanu and his organizations for promoting TruthGPT Coin, a cryptocurrency scam that falsely claimed AI capabilities and endorsements from figures like Elon Musk. The respondents misrepresented the AI model's ability to predict cryptocurrency prices and manipulated images to show false endorsements, targeting investors with unrealistic profit promises.

AI/Automated Decisions
CT

M&T Bank

Connecticut Attorney General William Tong testified in support of legislation to grant his office investigative authority under the Consumer Financial Protection Act to address widespread consumer complaints following the merger of People’s United Bank and M&T Bank, including issues with account access, unauthorized transactions, and payment processing errors.

FTC

Financial institutions covered by the Safeguards Rule

The FTC extended the compliance deadline for certain provisions of the Safeguards Rule by six months to June 9, 2023, due to challenges like shortage of qualified personnel and supply chain issues exacerbated by the COVID-19 pandemic. The rule requires non-banking financial institutions to implement enhanced data security measures, and the extension aims to facilitate compliance, especially for small entities.

NJ

Experian and T-Mobile

New Jersey Attorney General Matthew J. Platkin announced a multistate settlement with Experian and T-Mobile over a 2015 data breach that compromised personal information of over 15 million consumers. The companies will pay over $16 million to states and agree to improve data security and vendor management practices. New Jersey will receive approximately $500,000 from the settlement.

Data BreachSecurity Failure

$16.0M

CT

Mortgage Servicers

Connecticut Attorney General William Tong joined a coalition of 22 attorneys general in urging the Consumer Financial Protection Bureau (CFPB) to prohibit mortgage servicers from charging convenience fees. The coalition argues that these fees are exploitative and unfair, as homeowners have no choice in their servicers and fees often exceed the actual cost of processing payments. They request that the CFPB either ban such fees or limit them to actual costs, and require servicers to document their costs.

CT

Buy-Now-Pay-Later Lenders

Connecticut Attorney General William Tong joined a coalition of 19 attorneys general to submit comments to the CFPB, urging robust consumer protections for buy-now-pay-later (BNPL) lenders. The coalition expressed concerns that BNPL loans may trap consumers in debt through hidden fees, inadequate disclosures, and improper data monetization practices.

Notice FailureUnauthorized Data Sharing
FTC

Turbo Solutions Inc.

The FTC obtained an injunction against Turbo Solutions Inc. and Alex V. Miller for operating a deceptive credit repair scheme that filed fake identity theft reports without consumers' consent. The scheme charged illegal advance fees and made false promises about removing negative credit items. The court order halts the operation and seeks consumer redress.

Unauthorized Data Sharing
CT

Navient

Connecticut Attorney General William Tong announced a $1.85 billion multistate settlement with student loan servicer Navient for unfair and deceptive servicing practices. Navient steered borrowers into costly forbearances and originated predatory loans, resulting in debt relief for over 66,000 borrowers and restitution for 350,000 federal loan borrowers. The settlement includes a $142.5 million payment to attorneys general and conduct reforms to improve servicing practices.

Notice Failure

$142.5M

FTC

Ascension Data & Analytics, LLC

The FTC settled with Ascension Data & Analytics, LLC for violating the Gramm-Leach-Bliley Act's Safeguards Rule by failing to ensure its vendor properly protected consumer data. The company must strengthen its security safeguards and increase oversight of vendors. No monetary penalty was imposed.

Security Failure
FTC

Ascension Data & Analytics, LLC

Ascension Data & Analytics, LLC, a mortgage analytics company, settled FTC allegations that it violated the Gramm-Leach-Bliley Act's Safeguards Rule by failing to ensure its vendor adequately protected consumer data. The vendor stored sensitive mortgage information in plain text on a cloud server, leading to unauthorized access. Ascension must implement a data security program, undergo biennial assessments, and report future breaches.

Security Failure
FTC

Midwest Recovery Systems

The FTC settled with Midwest Recovery Systems for engaging in 'debt parking,' where it placed inaccurate debts on consumers' credit reports to force payment. The company collected over $24 million from such debts. The settlement requires it to delete all reported debts, stop the practice, and pay a $24.3 million monetary judgment.

Unauthorized Data SharingHealth Data

$24.3M

CA

Wells Fargo Bank

Wells Fargo Bank recorded consumer phone calls without providing timely notice as required by California law, violating privacy statutes. The settlement imposes a $7.616 million civil penalty, requires compliance with disclosure standards, and mandates an internal compliance program to protect consumer privacy.

Notice Failure

$7.6M

CA

Citibank, N.A.

In 2013, the California Attorney General filed a complaint against Citibank, N.A. alleging that the bank failed to implement adequate security measures and did not properly notify customers about a data breach exposing personal and financial information. The complaint asserts violations of California's data breach notification law.

Security FailureBreach Notification Delay