CiberLATAMbywhalemate

FinCEN Tightens Fraud Reporting Rules

Treasury is pushing banks to file more SARs on cyberfraud and added a keyword to flag possible scam centers.

Whalemate Labs · AI-assisted researchPublished:4 min read

The U.S. Treasury Department, through FinCEN and offices tied to the Bank Secrecy Act, is pushing banks and other entities to improve the quality and volume of suspicious activity reports tied to cyberfraud. The changes include a new SAR keyword, FIN-2026-SCAMCENTERS, to flag possible scam center involvement in fraud cases.

The U.S. Treasury Department, through FinCEN and offices tied to the Bank Secrecy Act, is pushing banks and other entities to increase both the quality and the volume of suspicious activity reports tied to cyberfraud. The move also adds a new SAR keyword, FIN-2026-SCAMCENTERS, intended to flag possible scam center involvement in fraud cases.

What is FinCEN trying to change?

FinCEN wants financial institutions to identify fraud patterns more accurately and submit reports that are more useful for early detection. The FIN-2026-SCAMCENTERS reference is being introduced as a specific marker within SARs to improve the classification of cases where there are signs of scam operations.

The initiative is grounded in the sharp rise in losses linked to these schemes. According to TechRadar Pro, Treasury has seen losses of nearly $13 billion since 2023, a figure that underpins the tougher reporting expectations.

Why does this matter for banks with a U.S. presence?

Because the regulatory tightening is not limited to fraud reports. It also intersects with existing identity, security and oversight obligations in the U.S. financial system. In September 2026, federal regulators clarified that verifiable digital credentials, if properly authenticated, can satisfy customer identification program requirements, clearing up uncertainty around their use in onboarding.

That development sits alongside a security framework that still demands concrete controls. The GLBA Safeguards Rule requires certain financial institutions to maintain a written security program, risk assessments, and administrative, technical and physical safeguards, including access controls, data inventory, encryption and continuous monitoring.

What other obligations are piling up for institutions?

The regulatory map also adds notification deadlines and testing expectations. Under 23 NYCRR Part 500, financial institutions regulated by the NYDFS must maintain a risk-based cybersecurity program and report certain incidents within 72 hours, a point especially relevant for foreign banks with operations or licenses in New York.

At the interagency level, the FFIEC IT Examination Handbook requires risk-based security testing programs that combine self-assessments, penetration tests, vulnerability assessments and audits. It does not impose a uniform federal annual penetration testing mandate, but it does require institutions to justify that the frequency and scope match their risk profile.

The GLBA also says certain security events affecting information on 500 or more consumers must be reported to the FTC within 30 days of discovery. That adds operational pressure for entities handling large data volumes.

How is supervision shifting in 2026?

The Federal Reserve is sharpening a supervisory approach that focuses on concrete risks, not after-the-fact explanations. In a September 2026 speech, Michelle Bowman said the main goal is to identify significant threats to banks' safety and soundness and to U.S. financial stability as early as possible, then act quickly to require proportional measures.

In the Silicon Valley Bank case, Bowman said the bank failed because of unrealized accounting losses that exceeded its capital, a highly concentrated and mostly uninsured deposit base, and an operational lack of readiness to access the Fed's discount window in time. Later coverage added that external analysis concluded Fed staff knew or should have known about those vulnerabilities and that there is no evidence social media triggered or accelerated the run.

Bowman also said in September 2026 interviews that the Fed is working to help banks, especially smaller ones, better protect their operations from risks tied to third-party vendor products, including those associated with artificial intelligence. At the same time, the OCC released its September 2026 enforcement actions, including multiple prohibition orders against affiliates for violations, unsafe practices and embezzlement, reinforcing that regulatory discipline also reaches individuals.

That tone showed up again in other enforcement digests from the month, which detailed cases of former bank employees sanctioned for embezzlement and unauthorized customer debits. In one of those cases, a former personal banker at U.S. Bank was said to have taken about $329,088 through unauthorized debits, a sign that supervisors continue to link internal fraud, weak controls and personal accountability.

Sources

View all