FinCEN Tightens Fraud Reporting Rules
Treasury is pushing banks to file more SARs on cyberfraud and added a keyword to flag possible scam centers.
The U.S. Treasury Department, through FinCEN and offices tied to the Bank Secrecy Act, is pushing banks and other entities to improve the quality and volume of suspicious activity reports tied to cyberfraud. The changes include a new SAR keyword, FIN-2026-SCAMCENTERS, to flag possible scam center involvement in fraud cases.
The U.S. Treasury Department, through FinCEN and offices tied to the Bank Secrecy Act, is pushing banks and other entities to increase both the quality and the volume of suspicious activity reports tied to cyberfraud. The move also adds a new SAR keyword, FIN-2026-SCAMCENTERS, intended to flag possible scam center involvement in fraud cases.
What is FinCEN trying to change?
FinCEN wants financial institutions to identify fraud patterns more accurately and submit reports that are more useful for early detection. The FIN-2026-SCAMCENTERS reference is being introduced as a specific marker within SARs to improve the classification of cases where there are signs of scam operations.
The initiative is grounded in the sharp rise in losses linked to these schemes. According to TechRadar Pro, Treasury has seen losses of nearly $13 billion since 2023, a figure that underpins the tougher reporting expectations.
Why does this matter for banks with a U.S. presence?
Because the regulatory tightening is not limited to fraud reports. It also intersects with existing identity, security and oversight obligations in the U.S. financial system. In September 2026, federal regulators clarified that verifiable digital credentials, if properly authenticated, can satisfy customer identification program requirements, clearing up uncertainty around their use in onboarding.
That development sits alongside a security framework that still demands concrete controls. The GLBA Safeguards Rule requires certain financial institutions to maintain a written security program, risk assessments, and administrative, technical and physical safeguards, including access controls, data inventory, encryption and continuous monitoring.
What other obligations are piling up for institutions?
The regulatory map also adds notification deadlines and testing expectations. Under 23 NYCRR Part 500, financial institutions regulated by the NYDFS must maintain a risk-based cybersecurity program and report certain incidents within 72 hours, a point especially relevant for foreign banks with operations or licenses in New York.
At the interagency level, the FFIEC IT Examination Handbook requires risk-based security testing programs that combine self-assessments, penetration tests, vulnerability assessments and audits. It does not impose a uniform federal annual penetration testing mandate, but it does require institutions to justify that the frequency and scope match their risk profile.
The GLBA also says certain security events affecting information on 500 or more consumers must be reported to the FTC within 30 days of discovery. That adds operational pressure for entities handling large data volumes.
How is supervision shifting in 2026?
The Federal Reserve is sharpening a supervisory approach that focuses on concrete risks, not after-the-fact explanations. In a September 2026 speech, Michelle Bowman said the main goal is to identify significant threats to banks' safety and soundness and to U.S. financial stability as early as possible, then act quickly to require proportional measures.
In the Silicon Valley Bank case, Bowman said the bank failed because of unrealized accounting losses that exceeded its capital, a highly concentrated and mostly uninsured deposit base, and an operational lack of readiness to access the Fed's discount window in time. Later coverage added that external analysis concluded Fed staff knew or should have known about those vulnerabilities and that there is no evidence social media triggered or accelerated the run.
Bowman also said in September 2026 interviews that the Fed is working to help banks, especially smaller ones, better protect their operations from risks tied to third-party vendor products, including those associated with artificial intelligence. At the same time, the OCC released its September 2026 enforcement actions, including multiple prohibition orders against affiliates for violations, unsafe practices and embezzlement, reinforcing that regulatory discipline also reaches individuals.
That tone showed up again in other enforcement digests from the month, which detailed cases of former bank employees sanctioned for embezzlement and unauthorized customer debits. In one of those cases, a former personal banker at U.S. Bank was said to have taken about $329,088 through unauthorized debits, a sign that supervisors continue to link internal fraud, weak controls and personal accountability.
Sources
- FinCEN Says the Quiet Part Out Loud: Banks Can Share Fraud Alerts in Real Timesecurityboulevard.com· FinCEN (analizado por Security Boulevard)Unverified URL
- Regulators clear path for verifiable digital credentials in customer identificationmcdermottlaw.com· McDermott Will & Emery
- Information Security Laws: What Organizations Must Knowterralogic.com· Terralogic
- Microsoft 365 Penetration Testing for Financial Institutionsmyabt.com· MyABT
- Initial Findings from Independent Review of Silicon Valley Bankfederalreserve.gov· Board of Governors of the Federal Reserve System
- Here's how the Fed is working to ensure banks protect themselves from AI risksfinance.yahoo.com· Yahoo Finance
- Regulatory penalties for global financial institutions surge 31% in H1 2024fenergo.com· Fenergo
- Weekly Enforcement & Compliance Insight Digest – September 21, 2026acrossoversight.com· Across Oversight
- OCC bars 2 former bank employees over embezzlement, debiting of customer accountsregreport.info· RegReport
- US Treasury wants banks to be better at filing cyber scam reports after noting nearly USD13 billion in losses since 2023techradar.com· TechRadar Pro
- OCC Announces Enforcement Actions for September 2026occ.treas.gov· OCC
- Fed sat on Silicon Valley Bank flaws because regulators feared being wrong, report findsfinance.yahoo.com· Yahoo Finance



