US Treasury Tightens Scam SAR Reporting
The Treasury asked banks to improve suspicious activity reports tied to cyber scams and added a SAR keyword after losses near $13 billion.
The U.S. Treasury Department is pushing changes so banks report suspicious activity tied to cyber scams more clearly, amid losses of nearly $13 billion since 2023. The move adds a new SAR keyword, FIN-2026-SCAMCENTERS, to flag possible scam center involvement.
The U.S. Treasury Department has asked banks to improve how they file suspicious activity reports tied to cyber scams, after estimating losses of nearly $13 billion since 2023. The measure adds a new SAR keyword, FIN-2026-SCAMCENTERS, intended to indicate possible involvement by scam centers.
What changes in scam reporting?
The adjustment is meant to help institutions identify and describe patterns linked to digital fraud more clearly in their suspicious activity reports. According to TechRadar's coverage of the Treasury policy, the new keyword is meant to flag the possible role of scam centers in those cases.
The reference comes as the Treasury tries to improve the quality of the signals received by financial supervision and analysis teams. TechRadar tied the request to the cumulative losses since 2023, which it put at about $13 billion.
How does this connect to the broader regulatory front in the United States?
The Treasury move adds to a series of adjustments that are tightening or refining financial and cyber oversight in the United States. On the corporate privacy front, FinCEN issued a final rule in August 2026 that largely exempts domestic entities and U.S. persons from reporting beneficial ownership information under the corporate transparency regime.
That easing narrows internal reporting requirements, but it does not eliminate customer due diligence, monitoring, and compliance obligations in other jurisdictions such as Mexico. The contrast is clear in the legal analysis from Snell & Wilmer, which says Mexico significantly expanded its anti-money-laundering obligations for vulnerable activities through 2025 reforms and additional 2026 rules.
What does this mean for banks operating in Latin America?
For banks and institutions active between the United States and Latin America, the impact is not limited to cyber fraud. U.S. sanctions policy also expanded on June 5, 2026, when an executive action enabled asset freezes and sanctions against individuals and companies linked to certain criminal organizations, even when those ties arise outside U.S. territory.
Rosa Luxemburg Stiftung says that extraterritorial reach increases the exposure of financial institutions that maintain relationships with regional counterparties. At the same time, Pablo A. Palazzi's article in the Fordham International Law Journal describes how Washington has been promoting a personal data free-flow approach in Latin America through trade agreements and the Cross-Border Privacy Rules system, in contrast with a more restrictive European framework.
NYDFS guidance published in September 2026 also pushes banks to review concentrations and single points of failure in shared infrastructure, cloud services, software, and managed services. American Banker reported that the regulator urged firms to look not only at the individual vendor, but also at the cross-dependencies that can turn seemingly low-risk technologies into a systemic issue.
Horizonscan added that the guidance does not create new formal obligations under Part 500, but clarifies supervisory expectations around incident spread, visibility into customer data, and cloud environments. On the same compliance front, Comply and FedLaws say the amendments to Regulation S-P already left registered entities with formal incident response and breach notification plans due by mid-2026, while FINRA continues to keep cybersecurity among its 2026 supervisory priorities.
Sources
- Beneficial Ownership Across the Border: United States Eases Reporting While Mexico Raises the AML Barswlaw.com· Snell & Wilmer
- What Is SEC Regulation S-P and Who Must Comply?fedlaws.org· FedLaws
- The 2026 CCO Playbookcomply.com· Comply
- AI Pulse Daily Brief | 2026-09-14buttondown.com· Horizonscan
- FinCEN Says the Quiet Part Out Loud: Banks Can Share Fraud Alerts in Real Timesecurityboulevard.com· Security BoulevardUnverified URL
- The FTO Map Is Expanding: Latin America Counterparty Risksigma360.com· Sigma360
- Criminals or Terrorists? US Security Policy in Latin Americarosalux.de· Rosa Luxemburg Stiftung
- International Transfers of Personal Data in Latin America: From the Brussels Effect to the Washington Effectfordhamilj.org· Fordham International Law Journal
- New York tells banks to find their single points of failureamericanbanker.com· American Banker
- Corporate Transparency Act Update- No Reporting Requirement for US Companies or US Persons for Nownatlawreview.com· The National Law Review
- Corporate Transparency Act 2026: Foreign-Owned Structuresinternationalestatelaw.com· International Estate Law
- Bahamas & Jamaica 2026 Geopolitical Risk Assessmentces-intelligence.com· CES Intelligence
- Beneficial Ownership Verification 2026: KYB & CDDcotribute.com· CoTribute
- US Treasury wants banks to be better at filing cyber scam reports after noting nearly USD13 billion in losses since 2023techradar.com· TechRadar



