Our Newsletter Is Moving to LinkedIn

To keep receiving your weekly insights, all you need to do is subscribe to our new Consumer Financial Services Weekly Newsletter — it’s quick and easy.

We’ll see you there!

Click here to subscribe


To keep you informed of recent activities, below are several of the most significant federal events that have influenced the Consumer Financial Services industry over the past week.

Federal Activities

State Activities

International Activities


Federal Activities:

On September 4, the Federal Reserve Board announced the termination of enforcement actions against United Texas Bank of Dallas and Quontic Bank Acquisition Corp. and Quontic Bank Holdings Corp., with the action against United Texas Bank (a cease-and-desist order originally issued August 29, 2024) having been terminated September 2, 2026. The United Texas Bank action had stemmed from an examination by the Federal Reserve Bank of Dallas that identified significant deficiencies in the bank’s risk management and anti-money laundering (AML) compliance program, including lax oversight related to crypto customers and foreign correspondent banking, as well as concerns about corporate governance and board-level supervision under Bank Secrecy Act (BSA) and Treasury standards. The Fed offered no explanation for the terminations, and the affected institutions did not immediately comment. For more information, click here.

On September 3, the Financial Crimes Enforcement Network (FinCEN) published a Financial Trend Analysis on digital asset investment scams (commonly known as “pig butchering” or “romance baiting” schemes) covering BSA reporting from September 8, 2023, through December 31, 2025, pursuant to its obligation under the Anti-Money Laundering Act of 2020 to periodically publish threat pattern and trend information. The analysis examined 33,904 BSA reports filed during the review period, identifying approximately $12.7 billion in financial activity tied to suspected digital asset investment scams, with reporting volume growing at an average rate of 10.9% per month and reported funds increasing at 18% per month — trends FinCEN characterized as accelerating. Money services businesses and depository institutions accounted for 96% of all reports filed. The scams typically involve illicit actors using fake personas to build trust with victims through social media, dating platforms, or unsolicited messages before introducing fraudulent digital asset investment opportunities, ultimately directing victims to transfer funds (sometimes by liquidating retirement accounts, taking out home equity loans, or soliciting money from family) to accounts controlled by the scammers. FinCEN noted that victims spanned all 50 states and several U.S. territories across all age demographics, with older Americans not found to be at disproportionately higher risk than other groups. For more information, click here.

On September 2, the Office of the Comptroller of the Currency (OCC), Board of Governors of the Federal Reserve System (Federal Reserve), Federal Deposit Insurance Corporation (FDIC), FinCEN, and National Credit Union Administration (NCUA) issued a joint statement clarifying the confidentiality requirements related to Suspicious Activity Reports (SARs), particularly when banks communicate with customers regarding potentially fraudulent transactions, other suspicious activity, or account closures. The statement applies to all banks, including community banks. The joint statement reviews the scope of the BSA. The BSA prohibits the disclosure of a SAR or any information that would reveal the existence of a SAR, including to the customer or other person who is the subject of the SAR. Unauthorized disclosure could undermine ongoing and future law enforcement investigations by alerting potential suspects, deterring financial institutions from filing SARs, and even endangering SAR filers. The unauthorized disclosure of a SAR is a violation of federal law, and violators face an array of sanctions that can be imposed on a financial institution for unauthorized disclosure, including civil and criminal penalties, fines, and imprisonment. The joint statement reaffirms that the BSA’s confidentiality requirements do not extend to the underlying facts, transactions, and documents upon which a SAR is based. Banks and credit unions may communicate with a customer, or with other financial institutions, about potentially fraudulent or suspicious transactions involving the customer’s account, including notifying the customer of an intention to close the account, so long as that communication does not reveal the existence of a SAR. Importantly, the agencies confirm that even if a reasonable and prudent person familiar with SAR filing requirements might suspect or deduce from the underlying facts that a SAR was or may have been filed, the communication of those underlying facts alone does not constitute prohibited disclosure of a SAR’s existence. For more information, click here.

On September 2, FinCEN reissued a Geographic Targeting Order (GTO) requiring certain money services businesses (MSBs) operating in specific ZIP codes along the southwest border to file Currency Transaction Reports for cash transactions between $1,000 and $10,000, a lower threshold than the standard $10,000 requirement, covering designated counties in New Mexico (Bernalillo, Dona Ana, and San Juan) and Texas (Cameron, El Paso, Hidalgo, Maverick, and Webb). The reissued GTO, effective for 180 days following Federal Register publication, is aimed at combating money laundering and illicit financial activity tied to Mexico-based cartels and drug trafficking organizations along the southwest border, and is intended to provide law enforcement with actionable data to track the flow of narcotics-related funds and deny criminal actors access to the U.S. financial system. For more information, click here.

On September 1, the U.S. Securities and Exchange Commission (SEC) proposed a comprehensive update to the rules and forms governing registered transfer agents, the first substantive revision since the original rules were adopted in the late 1970s and early 1980s, to better reflect the technological environment and expanded range of functions in which transfer agents now operate, including electronic recordkeeping, electronic communications, and the use of blockchain technology in connection with securities offerings and share transfers. The proposed rule would amend existing rules and forms, rescind at least one existing rule, and introduce new requirements aimed at modernizing the federal transfer agent framework while continuing to support the safe and efficient functioning of the U.S. securities markets and national clearance and settlement system, with a public comment period open for 60 days following Federal Register publication. For more information, click here.

On September 1, the Department of Housing and Urban Development (HUD) announced new guidance applying the Fair Housing Act’s statute of limitations to claims alleging violations of the act’s design and construction requirements, rescinding an Obama-era legal interpretation that HUD characterized as burdensome and without basis in law. Secretary Scott Turner stated that the previous guidance had resulted in over $110 million in repair costs imposed on building owners over the past five years, regardless of whether those owners contributed to the alleged violations, and that the new guidance is intended to reduce unnecessary liability exposure for builders and lower costs for homebuyers and renters by enforcing the statute of limitations as written by Congress and interpreted by the courts. For more information, click here.

On September 1, Federal Reserve Governor Michael S. Barr delivered remarks at the Second-Chance Lending Forum in Washington, D.C., addressing the economic and financial challenges facing individuals with criminal records and the opportunities that entrepreneurship, financial inclusion, and emerging technology, particularly AI, can provide to help them succeed. Barr noted that formerly incarcerated individuals face unemployment rates nearly five times higher than the general population, are significantly more likely to be unbanked, and rely disproportionately on high-cost alternative financial services, while also observing that roughly 20 to 30% of people with criminal records pursue self-employment as an alternative pathway to economic stability. He highlighted promising models such as Texas’s Prison Entrepreneurship Program and the Small Business Administration’s 2024 rule removing criminal history bars from its loan programs, and called for expanded pilot programs, long-term evaluations, and greater use of alternative data and AI-powered cash flow underwriting to improve credit access for this population. Barr also briefly addressed the broader economic outlook, noting that while the labor market remains stable and growth has been solid, inflation remains above the Fed’s 2% target and the September Federal Open Market Committee meeting would weigh whether further rate increases are warranted. For more information, click here.

On September 1, the FTC’s Bureau of Consumer Protection issued an alert warning consumers about a growing scam in which fraudsters create near-perfect clones of legitimate car dealership websites, sometimes using AI, to trick buyers into paying upfront for vehicles that don’t exist. Victims show up at the real dealership only to find no record of their order, their payment, or their car. Scammers copy a real dealer’s website in detail, replicating brand logos, vehicle listings, photos, and even customer testimonials. They often advertise rare or hard-to-find vehicles to draw in buyers, describe the buying process in reassuring detail, and offer flexible return policies to lower your guard. The FTC recommended buyers search the dealer’s name online paired with words like “scam,” “review,” or “complaint” before engaging, ask to see the car and the dealership in person, and never pay by wire transfer, as that is the hallmark of a scam. For more information, click here.

On August 31, the SEC and the U.S. Food and Drug Administration (FDA) executed a memorandum of understanding (MOU) establishing a formal framework for sharing nonpublic information between the two agencies. The MOU takes effect immediately upon signature and reflects a significant step toward coordinated regulatory and enforcement activity at the intersection of public health and financial markets. Public companies engaged in FDA-regulated activities, including pharmaceutical, biotechnology, medical device, food and cosmetics, and tobacco companies, now face a meaningfully increased risk that information in the FDA’s possession will find its way to the SEC, and vice versa. The MOU is designed to help each agency detect situations where a company may have made false or misleading statements to investors about matters within the FDA’s regulatory purview, such as: the status of FDA review or product approvals; clinical trial results; manufacturing compliance; or distribution or marketing activities. For more information, click here.

On August 28 and 31, the FDIC and the OCC respectively released their Community Reinvestment Act (CRA) examination and evaluation schedules covering the fourth quarter of 2026 and the first quarter of 2027. The CRA, enacted in 1977, requires federal bank regulators to assess whether banks are meeting the credit needs of their entire communities, including low- and moderate-income neighborhoods, consistent with safe and sound operations. Both agencies encouraged public comments on the institutions scheduled for review, noting that comments should be directed either to the institutions themselves or to the appropriate regional or supervisory office before the relevant examination period begins. The FDIC noted that examination frequency is tied to asset size and CRA rating — institutions with $250 million or less in assets rated Satisfactory or Outstanding are generally examined no more than once every 48 or 60 months, respectively — and that schedules are subject to change based on available resources and other supervisory needs. For more information, click here and here.

On August 28, the U.S. Department of the Treasury took coordinated action under Operation Economic Outcast, announced by Secretary Scott Bessent on August 24, 2026, and aimed at severing the Iranian regime’s remaining financial lifelines, targeting Banque Misr UAE and other facilitators of Iranian sanctions evasion. FinCEN issued a notice of proposed rulemaking (NPRM) finding that Banque Misr UAE is a foreign financial institution of primary money laundering concern, proposing under § 311 of the USA PATRIOT Act to prohibit U.S. financial institutions from opening or maintaining correspondent accounts for the institution and to require special due diligence to guard against transactions involving it, based on Treasury’s assessment that Banque Misr UAE processed approximately $1.8 billion for 103 companies potentially part of Iranian shadow banking networks between January 2024 and June 2026, including apparent front companies used by Iran’s Ministry of Defense, the Islamic Revolutionary Guard Corps, and individuals laundering funds on behalf of Iranian Supreme Leader Mojtaba Khamenei. Separately, OFAC sanctioned Reza Mohammad Taeedi, general manager of Bank Melli’s Dubai branch, which has facilitated billions of dollars in transactions for the IRGC Qods Force, and Hong Kong-based Kameng Trading Limited, a front company used to launder funds for the previously sanctioned Pedram Pirouzan Exchange House. Public comments on the FinCEN NPRM are due 30 days after Federal Register publication. For more information, click here.

On August 27, the FDIC Board of Directors approved an interim final rule implementing § 902 of the 21st Century ROAD to Housing Act, which amended the statutory framework governing reciprocal deposits and took effect July 11, 2026. The rule raises the amount of reciprocal deposits that a qualifying “agent institution” may exclude from treatment as brokered deposits, replacing the prior general cap of the lesser of $5 billion or 20% of total liabilities with a new tiered liability-based calculation — 50% of the first $1 billion in total liabilities, 40% of the next $9 billion, and 30% of liabilities above $10 billion — up to a maximum of $30 billion. The rule also expands the definition of “agent institution” to include institutions with a CAMELS composite rating of “1,” “2,” or “3” (broadening eligibility beyond the prior “outstanding or good” standard), provides clarifications on what constitutes “receipt” of nonmaturity reciprocal deposits, and addresses how and when institutions may requalify as agent institutions following a ratings or capital category change. The FDIC issued the rule without prior notice and comment, citing good cause given the need to align its regulations with the Housing Act immediately upon its enactment, but is accepting public comments through October 1, 2026, and anticipates updating Call Report instructions by December 31, 2026, to reflect the new framework. For more information, click here.

State Activities:

On September 2, Governor Matt Meyer signed House Bill 380, amending Delaware’s Personal Data Privacy Act (DPDPA) originally enacted in 2023, with most changes taking effect January 1, 2027. The amendments significantly expand the law’s reach by lowering the applicability thresholds (reducing from 35,000 to 10,000 the number of consumers whose data triggers coverage under the first prong, and from 10,000 to 5,000 under the revenue-based prong) and extending coverage to third parties that acquire personal data from controllers. Notably, the amendments remove the entity-level exemption for financial institutions subject to the Gramm-Leach-Bliley Act (GLBA), replacing it with a narrower exemption limited to banks, credit unions, and savings associations and their affiliates, while leaving the existing data-level GLBA exemption intact — a change that brings Delaware in line with approaches taken in Connecticut, Montana, and Oregon and will require many financial services companies to reassess their compliance obligations. The amendments also expand consumer rights by entitling consumers to receive a list of the specific third parties, not just categories, to which their personal data was disclosed, subject to limited exceptions for pseudonymized data, trade secrets, and situations where compiling such a list is not feasible. New contractual requirements govern data sharing with third parties, including obligations around purpose limitations, privacy protection standards, and controller audit rights, and controllers must now conduct impact assessments when engaging in profiling for automated decisions with legal or similarly significant effects, with added notice and human review rights for consumers subject to adverse actions based on such decisions. For more information, click here.

On August 31, California’s newly established Business and Consumer Services Agency, led by Secretary Rohit Chopra, published a blog post outlining the agency’s priorities around emerging technology, emphasizing that technological progress must benefit all Californians rather than undermine their health, safety, or legal protections. The agency, which consolidates dozens of boards, bureaus, and departments covering sectors including financial services, health care, real estate, and retail, announced that it will investigate how businesses are deploying new technologies such as chatbots and AI tools to ensure those uses do not harm consumers, perpetrate scams, exploit personal data, or constitute unlicensed practice of medicine or other regulated professions, while coordinating closely with other state agencies and complementing broader Newsom administration efforts to prepare California for AI-driven disruption. For more information, click here.

On August 26, New York State Senator Zellnor Myrie introduced Senate Bill S10688, legislation that would enact an express “opt out” from key provisions of the Depository Institutions Deregulation and Monetary Control Act of 1980 (DIDMCA), purporting to impose New York’s interest rate limitations on a broad range of consumer credit transactions. Consistent with the borrower-location reading of § 525 that Colorado and Oregon have adopted, S10688 adopts an expansive, multifactor test for determining when a transaction is “made in” New York. A transaction would be deemed “made in” New York when the consumer is a New York resident at account opening or consummation of the transaction and one or more material acts occur in the state, including solicitation, application submission, execution of an agreement, receipt of funds, or use of a New York payment account. Remote and digital lending is expressly captured. The bill provides that a contractual choice-of-law clause selecting another state would not override this determination. S10688 reaches beyond the originating institution to any person that markets, arranges, funds, services, purchases, acquires, securitizes, collects, or enforces a covered transaction, or receives a material portion of its revenues, where the person relies upon the bank’s interest rate authority. If enacted, S10688 would take effect 180 days after becoming law, with regulatory implementation authorized to begin immediately upon enactment. The bill was referred to the Senate Committee on Rules the same day. This proposed legislation marks the latest development in a continuing trend of state efforts to regulate state-chartered banks and fintech partnerships and impose restrictions on bank-model lending. For more information, click here.

On August 24, the California Department of Financial Protection and Innovation (DFPI) updated its guidance encouraging licensees to promptly report cybersecurity incidents, recommending notification within 48 hours, or as soon as possible, when a licensee has reason to believe it has experienced a reportable cyber incident with a nexus to California operations. Reportable incidents include a broad range of substantial events such as ransomware attacks, distributed denial of service attacks, unauthorized network intrusions, data breaches compromising sensitive client or employee information, phishing attacks causing significant downtime, social engineering attacks resulting in fraudulent fund transfers, and third-party vendor breaches, among others, with licensees directed to submit reports via the DFPI’s Cybersecurity Incident Report Form. For more information, click here.

On August 13, the California DFPI announced a consent order requiring Utah-based Academy Mortgage Corporation to pay $825,000 and provide one year of free identity theft insurance to affected customers after finding that the company failed to adequately protect the personal information of more than 284,443 individuals, including at least 34,452 California residents, due to serious, longstanding cybersecurity and recordkeeping deficiencies that left it vulnerable to a ransomware attack in March 2023. The DFPI found that Academy Mortgage did not detect the breach until after employee credentials were stolen and network security systems were disabled, and further failed to obtain a written forensic report to adequately document the incident, limiting transparency about its scope. Under the consent order, the company must also notify all affected California customers of their eligibility for the identity theft insurance coverage, comply with all applicable California laws, and maintain an adequate cybersecurity program going forward. For more information, click here.

International Activities:

On September 4, the Financial Stability Board (FSB) published its financial statements for the 12-month period ending March 31, 2026, along with details on its governance arrangements and accountability mechanisms. The FSB, established in April 2009 as a Swiss-law association hosted at the Bank for International Settlements (BIS) in Basel, reported total contributions of CHF 15.2 million for the period (a 2.6% decrease from CHF 15.6 million the prior year) with the BIS providing the vast majority of funding (CHF 14.9 million) alongside smaller contributions from the IMF and the Hong Kong Monetary Authority, and operating with an average Secretariat headcount of 38 staff. As an organization with no assets, liabilities, or independent revenue, the FSB’s financial statements consist solely of a statement of activities reflecting contributed expenses, primarily personnel costs. The FSB’s 70 member institutions span 25 jurisdictions, including 10 emerging market and developing economies, plus 10 international organizations and standard-setting bodies, and its reach extends to 70 additional jurisdictions through 6 Regional Consultative Groups; the financial statements were audited by PricewaterhouseCoopers Switzerland and approved by the FSB Plenary on June 30, 2026. For more information, click here.