By Staff Reporter
September 9, 2026
The U.S. Federal Trade Commission (FTC) has delivered a significant blow to the ecosystem of illicit financial services, announcing a sweeping enforcement action against two credit card payment processors. These entities have been ordered to pay substantial fines and are now subject to permanent injunctions that restrict their ability to service high-risk merchants. The action serves as a stern warning to the financial intermediary sector regarding their role in gatekeeping the payments landscape against fraudulent actors.
According to the FTC’s findings, the two firms were instrumental in enabling a series of consumer scams, processing upwards of $130 million in payments for "bogus companies." These companies, which operated under the guise of legitimate business entities, were reportedly defrauding unsuspecting members of the public through sophisticated deceptive practices.
The Nature of the Fraud: Gatekeepers Under Scrutiny
In the complex architecture of modern e-commerce, payment processors occupy a critical position. They are the conduits through which digital currency flows from the consumer to the merchant. Because of this, regulators like the FTC and the Consumer Financial Protection Bureau (CFPB) expect these entities to perform adequate "Know Your Customer" (KYC) and anti-money laundering (AML) due diligence.

The FTC’s investigation uncovered that these specific processors essentially turned a blind eye to obvious red flags. By providing financial infrastructure to companies that lacked valid business models, these processors effectively acted as the "financial backbone" for schemes that relied on deceptive marketing, non-existent products, and unauthorized credit card charges. The $130 million in processed payments represents more than just a balance sheet figure; it represents thousands of individual consumer harms that might have been prevented had the processors adhered to standard compliance protocols.
Chronology of the Regulatory Action
The timeline leading up to this week’s announcement highlights the meticulous process by which the FTC builds cases against financial intermediaries.
- Early 2024: The FTC initiates an informal inquiry into patterns of consumer complaints regarding unauthorized charges stemming from a cluster of high-risk online merchants.
- Late 2024: Initial discovery reveals that the common denominator among these disparate fraudulent merchants was the use of a small set of payment processing gateways.
- Early 2025: The FTC issues Civil Investigative Demands (CIDs) to the two processors, seeking internal communications, merchant vetting logs, and transactional data.
- Mid-2025: Evidence emerges that the processors continued to service these merchants despite receiving numerous "chargeback" alerts—the industry standard indicator that consumers are disputing transactions due to fraud.
- Early 2026: Settlement negotiations begin, with the FTC seeking not only financial restitution but also structural changes to the companies’ internal compliance departments.
- September 2026: The FTC finalizes the enforcement order, mandating the payment of fines and the implementation of rigorous new oversight measures.
Supporting Data: The Cost of Negligence
The $130 million figure is a stark reminder of the scale at which modern fraud operates. In the digital age, a single fraudulent merchant can process thousands of transactions per day. When payment processors fail to perform adequate due diligence, they allow these merchants to gain access to the global financial system.
Industry data suggests that high-risk merchants are characterized by high chargeback rates, inconsistent billing descriptors, and a lack of verifiable physical office locations. The FTC’s enforcement action emphasizes that these processors had clear visibility into these metrics. By ignoring the data, the firms allowed the fraudulent schemes to persist far longer than they would have in a regulated environment. The resulting consumer losses—ranging from identity theft to unauthorized subscription billing—underscore the systemic impact of this oversight failure.

Official Responses and the Regulatory Stance
The FTC has been clear in its messaging: payment processors are not neutral utility providers. They are active participants in the financial system and, as such, bear a significant responsibility for the character of the transactions they facilitate.
"Payment processors cannot hide behind the excuse of being a mere conduit," an FTC spokesperson noted during the press briefing regarding the case. "When you provide the tools for fraud, you are a participant in that fraud. The era of ‘willful blindness’ in the payments industry is coming to an end."
Representatives for the processors involved have largely remained quiet, though industry analysts suggest that the firms are likely undergoing massive restructuring of their compliance teams to meet the new, strict requirements imposed by the FTC. These requirements include mandatory, ongoing monitoring of merchant activity and the immediate termination of any account that exhibits a threshold level of suspicious activity.
Implications for the Financial Services Industry
The fallout from this enforcement action is expected to ripple across the fintech and traditional banking sectors. Several key implications have already begun to emerge:

1. The End of "Willful Blindness"
For years, some smaller processors operated on a model that prioritized volume over vetting. The FTC’s action signals that this model is no longer viable. Processors must now adopt a "proactive vetting" stance, where the burden of proof lies on the processor to demonstrate that their merchants are legitimate, rather than waiting for regulatory intervention to flag suspicious accounts.
2. Heightened Compliance Costs
The cost of compliance is set to rise. To avoid similar fines, processors will likely need to invest in more advanced AI-driven transaction monitoring systems. These systems will be required to cross-reference merchant data against various watchlists and detect patterns of "transaction laundering," where merchants hide the true nature of their sales.
3. Increased Scrutiny on "High-Risk" Verticals
The FTC has explicitly ordered these processors to steer clear of certain high-risk categories. This will likely lead to a "de-risking" trend across the industry, where processors may preemptively drop legitimate but high-risk businesses (such as adult entertainment, nutraceuticals, or certain subscription services) to avoid the risk of regulatory friction. While this protects the financial system, it raises concerns about access to financial services for niche industries.
4. Expansion of Regulatory Oversight
Legal experts suggest this case is a blueprint for future FTC actions. By targeting the "middleman" rather than just the primary fraudsters—who are often harder to track and prosecute—the FTC has found a more efficient way to dismantle fraud networks. This "choke point" strategy is likely to be employed in other sectors, including digital advertising and cloud hosting services.

Conclusion: A Shift in the Compliance Paradigm
The enforcement action against these two payment processors represents a fundamental shift in how the FTC views financial intermediaries. By holding them accountable for the $130 million in damages, the agency has sent a clear message: the financial infrastructure of the internet is not a lawless zone.
For compliance officers and legal counsel at financial institutions, the takeaway is unambiguous. The internal controls that were sufficient five years ago are insufficient today. As the tools for committing fraud become more sophisticated, the tools for detecting and preventing them must keep pace. The coming months will likely see a flurry of activity as firms rush to audit their own merchant portfolios, seeking to avoid becoming the next target of a high-profile FTC enforcement action.
The industry is now on notice: in the modern regulatory climate, the processor is just as responsible as the merchant. Compliance is no longer a back-office administrative task; it is a critical defensive barrier that guards the very integrity of the digital economy.
