Auditen
action postmortem

The Volume Was High. The Merchants Were Fakes.

Humboldt Merchant Services just handed $12 million to the FTC; this wasn't some mistake with a filing deadline or a glitch in the software. They paid because they knew they were processing payments for sham merchants running billing scams.

The temptation must be huge for a small firm. Imagine finding a client who brings in massive volume overnight, and fees roll in and growth charts look great. Who cares if the business model is opaque? You tell yourself you're just the plumbing, so you shouldn't have to care what flows through the pipes.

That logic is a financial suicide pact.

Humboldt didn't fail because their systems were weak. They just looked away. High-risk activity was right there in front of them, but the money was too good to stop, and the FTC doesn't care if you're just the processor. If you help a fraud happen, you're in on the scam.

The control they needed wasn't a million-dollar AI monitoring suite. It was a basic smell test applied to onboarding and volume spikes.

Look at a consultancy with a one page website and no LinkedIn profile; if they suddenly move more than $100,000 in seven days, it isn't a success story. It's a red flag. You can stop this with a cheap control (a manual review trigger), and any account hitting a set volume threshold in its first 30 days gets a human check. Why? Because you need to see if the product exists and if they have a physical address that isn't just a PO box.

Some will argue that this creates too much friction. They'll say that in a competitive market, you can't afford to slow down onboarding or risk offending high-value clients.

Go for it. If you want a $12 million fine and a permanent ban from processing high-risk payments, just leave the gates open, and a few hours of manual vetting is cheap when you compare it to losing your license.

The fallout hits harder than the fine. Insurance is where it really hurts. Most professional indemnity policies exclude dishonest or criminal acts, and you'll pay the regulator out of pocket, and you'll likely find yourself uninsurable across the sector; partners will drop you fast. They won't risk being the next target in a chain of facilitation probe.

The lesson is simple: if your growth feels too easy, it's probably because you're ignoring the risk.

Forget the myth that acting as a service provider lets you ignore who your customers are. You provide the tools for a crime. That makes you an accomplice with a balance sheet.

Check your top five clients by volume this week. If you can't explain exactly how they make their money in two sentences, find out before the regulator does.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. OneTouchPoint Agrees to Multi-Million Dollar Data Breach Settlement - The HIPAA Journal Data Privacy (Google News)
  2. American LGBTQ+ dating app Grindr to pay UK users £26 million over privacy breach - Peoples Gazette Nigeria Data Privacy (Google News)
  3. SEC Proposes Comprehensive Modernization of Transfer Agent Rules, Signals Further Progress on Framework for Tokenized Securities - Morgan Lewis Compliance Week (Google News)
  4. FTC Takes Action Against Payment Processor Humboldt Merchant Services for Knowingly Facilitating Payment Processing for Sham Merchants FTC Press Releases
  5. Broad Coalition Urges SEC To Reject NYSE Proposal Allowing Newly Listed Companies to Go Five Years Without Internal Audit - PR Newswire Compliance Week (Google News)
  6. The EU AI Act just gave you a breach notification clock you didn’t know about - cio.com Data Privacy (Google News)
  7. Florida DMV alleged breach claimed by ShinyHunters hackers - Cybernews Data Privacy (Google News)
  8. Hackers tease breach of Florida DMV by leaking Epstein’s driving record - Straight Arrow Data Privacy (Google News)

How stories are selected and assessed