← Broker database 2023-01-27
FINRA Fines Herbert J. Sims & Co. $100,000 for Failing to Review Cyber-Events for AML
According to FINRA, Herbert J. Sims & Co, Inc. was censured and fined $100,000 for failing to establish and implement an anti-money laundering (AML) program that was reasonably designed to detect and cause the reporting of suspicious cyber-events.
Cyber-events occurred at or through the firm wherein a bad actor gained unauthorized access to a customer's or a registered representative's email account. In two of those events, the bad actor initiated a request to wire funds to third-party bank accounts. In one instance, the firm approved an $80,000 wire request and funds were sent to the third-party account (but eventually recovered). In other events, bad actors gained access to the email accounts of the firm's employees.
Although the firm maintained a cybersecurity policy, it did not reference any requirement to review cyber-events for AML purposes. Further, the firm's written AML compliance program did not mention cyber-events and the firm had no process in place for conducting reviews of such events. Thus, although the firm became aware of each cyber-event soon after they occurred, and the firm's head of information technology conducted forensic investigations of each event, the firm failed to conduct any AML investigation concerning the events or recognize that the nature of the incidents and the assets put at risk by the cyber-events potentially necessitated the filing of Suspicious Activity Reports.
The intersection of cybersecurity and anti-money laundering compliance is increasingly important in today's digital environment. Cybercriminals often use compromised accounts to move illicit funds or commit fraud. When a firm experiences a cyber-event involving unauthorized access to accounts or wire transfer requests, this may be indicative of money laundering or other financial crimes that require filing a Suspicious Activity Report.
Firms must recognize that their AML programs need to address cyber-related risks. This includes having procedures to review cyber-events for potential money laundering red flags and determining whether Suspicious Activity Reports are warranted. Simply investigating the technical aspects of a cyber-event is not sufficient; firms must also consider the financial crime implications.
This case serves as an important reminder that AML compliance programs must evolve to address emerging risks, including those posed by cyber threats.