ARTICLE
14 August 2026

NYDFS Secures $250,000 Cybersecurity Settlement With Money Transmitter

SM
Sheppard, Mullin, Richter & Hampton LLP

Contributor

Businesses turn to Sheppard to deliver sophisticated counsel to help clients move ahead. With more than 1,200 lawyers located in 16 offices worldwide, our client-centered approach is grounded in nearly a century of building enduring relationships on trust and collaboration. Our broad and diversified practices serve global clients—from startups to Fortune 500 companies—at every stage of the business cycle, including high-stakes litigation, complex transactions, sophisticated financings and regulatory issues. With leading edge technologies and innovation behind our team, we pride ourselves on being a strategic partner to our clients.
The New York Department of Financial Services has imposed a $250,000 penalty on a licensed money transmitter following a 2022 ransomware attack that exposed critical gaps in the company's cybersecurity framework. The enforcement action highlights specific deficiencies in risk assessment protocols, cybersecurity program design, and software update policies that allegedly violated New York's Cybersecurity Regulation. This settlement underscores the regulatory expectation that financial institutions maintain r
United States Finance and Banking
Sheppard, Mullin, Richter & Hampton LLP are most popular:
  • within Insolvency/Bankruptcy/Re-Structuring topic(s)

On August 5, the NYDFS announced a $250,000 settlement with a licensed money transmitter over alleged violations of New York’s Cybersecurity Regulation, 23 NYCRR Part 500. NYDFS alleged that the money transmitter maintained inadequate cybersecurity risk assessments and policies governing system and software updates, deficiencies identified after a September 2022 ransomware event.

According to the consent order, the company discovered server-connectivity issues on September 7, 2022, shut down its network, and later determined that ransomware had encrypted just over half of its servers. The company timely reported the incident to NYDFS, which subsequently investigated its cybersecurity controls. Specifically, NYDFS alleged that the company:

  • Failed to conduct an adequate risk assessment. The company’s annual assessment addressed operational and information technology risks but allegedly did not sufficiently consider company-specific cybersecurity risks or evaluate the effectiveness of existing controls, in violation of Section 500.9(a).
  • Maintained an inadequate cybersecurity program. Because the company’s program was not based on an adequate risk assessment, NYDFS alleged that it was not sufficiently designed to identify and assess risks to nonpublic information, in violation of Section 500.2(b).
  • Maintained insufficient cybersecurity policies. The company’s policies governing application and system updates allegedly covered only a limited number of the third-party applications and software products it used, leaving other software exposed to known vulnerabilities and allegedly violating Section 500.3(g).

The company agreed to pay a $250,000 civil monetary penalty and has remediated the deficiencies identified by NYDFS. In assessing the penalty, NYDFS considered the company’s cooperation, size and revenue, and limited exemption from certain Part 500 requirements.

Putting It Into Practice: The settlement reflects NYDFS’s continued focus on cybersecurity governance and the adequacy of controls maintained by regulated financial institutions. The Department has increasingly emphasized risk assessments, patch management, and policies that are tailored to an institution’s actual systems and operations. Financial institutions subject to New York’s cybersecurity requirements should review their risk assessments and cybersecurity policies to ensure they address institution-specific threats, software vulnerabilities, and the effectiveness of existing controls.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More