$2.8B in Fines for
Off-Channel Communications
Since 2021, the SEC has fined over 100 firms for failing to preserve business communications on WhatsApp, iMessage, and personal email. The pattern is always the same: records were never captured, or were destroyed.
Featured Cases
JPMorgan Chase
December 2021
The case that started the wave. Employees firm-wide used WhatsApp, iMessage, and personal email for securities business from 2018-2020. Senior compliance managers participated in the violations. First major SEC off-channel enforcement.
Source: SEC Press ReleaseWave 2 — 8 Major Firms
September 2022
Goldman Sachs, Morgan Stanley, Bank of America, Barclays, Citigroup, Credit Suisse, Deutsche Bank, UBS — each fined $125M. All the same pattern: widespread off-channel communications, records destroyed or never captured.
Source: SEC Press ReleaseWells Fargo
August 2023
Three Wells Fargo entities fined together. Despite being aware of the SEC's enforcement wave, the firm still could not demonstrate adequate recordkeeping controls.
Source: SEC Press ReleaseWave 5 — 7 Financial Firms
August 2024
Ameriprise, Edward Jones, LPL Financial, Raymond James ($50M each), RBC Capital Markets ($45M), BNY Mellon/Pershing ($40M), TD Securities ($30M). The fines keep growing — firms are being caught years after the pattern was established.
Source: SEC Press ReleaseWave 6 — Private Equity Firms
January 2025
Blackstone ($12M), KKR ($11M), Charles Schwab ($10M), Apollo ($8.5M), Carlyle ($8.5M), TPG ($8.5M). The SEC expanded beyond broker-dealers to investment advisers and private equity.
Source: SEC Press ReleaseWhat went wrong in every case
The same violations appear across all enforcement actions, regardless of firm size or sophistication.
- Personal devices and apps (WhatsApp, iMessage, Signal) used for business communications
- Firms had no systems to capture or archive off-channel messages
- When regulators asked for records, they simply didn't exist
- Senior compliance officers were participating in the same violations
- Firms aware of the enforcement wave still got caught — knowing the risk wasn't enough
How tamper-proof evidence changes the equation
Cryptographic audit trails make it mathematically impossible to alter or destroy records without detection.
Record Existence is Provable
Every communication event gets a cryptographic receipt at the moment it occurs. If a record exists in the chain, it provably existed at that timestamp. If it doesn't, that gap is cryptographically detectable.
Completeness is Verifiable
The append-only chain makes it mathematically impossible to selectively delete records without detection. Regulators can verify that no records were removed between any two points in time.
Compliance is Continuous
Instead of point-in-time audits, cryptographic receipts provide continuous proof that recordkeeping controls were active. Not just "we had a policy" — "here's the mathematical proof it was enforced."
Ready to make your audit trail tamper-proof?
Create your free account and start protecting your data with cryptographic evidence that can't be altered or destroyed.