Back to Enforcement
SEC Enforcement · 26 cases · 2021–2025

$2.8B in Fines for
Off-Channel Communications

Since 2021, the SEC has fined over 100 firms for failing to preserve business communications on WhatsApp, iMessage, and personal email. The pattern is always the same: records were never captured, or were destroyed.

Featured Cases

JPMorgan Chase

December 2021

$200M

The case that started the wave. Employees firm-wide used WhatsApp, iMessage, and personal email for securities business from 2018-2020. Senior compliance managers participated in the violations. First major SEC off-channel enforcement.

Source: SEC Press Release

Wave 2 — 8 Major Firms

September 2022

$1.1B

Goldman Sachs, Morgan Stanley, Bank of America, Barclays, Citigroup, Credit Suisse, Deutsche Bank, UBS — each fined $125M. All the same pattern: widespread off-channel communications, records destroyed or never captured.

Source: SEC Press Release

Wells Fargo

August 2023

$125M

Three Wells Fargo entities fined together. Despite being aware of the SEC's enforcement wave, the firm still could not demonstrate adequate recordkeeping controls.

Source: SEC Press Release

Wave 5 — 7 Financial Firms

August 2024

$392.75M

Ameriprise, Edward Jones, LPL Financial, Raymond James ($50M each), RBC Capital Markets ($45M), BNY Mellon/Pershing ($40M), TD Securities ($30M). The fines keep growing — firms are being caught years after the pattern was established.

Source: SEC Press Release

Wave 6 — Private Equity Firms

January 2025

$63.1M

Blackstone ($12M), KKR ($11M), Charles Schwab ($10M), Apollo ($8.5M), Carlyle ($8.5M), TPG ($8.5M). The SEC expanded beyond broker-dealers to investment advisers and private equity.

Source: SEC Press Release

What went wrong in every case

The same violations appear across all enforcement actions, regardless of firm size or sophistication.

  • Personal devices and apps (WhatsApp, iMessage, Signal) used for business communications
  • Firms had no systems to capture or archive off-channel messages
  • When regulators asked for records, they simply didn't exist
  • Senior compliance officers were participating in the same violations
  • Firms aware of the enforcement wave still got caught — knowing the risk wasn't enough

How tamper-proof evidence changes the equation

Cryptographic audit trails make it mathematically impossible to alter or destroy records without detection.

Record Existence is Provable

Every communication event gets a cryptographic receipt at the moment it occurs. If a record exists in the chain, it provably existed at that timestamp. If it doesn't, that gap is cryptographically detectable.

Completeness is Verifiable

The append-only chain makes it mathematically impossible to selectively delete records without detection. Regulators can verify that no records were removed between any two points in time.

Compliance is Continuous

Instead of point-in-time audits, cryptographic receipts provide continuous proof that recordkeeping controls were active. Not just "we had a policy" — "here's the mathematical proof it was enforced."

Ready to make your audit trail tamper-proof?

Create your free account and start protecting your data with cryptographic evidence that can't be altered or destroyed.