NYDFS Fines Money Transmitter $250K Over Cybersecurity Failures

2 min readSources: National Law Review

NYDFS announced a $250,000 cybersecurity settlement with a money transmitter.

Why it matters: Financial firms face heightened regulatory scrutiny over cybersecurity practices. This settlement signals continued enforcement pressure on institutions to maintain strong security controls for compliance and risk management.

  • NYDFS imposed a $250,000 penalty on a money transmitter for failing to implement adequate cybersecurity controls.
  • In August 2025, NYDFS fined Healthplex, Inc. $2 million for cybersecurity violations including lack of multi-factor authentication.
  • In May 2023, bitFlyer USA, Inc. paid $1.2 million and OneMain Financial Group $4.25 million for similar cybersecurity compliance failures.
  • The settlement illustrates NYDFS’s ongoing commitment to enforcing cybersecurity regulations in the financial sector.

The New York Department of Financial Services (NYDFS) recently secured a $250,000 settlement with a money transmitter over inadequate cybersecurity controls, reaffirming strict regulatory expectations for financial institutions. The specific money transmitter involved was not disclosed publicly.

This enforcement action follows a pattern of substantial penalties NYDFS has imposed in recent years. For instance, in August 2025, NYDFS reached a $2 million settlement with Healthplex, Inc. for multiple cybersecurity violations, notably failing to implement multi-factor authentication and delaying breach notifications. Earlier, in May 2023, bitFlyer USA, Inc. paid $1.2 million and OneMain Financial Group incurred a $4.25 million penalty for failing to maintain adequate cybersecurity programs, as detailed in NYDFS’s 2025 Consumer Protection and Financial Fraud Enforcement Annual Report and the 2023 Enforcement Division Annual Report.

These actions highlight the NYDFS’s heightened focus on cybersecurity readiness within the financial services sector, especially for entities like money transmitters that handle sensitive financial data. The department’s enforcement strategy emphasizes timely breach reporting, implementation of multi-factor authentication, and comprehensive cybersecurity governance.

Financial firms should recognize the continuing regulatory trend toward rigorous cybersecurity compliance enforcement. Ensuring robust security measures not only protects institutions and consumers but also mitigates legal and financial risks posed by regulatory penalties.

By the numbers:

  • $250,000 — recent NYDFS settlement with a money transmitter
  • $2 million — penalty against Healthplex, Inc. in August 2025
  • $4.25 million — penalty against OneMain Financial Group, LLC in May 2023