News: 1664370011

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Ever suspected bankers could just use WhatsApp comms? $1.8b says you're right

(2022/09/28)


Updated Ever given a colleague a quick Signal call so you can sidestep a monitored workplace app? Well, we'd hope you're not in a highly regulated industry like staff at eleven of the world's most powerful financial firms, who yesterday were fined nearly $2 billion for off-channel comms.

[1]

Banking giants including Goldman Sachs, Credit Suisse, and Citigroup agreed to pay $1.1 billion in penalties from the US Securities and Exchange Commission (SEC) and $710 million in fines from the Commodity Futures Trading Commission (CFTC) in separate actions on Tuesday for failing to monitor and stop their workers from using unauthorized messaging apps. The action comes after months of wrangling between the federal regulators and the banks, culminating in fines many have criticized as being too small to be a real deterrent.

The companies yesterday admitted their staff, including senior investment bankers and equity traders, regularly shot the breeze on WhatsApp and other "unapproved" private channels.

The companies were also hit with cease and desist orders preventing them from continuing to "commit or caus[e] any violations and any future violations of Section 17(a) of the Exchange Act." In what might be the most unusual part of this situation, all of the companies (along with some of their subsidiaries) appear to have admitted to wrongdoing.

The SEC said in a [2]statement that its investigation uncovered "pervasive off-channel communications," and that after gathering communications from the personal devices of just a sample of the various firms' personnel they found off-channel exchanges between "senior and junior investment bankers and debt and equity traders."

[3]

SEC chair Gary Gensler said in a statement: "Finance, ultimately, depends on trust. By failing to honor their recordkeeping and books-and-records obligations, the market participants we have charged today have failed to maintain that trust."

[4]

[5]

The agency went on to say that secret squirrel comms failings had occurred across all "16 firms" (that number includes the 11 and their affiliates - there's a full [6]list here ), adding that it had "involved employees at multiple levels of authority, including supervisors and senior executives."

The [7]CFTC , meanwhile, said of its separate but related operation that the behavior was "egregious and widespread" and the "increasing reliance on novel communications platforms available on personal mobile devices, indicates a concern that — unless effectively addressed — may negatively impact market-participants' internal compliance ... and the Division of Enforcement's ability to effectively and efficiently investigate conduct that may violate the CEA and/or CFTC regulations."

[8]

The agency also said it was looking at allegations of similar misconduct at another "major financial institution" registered with the CFTC in the matter, citing a [9]2021 complaint where a dollar-swaps trader at a global investment bank was alleged to have deleted WhatsApp comms after the division made an order that he retain all communication on messaging apps including Facebook, Whatsapp, Telegram, Slack, or Signal, including any backed up versions in cloud storage etc.

Who's paying what?

Of Tuesday's settlements, Bank of America, aka BofA, will pay the most: $225 million, the bulk of which is the SEC penalty

[10]PDF

.

Barclays

[11]PDF

, Citigroup

[12]PDF

, Credit Suisse

[13]PDF

, Deutsche Bank

[14]PDF

, Goldman Sachs

[15]PDF

, Morgan Stanley

[16]PDF

and UBS

[17]PDF

will each pay $200 million each.

Nomura will pay $100 million

[18]PDF

, [19]Jefferies [PDF] agreed to $80 million, and Cantor Fitzgerald

[20]PDF

will pay $16 million.

JPMorgan already paid $125 million in [21]December last year for failing its recordkeeping and books-and-records obligations, admitting that from "at least January 2018 through November 2020, its employees often communicated about securities business matters on their personal devices, using text messages, WhatsApp, and personal email accounts. None of these records were preserved by the firm as required by the federal securities laws." The SEC complained this hurt its "ability to be an effective cop on the beat."

As for what's to stop them from doing it again, the businesses have all vowed to up their compliance efforts, agreeing to retain compliance consultants who will conduct comprehensive reviews of their policies and procedures on the retention of "electronic communications found on personal devices" and take a look at their "frameworks for addressing non-compliance by their employees with those policies and procedures."

[22]Open up, it's the IRS. We're here about the crypto tax you dodged

[23]Cisco asks shareholders to vote against global tax transparency

[24]Boeing to pay SEC $200m to settle charges it misled investors over 737 MAX safety

[25]Microsoft: Blobs can be WORMs in the new, regs-compliant Azure

Gurbir Grewal, director of the SEC's Division of Enforcement, said the 16 firms admitted the facts and acknowledged that their conduct violated these very important requirements, and have started to implement measures to prevent future violations.

The Register is keen to hear any of your solutions to the sticky shadow comms problem. You could require staff to place personal devices in secured containers, but what happens when they're needed outside the office? How do you enforce such a policy? And then how can the company be sure you don't just walk out the office after work after market close, and simply send a Telegram message from your own cellphone? Quants and traders, on the whole, are better than your average non-finance fan at memorizing strings of numbers. ®

Updated to add:

Bank of America, Barclays, Goldman Sachs, Credit Suisse, and Nomura all declined to comment while Deutsche Bank told us it "fully cooperated" with regulators on this "industry-wide matter" and "proactively deployed fully compliant and convenient text and chat platforms." You'll be relieved to know it doesn't expect any impact on its third quarter results.

Get our [26]Tech Resources



[1] https://regmedia.co.uk/2022/09/28/shutterstock_haha_business.jpg

[2] https://www.sec.gov/news/press-release/2022-174

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YzRvnWVnapRQCORo@kvUOwAAAME&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YzRvnWVnapRQCORo@kvUOwAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YzRvnWVnapRQCORo@kvUOwAAAME&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.sec.gov/news/press-release/2022-174

[7] https://www.cftc.gov/PressRoom/SpeechesTestimony/johnsonstatement092722

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YzRvnWVnapRQCORo@kvUOwAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.cftc.gov/PressRoom/PressReleases/8359-21

[10] https://www.sec.gov/litigation/admin/2022/34-95921.pdf

[11] https://www.sec.gov/litigation/admin/2022/34-95919.pdf

[12] https://www.sec.gov/litigation/admin/2022/34-95920.pdf

[13] https://www.sec.gov/litigation/admin/2022/34-95926.pdf

[14] https://www.sec.gov/litigation/admin/2022/34-95928.pdf

[15] https://www.sec.gov/litigation/admin/2022/34-95922.pdf

[16] https://www.sec.gov/litigation/admin/2022/34-95924.pdf

[17] https://www.sec.gov/litigation/admin/2022/34-95929.pdf

[18] https://www.sec.gov/litigation/admin/2022/34-95925.pdf

[19] https://www.sec.gov/litigation/admin/2022/34-95923.pdf

[20] https://www.sec.gov/litigation/admin/2022/34-95927.pdf

[21] https://www.sec.gov/news/press-release/2021-262

[22] https://www.theregister.com/2022/09/23/irs_cryptocurrency_income_tax/

[23] https://www.theregister.com/2022/09/27/cisco_tax_transparency/

[24] https://www.theregister.com/2022/09/23/boeing_sec_200m/

[25] https://www.theregister.com/2018/06/20/azure_goes_immutable_as_microsoft_plays_catchup/

[26] https://whitepapers.theregister.com/



They admitted to it...

steviebuk

..because they probably have their backup plan in action already to carry on with burner phones. If they admit guilt and can afford to pay the fine then they probably know they can easily get away with it again, make more money and know what they'd look for so know what how to hide better. Burner phones would be the way to go, set to not backup to the cloud and when asked to hand them over, accidently drop them in salt water (the sea).

Re: They admitted to it...

Cederic

Ah. Check with Rebekah Vardy regarding that last suggestion.

Re: They admitted to it...

JimboSmith

I’m slightly surprised no one has created an encrypted banking chat app. You’d have an auto purge for messages after a set period of time and possibly a self destruct/delete of the of the program if the wrong password is entered. Then these people could easily continue their nefarious behaviour on a burner device without worry.

Re: They admitted to it...

Yet Another Anonymous coward

Because all that is the easy part.

The hard part is how do you know that "Spazz69" is really a trader at Deutsche and not a kid in a basement, or a Russian bot, or an SEC agent ?

Even if you met them and confirmed it how do you know their account hasn't been taken over or that they aren't now cooperating with the Feds ?

You need 100% provable identity when making deals and 100% anonymity and deniability when caught - that's mathematically tricky

Fine bribe

Anonymous Coward

So a 1.1 Billion $ Fee, and nobody goes to jail. Makes you wonder how many more billions they made illegally to pay that "Fee" without a complaint.

Rich people have it so easy, just commit crimes and pay off the regulators.

No wonder these crimes are common, there are no repercussions that matter, just a tax/fee/fine/bribe.

Evil Auditor

"Finance, ultimately, depends on trust..."

Yeah right. And why again do I have the impression that "big finance" has been doing whatever they can to destroy that trust?

"Finance, ultimately, depends on trust..."

Paul Smith

Duh, no it doesn't.

Finance depends on having an edge and the biggest edge you can have is knowing what is going to happen before the rest of the market. Traders have always shared that knowledge among other traders to earn or repay favors. Before phones were invented, those back channel communications took place in coffee shops which is why financial institutions are packed so tightly together into places like wall street or the square mile.

TheRealRoland

This is my surprised and shocked face ->

A privileged elite?

Mike 137

" Banking giants [...] agreed to pay $1.1 billion in penalties from the US Securities and Exchange Commission (SEC) and $710 million in fines from the Commodity Futures Trading Commission (CFTC) "

Anyone else (except maybe a tech behemoth) would just be told to pay up, no agreement necessary.

That Reminds Me...

Commswonk

When I read the inset section Who's paying what? I was immediately reminded of the famous line from "Casablanca": Round up the usual suspects.

Fines mean nothing to banks

VoiceOfTruth

The money is merely taken from the shareholders by way of lower dividends.

You can be banned from driving for using a mobile phone. Ban the bankers using unapproved comms from banking for 1 year for the first offence, then 5 years for the inevitable second offence.

This is insider trading and it is not victimless. The victims are everyone who has shares or trades and is not a member of the gang. You go to a bank or a foreign exchange shop to get some foreign currency, which somebody has manipulated in their favour. You are the victim of a crime. It may only be a few £$€ to you, but added up it's millions. You buy some shares not knowing what insider traders know. Again you are the victim of a crime.

What do the regulators do? Make a little bit of a noise and let them get away with it.

Actually, they missed out on a second fine..

Anonymous Coward

Any of the organisations that were using WhatsApp in Europe very likely broke EU privacy laws as well, unless they can demonstrate permission of every single personal entry in their address book to have their contact details shipped to Zuckerberg.

WhatsApp is use is about the easiest way to get a company into trouble, even if they are not in finance.

That said, the sort of fines that most EU privacy regulators can levy would represent a mere rounding error on their balance sheet. The joy of much lobbying from the volume offenders.

Anonymous Coward

Having worked in the investment banking industry within a department with a partial responsibility to ensure regulatory compliance is met, I can tell you that the biggest problem is that no one wants to upset the star bankers by saying "No, you can't do that" **and preventing them doing so** for the fear of losing them to the competition. And likewise, no banker wants to tell his client "No, I can't do that anymore" for fear of losing the client to someone who will.

First Law of Bicycling:
No matter which way you ride, it's uphill and against the wind.