Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Compliance Strategy

FinCEN Extended 314(b) to Fraud: The Safe Harbor Most Financial Institutions Are Still Ignoring

On June 12, 2026, FinCEN updated its Section 314(b) Fact Sheet to explicitly cover fraud — including pig butchering, romance scams, and mule account activity. Institutions can now share transaction records, device data, IP addresses, and video footage in real time with other registered participants. Here's what changed, what you can and can't share, and why most compliance teams are leaving this tool unused.

By Rebecca Leung · July 21, 2026 ·
Table of Contents

Here’s a fraud network scenario that plays out hundreds of times a year: a pig butchering victim sends a series of wire transfers to what they believe is a crypto investment account. Your institution processes the outgoing wires. Another institution receives the inbound funds and converts them to crypto through what appears to be a legitimate customer account. A third institution sees unusual incoming wires from multiple first-time senders.

Each institution has a piece of the picture. None of them knows the others have it. The network disperses the funds across four more accounts before compliance at any one institution completes a SAR. The money is gone before the intelligence reaches law enforcement.

That’s the problem Section 314(b) was built to solve — and until June 12, 2026, it was mostly being used as an AML-only tool while fraud schemes adapted to exploit the gap.

On June 12, 2026, FinCEN released an updated Section 314(b) Fact Sheet that explicitly extends the safe harbor to fraud. The guidance isn’t a new program — 314(b) has existed since 2001. But the clarification matters because it removes the legal uncertainty that has kept compliance teams from using 314(b) as a fraud-fighting tool, and it adds operational guidance on real-time sharing that changes what the program can actually accomplish.

TL;DR

  • FinCEN’s June 12, 2026 Section 314(b) Fact Sheet explicitly extends the voluntary information-sharing safe harbor to fraud — including pig butchering, romance scams, and mule account activity
  • Registered institutions can now share transaction records, IP addresses, video surveillance, device data, and adverse media in real time — verbally or electronically
  • You cannot share a SAR or reveal one exists; you can share all the underlying facts it’s based on
  • FDIC and OCC both issued guidance encouraging institutions to register that haven’t already done so
  • Most compliance teams have treated 314(b) as an AML program — the June 2026 update turns it into a fraud intelligence network for institutions willing to use it

What Section 314(b) Actually Is

Section 314(b) of the USA PATRIOT Act, codified at 31 CFR 1010.540, creates a voluntary information-sharing mechanism between financial institutions to jointly identify and report money laundering and terrorist financing activity.

The core mechanism is simple: registered financial institutions can share information about individuals, entities, and transactions suspected of involving illicit activity — and the sharing is protected by a federal safe harbor from liability under state and federal privacy laws, including GLBA Regulation P.

Before the June 2026 update, the statute and FinCEN’s guidance technically covered “money laundering and terrorist financing” without explicitly addressing fraud. The legal question was whether fraud-derived proceeds fell within the program’s scope. In practice, many compliance teams treated 314(b) as an AML tool and reached for Section 314(a) — the mandatory information-sharing channel with law enforcement — or state fraud coalitions for fraud-specific intelligence sharing.

The June 2026 update closes that ambiguity. FinCEN’s Fact Sheet states plainly that the safe harbor extends to “suspected fraud” and gives specific examples: pig butchering scams, romance scams, and mule account activity. The guidance notes that a financial institution “need only suspect that activity may involve a fraud-related Specified Unlawful Activity” to share under the safe harbor — a lower bar than many compliance teams had assumed.


What Changed — and What Didn’t

The June 2026 guidance introduces meaningful operational changes alongside the fraud extension. Understanding both matters.

What’s new:

AreaPrevious GuidanceJune 2026 Update
Fraud coverageAmbiguous — technically AML-focusedExplicit: fraud is covered, including pig butchering, romance scams, mule accounts
Real-time sharingPermitted but not emphasizedExplicitly encouraged; “including in real time” language added throughout
Shareable data typesTransaction records, account informationExpanded to: video surveillance footage, IP addresses, device data, cyber-related data, adverse media
Sharing formatNot specified clearlyCan be verbal, written, or electronic
Recipient-transaction linkRequired in prior interpretationsNot required: information need not relate to a transaction of the receiving institution

What didn’t change:

  • Registration is still required and still voluntary — institutions must register with FinCEN to participate
  • The SAR wall remains: you cannot share a SAR or reveal that one has been filed
  • The safe harbor does not extend to information shared in bad faith or outside program requirements
  • Participating institutions are still bound by their own data handling and security obligations for 314(b) information received

The SAR Wall — and What It Doesn’t Protect

This distinction trips up compliance teams more than any other part of the program.

You cannot share a Suspicious Activity Report. You cannot tell another institution that you have filed a SAR. This is a hard statutory rule under 31 U.S.C. § 5318(g)(2), and it applies even in 314(b) sharing.

But the underlying facts that went into the SAR? Those are not protected.

If your transaction monitoring identified that account 7890 sent seventeen wires to seven different receiving institutions in forty-eight hours, each just below $10,000, and your blockchain analytics team traced the destination addresses to a known pig butchering network — you can share all of that. The transaction dates, amounts, routing, account characteristics, device fingerprints, IP addresses used during session activity, and the network attribution. You can share it in real time, electronically, with any institution registered in the 314(b) program.

You just can’t say “we also filed a SAR.”

The practical result is that the SAR wall, while real, protects less than it might appear. The analytical intelligence your team develops in the course of suspicious activity review — the substance of what makes the activity suspicious — is shareable. The formal designation of that conclusion is not.


The Fraud Types This Is Actually Built For

FinCEN’s June 2026 Fact Sheet names three fraud types because they’re exactly the scenarios where information fragmentation lets criminals move faster than compliance can respond.

Pig butchering / investment fraud: Victims are groomed over weeks or months before being convinced to send funds to fraudulent crypto investment platforms. The outgoing wires look like ordinary customer transfers at the originating institution. The receiving accounts — often mule accounts — look like ordinary customer activity. Only by sharing intelligence across institutions do the patterns emerge. By the time any one institution identifies the scheme, the funds have moved across four or five institutions to a crypto off-ramp.

Romance scams: Structurally similar to pig butchering, but often using established relationship patterns as the social engineering vector. The FBI’s 2024 Internet Crime Report documented $2.9 billion in romance scam losses — predominantly elderly victims, predominantly wire and crypto transfers. The victim’s financial institution sees a customer sending a series of wires to someone they’ve never met; real-time intelligence from the receiving institution about the destination account’s activity profile could trigger intervention before the transfer completes.

Mule account activity: Money mule networks use recruited or unknowing individuals to receive and forward criminal proceeds. Spotting a mule account requires seeing patterns across institutions — a series of small inbound wires from multiple sources, followed by immediate outbound transfers, is classic mule activity that’s nearly invisible from a single institution’s transaction view. Sharing in real time about suspicious high-velocity activity in receiving accounts lets originating institutions catch transfers before they clear.

The common thread: these schemes exploit the fact that each institution sees only its slice of the transaction chain, and traditional SAR filings reach law enforcement after the money moves. Real-time 314(b) sharing intercepts the transfer.


How to Actually Use It

If your institution isn’t registered in the 314(b) program, registration is the first step and it costs nothing. Both the OCC (Bulletin 2026-30) and FDIC (FIL-2026) have issued guidance explicitly encouraging institutions to register.

Once registered, here’s what an operational 314(b) fraud workflow looks like:

Step 1: Trigger identification. Your transaction monitoring or fraud detection system identifies activity that may involve fraud — unusual outgoing wire patterns, rapid fund forwarding, mule account indicators. This does not require a full SAR determination; suspicion is sufficient.

Step 2: Determine whether 314(b) sharing would add intelligence. The relevant question is: would another institution’s knowledge about the destination account, the counterparties, or related accounts help you assess or stop the activity? For most fraud schemes involving multiple financial institutions, the answer is yes.

Step 3: Identify receiving institutions. Check whether destination financial institutions are registered 314(b) participants. FinCEN maintains the participant database.

Step 4: Share — in real time if the situation warrants it. The June 2026 guidance is explicit that real-time verbal or electronic sharing is permitted. For an active transfer, a phone call to the receiving institution’s BSA team about a wire that just left your institution is a legitimate use of 314(b).

Step 5: Document the sharing and the response. Keep records of what you shared, when, with whom, and what (if any) information you received in return. This creates the audit trail for your BSA/AML program and supports any subsequent SAR filing.


What 314(b) Participation Looks Like in an Examiner Review

The OCC and FDIC have both issued guidance encouraging 314(b) participation — which means examiners are aware of whether your institution is registered and whether the program is being used.

The examiner question isn’t just “are you registered?” It’s “show me your 314(b) activity log.” An institution registered since 2015 with zero 314(b) sharing events signals that the program exists on paper but isn’t integrated into actual fraud response or AML operations.

Registration plus zero use is not the goal. The goal is registration plus an operational workflow that routes appropriate fraud intelligence through the 314(b) channel — documented, trained, and tested in your BSA/AML program.

For your AML/fraud program’s key risk indicators, 314(b) participation metrics are worth tracking: how many sharing events per quarter, what information types, how many inbound requests processed, and whether real-time sharing has been operationalized for high-velocity fraud scenarios. The KRI Library’s BSA/AML-specific indicators include transaction monitoring alert rates and SAR filing volumes — 314(b) usage rounds out the fraud response picture.


So What?

The June 2026 update to Section 314(b) doesn’t create new legal powers — it removes an ambiguity that had kept compliance teams from using existing powers for fraud. The practical change is significant: financial institutions now have an unambiguous, liability-protected channel to share fraud intelligence in real time, with any other registered institution, across every format including video and device data.

The fraud schemes that FinCEN explicitly calls out — pig butchering, romance scams, mule accounts — are also the schemes your fraud team is losing to right now. They move faster than SAR filings reach law enforcement. Real-time 314(b) sharing is the mechanism that can match the speed.

If your institution isn’t registered, registration takes a form submission. If your institution is registered but 314(b) is treated as an AML-only checkbox, the June 2026 guidance is your reason to rebuild that workflow. If your institution already has an active 314(b) program, the fraud extension and real-time guidance expand the scope of what you can share — which means updating your sharing procedures, training, and documentation to reflect what’s now explicitly permitted.

The tool is there. The question is whether your compliance program is set up to use it.


Internal Resources


External Sources

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did FinCEN's June 2026 update to Section 314(b) actually change?
FinCEN released an updated Section 314(b) Fact Sheet on June 12, 2026, replacing its December 2020 version. The key change is explicit: the safe harbor under Section 314(b) of the USA PATRIOT Act now covers suspected fraud, not just money laundering and terrorist financing. The update also provides new guidance on real-time sharing, expands the types of information institutions can share (including video surveillance, IP addresses, device data, and adverse media), and clarifies that institutions don't need to identify specific fraud proceeds being laundered — they only need to suspect fraud-related activity.
What types of fraud does the updated 314(b) guidance cover?
FinCEN's June 2026 Fact Sheet explicitly names pig butchering scams, romance scams, and mule account activity as within scope of the 314(b) safe harbor. More broadly, the guidance covers any fraud that constitutes a Specified Unlawful Activity (SUA) under 18 U.S.C. § 1956 — the money laundering statute. Most wire fraud, bank fraud, securities fraud, and elder financial fraud falls within SUA definitions, making 314(b) a broader fraud-fighting tool than most compliance teams have historically used it.
What information can a financial institution share under 314(b)?
Participating institutions can share transaction records, device data (device fingerprints, hardware identifiers), IP addresses and other cyber-related data, video surveillance footage, adverse media, and any other information relevant to identifying or reporting suspected fraud, money laundering, or terrorist financing. The information can be shared verbally, in writing, or through electronic platforms — including in real time. Critically, the information does not need to relate to a transaction of the receiving institution; you can share intelligence about a fraud network you've identified even if the receiving institution has no existing transaction with the subject.
What can't you share under 314(b)?
The hard limit: you cannot share a Suspicious Activity Report (SAR) or reveal that a SAR exists. This is a statutory requirement under 31 U.S.C. § 5318(g)(2). But here's the critical distinction — the underlying facts a SAR is based on are not protected by this rule. If you've identified that account 12345 is routing funds through a set of accounts your analytics flagged as a pig butchering network, you can share those transaction facts, account relationships, and IP patterns with other 314(b) participants. You just can't say 'we filed a SAR on this.'
How do you register to participate in the 314(b) program?
Registration is voluntary and free. Institutions submit a registration form to FinCEN at fincen.gov. Participation is open to depository institutions, broker-dealers, mutual funds, insurance companies, money services businesses, and loan and finance companies. Once registered, institutions can share information with any other registered participant. FinCEN maintains a database of registered participants. OCC Bulletin 2026-30 and FDIC FIL-2026 both explicitly encourage institutions that haven't registered to do so.
Is there liability protection for information shared under 314(b)?
Yes — the Section 314(b) safe harbor provides protection from liability under any law or regulation of the United States, any state or local law, and GLBA Regulation P's information-sharing restrictions, for disclosures made in good faith and in compliance with the rule. This protects institutions from both civil and regulatory liability for sharing information they reasonably believed was relevant to identifying or reporting fraud, money laundering, or terrorist financing. The protection applies even if the subject of the information is later determined to be uninvolved.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

KRI Library (132 Key Risk Indicators)

132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.