Feature Compliance Strategy
46 State AGs Just Settled with Cash App for $45 Million. Here's What Your Fraud Disclosure, KYC Design, and Customer Support Look Like Under That Lens.
On July 8, 2026, a bipartisan coalition of 46 state attorneys general announced a $45M settlement with Block Inc. over Cash App's fraud disclosure failures, identity verification gaps that enabled fraudsters, and the absence of any official customer support phone number. Combined with the January 2025 CFPB order, Block paid $220M in 18 months. Here's what that enforcement record means for your compliance program.
Table of Contents
TL;DR
- On July 8, 2026, a bipartisan coalition of 46 state AGs announced a $45M settlement with Block (Cash App) — the largest coordinated state-level consumer-fintech enforcement action of 2026
- The states’ allegations center on three failures: fake “bank-like safety” advertising, account opening with minimal identity verification that enabled fraudsters, and no official phone support that drove users to call scammer-operated fake numbers
- Combined with the January 2025 CFPB $175M order, Block paid approximately $220M in enforcement actions in 18 months
- The bipartisan coalition (Oregon + Texas AGs co-leading) demonstrates that consumer fintech enforcement is state-level, coordinated, and not waiting for federal CFPB priorities to align
- The specific failure modes here — KYC design, advertising accuracy, customer support access — are compliance design decisions, not just operational gaps
$220 Million Is a Compliance Program Post-Mortem
On July 8, 2026, the attorneys general of 46 states announced that Block, Inc. — the parent company of Cash App — had agreed to a $45 million settlement over allegations that the product misled consumers about its safety, enabled fraudster accounts through minimal identity verification, and left consumers with nowhere legitimate to call when things went wrong.
It was the largest coordinated state-level consumer-fintech enforcement action of 2026. And it came less than 18 months after the CFPB issued its own $175 million enforcement order against the same company for a related but distinct set of failures — Regulation E error resolution breakdowns detailed in our earlier analysis.
The combined enforcement record: $220 million in 18 months. Block denied wrongdoing in both settlements.
The question for every fintech compliance professional reading this isn’t “how did Block get here?” It’s “which of these failure modes exists in my compliance program right now?”
What the CFPB Found (And What You Already Know)
The January 2025 CFPB enforcement action against Block was primarily a Regulation E case. The bureau found that Cash App had systematically failed to investigate unauthorized transfer claims properly — relying on chargeback processes instead of running Reg E error resolution; failing to send required written denial findings to consumers; and failing to maintain the mandatory two-year documentation retention. The total: $55M civil penalty, $120M in consumer redress.
If that enforcement angle is familiar, it’s because it fits a well-established pattern. For background on the specific Reg E investigation process requirements the CFPB focused on, see our detailed breakdown of the CFPB consent order.
The state AG settlement announced in July is different. It’s not primarily about how Cash App handled fraud claims after they were reported. It’s about the product design choices that created the fraud environment in the first place.
What 46 States Found: The Three Failure Modes
The state AGs, led jointly by Oregon AG Dan Rayfield and Texas AG Ken Paxton, alleged that Cash App’s consumer protection failures fell into three categories.
1. “Bank-Like Safety” Advertising That Wasn’t True
Cash App’s marketing implied it offered fraud detection and account protections comparable to a bank. The states alleged this was false — the actual product provided materially weaker consumer protections than a traditional deposit account.
This is a UDAP/UDAAP violation at the advertising layer: the product didn’t deliver what the marketing promised. It follows a pattern regulators are consistently applying to fintech consumer products — if your marketing says “safe” and your product isn’t, the gap is the violation, not just the outcome.
Practitioners who lived through the CFPB’s 2025-2026 enforcement focus on fintech lending disclosures will recognize the pattern. The product your marketing describes and the product your engineering team built need to be the same product. Legal and compliance review of consumer-facing marketing isn’t optional — it’s where the UDAAP exposure lives.
2. Account Opening Without SSN or Date of Birth — Which Enabled Fraud at Scale
This is the finding that should get the most attention from compliance program designers.
Cash App allowed users to open accounts with minimal identity verification — without requiring a Social Security number or date of birth. The states alleged that this design choice made it easy for fraudsters to create fake accounts, which they used to receive scam proceeds and disappear.
The AGs did not allege that Cash App had no identity verification at all. The allegation was that the verification requirements were too minimal to prevent the creation of fraudulent accounts at scale.
This is a consumer protection framing of a KYC design question. The standard is not just: “Did we comply with BSA/AML minimum CIP requirements?” The standard is also: “Does our KYC design prevent bad actors from creating accounts that harm consumers?”
For compliance programs, this creates a design review obligation that’s broader than BSA compliance:
- What are the minimum data elements required to open an account?
- Does that minimum prevent fraudster account creation at scale, or just check a BSA box?
- Do you have a mechanism to detect accounts opened with fabricated or stolen identity data?
The Zelle ruling from July 21, 2026 raised a similar point — that Early Warning Services had shelved anti-fraud controls it had already designed. The Cash App settlement is the earlier version of that story: the company’s account opening design didn’t include controls that were reasonably available. In both cases, the enforcement theory is that the platform made an affirmative choice that created consumer harm.
3. No Official Phone Number — Which Drove Consumers to Call Scammers
This is the finding most likely to generate defensiveness among fintech operators: “We don’t have a phone support line because phone support doesn’t scale.”
Cash App had no official customer service telephone number. When consumers who were locked out of their accounts or had been defrauded searched for help, they found phone numbers operated by scammers posing as Cash App support. Those consumers called scammers. More money was lost.
The states alleged that Cash App’s failure to provide official phone support — combined with its failure to warn users that fake support numbers existed — was itself a consumer protection violation. Block created a vacuum and the vacuum was immediately filled by fraudsters.
As part of the settlement, Block is now required to provide 24-hour telephone support specifically for fraud complaints. That requirement — call it a regulatory mandate for live phone support — is now a consent judgment obligation for a product that previously avoided it entirely.
For fintech compliance programs: “how do we handle fraud disputes and account recovery?” is a consumer protection design question, not just a customer experience decision. The absence of accessible support channels, when consumers have nowhere else to turn, will be evaluated as a consumer harm factor.
The Bipartisan State Model Is the New Normal
The settlement was co-led by Oregon AG Dan Rayfield, a Democrat, and Texas AG Ken Paxton, a Republican. A 46-state bipartisan coalition is nearly impossible to attribute to partisan regulatory politics.
This matters because the enforcement landscape since the CFPB’s 2025 pullback has sometimes been characterized as primarily a blue-state phenomenon. The Cash App settlement breaks that framing. When consumer-facing fraud protection failures are the issue, state AGs across the political spectrum align.
The practical implication: fintechs that assumed state enforcement would be concentrated in California, New York, and a handful of progressive states are now calibrating against a 46-state model. That is effectively national enforcement — reached through state coordination rather than a single federal agency, but producing the same national settlement standard.
What to Audit in Your Compliance Program Now
The Cash App enforcement record covers the full arc of consumer product risk — from account opening (state AG settlement) through fraud dispute handling (CFPB Reg E order) through account closure (the separate Chime consent order for delayed refunds). Every phase has an enforcement case.
A compliance program that hasn’t reviewed each phase specifically is carrying exposure you can quantify:
| Phase | Enforcement Action | What Was Missing |
|---|---|---|
| Account opening | 46-state AG settlement ($45M) | Identity verification, fraud disclosure, customer support |
| During account / dispute | CFPB consent order ($175M) | Reg E investigation process, written denial findings, 2-year retention |
| Account closure | Chime CFPB consent order ($3.25M) | Timely refund processing, 14-day policy adherence |
Five controls to audit now:
1. Marketing and advertising review process. Does your legal/compliance team review consumer-facing marketing before it goes live — specifically testing whether what the marketing says matches what the product delivers? “Safe,” “protected,” “bank-like” language needs a defensibility review, not just a brand approval.
2. Account opening data requirements. What data elements does your onboarding collect? Is it the four BSA/CIP minimum elements (name, DOB, address, TIN) — or less? Is there a minimum set below which accounts won’t be opened? Is that documented as a policy?
3. Fraud complaint intake and channel. When a consumer is defrauded using your product, what’s their path to reporting it? If the answer is “submit a ticket online,” has your compliance team evaluated whether that’s the appropriate channel for fraud — or whether absence of accessible support creates consumer harm?
4. Error resolution documentation. For any product that handles electronic funds transfers, does your dispute resolution process produce written findings, meet the 10-business-day investigation window, and retain documentation for two years? The Reg E requirements exist whether or not the CFPB is actively examining you.
5. Account closure refund process. What’s your documented timeline for returning balances after account closure? Is it a policy that’s actually followed — and is there a monitoring mechanism that would catch cases where the policy is breached at scale?
If any of these five questions produces “I’m not sure,” you have an audit item. The Issues Management Tracker is built for exactly this kind of systematic finding documentation — tracking the gap, the owner, the remediation plan, and the closure evidence so you’re not managing it in someone’s inbox.
So What?
Block paid $220 million for compliance failures that were visible, avoidable, and — in most cases — documented internally before the enforcement actions started. The Zelle case record suggests Early Warning Services had designed the controls but didn’t deploy them. The Cash App record suggests the identity verification and customer support issues were known product design choices.
The state enforcement model is now 46 states, bipartisan, and looking at the same three categories: what did your marketing promise, what did your product design enable, and what happened when consumers needed help?
None of these are surprise enforcement theories. They’re the UDAP standards that have existed for decades, applied to fintech product design decisions. Build the compliance review into the design process — not as a remediation step after the settlement.
Sources: TechCrunch: Block reaches $45M settlement with 46 states | CFPB: Cash App $175M Order | Oregon AG Press Release | PYMNTS: Block Pays $45 Million to Settle 46-State Probe
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the 46 state AGs allege against Cash App in the July 2026 settlement?
What is the total amount Block has paid in enforcement actions related to Cash App?
What reforms did the state AG settlement require Cash App to make?
Why is the bipartisan composition of the state AG coalition significant?
What specific identity verification practices did the states find problematic?
What happened with Chime's parallel CFPB enforcement action?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Compliance Strategy
Bank Holding Company Source-of-Strength: What Fintechs Getting Bank Charters Haven't Accounted For
When a fintech gets a bank charter and forms a bank holding company, it inherits the source-of-strength obligation — a capital backstop requirement most fintech BHC playbooks don't address. The TS Banking Group July 2026 written agreement shows what happens when this surfaces at exam time.
Jul 30, 2026
Compliance Strategy
Federal Reserve Regulation O Proposal: Rebuild the Control Logic, Not Just the Limits
The 2026 Regulation O proposal raises insider-lending thresholds and changes passive-fund treatment. Here is the bank control impact.
Jul 30, 2026
Compliance Strategy
The House CFPB Reform Discussion Draft: What the $21B Supervisory Threshold and Congressional Appropriations Proposal Mean for Your Compliance Program
On July 24, 2026, the House Financial Services Committee published a 70-page CFPB restructuring draft. Here's what's in the five titles, what the $21B threshold change actually affects, and why the compliance programs that survive any version of this are built around legal obligations — not exam schedules.
Jul 28, 2026