Skip to content
RiskTemplates · The Daily Brief Monday, August 3, 2026
Wire The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs JUL 30

Feature Compliance Strategy

46 State AGs Just Settled with Cash App for $45 Million. Here's What Your Fraud Disclosure, KYC Design, and Customer Support Look Like Under That Lens.

On July 8, 2026, a bipartisan coalition of 46 state attorneys general announced a $45M settlement with Block Inc. over Cash App's fraud disclosure failures, identity verification gaps that enabled fraudsters, and the absence of any official customer support phone number. Combined with the January 2025 CFPB order, Block paid $220M in 18 months. Here's what that enforcement record means for your compliance program.

By Rebecca Leung · August 2, 2026 ·
Table of Contents

TL;DR

  • On July 8, 2026, a bipartisan coalition of 46 state AGs announced a $45M settlement with Block (Cash App) — the largest coordinated state-level consumer-fintech enforcement action of 2026
  • The states’ allegations center on three failures: fake “bank-like safety” advertising, account opening with minimal identity verification that enabled fraudsters, and no official phone support that drove users to call scammer-operated fake numbers
  • Combined with the January 2025 CFPB $175M order, Block paid approximately $220M in enforcement actions in 18 months
  • The bipartisan coalition (Oregon + Texas AGs co-leading) demonstrates that consumer fintech enforcement is state-level, coordinated, and not waiting for federal CFPB priorities to align
  • The specific failure modes here — KYC design, advertising accuracy, customer support access — are compliance design decisions, not just operational gaps

$220 Million Is a Compliance Program Post-Mortem

On July 8, 2026, the attorneys general of 46 states announced that Block, Inc. — the parent company of Cash App — had agreed to a $45 million settlement over allegations that the product misled consumers about its safety, enabled fraudster accounts through minimal identity verification, and left consumers with nowhere legitimate to call when things went wrong.

It was the largest coordinated state-level consumer-fintech enforcement action of 2026. And it came less than 18 months after the CFPB issued its own $175 million enforcement order against the same company for a related but distinct set of failures — Regulation E error resolution breakdowns detailed in our earlier analysis.

The combined enforcement record: $220 million in 18 months. Block denied wrongdoing in both settlements.

The question for every fintech compliance professional reading this isn’t “how did Block get here?” It’s “which of these failure modes exists in my compliance program right now?”

What the CFPB Found (And What You Already Know)

The January 2025 CFPB enforcement action against Block was primarily a Regulation E case. The bureau found that Cash App had systematically failed to investigate unauthorized transfer claims properly — relying on chargeback processes instead of running Reg E error resolution; failing to send required written denial findings to consumers; and failing to maintain the mandatory two-year documentation retention. The total: $55M civil penalty, $120M in consumer redress.

If that enforcement angle is familiar, it’s because it fits a well-established pattern. For background on the specific Reg E investigation process requirements the CFPB focused on, see our detailed breakdown of the CFPB consent order.

The state AG settlement announced in July is different. It’s not primarily about how Cash App handled fraud claims after they were reported. It’s about the product design choices that created the fraud environment in the first place.

What 46 States Found: The Three Failure Modes

The state AGs, led jointly by Oregon AG Dan Rayfield and Texas AG Ken Paxton, alleged that Cash App’s consumer protection failures fell into three categories.

1. “Bank-Like Safety” Advertising That Wasn’t True

Cash App’s marketing implied it offered fraud detection and account protections comparable to a bank. The states alleged this was false — the actual product provided materially weaker consumer protections than a traditional deposit account.

This is a UDAP/UDAAP violation at the advertising layer: the product didn’t deliver what the marketing promised. It follows a pattern regulators are consistently applying to fintech consumer products — if your marketing says “safe” and your product isn’t, the gap is the violation, not just the outcome.

Practitioners who lived through the CFPB’s 2025-2026 enforcement focus on fintech lending disclosures will recognize the pattern. The product your marketing describes and the product your engineering team built need to be the same product. Legal and compliance review of consumer-facing marketing isn’t optional — it’s where the UDAAP exposure lives.

2. Account Opening Without SSN or Date of Birth — Which Enabled Fraud at Scale

This is the finding that should get the most attention from compliance program designers.

Cash App allowed users to open accounts with minimal identity verification — without requiring a Social Security number or date of birth. The states alleged that this design choice made it easy for fraudsters to create fake accounts, which they used to receive scam proceeds and disappear.

The AGs did not allege that Cash App had no identity verification at all. The allegation was that the verification requirements were too minimal to prevent the creation of fraudulent accounts at scale.

This is a consumer protection framing of a KYC design question. The standard is not just: “Did we comply with BSA/AML minimum CIP requirements?” The standard is also: “Does our KYC design prevent bad actors from creating accounts that harm consumers?”

For compliance programs, this creates a design review obligation that’s broader than BSA compliance:

  • What are the minimum data elements required to open an account?
  • Does that minimum prevent fraudster account creation at scale, or just check a BSA box?
  • Do you have a mechanism to detect accounts opened with fabricated or stolen identity data?

The Zelle ruling from July 21, 2026 raised a similar point — that Early Warning Services had shelved anti-fraud controls it had already designed. The Cash App settlement is the earlier version of that story: the company’s account opening design didn’t include controls that were reasonably available. In both cases, the enforcement theory is that the platform made an affirmative choice that created consumer harm.

3. No Official Phone Number — Which Drove Consumers to Call Scammers

This is the finding most likely to generate defensiveness among fintech operators: “We don’t have a phone support line because phone support doesn’t scale.”

Cash App had no official customer service telephone number. When consumers who were locked out of their accounts or had been defrauded searched for help, they found phone numbers operated by scammers posing as Cash App support. Those consumers called scammers. More money was lost.

The states alleged that Cash App’s failure to provide official phone support — combined with its failure to warn users that fake support numbers existed — was itself a consumer protection violation. Block created a vacuum and the vacuum was immediately filled by fraudsters.

As part of the settlement, Block is now required to provide 24-hour telephone support specifically for fraud complaints. That requirement — call it a regulatory mandate for live phone support — is now a consent judgment obligation for a product that previously avoided it entirely.

For fintech compliance programs: “how do we handle fraud disputes and account recovery?” is a consumer protection design question, not just a customer experience decision. The absence of accessible support channels, when consumers have nowhere else to turn, will be evaluated as a consumer harm factor.

The Bipartisan State Model Is the New Normal

The settlement was co-led by Oregon AG Dan Rayfield, a Democrat, and Texas AG Ken Paxton, a Republican. A 46-state bipartisan coalition is nearly impossible to attribute to partisan regulatory politics.

This matters because the enforcement landscape since the CFPB’s 2025 pullback has sometimes been characterized as primarily a blue-state phenomenon. The Cash App settlement breaks that framing. When consumer-facing fraud protection failures are the issue, state AGs across the political spectrum align.

The practical implication: fintechs that assumed state enforcement would be concentrated in California, New York, and a handful of progressive states are now calibrating against a 46-state model. That is effectively national enforcement — reached through state coordination rather than a single federal agency, but producing the same national settlement standard.

What to Audit in Your Compliance Program Now

The Cash App enforcement record covers the full arc of consumer product risk — from account opening (state AG settlement) through fraud dispute handling (CFPB Reg E order) through account closure (the separate Chime consent order for delayed refunds). Every phase has an enforcement case.

A compliance program that hasn’t reviewed each phase specifically is carrying exposure you can quantify:

PhaseEnforcement ActionWhat Was Missing
Account opening46-state AG settlement ($45M)Identity verification, fraud disclosure, customer support
During account / disputeCFPB consent order ($175M)Reg E investigation process, written denial findings, 2-year retention
Account closureChime CFPB consent order ($3.25M)Timely refund processing, 14-day policy adherence

Five controls to audit now:

1. Marketing and advertising review process. Does your legal/compliance team review consumer-facing marketing before it goes live — specifically testing whether what the marketing says matches what the product delivers? “Safe,” “protected,” “bank-like” language needs a defensibility review, not just a brand approval.

2. Account opening data requirements. What data elements does your onboarding collect? Is it the four BSA/CIP minimum elements (name, DOB, address, TIN) — or less? Is there a minimum set below which accounts won’t be opened? Is that documented as a policy?

3. Fraud complaint intake and channel. When a consumer is defrauded using your product, what’s their path to reporting it? If the answer is “submit a ticket online,” has your compliance team evaluated whether that’s the appropriate channel for fraud — or whether absence of accessible support creates consumer harm?

4. Error resolution documentation. For any product that handles electronic funds transfers, does your dispute resolution process produce written findings, meet the 10-business-day investigation window, and retain documentation for two years? The Reg E requirements exist whether or not the CFPB is actively examining you.

5. Account closure refund process. What’s your documented timeline for returning balances after account closure? Is it a policy that’s actually followed — and is there a monitoring mechanism that would catch cases where the policy is breached at scale?

If any of these five questions produces “I’m not sure,” you have an audit item. The Issues Management Tracker is built for exactly this kind of systematic finding documentation — tracking the gap, the owner, the remediation plan, and the closure evidence so you’re not managing it in someone’s inbox.

So What?

Block paid $220 million for compliance failures that were visible, avoidable, and — in most cases — documented internally before the enforcement actions started. The Zelle case record suggests Early Warning Services had designed the controls but didn’t deploy them. The Cash App record suggests the identity verification and customer support issues were known product design choices.

The state enforcement model is now 46 states, bipartisan, and looking at the same three categories: what did your marketing promise, what did your product design enable, and what happened when consumers needed help?

None of these are surprise enforcement theories. They’re the UDAP standards that have existed for decades, applied to fintech product design decisions. Build the compliance review into the design process — not as a remediation step after the settlement.


Sources: TechCrunch: Block reaches $45M settlement with 46 states | CFPB: Cash App $175M Order | Oregon AG Press Release | PYMNTS: Block Pays $45 Million to Settle 46-State Probe

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the 46 state AGs allege against Cash App in the July 2026 settlement?
The states alleged three core failures: (1) Cash App falsely implied it offered bank-like consumer protections — including fraud detection and account safety — that the product did not actually provide; (2) Cash App's account opening process required minimal identity verification (no Social Security number or date of birth), making it easy for fraudsters to create fake accounts at scale; and (3) Cash App provided no official customer service phone number, so consumers who were locked out of their accounts or defrauded often called fake 'support' numbers operated by scammers. The states argued these failures, taken together, created a deceptive product experience that endangered consumers.
What is the total amount Block has paid in enforcement actions related to Cash App?
Block has paid approximately $220 million in enforcement actions over 18 months: in January 2025, the CFPB ordered Block to pay up to $175 million — $55 million in civil penalties and at least $120 million in consumer refunds — for Regulation E error resolution failures and UDAAP violations. In July 2026, Block agreed to pay $45 million to 46 state attorneys general for fraud disclosure failures and consumer protection violations. Block denied wrongdoing in both settlements.
What reforms did the state AG settlement require Cash App to make?
Under the settlement terms, Block must provide live customer support for the mobile payments platform, including 24-hour telephone support specifically for fraud complaints. The company must also educate consumers about common fraud schemes. These are operational changes, not just financial penalties — they go to the product's customer service infrastructure. Notably, requiring telephone fraud support is effectively a regulatory mandate for a product that had previously operated without any official phone number.
Why is the bipartisan composition of the state AG coalition significant?
The settlement was co-led by Oregon Attorney General Dan Rayfield (Democrat) and Texas Attorney General Ken Paxton (Republican) — a rare bipartisan partnership that produced a 46-state coalition. The bipartisan composition demonstrates that consumer fintech enforcement is not a politically partisan issue at the state level, even if federal CFPB enforcement has fluctuated with administrations. A 46-state coalition is also harder for a company to litigate against simultaneously and signals that the settlement terms reflect a broadly acceptable national standard, not the preferences of a single state.
What specific identity verification practices did the states find problematic?
According to the states' findings, Cash App allowed users to open accounts without providing a Social Security number or date of birth. The states argued this made it easy for fraudsters to create multiple fake accounts — accounts used to receive proceeds from scams and then disappear. The AGs did not allege that Cash App had no identity verification, but rather that the verification requirements were too minimal to prevent mass creation of fraudulent accounts. The implication for compliance programs is that the adequacy of KYC at account opening is evaluated not just against BSA/AML requirements but against the consumer protection standard of whether your design enabled harm at scale.
What happened with Chime's parallel CFPB enforcement action?
In a separate action, the CFPB issued a consent order against Chime Financial for failing to provide consumers with timely refunds after account closure. Chime's policy was to process refund checks within 14 days of account closure; in thousands of instances, Chime took more than 90 days. The CFPB ordered Chime to pay at least $1.3 million in consumer redress and a $3.25 million civil penalty, and placed Chime under a five-year consent order requiring a comprehensive compliance plan. The Chime and Cash App actions together illustrate that consumer protection exposure in fintech runs from account opening (Cash App's KYC) to account closure (Chime's refund delay).
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.