Breaking Regulatory Compliance
SEC's $64 Million Croft & Frost Offering Fraud Case: The Warning Email Compliance Teams Cannot Ignore
The SEC's $64 million Croft & Frost offering fraud case shows how ignored warnings, sales incentives, and weak escalation controls compound losses.
Table of Contents
TL;DR
- The SEC alleges Paul Croft and Jonathan Frost raised approximately $64 million from more than 230 investors through promissory notes and LLC interests, then used at least $53 million contrary to what investors were told.
- The sharpest compliance fact is not the luxury spending. It is the allegation that salesperson Matthew Dira kept selling after a September 13, 2022 email warned that new investor money was likely paying earlier investors.
- This is a complaint, not a final judgment. Frost has separately pleaded guilty in a parallel federal criminal case, while the SEC’s claims against the three defendants remain allegations unless proven or admitted.
- Compliance teams should test four things now: warning intake, authority to stop sales, compensation-to-registration mapping, and independent use-of-proceeds reconciliation.
The SEC’s Croft and Frost offering fraud case has a fact every CCO should put in front of the sales-supervision team: a warning allegedly arrived in writing, and the selling continued.
On September 11, 2026, the Securities and Exchange Commission filed a civil complaint against Paul Thomas Croft, Jonathan David Frost, and Matthew William Dira in the Eastern District of Tennessee. The SEC litigation release says Croft and Frost raised approximately $64 million from more than 230 investors between January 2021 and September 2023. They allegedly sold promissory notes and membership interests in four LLCs while describing profit-making uses such as real estate, small-business lending, housing projects, and hydrogen-power development.
According to the SEC’s complaint, at least $53 million went somewhere else.
The SEC has not called that $64 million a penalty. It is the amount allegedly raised. The requested relief includes injunctions, disgorgement with prejudgment interest, and civil penalties, with amounts still to be determined. That distinction matters: a complaint describes allegations, not adjudicated facts.
What the SEC alleges happened to the $64 million
The alleged flow of funds is blunt enough to read like a control-testing script.
| SEC allegation | Approximate amount | Control question it creates |
|---|---|---|
| Total raised from more than 230 investors | $64 million | Did onboarding confirm the offering, seller, and claimed business purpose? |
| Used contrary to represented purposes | At least $53 million | Did anyone reconcile bank activity to offering documents? |
| Transferred to Croft & Frost, PLLC, the accounting and tax business | Nearly $33 million | Were intercompany transfers approved and independently reviewed? |
| Used for Croft and Frost’s direct personal benefit | About $11 million | Did transaction monitoring distinguish business expenses from owner spending? |
| Used for Ponzi-style payments to earlier investors | About $10 million | Were investor payouts tested against documented earnings or asset sales? |
| Owed to investors when the operation collapsed | About $53 million | Was liability reporting independently verified? |
| Dira’s alleged salary and commissions | At least $500,000 | Was compensation mapped to licensing, conflicts, and sales activity? |
The complaint says the money supported payroll and loan repayments as well as residences, luxury vehicles, private flights, yacht charters, jewelry, and custom suits. Those details will draw headlines. For a risk team, the more useful question is how nearly $33 million could allegedly move into a related tax business without a documented use-of-proceeds exception shutting down additional fundraising.
That is where paper programs fail. An offering memorandum can restrict the use of proceeds, and an approval matrix can require sign-off, but neither matters if nobody compares actual cash movement to the representation. The preventive control is not “finance reviews transfers.” It is a monthly reconciliation in which a controller who does not initiate payments maps material disbursements to an approved purpose, attaches bank evidence, identifies exceptions, and sends unresolved exceptions to Compliance and Legal before the next sale.
The warning email is the real enforcement lesson
The SEC alleges Dira acted as a securities salesperson and administrator, maintained investor records, and managed and trained other sales personnel. It also alleges he continued selling after receiving communications that warned Croft and Frost were likely using new investor money to pay previous investors.
The complaint identifies a September 13, 2022 warning email. It further alleges Dira received $235,732 in compensation after that warning, part of at least $500,000 in salary and commissions during the broader period.
That sequence changes the control analysis. Before a credible warning, a firm may be dealing with a diligence failure. After a credible warning, continuing to solicit investors becomes an escalation, investigation, and stop-activity problem.
A usable warning protocol needs decisions, not just an inbox:
- Capture. Employees must forward allegations involving misuse of funds, false statements, unregistered sales, or circular investor payments to a monitored channel. The case record should preserve the original communication and metadata.
- Triage. Compliance or Legal should classify the allegation within a defined service level based on investor harm and ongoing sales activity. A next-business-day review is a reasonable internal starting point for allegations of active misuse, but firms should calibrate timing to their products, volume, and regulatory obligations.
- Contain. A named role—usually the CCO, General Counsel, or their documented delegate—must have authority to pause solicitations, commissions, disbursements, and marketing while facts are tested.
- Investigate. Review bank records, offering materials, investor communications, compensation data, and prior complaints. Interview the people who can explain the money flow, but do not let the business owner define the scope alone.
- Decide and document. Record who decided whether sales could resume, what evidence supported that decision, which corrective actions were opened, and who independently validated closure.
The messy part is containment. Sales will argue that a pause harms legitimate investors or kills a transaction. Finance may say the transfers were temporary. The founder may call the warning disgruntled-employee noise. That is precisely why authority and criteria must be written before the urgent case arrives.
If a warning can be closed by the same executive whose revenue depends on continued sales, the escalation process is decorative.
The broker-registration issue hiding inside the compensation data
The SEC charges Dira with offering-fraud and broker-registration violations. The complaint alleges he solicited and sold millions of dollars in promissory notes and LLC interests while receiving substantial compensation.
The SEC’s current broker-dealer resource for small businesses identifies several activities that may indicate someone is acting as a broker: soliciting investors, participating in important parts of a transaction, handling securities or funds, engaging in the business of facilitating purchases and sales, and receiving compensation based on transaction outcome or size. Registration analysis is fact-specific, and an issuer or salesperson should get legal advice rather than treating any one factor as a safe harbor.
For compliance teams, that means a spreadsheet of licenses is not enough. Build a person-to-activity map:
| Field | Evidence to retain | Owner |
|---|---|---|
| Person and employing entity | HR file, contract, organization chart | HR / Legal |
| Securities-related activities | Scripts, emails, call recordings, meeting notes | Sales Supervision |
| Products or offerings discussed | Approved product list and offering documents | Compliance |
| Compensation method | Payroll record, commission schedule, referral agreement | Finance |
| Registration or exemption analysis | Dated legal memorandum with factual assumptions | Legal |
| Supervisory approval and monitoring | Approval record, sample review, exception log | CCO |
The common miss is factual drift. Legal approves an arrangement based on a person making introductions for a flat fee. Six months later, that person is pitching returns, answering investor objections, and receiving more money as fundraising rises. The old memo remains in the file, but its assumptions no longer describe the job.
Quarterly certification alone will not catch that. Pair the certification with data: commission payments, CRM activity, investor-facing email terms, calendar invites, and transfers from offering entities. Where registered broker-dealers are involved, FINRA Rule 3110 requires a supervisory system reasonably designed to achieve compliance with applicable securities laws and FINRA rules. Firms outside FINRA membership still need controls appropriate to their actual securities activity and legal obligations.
For a related example of compensation creating registration and conflict problems, see the SEC’s Ortiz and DaveGlo case. The operational lesson is also close to the Hidden Wealth Radio outside-business-activity case: disclosures are only useful when someone verifies the activity behind them.
Why promissory notes deserve their own surveillance rule
Promissory notes sound familiar. That familiarity can lower skepticism, especially when the seller already prepares a customer’s taxes, sells insurance, or has another trusted professional relationship.
Promissory notes can be legitimate, but the product name says nothing about whether proceeds are being used as represented. In the Croft and Frost complaint, investors allegedly came from existing tax clients, insurance clients, and referrals.
A risk-based review should therefore look beyond the product label. A realistic surveillance rule could flag clusters where:
- multiple customers send funds to the same newly formed LLC;
- memo fields reference “note,” “investment,” “ROI,” or fixed returns;
- the receiving entity rapidly transfers money to an affiliated operating company;
- investor payments occur shortly after new deposits rather than documented operating revenue; or
- a salesperson’s compensation rises with inbound investor funds.
Those are proposed control scenarios, not universal regulatory thresholds. Calibrate them against at least several months of internal transaction history, document expected false positives, and test for evasion through renamed entities or split transfers. The evidence artifact is a scenario inventory showing logic, data lineage, alert disposition, and periodic tuning approval.
A 30/60/90-day response plan
Days 1–30: prove warnings cannot disappear
The CCO should sample the last six months of ethics reports, complaint emails, legal escalations, and manager-raised concerns. Reconcile them to the case-management system. Every credible allegation should have an owner, date, severity, decision, evidence, and closure approval.
Then run a tabletop: “An employee says investor returns are being funded with new investor deposits while sales remain open.” Confirm who can pause sales and payments, how quickly that person is reached, and what evidence is required before activity resumes.
Days 31–60: map people, products, and pay
Legal, Compliance, HR, and Finance should inventory everyone who finds investors, discusses offerings, handles subscription materials, or receives referral or sales-linked compensation. Validate actual activity through samples rather than relying only on job titles and attestations.
Open issues for missing or stale registration analyses. If an analysis depends on limited activity, encode that limit in procedures and monitoring. “Introductions only” should be testable against communications and CRM records.
Days 61–90: test the money against the promise
Finance should select material offering disbursements and reconcile them to authorized uses. Compliance should independently review exceptions, related-party transfers, investor-payment sources, and unsupported business-purpose descriptions.
Report results to the appropriate risk or audit committee in numbers: population tested, exceptions, dollars affected, ongoing sales paused, issues opened, and closure validation due dates. Do not reduce the report to “no material concerns” without showing the work.
Five checks for Monday morning
- Search open complaint and ethics cases for “new money,” “paying old investors,” “guaranteed return,” “misuse of funds,” and “unregistered.”
- Identify every role receiving referral fees, commissions, overrides, or offering-linked bonuses.
- Confirm the CCO or General Counsel can pause sales without business-owner approval.
- Reconcile a sample of related-party transfers to written use-of-proceeds authority.
- Verify that closed high-severity warnings include independent closure evidence—not only management’s explanation.
Frost’s exposure is not limited to the SEC complaint. The Department of Justice announced that he pleaded guilty on February 11, 2026 to conspiracy to commit wire fraud, conspiracy to commit money laundering, and conspiracy to defraud the United States in a parallel criminal matter. The DOJ said the plea agreement involved money solicited for a solar-powered hydrogen facility and a monetary judgment of not less than $70 million. The SEC’s civil allegations against Croft, Frost, and Dira should still be described on their own procedural footing.
The practical takeaway is narrower and more useful than “fraud is bad.” When a written warning alleges that investor payments depend on new investor cash, somebody must own the decision to stop activity. If your system cannot show the warning, the pause decision, the investigation evidence, and independent closure, it cannot show that the control worked.
Use the Issues Management Tracker & Template to turn warnings and control exceptions into assigned, evidenced remediation—not another email thread that disappears when revenue pushes back.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What does the SEC allege in the Croft and Frost offering fraud case?
What is Matthew Dira accused of doing?
Why does transaction-based compensation create broker-dealer registration risk?
What controls should firms test after the Croft and Frost SEC case?
Did the SEC impose a $64 million fine in this case?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
● Don't wait for your own enforcement action
Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Regulatory Compliance
Treasury Just Added 27 Iranian Airlines to the SDN List. What Operation Economic Outcast Means for Your Sanctions Screening Program.
On September 8, 2026, OFAC designated 27 Iranian commercial airlines and 36 supporting entities under Operation Economic Outcast, targeting Iran's aviation procurement networks. FinCEN simultaneously issued Alert FIN-2026-Alert006. Here's what financial institutions need to update in their screening programs right now.
Sep 14, 2026
Regulatory Compliance
The DOJ Tried to Exit a Redlining Consent Order Two Years Early. A Federal Judge Said No. Here's What That Means for Your Compliance Program.
When Provident Financial Services acquired Lakeland Bank, it inherited a 2022 redlining consent order. The Trump administration DOJ then tried to terminate it early. A federal judge rejected the motion on July 31, 2026 — ruling that future compliance promises don't satisfy current obligations. Here's what every bank compliance team needs to learn from this.
Sep 13, 2026
Regulatory Compliance
SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test
The SEC's Doximity insider trading judgment exposes two MNPI control tests: earnings access and post-termination trading.
Sep 11, 2026