Feature Operational Risk
FTC Just Fined a Payment Processor $12 Million for Sham Merchants. Here's What 'Knowingly Facilitating Fraud' Actually Looks Like.
On September 8, 2026, the FTC filed a proposed $12 million order against Humboldt Merchant Services for processing payments for 1,000+ sham merchant accounts running chargebacks at 10x card network thresholds. This is what payment processor liability looks like—and why it matters for every fintech that routes transactions.
Table of Contents
TL;DR
- On September 8, 2026, the FTC filed a proposed $12 million order against Humboldt Merchant Services (5967 Ventures, LLC) for processing payments for more than 1,000 sham merchant accounts linked to billing fraud schemes
- The merchants ran chargebacks at nearly 10x Mastercard and Visa network thresholds — for extended periods — while Humboldt kept opening new accounts for them
- Humboldt allegedly moved high-chargeback merchants onto lower-risk bank BINs to mask the fraud from card network monitoring
- Settlement includes a lifetime ban on processing for highest-risk merchant categories — the FTC’s standard remedy when a processor has demonstrated it cannot operate safely in a segment
Payment processors like to describe themselves as neutral infrastructure. The FTC’s September 2026 case against Humboldt Merchant Services describes something different: a company that built a business model around opening merchant accounts for fraudulent operators, processed over $100 million in transactions through those accounts, and continued doing so after chargeback data made the fraud undeniable.
The case is one of the clearest articulations of payment processor liability the FTC has produced in years. Whether you’re a fintech running a payment program, a bank that sponsors card processing, or a compliance officer trying to understand what “adequate merchant controls” actually means, the Humboldt case is worth your attention.
What Humboldt Actually Did
According to the FTC’s complaint, Humboldt Merchant Services (operating as 5967 Ventures, LLC) provided payment processing services to more than 1,000 entities that were shell companies — fronts set up to hold merchant accounts on behalf of the actual fraudulent operators running billing scams.
The most significant connection was to Legion Media, a company the FTC separately charged in 2024 with running business impersonation scams. Legion Media and its associated entities created hundreds of shell merchant accounts, moved transaction volume through them, and cycled through new accounts when old ones were terminated or suspended. Humboldt was the processor that kept accepting these accounts.
The numbers in the complaint are stark:
- Chargeback rates of almost 10x network thresholds. Mastercard’s Excessive Chargeback Program triggers at 1.5% chargeback-to-transaction ratio. Visa’s Dispute Monitoring Program triggers at 0.9%. The FTC alleged that Humboldt’s sham merchants were running at rates approaching 10 times these thresholds — for sustained periods — and Humboldt continued processing for them.
- Over $100 million processed. From 2021 through 2023, Humboldt processed more than $100 million through the sham merchant network.
- BIN manipulation. Rather than terminating high-chargeback accounts, the FTC alleged that Humboldt moved them to lower-risk Bank Identification Numbers to reduce the visibility of their chargeback rates to card network monitoring systems.
The FTC’s complaint was filed on September 8, 2026, in the U.S. District Court for the Eastern District of Michigan. The proposed stipulated order was entered September 11, 2026. Humboldt agreed to pay $12 million — the full amount required within seven days of entry — and to permanently stop processing for the highest-risk merchant categories.
The “Knowingly Facilitating” Standard
The Humboldt case turns on the FTC’s theory that a payment processor can be liable under Section 5 of the FTC Act as a facilitator of fraud — even if the processor didn’t design the underlying scheme.
The FTC’s complaint alleges that Humboldt either knew the accounts were sham merchants or “consciously avoided knowing.” This is the willful blindness standard: Humboldt had enough information to recognize the pattern, but took steps (including BIN reassignment) that allowed it to continue processing while avoiding the formal acknowledgment that would have required it to act.
What creates liability at this threshold? The FTC’s complaint points to three categories of evidence:
1. Chargeback rates that were self-evidently anomalous. Card network thresholds exist specifically to identify fraud-adjacent merchants. When chargebacks consistently exceed those thresholds by factors of 5 or 10, the merchant population isn’t suffering from bad luck or poor customer service — it’s running schemes that generate disputes at scale. A processor that sees these ratios month after month and continues processing has crossed from negligent oversight into facilitation.
2. Structural red flags in the merchant profile. Shell companies used as fronts for fraud have characteristic features: thin business history, no online presence, transaction patterns inconsistent with the stated merchant category, rapid volume growth from zero. The FTC’s theory is that Humboldt’s merchant underwriting failed to catch — or chose to ignore — these indicators across more than 1,000 accounts.
3. Active concealment through BIN migration. This is the element that elevates the conduct from negligence to something more serious. Reassigning a high-chargeback merchant to a lower-risk BIN isn’t a mistake — it’s a deliberate action that uses card network infrastructure to reduce the visibility of problematic activity. Processors that do this are not failing to catch fraud; they are taking affirmative steps to preserve the processing relationship after the fraud is apparent.
What Card Network Thresholds Actually Mean for Compliance Programs
The chargeback ratios in the Humboldt case aren’t just FTC enforcement benchmarks. They’re operational trip wires that every payment program should be monitoring in real time.
| Card Network | Program | Trigger Threshold | Action Required |
|---|---|---|---|
| Mastercard | Excessive Chargeback Program (ECP) | 1.5% ratio, 100+ disputes | Enhanced monitoring, potential fines |
| Visa | Dispute Monitoring Program (DMP) | 0.9% monthly | Early warning, remediation plan |
| Mastercard | High Excessive Chargeback (HECM) | 3.0% ratio, 300+ disputes | Immediate remediation program |
| Visa | Excessive Dispute Program (EDP) | 1.8% monthly | Escalated remediation |
Running chargebacks at “nearly 10x” these thresholds means some Humboldt merchants were generating chargeback ratios of 9–15% — ranges that indicate a substantial fraction of every transaction being disputed by cardholders. At those rates, it is not possible to characterize the pattern as merchant error or cardholder confusion. These are indicators of systematic fraud.
For a payment program or fintech routing transactions through an acquirer, the question isn’t whether you’re the FTC’s target — it’s whether you know what your chargeback rates are, by merchant, and whether your program documents what happens when a merchant hits or approaches network thresholds.
Why BIN Management Matters Here
The BIN manipulation allegation deserves specific attention because it reflects a compliance failure mode that isn’t visible in aggregate chargeback data.
Bank Identification Numbers segment transaction volume by risk tier. A merchant placed on a BIN associated with low-risk retail transactions receives different monitoring treatment than one placed on a BIN flagged for high-risk categories. Humboldt allegedly exploited this by transferring high-chargeback merchants from BINs where their activity would trigger network monitoring to BINs where it would not — effectively resetting the network’s view of the merchant’s history.
For sponsor banks and program managers, the implication is that BIN assignment is a compliance decision, not just a technical one. If a payment processor or program partner can migrate merchants between BINs without documented criteria and oversight, the resulting chargeback data becomes unreliable as a fraud indicator.
What This Means for Fintechs and Program Managers
Most fintechs don’t operate acquiring relationships directly — they run payment programs through a sponsor bank or acquirer. That intermediation creates a compliance dependency: the fintech’s merchants are underwritten and monitored by the acquirer, not by the fintech itself.
The Humboldt case is a reminder that this dependency doesn’t eliminate the fintech’s exposure. A fintech whose merchants are generating fraud-level chargebacks is not protected from regulatory scrutiny by the fact that it used a processor to underwrite them. The FTC’s theory of liability in payment processor cases reaches the entities that benefit from and enable the processing, not just the entity that clicks “approve” in the merchant portal.
Three operational implications stand out:
Merchant standards should be documented and contractual. If you use a payment processor or sponsor bank for merchant acquiring, your contract should specify the chargeback monitoring thresholds, the remediation triggers, and what happens when a merchant hits them. If your processor doesn’t have written standards, that’s a vendor risk finding — not an acceptable operating condition.
Chargeback monitoring should be granular, not aggregate. Aggregate chargeback rates can be healthy even when individual merchants are generating rates that would trigger network programs. Your monitoring should identify merchant-level outliers, not just portfolio-level averages, and escalate them on a defined timeline.
BIN assignment and migration should require oversight. If your sponsor bank or processor can move your merchants between BINs without your involvement or documented criteria, the chargeback visibility you rely on may not reflect the actual risk profile of your merchant base. This is a due diligence question for your third-party risk management program.
The FTC’s Pattern of Payment Processor Cases
Humboldt is not the FTC’s first payment processor enforcement action, and the pattern of cases reveals a consistent theory of liability:
- Payday Financial (2013): The FTC settled with Payday Financial and related entities for processing remotely created checks for tribal payday lenders that had made fraudulent withdrawals.
- Vantiv (2015): The FTC reached a $54 million settlement with Vantiv Merchant Services (then Fifth Third Processing Solutions) over card fraud and chargebacks at a client company.
- Alliance Wallet (2020): The FTC sued a payment processor and individual principals for processing payments that they knew or should have known were linked to tech support fraud.
- Corpay/FleetCor (2026): The FTC’s recent $100 million action against Corpay involved unauthorized fee billing, a different theory — but it demonstrates the same principle that the entity that processes a transaction can bear liability for its nature.
In each of these cases, the FTC’s theory requires either actual knowledge or conscious avoidance. The common element is that the processor had access to information — chargeback data, merchant profiles, transaction patterns — that made the fraud discernible, and chose not to act on it.
So What?
The $12 million in the Humboldt settlement is an operational loss. The lifetime ban from high-risk merchant categories is a business model restriction. Neither is the most important thing that happened here.
The most important thing is what the complaint documents: a processor that saw chargebacks running at 10x normal, saw shell companies with no business history, saw merchants cycling through new accounts when old ones got terminated — and found a way to keep processing. The FTC’s case describes a compliance failure that was progressive and deliberate, not accidental.
For any fintech or payment program, the operational question is: what would your chargeback data look like to an investigator? If you have merchants running at 3%, 5%, or 10% chargeback rates, and your program doesn’t have documented criteria for what triggers review and what triggers termination, you’re in the territory that precedes this kind of enforcement action.
The card network thresholds — 0.9% for Visa, 1.5% for Mastercard — are not aspirational benchmarks. They’re the floor below which normal commerce operates. A program that doesn’t manage to those thresholds has a problem. A program that actively reroutes merchants to hide that it’s not managing to those thresholds has a bigger one.
Primary sources
- FTC: Takes Action Against Humboldt Merchant Services for Knowingly Facilitating Payment Processing for Sham Merchants (Sept. 8, 2026)
- FTC: Humboldt Merchant Services — Case Proceedings
- National Law Review: FTC Targets Payment Processor in Proposed $12 Million Sham-Merchant Settlement
- Consumer Financial Services Law Monitor: FTC Secures $12 Million Settlement Against Payment Processor for Facilitating Merchant Fraud
- PYMNTS: FTC Blocks Humboldt From High-Risk Merchants in $12 Million Settlement
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is a 'sham merchant' in payment processing?
What chargeback threshold makes a merchant 'high-risk' under Visa and Mastercard rules?
What does 'conscious avoidance' mean in FTC enforcement against payment processors?
How does routing sham merchants to lower-risk bank BINs constitute fraud facilitation?
What should a payment processor or fintech do today in response to the Humboldt case?
What is the FTC's legal authority over payment processors?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Operational Risk
The Fed's 2026 Risk Officer Survey Is Out. No Major Fraud Category Is Getting Better. Here's What Your Controls Are Flagging Late.
The Federal Reserve's 2026 Risk Officer Survey of 400+ financial institutions shows fraud rising or persisting in every payment channel. Debit card fraud is near-universal. Money mule accounts are discovered after funds disappear. Synthetic identities are defeating KYC. Here's the diagnostic checklist your program needs.
Oct 1, 2026
Operational Risk
FTC Made Corpay's CEO Pay Personally. The $100 Million Unauthorized Fee Case Rewrites What 'Authorization' Means for Billing Controls.
On September 17, 2026, the FTC announced a $100 million settlement with Corpay (formerly FleetCor) and personally named CEO Ronald Clarke for charging unauthorized fees on commercial fuel cards. The injunction's 'clear and unavoidable' disclosure standard goes further than any prior FTC action. Here's what every compliance team with a recurring billing product needs to audit.
Sep 26, 2026
Operational Risk
Congress Never Defined 'Unsafe or Unsound.' Regulators Just Did. What the OCC/FDIC Final Rule Means for Your Risk Program.
The OCC and FDIC finalized a rule on September 1, 2026 that — for the first time in US banking history — defines 'unsafe or unsound practice' in regulation. Effective November 2, it reshapes what kinds of operational failures trigger MRAs. Here's what your risk program needs to change.
Sep 25, 2026