Skip to content
RiskTemplates · The Daily Brief Thursday, October 1, 2026
Wire SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake SEP 30

Feature Operational Risk

FTC Just Fined a Payment Processor $12 Million for Sham Merchants. Here's What 'Knowingly Facilitating Fraud' Actually Looks Like.

On September 8, 2026, the FTC filed a proposed $12 million order against Humboldt Merchant Services for processing payments for 1,000+ sham merchant accounts running chargebacks at 10x card network thresholds. This is what payment processor liability looks like—and why it matters for every fintech that routes transactions.

By Rebecca Leung · September 28, 2026 ·
Table of Contents

TL;DR

  • On September 8, 2026, the FTC filed a proposed $12 million order against Humboldt Merchant Services (5967 Ventures, LLC) for processing payments for more than 1,000 sham merchant accounts linked to billing fraud schemes
  • The merchants ran chargebacks at nearly 10x Mastercard and Visa network thresholds — for extended periods — while Humboldt kept opening new accounts for them
  • Humboldt allegedly moved high-chargeback merchants onto lower-risk bank BINs to mask the fraud from card network monitoring
  • Settlement includes a lifetime ban on processing for highest-risk merchant categories — the FTC’s standard remedy when a processor has demonstrated it cannot operate safely in a segment

Payment processors like to describe themselves as neutral infrastructure. The FTC’s September 2026 case against Humboldt Merchant Services describes something different: a company that built a business model around opening merchant accounts for fraudulent operators, processed over $100 million in transactions through those accounts, and continued doing so after chargeback data made the fraud undeniable.

The case is one of the clearest articulations of payment processor liability the FTC has produced in years. Whether you’re a fintech running a payment program, a bank that sponsors card processing, or a compliance officer trying to understand what “adequate merchant controls” actually means, the Humboldt case is worth your attention.

What Humboldt Actually Did

According to the FTC’s complaint, Humboldt Merchant Services (operating as 5967 Ventures, LLC) provided payment processing services to more than 1,000 entities that were shell companies — fronts set up to hold merchant accounts on behalf of the actual fraudulent operators running billing scams.

The most significant connection was to Legion Media, a company the FTC separately charged in 2024 with running business impersonation scams. Legion Media and its associated entities created hundreds of shell merchant accounts, moved transaction volume through them, and cycled through new accounts when old ones were terminated or suspended. Humboldt was the processor that kept accepting these accounts.

The numbers in the complaint are stark:

  • Chargeback rates of almost 10x network thresholds. Mastercard’s Excessive Chargeback Program triggers at 1.5% chargeback-to-transaction ratio. Visa’s Dispute Monitoring Program triggers at 0.9%. The FTC alleged that Humboldt’s sham merchants were running at rates approaching 10 times these thresholds — for sustained periods — and Humboldt continued processing for them.
  • Over $100 million processed. From 2021 through 2023, Humboldt processed more than $100 million through the sham merchant network.
  • BIN manipulation. Rather than terminating high-chargeback accounts, the FTC alleged that Humboldt moved them to lower-risk Bank Identification Numbers to reduce the visibility of their chargeback rates to card network monitoring systems.

The FTC’s complaint was filed on September 8, 2026, in the U.S. District Court for the Eastern District of Michigan. The proposed stipulated order was entered September 11, 2026. Humboldt agreed to pay $12 million — the full amount required within seven days of entry — and to permanently stop processing for the highest-risk merchant categories.

The “Knowingly Facilitating” Standard

The Humboldt case turns on the FTC’s theory that a payment processor can be liable under Section 5 of the FTC Act as a facilitator of fraud — even if the processor didn’t design the underlying scheme.

The FTC’s complaint alleges that Humboldt either knew the accounts were sham merchants or “consciously avoided knowing.” This is the willful blindness standard: Humboldt had enough information to recognize the pattern, but took steps (including BIN reassignment) that allowed it to continue processing while avoiding the formal acknowledgment that would have required it to act.

What creates liability at this threshold? The FTC’s complaint points to three categories of evidence:

1. Chargeback rates that were self-evidently anomalous. Card network thresholds exist specifically to identify fraud-adjacent merchants. When chargebacks consistently exceed those thresholds by factors of 5 or 10, the merchant population isn’t suffering from bad luck or poor customer service — it’s running schemes that generate disputes at scale. A processor that sees these ratios month after month and continues processing has crossed from negligent oversight into facilitation.

2. Structural red flags in the merchant profile. Shell companies used as fronts for fraud have characteristic features: thin business history, no online presence, transaction patterns inconsistent with the stated merchant category, rapid volume growth from zero. The FTC’s theory is that Humboldt’s merchant underwriting failed to catch — or chose to ignore — these indicators across more than 1,000 accounts.

3. Active concealment through BIN migration. This is the element that elevates the conduct from negligence to something more serious. Reassigning a high-chargeback merchant to a lower-risk BIN isn’t a mistake — it’s a deliberate action that uses card network infrastructure to reduce the visibility of problematic activity. Processors that do this are not failing to catch fraud; they are taking affirmative steps to preserve the processing relationship after the fraud is apparent.

What Card Network Thresholds Actually Mean for Compliance Programs

The chargeback ratios in the Humboldt case aren’t just FTC enforcement benchmarks. They’re operational trip wires that every payment program should be monitoring in real time.

Card NetworkProgramTrigger ThresholdAction Required
MastercardExcessive Chargeback Program (ECP)1.5% ratio, 100+ disputesEnhanced monitoring, potential fines
VisaDispute Monitoring Program (DMP)0.9% monthlyEarly warning, remediation plan
MastercardHigh Excessive Chargeback (HECM)3.0% ratio, 300+ disputesImmediate remediation program
VisaExcessive Dispute Program (EDP)1.8% monthlyEscalated remediation

Running chargebacks at “nearly 10x” these thresholds means some Humboldt merchants were generating chargeback ratios of 9–15% — ranges that indicate a substantial fraction of every transaction being disputed by cardholders. At those rates, it is not possible to characterize the pattern as merchant error or cardholder confusion. These are indicators of systematic fraud.

For a payment program or fintech routing transactions through an acquirer, the question isn’t whether you’re the FTC’s target — it’s whether you know what your chargeback rates are, by merchant, and whether your program documents what happens when a merchant hits or approaches network thresholds.

Why BIN Management Matters Here

The BIN manipulation allegation deserves specific attention because it reflects a compliance failure mode that isn’t visible in aggregate chargeback data.

Bank Identification Numbers segment transaction volume by risk tier. A merchant placed on a BIN associated with low-risk retail transactions receives different monitoring treatment than one placed on a BIN flagged for high-risk categories. Humboldt allegedly exploited this by transferring high-chargeback merchants from BINs where their activity would trigger network monitoring to BINs where it would not — effectively resetting the network’s view of the merchant’s history.

For sponsor banks and program managers, the implication is that BIN assignment is a compliance decision, not just a technical one. If a payment processor or program partner can migrate merchants between BINs without documented criteria and oversight, the resulting chargeback data becomes unreliable as a fraud indicator.

What This Means for Fintechs and Program Managers

Most fintechs don’t operate acquiring relationships directly — they run payment programs through a sponsor bank or acquirer. That intermediation creates a compliance dependency: the fintech’s merchants are underwritten and monitored by the acquirer, not by the fintech itself.

The Humboldt case is a reminder that this dependency doesn’t eliminate the fintech’s exposure. A fintech whose merchants are generating fraud-level chargebacks is not protected from regulatory scrutiny by the fact that it used a processor to underwrite them. The FTC’s theory of liability in payment processor cases reaches the entities that benefit from and enable the processing, not just the entity that clicks “approve” in the merchant portal.

Three operational implications stand out:

Merchant standards should be documented and contractual. If you use a payment processor or sponsor bank for merchant acquiring, your contract should specify the chargeback monitoring thresholds, the remediation triggers, and what happens when a merchant hits them. If your processor doesn’t have written standards, that’s a vendor risk finding — not an acceptable operating condition.

Chargeback monitoring should be granular, not aggregate. Aggregate chargeback rates can be healthy even when individual merchants are generating rates that would trigger network programs. Your monitoring should identify merchant-level outliers, not just portfolio-level averages, and escalate them on a defined timeline.

BIN assignment and migration should require oversight. If your sponsor bank or processor can move your merchants between BINs without your involvement or documented criteria, the chargeback visibility you rely on may not reflect the actual risk profile of your merchant base. This is a due diligence question for your third-party risk management program.

The FTC’s Pattern of Payment Processor Cases

Humboldt is not the FTC’s first payment processor enforcement action, and the pattern of cases reveals a consistent theory of liability:

  • Payday Financial (2013): The FTC settled with Payday Financial and related entities for processing remotely created checks for tribal payday lenders that had made fraudulent withdrawals.
  • Vantiv (2015): The FTC reached a $54 million settlement with Vantiv Merchant Services (then Fifth Third Processing Solutions) over card fraud and chargebacks at a client company.
  • Alliance Wallet (2020): The FTC sued a payment processor and individual principals for processing payments that they knew or should have known were linked to tech support fraud.
  • Corpay/FleetCor (2026): The FTC’s recent $100 million action against Corpay involved unauthorized fee billing, a different theory — but it demonstrates the same principle that the entity that processes a transaction can bear liability for its nature.

In each of these cases, the FTC’s theory requires either actual knowledge or conscious avoidance. The common element is that the processor had access to information — chargeback data, merchant profiles, transaction patterns — that made the fraud discernible, and chose not to act on it.

So What?

The $12 million in the Humboldt settlement is an operational loss. The lifetime ban from high-risk merchant categories is a business model restriction. Neither is the most important thing that happened here.

The most important thing is what the complaint documents: a processor that saw chargebacks running at 10x normal, saw shell companies with no business history, saw merchants cycling through new accounts when old ones got terminated — and found a way to keep processing. The FTC’s case describes a compliance failure that was progressive and deliberate, not accidental.

For any fintech or payment program, the operational question is: what would your chargeback data look like to an investigator? If you have merchants running at 3%, 5%, or 10% chargeback rates, and your program doesn’t have documented criteria for what triggers review and what triggers termination, you’re in the territory that precedes this kind of enforcement action.

The card network thresholds — 0.9% for Visa, 1.5% for Mastercard — are not aspirational benchmarks. They’re the floor below which normal commerce operates. A program that doesn’t manage to those thresholds has a problem. A program that actively reroutes merchants to hide that it’s not managing to those thresholds has a bigger one.

Primary sources

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is a 'sham merchant' in payment processing?
A sham merchant is a shell company or pass-through entity that exists to open merchant accounts on behalf of fraudulent operators. The actual merchant—the company running the scheme—cannot or will not open an account in its own name, so it uses a network of sham entities as front accounts. The FTC alleged that Humboldt processed for more than 1,000 such entities, many tied to Legion Media, which the FTC had separately sued for business impersonation scams.
What chargeback threshold makes a merchant 'high-risk' under Visa and Mastercard rules?
Mastercard's Excessive Chargeback Program triggers at a 1.5% chargeback-to-transaction ratio (and a dispute count of 100+). Visa's Dispute Monitoring Program triggers at 0.9% monthly. The FTC alleged that Humboldt's sham merchants were running chargebacks at rates nearly 10 times these thresholds—suggesting chargeback rates well above 10%—for extended periods while Humboldt continued processing.
What does 'conscious avoidance' mean in FTC enforcement against payment processors?
Conscious avoidance (also called willful blindness) means the processor had enough warning signs to know fraud was likely, but deliberately avoided conducting the inquiry that would have confirmed it. Under FTC Act Section 5, a processor can be liable even if it didn't affirmatively know fraud was occurring, if it took deliberate steps to avoid acquiring that knowledge—for example, by skipping merchant underwriting reviews despite obvious red flags like extreme chargeback ratios.
How does routing sham merchants to lower-risk bank BINs constitute fraud facilitation?
Bank Identification Numbers (BINs) are the first 6 digits of a payment card number. Different BINs carry different risk classifications, with some BINs associated with lower-risk merchant categories that receive less scrutiny. The FTC alleged Humboldt moved high-chargeback sham merchants onto lower-risk BINs to avoid the card network triggers that would have flagged the accounts—essentially using infrastructure designed for lower-risk transactions to mask ongoing fraud.
What should a payment processor or fintech do today in response to the Humboldt case?
Three immediate steps: (1) Audit your merchant underwriting criteria to confirm you have objective chargeback ratio thresholds that trigger review or termination; (2) Confirm that merchant monitoring is continuous, not just at onboarding—high-chargeback merchants should trigger escalation regardless of when they were boarded; and (3) Review whether your third-party payment processors (if you use one) have written merchant standards you've actually seen and validated.
What is the FTC's legal authority over payment processors?
The FTC has authority under Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices in commerce. A payment processor that knowingly—or through conscious avoidance—processes transactions for merchants engaged in fraud can be liable under Section 5 as a facilitator of the underlying unfair practice. The FTC has used this theory in prior payment processor cases including Alliance Wallet (2020), Vantiv (2015), and Payday Financial (2013).
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

◆ Keep reading

Related posts.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.