← All enforcement actions
CFPAGLBAEFTA Reg EFintech

Block / Cash App$175M GLBA fine (2025)

Failed fraud investigations + inadequate Reg E dispute handling

Penalty
$175M
Regulator
CFPB + 48 State AGs
Jurisdiction
United States

What happened

CFPB and state regulators ordered Block to pay up to $120M in consumer redress + $55M in penalties for failing to investigate unauthorized-transaction disputes on Cash App, mishandling chargebacks, and inadequate fraud protection. The order also imposed program changes for dispute, fraud, and customer-service operations.

Root cause

What every team should do

  1. Treat Reg E (12 CFR §1005.11) timelines as a compliance KPI — measured weekly
  2. Build fraud-loss + dispute SLAs into product roadmap, not just CX
  3. Maintain documented playbooks for unauthorized-transfer investigations
Source: CFPB consent order (Jan 2025).
Would your controls have stopped this?

ComplianceIQ audits your existing policies in 60 seconds and shows you exactly which GLBA controls you are missing — mapped to enforcement patterns like this one.

Run my GLBA audit Generate missing policies

Related enforcement actions

Equifax
$700M+
Largest consumer-data settlement in US history — Apache Struts patch ignored for 76 days
Capital One
$80M + $190M class
Mis-configured AWS WAF → 106M records exfiltrated by a former AWS engineer