Earlier this week, we spoke with a physician who operates a busy medical practice in New York.
Thousands of patient records. Employees handling sensitive information every day.
He had never heard of the New York SHIELD Act.
He is not alone.
Many New York businesses do not realize that the SHIELD Act applies to them and imposes legal obligations to protect personal information.
There is another problem. The statute was enacted in 2019 for a cybersecurity environment that no longer exists.
Today, according to the NSA and other Five Eyes cybersecurity agencies (June 22, 2026 statement):
“Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months.”
Yet the SHIELD Act still requires businesses to implement and maintain “reasonable safeguards” to protect sensitive information.
What qualifies as “reasonable” in an era of AI-driven cyberattacks is becoming one of the most important questions facing New York businesses.
Whether the law has kept pace with technology or not, the legal obligation remains.
What the SHIELD Act actually requires
The Stop Hacks and Improve Electronic Data Security (SHIELD) Act was signed into law on July 25, 2019 (NY Senate, S5575B).
The data security provisions became effective on March 21, 2020 (S5575B, § 6)

New York already had a law requiring businesses to respond after a data breach occurred.
The SHIELD Act went further. It imposed a legal duty to protect personal information before a breach happens:
“Any person or business that owns or licenses computerized data which includes private information of a resident of New York shall develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of the private information including, but not limited to, disposal of data.” See N.Y. Gen. Bus. Law § 899-bb(2)(a). [Emphasis added].
It applies broadly to businesses of all sizes, including:
- medical practices/healthcare providers
- financial institutions;
- law firms;
- investment advisers;
- startups;
- family offices; and
- co-op/condo boards
The law is triggered by the residency of the individual whose data is collected; not by the location of the business.
As a result, even out-of-state companies could be covered if they hold personal information about New York residents.
The standard is simply “reasonable safeguards.” The problem is that the statute never defines what “reasonable” means.
It certainly does not explain what reasonable security looks like in an age of AI-driven cyberattacks ( which the NSA warned in 2026 are evolving on a timeline measured in months, not years).
The statute gives categories, not a level
Instead of providing a definition, the statute describes a compliance framework that businesses can follow.
The cybersecurity provisions require a business to “designate one or more employees to coordinate the security program.” § 899-bb(2(b)(ii)(A)(i).
The law also requires businesses to:
- Identify “reasonably foreseeable internal and external risks.”
- Assess “the sufficiency of safeguards in place to control the identified risks.”
- Train and manage “employees in the security program practices and procedures.”
- “Adjust[] the security program in light of business changes or new circumstances.”

Notably, the statute outlines these requirements but never defines what qualifies as a “reasonable” safeguard in practice.
That question has become increasingly important as AI-driven cyber threats continue to evolve.
The technical safeguards focus on a business’s systems and controls. The statute requires businesses to:
- Assess “risks in network and software design.”
- Assess “risks in information processing, transmission and storage.”
- Detect, prevent, and respond to “attacks or system failures.”
- Regularly test and monitor “the effectiveness of key controls, systems and procedures.”
The physical safeguards address the protection and handling of data. Businesses must:
- Assess “risks of information storage and disposal.”
- Detect, prevent, and respond to “intrusions.”
- Protect against “unauthorized access to or use of private information during or after the collection, transportation and destruction or disposal of the information.”
See N.Y. Gen. Bus. Law § 899-bb(2)(b)(ii)(B)-(C).
A 2019 standard meets a 2026 threat
On June 22, 2026, the National Security Agency and allied cyber security agencies published a joint statement:
“Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months” (NSA, Five Eyes Cyber Security Agencies Statement, June 22, 2026). {emphasis added].
Agencies drove the point home with another observation:
“Cyber risk assumptions can become outdated in months, not years” (Id.).
That creates an obvious problem. The New York SHIELD Act was enacted in 2019.
It was written for a cybersecurity environment that no longer exists.
Today’s threat landscape is being reshaped by AI at a pace measured in months, not years.
Yet the law remains in force. The fact that technology has evolved does not relieve businesses of their obligations.
If anything, it raises the bar. What is “reasonable” security is measured against what a business knew, or should have known, about foreseeable risks.
Following a public warning from the NSA, it is becoming increasingly difficult to argue that AI-enabled cyberattacks are unforeseeable.
The SHIELD Act already requires businesses to adjust their security programs for “business changes or new circumstances.”
A risk assessment prepared before June 22, 2026 and never revisited may therefore present its own compliance problem.
In short, the threat environment has changed dramatically. The legal obligation to maintain reasonable safeguards has not.
What information triggers the duty
“Private information” is far broader than most New York businesses assume.
It includes traditional identifiers such as Social Security numbers, driver’s license numbers, and payment card data.
But the statute also covers biometric information, health insurance information, and “medical information” concerning an individual’s “medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional.”
Even login credentials can qualify.
A “user name or e-mail address in combination with a password” that provides access to an online account is protected under the statute as well. (§ 899-aa(1)(b)).
“Private information” is broader than most owners assume.
Two important qualifications apply.
First, the SHIELD Act recognizes that not every business has the same resources.
A “small business” is generally one with less than 50 employees (less than $3 million in annual revenue) or or less than $5 million in total assets.
Such businesses are only required to maintain safeguards that are “appropriate for the size and complexity” of the business. (§ 899-bb(1)(c), (2)(c)).
Second, some businesses could qualify for a statutory safe harbor.
An entity that is already subject to and compliant with regulatory frameworks such as HIPAA, the Gramm-Leach-Bliley Act, or 23 NYCRR Part 500 is deemed compliant with the SHIELD Act’s data security requirements. (§ 899-bb(1)(a), (2)(b)(i)).
The key point is that the safe harbor depends on actual compliance. It is not enough to operate in a regulated industry.
A business must be able to demonstrate that it is complying with the applicable regulatory framework.
No private right of action — and why that is not comfort
The SHIELD Act has teeth. A business that fails to maintain “reasonable safeguards” may face enforcement by the New York Attorney General and civil penalties of up to $5,000 per violation.
The statute also states that “Nothing in this section shall create a private right of action.”
That does not mean a business can’t be sued after a breach.
Plaintiffs often bring negligence claims instead, and the SHIELD Act could become a benchmark for what constitutes reasonable cybersecurity.
In practice, your compliance records can become either your strongest defense or the plaintiff’s strongest exhibit.
How Dilendorf Law Firm helps
Max Dilendorf has worked as a digital asset attorney since 2017. He has handled more than 100 cybercrime matters involving financial institutions, telecommunications carriers, account takeovers, SIM swaps, and authentication failures.
That experience shapes how we approach compliance. We know which records are requested after an incident and which documents become critical evidence.
Our team also includes retired federal law enforcement investigators, including former FBI and U.S. Secret Service agents with decades of cybercrime experience.
We help businesses answer a question the SHIELD Act does not: What is reasonable for your business?
We assess existing safeguards, review vendor agreements, and conduct tabletop exercises. The goal is to identify gaps before an incident occurs; not afterward.
We advise medical practices, financial firms, investment advisers, startups, family offices, and co-op and condominium boards throughout New York.
If you have already been breached, call today — the first days decide everything: +1 212 457 9797 or info@dilendorf.com.
Frequently asked questions
Does the SHIELD Act apply to my small practice or business?
Most likely, yes. The duty applies to “any person or business that owns or licenses computerized data which includes private information of a resident of New York” (§ 899-bb(2)(a)). There is no industry limitation and no minimum size. A business with fewer than fifty employees, or under $3 million in gross annual revenue in each of the last three fiscal years, or under $5 million in year-end total assets may satisfy the statute with safeguards “appropriate for the size and complexity” of the business (§ 899-bb(1)(c), (2)(c)) — a scaled duty, not an exemption.
My practice complies with HIPAA. Am I already covered?
Possibly, but only if the compliance is real and documented. A “compliant regulated entity” — one subject to and in compliance with HIPAA and HITECH regulations, Gramm-Leach-Bliley safeguards rules, or 23 NYCRR Part 500 — is deemed to satisfy the reasonable safeguards requirement (§ 899-bb(1)(a), (2)(b)(i)). The safe harbor depends on actual compliance rather than industry status, so the practical question is whether your risk analysis, training records, and vendor agreements would survive review.
What does “reasonable” mean in practice?
The statute never defines it. It lists categories instead: designating a security coordinator, identifying “reasonably foreseeable internal and external risks,” assessing “the sufficiency of safeguards in place,” training employees, requiring vendor safeguards by contract, and adjusting the program for “new circumstances” (§ 899-bb(2)(b)(ii)(A)). Because the level is left open, reasonableness is assessed against your specific data, threats, and resources — and against what was publicly known at the time.
Why does the June 2026 NSA statement matter to my compliance file?
It affects foreseeability. The Five Eyes cyber security agencies stated that frontier AI is transforming offensive cyber capability and that “The timeline is not years, it is months” (NSA, June 22, 2026). Reasonableness is measured against what a business knew or should have known, and the statute requires the program to be adjusted for new circumstances. A risk assessment last updated before that date, with no review since, is difficult to defend as current.
Can my patients or clients sue me under the SHIELD Act?
Not under the statute itself: “Nothing in this section shall create a private right of action” (§ 899-bb(2)(e)). That is narrower protection than it sounds. Private plaintiffs typically sue in negligence after a breach, and negligence turns on what reasonable care required, which makes the statute’s safeguard categories a ready benchmark for measuring your conduct. Your documentation is usually the central evidence either way.
What can the Attorney General do if I am not compliant?
A failure to maintain reasonable safeguards is deemed a violation of General Business Law § 349, and the Attorney General may sue to enjoin it and obtain civil penalties (§ 899-bb(2)(d)). Penalties run up to “five thousand dollars for each violation” (§ 350-d), and the Attorney General’s guidance confirms up to $5,000 per violation for safeguard failures, alongside separate penalties of up to $20 per instance of failed notification, capped at $250,000 (NY OAG, SHIELD Act).
What counts as private information?
More than Social Security numbers. The definition includes driver’s license numbers, financial account and payment card numbers, biometric data, “medical information” regarding medical history, condition, treatment or diagnosis, health insurance information, and a username or email address combined with a password or security question and answer permitting access to an online account (§ 899-aa(1)(b)). For medical offices and advisory businesses, ordinary records routinely qualify.
Do I have to notify anyone if there is no evidence of misuse?
Sometimes not, but the exception must be documented. Where exposure resulted from inadvertent disclosure by authorized persons and the business reasonably determines misuse or harm is unlikely, consumer notice may not be required — but the determination must be made in writing and kept for at least five years, and if more than 500 New York residents are affected it must be provided to the Attorney General within ten days (NY OAG, SHIELD Act).
When should a business bring in a lawyer rather than an IT vendor?
Before an incident, and certainly at the moment one is suspected. Technical remediation and legal defensibility are different objectives: a vendor secures the environment, while counsel builds the record that answers the negligence question, handles notification analysis, preserves privilege where available, and allocates risk in vendor contracts. Dilendorf Law Firm combines that legal work with investigators who came from federal cybercrime enforcement.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Sources
[1] N.Y. Gen. Bus. Law § 899-bb, Data security protections (NYS Open Legislation). https://www.nysenate.gov/legislation/laws/GBS/899-BB
[2] N.Y. Gen. Bus. Law § 899-aa, Notification; person without valid authorization has acquired private information (NYS Open Legislation). https://www.nysenate.gov/legislation/laws/GBS/899-AA
[3] N.Y. Gen. Bus. Law § 350-d, Civil penalty (NYS Open Legislation). https://www.nysenate.gov/legislation/laws/GBS/350-D
[4] New York State Senate, Bill S5575B (2019), signed July 25, 2019, Chapter 117. https://www.nysenate.gov/legislation/bills/2019/S5575
[5] New York State Senate, S5575B bill text, § 6 (effective dates). https://legislation.nysenate.gov/pdf/bills/2019/S5575B
[6] Office of the New York State Attorney General, “SHIELD Act.” https://ag.ny.gov/resources/organizations/data-breach-reporting/shield-act
[7] National Security Agency, “Five Eyes Cyber Security Agencies Statement,” June 22, 2026. https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4523810/five-eyes-cyber-security-agencies-statement/
After a cryptocurrency theft, victims are often told the same thing:
A tracing report is needed.
A few weeks later they were sent a PDF document which looked professional and showed where the stolen cryptocurrency had ended up.
The victim now knows exactly where the money has gone, but the money is still missing.
A mistake that we frequently come across is the idea that crypto tracing and cryptocurrency recovery are identical. Yet they aren’t.
The tracing process shows how stolen assets move around the blockchain, and for them to be recovered, legal authority is needed so that the assets can be seized and then given back to the victims.
When we have been dealing with people who have been victims of crypto theft, many of them spend a good deal of time and money getting trace reports even though they never first consider some of the important questions mentioned below.
Who actually has the power to get the money back?
The response is a surprise to a great many victims.
A private forensic company is able to trace blockchain transactions but it cannot send out subpoenas since it doesn’t have the authority to do so.
It is impossible to obtain seizure warrants, it cannot require a cryptoexchange to do anything, and it also can’t start federal forfeiture proceedings.
The authority is given to law enforcement agencies and prosecutors through 18 USC § 981 (civil forfeiture).
This distinction is critical.
It might be possible to discover where the stolen assets ended up. Yet merely tracing them does not result in a legal duty on an exchange or stablecoin issuer to freeze the funds (or return them to the victim).
That is to say, a tracing report usually marks the start of a recovery strategy but is not the strategy itself.
The 2025 Internet Crime Report by the FBI states that the Internet Crime Complaint Center (IC3) received 181,565 complaints concerning cryptocurrency, the amount of losses being over $11.3 billion. (FBI IC3, 2025 Internet Crime Report, p. 52)
Since crypto-related crime is still increasing, it is important for victims to know what is possible through tracing and why legal authority under 18 U.S.C. § 981 is usually more important than blockchain analytics alone.
How Dilendorf Law Firm helps
Max Dilendorf has practiced as a digital asset lawyer since 2017 and has handled more than 100 cybercrime arbitrations and investigations.
When the funds are offshore, the firm collaborates with former law enforcement officers in order to draw the attention of U.S. law enforcement so that section 981 remedies may be invoked. The firm also assists clients through the recovery process.
If a U.S. exchange or stablecoin issuer is holding your funds, the firm will assist you in considering your legal options, such as filing a TRO, a complaint and/or applying for injunctive relief.
If your cryptocurrency has been stolen, contact Dilendorf Law Firm at +1 212 457 9797 or info@dilendorf.com.
What a tracing report can and can’t do
An analyst is able to track stolen coins through swaps and mixers until they get to a custodial exchange using public ledgers. Yet that marks only the start of the recovery, not its end.
The FBI was blunt when it stated that: “Private sector recovery companies cannot issue seizure orders to recover cryptocurrency.” (FBI PSA, Aug. 11, 2023).
Furthermore, FBI said that “Cryptocurrency exchanges only freeze accounts based on internal processes or in response to legal process.” Id.

The same alert describes the failure mode: “Recovery scheme fraudsters charge an up-front fee and either cease communication with the victim after receiving an initial deposit or produce an incomplete or inaccurate tracing report and request additional fees to recover funds” (FBI PSA, Aug. 11, 2023).
A genuine forensic vendor is not a scammer, but it must be understood that a tracing report is not a recovery tool.
If there is no seizure warrant or court order, the report will not result in any exchange or financial institution having a legal obligation to take any action.
Who can actually seize stolen crypto
The Federal Civil Forfeiture statute set out in 18 USC § 981 states that “Any property, real or personal, which is derived from or consists of proceeds traceable to” wire fraud (for example, Sections 1029, 1030, 1032, or 1344) and other “specified unlawful activity” (18 U.S.C. § 981(a)(1)(C)).
“Any property subject to forfeiture to the United States under subsection (a) may be seized by the Attorney General…”(18 U.S.C. § 981(b)(1)).
Moreover, “Seizures pursuant to this section shall be made pursuant to a warrant obtained in the same manner as provided for a search warrant under the Federal Rules of Criminal Procedure…” (18 U.S.C. § 981(b)(2)). [emphasis added].
The statute also covers “The property was lawfully seized by a State or local law enforcement agency and transferred to a Federal agency.” (18 U.S.C. § 981(b)(2)(C)).
That is the only approach available to a district attorney’s cybercrime unit, not one that is operated by a private tracing firm lacking the power to issue subpoenas or seizure warrants.
It should be noted that the term ‘private party’ is not mentioned anywhere in the text of 18 USC § 981 (‘Civil Forfeiture’).
What a real recovery looks like
Recent cases handled by the Secret Service illustrate how crypto seizure cases function.
In one instance, the agents confiscated the funds that had been obtained through investment fraud from an account at a foreign bank.
The U.S. Attorney filed a civil forfeiture complaint, and a settlement provided that “$7 million of the seized funds would be forfeited to the United States, allowing victims to petition to recover on their losses” (U.S. Attorney’s Office, E.D. Va., Mar. 21, 2025).
In December 2025 the same office recovered stablecoins that Secret Service agents had seized “from three cryptocurrency wallets” (U.S. Attorney’s Office, E.D. Va., Dec. 5, 2025).

On July 21, 2026, the U.S. Attorney for the District of Columbia filed five civil forfeiture complaints covering more than $25 million in cryptocurrency seized by Secret Service agents (U.S. Attorney’s Office, D.C., July 21, 2026).
Each case started with tracing, but these cases stand for the principal that to successully recover the funds you need a federal agencies with § 981 power.
How victims are paid
The money that has been forfeited is returned to the victims by means of remission or restoration.
In order to be considered a victim, one must demonstrate “a financial loss amounting to a specific figure…and that the loss is supported by documentary evidence such as invoices and receipts.” (28 C.F.R. § 9.8(b)(1)).
Moreover, the monetary loss endured by a victim… is to be restricted to the fair market value of the property from which the victim was deprived as of the date on which the loss occurred. No account shall be made for the interest lost or for any incidental expenses incurred in recovering the lost property or in seeking other compensation.” (28 C.F.R. § 9.8(c)). [emphasis added].
Where a private law firm fits
The FBI notes that “Victims can also choose to pursue civil litigation to seek recovery of their funds” (FBI PSA, Aug. 11, 2023).
That path works usually works when a counterparty is located inside U.S. jurisdiction: an exchange, stablecoin issuer, bank, or domestic account holder.
Depending on the facts, counsel could file a temporary restraining order (TRO) over identified assets, file a complaint, and pursue injunctive relief.
When the funds are located at an offshore exchange with no U.S. presence, only an agency with seizure authority under § 981 can act.
What to do this week
- The most important information you can give is details of the transaction. This includes the cryptocurrency address, the amount and type of cryptocurrency, the date and time, and the transaction ID (hash) (FBI, Guidance for Cryptocurrency Scam Victims, Aug. 24, 2023).
- Make sure to write to each exchange and ask them to keep the records and to hold the funds until a legal procedure has been carried out. “Cryptocurrency exchanges only freeze accounts based on their internal procedures or as a result of a legal process” (FBI PSA, Aug. 11, 2023). Requesting that the funds be frozen could give you additional time.
- Check the forensic engagement to verify that the forensic vendor will provide exhibits suitable for use in an affidavit, will file freeze requests, and will assist with an agency referral. Make sure that all of these points are included in your engagement letter to the forensic firm.
- Look at the corresponding counterparts in the United States. Any domestic exchange, issuer, or bank which holds your money could be a suitable target for a TRO or a civil suit.
- It is important to keep all your receipts since remission requires documentary proof of “a pecuniary loss of a specific amount…and that the loss is supported by documentary evidence including invoices and receipts.” (28 C.F.R. § 9.8(b)(1)).
- Be careful about anyone offering to recover your money since they might be engaging in another scam (FBI, August 24, 2023).
Frequently asked questions
Can a blockchain forensic firm get my stolen crypto back?
Not by itself. A forensic company will be able to track the funds and find out at which exchange your funds have been deposited (which is important evidence). However, the FBI says that “Private sector recovery companies are not allowed to issue seizure orders in order to recover cryptocurrency.” Moreover, exchanges only freeze accounts “through their internal procedures or in response to a legal request” (FBI PSA, Aug. 11, 2023). A recovery process requires a court order or a seizure warrant, something that a forensic report cannot take the place of.
Who has the authority to seize stolen cryptocurrency?
According to the federal civil forfeiture law, property which can be traced to wire fraud “may be seized by the Attorney General”; seizures “must be carried out on the basis of a warrant obtained in the manner provided for a search warrant under the Federal Rules of Criminal Procedure” (18 U.S.C. § 981(b)(1)–(2)).In reality, federal agents (typically the FBI or the U.S. Secret Service) act in conjunction with an Assistant United States Attorney; furthermore, state and local agencies are also able to seize property and hand it over to a federal agency (18 U.S.C. § 981(b)(2)(C)); private firms and law firms, on the other hand, do not have the power to carry out seizures.
What is 18 U.S.C. § 981 and why does it matter to victims?
It is the federal civil forfeiture statute. It makes “any property, real or personal, which constitutes or is derived from proceeds traceable to” wire fraud and other specified unlawful activity forfeitable to the United States (18 U.S.C. § 981(a)(1)(C)).
It matters because it is mechanism by which stolen crypto held at an exchange or in a wallet is frozen/seized and then returned to victims (typically through remission or restoration program). Without an agency willing to use tracing firm’s forensic report, tracing doesn’t really have an endpoint.
Will an exchange freeze the thief’s account if I ask?
Sometimes briefly, but you should not count on it. The FBI explains that “Cryptocurrency exchanges only freeze accounts based on internal processes or in response to legal process” (FBI PSA, Aug. 11, 2023).
Prompt written notice with transaction hashes could trigger internal compliance review; that’s why it is worth sending it. However, a proper freeze usually requires a subpoena/seizure warrant, or court order. This is where U.S. law enforcement comes in.
How do victims actually receive forfeited cryptocurrency?
Through the Department of Justice remission process or through restoration to satisfy a restitution order. After seizure, the U.S. Attorney’s Office “identifies all potential victims and notifies them of the opportunity to file a petition for remission” (DOJ, Returning Forfeited Assets to Crime Victims). The victim must document “a pecuniary loss of a specific amount” with “invoices and receipts,” and when funds are insufficient they are generally distributed “on a pro rata basis” (28 C.F.R. § 9.8(b), (f)).
Can I recover the fees I paid a tracing company?
Not through remission. The regulation limits recovery to the fair market value of the property on the date of loss and states that “no allowance shall be made for interest forgone or for collateral expenses incurred to recover lost property or to seek other recompense” (28 C.F.R. § 9.8(c)). Forensic fees, legal fees, and investigative costs fall within that exclusion. This is a practical reason to tie any forensic engagement to concrete referral and recovery work rather than paying for a standalone report.
When can a private law firm help, and when is it only law enforcement?
The FBI notes that “Victims can also choose to pursue civil litigation to seek recovery of their funds” (FBI PSA, Aug. 11, 2023).
Depending on the facts/circumstances, a firm like Dilendorf Law Firm could file a TRO, a complaint, or pursue injunctive relief against U.S. counterparties (e.g., crypto exchange or stablecoin issuer).
Where funds are located at an offshore exchange, only an agency with seizure and forfeiture authority, such as the FBI or Secret Service, or a prosecutor’s office can reach them; counsel’s job then is to build a referral those agencies can adopt.
How do I tell a legitimate crypto recovery lawyer from a scam?
FBI issued the list of red flags to watch out for. Be cautious of firms that contact you unexpectedly, and “Request video verification or documentation…” (FBI PSA, Aug. 13, 2025).
Claims of official government partnership are false: “There are no law firms which are officially authorized partners of US Government agencies” (FBI PSA, Aug. 13, 2025). Requests for payment in cryptocurrency or gift cards (or promises of guaranteed recovery) are clear warning signs.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Sources
[1] Federal Bureau of Investigation, Internet Crime Complaint Center, “2025 Internet Crime Report,” April 2026, p. 52. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[2] Federal Bureau of Investigation, Public Service Announcement I-081123-PSA, “Increase in Companies Falsely Claiming an Ability to Recover Funds Lost in Cryptocurrency Investment Scams,” August 11, 2023. https://www.ic3.gov/PSA/2023/psa230811
[3] Federal Bureau of Investigation, Public Service Announcement, “Fictitious Law Firms Targeting Cryptocurrency Scam Victims Offering to Recover Funds” (update), August 13, 2025. https://www.ic3.gov/PSA/2025/PSA250813
[4] Federal Bureau of Investigation, Public Service Announcement, “FBI Guidance for Cryptocurrency Scam Victims,” August 24, 2023. https://www.ic3.gov/PSA/2023/psa230824
[5] 18 U.S.C. § 981, Civil forfeiture (U.S. Code 2023 edition, Office of the Law Revision Counsel via GovInfo). https://www.govinfo.gov/content/pkg/USCODE-2023-title18/html/USCODE-2023-title18-partI-chap46-sec981.htm
[6] 28 C.F.R. § 9.8, Remission procedures for victims (Electronic Code of Federal Regulations, current as of September 15, 2026). https://www.ecfr.gov/current/title-28/chapter-I/part-9/section-9.8
[7] U.S. Department of Justice, Criminal Division, “Returning Forfeited Assets to Crime Victims: An Overview of Remission and Restoration.” https://www.justice.gov/file/440746/dl
[8] U.S. Attorney’s Office, Eastern District of Virginia, “United States uses civil asset forfeiture to recover $7M of investment fraud proceeds,” March 21, 2025. https://www.justice.gov/usao-edva/pr/united-states-uses-civil-asset-forfeiture-recover-7m-investment-fraud-proceeds
[9] U.S. Attorney’s Office, Eastern District of Virginia, “United States uses civil asset forfeiture to recover nearly $1.7M for victims of cryptocurrency investment scam,” December 5, 2025. https://www.justice.gov/usao-edva/pr/united-states-uses-civil-asset-forfeiture-recover-nearly-17m-victims-cryptocurrency
[10] U.S. Attorney’s Office, District of Columbia, “Investigations into Cryptocurrency Scams Result in Seizure of More Than $25 Million,” July 21, 2026. https://www.justice.gov/usao-dc/pr/investigations-cryptocurrency-scams-result-seizure-more-25-million
A fraudulent wire transfer is not complete as soon as the money leaves your account.
For a few hours, the funds remain in the recipient’s account, and the bank can still freeze them.
FBI and the Treasury Department’s Financial Crimes Enforcement Network (“FinCEN”) have two programs designed for this short window: (i) Financial Fraud Kill Chain; and (ii) the Rapid Response Program.
Both require the victim to act quickly.
The 72-hour window, in the government’s words
According to FinCen’s Program Fact Sheet dated April 15, 2026 – “FinCEN is most likely to be able to interdict or recover funds when fraudulently induced wire transfers are reported to law enforcement within 72 hours of the transaction” (FinCEN, Rapid Response Program Fact Sheet, Apr. 15, 2026, p. 2).

The time frame set out in FinCEN’s email-compromise advisory is even more strict: “FinCEN has been more successful in recovering funds when victims or financial institutions report BEC-unauthorized and fraudulently induced wire transfers to law enforcement within 24 hours.” (FinCEN, FIN-2019-A005, July 16, 2019, p. 8).
The reason is often structural: [Wire] transactions are irrevocable, making financial institutions and customers unable to cancel payments or recall funds.” (FIN-2019-A005, p. 8).
FBI’s Internet Crime Complaint Center (IC3) agrees: “If you discover a fraudulent transfer, time is of the essence. Immediately, contact your financial institution and request a recall of the funds along with any necessary indemnification documents” (FBI IC3, 2025 Internet Crime Report, Apr. 2026, p. 17).
What the Financial Fraud Kill Chain does

“Established in 2018, the IC3 RAT streamlines communications with financial institutions and FBI field offices to assist in the freezing of funds for victims of fraudulent domestic and international transactions” (IC3 Report, p. 17).
For domestic Kill Chain Process – “IC3 RAT will expand the FFKC process beyond the initial recipient bank if information is provided during the FFKC initiation on “second hop” transactions to other domestic or international accounts to request freezes on as much of the lost funds as possible.” (IC3 Report, p. 17).
In 2025 the kill chain was initiated on 3,900 incidents involving $1,163,919,846 in attempted theft and froze $679,013,183, a 58 percent success rate; 3,574 of those incidents were domestic and 326 international (IC3 Report, p. 17).
What FinCEN’s Rapid Response Program does
When the funds left the country, FinCEN takes over.
According to FinCen’s Fact Sheet dated April 15, 2026 – “Since its inception in 2015, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network’s (FinCEN) Rapid Response Program (RRP) has facilitated the interdiction of $1.8 billion and the recovery of over $1 billion in stolen proceeds on behalf of 5,790 U.S. victims.” (RRP Fact Sheet, p. 1).
Two rules matter for victims.
First, “Please do not contact FinCEN directly”; the program activates only when law enforcement refers a complaint filed at IC3 or with the Secret Service (RRP Fact Sheet, p. 1).
Second, the complaint must contain details information about the victim. That information includes victim’s and beneficiary’s account names and numbers, both banks and their countries, the date, currency, amount, and a summary of the fraud (RRP Fact Sheet, p. 2). Incomplete information could delay investigation process.

How the wire gets out: five attack vectors
Business email compromise once dominated kill chain cases.
“However, in 2025, the [Kill Chain] process saw a rise in Tech Support and Account Takeover (ATO) initiations.”
Furthermore, “AT)-related incidents can contain upwards of 50 or more transactions to different recipient accounts at multiple banks happening simultaneously via ACH transactions” (IC3 Report, p. 17). [emphasis added].
The way fraud occurred matters because it could affect who is responsible for the loss.
- Bank’s “fraud department.” “The scammer falsely informs the victim their computer and financial accounts have been accessed by a foreign hacker and the victim must move their money to a “safe” third-party account, such as an account with the Federal Reserve or another US Government agency.” (FBI PSA, “Phantom Hacker” Scams, Sept. 29, 2023). In this situation, the victim would be initiating/authorizing the wire transfer.
- Phishing links. “Cyber criminals use advertisements that imitate legitimate companies to misdirect targets…. fraudulent URL appears at the top of search results…When targets click on the fraudulent advertisement link, they are redirected to a phishing website that closely mirrors the legitimate website…target enters login credentials, the cyber criminal intercepts the credentials.” (FBI PSA, Apr. 24, 2025).
- Account takeover. “Once the impersonators have access and control of the accounts, the cyber criminals quickly wire funds to other criminal-controlled accounts, many of which are linked to cryptocurrency wallets; therefore, funds are disbursed quickly and are difficult to trace and recover. In some cases, including nearly all social engineering cases, the cyber criminals change the online account password, locking the owner out of their own financial account(s).” (FBI PSA, Nov. 25, 2025).
- Malware/ Remote-access software. The FBI lists credentials obtained “via malware on the victim’s device” among ATO methods (FBI IC3, Account Takeover Fraud). In the tech-support variant, the scammer installs remote-desktop software and “can lock the victim out of their computer or place a black screen as they conduct unauthorized wire transfers” (FBI PSA, Nov. 10, 2022).
- Business email compromise. Criminals “insert themselves into communications by impersonating a critical player in a business relationship or transaction” and alter the payment instructions (FIN-2019-A005, p. 6). BEC losses reported to IC3 in 2025: $3,046,598,558 (IC3 Report, p. 9).
The first 72 hours: what to do
- Call the bank (Use number on your card or statement). Contact the originating institution “as soon as fraud is recognized to request a recall or reversal as well as a Hold Harmless Letter or Letter of Indemnity” (FBI IC3, Domestic Financial Fraud Kill Chain Process). Get the wire reference number.
- File at ic3.gov the same day. “It is vital the complaint contain all required data in provided fields, including banking information” (FBI PSA, Nov. 25, 2025). File “Regardless of the amount lost” (IC3 Report, p. 17).
- Lock the intruder out. “Reset all credentials and passwords that may have been exposed,” from a device you trust (FBI PSA, Nov. 25, 2025).
- Preserve everything. Save emails, texts, phone numbers, wire confirmations, and screenshots; the FBI asks for the caller’s name, contact methods, and the receiving account numbers (FBI PSA, Sept. 29, 2023).
- Send nothing more. Scammers “may instruct the victim to send multiple transactions over a span of days or months” (FBI PSA, Sept. 29, 2023).
- Get the bank’s timeline in writing. When was the recall sent, and what did the beneficiary bank answer? That record decides what can still be frozen and, later, who bears the loss.
How Dilendorf Law Firm helps
Max Dilendorf has practiced as a digital asset lawyer since 2017 and handled more than 100 cybercrime arbitrations and investigations.
When a client reports a fraudulent wire, firm works with retired law enforcement professionals to decide within the first 24-to-72-hour window if the wire could be recalled or frozen, prepares the IC3 complaint with the data the Kill Chain and Rapid Response Program require, and coordinates with the originating and beneficiary banks.
Once funds are contained, the firm evaluates if a bank, carrier, or platform may share responsibility for the loss, depending on the facts and the account agreements.
If a fraudulent wire just went out, contact Dilendorf Law Firm for a confidential consultation at +1 212 457 9797 or info@dilendorf.com.
Frequently asked questions
What is the FBI’s Financial Fraud Kill Chain?
It is the FBI process for freezing fraudulently wired funds before criminals withdraw them. The IC3 Recovery Asset Team, established in 2018, “streamlines communications with financial institutions and FBI field offices to assist in the freezing of funds” for domestic and international transfers (IC3 Report, p. 17). In 2025 it handled 3,900 incidents and froze $679,013,183, a 58 percent success rate (IC3 Report, p. 17).
How fast do I need to act after a fraudulent wire transfer?
Within hours, and no later than three days. FinCEN reports it is “most likely to be able to interdict or recover funds” when the wire is reported to law enforcement “within 72 hours of the transaction” (RRP Fact Sheet, p. 2), and it has had “greater success” when reports arrive “within 24 hours” (FIN-2019-A005, p. 8).
Can a wire transfer be reversed once it has been sent?
Sometimes, but not automatically. FinCEN notes that wire transactions “are often irrevocable,” leaving banks and customers “unable to cancel payments or recall the funds” (FIN-2019-A005, p. 8). Recovery depends on the receiving bank freezing the account before withdrawal, which is what the Kill Chain and a prompt recall request are designed to achieve. The FBI cautions that “Different financial institutions have varying policies” on recovery assistance (IC3 Report, p. 17).
What is a Hold Harmless Letter, and why does the FBI say to request one?
It is the indemnification paperwork the FBI tells victims to request from their bank together with the recall. The FBI’s guidance is to contact the originating bank “to request a recall or reversal as well as a Hold Harmless Letter or Letter of Indemnity.” Otaining these documents ASAP “may reduce or eliminate your financial losses” (FBI PSA, Nov. 25, 2025).
How does FinCEN’s Rapid Response Program get involved in my case?
Only through law enforcement. The victim or the bank files a complaint with IC3 or the Secret Service, law enforcement reviews it and refers it to FinCEN, and FinCEN then asks the foreign financial intelligence unit to stop and return the funds (RRP Fact Sheet, p. 1). FinCEN states plainly: “Please do not contact FinCEN directly” (RRP Fact Sheet, p. 1). Since 2015 the program has helped recover over $1 billion for 5,790 U.S. victims (RRP Fact Sheet, p. 1).
What information do I need to file the IC3 complaint?
Complete banking details on both sides of the wire. FinCEN lists the victim’s account name and number, the victim’s bank and its country, the beneficiary’s account name and number, the beneficiary’s bank and its country, the transaction date, the currency and amount, and a summary of the fraud (RRP Fact Sheet, p. 2). Add the scammer’s names, phone numbers, emails, websites, and any software you were asked to install (FBI PSA, Nov. 25, 2025).
I sent the wire myself after a fake bank call. Can anything still be done?
Yes. The government programs cover “fraudulently induced wire transfers,” not only wires a hacker sent (RRP Fact Sheet, p. 2), and the FBI’s Phantom Hacker alert describes exactly this pattern of victims moving money to a “safe” account at a scammer’s direction (FBI PSA, Sept. 29, 2023). File the recall request and IC3 complaint immediately. Whether a bank or other party shares responsibility for the loss is a separate question that depends on the facts and the account agreement.
When should I call a wire fraud attorney?
As soon as you have called the bank, and before the 72-hour window closes. Dilendorf Law Firm, led by Max Dilendorf, a digital asset lawyer since 2017 with more than 100 cybercrime arbitrations and investigations, works with retired law enforcement professionals (including retired FBI and Secret Service cybercrime professionals). Max and his team help victims to evaluate if a wire can be recalled; assists victims to develop IC3 complaint around the data the Kill Chain and Rapid Response Program require; and then evaluates if a bank, carrier, or platform could be held responsible for the loss. Early involvement protects both the recovery window and the evidence.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Sources
[1] Financial Crimes Enforcement Network, “FinCEN Rapid Response Program (RRP) Fact Sheet,” April 15, 2026. https://www.fincen.gov/system/files/2026-04/RRPFactSheet.pdf
[2] Financial Crimes Enforcement Network, “Updated Advisory on Email Compromise Fraud Schemes Targeting Vulnerable Business Processes,” FIN-2019-A005, July 16, 2019. https://www.fincen.gov/system/files/advisory/2019-07-16/Updated%20BEC%20Advisory%20FINAL%20508.pdf
[3] Federal Bureau of Investigation, Internet Crime Complaint Center, “2025 Internet Crime Report,” April 2026, pp. 9, 17. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[4] Federal Bureau of Investigation, Internet Crime Complaint Center, “Domestic Financial Fraud Kill Chain (D-FFKC) Process” (hosted by U.S. Department of Justice, Elder Justice Initiative). https://www.justice.gov/elderjustice/media/1364051/dl?inline
[5] Federal Bureau of Investigation, Public Service Announcement, “Account Takeover Fraud via Impersonation of Financial Institution Support,” November 25, 2025. https://www.ic3.gov/PSA/2025/PSA251125
[6] Federal Bureau of Investigation, Public Service Announcement, “‘Phantom Hacker’ Scams Target Senior Citizens and Result in Victims Losing their Life Savings,” September 29, 2023. https://www.ic3.gov/PSA/2023/PSA230929
[7] Federal Bureau of Investigation, Public Service Announcement, “Cyber Criminals Targeting Users of Employee Self-Service Websites Through Search Engine Advertisements,” April 24, 2025. https://www.ic3.gov/PSA/2025/PSA250424
[8] Federal Bureau of Investigation, Public Service Announcement, “Scammers Using Computer-Technical Support Impersonation Scams to Target Victims and Conduct Wire Transfers,” November 10, 2022. https://www.ic3.gov/PSA/2022/PSA221110
[9] Federal Bureau of Investigation, Internet Crime Complaint Center, “Account Takeover Fraud (ATO),” crime information page. https://www.ic3.gov/CrimeInfo/AccountTakeover
Consider a hypothetical. An investor opens a wallet one morning and finds that a six-figure balance of USD Coin (USDC) is gone.
All of his USDC was moved in five transactions to addresses the investor has never seen, without a single click or signature.
The first instinct is to ask Circle (issuer of USDC) to freeze the funds and reverse the transfer. The problem is that an issuer generally can’t do it.
This article explains why and what the GENIUS Act now requires of stablecoin issuers.
It also examines legal mechanisms available to freeze stolen USDC and pursue its recovery.
These could include providing notice to the issuer, getting assistance from (i) federal authorities through an asset forfeiture referral; (ii) obtaining a temporary restraining order (“TRO”) in New York Supreme Court; and (iii) navigating reissuance process in coordination with Circle and authorities.
Why Circle can’t simply reverse a stolen USDC transfer
The short answer is custody.
Once USDC reaches an external wallet, the tokens are controlled by whoever holds that wallet’s private key (not by the issuer).
The issuer does not have keys to a third party’s address. USDC is a token on a public blockchain; the issuer maintains the smart contract, but it does not hold the balances recorded in it.
What an issuer can do is block.
In an April 10, 2026 proposed rule, the Financial Crimes Enforcement Network (“FinCEN”) and the Office of Foreign Assets Control (“OFAC”) explained: “For example, a stablecoin issuer may be able to prohibit specific wallet addresses from interacting with the stablecoin and its smart contract. ”
Furthermore, Fincen and OFAC stated that “Applying such controls to a particular wallet address would effectively prevent the holder of a stablecoin from transferring, redeeming, or otherwise moving the stablecoin.” ([2]).
Finally, FinCEN notes that “In some cases, including when required by a lawful order, stablecoin issuers reissue stablecoins equivalent to burned or frozen funds to different wallets as part of efforts to recover and return funds to victims of criminal activity.” ([2]).
Whether a stablecoin issuer can do that for a given contract is a technical question a court may need to resolve on evidence.
What GENIUS Act requires of stablecoin issuers
The Guiding and Establishing National Innovation for U.S. Stablecoins Act (GENIUS Act), Public Law 119-27, was signed on July 18, 2025 ([1]).
Section 4(a)(“Compliance with Lawful Orders”) says that “A permitted payment stablecoin issuer may issue payment stablecoins only if the issuer has the technological capability to comply, and will comply, with the terms of any lawful order.” ([1]).
Under §5901 (16). Definitions …”Lawful Order” is defined as “any final and valid writ, process, order, rule, decree, command, or other requirement issued or promulgated under Federal law, issued by a court of competent jurisdiction or by an authorized Federal agency pursuant to its statutory authority, that—(A) requires a person to seize, freeze, burn, or prevent the transfer of payment stablecoins issued by the person…” ([1]).
The definition is federal; a New York state-court order rests on New York law, discussed below.
The Act is not yet fully effective; under Section 20 it takes effect on the earlier of 18 months after enactment or 120 days after final regulations ([1]).
Even so, FinCEN stated that “”Additionally, with some regularity, Federal court orders require stablecoin issuers to burn and reissue an equivalent amount of stablecoins to a government-controlled wallet” ([2]).
Step one: report to IC3 and put the issuer on notice
File a complaint with the FBI’s Internet Crime Complaint Center (“IC3”) asap after your incident (include all details relevant to unauthorized crypto transfer).
In 2025, the IC3 Unit received 181,565 complaints involving cryptocurrency with $11.366 billion in reported losses ([6]).
FBI specifically encourages investors who suspect that criminals exploited DeFi smart contract to report to IC3 or a local field office ([7]).
At the same time, counsel should send the issuer, among other things, (i) a written notice of the theft; (ii)tainted blockchain addresses; (iii) the victim’s ownership claim. Also send the request that the addresses be blocked/frozen pending legal process.
Step two: work with federal authorities toward forfeiture
Forfeiture is how the government takes title to stolen stablecoins and returns them to victims.
On June 18, 2025, the Department of Justice (“DOJ”) filed a civil forfeiture complaint against more than $225.3 million in cryptocurrency tied to investment-fraud laundering.
“The Department of Justice thanks Tether for its … assistance in this investigation”, further described the effort as made “all with the eye toward making victims whole” ([4]).
Victims then recover through remission or restoration administered by DOJ’s Money Laundering and Asset Recovery Section. The agency reported returning “more than $13 billion in forfeited assets to victims” since 2000 and publishes a model petition under 18 US Code. § 981e)(6) ([5]).
The government decides whether and when to act. Accordingly, a well-prepared referral from counsel and former federal investigators matters (supported by blockchain analytics and crypto title reports); however, no outcome can be promised.
Step three: seek a TRO in New York Supreme Court
New York is a natural forum.
Circle Internet Group, Inc. lists its business address as One World Trade Center, New York, NY 10007 in its SEC filings ([11]).
New York State Department of Financial Services (“NYDFS”) lists Circle Internet Financial, LLC as licensed since September 2015. NYDFS also list Circle Internet Trust Company, LLC as chartered since July 2026 ([12]).
Under Civil Practice Law and Rules (“C.P.L.R.”) 6301 (“Grounds for Preliminary Injunction and Temporary Restraining Order (TRO) – “A temporary restraining order may be granted pending a hearing for a preliminary injunction where it appears that immediate and irreparable injury, loss or damage will result unless the defendant is restrained before the hearing can be had.” ([8]).
C.P.L.R. 6313(a) states that “Upon granting a temporary restraining order, the court shall set the hearing for the preliminary injunction at the earliest possible time.” Furthermore, the court may require an undertaking – “Undertaking. Prior to the granting of a temporary restraining order the court may, in its discretion, require the plaintiff to give an undertaking in an amount to be fixed by the court…” ([9]).
Depending on the facts, the relief sought against the unknown thief and the issuer may include restraining any transfer from the identified addresses.
Where the evidence shows it is technically feasible, directing the issuer to burn the frozen tokens and issue replacements to a court-supervised wallet.
Where the thief is a non-domiciliary or has secreted property, C.P.L.R. § 6201 also supplies grounds for attachment ([10]). “Grounds for attachment. An order of attachment may be granted in any action…when (1) the defendant is a nondomiciliary residing without the state, or is a foreign corporation not qualified to do business in the state…” Step four: from frozen to returned
A freeze is just the midpoint.
Frozen USDC comes back to a victim in one of two ways. Either through the federal forfeiture action, in which the government forfeits the tokens and a victim petitions for remission or restoration ([5]).
Or, alternatively, through a court order directing the issuer to burn the blocked tokens and reissue an equivalent amount to a wallet the court or the victim controls (mechanism FinCEN describes as already used with some regularity by federal courts ([2]).)
Which path applies depends on whether the government has opened a case and how quickly the freeze was obtained.
| Route | Who acts | Legal basis | What it can realistically achieve |
|---|---|---|---|
| Issuer notice | Circle, directed at counsel’s request | Issuer’s own compliance program; FinCEN-described blocking capability | Blocking of tainted addresses pending legal process; no voluntary reversal |
| Federal forfeiture | DOJ, FBI, U.S. Secret Service | 18 US Code § 981; 28 C.F.R. Part 9 remission and restoration | Government seizure, then return to victims through petition; timing controlled by the government |
| New York Supreme Court “TRO” | Victim, through counsel | C.P.L.R. 6301, 6313; CPLR 6201 attachment | Court-ordered freeze; burn-and-reissue where feasible; preliminary injunction hearing |
How Dilendorf Law Firm helps
Max Dilendorf is a New York crypto lawyer who has practiced cryptocurrency and blockchain law since 2017 and has represented hundreds of victims of crypto cybercrime, including holders whose USDC and other stablecoins were stolen through wallet drains, exchange account takeovers, SIM-swap attacks, and DeFi exploits.
Dilendorf Law Firm coordinates correspondence with Circle and its legal team to request that stolen funds be blocked, works with a team of retired FBI and Department of Justice experts to trace funds and prepare a forfeiture referral.
Depending on the facts and circumstances of the case, files a TRO action and preliminary injunction in New York Supreme Court (jurisdiction where Circle is based), so that frozen USDC can be burned and reissued to the victim.
The firm is counsel of record in more than 130 cybercrime-related arbitration matters before AAA, JAMS, and NAM. Represents U.S. and non-U.S. crypto cybercrime victims nationwide. Contact Max Dilendorf for a consultation about stolen USDC or other stablecoins, including Tether.
Contact US
Call +1 212 457 9797, email info@dilendorf.com, or request a consultation. Bring the wallet addresses, transaction hashes, dates, any IC3 complaint number, and every message exchanged with the issuer or exchange.
This article does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Frequently asked questions
Can Circle reverse a USDC transaction or return stolen USDC?
Not by simply moving the tokens back: once USDC sits at an external address, the issuer holds no private key for that address and cannot transfer tokens out of it. What an issuer generally can do is block a specific address from interacting with the stablecoin, which the Treasury Department describes as effectively preventing the holder from transferring or redeeming it ([2]). Blocking preserves the asset; a court order or federal forfeiture proceeding is then needed to move it.
How do you get Circle to freeze stolen USDC?
By written notice from counsel that identifies the theft, the tainted addresses, and the on-chain tracing, requests that the addresses be blocked pending legal process, and references the IC3 complaint. FinCEN’s proposed rule describes address blocking as a capability issuers may have, and the GENIUS Act conditions issuance on the “technological capability to comply” with lawful orders to seize, freeze, or burn tokens ([2]; [1]). A voluntary block is at the issuer’s discretion; a court order or government request is what compels it.
What is a “lawful order” under the GENIUS Act?
Section 2(16) of the GENIUS Act defines it as a final and valid order issued under Federal law by a court of competent jurisdiction or an authorized Federal agency that requires a person “to seize, freeze, burn, or prevent the transfer of payment stablecoins issued by the person,” identifies the stablecoins or accounts with reasonable particularity, and is subject to review or appeal ([1]). Section 4(a)(6)(B) then conditions issuance on the “technological capability to comply, and will comply,” with such orders ([1]).
Is the GENIUS Act in effect yet?
Not fully. Under Section 20, the Act takes effect on the earlier of 18 months after the July 18, 2025 enactment or 120 days after the primary federal regulators issue final implementing rules ([1]). FinCEN and OFAC published a joint proposed rule on April 10, 2026, with comments due June 9, 2026 ([2]), and the Congressional Research Service updated its overview of the Act on August 20, 2026 ([3]).
Can a court order a stablecoin issuer to burn stolen tokens and reissue them?
Federal courts have done so. FinCEN states that “with some regularity, Federal court orders require stablecoin issuers to burn and reissue an equivalent amount of stablecoins to a government-controlled wallet,” and that issuers sometimes reissue tokens “as part of efforts to recover and return funds to victims of criminal activity” ([2]). Whether a particular court will grant such relief to a private victim, and whether a particular contract permits it, depends on the evidence and the issuer’s technical capabilities.
Why file the TRO in New York Supreme Court?
Because the issuer is here. Circle Internet Group, Inc. reports its business address as One World Trade Center, New York, NY 10007 ([11]), and its affiliates hold New York DFS virtual currency and money transmitter licenses dating to September 2015 and a limited purpose trust charter granted in July 2026 ([12]). CPLR 6301 and 6313 allow a TRO, including without notice, where immediate and irreparable injury would otherwise result ([8]; [9]).
How does federal forfeiture return stolen stablecoins to victims?
The government seizes and forfeits the assets, then returns them through remission or restoration. DOJ’s Money Laundering and Asset Recovery Section reports returning more than $13 billion in forfeited assets to victims since 2000, provides a model petition under 18 U.S.C. § 981(e)(6), and never charges victims a fee for the process ([5]). In June 2025, DOJ filed a forfeiture complaint against $225.3 million in stablecoins linked to investment fraud with the issuer’s assistance ([4]; [2]).
How can USDC be stolen from a wallet without a signature?
Often through a stale token approval: an ERC-20 approval lets a smart contract move a set amount of tokens from a wallet at any later time, and if the approved contract is later compromised, the attacker can call it without the owner ever signing again. The FBI has warned that criminals “are increasingly exploiting vulnerabilities in the smart contracts governing DeFi platforms to steal cryptocurrency” and encourages victims to report to IC3 ([7]). Reviewing and revoking old approvals is a basic wallet-hygiene step.
Why hire a crypto lawyer who has practiced since 2017 for a stolen-stablecoin case?
Because the case turns on issuer mechanics, on-chain evidence, and forum choice, and it moves quickly. Max Dilendorf has practiced cryptocurrency and blockchain law since 2017, has represented hundreds of crypto cybercrime victims, and is counsel of record in more than 130 cybercrime-related arbitration matters before AAA, JAMS, and NAM. Dilendorf Law Firm coordinates with Circle’s legal team on freezing stolen USDC, works with retired FBI and DOJ experts on forfeiture referrals, and, where the facts support it, seeks a TRO in New York Supreme Court.
Sources
[1] Guiding and Establishing National Innovation for U.S. Stablecoins Act (GENIUS Act), Pub. L. No. 119-27, 139 Stat. 419 (July 18, 2025), §§ 2(16), 2(22), 4(a)(6)(B), 20. https://www.govinfo.gov/content/pkg/PLAW-119publ27/html/PLAW-119publ27.htm
[2] Financial Crimes Enforcement Network and Office of Foreign Assets Control, U.S. Department of the Treasury, Joint Proposed Rule implementing the GENIUS Act (Bank Secrecy Act and sanctions obligations of permitted payment stablecoin issuers), 91 Fed. Reg. 18582 (Apr. 10, 2026), FR Doc. 2026-06963, including discussion of proposed 31 C.F.R. § 1033.240(b). https://www.federalregister.gov/documents/full_text/html/2026/04/10/2026-06963.html
[3] Congressional Research Service, “Stablecoin Legislation: An Overview of the GENIUS Act of 2025 (P.L. 119-27),” Insight IN12553, updated Aug. 20, 2026. https://www.congress.gov/crs-product/IN12553
[4] U.S. Department of Justice, Office of Public Affairs, Press Release No. 25-633, “United States Files Civil Forfeiture Complaint Against $225M in Funds Involved in Cryptocurrency Investment Fraud Money Laundering,” June 18, 2025. https://www.justice.gov/opa/pr/united-states-files-civil-forfeiture-complaint-against-225m-funds-involved-cryptocurrency
[5] U.S. Department of Justice, Criminal Division, Money Laundering and Asset Recovery Section, “Victims” (remission and restoration of forfeited assets), updated May 1, 2026. https://www.justice.gov/criminal/criminal-mnf/victims
[6] FBI Internet Crime Complaint Center, 2025 Internet Crime Report, pp. 17, 52. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[7] FBI IC3, Public Service Announcement, “Cyber Criminals Increasingly Exploit Vulnerabilities in Decentralized Finance Platforms to Obtain Cryptocurrency, Causing Investors to Lose Money,” Aug. 29, 2022. https://www.ic3.gov/PSA/2022/PSA220829
[8] N.Y. Civil Practice Law and Rules § 6301, Grounds for preliminary injunction and temporary restraining order (New York State Senate). https://www.nysenate.gov/legislation/laws/CVP/6301
[9] N.Y. Civil Practice Law and Rules § 6313, Temporary restraining order (New York State Senate). https://www.nysenate.gov/legislation/laws/CVP/6313
[10] N.Y. Civil Practice Law and Rules § 6201, Grounds for attachment (New York State Senate). https://www.nysenate.gov/legislation/laws/CVP/6201
[11] U.S. Securities and Exchange Commission, EDGAR entity record, Circle Internet Group, Inc. (CIK 0001876042), business address One World Trade Center, New York, NY 10007. https://www.sec.gov/edgar/browse/?CIK=1876042
[12] New York State Department of Financial Services, “Virtual Currency Businesses” (list of licensed and chartered entities), entries for Circle Internet Financial, LLC (2015-09) and Circle Internet Trust Company, LLC d/b/a Circle New York Trust (2026-07). https://www.dfs.ny.gov/virtual_currency_businesses
Search the 136-page Standard Form 86 for the words “cryptocurrency,” “bitcoin,” or “digital asset” and you will find nothing.
Many applicants take that to mean crypto is irrelevant to the security clearance process. It isn’t.
SF-86 asks about (i) foreign financial interests; (ii) tax compliance; (iii) debt problems; (iv) self-employment; (v) unauthorized computer access, etc. And a crypto portfolio can touch every one of those categories. ([1]).
Defense Office of Hearings and Appeals (“DOHA) judges have already denied clearances in cases where Bitcoin was central to unresolved debt, tax issues, or the purchase of illegal drugs. ([5], [6]).
Below are the actual questions (quoted from the form), and what they mean for federal employees, contractors, and military members who own crypto.
Key takeaways
- The SF-86 never uses the word crypto, but Sections 13A, 20A, 20B, etc. could technically reach it.
- Every answer is certified under 18 US Code § 1001. Your answers are compared against your previous SF-86s responses.
- DOHA denied clearances where crypto losses, crypto-funded debt, or dark-web bitcoin purchases tied to dark-web marketplaces.
- Once clearance is granted, reporting obligations could continue under Security Executive Agent Directive 3 (“SEAD 3).
How Dilendorf Law Firm helps
Max Dilendorf has practiced in the cryptocurrency and digital asset space since 2017. He advises clients on crypto compliance matters involving the Bank Secrecy Act (“BSA”), securities laws, CFTC regulations, and FinCEN requirements.
Dilendorf Law Firm analyzes actual SF-86 questions in light of your cryptocurrency history (exchange records, wallet activity, blockchain data).
We help clients prepare responses that are accurate and consistent with their tax filings, prior security clearance questionnaires, and various financial disclosure reports.
The firm served as counsel of record in more than 130 crypto-related cybercrime arbitration matters before AAA, JAMS, and NAM, involving testimony from retired FBI law enforcement expert witnesses.
Depending on the nature of a client’s case, the firm regularly works with retired law enforcement experts from the FBI, U.S. Department of Justice (“DOJ”), and Department of Homeland Security (“DHS”) to provide expert witness support in crypto and regulatory matters.
The certification you sign before the questions start
SF-86 begins with a clear warning. The form states that falsifying/concealing a material fact is a felony and that agencies “generally fire, do not grant a security clearance, or disqualify individuals who have materially and deliberately falsified these forms” ([1]).
SF-86, Penalties for Inaccurate or False Statements (verbatim)
The U.S. Criminal Code (title 18; section 1001) provides that knowingly falsifying or concealing a material fact is a felony which may result in fines and/or up to five (5) years imprisonment. In addition, Federal agencies generally fire, do not grant a security clearance, or disqualify individuals who have materially and deliberately falsified these forms, and this remains a part of the permanent record for future placements.
The same instructions add a line that crypto holders should read twice: “responses to this form may be compared with your responses to previous SF 86 questionnaires” ([1], [2]).
For example, a crypto wallet omitted from a 2017 SF-86 but disclosed in 2026 is the type of inconsistency the form is designed to identify.
Statute itself carries fines and imprisonment of up to 5 years for materially false statements in any matter within federal jurisdiction ([12]).
Section 20A: your offshore exchange account is a foreign financial interest
Section 20A is the question most crypto holders get wrong, because it never says “exchange” or “token.” It says this:
SF-86, Question 20A.1 (verbatim)
Have you, your spouse or legally recognized civil union/domestic partner, cohabitant, or dependent children EVER had any foreign financial interests (such as stocks, property, investments, bank accounts, ownership of corporate entities, corporate interests or exchange traded funds (ETFs) held in specific geographical or economic sectors) in which you or they have direct control or direct ownership? (Exclude financial interests in companies or diversified mutual funds or diversified ETFs that are publicly traded on a U.S. exchange.)
The word is “EVER,” in capitals, with no seven-year lookback.
That could be a challenging question for cryptocurrency holders.
Consider an applicant who received dozens of airdrops, moved assets across multiple exchanges, interacted with decentralized finance (DeFi) protocols.
In some cases, DeFi transactions could involve liquidity pools, validators or protocols connected to foreign jurisdictions.
Developing a complete history of potentially foreign financial interests could require reviewing years of wallet activity, exchange records, smart-contract interactions, and blockchain data.
The adjudicator may then analyze those facts under Guideline B (Foreign Influence), which identifies as a security concern “substantial business, financial, or property interests in a foreign country, or in any foreign-owned or foreign-operated business that could subject the individual to a heightened risk of foreign influence or exploitation” ([3]).
SF-86, Question 20A.1 follow-ups (verbatim)
Provide the type of financial interest.
Provide the date acquired.
Provide how the financial interest was acquired (such as purchase, gift, etc.).
Provide the cost (in U.S. dollars) at time of acquisition.
Provide the current value (in U.S. dollars) or the value at the time control or ownership was sold, lost or otherwise disposed of.
Are there any co-owners of this foreign financial interest?
Now try answering those questions for a crypto portfolio built over multiple years.
Digital assets may have been acquired through purchases, airdrops, forks, staking rewards, liquidity mining, DAO participation, exchange migrations, or DeFi transactions.
Section 26: the crypto tax years
Section 26 asks about bankruptcy, gambling, taxes, liens, and delinquent debt.
For crypto holders, one question stands out:
SF-86, Question 26.3 (verbatim)
In the last seven (7) years have you failed to file or pay Federal, state, or other taxes when required by law or ordinance?
The IRS treats digital assets as property, puts a yes-or-no digital asset question on Form 1040.
Any taxes income from staking, mining, airdrops, and sales ([8]).
The guideline addresses unexplained wealth.
“Unexplained affluence, as shown by a lifestyle or standard of living, increase in net worth, or money transfers that are inconsistent with known legal sources of income” is its own disqualifying condition, so a crypto windfall you cannot document is a problem even when you owe nothing ([3]). Section 26.7 then asks whether you “defaulted on any type of loan” or had “bills or debts turned over to a collection agency,” which is how leveraged crypto positions surface ([1]).
What DOHA judges have already said about crypto
In June 2025, DOHA judge denied a clearance to an applicant with more than $97,000 in delinquent federal taxes.
The applicant testified that, “[b]elieving that his cryptocurrency investment returns would cover his owed back taxes,” he withdrew $300,000 from a crypto account to purchase a home.
The judge found that it was not clear if the applicant’s tax payments accounted for his “large amount of profit from crypto currency” sales.
The decision noted that this was “not documented.” The judge further observed that “[e]qually unclear are his mounted losses from his gambling in crypto currency” ([5]).
In July 2024 another applicant lost his clearance over a $38,431 charged-off loan.
He “took the money from this loan and invested it in the bitcoin cyber-currency market, with the hopes that it would increase in value.” The judge found the debt to be unresolved ([6]).
The lesson from these decisions is straightforward: cryptocurrency itself is not disqualifying. However, but failing to document/properly report crypto activity on Form SF-86 could be.
For clearance purposes, owning crypto is rarely the issue. Explaining it and documenting it is.
After the clearance: the disclosures do not stop
Clearance holders have continuing reporting duties under Security Executive Agent Directive 3.
Federal employees who file financial disclosures reports must generally report virtual currency held for investment.
Office of Government Ethics treats cryptocurrency as “property held . . . for investment or the production of income,” subject to applicable reporting thresholds. ([9]).
Crypto is not treated as a “publicly traded security.” That means even a small cryptocurrency holding can create a conflict if the employee is involved in a matter that could affect its value ([10]).
FinCEN has also announced its intent to amend the FBAR rules to cover virtual currency held in foreign accounts ([11]).
Contact Us
Questions about cryptocurrency and security clearances? Contact Max Dilendorf at +1 212 457 9797 or info@dilendorf.com, or use our contact page.
Max Dilendorf also advises individuals outside the government sector on cryptocurrency-related disclosure and compliance issues. His represents investment advisers, hedge fund professionals, and other regulated financial industry employees.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Frequently asked questions
Does the SF-86 ask about cryptocurrency directly?
No. The current Standard Form 86 doesn’t use words crypto, bitcoin, or digital asset. It asks about foreign financial interests, taxes, debts, employment, unauthorized computer access, etc. Crypto activity is frequently responsive to those questions ([1]).
Is an account at a non-U.S. crypto exchange a “foreign financial interest” under Section 20A?
Question 20A.1 asks if you have “EVER had any foreign financial interests (such as stocks, property, investments, bank accounts . . .)” and excludes only companies and diversified funds “publicly traded on a U.S. exchange.” Holdings on a foreign platform fit the plain language of “investments” and “bank accounts,” and the safer reading is to disclose them ([1], [2]).
What if I did not report crypto gains on a prior tax return?
Question 26.3 asks whether, in the last 7 years, you “failed to file or pay Federal, state, or other taxes when required by law.” IRS treats crypto as property and taxes income from sales, staking, mining, and airdrops. Unreported crypto year is generally a yes answer ([1], [8]).
Can crypto losses alone cost me a clearance?
Losses are not a listed disqualifying condition, but the debts they leave behind are. Guideline F lists “inability to satisfy debts,” “a history of not meeting financial obligations,” and borrowing to fund gambling as disqualifying conditions, and DOHA denied a clearance where a $38,431 charged-off loan had been invested in bitcoin ([3], [6]).
What is “unexplained affluence,” and does a crypto windfall count?
Guideline F treats “unexplained affluence, as shown by a lifestyle or standard of living, increase in net worth, or money transfers that are inconsistent with known legal sources of income” as a disqualifying condition. Large crypto gain is a legal source of income (…but only if you can document it with transaction records and tax filings) ([3]).
I left crypto off my last SF-86. Should I disclose it now?
The form warns that your answers “may be compared with your responses to previous SF 86 questionnaires,” and Guideline E lists “deliberate omission, concealment, or falsification” on a security questionnaire as disqualifying. Omission is generally easier to explain than a second inconsistent form, and this is a question to work through with counsel before you sign ([1], [3]).
Do I have to report crypto after I am cleared?
Under SEAD 3, the DCSA reporting aid lists foreign bank accounts, financial anomalies, and ownership of foreign properties as reportable events for Top Secret and “Q” holders. Federl employees who file financial disclosure reports must also list virtual currency as investment property ([4], [9]).
Does the penalty for a false SF-86 answer really include prison?
The form itself states that knowingly falsifying or concealing a material fact under 18 US Code. § 1001 “is a felony which may result in fines and/or up to 5 years imprisonment.” This is addition to denial or revocation of a clearance and removal from federal service ([1], [12]).
Sources
[1] U.S. Office of Personnel Management, Standard Form 86, Questionnaire for National Security Positions (rev. Nov. 2016). https://www.opm.gov/forms/pdf_fill/sf86.pdf
[2] Defense Counterintelligence and Security Agency, Guide for the Standard Form (SF) 86. https://www.dcsa.mil/Portals/128/Documents/pv/mbi/standard-form-sf-86-guide-for-applicants.pdf
[3] Office of the Director of National Intelligence, Security Executive Agent Directive 4, National Security Adjudicative Guidelines (effective June 8, 2017), hosted by the U.S. Department of Energy. https://www.energy.gov/sites/prod/files/2018/02/f48/SEAD4_20170608.pdf
[4] Defense Counterintelligence and Security Agency, SEAD 3 Industry Reporting Desktop Aid (rev. May 2024). https://www.dcsa.mil/Portals/128/Documents/CTP/tools/SEAD-3_Reporting_Desktop_Aid_for_Cleared_Industry-revisedMay2024.pdf
[5] Defense Office of Hearings and Appeals, ISCR Case No. 24-01107 (June 5, 2025). https://doha.ogc.osd.mil/Industrial-Security-Program/Industrial-Security-Clearance-Decisions/ISCR-Hearing-Decisions/2025-ISCR-Hearing-Decisions/FileId/237257/
[6] Defense Office of Hearings and Appeals, ISCR Case No. 23-00320 (July 23, 2024). https://doha.ogc.osd.mil/Industrial-Security-Program/Industrial-Security-Clearance-Decisions/ISCR-Hearing-Decisions/2024-ISCR-Hearing/FileId/223318/
[7] Defense Office of Hearings and Appeals, ISCR Case No. 24-01844 (July 29, 2025). https://doha.ogc.osd.mil/Industrial-Security-Program/Industrial-Security-Clearance-Decisions/ISCR-Hearing-Decisions/2025-ISCR-Hearing-Decisions/FileId/239976/
[8] Internal Revenue Service, Digital Assets. https://www.irs.gov/filing/digital-assets
[9] U.S. Office of Government Ethics, Legal Advisory LA-18-06, Guidance for Reporting Virtual Currency on Financial Disclosure Reports (June 18, 2018). https://www.oge.gov/web/oge.nsf/News+Releases/D9038B8D8DE24D88852585BA005BEC34/$FILE/LA-18-06.pdf
[10] U.S. Office of Government Ethics, Legal Advisory LA-22-04, Application of the Securities and Mutual Fund Exemptions to Cryptocurrency, Stablecoins, and Related Investments (July 5, 2022). https://www.oge.gov/web/oge.nsf/News+Releases/E116F1FD24F94BB3852588770058A0FA/$FILE/LA-22-04.pdf
[11] Financial Crimes Enforcement Network, Notice 2020-2, Report of Foreign Bank and Financial Accounts (FBAR) Filing Requirement for Virtual Currency (Dec. 2020). https://www.fincen.gov/system/files/shared/Notice-Virtual%20Currency%20Reporting%20on%20the%20FBAR%20123020.pdf
[12] 18 U.S.C. § 1001, Statements or entries generally (Legal Information Institute, Cornell Law School). https://www.law.cornell.edu/uscode/text/18/1001
Around July 29, 2026, unknown group of attackers gained unauthorized access to Liechtenstein’s Register of Beneficial Owners.
They copied records of approx. 31K+ legal entities, including companies, foundations, and trusts ([1]).
For U.S. families and family offices that hold assets through those structures (including crypto), this is not a tale about how European compliance works.
It is a personal security event, and the next wave of attacks could happen by email, phone, and video call.
This article explains what information was exposed and who may be affected.
It also explores how ordinary data can could become more sensitive when combined with information available through US public databases (e.g., ADV filings submitted by investment advisers to the SEC).
With today’s advanced AI-powered search and pattern-recognition tools, bad actors can uncover insights that would have been difficult to identify just a few years ago.
Finally, it talks about the steps that families with asset protection trusts in Liechtenstein,Cook Islands, Nevis, and other trust-register jurisdictions should consider reviewing now.
This article also touches upon a question that offshore asset protection trust attorneys are increasingly asked after incidents like this: if trust assets are compromised as part of a cyberattack (e.g., account takeover involving a trust bank account or cryptocurrency wallet,), who bears the loss?
Many readers would be surprised to learn that many trust agreements are either silent on this issue or have provisions, placing the risk of loss on someone other than the trustee.
For a more detailed discussion of that issue, see our article, “AI Cyberattacks and Asset Protection Trusts: Who Bears the Loss?“
Key takeaways
- Liechtenstein’s government confirms that data on more than 30K+ legal entities was copied without authorization.
- The Five Eyes cyber agencies, including the NSA, said on June 22, 2026 that frontier AI is changing offensive cyber capabilities – “The timeline is not years, it is months.”
- U.S.families and invididuals should assess their exposure and upgrade cybersecurity.
What was taken
According to the Liechtenstein government, compromised records included names of legal entities and identifying information about their beneficial owners, including names, DOBs, nationalities, countries of residence, etc. ([1]).
The government’s incident response review determined that intrusion was made possible by a flaw in the system’s authorization controls ([2]). Officials described the incident as highly sophisticated attack. ([3]).
For families that use offshore structures, the significance of the breach is beyond the loss of data.
Whoever got these records may now have verified information of who owns or controls thousands of private wealth structures (together with personal information that could be used in phishing, social engineering and impersonation).
How Cybercriminals Build a Targeted List
Beneficial ownership data becomes far more sensitive when it can be matched with info available from other public sources.
For example, every U.S. investment adviser registered with the US Securities and Exchange Commission has to file Form ADV. Much of the information disclosed in those filings is publicly available through SEC’s portal ([4], p. 12).

The issue is that Form ADV shows not only the identity of an advisory firm and its key personnel, but also the firm’s AUM, approx. number of client accounts, and portion of assets that attributed to non-U.S. clients ([5], pp. 13-14).
When combined with beneficial ownership records, this information can provide a road map for cybercriminals.
Recent cyber warnings (e.g., NSA Five Eyes report) and the fallout from the Liechtenstein breach highlight how investment advisers could become attractive targets for sophisticated cyberattacks.
Aggregated public records can identify HNW, where they operate, and professionals who advise them.They could also trace the entities through which they hold and manage assets.
That, in turn, could increase the risk of targeted phishing, business email compromise, impersonation, and other social engineering attacks.
FinCEN has already warned that criminals combine generative-AI images with “stolen personally identifiable information” to build fake identities that pass customer identification and due diligence controls ([7], pp. 2–3).
The FBI’s Internet Crime Complaint Center received 1,008,597 complaints in 2025 with $20.877 billion in reported losses; personal data breach alone accounted for $1.31 billion; business email compromise was apprx. $3.05 billion ([8], pp. 6–8).
Five Eyes Warning
Liechtenstein breach did not occur in isolation.
Just weeks before news of the incident emerged – on June 22, 2026, the NSA and its counterparts in the United Kingdom, Canada, Australia, and New Zealand issued a joint statement on artificial intelligence and cyber risk ([9]).

“Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months.” — Five Eyes Cyber Security Agencies Statement, June 22, 2026 ([9])
Five Eyes agencies urged organizations saying “Breaches will occur. Preparedness helps you contain them quickly and prevent escalation into major operational and financial crises.”
The guidance was even more than blunt: “Test response plans, train and prepare teams, and assume breaches will occur” ([9]).
For many families with domestic/offshore asset protection trusts, that advice is no longer theoretical.
If the organization never rehearsed how to verify and respond to such a request, it could be exactly the type of target the Five Eyes warning was describing.
Family offices, trustees, and advisers should consider running tabletop exercises and updating their business continuity and incident response plans. This could help to address AI-enabled fraud and attacks.
Cook Islands, Nevis, Liechtenstein: what to review in an existing offshore trust
Liechtenstein register exists because anti-money-laundering rules now require most jurisdictions to record who stands behind a structure ([1]).
The lesson is not limited to Liechtenstein.
Families with offshore structures in foreign jurisdictions (Cayman Islands, Cook Islands, Nevis, Jersey etc.) should assume that similar information exists in trustee records, banking files, and due diligence databases.
Each database has valuable identity information. Each can become a target. Choose your jurisdiction wisely.
The takeaway is not to abandon offshore planning. It is to choose the jurisdiction, trustee, and structure carefully. You should understand that cyber risks are now as important as legal, creditor and tax risk.
In our experience, many U.S. domestic and offshore trusts were drafted long before today’s cyber threats emerged, i.e., the Five Eyes’s Report.
If the trust agreement is silent or unclear on cyber risk and loss allocation, a fresh review of the trust agreement would not hurt.
Depending on the trust instrument and governing law, cyber-related gaps can often be addressed through amendments, trust protector action, or other mechanisms.
If a structure no longer serves its purpose, orderly wind-down could be appropriate.
U.S. tax and reporting consequences should be reviewed before any assets are moved. U.S. tax and reporting obligations should be reviewed before any assets are moved.
When a trustee loses the money: who bears the loss
If a trustee wires trust assets to a fraudster impersonating a settlor, protector, or adviser, the first document to read is the trust agreement.
Many clients are surprised to learn that, for example, New York Banking Law § 100 authorizes a trust company to act in a fiduciary capacity and to “receive, take, manage, hold and dispose of” trust property according to the terms of the trust.
The statute, however, DOES NOT expressly say that the trustee must protect (or has a duty to safeguard) trust assets from foreseeable account takeovers, deepfakes, or other cyber fraud schemes.
That should raise an obvious question: if New York does not clearly address those duties by default, what exactly do the default rules say in Delaware, South Dakota, the Cook Islands, Nevis, or another offshore jurisdiction?
From our experience, most settlors and beneficiaries have no idea.
To be sure, trust statutes establish guardrails. Delaware, for example, allows a trust instrument to modify a fiduciary’s powers, duties, standard of care, indemnification rights, and liability ([15], § 3303(a)).
New York goes even further. Under New York E.P.T.L. § 11-1.7, a provision that relieves a fiduciary from liability for failing to exercise reasonable care, diligence, and prudence is void as against public policy ([16]).
These statutory frameworks provide useful guidance.
However, they don’t fully address a critical modern question – does a trustee have affirmative duty to protect trust assets from AI-enabled fraud, account takeovers, or other cyber threats? And if those safeguards fail, is the trustee responsible?
That is why families should not rely on default rules.
If the settlor expects the trustee to follow specific cybersecurity procedures or pick-up the risk of loss due a cyber-event like an account-takeover, those expectations should be written directly into the trust agreement.
If your trust agreement does not address cybersecurity risks, Dilendorf Law Firm can help evaluate whether an amendment, decanting, or other trust modifications may be appropriate.
Likewise, if your trust has suffered losses as a result of a cyber incident, account takeover, or related fraud, please contact us to discuss your potential claims and evaluate your legal options.
What to do in the first 30 days
- Confirm your exposure. Liechtenstein instructed legal entities to notify their beneficial owners in writing, with letters going out since August 4, 2026; questions may be directed to the Office of Justice at vwbpfragen@llv.li ([1]). Ask your trustee or foundation council for a copy of the notice and a list of the data fields involved.
- Upgrade Security. CISA advises highly targeted individuals to use phishing-resistant FIDO security keys or passkeys. Review CISA guidance for more personal cybersecurity tips ([10]).
- Account Security. Increase security controls for bank and investment accounts. ,
- Review the trust instrument. Review trust agreements to understand trustee’s cyber responsibilities and who bears the risk of loss from an account takeover.
How Dilendorf Law Firm helps
Dilendorf Law Firm advises HNW individuals and family offices on offshore and domestic asset protection trusts. The firm reviews and updates existing trust structures to address modern cyber risks.
Where appropriate, it also represents settlors and beneficiaries in claims involving trustee misconduct, negligence and breach of fiduciary duties that resulted in cyber-related losses.
The firm helps HNW clients, family offices and investment managers prepare for cyber threats through tabletop exercises and incident-response planning.
Following a cyber incident, the firm works with the FBI’s IC3 and retired law enforcement cyber specialists on evidence preservation, fund recovery efforts, and communications with financial institutions and trustees.
If trust assets were transferred as a result of an account takeover, fraudulent instruction, or other cyberattack, and you believe the loss resulted from a trustee’s negligence, Dilendorf Law Firm can evaluate potential claims against the trustee and other responsible parties.
Contact Us
To discuss an offshore or domestic asset protection trust, a breach notice, or losses involving a trustee or custodian, contact Max Dilendorf at +1 212 457 9797 or info@dilendorf.com. You may also reach us through our contact page.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Frequently asked questions
How do I find out whether my family’s structure was affected by the Liechtenstein breach?
Ask the entity’s trustee, foundation council, or registered agent. The Liechtenstein government has directed legal entities to inform their beneficial owners of the personal data breach, with letters going out since August 4, 2026. It operates a dedicated inquiry address, vwbpfragen@llv.li, staffed by the Office of Justice ([1]). Because deleted entities were also affected, structures wound up years ago may still be included ([1]).
What personal information did the attackers get?
The government states the copied data includes the legal entity’s name and, for each beneficial owner, the role held, surname, first name, date of birth, nationality or nationalities, and country of residence ([1]). There is no indication that records were altered or deleted, and the government has not stated that the data has been publicly released ([1]).
How could criminals use a beneficial owner list against me?
The most likely uses are impersonation and social engineering. FinCEN reports that criminals pair stolen personally identifiable info with AI-generated data to create fake identities that could defeat bank verification controls ([7], pp. 2–3). Knowing the exact entity a family controls also makes a fraudulent trustee, banker, or lawyer email far more convincing. Business email compromise produced $3.05 billion in reported U.S. losses in 2025 ([8], p. 8).
Should I update, move, or terminate my Cook Islands or Nevis trust after the Liechtenstein breach?
Not automatically, and not without reading the deed first. The breach shows that identity data behind offshore structures is a target. Practical question becomes is whether your instrument tells the trustee how to verify instructions and what to do after a breach notice. Depending on the deed and the governing law, trust agreement could be fixed by amendment, protector action, decanting, etc.; a wind-down is a last resort that must be coordinated with U.S. tax and reporting obligations. Offshore asset protection trust attorney should review the instrument before any asset moves. Contact Dilendorf Law Firm for a consultaiton.
Can I sue my offshore trustee if it wired trust funds to a fraudster?
Possibly, depending on the facts. The trust instrument and governing law decide most of these cases. Delaware lets an instrument vary a fiduciary’s “standard of care, rights of indemnification and liability” but not excuse “wilful misconduct” ([15]), and New York voids clauses that exonerate a fiduciary “from liability for failure to exercise reasonable care, diligence and prudence” ([16]). Offshore statutes often allow broader exculpation, and Delaware bars claims one year after an adequate trustee report ([17]), so timing and evidence preservation matter.
Is my U.S. beneficial ownership information also exposed?
Not through FinCEN’s register, based on current rules. FinCEN’s March 2025 interim final rule, finalized on August 11, 2026, exempts all entities created in the United States and their beneficial owners from reporting; only certain foreign-formed companies registered to do business in a U.S. state remain reporting companies ([12]). Your exposure in the United States comes mainly from public adviser filings and from your own advisers’ systems, not from a federal ownership database.
What are the warning signs of an attack that uses this data?
Watch for unexpected contact that references your specific foundation, trust, or company by name; requests to change wire instructions or add a signatory; new devices or logins on email and brokerage accounts; and a mobile phone that suddenly loses service, which can signal a number-porting attack. CISA recommends a carrier PIN precisely because porting a number is “a critical step in countering” account takeover ([10]).
What should I do in the first 48 hours after a suspicious wire or account change?
Contact the bank immediately and request a recall of the funds, then file a complaint at ic3.gov with the full transaction details ([8], p. 17). Complaints that meet IC3’s thresholds are routed to the Recovery Asset Team, and for foreign wires the International Financial Fraud Kill Chain is coordinated through FinCEN’s Rapid Response Team and FBI legal attachés ([13]). Preserve emails, call logs, and instruction records before anything is deleted.
What is a tabletop exercise and why would a family office need one?
A tabletop exercise is a facilitated discussion that walks decision-makers through a realistic incident, tests who does what, and exposes gaps before a real event. The Five Eyes agencies told organizations to “Test response plans, train and prepare teams, and assume breaches will occur” ([9]). CISA’s free packages include template objectives, scenarios, and discussion questions for ransomware, phishing, and insider threats ([11]). Dilendorf Law Firm runs these exercises for family offices and investment managers and tailors the scenarios to the family’s actual structures and counterparties.
When should I involve a lawyer?
Involve counsel as soon as you receive a breach notice, before any funds move. A lawyer can coordinate the response with trustees in multiple jurisdictions, preserve evidence in a form law enforcement can use, manage the IC3 filing and bank recall requests, and evaluate whether a bank, custodian, or trustee that honored a fraudulent instruction may bear responsibility, which depends on the facts and the governing agreements. Dilendorf Law Firm coordinates with IC3 and retired cybersecurity law enforcement specialists in these matters.
Sources
[1] Government of the Principality of Liechtenstein, “Cyberattack on the VwbP: latest information” (updated August 2026). https://regierung.li/text/16188/topics
[2] Government of the Principality of Liechtenstein, press release, “Following the cyberattack: security analyses completed” (August 19, 2026). https://www.regierung.li/medienportal-medium/16444/234754/0/medienmitteilung
[3] Government of the Principality of Liechtenstein, press release, “Krimineller Angriff auf das VwbP: Potenzielles Einfallstor identifiziert” (August 4, 2026). https://www.regierung.li/medienportal-medium/16182/234671/medienmitteilung
[4] U.S. Securities and Exchange Commission, Form ADV General Instructions, SEC 1707 (07-24), p. 12. https://www.sec.gov/files/formadv-instructions.pdf
[5] U.S. Securities and Exchange Commission, Form ADV Part 1A, Item 5.F, pp. 13–14. https://www.sec.gov/files/formadv-part1a_1.pdf
[6] 17 C.F.R. § 275.202(a)(11)(G)-1, Family offices (Legal Information Institute, Cornell Law School). https://www.law.cornell.edu/cfr/text/17/275.202(a)(11)(G)-1
[7] FinCEN, Alert FIN-2024-Alert004, “FinCEN Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions” (November 13, 2024), pp. 2–3. https://www.fincen.gov/system/files/shared/FinCEN-Alert-DeepFakes-Alert508FINAL.pdf
[8] FBI Internet Crime Complaint Center, 2025 Internet Crime Report, pp. 6–8, 17. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[9] National Security Agency, “Five Eyes Cyber Security Agencies Statement” (June 22, 2026). https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4523810/five-eyes-cyber-security-agencies-statement/
[10] Cybersecurity and Infrastructure Security Agency, “Mobile Communications Best Practice Guidance” (December 18, 2024). https://www.cisa.gov/sites/default/files/2024-12/guidance-mobile-communications-best-practices.pdf
[11] Cybersecurity and Infrastructure Security Agency, “CISA Tabletop Exercise Packages.” https://www.cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages
[12] FinCEN, “Beneficial Ownership Information Reporting” (final rule issued August 11, 2026, effective August 14, 2026). https://www.fincen.gov/boi
[13] FBI Internet Crime Complaint Center, “International Financial Fraud Kill Chain Process.” https://www.ic3.gov/Outreach/Brochures/IC3-FFKC_International.pdf
[14] FinCEN, “FinCEN Issues Final Rule to Postpone Effective Date of Investment Adviser Rule to 2028” (December 31, 2025). https://www.fincen.gov/news/news-releases/fincen-issues-final-rule-postpone-effective-date-investment-adviser-rule-2028
[15] 12 Del. C. ch. 33, Administrative Provisions, §§ 3302(e), 3303(a) (Delaware Code Online). https://delcode.delaware.gov/title12/c033/index.html
[16] N.Y. Estates, Powers and Trusts Law § 11-1.7 (New York State Senate). https://www.nysenate.gov/legislation/laws/EPT/11-1.7
[17] 12 Del. C. §§ 3585–3586, Limitations on actions against trustees (Delaware Code Online). https://delcode.delaware.gov/title12/c035/sc07/index.html
Regulated employers and government agencies increasingly ask about crypto holdings and activities on job applications, renewal forms, and background questionnaires.
The questions could appear straightforward, but for individuals who have been involved with crypto for several years, the answers get more complex.
A disclosure may involve multiple exchanges, offshore trading platforms, self-custody wallets, token investments, staking activities, or participation in crypto projects.
This article examines common situations that can make crypto-related disclosures challenging. It explains how Dilendorf Law Firm helps applicants provide accurate, complete, and defensible responses.
How Dilendorf Law Firm helps
Max Dilendorf has practiced in the cryptocurrency and digital asset space since 2017. He advises clients on crypto compliance matters involving the Bank Secrecy Act (BSA), securities laws, CFTC regulations, and FinCEN requirements.
Dilendorf Law Firm reviews the actual form language, reconstructs your crypto history from exchange records and blockchain data. It will help you draft answers that are truthful, complete, and consistent across employment, licensing and security-clearances. .
Where the underlying problem needs fixing, the firm works with your accountant on prior-year tax reporting, requests records and explanations from exchanges, and evaluates claims against platforms whose freezes or closures caused loss.
The firm has served as counsel of record in more than 130 crypto-related cybercrime arbitration matters before AAA, JAMS, and NAM, involving testimony from retired FBI law enforcement expert witnesses.
Depending on the nature of a client’s case, the firm regularly works with retired law enforcement experts from the FBI, U.S. Department of Justice (DOJ), and Department of Homeland Security (DHS) to provide expert witness support in crypto and regulatory matters, including issues arising from employment applications, background investigations, and professional license renewals discussed in this article.
Who gets asked about crypto, and why
Regulators treat crypto as investment property that can create conflicts of interest.
The U.S. Office of Government Ethics (“OGE”) determined in 2018 that crypto “property held . . . for investment or the production of income” must be reported on federal financial disclosure reports, naming the exchange or platform where it is held ([1]).
The same logic applies to private-sector job application/renewal forms.
Traders and analysts at hedge funds and registered investment advisers file holdings reports within 10 days of becoming an “access person.”
After that, the filing comes in every 12 months, plus quarterly transaction reports listing every account holding securities for them ([8]).
Registered representatives at broker-dealers certify on Form U4 that their answers are “true and complete to the best of my knowledge” and accept “a continuing obligation to amend and update” the form ([9]).
Federal employees, contractors, and clearance holders complete the Standard Form 86 (SF-86). This form asks, among other things, about foreign financial interests, self-employment, tax compliance, debts, and civil court actions ([10]).
Bank and fintech compliance staff face a statutory bar on anyone convicted of an offense involving “dishonesty or a breach of trust or money laundering” ([12]).
Five situations where the truthful answer gets complicated
Clients come to Dilendorf Law Firm with one of these fact patterns, and often with several.
1. An exchange closed or froze your account citing KYC or AML rules. Exchanges are money transmitters subject to anti-money-laundering programs and suspicious activity reports(“SAR”) filings ([3]).
Under SAR regulations, crypto exchanges “are prohibited from disclosing to a person involved in the transaction that a suspicious activity report has been filed” ([4]).
So as an exchange’s customer, you will never find out that the exchange filed SAR form with FinCen (unless you hear from FinCen directly – which hopefully will never be the case).
The CFPB has found that platforms “sometimes cite boilerplate user agreement language to absolve themselves of responsibility” for frozen accounts ([7]).
You are left with a closure notice (sometimes citing alleged violations of KYC/BSA regulations), no explanation, and a form asking whether any account was ever restricted.
2. Your crypto sits on a foreign exchange or in an offshore entity. The SF-86 asks if you have “EVER had any foreign financial interests (such as stocks, property, investments, bank accounts . . .)” under your direct control ([10]).
FinCEN explained that that a foreign account holding only virtual currency “is not reportable on the FBAR” today but that it “intends to propose to amend the regulations” to cover it ([5]).
How to list a non-U.S. exchange account depends on the form’s wording and your prior answers.
3. A past tax year never accounted for your crypto. Every Form 1040 filer must answer the digital asset question, and “taxpayers must report all income related to their digital asset transactions” ([6]).
The SF-86 separately asks whether, in the last seven years, you “failed to file or pay Federal, state, or other taxes when required by law” ([10]).
For example, an unreported staking reward or an unfiled amended return can turn a holdings question into a tax-compliance question.
4. Your holdings conflict with the job. OGE determined that because crypto and stablecoins are not publicly traded securities, “no de minimis exemption applies,” so an employee holding any amount may not work on a matter that could directly and predictably affect its value ([2]).
Fund codes of ethics impose pre-clearance and reporting duties of their own ([8]).
Deciding what to divest, disclose, or recuse from before the start date is a legal judgment.
5. You built, advised, or lost money in a crypto venture. Form U4 asks if you are “engaged in any other business either as a proprietor, partner, officer, director, employee, trustee, agent or otherwise” ([9]).
Moreover, the SF-86 requires all self-employment for ten years ([10]).
A token launch, a DAO role, or a mining operation belongs on those forms. The same could be true for aftermath of a hack or fraud: the SF-86 asks about judgments, liens, debts over 120 days delinquent, and any civil court action in ten years ([10]).
How to answer truthfully
Answer the questions that were actually asked. You should be disclosing information only that it responsive to the question; don’t characterize unexplained account closure as legal misconduct or violation unless the finding of law was actually made.
Gather the closure notice, statements, tax returns, and prior forms first, and check every new answer against every earlier one.
For example, the SF-86 guide warns that “responses to this form may be compared with your responses to previous SF 86 questionnaires” ([11]). Amend when facts change.
The stakes are high. Knowingly and willfully making a materially false statement in a matter within federal jurisdiction can result in criminal penalties, including up to five years’ imprisonment ([13]).
The the SF-86 warns that agencies “generally fire, do not grant a security clearance, or disqualify individuals who have materially and deliberately falsified these forms” ([10]).
Contact Us
To discuss a job application, renewal, clearance, or disclosure question involving crypto, contact Max Dilendorf at +1 212 457 9797 or info@dilendorf.com, or use our contact page.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Frequently asked questions
Do I have to disclose crypto holdings on a hedge fund job application?
Often yes, if you will be an “access person” of a registered investment adviser. The SEC’s code-of-ethics rule requires access persons to report their securities holdings within 10 days of joining, at least every 12 months afterward, and to file quarterly transaction reports, including the name of every broker, dealer, or bank holding securities for them ([8]). Whether a token is a reportable security depends on the facts, and many funds require reporting of all digital assets regardless.
My exchange closed my account citing KYC or AML rules. Do I have to report that?
It depends on the exact question, and the wording matters. Some forms ask only about holdings; others ask about accounts, investigations, or findings. Exchanges are money transmitters with anti-money-laundering and suspicious-activity-reporting duties, and they may not tell you whether a report was filed ([3], [4]). Answer the question asked, accurately, without guessing at the exchange’s reasons.
Is an exchange account closure the same as a finding of money laundering?
No. A closure is a private company’s decision under its user agreement, not a determination by a regulator or court. The CFPB has noted that platforms “sometimes cite boilerplate user agreement language to absolve themselves of responsibility” when consumers lose access to accounts ([7]). Forms that ask about convictions or pretrial diversion, such as the bank-hiring bar in 12 U.S.C. § 1829, address a different category of event ([12]).
Do federal employees and clearance holders have to report crypto?
Yes, subject to thresholds. OGE treats virtual currency as property held for investment and requires it to be reported when the holding exceeded $1,000 at the end of the reporting period or produced more than $200 of income, naming the exchange or platform ([1]). Because no de minimis exemption applies, any holding can require recusal from a matter that would affect its value ([2]).
Does crypto on a foreign exchange count as a foreign financial interest on the SF-86?
It may. Section 20A.1 asks whether you have “EVER had any foreign financial interests (such as stocks, property, investments, bank accounts . . .)” in which you have direct control or ownership ([10]). The form does not mention crypto by name, and FinCEN has said a foreign account holding only virtual currency is not currently reportable on the FBAR, although it intends to propose a rule change ([5]). How a non-U.S. exchange account fits depends on the facts, so get advice before answering.
I never reported crypto on an old tax return. Does that matter for a job application?
It can. The IRS requires every Form 1040 filer to answer the digital asset question and to report all income from digital asset transactions ([6]). The SF-86 asks whether you failed to file or pay taxes when required in the last seven years ([10]). Correcting prior returns before you sign the questionnaire is often the cleanest path, and counsel can coordinate that with your accountant.
Do I have to list a token project, DAO role, or mining operation on Form U4 or the SF-86?
Usually yes. Form U4 Section 13 asks whether you are “engaged in any other business either as a proprietor, partner, officer, director, employee, trustee, agent or otherwise,” including whether it is investment-related and how many hours you devote to it ([9]). The SF-86 requires all employment and self-employment for the past ten years without gaps ([10]). How to describe an informal or unincorporated crypto venture is a judgment call worth making with counsel.
What happens if I answer a crypto question wrong on a federal form or Form U4?
The consequences can be severe. Knowingly and willfully making a materially false statement to the federal government carries up to five years in prison ([13]), and the SF-86 warns that agencies “generally fire, do not grant a security clearance, or disqualify” applicants who falsify the form ([10]). Form U4 applicants acknowledge exposure to “administrative, civil or criminal penalties” for false or misleading answers ([9]). Honest mistakes should be corrected by amendment as soon as they are discovered.
Why hire an experienced crypto attorney for a job application question?
Because the answer turns on how exchanges, custody, tax reporting, and compliance programs actually work. Max Dilendorf has practiced cryptocurrency and digital-asset law since 2017, and Dilendorf Law Firm has been counsel of record in more than 130 cybercrime-related arbitration matters before AAA, JAMS, and NAM. The firm helps applicants address crypto questions on employment, licensing, clearance, and financial-disclosure forms, and it evaluates claims against exchanges when a freeze or closure causes loss.
Sources
[1] U.S. Office of Government Ethics, Legal Advisory LA-18-06, “Guidance for Reporting Virtual Currency on Financial Disclosure Reports,” June 18, 2018. https://www.oge.gov/web/oge.nsf/News+Releases/D9038B8D8DE24D88852585BA005BEC34/$FILE/LA-18-06.pdf
[2] U.S. Office of Government Ethics, Legal Advisory LA-22-04, “Application of the Securities and Mutual Fund Exemptions to Cryptocurrency, Stablecoins, and Related Investments,” 2022. https://www.oge.gov/web/oge.nsf/News+Releases/E116F1FD24F94BB3852588770058A0FA/$FILE/LA-22-04.pdf
[3] FinCEN, Guidance FIN-2019-G001, “Application of FinCEN’s Regulations to Certain Business Models Involving Convertible Virtual Currencies,” May 9, 2019. https://www.fincen.gov/sites/default/files/2019-05/FinCEN%20Guidance%20CVC%20FINAL%20508.pdf
[4] FinCEN, “Money Services Business (MSB) Suspicious Activity Reporting.” https://www.fincen.gov/money-services-business-msb-suspicious-activity-reporting
[5] FinCEN, Notice 2020-2, “Report of Foreign Bank and Financial Accounts (FBAR) Filing Requirement for Virtual Currency,” Dec. 2020. https://www.fincen.gov/system/files/shared/Notice-Virtual%20Currency%20Reporting%20on%20the%20FBAR%20123020.pdf
[6] Internal Revenue Service, IR-2023-12, “IRS: Updates to question on digital assets; taxpayers should continue to report all digital asset income,” Jan. 24, 2023. https://www.irs.gov/newsroom/irs-updates-to-question-on-digital-assets-taxpayers-should-continue-to-report-all-digital-asset-income
[7] Consumer Financial Protection Bureau, “Complaint Bulletin: An analysis of consumer complaints related to crypto-assets,” Nov. 10, 2022. https://files.consumerfinance.gov/f/documents/cfpb_complaint-bulletin_crypto-assets_2022-11.pdf
[8] 17 C.F.R. § 275.204A-1, Investment adviser codes of ethics (Legal Information Institute). https://www.law.cornell.edu/cfr/text/17/275.204A-1
[9] Form U4, Uniform Application for Securities Industry Registration or Transfer, as filed on SEC.gov. https://www.sec.gov/files/rules/other/nasdaqllcf1a4_5/f_formu4.pdf
[10] U.S. Office of Personnel Management, Standard Form 86, Questionnaire for National Security Positions (rev. Nov. 2016). https://www.opm.gov/forms/pdf_fill/sf86.pdf
[11] Defense Counterintelligence and Security Agency, “Completing your Investigation Request in e-QIP: Guide for the Standard Form (SF) 86,” July 2018. https://www.dcsa.mil/Portals/128/Documents/pv/mbi/standard-form-sf-86-guide-for-applicants.pdf
[12] 12 U.S.C. § 1829, Penalty for unauthorized participation by convicted individual (Legal Information Institute). https://www.law.cornell.edu/uscode/text/12/1829
[13] 18 U.S.C. § 1001, Statements or entries generally (Legal Information Institute). https://www.law.cornell.edu/uscode/text/18/1001
Asset protection trusts (domestic and offshore) were designed to keep assets away from creditors.
In 2026, a different question is becoming just as important: can the trustee protect those assets from cybercriminals?
If a criminal gains control of the trust’s bank, brokerage, or custody account, who bears the loss? Does the trustee absorb that risk, or do the beneficiaries?
These issues are best addressed in the trust agreement from the outset. Waiting for a judge or arbitrator to determine responsibility after trust assets have been compromised is a far less desirable outcome.
Why the Question Matters Now
The threat to trust accounts is no longer theoretical. The federal agencies that track the evolving AI risks are measuring the timeline in months.
On June 22, 2026, the Five Eyes cyber security agencies, led by the National Security Agency (“NSA”), warned that:
“Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months. In this environment, cyber resilience is integral to advancing business continuity, market confidence, and long-term value” ([1]). [emphasis added]
The same statement calls cyber risk “a core business risk and leadership responsibility,” and a trustee holding a family’s liquid wealth is exactly the kind of leader it is addressing ([1]).
The Federal Bureau of Investigation (“FBI”) Internet Crime Complaint Center (IC3) recorded $20.877 billion in reported losses for 2025, including $3,046,598,558 from business email compromise and roughly 4,700 account-takeover complaints totaling $359.7 million ([2]).
Family offices and investment managers are exposed for a structural reason. Form ADV (including the adviser’s business, ownership, clients ) is published on the Securities and Exchange Commission’s (“SEC”) Investment Adviser Public Disclosure website. This is a public domain of who manages significant wealth ([14]).
What New York and Delaware Law Say
Neither New York nor Delaware imposes a specific statutory duty on trustee to safeguard trust accounts against cyberattack or account takeover. Both rely on general prudence standards that written before frontier AI existed.
New York. The Estates, Powers and Trusts Law (EPTL) § 11-2.3 requires a trustee to “exercise reasonable care, skill and caution” as “a prudent investor would,” judged by “facts and circumstances prevailing at the time of the decision or action” ([3]).
The section appears to apply to investments held on or after January 1, 1995. It does not mention anything about cybersecurity standards. It just says that: “A trustee shall exercise reasonable care, skill and caution to make and implement investment and management decisions as a prudent
investor would for the entire portfolio…” ([3])
Banking Law § 100 lists a trust company’s fiduciary powers without imposing any affirmative safeguarding duty ([4]).
In our arbitration practice, a trustee has taken the position that under the NY Banking Law § 100, a trustee does not have an express duty to safeguard trust assets against a foreseeable account takeover.
New York does, however, void any attempt to exonerate an inter vivos or testamentary trustee “from liability for failure to exercise reasonable care, diligence and prudence” ([5]). But the question becomes – what’s reasonable in the agentic AI era?
Delaware. Title 12, § 3302(a) requires a fiduciary to act “with the care, skill, prudence and diligence under the circumstances then prevailing that a prudent person acting in a like capacity and familiar with such matters would use” ([6]).
The section’s history note runs from the Delaware Code of 1915 through later amendments. None of the amendments added anything relating to cybersecurity, account security, or safeguarding ([6]). A prudent-person standard that was initially drafted in 1915 now has to be applied to AI cyber threats the NSA says is measured in months.
Delaware also lets the governing instrument “expand, restrict, eliminate, or otherwise vary” a fiduciary’s “standard of care, rights of indemnification and liability,” with a floor only at “wilful misconduct” ([7]).
A settlor who signs a trust-company form without reading that clause may have waived the right to recover a negligent cyber loss.
| Jurisdiction | Standard of care | May the instrument reduce it? | Express cyber or safeguarding duty? |
|---|---|---|---|
| New York | “reasonable care, skill and caution” as a “prudent investor” ([3]) | Not below reasonable care; exoneration void ([5]) | None found ([3], [4]) |
| Delaware | “care, skill, prudence and diligence under the circumstances then prevailing” ([6]) | Yes, down to a wilful-misconduct floor ([7]) | None found, including in the Qualified Dispositions in Trust Act ([6], [9]) |
Regulation Is Not Private Risk Allocation
A regulated trustee’s cybersecurity rules protect the institution and its regulator, not the settlor’s trust agreement. New York’s 23 NYCRR Part 500 requires every “covered entity” licensed under the Banking Law to maintain a cybersecurity program and use multi-factor authentication ([11]).
Those duties apply to the NY Department of Financial Services (“NYDFS”), not to a beneficiary, and an individual or family.
As a matter of fact, grantor, beneficiary or family can’t even asset a claim against a trustee based on alleged violation of NYDFS cybersecurity standards. Part 500 does not provide a private right of action.
A separate question is what cybersecurity requirements apply to a foreign trustee. The answer will depend on the laws and regulatory framework of the trustee’s jurisdiction. This is is one of many considerations for those evaluating offshore asset protection trusts.
The bank owes less than clients expect. Under Uniform Commercial Code (UCC) § 4A-202(b), an unauthorized wire is effective as the customer’s order if the bank’s security procedure was “a commercially reasonable method of providing security against unauthorized payment orders” and was followed in good faith ([10]).
The trustee, not the bank, is often the first and last line of defense.
A Public Yardstick for Trustee Cybersecurity
Settlors do not need to be technologists to measure a trustee.
The National Institute of Standards and Technology (“NIST”) Cybersecurity Framework (CSF) 2.0 organizes cybersecurity outcomes into six functions, “GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER,” and is “designed to be used by organizations of all sizes and sectors” ([12]).
The Cybersecurity and Infrastructure Security Agency (“CISA”) ranks multi-factor authentication types from strongest to weakest, with phishing-resistant MFA a distinct category from text-message codes ([13]).
Before signing, a settlor should ask the prospective trustee, in writing:
- Who bears the loss if an account is taken over despite your controls?
- How much cybersecurity insurance does the trustee have?
- Which NIST CSF 2.0 functions does your program map to ([12])?
- Is phishing-resistant MFA required for everyone who can move trust funds ([13])?
- How is a distribution request verified out of band before a wire is released?
Putting It in the Trust Agreement
If the statute is silent, then the trust agreement should define how risk of risk of loss is allocated.
Depending on the jurisdiction, a trust agreement could impose an express duty on the trustee to safeguard accounts, credentials, and digital assets. It could also place the risk of loss arising from account takeovers to the trustee (which is a reasonable approach given today’s threat environment).
It is no longer unusual for a trust to name a cybersecurity adviser together the investment adviser and administrative trustee (especially true where cryptocurrency is part of the estate).
Delaware’s directed-trust statute allows the instrument to give a person authority to direct or veto a fiduciary’s “investment decisions, distribution decisions or other decision of the fiduciary” ([8]).
The instrument should also say where a dispute will be heard.
Under the Federal Arbitration Act, a written arbitration provision in a contract involving commerce is “valid, irrevocable, and enforceable” ([15]). Settlors commonly designate American Arbitration Association (AAA) or JAMS arbitration in a U.S. venue so that a negligence claim is not litigated first in the trustee’s home forum.
Offshore Trusts Raise the Stakes
An offshore trustee can be excellent at creditor protection, but still be unexamined on AI cyber risks.
A Cook Islands trust is governed by the International Trusts Act 1984 and its amendments through 2013, published by the Cook Islands Financial Supervisory Commission ([18]). Notably, U.S. persons who fund foreign trusts must report those transactions on Internal Revenue Service (IRS) Form 3520 ([17]).
We believe many foreign trustees are still working out what the Five Eyes statement means for their business; that’s provided they’re even ware of the NSA report.
The client’s job is to know (before funding the trust) what legal mechanism operate between settlor and trustee if something goes wrong, because no one wants to litigate a negligence claim in Rarotonga.
Existing Trusts Are Not Frozen
An irrevocable trust can often be updated.
New York’s decanting statute, EPTL § 10-6.6, allows an authorized trustee to appoint principal to a new trust for the same beneficiaries ([16]).
Depending on the circumstances, decanting could be used to update a legacy trust by adding specific cybersecurity provisions and allocating the risk of cyber-related losses.
If your asset protection trust is governed by the laws of Wyoming, Delaware, South Dakota, or another jurisdiction, we can help evaluate if decanting is appropriate. Our team, which includes retired IC3 cybercrime specialists, can help structure and transfer trust assets to a new trust designed to address modern cybersecurity risks (including agentic AI cyber threats).
How Dilendorf Law Firm helps
Dilendorf Law Firm PLLC has been counsel of record in more than 130 cybercrime-related arbitration matters before AAA, JAMS, and NAM, including account-takeover and SIM-swap matters involving telecommunications carriers, cryptocurrency exchanges, and trust companies. That work, carried out alongside retired law enforcement and retired IC3 specialists, informs how the firm drafts domestic and offshore asset protection trusts for the age of AI cyber risk.
The firm drafts trust instruments with express safeguarding duties, cyber-loss risk allocated to the trustee, out-of-band verification for distributions, NIST- and CISA-benchmarked security schedules, cybersecurity adviser roles, and forum clauses. It conducts written cyber due diligence on prospective trustees, decants existing irrevocable trusts, and advises family offices, wealth managers, and investment managers on evolving risks.
Contact Us
To discuss a domestic or offshore asset protection trust, contact Max Dilendorf at +1 212 457 9797 or info@dilendorf.com.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Frequently asked questions
Can my trustee be held responsible if the trust’s account is hacked?
Possibly, but only if the governing law or the instrument imposes a duty the trustee breached. New York’s EPTL § 11-2.3 and Delaware’s § 3302 impose general prudence standards judged by circumstances then prevailing, and neither mentions account security ([3], [6]). An express safeguarding duty and risk-of-loss clause in the trust agreement removes that ambiguity.
What did the NSA and Five Eyes agencies actually say in June 2026?
They said frontier AI models will transform offensive and defensive cyber capabilities and that “the timeline is not years, it is months” ([1]). The statement frames cyber risk as a leadership responsibility rather than a technical issue, which is the standard a settlor should hold a trustee to ([1]).
Does Delaware law let a trust company limit its liability for a cyber loss?
Yes, within limits. Delaware § 3303 permits the governing instrument to vary a fiduciary’s standard of care and liability, but not to exculpate the fiduciary’s own wilful misconduct ([7]). A settlor should read the exculpation clause before signing.
Will the bank reimburse the trust for an unauthorized wire?
Not necessarily. Under UCC § 4A-202(b), an unauthorized payment order binds the customer if the bank’s security procedure was commercially reasonable and was followed in good faith ([10]). The trustee’s own controls therefore matter more than most clients assume.
What does it mean for a trustee to be NIST-aligned?
It means the trustee’s program maps to the six NIST CSF 2.0 functions: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER ([12]). NIST designed the framework for organizations of all sizes, so a small trust company cannot claim it does not apply ([12]).
Is a regulated trust company automatically safe?
No. Rules such as 23 NYCRR Part 500 require covered entities to maintain a cybersecurity program and use multi-factor authentication, but those duties run to the regulator ([11]). They do not allocate a cyber loss between trustee and beneficiary; only the trust agreement does that.
Can an existing irrevocable trust add cybersecurity duties?
Often, yes. New York’s EPTL § 10-6.6 allows an authorized trustee to decant principal into a new trust for the same beneficiaries ([16]), and Delaware gives broad effect to instrument terms that vary fiduciary duties ([7]). Whether a specific trust qualifies depends on its terms and jurisdiction.
How should disputes with an offshore trustee be handled?
Decide before funding. A written arbitration clause is enforceable under the Federal Arbitration Act ([15]), and settlors commonly select AAA or JAMS arbitration in a U.S. venue. Without such a clause, a negligence claim may have to be brought in the trustee’s home jurisdiction.
How does Dilendorf Law Firm approach trustee cybersecurity?
The firm has been counsel of record in more than 130 cybercrime-related arbitration matters before AAA, JAMS, and NAM and drafts domestic and offshore trusts with express safeguarding duties, risk-of-loss allocation, security schedules, and cybersecurity adviser roles. It also conducts written cyber due diligence on prospective trustees before the client signs.
Sources
[1] National Security Agency, Five Eyes Cyber Security Agencies Statement (June 22, 2026). https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4523810/five-eyes-cyber-security-agencies-statement/
[2] Federal Bureau of Investigation, Internet Crime Complaint Center, 2025 IC3 Annual Report, pp. 4, 6, 8, 12, 44. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[3] N.Y. Estates, Powers and Trusts Law § 11-2.3 (Prudent investor act). https://www.nysenate.gov/legislation/laws/EPT/11-2.3
[4] N.Y. Banking Law § 100 (Fiduciary powers). https://www.nysenate.gov/legislation/laws/BNK/100
[5] N.Y. Estates, Powers and Trusts Law § 11-1.7 (Limitations on powers and immunities). https://www.nysenate.gov/legislation/laws/EPT/11-1.7
[6] 12 Del. C. § 3302 (Degree of care; authorized investments). https://delcode.delaware.gov/title12/c033/index.html#3302
[7] 12 Del. C. § 3303 (Effect of provisions of instrument). https://delcode.delaware.gov/title12/c033/index.html#3303
[8] 12 Del. C. § 3313 (Advisers). https://delcode.delaware.gov/title12/c033/index.html#3313
[9] 12 Del. C. §§ 3570–3576 (Qualified Dispositions in Trust). https://delcode.delaware.gov/title12/c035/sc06/index.html
[10] Uniform Commercial Code § 4A-202 (Legal Information Institute, Cornell Law School). https://www.law.cornell.edu/ucc/4A/4A-202
[11] N.Y. Department of Financial Services, 23 NYCRR Part 500 (Second Amendment, Nov. 1, 2023). https://www.dfs.ny.gov/system/files/documents/2023/12/rf23_nycrr_part_500_amend02_20231101.pdf
[12] National Institute of Standards and Technology, The NIST Cybersecurity Framework (CSF) 2.0 (Feb. 26, 2024). https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
[13] Cybersecurity and Infrastructure Security Agency, More than a Password (MFA). https://www.cisa.gov/MFA
[14] U.S. Securities and Exchange Commission, Investor.gov, Form ADV. https://www.investor.gov/introduction-investing/investing-basics/glossary/form-adv
[15] 9 U.S.C. § 2 (Federal Arbitration Act). https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title9-section2&num=0&edition=prelim
[16] N.Y. Estates, Powers and Trusts Law § 10-6.6 (Decanting). https://www.nysenate.gov/legislation/laws/EPT/10-6.6
[17] Internal Revenue Service, About Form 3520. https://www.irs.gov/forms-pubs/about-form-3520
[18] Cook Islands Financial Supervisory Commission, Legislation (International Trusts Act 1984 and amendments). https://www.fsc.gov.ck/public/content.aspx?cn=legislation
Common wire fraud fact pattern: U.S. company receives an email from a vendor that appears to be ordinary, requesting that it update its bank details before the next payment.
The controller then wires $500,000. Two days later, the vendor calls to ask where the money is.
The company contacts its bank. Bank issues a request to recall the funds.
Within a few hours, it receives a reply that the receiving bank has credited the money and that the account holder has already transferred it out in amounts ranging from $60,000 to $80,000.
There is now nothing left to return.
Business email compromise (“BEC”) is a type of fraud. The FBI’s Internet Crime Complaint Center (IC3) recorded 24,768 BEC complaints and reported losses of $3.05 billion in 2025. This makes it the second-most costly type of cybercrime ([1]).
By the 48-hour mark, when the first account has been emptied, the chances have decreased (although they have not disappeared completely).
Once the bank says that it can’t reverse the transfer, victim company should consider the following protective steps described in this post.
Why the bank can’t simply take the money back
According to Article 4A of the Uniform Commercial Code, once a payment order has been accepted, cancellation is not valid unless the receiving bank agrees to it. There is, however, a narrow exception in the case of unauthorized or mistaken orders ([11]).
Even if deceived, the company agreed to the wire. When the account number and the name do not match, the beneficiary’s bank as a general rule “may rely on the number as the proper identification of the beneficiary” ([12]). And that’s the big problem for the victim company.
A recall is a request (not a default right), and it applies only as long as the money remains in the first account.
However, by the time the victim realizes the fraud, the money is often long gone from that account.
The FBI continues to tell victims to make this request right away, together with “any necessary indemnification documents” ([1]). A request must be made; it is not the final step.
The money is not gone; it has moved
Criminals send the money stolen from victims via “money mules.” These mules get the money from the victims and send the funds to conspirators, many of whom are based overseas ([7]).
According to FBI data, the funds involved in BEC are being sent to over 140 different receiving countries, via intermediary banks in the United Kingdom, Hong Kong, China, Mexico, and the United Arab Emirates.
More and more are going into custodial accounts held by payment processors, peer-to-peer platforms, and crypto exchanges ([2]).
Batches ranging from $60,000 to $80,000 are intended to bypass banks’ AML filters.
Each of those transfers ends up in a different account at another bank, where it can be identified and, depending on the circumstances, frozen.
Step one: complete IC3 complaint
The FBI’s Recovery Asset Team (RAT) operates the Financial Fraud Kill Chain (“FFKC”). The FFKC works with banks, asking them to freeze fraudulent transfers. Dilendorf Law Firm works with retired FBI IC3 agents to facilitate processing of complaints with the IC3 unit.
In 2025, the RAT froze $679 million out of the $1.16 billion that criminals had attempted to steal, achieving a success rate of 58 percent ([1]).
For a company at hour 48, the FBI states that it “will expand the FFKC process beyond the initial recipient bank if information is provided during the FFKC initiation on ‘second hop’ transactions to other domestic or international accounts” ([1]).
FinCEN’s Rapid Response Program handles cases involving wires sent to foreign accounts and has assisted in the recovery of over $1 billion since 2015.
FinCEN says that it is most likely to interdict funds reported to law enforcement within 72 hours; however, it does not claim that recovery is impossible after that time ([3]).
Victims do not contact FinCEN themselves. Instead, they file a complaint with IC3 or the nearest Secret Service field office, providing all account and bank details for both parties along with a summary of the fraud ([3]).
A bare complaint only goes as far as the first account. One that includes all that the bank knows about the onward transfers allows the FBI to pursue the second hop.
Step two: push the banks to use their own tools
FinCEN’s advisory on BEC informs financial institutions that they have a duty to file a suspicious activity report “regardless of whether the scheme or involved transactions were successful.”
Furthermore, the fact that a recovery request has been made does not release them from that obligation ([4]).
Section 314(b) of the USA PATRIOT Act enables banks to share information with one another, benefiting from a liability safe harbor, regarding transactions which may involve fraud proceeds, such as those connected with wire fraud and “money mule” schemes ([5]).
You should ask the company’s bank in writing to activate both of these channels with the receiving bank and with each subsequent bank as it is identified.
Step three: the forfeiture route
Even after the first account has been emptied, the Department of Justice can trace and seize the stolen money and return it.
In a case in Massachusetts, a workers’ union sent $6.4 million via an email that had been spoofed by only one letter.
The government’s complaint states that the money passed “through a series of intermediary bank accounts,” some of it being routed to a cryptocurrency exchange and to banks in Hong Kong, China, Singapore, and Nigeria.
The investigators were still able to trace the funds to seven domestic accounts, seized them, and brought a civil forfeiture action worth about $5.3 million ([8]).
In a case in Florida, $2,462,000 that had been stolen through an email impersonating a vendor was seized, forfeited, and sent “back to the victim” ([9]).
The process involves remission and restoration as set out in 28 C.F.R. Part 9. A person qualifies as a victim if they have suffered a specific pecuniary loss as a direct result of the crime, and the petition must contain “documentary evidence of a specific pecuniary (i.e., monetary) loss and the date the loss occurred” ([6]).
A petitioner could be disqualified if they have recourse to other reasonably available assets or compensation, so the insurance and counterparty issues discussed below should be dealt with carefully ([6]).
Step four: identify every other pocket
Depending on the facts, a victim may have claims or leverage beyond the thief’s accounts:
- The other party involved. FinCEN recommends that banks record which “compromised or impersonated parties” were involved, note whether auto-forwarding or inbox rules had been set, and indicate whether the authentication compromised was single-factor or multi-factor ([4]). When the vendor’s mailbox has been breached, the question of how to allocate the loss between the two companies is still an open one and will be decided by forensic evidence.
- The holders of the receiving accounts. The attachment statute in New York allows a court, on an appropriate showing, to attach the property of a defendant who is a nondomiciliary or foreign corporation, or one who “has assigned, disposed of, encumbered or secreted property” with the intent to defraud creditors ([14]). Civil proceedings directed at the identified holders of mule accounts can reach funds that have not been seized criminally.
- The company’s own bank. Under Article 4A, the risk of an unauthorized payment order is allocated in accordance with the bank’s security procedure ([13]). Where the customer has authorized the wire, the claim is less extensive, but it still needs to be examined.
- Insurers. Make sure that every policy which could possibly respond to the loss is notified promptly.
- Taxes. The IRS regards money taken “through fraud or misrepresentation” as stolen, and the loss can be deducted in the year the theft is discovered, but not so long as there is “a claim for reimbursement with a reasonable prospect of recovery” ([15]).
Preserve the evidence
The Secret Service states that “any delays will decrease the likelihood of financial recovery” and advises victims to “maintain records of all potential evidence” ([10]).
Victims should not wipe the devices in question. They must export the full email headers and obtain the mailbox audit logs before the retention periods expire.
How Dilendorf Law Firm helps
Dilendorf Law Firm has arbitrated over 130 cases involving cybercrime and represents victims of business email compromise both in the United States and overseas.
If a bank recall fails, we will work with you on filing the IC3 complaint with the details that the Recovery Asset Team requires.
Through our team of retired IC3 expert witnesses, we contact the FBI and the Secret Service on your behalf, both for U.S. and for non-U.S. companies.
Dilendorf Law Firm also works with retired IC3 law enforcement investigators who can help trace funds and determine which network (the company’s internal systems or the counterparty’s network) was breached.
We apply pressure on the banks through the 314(b) and SAR channels and submit remission and restoration petitions whenever funds are seized.
Contact US
At Dilendorf Law Firm, we represent U.S. and non-U.S. companies whose wires have been diverted through business email compromise, from the first IC3 complaint through tracing, bank negotiations, and forfeiture petitions.
Where appropriate, we may pursue claims against counterparties, account holders, and financial institutions.
You can reach us at +1 212 457 9797 or by email at info@dilendorf.com.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Frequently asked questions
Frequently asked questions
Should the money be considered lost if the receiving bank says the account is empty?
It does not have to be. When a complaint points out “second hop” transactions to other accounts, the FBI’s Recovery Asset Team will carry forward its freeze requests “beyond the initial recipient bank” ([1]).
For example, in a case from 2024, a BEC wire for $6.4 million was traced via intermediary accounts to seven domestic accounts, and the government asked for the forfeiture of about $5.3 million ([8]). The results depend on how quickly action is taken and on how complete the information provided is.
What prevents my bank from simply cancelling the wire?
The law regards an accepted wire as final. After the beneficiary’s bank has accepted the payment order, cancellation will not take effect unless the receiving bank agrees or a rule of the funds-transfer system permits it, with a limited exception in the case of unauthorized or mistaken orders ([11]).
A bank which pays into the account number stated on a wire can generally rely on that number even if the name does not match ([12]). A recall is a request which the receiving bank may choose to carry out if the funds still exist.
Can you still file with IC3 after 48 hours?
Yes. FinCEN is most likely to recover funds reported within 72 hours, meaning that hour 48 falls within that time frame, and neither FinCEN nor the FBI says that reporting later is pointless ([3]).
The FBI urges victims to file a report “regardless of the amount lost” and to include all details about the transactions ([1]). You should file the report immediately and then add further information as the banks provide details about subsequent transfers.
What information should the complaint include?
When a wire is sent overseas, FinCEN requires the name and account number of the victim, the name and home country of the victim’s bank, a summary of the fraud, the name and account number of the beneficiary, the beneficiary’s bank and country, and the amount, date, and currency of the transfer ([3]).
You should also include any details concerning second-hop accounts that your bank has obtained, so that the FBI can ask for downstream freezes ([1]).
What action can banks take that I myself cannot?
Banks are allowed by law to exchange information with one another regarding proceeds suspected to be the result of fraud, thanks to a legal safe harbor. FinCEN’s Section 314(b) guidance covers wire fraud and “money mule” schemes, and it does not require the bank to have previously identified the specific funds that have been laundered ([5]).
Furthermore, banks are required to file suspicious activity reports in the case of BEC whether or not the wire transaction was successful ([4]). Therefore, you should request in writing that your bank make use of both methods.
How can a victim recover their money after the government has seized it?
By means of remission or restoration as provided in 28 C.F.R. Part 9. The U.S. Attorney’s Office informs known victims, who then submit a petition together with “documentary evidence of a specific pecuniary (i.e., monetary) loss and the date the loss occurred” ([6]).
A victim who has “recourse to other reasonably available assets or compensation” may be deemed ineligible ([6]). In the 2023 Florida BEC case, $2,462,000 was forfeited and paid over to the victim ([9]).
Should I take the people whose accounts were credited with the money to court?
It depends on the specific circumstances. People who act as money mules receive the funds obtained through fraud and pass them on to the offenders, and in some cases they know precisely what they are doing ([7]).
Under New York law, it is possible to attach a defendant’s property if the defendant is not a resident of the state or has disposed of or hidden the property with the intention of defrauding creditors ([14]). Whether it is worthwhile to proceed with a civil action depends on who the account holders are and what is left.
May the company write off the loss?
Yes in general, but the timing is important. The IRS considers money obtained “through fraud or misrepresentation” to be stolen and allows the deduction of theft losses in the year that the theft is discovered ([15]).
If there is “a claim for reimbursement with a reasonable prospect of recovery,” the loss is not recognized until there is reasonable certainty that the reimbursement will not be received ([15]). It is necessary to coordinate the recovery effort with the company’s tax advisers.
At what stage should a lawyer become involved?
As soon as the bank reports that the recall has failed. The company then begins to manage a number of parallel initiatives: the IC3 complaint and second-hop tracing, bank-to-bank information sharing, evidence preservation, possible forfeiture petitions, and any potential claims against a counterparty or account holders.
Dilendorf Law Firm takes charge of all of these actions, including coordination with the FBI and the Secret Service whether the company is based in the U.S. or not, retired law enforcement forensics, and assessment of claims against banks and other parties.
Sources
[1] FBI Internet Crime Complaint Center, 2025 Internet Crime Report, pp. 7–9, 17. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[2] FBI IC3, PSA I-091124, “Business Email Compromise: The $55 Billion Scam,” Sept. 11, 2024. https://www.ic3.gov/PSA/2024/PSA240911
[3] FinCEN, Rapid Response Program Fact Sheet, Apr. 15, 2026, pp. 1–2. https://www.fincen.gov/system/files/2026-04/RRPFactSheet.pdf
[4] FinCEN, Advisory FIN-2019-A005, “Updated Advisory on Email Compromise Fraud Schemes,” July 16, 2019, pp. 9–10. https://www.fincen.gov/system/files/advisory/2019-07-16/Updated%20BEC%20Advisory%20FINAL%20508.pdf
[5] FinCEN, Section 314(b) Fact Sheet. https://www.fincen.gov/system/files/shared/314bfactsheet.pdf
[6] U.S. Department of Justice, “Returning Forfeited Assets to Crime Victims,” pp. 2–3, 6. https://www.justice.gov/file/440746/dl
[7] U.S. Department of Justice, Office of Public Affairs, “U.S. Law Enforcement Disrupts Networks Used to Transfer Fraud Proceeds, Taking Over 4,000 Actions,” Feb. 6, 2025. https://www.justice.gov/archives/opa/pr/us-law-enforcement-disrupts-networks-used-transfer-fraud-proceeds-taking-over-4000-actions
[8] U.S. Attorney’s Office, District of Massachusetts, “United States Files Forfeiture Action To Recover Over $5 Million From Business Email Compromise Scheme Targeting Massachusetts Workers Union,” June 5, 2024. https://www.justice.gov/usao-ma/pr/united-states-files-forfeiture-action-recover-over-5-million-business-email-compromise
[9] U.S. Attorney’s Office, Middle District of Florida (published by U.S. Secret Service), “United States Recovers $2.4 Million Obtained In Business Email Compromise,” Oct. 31, 2023. https://www.secretservice.gov/newsroom/releases/2023/10/united-states-recovers-24-million-obtained-business-email-compromise
[10] U.S. Secret Service, “Understanding Business Email Compromise.” https://www.secretservice.gov/investigations/bec
[11] Uniform Commercial Code § 4A-211, Cancellation and Amendment of Payment Order (Cornell LII). https://www.law.cornell.edu/ucc/4A/4A-211
[12] Uniform Commercial Code § 4A-207, Misdescription of Beneficiary (Cornell LII). https://www.law.cornell.edu/ucc/4A/4A-207
[13] Uniform Commercial Code § 4A-202, Authorized and Verified Payment Orders (Cornell LII). https://www.law.cornell.edu/ucc/4A/4A-202
[14] New York Civil Practice Law and Rules § 6201, Grounds for Attachment (New York State Senate). https://www.nysenate.gov/legislation/laws/CVP/6201
[15] Internal Revenue Service, Publication 547 (2025), Casualties, Disasters, and Thefts, pp. 6, 8, 23. https://www.irs.gov/publications/p547
The most authoritative cyber warning of 2026 came on June 22, when the National Security Agency (“NSA”), joined by the cyber security agencies of the United Kingdom, Canada, Australia, and New Zealand, stated:
“Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months” ([1]). [emphasis added]
The agencies warned that AI is “shrinking the window between vulnerability discovery and exploitation” and state flatly that “Breaches will occur” ([1]).
For wealth managers and family offices holding digital assets, this warning highlights a complex network of risks rather than a single threat.
If you use an exchange, the user agreement typically assigns the risk of loss to you. If you choose self-custody, you are solely responsible for security.
If you use a trust or regulated custodian, their duty to protect your assets depends entirely on the terms of the governing document. Each arrangement should be reviewed carefully.
Exchanges: the loss is contractually yours
The FBI attributed the theft of approximately $1.5 billion from the exchange Bybit in February 2025 to North Korea ([2]).
In 2025 alone, the FBI received 181,565 complaints involving cryptocurrency with $11.366 billion in reported losses, up 22 percent from 2024 ([3]).
When customers report account takeovers, the Consumer Financial Protection Bureau found that companies “often” respond that transfers are irreversible and that “consumers are responsible for the security of their accounts” ([4]).
One platform cited terms stating the customer would not hold it liable for “equipment or software failures or malfunctions … security breaches and unauthorized access” ([4]).
In our experience, platform agreements routinely include clauses that shift losses to the customer if their device is compromised. Review these agreements proactively, before any incident occurs.
Self-custody: you are the security team
Hardware and browser wallets do not eliminate risk; instead, they transfer it to the holder.
A joint FBI, CISA, and Treasury advisory describes North Korean actors targeting “individual holders of large amounts of cryptocurrency” with trojanized applications whose fake “update” function installs malware that steals private keys ([5]).
The Federal Trade Commission is direct: if a wallet “is stolen or compromised,” you are “likely to find that no one can step in to help you recover your funds” ([6]).
AI-generated voice clones and deepfake video calls are already used to walk holders through the steps that drain a wallet ([7]). The NSA expects those tools to improve within months, not years ([1]).
Trusts and custodians: the duty is what the document says
Many families have placed digital assets in U.S. or offshore asset protection trusts with a professional trustee or a regulated custodian. This approach is often sound, but it does not provide automatic protection.
New York Banking Law § 100 gives trust companies fiduciary powers, including the power to “receive, take, manage, hold and dispose of according to the terms of such trust” the property entrusted to them ([8]).
The statute gives these powers; however, it does not contain any express duty to safeguard digital assets against foreseeable account takeovers or cyber attacks.
If that duty is not written into the trust agreement or custody agreement, you should expect the trustee will argue (in case of an account takeover or stolen funds from the trust) that the duty to safeguard does not exist.
The same considerations apply outside New York.
If the asset protection trust is established in South Dakota, Wyoming, or an offshore jurisdiction, do not assume that default rules impose the duties omitted by New York’s statute.
The trust agreement should clearly define the trustee’s responsibilities for safeguarding assets, including cryptocurrency and bank accounts, and specify the consequences of any breach in the age of agentic AI cyberattacks.
Regulators expect more of licensed custodians. DFS guidance issued September 30, 2025, to BitLicensees and limited purpose trust companies requires custodians to hold customer crypto only for custody and safekeeping and to segregate it on-chain and on their ledger.
It also requires trust companies to treat customers’ crypto as belonging solely to customers, and to disclose the customer’s property interest and any material sub-custodian risks ([9]).
These expectations are excellent, but they do not replace the need for enforceable contract terms and insurance.
What to check this month
1. Exchange and platform agreements: locate the loss-allocation, device-compromise, and arbitration clauses ([4]).
2. Trust and custody agreements, in every jurisdiction: confirm an express duty to safeguard digital assets, a defined security standard, and remedies for breach (given NSA’s June 22, 2026 warning concerning agentic AI cybercrime).
3. Trustee and custodian insurance: confirm coverage, limits, and exclusions for cyber theft, and whether your assets are within the covered class.
4. Key control: document who holds keys, who can authorize transfers, and what verification is required ([9]).
5. Incident plan: know that the first report goes to the FBI’s IC3 with wallet addresses, transaction hashes, amounts, and timestamps ([10]).
How Dilendorf Law Firm helps
We have addressed each of the issues described above. Dilendorf Law Firm has arbitrated more than 130 cyber crime cases involving custody disputes and represents clients in all types of crypto compromise cases, including (i) assigning retired law enforcement agents, (ii) tracing stolen assets, (iii) investigating intrusions, and (iv) arbitrating claims against custodians, trust companies, and exchanges. We know the attack vectors used against wallets, exchanges, trustees, and custodians, and the defenses each raises afterward. On the prevention side, working with retired IC3 cybercrime specialists, we design asset protection trusts for cryptocurrency and negotiate custody and trustee agreements that state the duty to safeguard expressly. We also help clients verify a trustee’s insurance limits and plan secure transfers of assets from one wallet or custodian to another, using the services of retired IC3 cybercrime specialists. The NSA has emphasized the urgency of this issue. All trust, bank, and custody agreements should be reviewed promptly.Contact US
At Dilendorf Law Firm, we advise wealth managers, family offices, and individual holders on the custody of digital assets held on exchanges and in self-custody wallets.
We also help clients complete due diligence on onshore and offshore trustees and regulated custodians in New York and other U.S. jurisdictions.
If your crypto has already been compromised, we assign retired law enforcement agents to trace and investigate the theft and arbitrate claims against exchanges, trust companies, and custodians.
Contact us at +1 212 457 9797 or email us at info@dilendorf.com.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Frequently asked questions
Does my exchange have to reimburse me if my account is hacked?
Usually the exchange will say no. The CFPB found that companies “often” tell consumers that transfers are irreversible and that consumers are responsible for account security, and some cite terms disclaiming liability for “security breaches and unauthorized access” ([4]). Whether that holds depends on the agreement and the platform’s own failures.Is a hardware wallet safer than a regulated custodian?
Neither is safe by default. U.S. agencies report state actors targeting both exchanges and “individual holders of large amounts of cryptocurrency” with malware that steals private keys ([5]). The better question is which model gives you an enforceable duty, insurance, and a recovery path if the attack succeeds.Does a New York trustee automatically owe a duty to protect crypto from hackers?
Not expressly. Banking Law § 100 grants powers to hold and manage property “according to the terms of such trust” and sets no cybersecurity standard ([8]). The duty to safeguard digital assets should be written into the trust or custody agreement, with a defined standard and remedies.What should a settlor check in an existing crypto trust?
Whether the trust is in New York, South Dakota, Wyoming, or offshore, confirm the trustee has an express duty to safeguard digital assets, review the security standard and key-control provisions, and verify that the trustee’s insurance covers cyber theft with limits adequate for the holdings. DFS expects licensed custodians to disclose segregation, the customer’s property interest, and sub-custody risks ([9]); ask your trustee for the same.Is crypto held with a custodian insured like a bank deposit?
No. The FTC states that crypto in accounts “is not insured by a government like U.S. dollars deposited into an FDIC insured bank account,” and that if the storage provider is hacked, “the government has no obligation to step in” ([6]). Any coverage is private and defined by the policy.What should be done in the first hours after a theft?
Report immediately to the FBI’s Internet Crime Complaint Center at ic3.gov or a local FBI field office, providing cryptocurrency addresses, amounts and asset types, dates and times, and transaction hashes ([10]). Preserve devices and messages. Be wary of anyone offering to recover funds for a fee, which the FBI warns may be another scam ([10]).How does Dilendorf Law Firm approach a custody engagement?
We start from the record of more than 130 arbitrated cyber crime custody disputes: what attacks succeeded, and what defenses exchanges, trustees, and custodians raised. For a compromise that has already happened, we assign retired law enforcement agents, trace and investigate, and arbitrate against the custodian, trust company, or exchange. For prevention, we review agreements and insurance, design or restate an asset protection trust with an express duty to safeguard, and plan secure transfers. Outcomes depend on the facts.Sources
[1] National Security Agency, “Five Eyes Cyber Security Agencies Statement,” June 22, 2026. https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4523810/five-eyes-cyber-security-agencies-statement/
[2] FBI Internet Crime Complaint Center, PSA “North Korea Responsible for $1.5 Billion Bybit Hack,” Feb. 26, 2025. https://www.ic3.gov/psa/2025/psa250226
[3] FBI Internet Crime Complaint Center, “2025 Internet Crime Report,” pp. 7–8, 52. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[4] Consumer Financial Protection Bureau, “Complaint Bulletin: An analysis of consumer complaints related to crypto-assets,” Nov. 2022, pp. 17–18, 20, 42–43. https://files.consumerfinance.gov/f/documents/cfpb_complaint-bulletin_crypto-assets_2022-11.pdf
[5] CISA, FBI, and U.S. Treasury, Joint Cybersecurity Advisory AA22-108A, “TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies,” Apr. 18, 2022 (updated Apr. 20, 2022). https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a
[6] Federal Trade Commission, “What To Know About Cryptocurrency and Scams.” https://consumer.ftc.gov/articles/what-know-about-cryptocurrency-scams
[7] FBI Internet Crime Complaint Center, PSA “Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud,” Dec. 3, 2024. https://www.ic3.gov/PSA/2024/PSA241203
[8] New York Banking Law § 100, Fiduciary powers (New York State Senate). https://www.nysenate.gov/legislation/laws/BNK/100
[9] New York State Department of Financial Services, Industry Letter, “Updated Guidance on Custodial Structures for Customer Protection in the Event of Insolvency,” Sept. 30, 2025. https://www.dfs.ny.gov/industry-guidance/industry-letters/il20250930-updated-guidance-custodial-structures
[10] FBI Internet Crime Complaint Center, PSA “FBI Guidance for Cryptocurrency Scam Victims,” Aug. 24, 2023. https://www.ic3.gov/PSA/2023/psa230824
