On September 2, 2026, the Financial Crimes Enforcement Network (FinCEN) and four other federal agencies—the Federal Reserve, the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), and the Office of the Comptroller of the Currency (OCC)—released a joint statement addressing long-standing uncertainty over what banks can tell their customers about suspected fraud. The statement clarifies that the confidentiality rules surrounding Suspicious Activity Reports (“SARs”) do not bar financial institutions from discussing potentially fraudulent transactions, other suspicious account activity, or impending account closures with affected customers. Although banks remain prohibited from disclosing the existence of a SAR itself, the agencies emphasized that the underlying facts, transaction details, and supporting documents on which a report is based may be shared freely. The guidance was prompted, in part, by public comments received in response to a June 2025 request for information on payments fraud, in which industry participants sought clearer boundaries around permissible customer communications.
By drawing a clear line between SAR filings and the factual information underlying them, the guidance enables banks and credit unions to engage more transparently with customers—for example, by notifying a customer that a deposit was rejected due to suspected fraud, asking about the purpose or source of funds, or warning customers about known money-mule schemes. The statement also aligns with Executive Order 14331, which calls for fair banking access for all Americans, and signals a broader regulatory push toward greater accountability and customer engagement in the fraud-prevention process. The agencies also stressed that the guidance does not impose any new legal or supervisory obligations but reaffirms the existing regulatory framework while encouraging institutions to take a case-by-case approach to customer communications.
FinCEN Press Release | Joint Statement