September 10, 2026
A payment processor doesn’t have to run the fraud itself to face liability for enabling it. On September 8, 2026, the FTC announced a proposed $12 million settlement with 5967 Ventures, LLC, doing business as Humboldt Merchant Services, over allegations that it kept processing payments for merchants it knew — or consciously avoided knowing — were fronts for fraud.
What Happened.
The FTC alleges Humboldt opened and maintained accounts for more than 1,000 merchants that were actually shell companies serving as pass-throughs for unauthorized billing schemes, including Legion Media, a company the FTC shut down in 2024. These accounts allegedly generated chargeback rates nearly 10 times higher than what card networks consider excessive — a red flag Humboldt allegedly saw and didn’t act on. Instead, the FTC alleges Humboldt tried to boost approval rates by routing the suspect accounts through a lower-risk bank identification number (BIN) belonging to an affiliated entity, making the transactions look safer to card-issuing banks than they were.
Under the proposed order — still pending approval from the U.S. District Court for the Eastern District of Michigan — Humboldt would pay $12 million for consumer redress and be permanently barred from processing payments for straw companies, merchants on Mastercard’s high-risk MATCH list, merchants already subject to law-enforcement action, and certain e-commerce businesses using only a UPS-style mailbox as their business address. Humboldt neither admits nor denies the allegations, and the case remains pending final court approval.
Why this Matters Beyond Payment Processing.
The core lesson isn’t really about payments infrastructure — it’s about what a business does after it discovers a red flag involving a customer, vendor, affiliate, or partner. Any company that works through third-parties — affiliate networks, lead generators, marketing platforms, vendors — faces the same exposure if it keeps supporting a partner after credible signs of fraud or deception appear. High complaint rates, unverifiable business information, or suspicious transaction patterns don’t stay “someone else’s problem” once you know about them.
CLIClaw Compliance Tip: Build a Red-Flag Response Process.
Monitoring only protects you if the warning signs it surfaces actually trigger action. Set up a documented process covering four steps:
-
Screen before onboarding — Review any new customer, vendor, or partner’s business identity, ownership, operating history, complaint history, and marketing practices before granting access to your systems or customer relationships. Apply deeper scrutiny to higher-risk categories (e.g., new e-commerce sellers with no processing history, or businesses using only a mailbox address).
-
Monitor after approval, not just at intake — Track chargeback rates, complaint volume, and transaction patterns on an ongoing basis. A partner that looked clean at signup can develop problems later.
-
Set escalation triggers in advance — Decide now what chargeback rate, complaint volume, or type of regulatory action automatically triggers investigation, suspension, or termination — don’t leave that decision to be improvised in the moment.
-
Document every decision — Keep records of the warning sign, who reviewed it, what evidence was considered, and what action was taken. If you can’t reconstruct why a decision was made, your compliance program has a gap even if the right call was made at the time.
Periodically test this process on your highest-risk partners: pick a few that generated unusual complaint or chargeback activity in the past year, and see if you can trace the full history — the red flag, the review, the decision, and the follow-up. If you can’t, that’s the gap to fix before a regulator finds it for you.
For operational guidance and structured compliance documentation tools, visit the CLIClaw Marketing Compliance Library.
© 2026 CLIClaw.com
This article is for information purposes only. It is not intended to be and should not be relied on as legal advice for any particular matter.