FINRA’s 2026: 7 Signals for Financial Crimes & Cybersecurity

FINRA’s 2026: 7 Signals for Financial Crimes & Cybersecurity

Panel discussion on stage at a Financial Crimes and Cybersecurity Conference with four speakers seated in blue chairs and a large blue backdrop featuring a lock icon and circuit graphics, MCG logo visible bottom left.
7 Signals from FINRA's 2026 Financial Crimes & Cybersecurity Conference | MCG Consulting
Cybersecurity & Financial Crime Compliance

7 Signals from FINRA's 2026 Financial Crimes & Cybersecurity Conference

What two days at the Conrad New York Downtown revealed about where financial crime and cyber risk are heading — and what broker-dealers can do about it.

On August 10–11, 2026, the financial-crimes and cybersecurity community gathered at the Conrad New York Downtown for FINRA's Financial Crimes & Cybersecurity Conference. Across sessions on account takeover, elder fraud, anti-money-laundering typologies, crypto, and securities enforcement, a handful of themes surfaced again and again. Here are the seven signals MCG Consulting took away — and what they mean for your firm's controls.

Account Takeover Fraud Elder Fraud Protection AML & BSA Modernization Crypto Compliance Risk AI in Fraud Detection

The 7 Signals

SIGNAL 01

Attackers Are Getting Past Authentication — Not Just Guessing Passwords

Account takeover (ATO) was a headline topic, and the conversation focused less on stolen passwords and more on how attackers defeat the controls meant to stop them: MFA-bypass techniques, MFA fatigue, and credential stuffing. Related attack methods came up too, including SEO poisoning and threat alerts tied to Salesforce/ShinyHunters activity.

Takeaway: Having MFA in place is no longer the finish line — how it's implemented and monitored matters.

SIGNAL 02

Collaboration Was the Throughline of the Entire Event

If one idea connected every session, it was that no single team or agency stops financial crime alone. The securities enforcement panel illustrated it directly, with the SEC, FBI, DOJ, and U.S. Attorney's Office working alongside FINRA — with regulatory versus criminal classification often decided jointly. The same message ran through references to the Financial Intelligence Fusion Center (FIFC) and its task force to claw back funds, and to industry resources like InfraGard and the Domestic Security Alliance Council (DSAC).

Takeaway: Internally, the refrain was blunt — teams "can't be siloed," and departments should be sharing information.

SIGNAL 03

Protecting Seniors and Vulnerable Investors Got a Dedicated, Practical Focus

An elder cyber-fraud workshop worked through real-world case studies and the tools available to respond. Recurring reference points included FINRA's Vulnerable Adult and Seniors Team (VAST), Rule 2165 temporary holds, Trusted Contact designations under Rule 4512, and the Securities Helpline for Seniors.

The cases surfaced practical red flags — a manufactured sense of urgency, communications arriving over unofficial platforms like WhatsApp, and suspicious message timestamps — as well as tools such as voice technology to detect diminished capacity and annual cognitive assessment considerations. Operation Shamrock came up as an example.

SIGNAL 04

AML and BSA Reporting Are Modernizing — and Being Reframed as Intelligence Sharing

The AML sessions returned to fundamentals under Rule 3310 (understand, detect, respond) while pointing to where the framework is heading. SAR filing was framed not just as compliance but as intelligence sharing. Speakers pointed to 314(b) voluntary information sharing, FinCEN's Section 311 authority to cut foreign firms off from the U.S. financial system, FinCEN advisories and alerts, and rapid-response coordination between the FBI and FinCEN.

"BSA modernization" was named directly as a theme to watch.

SIGNAL 05

Crypto Is Now Every Firm's Concern — Not Just Crypto Firms

A dedicated session made the case that firms should be alert regardless of whether they touch digital assets today. Topics ranged from wallets and custody questions to airdrops (described as a digital form of phishing), stablecoins, and mixers like Tornado Cash. Firms staking out crypto business lines inherit both the technology and its vulnerabilities — money mules, exploitation of disclosure-based filings, and reinvestment schemes among them.

Takeaway: The recommended posture is a strong frontline that reviews patterns and shares information across departments.

SIGNAL 06

AI Is Both a Weapon and a Tool

Generative AI was cited as an active ingredient in fraud schemes. At the same time, the discussion looked ahead to AI and data agents as a monitoring approach, weighed against traditional rule-based systems.

The message wasn't "AI is coming" so much as "AI is already on both sides of the table."

SIGNAL 07

The Strongest Defense Is Still the Human Layer — Plus Friction by Design

Emerging typologies underscored the stakes: the IC3 2025 report referenced $21 billion in losses, alongside market manipulation schemes (pump-and-dump and ramp-and-dump), check fraud/kiting, and identity theft.

The recommended countermeasures were as much cultural as technical: training, carrying a security mindset from personal life into the workplace (something as simple as a password manager), and deliberately building "speed bumps" — friction points and written supervisory procedures (WSPs) — into processes so fraud has more chances to be caught.

$21B IC3 2025 Reported Losses
Rule 2165 Temporary Holds for Seniors
Rule 3310 AML Program Requirements

The firms best positioned to respond aren't working in silos. They're collaborating across teams and agencies, treating reporting as intelligence, and designing friction into the places fraud tries to move fastest.

The Bottom Line

The 2026 conference painted financial crime as a shared, fast-moving problem — one where attackers exploit authentication, target seniors, move through crypto rails, and increasingly enlist AI.

For broker-dealers, the path forward isn't a single fix. It's a combination of tighter authentication monitoring, elder-fraud protocols under Rules 2165 and 4512, modernized SAR and BSA processes, crypto-aware surveillance, and a culture that treats every employee as part of the control environment.

Where Does Your Firm's Program Stand?

MCG Consulting helps broker-dealers translate conference-floor signals into working controls — from AML program reviews to WSP updates and cyber-risk assessments.

Talk to MCG Consulting →
WW

William A. White, Jr.

Sr. Consultant, MCG Consulting · Connect on LinkedIn

MCG Consulting · FINRA & SEC Regulatory Compliance Advisory · mcgcomply.com

Leave a Reply

Your email address will not be published. Required fields are marked *

Post comment