By MFJ Staff | Sources: FTC press release, and PYMNTS
Key takeaway: The FTC is now willing to permanently bar a payment processor from an entire merchant risk category, not just fine it, when screening failures let fraud schemes run at scale.
The Federal Trade Commission has permanently barred payment processor Humboldt Merchant Services from serving high-risk merchants and ordered it to pay $12 million, after finding the company knowingly processed payments for more than 1,000 shell companies fronting fraud schemes.
The FTC announced the settlement on September 8, 2026, resolving allegations that Humboldt kept approving and processing sham merchant accounts despite clear warning signs that the businesses behind them were scamming consumers.
According to the FTC’s complaint, Humboldt processed payments for shell companies fronting unauthorized billing and credit card laundering operations, including Legion Media, a scheme the FTC shut down in 2024 for billing consumers without their consent. The shell accounts Humboldt processed for racked up chargeback rates roughly 10 times higher than what credit card networks consider excessive, the FTC said.
The FTC also alleged Humboldt placed these high-risk accounts on lower-risk bank identification numbers (BINs) licensed to an affiliated entity, a move meant to make the transactions more likely to clear with cardholders’ banks and push more volume through the accounts.
“Humboldt was processing payments for companies despite red flags indicating they were scamming consumers,” said Katherine White, deputy director of the FTC’s Bureau of Consumer Protection.
Under the settlement, Humboldt is permanently barred from engaging in or assisting others in credit card laundering; processing payments for straw companies, merchants on Mastercard’s MATCH list, and merchants already facing law enforcement action; processing for e-commerce entities that use negative option billing, are new or lack past processing history, and operate solely out of third-party mailbox providers like UPS Stores; providing false or misleading information to obtain payment processing, including in merchant account applications; and assisting tactics meant to dodge fraud and risk monitoring, including load balancing.
Why it matters: For merchants, the case is a reminder that regulators are now treating lax merchant screening and BIN manipulation as enforcement priorities, not just theoretical compliance risk. A legitimate business banking with a processor that cuts corners on underwriting can end up lumped in with fraud fronts once a card network or regulator starts looking, which makes processor due diligence worth real scrutiny, not just a line item.
Source: FTC press release; PYMNTS












