Regulatory · Enforcement Trend

The Off-Channel Fine Total Just Crossed $3.5 Billion — Telegram Is Named in the Same Sentence as WhatsApp and Signal

US regulators have fined financial firms over $3.5 billion combined for off-channel communications since 2021. The list of named platforms keeps including the same three apps. Here's what the trend actually shows.

Published August 7, 2026 8 min read By the MessengerKit team

Since 2021, US regulators have collected more than $3.5 billion in penalties from financial firms over off-channel communications, employees conducting business on messaging apps outside the firm's approved, archived, and supervised systems. The platforms named across these actions are consistently the same handful: WhatsApp, Signal, Telegram, and similar consumer messaging apps. The pattern is no longer a warning shot. It's an established enforcement category with its own track record.

The number, and how it got there

The SEC's own account of its initiative states that, since December 2021, it has brought charges against more than 100 firms and collected over $2 billion in penalties for off-channel communications failures. Layer in the parallel penalties CFTC, FINRA, and international regulators like Ofgem have issued against firms for the same underlying conduct, and industry trackers put the combined total north of $3.5 billion. That combined figure spans several regulators and several years, not one single sweep, and it's worth being precise about that rather than implying it's all one number from one source.

The 2022 sweep that set the pattern

The single largest coordinated action came in September 2022, when sixteen major Wall Street firms, Goldman Sachs, Morgan Stanley, Citigroup, Bank of America, Barclays, Deutsche Bank, UBS, and others, were fined a combined $1.1 billion for failing to maintain and preserve business communications sent over personal devices and unapproved apps. Fiscal year 2024 added over $600 million more across more than seventy firms, and a further wave in January 2025 fined twelve more firms a combined $63 million, showing the enforcement pattern extending well beyond the largest institutions to a much broader base of mid-size and smaller firms before the sweep's pace changed.

Why the same platforms keep getting named

WhatsApp, Signal, and Telegram show up repeatedly in these actions for a straightforward reason: they're the apps employees already have installed, already trust, and already default to when a quick message is faster than logging into an approved system. Regulators aren't targeting these platforms specifically, they're targeting the pattern of business communication migrating to whatever's convenient, and these three happen to be the most common landing spots.

The UK's Financial Conduct Authority has flagged the identical risk using nearly identical language, which signals this isn't a US-specific regulatory quirk, it's a shared recognition among financial regulators globally that consumer messaging apps are where recordkeeping controls are most likely to break down.

Why the obligation outlasts the enforcement wave

It's worth being straight about the recent trend: the SEC's large coordinated sweeps effectively paused in 2025 under new leadership, and the January 2025 wave of twelve firms is, so far, the last action of its kind. Some firms read that as the pressure being off. That reading misses what actually changed, and what didn't.

What changed is which regulator is doing the enforcing, and at what scale. What didn't change is the underlying rule: the recordkeeping requirements under the Exchange Act and the Advisers Act are exactly what they were in 2021, and FINRA has continued bringing individual, firm-level cases through its ordinary examination cycle rather than headline sweeps, including a $1.3 million sanction against Velox Clearing in June 2025 after a routine exam found over 10,000 unretained messages that the firm's own compliance team had flagged internally and never acted on, and an individual barred from the industry entirely in early 2026 over off-channel use. A quieter enforcement calendar is not the same as a closed case file, and a firm that treats 2025's pause as permission is building exposure that a future exam, a new SEC posture, or a state regulator can still surface.

What firms are actually supposed to do about it

The regulatory expectation isn't that firms ban messaging apps outright, that's proven unrealistic in practice. It's that any platform used for business communication needs to be captured, retained, and supervisable, the same standard applied to email and recorded phone lines for decades. A firm that can produce a complete, retrievable record of what was said on Telegram is in a fundamentally different position than one that can't, regardless of whether Telegram itself was ever formally "approved." The same exact-wording standard applies well outside securities regulation too, including debt collection, where regulation cares about the specific words used.

This is the specific gap MessengerKit closes for firms that have decided, realistically, that Telegram is where business communication is going to happen. Media Vault provides continuous, independently owned archiving of group history, and Watchtower surfaces compliance-relevant language in real time, so a firm's Telegram usage looks, from a recordkeeping standpoint, like an approved and supervised channel rather than an off-channel liability waiting to be discovered in the next enforcement sweep.

Frequently asked questions

Does this only apply to large financial institutions?

No, the trend from 2022 to 2024 shows enforcement broadening from the largest firms to a much wider range of mid-size and smaller ones. Firm size doesn't create an exemption from the underlying recordkeeping rules.

Is banning Telegram for employees a safer approach than governing it?

Bans are difficult to enforce in practice and don't address the underlying reason employees migrate to convenient apps in the first place. Most regulatory guidance points toward proper capture and retention of actual usage over prohibition that's hard to verify.

Does this enforcement trend apply outside the US?

The specific fines are US actions, but the underlying concern, unrecorded business communication on consumer messaging apps, is shared by regulators including the UK's FCA, and is a reasonable baseline expectation in most developed financial regulatory regimes.

Hasn't the SEC stopped bringing these cases?

The SEC's large coordinated sweeps have slowed since January 2025, but the recordkeeping rules themselves haven't changed, and FINRA has continued pursuing individual cases through routine exams. A quiet enforcement calendar isn't the same as the underlying obligation disappearing.