Iclg UK Imposes £4.7M Sanctions Penalty on Citibank for Russian Transactions
Article Content
- •OFSI imposed a £4.7 million penalty on Citibank for breaching Russian sanctions.
- •The penalty is the largest to date under UK sanctions against Russia.
- •Firms are urged to improve sanctions compliance to avoid enforcement actions.
On 11 August 2026, the UK's Office of Financial Sanctions Implementation (OFSI) imposed a £4.7 million penalty on Citibank for processing 970 payments totaling approximately £19.7 million to sanctioned entities between February 2022 and July 2025. This penalty marks OFSI's largest sanction against a Russian entity to date, reflecting the UK's intensified enforcement of sanctions following Russia's invasion of Ukraine. The case highlights the strict liability nature of UK sanctions enforcement, where penalties can be imposed without proving knowledge of the breach. The revised enforcement framework introduced in February 2026 includes new discounts for voluntary disclosure and cooperation, encouraging firms to enhance their sanctions compliance systems. As of now, firms are advised to strengthen their sanctions controls to avoid similar penalties.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Capstans Holdings in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What triggered the penalty against Citibank?
What are the implications of the revised enforcement framework?
How can firms avoid similar penalties?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…