SanctionsLookup

Data last synced:

PayPal, Inc. OFAC Settlement: $7.7M (2015)

Last updated:

PayPal, Inc., a licensed money services business, settled its potential civil liability for apparent violations of multiple sanctions programs by agreeing to remit $7,658,300 to the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC). The company processed 486 transactions totaling approximately $43,934 in apparent violation of the Weapons of Mass Destruction Proliferators Sanctions Regulations, the Iranian Transactions and Sanctions Regulations, the Cuban Assets Control Regulations, the Global Terrorism Sanctions Regulations, and the Sudanese Sanctions Regulations.

Penalty Amount

$7,658,300.00

Enforcement Date

March 25, 2015

Rank in Top Penalties

#43

Case Details

Type:
Entity
Name:
PayPal, Inc.
Country:
πŸ‡ΊπŸ‡Έ United States
Industry:
Payments
Address:
San Jose, California
Penalty amount:
$7,658,300.00
Base civil monetary penalty:
$17,018,443.00
Egregious case:
Partial
Apparent violations:
486
Voluntary self disclosure:
Yes
Case:
Settlement
Violation period:
September 16, 2009 to October 11, 2013
Program:
Weapons of Mass Destruction Proliferators Sanctions Regulations, 31 C.F.R. part 544 (WMDPSR)Iranian Transactions and Sanctions Regulations, 31 C.F.R. part 560 (ITSR)Cuban Assets Control Regulations, 31 C.F.R. part 515 (CACR)Global Terrorism Sanctions Regulations, 31 C.F.R. part 594 (GTSR)Sudanese Sanctions Regulations, 31 C.F.R. part 538 (SSR)
Enforcement date:
March 25, 2015

Nature of the Apparent Violations

For several years up to and including 2013, PayPal failed to employ adequate screening technology and procedures to identify the potential involvement of U.S. sanctions targets in transactions it processed. As a result, PayPal did not screen in-process transactions to reject or block prohibited transactions pursuant to applicable U.S. economic sanctions requirements.

The apparent violations span four country-based sanctions programs. Between December 17, 2010 and September 29, 2013, PayPal processed 98 transactions totaling $19,344.89 in apparent violation of the Cuban Assets Control Regulations, 31 C.F.R. part 515 (CACR). Between September 16, 2009 and October 11, 2013, PayPal processed 125 transactions totaling $8,257.66 in apparent violation of the Iranian Transactions and Sanctions Regulations, 31 C.F.R. part 560 (ITSR). Between November 29, 2009 and May 11, 2013, PayPal processed 94 transactions totaling $5,925.27 in apparent violation of the Global Terrorism Sanctions Regulations, 31 C.F.R. part 594 (GTSR). Between May 9, 2010 and August 19, 2013, PayPal processed 33 transactions totaling $3,314.43 in apparent violation of the Sudanese Sanctions Regulations, 31 C.F.R. part 538 (SSR). Each of these transactions either contained an explicit reference to a sanctioned country or a linked term (i.e., "Tehran," "Khartoum," "Cuba," "Iran," "Sudan," "Iranian," or "Cuban"), or involved a PayPal account in which the Specially Designated Global Terrorists Interpal or Kahane Chai had an interest.

Separately, between October 20, 2009 and April 1, 2013, PayPal processed 136 transactions totaling $7,091.77 to or from an account registered to Kursad Zafer Cire, an individual designated by the U.S. State Department on January 12, 2009 pursuant to Executive Order 13382, in apparent violation of the Weapons of Mass Destruction Proliferators Sanctions Regulations, 31 C.F.R. part 544 (WMDPSR). PayPal stated that its automated interdiction filter failed to identify Cire as a potential SDN match at the time of his designation because the filter was not "working properly." The filter subsequently flagged Cire's account five times between July 30, 2009 and November 16, 2009; on each occasion, separate PayPal Risk Operations Agents dismissed the alerts without requesting additional information to clear the potential SDN name matches. PayPal stated that this conduct did not comply with the MSB's internal policies and procedures for handling SDN name matches. On February 14, 2013, the filter flagged Cire's account a sixth time; a PayPal Risk Operations Agent created a case, restricted the account, and requested additional information β€” including a copy of Cire's passport showing a date of birth and place of birth identical to those of the SDN β€” but ultimately dismissed the match due to an apparent misunderstanding of why the filter had flagged the account for review. On April 3, 2013, the filter flagged Cire's account a seventh time, and PayPal appropriately blocked the account and reported it to OFAC.

How OFAC Determined the Penalty

OFAC determined that PayPal voluntarily self-disclosed all apparent violations. OFAC further determined that the apparent violations of the ITSR, CACR, GTSR, and SSR constitute a non-egregious case, and that the apparent violations of the WMDPSR constitute an egregious case. The base penalties for each program were: $9,672.45 (CACR), $4,129 (ITSR), $2,984.88 (GTSR), $1,657 (SSR), and $17,000,000 (WMDPSR), for a total base penalty of $17,018,443.

In determining that the WMDPSR violations were egregious, OFAC considered: (1) PayPal demonstrated reckless disregard for U.S. economic sanctions requirements when its interdiction software failed to identify Cire as a potential match to the SDN List for approximately six months after his designation, and when employees cleared name matches against Cire's account on six separate occasions prior to appropriately identifying and blocking the account β€” conduct that was particularly reckless with respect to transactions on or after September 3, 2009; (2) PayPal agents engaged in a pattern of conduct by repeatedly ignoring warning signs about potential matches to the SDN List; (3) PayPal provided economic benefit to Cire and undermined the integrity of the WMDPSR and its policy objectives; and (4) multiple PayPal Risk Operations Agents failed to adhere to the MSB's policies and procedures pertaining to SDN match escalation.

PayPal agreed to remit $7,658,300 to settle its potential civil liability.

Aggravating Factors

  • PayPal's management demonstrated reckless disregard for U.S. economic sanctions requirements in deciding to operate a payment system without implementing appropriate controls to prevent the system from processing transactions in apparent violation of OFAC regulations
  • PayPal management and supervisors knew of the conduct giving rise to the apparent violations
  • PayPal's conduct resulted in harm to U.S. sanctions program objectives, and the MSB provided economic benefit to Cire and undermined the integrity of the WMDPSR by operating an account and processing transactions on behalf of an SDN for approximately three-and-a-half years
  • PayPal's OFAC compliance program was inadequate to prevent the apparent violations

Mitigating Factors

  • PayPal hired new management within its Compliance Division, identified OFAC-related issues with regard to the MSB's payment system in 2011, and undertook various measures to strengthen PayPal's OFAC screening processes and measures, including steps to implement more effective controls
  • PayPal has not received a penalty notice or Finding of Violation in the five years preceding the earliest date of the transactions giving rise to the apparent violations
  • PayPal substantially cooperated with OFAC's investigation, including by submitting the relevant documents and information in a clear and organized fashion, answering numerous follow-up inquiries for information over the course of OFAC's investigation, and by entering into a statute of limitations tolling agreement and an extension to the agreement

Compliance Takeaways

The case illustrates how failures in automated screening technology can cascade into multi-program sanctions violations. PayPal's interdiction filter was not "working properly" at the time a customer was designated as an SDN, allowing transactions to proceed for approximately six months before the filter began flagging the account. Even once the filter properly identified the account as a potential SDN match, multiple Risk Operations Agents dismissed the alerts on six separate occasions without requesting additional information β€” conduct that did not comply with the MSB's own internal policies and procedures for SDN name match escalation. A seventh flag was required before the account was appropriately blocked and reported to OFAC. Management's decision to operate a payment system without implementing appropriate controls, and a compliance program that was inadequate to prevent violations across five sanctions programs simultaneously, were identified as separate aggravating factors. Conversely, PayPal's subsequent remediation β€” hiring new compliance management, identifying systemic issues, and implementing more effective controls β€” was credited as a mitigating factor, as was its substantial cooperation with OFAC's investigation throughout.

Official Source Documents

This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.

Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.

Archived on June 13, 2026

SHA-256: aa0cc51f7419541cadfafa8f11fe5857c702a131bf11a83b1223fa4d69f99ecc

More OFAC Cases