Data last synced:
Last updated:
Tango Card, Inc., a company that supplies and distributes electronic rewards, settled with OFAC for $116,048.60 to resolve apparent violations of multiple U.S. sanctions programs. Due to deficient geolocation identification processes, Tango Card transmitted stored value products to individuals with Internet Protocol (IP) and email addresses associated with Cuba, Iran, Syria, North Korea, and the Crimea region of Ukraine, in apparent violation of the Cuban Assets Control Regulations, the Iranian Transactions and Sanctions Regulations, the Syrian Sanctions Regulations, the North Korea Sanctions Regulations, and Executive Order 13685.
Penalty Amount
$116,048.60
Enforcement Date
September 30, 2022
Rank in Top Penalties
#230
Tango Card serves two primary roles in the rewards life cycle. During the issuance process, it provides awards to recipients via email. During the redemption process, recipients click on a reward link within the email that enables them to use the rewards to make a subsequent purchase.
In February 2021, one of Tango Card's clients found that several reward recipient email addresses it had previously provided to Tango Card had top-line domains (TLDs) associated with sanctioned jurisdictions. Tango Card subsequently conducted a lookback review of its database for any similar occurrences involving email addresses previously provided by other clients, and also identified instances in which a reward recipient redeemed a reward issued by Tango Card from an IP address located in a sanctioned jurisdiction. In total, between September 2016 and September 2021, Tango Card transmitted 27,720 merchant gift cards and promotional debit cards, totaling $386,828.65, to individuals with email or IP addresses associated with Cuba, Iran, Syria, North Korea, or the Crimea region of Ukraine.
While Tango Card used geolocation tools to identify transactions involving countries at high risk for suspected fraud and had OFAC screening and Know Your Business mechanisms around its direct customers, it did not use those controls to identify whether recipients of rewards, as opposed to senders of rewards, might involve sanctioned jurisdictions.
These transmissions constituted apparent violations of § 515.201 of the Cuban Assets Control Regulations (CACR), 31 C.F.R. part 515; § 560.204 of the Iranian Transactions and Sanctions Regulations (ITSR), 31 C.F.R. part 560; § 542.207 of the Syrian Sanctions Regulations (SSR), 31 C.F.R. part 542; § 510.206 of the North Korea Sanctions Regulations (NKSR), 31 C.F.R. part 510; and Executive Order 13685, "Blocking Property of Certain Persons and Prohibiting Certain Transactions with Respect to the Crimea Region of Ukraine."
The statutory maximum civil monetary penalty applicable in this matter is $9,168,949,062. OFAC determined that Tango Card self-disclosed the Apparent Violations and that the Apparent Violations constitute a non-egregious case. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A, the base civil monetary penalty applicable in this matter equals the sum of one-half of the transaction value for each apparent violation, which is $193,414.33. The settlement amount of $116,048.60 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines.
This case demonstrates the importance of using relevant geographic information as part of an effective, risk-based sanctions compliance program, including the use of appropriate geolocation tools to identify transactions potentially involving sanctioned jurisdictions. In addition, while contractually obligating customers to comply with sanctions regulations can help mitigate risk, it does not obviate the need to impose other sanctions compliance controls when appropriate on a risk basis.
This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.
Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.
Archived on June 13, 2026
SHA-256: 9f7c8580128e0ef0672df3aac9eb27fd7d30eca9d77f00f1dca7ce425748bdc2