Four days.
That is how much time passed between two Federal Trade Commission announcements involving payment processors in September.
On September 4, 2026, the FTC announced that Nuvei would pay $4.85 million to settle charges that the company opened and maintained payment processing accounts for merchants that the agency alleged Nuvei knew or should have known were engaged in deception.
On September 8, the FTC announced an action against Humboldt Merchant Services. Humboldt agreed to pay $12 million for consumer redress and, under the proposed order, would be permanently prohibited from processing for certain categories of merchants with heightened fraud risk.
These are different companies.
Different merchants.
Different alleged conduct.
Different orders.
So this is not an article arguing that the two cases are identical.
It is an article asking the payments industry to notice the pattern.
The FTC is not limiting its attention to the merchant accused of defrauding consumers.
It is looking upstream.
At the processor.
At the onboarding decisions.
At the monitoring.
At the warning signs.
At what the payment company knew, what it should have known, and what it did after the risk became visible.
That should have the attention of processors, PayFacs, sponsor banks, fintechs, marketplaces, merchant acquirers, and anyone else responsible for deciding who gets access to the payments system and whether they get to keep it.
First Came Nuvei
The FTC's September 4 announcement said Nuvei would pay $4.85 million to settle charges that it opened and maintained payment processing accounts for merchants the FTC alleged were engaged in deception.
One of the central examples in the complaint was Reimage, an offshore tech support business. According to the FTC, Nuvei processed more than $30 million in consumer payments for Reimage from 2017 through 2023.
The FTC also alleged that a Nuvei U.S. subsidiary opened and maintained merchant accounts for businesses accused of making false or baseless earnings claims, impersonating government tax authorities, and merchants that other processors or acquiring banks had previously terminated for excessive chargebacks or fraud.
The proposed order goes beyond the monetary payment.
Among other provisions described by the FTC, Nuvei is prohibited from certain deceptive processing practices and tactics intended to avoid fraud or risk monitoring programs. The order also requires screening and monitoring of existing and prospective clients, with enhanced review for certain categories and for clients whose chargeback rates cross thresholds set by the order.
That last part matters.
Because this is not just about whether a processor had a merchant application in the file.
It is about whether the risk program actually worked after the merchant was approved.
Four Days Later: Humboldt
Then came Humboldt Merchant Services.
On September 8, the FTC announced that Humboldt would pay $12 million and be permanently prohibited from processing for certain categories of merchants with heightened fraud risk to settle allegations that the company processed payments for merchants that defrauded consumers.
According to the FTC complaint, Humboldt processed for more than 1,000 merchants that the agency alleges were shell entities serving as fronts or pass-throughs for fraudulent companies involved in unauthorized billing schemes.
The allegations get more uncomfortable from there.
The FTC says Humboldt opened accounts despite red flags suggesting that merchants were shell companies. It also alleges those merchants typically generated chargeback rates almost ten times higher than what card brands consider excessive.
The complaint further alleges that Humboldt attempted to increase transaction approvals by placing sham merchant accounts on a lower-risk bank BIN used by an affiliated entity.
Under the proposed order described by the FTC, Humboldt would be prohibited from engaging in or assisting credit card laundering and from processing for several specified categories of merchants, including straw companies and certain merchants on the Mastercard MATCH list. The order also addresses misleading information in merchant applications and tactics designed to avoid fraud and risk monitoring, including load balancing.
Again, this is a different case from Nuvei.
But read the allegations side by side and the common question becomes difficult to miss.
What happens when a payment processor is confronted with evidence that a merchant may be abusing the payments system?
Payment Processors Are a Control Point
Fraudulent merchants need something very important in order to make money.
A way to get paid.
That makes the payments ecosystem a natural control point.
A fraudulent merchant can build a website.
It can buy advertising.
It can create shell entities.
It can change names.
It can change domains.
But if it wants to charge cards at scale, it needs access to payment infrastructure.
Somebody has to underwrite it.
Somebody has to board it.
Somebody has to provide a merchant account or otherwise facilitate acceptance.
Somebody sees the chargebacks.
Somebody sees the fraud indicators.
Somebody sees unusual changes in volume.
Somebody receives the alerts.
Somebody knows when another institution terminated the merchant.
Somebody has to decide whether the warning signs are acceptable, explainable, remediable, or a reason to shut the relationship down.
That is why these two FTC actions matter beyond the specific companies involved.
They reinforce the idea that the payments layer is not passive infrastructure.
It can be treated as part of the control environment around merchant fraud.
Underwriting Is Not "Approved"
Payments companies love a binary answer.
Approved.
Declined.
But merchant risk does not stop moving once somebody clicks the approve button.
A company can look legitimate at onboarding and deteriorate later.
Ownership can change.
Products can change.
Marketing practices can change.
Transaction volume can change.
Average ticket can change.
Chargeback rates can change.
Refund behavior can change.
Customer complaints can change.
Processing patterns can change.
The merchant you underwrote six months ago is not automatically the merchant you are processing for today.
That means underwriting is not a moment.
It is the beginning of a lifecycle.
Monitoring That Nobody Acts On Is Not Much of a Control
Most sophisticated payment organizations have monitoring.
That does not automatically mean they have effective monitoring.
A dashboard can generate an alert.
A report can show elevated chargebacks.
A risk system can identify unusual activity.
An analyst can open a case.
None of those things, by themselves, resolve the risk.
The harder questions are operational.
Who reviews the alert?
How quickly?
What evidence do they request?
What happens when the merchant's explanation does not make sense?
What happens when complaints continue?
Who has authority to restrict processing?
Who can suspend settlement?
Who can terminate the relationship?
What happens when revenue teams want to keep the merchant?
What gets escalated to the sponsor bank?
How is the decision documented?
A monitoring program is only as strong as the decisions it produces.
If every red flag results in another exception, another extension, another explanation, and another month of processing, the existence of the monitoring system will not be very comforting when somebody later asks why the relationship continued.
Chargebacks Are Not Just a Card-Brand Problem
Payments companies often think about chargebacks through a network-compliance lens.
Are we above a threshold?
Are we approaching a monitoring program?
What will the card brands do?
Those are valid questions.
But the Humboldt allegations are a reminder that high chargebacks can also be evidence of something more fundamental.
Consumers may be telling you that the merchant relationship itself has a problem.
A chargeback ratio is not merely a score to keep underneath a network threshold.
It is information.
So are refunds.
Complaints.
Fraud reports.
Merchant descriptor disputes.
Unexpected shifts in ticket size.
Rapid volume changes.
MATCH information.
Prior terminations.
Changes in websites or fulfillment practices.
None of these signals automatically proves fraud.
But a risk program should be able to show that signals were seen, investigated, understood, and acted upon appropriately.
"We Did Not Know" Is Different From "We Did Not Look"
No processor can guarantee that every merchant it boards will behave perfectly forever.
Fraudsters lie.
Documents can be falsified.
Companies change after onboarding.
Legitimate businesses can develop serious problems.
Risk management is not clairvoyance.
The issue is whether the control environment is designed to identify meaningful risk and respond when warning signs accumulate.
There is an important difference between a risk that could not reasonably have been identified and a risk that became obvious because nobody wanted to look too closely.
There is also a difference between having a policy and operating the policy.
If your underwriting standards say one thing but exceptions routinely override them, the exception process is part of your actual risk model.
If your monitoring system creates alerts that sit unresolved for weeks, that backlog is part of your actual risk model.
If your sales incentives reward volume without meaningful risk accountability, those incentives are part of your actual risk model.
If your sponsor bank only hears about a merchant after the problem becomes impossible to hide, that escalation process is part of your actual risk model.
Regulators, banks, networks, and plaintiffs do not experience your risk program as a PowerPoint deck.
They experience the decisions your organization made.
Sponsor Banks Should Be Paying Attention Too
These actions were against payment processors, but sponsor banks should not file them away as somebody else's problem.
Banks depend heavily on the quality of the underwriting and monitoring performed by their payment partners.
A PayFac, ISO, processor, marketplace, or embedded payments platform may perform much of the daily merchant-facing activity.
The bank still needs enough visibility to understand whether those controls are working.
That means asking harder questions than whether a policy exists.
Show me how merchants are risk-rated.
Show me the exception population.
Show me overdue monitoring cases.
Show me merchants approaching chargeback thresholds.
Show me how prior terminations and MATCH information are handled.
Show me high-risk categories and how enhanced diligence works.
Show me how quickly serious alerts reach the bank.
Show me who has authority to keep a questionable merchant processing and who has authority to shut it down.
The quality of merchant oversight should be visible in operating data, not just described in a compliance questionnaire.
Growth Teams Need to Understand This Too
Merchant risk is often treated like the department that says no.
That is a bad operating model.
Good risk teams help a payment company grow without accidentally building a book of business that can destroy the economics, reputation, bank relationships, or regulatory posture of the platform.
There will always be pressure around merchant approval.
Every declined merchant is lost revenue.
Every reserve requirement can make the deal harder.
Every additional diligence request adds friction.
Every termination costs volume.
But that framing only looks at one side of the equation.
A merchant that should never have been boarded can cost far more than the revenue it generated.
Chargebacks.
Consumer losses.
Sponsor-bank escalation.
Network monitoring.
Legal expense.
Regulatory action.
Remediation.
Reputation.
Executive distraction.
Suddenly that merchant account was not great revenue after all.
Two Cases Do Not Make a New Rule. But They Do Make a Signal.
It would be easy to overstate what happened here.
Two FTC actions do not mean every processor is about to receive an enforcement letter.
They do not create a new universal underwriting standard by themselves.
And the specific allegations and restrictions in each case matter.
But Nuvei on September 4 and Humboldt on September 8 are close enough together, and focused enough on payment-processing conduct, that the industry should pay attention.
The FTC's own language in both matters emphasizes the role payment companies can play in enabling or constraining merchant fraud.
That is the signal.
If you control access to payment processing, you are standing at an important point in the transaction chain.
The merchant may be the company interacting directly with the consumer.
But the processor, PayFac, acquirer, sponsor bank, or fintech may be the company that makes the transaction possible.
That creates responsibility.
The Question to Ask Now
Do not read these cases and ask only:
"Could that happen to us?"
Ask something more useful.
If one of our merchants became the subject of an FTC complaint tomorrow, could we explain why we boarded them, what we knew at the time, how we monitored them, every material red flag we received, what we investigated, what decisions we made, who approved the exceptions, and why we allowed processing to continue?
Could the sponsor bank tell the same story?
Could the records tell the same story?
If the answer depends on finding an old employee, reconstructing Slack messages, or saying that somebody probably reviewed an alert, the problem is not the regulator.
The problem is the control environment.
Nuvei and Humboldt are different cases.
But four days apart, they deliver one message worth hearing clearly:
Payment processors are not invisible plumbing when merchant fraud moves through the system.
Pay attention.