Washington, D.C. – AMP Global Clearing LLC, a registered Futures Commission Merchant, has been penalized by the Commodity Futures Trading Commission (CFTC) for failing to adequately protect customer data, resulting in a significant security breach. The CFTC issued an order on February 12, 2018, simultaneously filing and settling charges against the firm for lapses in its information systems security program (ISSP) between June 21, 2016, and April 17, 2017.
The investigation revealed that AMP neglected diligent supervision of critical ISSP provisions, leaving approximately 97,000 customer records and personally identifiable information vulnerable for nearly ten months. In April 2017, an unauthorized third party successfully accessed AMP’s IT network and copied the files. The third party subsequently contacted federal authorities, securing the data and informing AMP of its actions.
CFTC Director of Enforcement, James McDonald, emphasized the importance of data protection for firms handling sensitive information, stating, “Entities entrusted with sensitive information must work diligently to protect that information…the CFTC will work hard to ensure regulated entities live up to that responsibility.”
Specifically, the CFTC found that AMP failed to oversee its IT provider’s implementation of key ISSP components, including risk assessments of network access points, quarterly network vulnerability scans, firewall maintenance, and detection of unauthorized activity. A critical vulnerability existed in a network attached storage device (NASD), which remained undetected through three successive quarterly risk assessments. Public reports of similar NASD breaches at other organizations, including those using the same manufacturer as AMP, also failed to prompt corrective action.
As a result of the findings, AMP has been ordered to pay a $100,000 civil monetary penalty and cease and desist from violating CFTC regulations regarding diligent supervision. Additionally, AMP must submit two follow-up reports within one year, detailing its ongoing efforts to strengthen network security and ISSP compliance. The CFTC acknowledged AMP’s cooperation and remediation efforts during the investigation, which included providing key information.
Source: CFTC.gov
Related Federal Cases
- Usama Malik, Securities Fraud, N.J. 2021 · Virginia
- Thomas E. Delahanty II, Election Fraud Crackdown, Maine, 2016 · New Mexico
- Jensen Moors Pleads Guilty to Health Care Fraud, Lauderdale Lakes F… · Florida
- Jill Murray, Wire Fraud, D.C. 2024 · Washington
- Michelle Cho, Wire Fraud Conspiracy, DC 2023 · Washington

