07/09/26

CRF fraudulent-account alerts: register, use, confidentiality

As banking scam techniques multiply and become more sophisticated (phishing, CEO fraud, vendor fraud, investment scams), the Luxembourg police counted 5,553 cases of fraud in 2025. These schemes often use one or more fraudulent accounts that can simultaneously target the clients of several institutions without other institutions being made aware.

The law of 22 July 2026 (the Law) aims to bridge this gap by giving the Luxembourg Financial Intelligence Unit (Cellule de Renseignement Financier, CRF) the legal basis to send alerts about these fraudulent accounts to credit institutions, professionals of the financial sector, payment institutions, electronic money institutions and crypto-asset service providers established in Luxembourg (Professionals).

Objective of the Law

The Law is primarily preventive: blocking banking and financial flows to identified fraudulent accounts before new victims are affected. It targets both large-scale scams (such as phishing campaigns) and scams aimed at specific victims using social engineering (such as CEO fraud and vendor fraud).

Process

Alerts are sent to Professionals who have requested to receive them via the secure goAML channel.

Information provided by the CRF will include (i) at-risk account numbers (such as IBANs, including virtual IBANs, and electronic money or crypto-asset accounts) and (ii) the types of fraud associated with them.

The CRF will hold meetings with Professionals at least every six months to adjust the relevance of alerts and continuously improve the mechanism.

Restrictions on data use

Professionals are subject to strict obligations regarding CRF alert data:

  • use the information solely for fighting money laundering, its predicate offences and terrorist financing (AML/CFT), notably when updating client risk assessments and strengthening monitoring of transactions linked to their accounts;
  • observe strict confidentiality, prohibiting them from revealing, directly or indirectly, the existence or content of an alert to the client concerned or to third parties; and
  • delete information received within a maximum of six months from receipt, or earlier when keeping it is no longer necessary for the prevention goal pursued.

Key points

The measure is formally optional: only Professionals who have registered with the CRF will receive alerts. In practice, refraining from registering raises serious regulatory risk, because alerts feed the AML/CFT risk-assessment tools that institutions are legally required to keep up to date.

An institution that has access to this information, chooses not to use it and nevertheless makes a transfer to a flagged account opens itself up to its due diligence obligations being called into question. The Council of State (Conseil d'État) itself highlights that failure to register would create a gap in the alert system. Consequently, Professionals will be de facto required to register.

The CRF does not guarantee the exactness of the information sent or of its uses. Professionals must assess, on their own liability, the follow-up given to each alert and, if necessary, put in place appropriate AML/CFT due diligence measures.

The Law does not provide a specific measure allowing a wrongly flagged account holder to contest an alert, especially as the non-disclosure rule means the client cannot be informed that an alert concerns them. A wrongly flagged account could therefore be subject to restrictive measures for up to six months. Ordinary-law remedies remain open, but the text provides no dedicated procedure.

What Professionals should do now

The Law entered into force on 8 August 2026. Arendt strongly recommends that Professionals carry out the following without delay:

  • register with the CRF alert mechanism via goAML and document this in their AML/CFT policy;
  • ensure that monitoring procedures and tools are compatible with CRF alert processing; and
  • integrate data taken from CRF alerts into AML/CFT due diligence and supervisory procedures.

How Arendt can help

If you have concerns about compliance, or if verifications or corrections prove necessary, contact Arendt & Medernach's Banking & Financial Services and Business Crime teams, as well as Arendt Regulatory & Consulting's Forensic Investigations, Corporate Intelligence & Litigation Support team regarding fraud detection mechanisms, so they can assist with making your entity compliant.

Authors:

  • Jean-Luc Putz, Partner at Arendt & Medernach
  • Sarah Houplon, Arendt & Medernach
dotted_texture