[HN Gopher] JPMorgan hit with $200M in fines for letting employe...
       ___________________________________________________________________
        
       JPMorgan hit with $200M in fines for letting employees use WhatsApp
        
       Author : hassanahmad
       Score  : 127 points
       Date   : 2021-12-18 14:52 UTC (8 hours ago)
        
 (HTM) web link (www.cnbc.com)
 (TXT) w3m dump (www.cnbc.com)
        
       | vmception wrote:
       | I don't actually like this dual agency enforcement action at the
       | same time, when Gary Gensler at the SEC was also chair of the
       | CFTC several years before.
       | 
       | Its really clear that he is coordinating this and making it more
       | likely to stick by splitting each cattle prod between the
       | agencies.
        
         | rp1 wrote:
         | This would be more convincing if you had specific reasons,
         | unrelated to the enforcement, that JPM shouldn't be punished
         | for this.
        
           | vmception wrote:
           | no, I don't, I think Gary Gensler is uniquely dangerous and
           | that the oversight is inadequate. Its not about JP Morgan.
           | Its about him exercising his craftily accumulated power.
           | Would have totally flown under my radar if it was just the
           | SEC for now, or just the CFTC for now. But the simultaneous
           | thing rings the alarms for me.
        
             | rp1 wrote:
             | Normally people say that power is being wielded dangerously
             | when the power is used to do something disagreeable. Simply
             | enforcing the law correctly doesn't seem dangerous to me.
        
               | aftbit wrote:
               | More perceptive people separately consider the means and
               | goals. Just because power is currently being used in a
               | way that you agree with does not imply that the power is
               | not dangerous. See "nothing to hide, nothing to fear" and
               | "think of the children" as distractions to keep people
               | complacent while excessive power is accumulated. After
               | that, the excuses become unnecessary and the power can be
               | used for any goal, aligned or unaligned with the people.
        
               | rp1 wrote:
               | You still haven't given an example of how coordinating
               | the two agencies can lead to a bad outcome. If all that
               | can be done is enforce the law, then there is no issue.
               | You keep implying something extra-legal can be done
               | through the coordination, but aren't providing any
               | specifics.
        
               | vmception wrote:
               | oh, context is important then. those agencies are
               | bullies. many times they operate under broad and
               | ambiguous fraud/compliance statutes that don't
               | specifically codify the infraction they disagree with.
               | this puts all market participants in a constant guessing
               | game with them, some more than others. so its Christmas
               | and they want a kickback before the end of the year,
               | whatsapp bro? send the money to our Miami field office,
               | kthxbai.
        
               | Barrin92 wrote:
               | that's a feature and not a bug because a regulatory
               | agency without leeway and too strict formal requirements
               | in reality has no ability to deal with actors who know
               | how to maneuver around them and is toothless.
               | 
               | That market participants don't know how far an agency can
               | go is equivalent to Israel's nuclear policy, little bit
               | of ambiguity and uncertainty has a deterrent effect. And
               | if anything given how routinely market participants still
               | abuse every little trick they can regulators aren't scary
               | scary enough.
               | 
               | And no offense but you've got "fintech, commodities and
               | digital assets" in your bio, are you by any chance making
               | money off some underregulated crypto scheme and have been
               | at the receiving end of regulatory action?
        
               | vmception wrote:
               | Hahaha good catch, no, have not been sanctioned by a
               | financial regulator :) like, I would be defensive about
               | that but its a routine question every financial
               | institution asks during onboarding or account creation
               | 
               | I've felt similarly about these agencies long before I
               | brushed against their purview
        
       | wfh wrote:
       | (do not work in finance so excuse the dumb question but) if there
       | is this requirement for all employee communications to be tracked
       | for compliance purposes, how are/were face to face meetings
       | recorded? Or just chatting in the corridor? Is that not allowed?
        
         | nata79 wrote:
         | They're required to keep minutes from face to face meetings for
         | compliance. Of course people still talk informally but they
         | need to know to constraint what they talk about in those
         | circumstances. This likely was triggered because some employees
         | were using whatsapp to evade compliance checks on topics that
         | should have been regulated.
        
       | throwaway_2009 wrote:
       | The headline here reads a bit like "person takes mask off to eat
       | a sandwich".
       | 
       | Obviously people use messaging software with their colleagues.
       | 
       | The correct solution is to design systems in which that isn't an
       | issue. If you need to monitor what people are saying at all times
       | then you have far bigger problems.
        
       | ourmandave wrote:
       | JPMorgan has been fined 191 times for over $35B since 2000.
       | 
       | https://violationtracker.goodjobsfirst.org/parent/jpmorgan-c...
       | 
       | "Oh, $200M? Yeah just stack it over there with the others. 'k thx
       | bye."
        
         | walrus01 wrote:
         | a few months ago somebody in NYC asked me if I felt unsafe
         | temporarily living in a certain part of Harlem.
         | 
         | my response was, paraphrased: "no, you want to know where the
         | actually dangerous criminals are? down near wall street/broad
         | street/beaver street".
        
       | sidpatil wrote:
       | Title from article: "JPMorgan hit with $200 million in fines for
       | letting employees use WhatsApp to evade regulators' reach"
        
         | johnhenry wrote:
         | Without the regulation part, the titles makes it seem like an
         | easily dismissible bureaucratic issue.
        
         | [deleted]
        
       | simplezeal wrote:
       | In my last trip to South Asia I was surprised banks using
       | WhatsApp to request identification documents.
        
         | xwolfi wrote:
         | What matters is to they keep record of these whatsapp requests,
         | not that they use whatsapp. If they screeshot all the chats one
         | by one print them and airmail them to the SEC in postcard
         | format, this is still ok. Saying "oh snap we dont know why we
         | traded 5M of this just before a market moving event because we
         | lost employee communication" is not ok.
        
       | raymondh wrote:
       | Accountants, traders, executives, bankers, etc all have strict
       | rules designed to avoid the appearance of impropriety. However,
       | it seems that members of congress are held to a much lower
       | standard.
        
       | tibbetts wrote:
       | I'd be pretty embarrassed if I was JPMorgan and I hadn't profited
       | at least ten times that much from illicit private messaging.
        
         | Aunche wrote:
         | If you were profiting from from private messaging, it would
         | either be at the expense of your employer or your client. Even
         | if the second case, JP Morgan is taking on reputational risk,
         | so at the very least they wouldn't encourage it.
        
           | dundarious wrote:
           | JP Morgan is _notorious_ for profiting at the expense of
           | their clients, even to the extent of calling clients names in
           | internal communications when they're selling them "solid
           | investments" that they know are junk. They've been charged
           | with 5 felonies in the last 7 years or so, always with
           | deferred prosecution agreements and multi-year probation, but
           | enforcement is still rather weak, considering the net profit
           | they've been able to achieve from those actions. And I don't
           | think it's unreasonable to assume that is only the tip of the
           | iceberg.
           | 
           | It's a large organization, sure, but at this point one has to
           | ask just how much they "wouldn't encourage it" or how much do
           | they actually institutionally discourage it.
        
         | gruez wrote:
         | What type of illegal activities were they doing that generated
         | $2B in profits over 2 years?
        
           | overcast wrote:
           | Insider trading, market manipulation, every trick possible?
        
           | tibbetts wrote:
           | I certainly don't know. Maybe they didn't, in which case it's
           | embarrassing.
        
         | LatteLazy wrote:
         | Ten times 200m would be 2bn. JPMs revenue is 36bn. So you have
         | to make over 5% of the companies whole revenue just from your
         | WhatsApp account.
         | 
         | And that's just revenue. If the profit margin on your deals was
         | 20% (pretty whopping for banking services) you'd need to bring
         | in 10bn in revenue. That would mean doing maybe $1tn worth of
         | deals.
        
       | jeidz wrote:
       | Does this mean that WhatsApp is secure or that this particular
       | agency didn't care enough to break the encryption?
        
         | avsmithy wrote:
         | No, they were fined because bankers must only communicate via
         | channels that are monitored. By using whatsapp, they bypass all
         | the internal and external audit/compliance teams.
        
         | malshe wrote:
         | The SEC is pretty much a nobody when it comes to 3-letter
         | agencies. See how Elon Musk challenges them publicly and all he
         | got in return was a slap on the wrist.
         | 
         | On a related note, the major issue with the SEC as highlighted
         | by every knowledgeable commenter is that they have a revolving
         | door shared with the same banks and organizations they are
         | supposed to monitor. People leave SEC and join Goldman Sachs or
         | JPM and then when new administrators come in they rejoin the
         | SEC. It's corruption at an unprecedented level.
        
           | xwolfi wrote:
           | He got much more than a slap on the wrist, he go removed from
           | his chairman incestuous position from Tesla. It's the first
           | red flag of bad governance when the CEO is also the chairman
           | (others are to have the board full of family members and
           | overly paid sycophants, I let you google who s on Tesla
           | board).
           | 
           | This will eventually be the starting point of a very slow
           | reform at Tesla, so not a bad deal.
        
           | shukantpal wrote:
           | > See how Elon Musk challenges them publicly and all he got
           | in return was a slap on the wrist.
           | 
           | Publicly challenging them is not illegal or even bad so that
           | seems reasonable.
        
         | bidirectional wrote:
         | If WhatsApp encryption can be broken, there is no way the
         | agencies capable of doing so would share it with the lowly SEC.
         | That would be a top level state secret.
        
           | paganel wrote:
           | On top of that I assume that the NSA (mostly) still has a
           | PRISM-like programme in place, it would be foolish to assume
           | otherwise. More exactly I do think that they (NSA and some
           | other agencies) still have direct access to the servers of
           | Google, MS, Facebook and Apple.
           | 
           | But I 100% agree with you, such lowly use-cases like the SEC
           | chasing some bankers don't register on NSA's (and similar
           | agencies') radar, it's only money, after all, I think they're
           | more interested in dealings involving power itself.
        
         | gruez wrote:
         | unknown. seems like they were being punished because their
         | employees used whatsapp for business communication, not that it
         | was discovered the employees used whatsapp and did something
         | illegal
        
       | cameronh90 wrote:
       | I work in finance and, for compliance reasons, we've been trying
       | to stamp out employees using WhatsApp but it is basically
       | impossible.
       | 
       | No matter how much we threaten disciplinary action in our
       | handbook, people still use it, they just hide it more. Obviously
       | we have no way of proving it, but we can see people doing it when
       | the office is open. The financial regulator says we should use
       | technology to reduce WhatsApp use - but given it's happening on
       | personal phones, I'm not sure what we're supposed to do.
       | Obviously nobody would accept company spyware on their personal
       | phone.
       | 
       | Is there some solution to this issue that I'm missing?
        
         | throwaway_2009 wrote:
         | Lobby to change the rules because they're ridiculous, or
         | develop a method that makes it impossible for them to get
         | caught?
         | 
         | It just makes no sense to me on the face of it. What do you do
         | if they have a chat in the pub after work, bug the table?
        
         | salawat wrote:
         | Why exactly is WhatsApp a problem?
         | 
         | After further reading I'm torn. This feels like regulatory
         | overreach. The only measure I can think of is supplying a
         | company phone and doing everything possible to encourage people
         | to only use their personal phone for non-business work.
         | 
         | This is up to and including being tolerant of personal use of
         | company phones within reason.
         | 
         | Otherwise, you're hosed. There's really no way to comply.
         | Strangely enough, I'm both in favor of, but abhor this type of
         | regulation.
         | 
         | Yes. White collar insider trading needs this type of draconian
         | control to chart info flow...
         | 
         | Yet yeeech! It makes me want to puke. I do not envy you.
         | Godspeed.
        
       | lhnz wrote:
       | No doubt widespread and certainly not a good idea for oversight,
       | however, the insinuation that all usage was due to employees
       | wanting to avoid oversight isn't correct. Particularly during the
       | pandemic, employees were forced into communicating using
       | messaging software and many prefer to communicate using software
       | with a good user experience.
       | 
       | The messaging software used within banks (e.g. Symphony) is
       | really awful and it is particularly bad when you're no longer
       | able to speak to clients in person.
       | 
       | They should improve the messaging software they use, on top of
       | getting everybody to do the training for the 100th time, etc.
        
         | lordnacho wrote:
         | I've worked in finance for a long time, I don't buy this line.
         | People are getting told all the time that they need to use
         | certain tools, they know what the rules are. You can't just set
         | up your own line to clients just because it's convenient.
         | 
         | It's not like everyone is doing illegal stuff just because they
         | can set up WhatsApp either, it's just it's been drilled in so
         | many times, there's no excuse.
        
           | tata71 wrote:
           | Your experience is anecdotal, and I have anecdotal experience
           | directly to the contrary.
           | 
           | Laws don't stop people who don't know, don't understand,
           | don't care, or some combination.
        
             | sdenton4 wrote:
             | It's the responsibility of the multi-billion dollar
             | financial institution to ensure that their employees know
             | the rules via regular trainings. This isn't mysterious.
        
             | lordnacho wrote:
             | Sorry but what is anecdotal about this? It's well
             | documented that there are rules that people are told.
        
             | blitzar wrote:
             | > Laws don't stop people who don't know, don't understand,
             | don't care, or some combination.
             | 
             | There is litterally zero opportunity to not know or
             | understand. The only reason to flout the rules is if you
             | are either stupid, hate getting paid your bonus or straight
             | up want to be fired.
             | 
             | Annecdoteally, I have personally been involved with
             | multiple firings of people for breaking these rules. Not a
             | single one is emplyable within the finance industry as a
             | result.
        
             | shukantpal wrote:
             | > Laws don't stop people who don't know, don't understand,
             | don't care, or some combination.
             | 
             | So what? That doesn't take away from the credibility of the
             | insinuation.
        
             | mrcode007 wrote:
             | The rules in finance are clear. On top of that, every year
             | you have to certify and confirm that you followed them.
             | Willingly certifying to the contrary on a legally binding
             | document has serious consequences. Sometimes to the tune of
             | $200M...
        
             | maxbond wrote:
             | I'd be interested to hear your counter anecdote.
        
         | tomp wrote:
         | No, it's correct. There's no reason to use WhatsApp, and all
         | reason not to use WhatsApp, except if you want to avoid
         | oversight.
         | 
         | Working in finance, _in general_ , isn't "good user
         | experience". Compliance manuals (reread yearly!), compliance
         | training (e.g. anti-money laundering even for employees that
         | have _no_ contact with any cash, bank accounts or clients),
         | trading oversight /restrictions, ... But people do it because
         | it is (might be) worth the money.
         | 
         | "All communication must be recorded" is the least of these
         | nuisances. People who avoid it are doing so willingly, for a
         | reason.
         | 
         | Edit: Also, judging by the title, this is next level bad:
         | JPMorgan "letting" means they _knew_ and didn 't do anything
         | against it (e.g. fire employees or report them to the
         | authorities). Normally the punishment for these kinds of things
         | is severe, you can easily get "cannot ever work in finance
         | again" by the regulator.
        
         | xwolfi wrote:
         | The argument the SEC presented however is that it hindered
         | investigations which means it was extreme. There s no excuse
         | dropping an email with the details of the communications out of
         | channel was impossible, even by hiding the fact it was out of
         | channel: after all you could meet the client on premise and
         | discuss the same things with no record and everyone would agree
         | an email memo should be shared.
         | 
         | Here it feels like it became completely normal to take decision
         | completely out of record, and with no way to trace who said
         | what when, no way to defend themselves out of suspicion, which
         | is why we keep records in banks in the first place.
        
         | DisjointedHunt wrote:
         | This is incorrect. When you work in a heavily regulated
         | industry such as Finance, everyone knows the basic requirements
         | of official record keeping and process. The industry has a long
         | history of being hit with "slap on the wrist" type fines for
         | things exactly like this ie, using unofficial tools and
         | software to communicate.
        
         | hellbannedguy wrote:
         | Old slick Jamie Diamond knew exactly why his guys were using
         | Whatsapp.
         | 
         | "Federal law requires financial firms to keep meticulous
         | records of electronic messages between brokers and clients so
         | regulators can make sure those firms aren't skirting anti-fraud
         | or antitrust laws."
         | 
         | I'm shocked they were doing this since 2018.
         | 
         | Diamond probally wishes he had this tech when he was an
         | apprentance.
        
         | brendoelfrendo wrote:
         | One of the big things I was told repeatedly while working for a
         | financial institution is that the appearance of impropriety is,
         | in many cases, _just as bad_ as actual impropriety, and this is
         | why. Oh, you avoided oversight because you wanted to have a
         | better connection with your client? Well, too bad: everyone is
         | now assuming the worst because assuming anything less is how
         | people get away with the worst.
         | 
         | And, frankly, it's hard to assume positive intent. These are
         | bankers, they should know this. If they knew it and did it
         | anyway, then yeah, I'm glad they got hit by the fine and I
         | don't really have any sympathy for the blight of bad chat
         | software.
        
           | lhnz wrote:
           | I agree that you can't discern the difference between the
           | appearance of impropriety and literal impropriety and
           | shouldn't try to.
           | 
           | My point is that the existence of fines and non-stop training
           | courses drilling in the correct messaging software to use to
           | all employees doesn't end this behaviour. Do we increase the
           | punishments or require more training courses to be taken?
           | Will that have any effect?
           | 
           | I'm suggesting that if we really care about reducing
           | impropriety we should also improve the software in use.
        
             | acdha wrote:
             | The fines are what will make the software improve. Someone
             | was slacking on that for years but now they have to pay
             | enough that they could have lavishly staffed an entire
             | company if they could use something like Teams.
        
               | OnlineGladiator wrote:
               | You're assuming they didn't make more than $200 MM by
               | evading regulations. I'm willing to bet they made
               | significantly more than this and will continue to operate
               | profitably as that is their business. This fine is barely
               | 1% of their quarterly profits.
        
               | acdha wrote:
               | I was responding specifically to this thread, which is
               | not assuming malice but was arguing that bad software
               | incentivized using WhatsApp. In that case, licensing or
               | building anything would be cheaper.
               | 
               | If this was done for malice, I agree that the fine would
               | have minimal effect.
        
               | OnlineGladiator wrote:
               | Fair point. My mistake.
        
               | acdha wrote:
               | No worries -- I certainly wouldn't rule out malice from
               | them but in this case general IT mishaps seems entirely
               | plausible.
        
               | xwolfi wrote:
               | No I think it's never that simple. I would agree they
               | shot themselves in the foot and it s fair game to assume
               | as much, but in reality it was a sentiment of systemic
               | impunity laced with laziness, most likely.
               | 
               | This also means that since financial crime most arises
               | out of opportunity rather than genetic predisposition,
               | this would eventually have let to it if it had not
               | already. The fact the SEC discovered it during
               | investigations doesn't sound very good in that regard.
               | 
               | And a lot of non finance people always dismiss fines
               | because they sound small vs the whole group profit, but
               | damn 200 mil it s a team entire year of profit and it
               | would fuck me to hear the bank had to give it back
               | because assholes couldnt get bothered to transcribe
               | whatsapp into emails at the very least.
        
               | OnlineGladiator wrote:
               | I hear these arguments over and over again. 'The fines
               | are significant and surely it won't happen again!' And
               | yet, the same things keep happening over and over and
               | over again.
               | 
               | Please point me towards some examples where these types
               | of fines actually changed how companies do business,
               | because as far as I can tell they keep getting fined for
               | the same things over and over again and they keep making
               | record profits!
               | 
               | I can dig up examples where banks are fined hundreds of
               | millions when they made billions. Why should I believe
               | this is any different?
        
           | ByteJockey wrote:
           | Does this mean that we're training bank employees that "If
           | something looks bad, you might as well do the actual bad
           | thing because the punishment is the same"?
           | 
           | Could this have the effect of actually increasing incidents
           | of bad behavior?
        
             | xwolfi wrote:
             | No, it has the opposite effect on me, a bank employee, to
             | immediately report everything weird because even if I do
             | nothing wrong, want banks to behave legally, and have never
             | personally traded a stock in my life, the appearance of
             | impropriety is just as bad as actual dishonesty.
             | 
             | Never did it make me think I could just as well front run
             | clients with a secret account since forgetting to disclose
             | an old account I never used was bad too. I declared late
             | that old account and apologized instead, for instance.
             | 
             | I think these rules are, like all rules, also mostly to
             | draw responsibilities in case of trouble: they do nothing
             | to prevent a criminal to crime, but once the crime is done,
             | he cant claim he did everything by the book if the book was
             | so clear.
        
       | known wrote:
       | "It takes 20 years to build a reputation and five minuted to ruin
       | it. If you think about that you'll do things differently"
       | --Warren Buffett (b. 1930)
        
         | spaetzleesser wrote:
         | The beauty of the financial and many others ( see oil, tobacco,
         | cable, health ) industry is that they have a bad reputation but
         | still manage to be politically favored. Once you have achieved
         | the status where your broad reputation doesn't matter as long
         | you keep political leadership in check you really have won the
         | game.
        
           | [deleted]
        
         | anadem wrote:
         | An issue here may be that the people involved may think it's
         | better to look clever than to be hide-bound
        
       ___________________________________________________________________
       (page generated 2021-12-18 23:01 UTC)