Nuvei settles FTC fraud case for $4.85m: processors get a knowledge test

The Federal Trade Commission has settled with Nuvei, one of the larger independent payment processors serving global e-commerce, over allegations that the company opened and kept merchant accounts for businesses it knew or should have known were defrauding American consumers. Nuvei will pay $4.85 million in consumer redress and accept a set of permanent restrictions on who it may onboard.

The dollar figure is small by enforcement standards. The legal reasoning attached to it is not.

In a joint statement issued alongside the complaint, FTC Chairman Andrew N. Ferguson and Commissioner Mark R. Meador used the Nuvei matter to announce something the agency had never formally stated in more than two decades of payment-processing cases: that Section 5 of the FTC Act requires the Commission to plead and prove that a processor knew, should have known, or consciously avoided knowing that its merchant was breaking the law. That is a rejection of strict liability, and it draws the first clear line around how far an intermediary’s exposure extends when a merchant turns out to be a scam.

For every marketplace, platform, acquirer and merchant of record that sits between a shopper’s card and a seller’s bank account, this is the case to read. It sets out both the shield and the trapdoor.

In short

  • Nuvei will pay $4.85 million in consumer redress to settle FTC charges that it processed payments for merchants it knew or should have known were engaged in deception, according to the Commission’s announcement on September 4, 2026.
  • The headline allegation is Reimage, an offshore tech support scheme for which Nuvei entities allegedly processed more than $30 million in card payments, with the complaint describing conduct running from at least 2011 to 2023.
  • The FTC says Nuvei helped hide the fraud by spreading Reimage’s transactions across multiple merchant accounts, a practice the complaint calls load balancing, which kept chargeback rates below card network alarm thresholds.
  • The real news is the standard. Ferguson and Meador wrote that the Commission now reads Section 5 to require actual or constructive knowledge in unfair-payment-processing claims, which protects good-faith processors and narrows the theory the agency can bring.
  • The order bans specific categories outright, including processing for tech-support sellers that use telemarketing or pop-up advertising, and for any merchant on Mastercard’s high-risk list, alongside mandatory underwriting and monitoring duties.

What did the FTC accuse Nuvei of doing?

The complaint was filed on September 3, 2026 in the United States District Court for the District of Arizona, docketed as case 2:26-cv-06306-KML, with the Commission announcing the resolution the following day. It names five defendants across four jurisdictions: Nuvei Corporation, a Canadian company; Nuvei International Group Limited, a Guernsey private company formerly known as SafeCharge International Group Limited; Nuvei Limited, a Cyprus company formerly known as SafeCharge Limited; SafeCharge Digital Limited, also Cypriot; and Nuvei Technologies Inc., a Delaware corporation.

That corporate spread matters to the theory of the case. The FTC alleges that the offshore acquiring entities, principally the Cyprus-registered ones, supplied card acceptance to overseas deceptive tech-support schemes, while the Delaware subsidiary handled a separate group of domestic merchants. The Commission’s position is that the group operated as an integrated payment-processing business, and that its own written onboarding policies were ignored when the revenue justified it.

Those policies, as quoted in the complaint, prohibited onboarding merchants in industries plagued by fraud such as antivirus software “sold via inaccurate advertisements”, merchants “previously identified by any Card Brand for deceptive practices”, merchants with “a history of excessive chargebacks or fraud”, and merchants whose “true beneficial ownership is not clear or is masked”. The FTC’s argument is not that Nuvei lacked rules. It is that Nuvei wrote the right rules and then declined to follow them.

The Reimage accounts

Reimage, which also traded as Restoro, sold tech-support software through a stable of websites including reimageplus.com, reimage.com, efix.com and restoro.com. The FTC brought a separate action against the operators in 2024, and that case settled for $26 million; the agency returned more than $25.5 million to affected consumers in March 2025. Reimage’s method, as described by the Commission, involved fake virus alerts and impersonation of Microsoft, funnelling worried users toward offshore call centers.

According to the complaint, from January 2017 to July 2023 the Nuvei defendants processed more than 310,000 separate Reimage sales transactions with net sales totalling $28 million through accounts opened under the names Reimage Limited and SC Digital. A further 89,000 transactions worth $3.8 million in net sales ran through accounts opened in the name of Upclick, a payment facilitator that the defendants allegedly knew was itself processing for Reimage. Together with earlier activity, the FTC puts the total above $30 million.

The complaint also alleges that merchant applications submitted for Reimage contained false information, including nominee directors and fabricated European business locations, plus a misleading description of what the business actually did. That is the part that moves the conduct from negligent underwriting toward active concealment. Card networks and acquiring banks assess risk from what the application says, so a false application defeats the control at its source.

The Visa warning and the fine that changed nothing

The sequence the FTC leans on hardest is from 2020. In early that year, Visa sent Nuvei Limited a warning that Reimage was impersonating Microsoft with fake virus alerts and steering consumers to offshore call centers under the guise of remote tech support. In May 2020 Visa rejected Reimage’s response to the resulting violation and issued a fine of EUR 25,000 (about USD 27,000 to USD 29,000 at prevailing 2020 rates).

Nuvei paid the fine by deducting it from Reimage’s sales proceeds, according to the complaint, and then increased the volume it processed for the merchant, including recurring subscription charges. When an underwriting manager raised concerns about taking on more Reimage volume in light of Visa’s determination, the complaint describes internal pressure to proceed. One account manager is quoted urging the risk group to approve more volume, noting that the chief operating officer “is pushing to get all traffic from this merchant and we could be waiting a year to hear back from Visa.”

Elsewhere the complaint reproduces an internal message in which staff justified continuing with Reimage because they “kn[e]w reimage (and the owner”, followed by a smiley face emoji. Nuvei’s own underwriters had at one point flagged the scheme as “very bad”. Documents of that kind are why the case settled rather than proceeding to a contested reading of what a processor should have known.

Why is the knowledge standard the real story?

Payment processors have been an FTC enforcement target since at least 2004, when the agency sued electronic payment processors for facilitating fraudulent telemarketing. The list since then includes the processor for the MOBE business coaching scheme in 2020, a $40.2 million settlement with a global processor and an industry executive in 2020, actions against Qualpay and Complete Merchant Solutions, and the BlueSnap credit-card-laundering case in 2024. In every one of those matters the agency had evidence of knowing assistance. It never said out loud that knowledge was required.

That silence had a practical cost. If the Commission had never conceded a knowledge element, then in principle a processor could face a Section 5 unfairness claim purely because a merchant it onboarded turned out to be fraudulent, no matter how careful the underwriting had been. Ferguson and Meador address that head on, writing that without a knowledge requirement, good-faith processors “would be on the hook for all their merchant clients’ fraudulent conduct even when they deployed industry-standard anti-fraud measures”.

Their reasoning runs through the unfairness test in Section 5(n) of the FTC Act. An act is unfair if it causes substantial injury that consumers cannot reasonably avoid and that is not outweighed by countervailing benefits. Processing a payment for a fraudulent merchant clears the injury and unavoidability hurdles easily, the statement says, so the analytical weight falls entirely on the balancing step.

On that balance the commissioners come down decisively. A processor that knows or consciously avoids knowing it is handing scammers access to American consumers offers no countervailing benefit. A good-faith processor that opens the payments system to small businesses, startups and other risk-taking enterprises provides what they call “immense countervailing benefits to both consumers and competition”. The two cases are not the same, and the statement holds that Section 5 does not treat them the same.

The limits of the shield

Anyone reading this as a general amnesty should read the qualifications. The statement is explicit that a processor cannot “bury its head in the sand to avoid learning the truth about what its existing or prospective merchants are doing”. Constructive knowledge counts, and so does conscious avoidance.

The most consequential sentence for compliance teams is the one on attribution: the Commission says it will attribute to a processor knowledge of those facts it would have uncovered had it performed the fraud-prevention practices and investigations that the card networks already require. In other words, network rules become the floor of the legal standard. Underwriting, ongoing monitoring, MATCH list checks and chargeback investigation are not merely contractual obligations to Visa and Mastercard; skipping them now imputes knowledge under federal law.

The statement also disposes of the most common defense. A low chargeback rate, it says, does not establish that a processor lacked knowledge drawn from other facts it was or should have been aware of. That closes off the metric most processors point to first, which is relevant given how much of the Nuvei complaint concerns the manipulation of that very number. The FTC’s broader posture here is consistent with its recent willingness to attack intermediary conduct directly, visible in the way it framed its case over Amazon’s hidden ad auction surcharges earlier this month.

How does load balancing hide a fraudulent merchant?

The mechanics deserve attention because they are the operational heart of the complaint. Card networks run chargeback monitoring programs with published thresholds. According to the complaint, monthly chargeback rates above 1% draw warning letters and placement in a monitoring program, and rates above 1.5% for two consecutive months mark a merchant as excessive, exposing it to fines and potential termination.

Load balancing defeats this by arithmetic rather than by deception at the transaction level. A merchant with a genuinely toxic chargeback rate spreads its sales volume across several merchant accounts, so that the disputes attached to each individual account stay below the threshold. Nothing about the underlying fraud changes. Only the denominator does.

The numbers in the Nuvei complaint show what was being concealed. A risk report covering nine months showed Reimage’s chargeback rates averaging as high as 8.5% on Discover. A 2016 review of accounts at SC Digital found rates above the 1% threshold in every month examined, peaking at 4.91%. By February 2017, Reimage was running 2.85% on Visa and 1.72% on Mastercard, which prompted Nuvei to flag it internally as one of the top ten merchant migrations that would be “[r]isky” and “[p]roblematic with the chargebacks in the past”.

Later figures are worse. The complaint describes months with rates between 4% and 9% in 57 out of 60 months for one account grouping, and an annual chargeback rate on one Reimage merchant account averaging over 8.5%, representing 1,108 chargebacks. The complaint states plainly that these rates did not trigger warnings or fines from Visa or Mastercard because of how the volume was distributed. Dispute-rate arithmetic is becoming a live regulatory surface generally, a pattern also visible in the way agent-initiated chargeback rules are being drafted for automated checkout flows.

What the thresholds look like in practice

Chargeback measure Network trigger Reimage rate cited in complaint
Monthly rate, warning stage Above 1% Above 1% in every month of a 2016 six-month review
Monthly rate, excessive designation Above 1.5% for two consecutive months 2.85% (Visa) and 1.72% (Mastercard) in February 2017
Peak single month cited Termination territory 4.91% (2016 review), rates “up over 9%” on later accounts
Nine-month average by network Sustained excess As high as 8.5% on Discover
Annual average on one account Sustained excess Over 8.5%, being 1,108 chargebacks

Which other merchants does the complaint name?

Reimage carries the headline, but the FTC also details two domestic schemes handled by Nuvei Technologies Inc., and these are the ones most relevant to anyone underwriting US e-commerce sellers.

The first is DK Automation, a business-opportunity operation run under the brand names DK Automation, The Official Kevin David, Digital Ninjaz and That Lifestyle Ninja. The FTC alleges it used false and unfounded earnings claims to sell business opportunities, and the agency brought its own enforcement action against the scheme. Nuvei Technologies allegedly processed sales totalling more than $10 million for it.

The timeline the complaint sets out for DK Automation is unusually detailed. The underwriting file contained red flags including excessive chargeback levels at other processors. Nuvei approved a purchase-limit increase, and later placed a 100% hold on remitting funds while continuing to let the merchant process. In one incident, Nuvei flagged a $23,500 charge that DK Automation’s sales agents attempted to put on a consumer’s credit card. By late 2021 the accounts were closed over chargeback levels.

The second is American Tax Service, also known as American Tax Solutions, described as a tax consulting and government impersonation scam. Nuvei Technologies opened accounts for it around 2019, taking personal guarantees from the owners and designating it internally as a “high volume-high risk” merchant transacting entirely through mail order or telemarketing. The complaint says due diligence was inadequate and red flags including excessive chargebacks were ignored.

A common thread runs through all three. In each instance the compliance function generated the correct signal, documented it, and was overruled or ignored downstream. The recurring-charge dimension of the Reimage accounts also connects this case to the agency’s continuing interest in automatic renewal and subscription-trap enforcement, since the complaint notes Nuvei began processing auto-renewing subscription charges for the scheme after the Visa warning.

What does the settlement actually require Nuvei to do?

The stipulated order runs beyond the monetary component. The Commission voted 2-0 to authorize staff to file both the complaint and the proposed order, which requires court approval to take effect.

Four obligations stand out. First, a ban on processing payments for tech-support product or service providers that engage in telemarketing or use pop-up advertisements, and for any merchant appearing on Mastercard’s high-risk merchant list, which is the MATCH database maintained for merchants terminated for cause. Second, a prohibition on making, or assisting others in making, false or misleading statements, which reaches directly at the falsified merchant applications alleged in the complaint.

Third, a prohibition on helping merchants circumvent fraud-monitoring systems, which is the load-balancing conduct written into an injunction. Fourth, an injunction requiring the defendants to implement and adhere to strict underwriting and monitoring requirements, with enhanced investigation of clients that exceed chargeback limits.

Christopher Mufarrige, Director of the FTC’s Bureau of Consumer Protection, framed the outcome around systemic integrity rather than the specific merchants, saying the action “underscores the Commission’s commitment to ensuring that our payments system operates free of fraud.”

How the Nuvei order compares with recent processor cases

Case Announced Monetary relief Distinguishing feature
Nuvei Corporation and affiliates September 4, 2026 $4.85 million First case pleading a knowledge element; category bans plus underwriting injunction
Paddle.com Market Limited June 2025 $5 million Merchant of record model; permanent ban on processing for tech-support telemarketers
Restoro and Reimage operators March 2024 $26 million The underlying scheme; more than $25.5 million returned to consumers in March 2025
BlueSnap and two executives May 2024 Not directly comparable Credit card laundering, individual executive liability
Global processor and industry executive May 2020 $40.2 million Assisting fraudulent schemes and card laundering at scale

Read together, the pattern is that the Commission has been steadily working its way up the stack. It sued the scheme, then the merchant of record, and now the acquiring processor group behind both. Each layer removed makes the next layer’s defense harder, because the earlier findings become part of the factual record.

Who is Nuvei and how much does this matter to it?

Nuvei is a Montreal-headquartered payments company that grew substantially through acquisition, including of SafeCharge, whose Cyprus and Guernsey entities appear as defendants here under their former names. Its business spans global e-commerce, business-to-business payments and embedded payments, and it competes with the larger acquirers and payment service providers serving cross-border online merchants.

According to its 2023 annual financial statement, the company processed more than $200 billion in total volume and recorded $1.2 billion in revenue. Against a revenue base of that size, $4.85 million is a rounding error. The injunctive terms are the cost that matters, because category bans and mandatory underwriting reduce the addressable merchant base in exactly the high-margin, high-risk verticals that independent processors have historically used to differentiate from bank acquirers.

Nuvei was taken private in a transaction announced in April 2024, in which Advent International acquired the company alongside existing Canadian shareholders at $34.00 per share in an all-cash deal valuing it at approximately $6.3 billion. That price represented a 56% premium to the unaffected closing price. Chair and CEO Philip Fayer, Novacap and CDPQ rolled equity into the private company, holding roughly 24%, 18% and 12% respectively.

Private ownership changes the calculus around a settlement like this. There is no public share price to defend and no quarterly earnings call at which the charge must be explained. There is, however, a sponsor with an eventual exit to plan, and an unresolved FTC injunction is the kind of item that surfaces in diligence.

What does this mean for marketplaces and platforms?

The reasoning in the joint statement is written about payment processors, but the structure of the argument travels. Ferguson and Meador describe processors as “crucial intermediaries” that control merchant access to the card ecosystem, and they ground liability in the ability to screen. Any intermediary that performs an equivalent gatekeeping function fits that description.

Marketplaces that onboard third-party sellers, payment facilitators that sub-merchant under a master account, and merchant-of-record platforms that present themselves as reseller of record all sit in the same position. The Paddle case from June 2025 already established that the merchant-of-record structure does not escape the analysis; the FTC alleged there that Paddle used its reseller position to process for unrelated third parties, obscuring their identities from card networks and banks.

The practical read for platform operators is that the knowledge standard is a two-sided instrument. It removes the tail risk of being held responsible for a well-hidden bad actor that survived a genuine screening process. It also means that any documented internal warning that was overruled becomes close to dispositive, because it establishes actual knowledge in writing.

The documentation problem

Every large intermediary generates the sort of evidence that appears in this complaint. Risk teams flag merchants. Underwriters write blunt assessments in ticketing systems. Account managers push back on behalf of revenue. Those exchanges are ordinary and mostly healthy, and they are also discoverable.

What distinguishes a defensible file from an indefensible one is what happened after the flag. A merchant that was flagged, investigated, and either declined or onboarded with documented mitigations shows a functioning process. A merchant that was flagged “very bad” and onboarded anyway because the relationship was profitable shows the opposite, and it does so in the company’s own words.

Compliance teams should also assume the FTC will read chargeback data at the entity level rather than the account level. The load-balancing theory in this complaint works precisely by aggregating what the merchant spread out. Consumer-facing dispute handling is under similar scrutiny elsewhere in payments, including in how buy-now-pay-later providers manage refunds and disputes when an order fails.

Where does the risk sit for ordinary merchants?

Legitimate online sellers are not the target of this action, but they will feel its effects through underwriting. When a processor accepts a category ban and a monitoring injunction, the internal response is rarely surgical. Risk appetite tightens across adjacent categories, and merchants that look superficially similar to the prohibited ones get caught in the adjustment.

Sellers most exposed are those in verticals with structurally elevated dispute rates: software and digital downloads, subscription services with free trials, coaching and business-opportunity content, supplements, and anything sold primarily through outbound calling or pop-up-style advertising. None of those are unlawful. All of them now read as elevated risk in an underwriting file that a federal court order is watching.

Merchant situation Likely underwriting effect Reasonable mitigation
Digital goods with auto-renewal Closer review of cancellation and disclosure flow Document consent, renewal notice and one-click cancellation
Dispute rate between 0.6% and 1% Monitoring, possible reserve requirement Deploy prevention alerts and reconcile descriptors to the brand consumers recognize
Multiple merchant accounts across processors Read as potential load balancing Explain the commercial rationale in writing before it is asked for
Any prior termination for cause MATCH listing blocks onboarding outright Pursue removal through the terminating acquirer; disclose proactively
Ownership through nominees or agents Beneficial ownership policy breach Disclose ultimate beneficial owners at application, not on request

What happens next?

The immediate procedural step is judicial. The stipulated order is proposed, and it becomes binding only when the District of Arizona enters it. Redress distribution to affected consumers follows entry, and the FTC has historically taken months to a year to run distributions of this kind, as it did with the $25.5 million returned in the underlying Reimage matter in March 2025.

The more interesting question is whether the knowledge standard survives contact with a litigated case. A settlement plus a commissioner statement is agency policy, not binding precedent. The standard becomes durable only when the Commission pleads it against a defendant who fights, and a federal court either adopts it or declines to.

Watch also for whether the reasoning migrates. The same structure could apply to advertising intermediaries, hosting providers and app stores, all of which control access to consumers and all of which run screening processes that generate documentary evidence. The Commission has not signalled that move, and the statement is careful to confine itself to processors.

In the nearer term, the agency’s consumer-protection docket stays busy. The comment period on the FTC’s proposed enforcement policy statement on personalized pricing was extended by seven days and now closes on September 25, 2026, which keeps a second major pricing-and-data question open for retailers already tracking the personalized pricing policy proposal. Two Commission initiatives touching e-commerce economics are running in parallel, and both turn on what a business knew about the consumer on the other side of the transaction.

What should retailers and sellers do now?

The practical takeaways are narrow and cheap to act on. None require legal advice to start.

  1. Audit your descriptor and dispute data at entity level. If your business runs multiple merchant IDs, calculate the blended dispute rate the way a regulator would, not the way each account reports individually.
  2. Write down the rationale for account structure. Multiple MIDs for genuine reasons such as separate brands, currencies or entities are normal. The rationale should exist in a document dated before anyone asks for it.
  3. Check your own onboarding file. Request from your processor what you disclosed at application and confirm it still matches your business, including beneficial ownership and product description.
  4. Treat internal risk flags as terminal decisions, not opening bids. The Nuvei complaint is a catalogue of flags that were raised correctly and then overridden. Whoever overrides gets quoted.
  5. Reconcile refund policy with renewal mechanics. Recurring charges after a warning are what turned a monitoring problem into a Telemarketing Sales Rule count in this case.

The broader message from the Commission is not that intermediaries are now liable for their customers. It is closer to the opposite. Processors that run the screening the card networks already mandate get a defence they did not previously have in writing. Those that treat screening as a formality now face a standard that will attribute to them everything a real investigation would have found.

The full complaint and stipulated order are available on the FTC’s case page for the matter.

Frequently asked questions

How much is Nuvei paying and who gets the money?

Nuvei agreed to pay $4.85 million, which the FTC describes as redress for consumers harmed by the merchants it processed for. Distribution happens after the court enters the stipulated order, and the agency administers the process rather than the company.

Has Nuvei admitted wrongdoing?

The matter resolved through a stipulated order rather than a litigated judgment, which is the standard route for FTC consumer-protection settlements and does not typically involve an admission of liability. The allegations described here are the Commission’s, as set out in its complaint filed on September 3, 2026.

What exactly is load balancing?

It is the practice of spreading a merchant’s transaction volume across several merchant accounts so that the chargeback rate attached to any single account stays below the card networks’ monitoring thresholds. The underlying dispute volume does not change, only its distribution across accounts, which defeats the alarm that would otherwise trigger a warning or termination.

What is the MATCH list and why does it appear in the order?

MATCH stands for Mastercard Alert to Control High-risk Merchants, a database on which acquirers and processors are required to place merchants they terminate for cause. The proposed order bars Nuvei from processing for merchants on Mastercard’s high-risk merchant list, converting a network obligation into a court-enforced one.

Does the knowledge standard make it harder for the FTC to sue processors?

In one sense yes, because the Commission must now plead and prove actual knowledge, constructive knowledge, or conscious avoidance rather than relying on consumer injury alone. In practice the effect is narrower than it sounds, because the statement says the agency will attribute to a processor any facts it would have discovered had it performed the checks the card networks already require.

Does this apply to marketplaces and merchant-of-record platforms?

The statement is written about payment processors, but its logic rests on the ability to screen and to control merchant access to consumers, which marketplaces and merchant-of-record platforms also possess. The FTC’s 2025 action against Paddle, which used a merchant-of-record structure, indicates the agency does not regard that model as sitting outside the analysis.

What was Reimage and is it still operating?

Reimage, also trading as Restoro, sold tech-support software through sites including reimage.com and restoro.com, using fake virus alerts and Microsoft impersonation according to the FTC and a 2020 Visa warning quoted in the complaint. The operators settled with the FTC for $26 million in March 2024, and the complaint describes the payment processing relationship as running to 2023.

Will this change what my payment processor asks me for?

Expect more scrutiny of beneficial ownership, product descriptions and cancellation flows, particularly if you sell digital goods, subscriptions or anything with an elevated dispute rate. Processors operating under injunctions tend to tighten policy across adjacent categories rather than only the prohibited ones.

When does the settlement take effect?

The stipulated order was filed alongside the complaint on September 3, 2026 and announced on September 4, but it binds Nuvei only once the United States District Court for the District of Arizona enters it. The Commission vote authorizing staff to file both documents was 2-0.