Skip to main content
Payment Processor Hit With $6.5M PenaltyFraud Detection Analytics
4 min readFor Fraud Risk Managers

Payment Processor Hit With $6.5M Penalty

The Challenge

In May 2026, a federal court found Cliq Inc. (formerly Cardflex Inc.) and its executives, Andrew Phillips and John Blaugrund, in civil contempt for violating a 2015 FTC order designed to prevent consumer fraud. The court imposed $6.5 million in sanctions after determining the defendants had systematically failed to comply with provisions meant to protect the payment system from fraudulent merchants.

These violations were not minor errors. Cliq processed hundreds of millions of dollars for merchants listed on Mastercard's MATCH list, a database for entities terminated by other processors for fraud or excessive chargebacks. The company also helped merchant groups manipulate fraud monitoring systems and failed to conduct the underwriting required by the 2015 order.

This case shows the consequences when a payment processor treats compliance obligations as optional rather than mandatory.

Operating Under Constraints

Cliq operated under a 2015 federal court order that imposed specific obligations on how the company could onboard and monitor merchants. These were legally binding requirements, including:

  • Mandatory underwriting procedures before processing for any merchant
  • Prohibition against processing for merchants on the MATCH list
  • Chargeback threshold monitoring with required investigations and reports
  • Collection and verification of business information from merchant applicants

The order gave Cliq a second chance to operate as a payment processor, but only if it maintained rigorous controls to prevent fraud. The company had clear documentation requirements, explicit thresholds, and specific reporting obligations.

Payment processors in this position face a straightforward choice: build compliance into your operations or exit the business. Cliq attempted a third path, trying to process high-risk merchants while ignoring the controls that make such processing legally defensible.

Where Cliq Went Wrong

The court's findings reveal a pattern of systematic non-compliance across multiple areas:

MATCH List Violations: Cliq processed transactions for merchants flagged in Mastercard's high-risk database. Processing for MATCH-listed merchants means you're taking on fraud risk and working with entities other processors found too risky.

Facilitated Monitoring Evasion: Cliq helped merchant groups avoid fraud and risk monitoring programs. This included processing "friendly" transactions to mask true chargeback rates and helping merchants process under different names. When one account was closed due to problems, Cliq shifted transactions to other accounts instead of investigating.

Underwriting Failures: The order required Cliq to collect and verify business information before onboarding merchants. Instead, the company neglected documentation requirements, ignored evidence of shell companies, and accepted "obviously false" websites on applications without further investigation.

Chargeback Threshold Breaches: Merchants consistently exceeded chargeback thresholds, but Cliq failed to conduct investigations or produce reports justifying continued processing. The court found the company "systematically failed" to meet reporting obligations.

Each failure compounded the others. Without verifying business information during underwriting, you can't effectively monitor chargebacks later. Helping merchants mask their true performance metrics prevents identifying genuine fraud risks.

Results and Consequences

The court imposed $6.5 million in civil contempt sanctions to compensate for harm caused by these violations. Beyond the financial penalty, the case establishes precedents affecting how payment processors under FTC orders must operate:

The court rejected any argument that compliance obligations were ambiguous. The 2015 order specified exactly what underwriting documentation Cliq needed, what chargeback thresholds triggered investigation requirements, and what reporting the company owed the FTC.

The finding that Cliq "assisted and facilitated" fraud evasion sets a clear standard. Helping merchants manipulate monitoring systems or shift transactions between accounts isn't operating in a gray area; it's actively enabling fraud.

The MATCH list violation is significant. Payment networks maintain these databases for a reason. Processing for MATCH-listed merchants signals you're willing to accept merchants other processors have deemed too risky.

What a Compliant Approach Requires

If Cliq had genuinely committed to compliance, several controls would have prevented these violations:

Automated MATCH screening before merchant onboarding and as part of ongoing monitoring. This isn't optional under an FTC order. You need system-level controls that flag MATCH-listed entities before they process transactions.

Documented underwriting procedures with required fields, verification steps, and approval workflows. Basic verification would have caught "obviously false" websites. If you can't verify a merchant's website, business address, or corporate structure, don't approve the application.

Chargeback monitoring with automated threshold alerts and mandatory investigation protocols. When a merchant exceeds defined thresholds, your system should require a written report before allowing continued processing.

Transaction pattern analysis to identify merchants processing under multiple names or shifting volume between accounts. These patterns are detectable if you're looking for them.

Takeaways for Your Team

If you're operating under an FTC order or similar regulatory obligation, this case clarifies what compliance means:

Document everything. The court noted Cliq's failure to produce reports justifying processing decisions. If your order requires documentation, it must exist and be producible on demand.

Treat thresholds as hard limits. When your order specifies chargeback thresholds that trigger investigation requirements, exceeding those thresholds without investigation is contempt.

Don't help merchants evade monitoring. If a merchant asks you to process transactions under a different name or shift volume between accounts, you're being asked to facilitate fraud. The correct response is termination.

Verify what you're required to verify. If your underwriting obligations include collecting business information, you must collect it and confirm it's accurate. Accepting applications with obviously false information isn't underwriting; it's rubber-stamping.

The FTC's Bureau of Consumer Protection made clear this case reflects the agency's priority to "root out fraud in the payments system." Payment processors that treat compliance orders as negotiable will face enforcement. The $6.5 million sanction against Cliq shows that contempt findings carry real financial consequences beyond the original order's requirements.

You Might Also Like