CRF and fraudulent bank accounts: new alert mechanism
A new law now enables the CRF to alert financial sector professionals to bank accounts identified as fraudulent, strengthening the fight against scams in Luxembourg.
As banking scam techniques multiply and become more sophisticated (phishing, CEO fraud, vendor fraud, investment scams), the Luxembourg police counted 5,553 cases of fraud in 2025. These fraud schemes often use one or more fraudulent accounts that can simultaneously target the clients of several institutions without other institutions being made aware.
The law of 22 July 2026 (Law) aims to bridge this gap by providing the Luxembourg Financial Intelligence Unit (Cellule de Renseignement Financier, CRF) with the legal basis to send alerts about these fraudulent accounts to credit institutions, professionals of the financial sector, payment institutions, electronic money institutions and cryptoassets service providers established in Luxembourg (Professionals).
Objective of the Law
The objective of this Law is, above all, prevention, namely blocking banking and financial flows to identified fraudulent accounts before new victims are affected.
On the one hand, it targets large-scale scams (such as phishing campaigns and other schemes aimed at a large number of victims) and, on the other hand, scams aimed at specific victims using social engineering techniques (such as CEO fraud and vendor fraud).
Process to follow
Alerts will be sent to Professionals who have requested to receive them via the secure goAML channel.
Information provided by the CRF will include (i) at-risk account numbers (such as IBANs (including virtual IBANs) and electronic money accounts or cryptoassets) and (ii) the types of fraud associated with them.
The CRF will hold meetings with Professionals at least every six months to adjust the relevance of alerts and to continuously improve the mechanism’s efficiency.
Restrictions on data use
The Professionals are subject to strict obligations with regard to the use of data sent by the CRF, namely:
- to use the information provided solely for the purposes of fighting money laundering, its predicate offences and terrorist financing (AML/CFT), notably in the context of updating client risk assessments and strengthening the monitoring of transactions linked to their bank accounts.
- of strict confidentiality prohibiting Professionals from revealing, directly or indirectly, the existence or content of an alert to the client concerned or third parties.
- to delete information received within a maximum period of six months from receipt, or earlier when keeping it is no longer necessary with regard to the prevention goal being pursued.
Key points to keep in mind
The measure is optional: only Professionals who have registered with the CRF will receive alerts. In practice, refraining from doing so raises a serious regulatory risk as alerts fuel the AML/CFT risk assessment tools that institutions are legally required to keep up to date.
An institution that has access to this information, chooses not to use it and nevertheless makes a transfer to a flagged account opens itself up to its due diligence obligations being called into question. The Council of State (Conseil d’État) itself highlights that failure to register by Professionals would create a gap in the alert system. Consequently, Professionals will be de facto required to register.
The CRF does not guarantee the exactness of the information sent or its uses. It is the responsibility of the Professionals to assess, on their own liability, the follow-up given to each alert received and, if necessary, to put in place appropriate AML/CFT due diligence measures.
The Law does not provide for any specific measure allowing a wrongly flagged account holder to contest this alert, especially as the non-disclosure rule applies, meaning that the client cannot be informed there is an alert concerning them. Given these conditions, a wrongly flagged account could be subject to restrictive measures for a period of up to six months. Although the means of appeal under ordinary law remain open, the text provides no specific procedure to remedy such situations.
What should you do now?
The Law entered into force on 8 August 2026. With this in mind, we strongly recommend that Professionals carry out the following checks without delay:
- register with the CRF alert mechanism via goAML and document it in their AML/CFT policy.
- ensure that their monitoring procedures and tools are compatible with the CRF’s alert processing.
- integrate the data taken from CRF alerts into their AML/CFT due diligence and supervisory procedures.
Authors: Jean-Luc Putz, Sarah Houplon

How we can help
If you have any concerns about whether you are compliant, or if verifications or corrections prove to be necessary, contact our experts in Arendt & Medernach’s Banking & Financial Services and Business Crime teams, as well as Arendt Regulatory & Consulting’s Forensic Investigations, Corporate Intelligence & Litigation Support team regarding fraud detection mechanisms, as soon as possible, so that they can assist with making your entity compliant.