TL;DR
- The ACAMS/GASA report finds that financial crime information sharing is often permitted more broadly than institutions assume.
- Section 314(b), CISA, RFPA, GLBA, CCPA, and the Stored Communications Act each create pathways for different forms of sharing.
- Safe harbors matter because they reduce liability anxiety, while general exceptions may make sharing legal without giving institutions the same protection.
- Non-content metadata, including wallet addresses, IP addresses, device identifiers, and transaction data, has more sharing flexibility than message content.
- The operational challenge is turning legal permission into trusted, controlled, useful intelligence sharing.
Financial crime information sharing has an uncomfortable problem. It is often discussed as though institutions need permission to do it. The latest ACAMS and Global Anti-Scam Alliance report argues that, in many cases, they already have it.
That does not mean every type of data can be freely exchanged, or that privacy and legal review no longer matter. They do. Still, the report’s central finding is difficult to ignore: the gap between what the law permits and what institutions actually do has become a risk in its own right.
Fraud networks do not operate in neat categories. They can recruit victims on social media, move them to encrypted messaging apps, direct payments through bank accounts, convert funds into crypto, and cash out through several intermediaries. Each move may involve a different company, a different regulator, and a different internal team.
Meanwhile, the people trying to stop the activity often remain separated by policy, uncertainty, and old assumptions about what may be shared.
That is the real threat intelligence paradox. Criminals are coordinating across sectors. Defenders often have legal pathways to do the same, yet hesitate to use them.
Why is financial crime information sharing now an operational problem?
The report does not frame information sharing as a philosophical debate. It frames it as a practical failure.
A single scam can touch a social platform, messaging app, telecom provider, bank, payment processor, exchange, and law-enforcement agency in a matter of hours. No one participant necessarily has the complete picture. A bank may see a new payee and a large transfer. An exchange may see a wallet receiving the funds. A platform may have indicators linked to the scammer’s account. Law enforcement may have victim reports that connect all of it.
When these signals stay separate, the fraud network benefits.
This is why financial crime information sharing is not just a compliance question. It is an investigation-quality question. The faster an institution can understand whether an alert connects to a known victimization pattern, a live case, or a reused cash-out route, the more informed its next action can be.
The alternative is familiar. Teams review risk in isolation, file reports with incomplete context, and discover the broader network only after the funds have moved on.
What does the ACAMS/GASA report actually say?
The report, Information Sharing to Combat Fraud: Analysis of Statutory Permissions and Constraints, examines the U.S. legal landscape for sharing fraud and threat indicators. Its conclusion is clear: many institutions are more constrained by uncertainty and inertia than by the law itself.
Its analysis identifies several existing routes for financial crime information sharing. These include the Section 314(b) safe harbor, the Cybersecurity Information Sharing Act, voluntary disclosures to government authorities under the Right to Financial Privacy Act, and privacy-law exceptions designed to prevent fraud, unauthorized transactions, and consumer harm.
The important point is not that every organisation can share every piece of information with every other organisation. The rules remain specific. The purpose, data type, participants, safeguards, and legal basis all matter.
Still, the report shows that institutions often treat uncertainty as a reason to avoid sharing altogether. That approach may feel safer internally. It does little to address fraud that is already moving across the systems those institutions operate.
ACAMS and GASA describe this as a policy gap between lawful action and actual practice. It is a gap that fraud networks understand very well.
Why do safe harbors make such a difference?
A legal exception and a safe harbor are not the same thing.
An exception can make a form of sharing lawful. A safe harbor goes further by limiting civil liability when an institution acts in good faith and follows the relevant requirements. That difference affects behaviour.
Section 314(b) is the most important example for financial institutions. It allows eligible participants to voluntarily share information to identify and report possible money laundering or terrorist activity, subject to its conditions. FinCEN continues to encourage participation, and its FY2025 review reported more than 7,200 registered institutions and more than 65,000 SARs referencing 314(b).
The report argues that safe harbors create the confidence general permissions often do not. This is not simply a legal distinction. It is an operating-model distinction.
When legal, compliance, fraud, and security teams believe the liability position is unclear, information sharing becomes slow, narrow, or dependent on case-by-case escalation. Criminals do not wait for internal certainty. Therefore, institutions need workflows that make permissible sharing controlled, documented, and easy to govern.
Why does the metadata distinction matter?
One of the report’s most useful observations concerns content versus metadata.
Message content is highly sensitive and subject to tighter legal restrictions. Non-content metadata often has a different legal pathway. That can include information such as account identifiers, wallet addresses, transaction hashes, IP addresses, device identifiers, login timestamps, and routing data.
This distinction matters because effective financial crime information sharing does not always require institutions to share the content of private communications. It may require them to exchange the indicators that reveal how a network is operating.
A wallet address linked to a live investigation can be meaningful. So can a device identifier associated with repeated account takeovers, an IP address tied to scam infrastructure, or a newly added beneficiary followed by unusual transfers.
The report’s message is practical: design information-sharing programmes around the side of the line where the legal basis is clearer and the data is relevant to prevention.
That is also where Deconflict operates. Our platform delivers law-enforcement-verified intelligence, including relevant on-chain indicators and investigative context, into compliance workflows without requiring organisations to trade in unnecessary message content or sensitive case details.
How does Deconflict turn permission into action?
Legal permission alone does not help an analyst reviewing an alert. The intelligence needs to arrive in a form they can understand, document, and use.
Deconflict helps close that operational gap in three ways.
Signal delivers law-enforcement-sourced context alongside the systems financial crime teams already use. When relevant intelligence exists, analysts can see whether an alert, wallet, or counterparty may connect to an active investigation, victim reports, or other verified context.
Nexus provides a secure route for coordination when the case requires more than an internal review. Verified participants can communicate with a clear record of the interaction, while sensitive information remains protected.
Finally, the Deconflict brings together more than 1600 participating law-enforcement agencies across all 50 U.S. states and 37 countries. That network matters because financial crime information sharing is only valuable when the intelligence is credible, attributable, and connected to the people who can act on it.
What should institutions do next?
The report does not suggest that institutions should ignore privacy, legal review, or governance. It suggests they should stop treating those obligations as a reason to preserve every silo.
A better approach starts with four questions:
- What threat indicators are already collected but not shared?
- Which information can be shared under an existing safe harbor or statutory exception?
- Can the programme focus on non-content metadata and verified indicators?
- Is there a secure way to connect the intelligence to the right investigator when appropriate?
The institutions that answer these questions well will not just share more information. They will make better decisions with the information already available.
FAQs
What is financial crime information sharing?
Financial crime information sharing is the controlled exchange of relevant risk indicators, investigative context, and threat intelligence to identify, prevent, investigate, or report suspected illicit activity.
Does Section 314(b) allow banks to share fraud information?
Section 314(b) allows eligible financial institutions to voluntarily share information to identify and report activities that may involve money laundering or terrorist activity, subject to the programme’s requirements.
Can institutions share metadata without sharing message content?
Often, yes. The legal analysis depends on the data, purpose, parties, and applicable law. The report identifies non-content metadata as an area with broader sharing pathways than communication content.
Does Deconflict replace blockchain analytics?
No. Blockchain analytics helps teams assess on-chain activity. Deconflict adds verified law-enforcement context that can help explain whether an alert is connected to real investigative activity.
How does Deconflict support secure coordination?
Signal provides investigative context, while Nexus enables verified financial institutions and law-enforcement participants to coordinate securely when a case requires follow-up.