22 July 2026
Legilux ¦ Law of 22 July 2026: Luxembourg’s New Fraud Signal Regime
A legal basis for targeted fraud prevention
Luxembourg has now given the financial intelligence unit (FIU), the Cellule de Renseignement Financier (CRF), a formal legal basis to share fraud-related signals with selected professionals in the financial sector. The new law of 22 July 2026 inserts article 74-4bis into the law on judicial organisation and creates article 5-1 in the anti-money laundering law. Together, these provisions establish a structured channel for sharing account-level fraud intelligence where the risk is serious enough to justify intervention.
This is not a broad public warning system. It is a targeted mechanism for professionals who actively ask to receive the information. The objective is narrower and more operational: to help prevent the reuse of accounts tied to major fraud patterns, and to strengthen anti-money laundering controls around the proceeds of those offences.
What the financial intelligence unit may share
Under article 74-4bis, the financial intelligence unit may signal typologies and information presenting a significant fraud risk to professionals covered by article 2(1), points 1 and 20, of the anti-money laundering law. In practical terms, this covers banks and the relevant payment and virtual asset service professionals that fall within that scope.
The law is precise about the kind of information that can be shared. It concerns the numbers of accounts that have come to the attention of the financial intelligence unit in the exercise of its legal functions and that present a significant fraud risk. The signal also identifies the fraud typology in which those accounts were used.
That is an important limitation. The law does not create a general blacklist. It does not authorise open-ended circulation of all suspicious accounts. It does not transform every fraud-related file into a sector-wide alert. The signal must be tied to a serious fraud typology and to accounts that have been specifically identified in that context.
The fraud types covered
The law defines “typologies presenting a significant fraud risk” as frauds and attempted frauds under the Criminal Code, as well as the laundering of the proceeds of those offences, when they are carried out on a large scale against unidentified victims or use social engineering techniques aimed at specific victims.
That wording captures the fraud patterns that matter most in modern financial crime practice. It includes phishing campaigns with broad victim pools, president fraud, business email compromise, false payment order schemes, and similar methods that combine speed, impersonation, and rapid movement of funds. It also captures the laundering side of the problem, which is just as important as the initial deception.
The inclusion of laundering of the proceeds is especially relevant. Fraud today is rarely confined to the initial transfer. Once the money leaves the victim, it often passes through several accounts or payment instruments, including accounts opened specifically to receive and disperse stolen funds. The law is designed to give institutions a better chance of interrupting that chain.
How access works
The signal is only sent to professionals who have requested it through a secure channel. Unless they expressly withdraw, that request applies to all signals transmitted by the financial intelligence unit.
That structure matters because it avoids indiscriminate distribution. It also means the receiving institution has made a deliberate choice to be part of the mechanism and must therefore be ready to handle the information properly.
The law requires that all transmission of signals, and all exchanges between the professionals and the financial intelligence unit, occur exclusively through a secure channel. This is not a decorative formality. It is the legal backbone of the system. It ensures traceability, confidentiality, and a defensible audit trail.
What the professionals may do with the information
Article 5-1 is equally clear about the use of the signals. Professionals may use them only in the context of anti-money laundering, the associated predicate offences, and terrorist financing. The use is under their sole responsibility.
That responsibility clause is central. The signal is not an order to block a transaction, not a mandatory instruction to file a suspicious activity report, and not a legal determination that an account holder is guilty. It is a control input. The professional must decide how to act, based on its own risk framework and the wider circumstances of the case.
In practice, the signal may support a stronger customer risk assessment, a transaction review, a payment decision, or an internal escalation. It may also help determine whether there is enough basis to file a report to the financial intelligence unit. But the law does not turn the signal into an automatic trigger. That choice is deliberately left to the professional.
No disclosure to clients or third parties
The law also prohibits revealing the signal to the client concerned or to any third party. That confidentiality rule is crucial. If a fraudster learns that an account has been flagged, the account can be abandoned and the funds moved elsewhere before any preventive measure takes effect.
The secrecy rule also protects the broader intelligence value of the mechanism. If market participants or clients could see the signals, the system would quickly lose credibility and operational usefulness. The prohibition therefore supports both enforcement and effectiveness.
The six-month deletion rule
Professionals must delete all information received under article 74-4bis paragraph 4, first subparagraph, within six months of receipt. This is a strict retention limit, and it is one of the most practical aspects of the law.
For compliance teams, this will require a clear lifecycle process. Institutions will need to track when each signal was received, how it was used, and when it must be deleted. That means internal controls, logging, access limitation, and retention logic will all need to work together.
The six-month limit also signals that the legislature sees this information as time-sensitive. Fraud intelligence loses value fast. An account used in an active scam may be highly relevant for a few days or weeks, but much less so after the trail has gone cold. The deletion rule reflects that reality.
Feedback is built into the model
The financial intelligence unit must organise meetings with participating professionals at least every six months, especially to discuss the relevance of the signals sent. It must adapt future signals based on the feedback received.
This is one of the strongest features of the law. It makes the mechanism iterative rather than static. That is essential in fraud prevention, where tactics shift quickly and the quality of the intelligence matters as much as the existence of the channel.
Regular feedback should help identify whether the signals are useful, whether the typologies are well chosen, whether false positives are a problem, and whether the institutions are seeing the same patterns in their own files. It should also help the financial intelligence unit refine which accounts and typologies deserve inclusion.
Why this law matters for Luxembourg’s financial crime strategy
The law reflects a broader shift toward operational cooperation between the public sector and regulated professionals. Fraud is too fast-moving to be handled only through traditional reporting after the fact. By the time a suspicious activity report is filed, the victim’s funds may already be gone. A targeted signal delivered earlier can make the difference between loss and interception.
That is especially important in Luxembourg, where the risk landscape includes cross-border account use, fast payment rails, and sophisticated fraud schemes that often span several jurisdictions. The law does not solve all of that, but it gives the financial intelligence unit a clearer role in prevention, not just detection and post-event analysis.
It also places real responsibility on the private sector. Institutions that opt in will need to integrate the signals into their controls, understand their limits, and handle them in a way that is both useful and legally compliant. The law gives them a tool. It does not remove the need for judgment.
The bottom line
Luxembourg has taken a practical step toward better fraud prevention. The new framework allows the financial intelligence unit to share account-based fraud signals with selected professionals through a secure channel, but only for significant fraud typologies and only within a tightly controlled legal structure.
The model is selective, confidential, and time-limited. It is also deliberately dependent on professional judgment. That makes it more demanding than a simple blacklist system, but also more defensible and more in line with modern anti-money laundering practice.
Its success will depend on whether institutions use the signals consistently, whether the information is accurate enough to act on, and whether the feedback loop improves the quality of future signals. If those conditions are met, the law could become a useful part of Luxembourg’s anti-fraud toolkit.
Dive deeper
- Journal officiel (Mèmorial A) ¦ Loi du 22 juillet 2026 (Law of 22 July 2026) ¦ Link