Market abuse undermines the basic mechanism through which financial markets allocate capital and establish prices. When traders misuse confidential information, create false signals or distort benchmarks, other participants make decisions within an environment that no longer reflects genuine supply, demand or publicly available information.
Insider dealing and market manipulation remain the two principal categories, but the operational landscape is considerably broader. It includes unlawful disclosure of inside information, spoofing, layering, wash trading, marking the close, pump-and-dump campaigns, benchmark manipulation, misleading issuer disclosures and coordinated activity across related instruments or venues.
Regulatory fines provide one measure of the response. They do not provide a complete measure of the misconduct, the effectiveness of supervision or the real cost to the institution. Cases can take years to conclude, jurisdictions calculate penalties differently and many actions involve individuals, criminal proceedings, disgorgement, bans or remediation rather than a corporate fine.
For financial institutions, the central question is therefore not how much regulators fined the industry in a particular year. It is whether the organisation can identify changing forms of abuse across fragmented markets, communications channels, asset classes and jurisdictions before regulators reconstruct the activity retrospectively.
Key Takeaways
- Market Abuse Remains a Major Global Regulatory Priority
- Market Manipulation Drives a Significant Share of Enforcement Activity
- Insider Trading Continues to Create Individual and Institutional Exposure
- Regulatory Fines Represent Only Part of the True Cost of Non-Compliance
- US Regulators Remain Particularly Active in Market Abuse Enforcement
- Enforcement Cases Often Relate to Conduct Several Years in the Past
- Weak Surveillance Systems and Controls Are Increasingly Regulatory Targets
- Firms Can Face Consequences Even When Misconduct Is Driven by Individuals
- Regulators Are Investing Heavily in Advanced Surveillance Technology
- Market Abuse Detection Is Becoming More Data-Driven
- Electronic Communications and Trading Activity Must Be Analysed Together
- Effective Surveillance Requires Continuous Investment and Modernisation
- Market Integrity Depends on Strong Governance and Compliance Culture
Listen the podcast
Watch the video
Why market abuse matters now
The original analysis identified approximately $1.9 billion in corporate market-abuse fines across nine major jurisdictions between 2019 and 2022. The United States accounted for much of the recorded value, reflecting the scale of its markets, the resources available to its regulators, extraterritorial enforcement and several high-value cases.
That comparison remains informative, but it should not be treated as a global measure of prevalence. A jurisdiction with a lower fine total may have fewer completed cases, different statutory penalties or a stronger reliance on criminal prosecution and individual sanctions. Conduct occurring during one period may not produce a final penalty until five or ten years later.
Recent enforcement data reinforce the difficulty of comparing totals. The US Securities and Exchange Commission reported $17.9 billion in monetary relief across all enforcement activity during fiscal year 2025. However, the headline figure included amounts treated as satisfied through other proceedings and judgments connected with a long-running Ponzi-scheme case. After excluding those elements, the adjusted total was approximately $2.7 billion.
The figure also covered many offences beyond market abuse. It illustrates why aggregate enforcement statistics require careful interpretation rather than proving that one year or jurisdiction experienced more manipulative trading.
The UK Financial Conduct Authority recorded approximately £124.2 million in fines across all regulatory matters during 2025. Market-abuse outcomes included penalties and prohibitions against individuals for manipulation, insider dealing and issuer-related breaches. During the first year of its current strategy, the FCA also reported that 12 individuals had been fined a combined £1.77 million for market-abuse offences and that criminal convictions included insider dealing and associated money laundering.
The enforcement message is broader than financial severity. Regulators are targeting the people who trade, the employees who disclose information, the issuers that mislead markets and the institutions whose surveillance systems fail to detect suspicious behaviour.
What market abuse looks like in practice
Insider dealing occurs when a person trades, recommends a trade or induces another person to act while possessing material non-public information, subject to the legal requirements of the relevant jurisdiction. The information may concern a takeover, earnings result, capital raising, regulatory decision, drug trial, contract award or planned asset listing.
Unlawful disclosure can occur even where the person sharing the information does not trade personally. A corporate employee, adviser, banker or consultant may pass confidential information to a relative, friend or business contact who then trades.
Market manipulation concerns conduct that creates, or is likely to create, a false or misleading impression of supply, demand or price, or secures a price at an artificial level.
Spoofing and layering involve entering orders without a genuine intention to execute them, often to create an impression of buying or selling pressure. The orders are cancelled after other participants react.
Wash trading involves transactions in which the economic ownership does not meaningfully change. The purpose may be to fabricate volume, influence price or create the appearance of liquidity.
Marking the close involves trading near the end of a session to influence an official closing or settlement price. The impact can extend beyond the transaction itself where that price determines derivatives valuation, collateral, fund performance or the cost of physical commodities.
Pump-and-dump schemes use promotion and coordinated buying to inflate an asset before insiders sell. Social media, messaging groups and online influencers have expanded the potential reach and speed of these campaigns.
Misleading issuer disclosure creates another form of market-integrity harm. Inaccurate or delayed information can affect investor decisions even where no manipulative order is placed.
These behaviours require different evidence and surveillance techniques. Treating all unusual trading as one generic typology produces excessive alerts while missing the context that separates legitimate strategy from abuse.
Why fine totals provide an incomplete picture
The first limitation is enforcement latency. A penalty imposed in 2026 may concern trading from several years earlier. Annual totals therefore combine historical misconduct with current enforcement capacity.
The second limitation is classification. Some regulators publish market-manipulation penalties separately, while others include them within wider fraud, supervision or systems-and-controls categories.
The third is the difference between firm and individual liability. Insider dealing is frequently pursued against the trader or tipper, while the employer may face no penalty unless its controls, supervision or disclosures were deficient.
The fourth is the treatment of disgorgement, restitution and forfeiture. A settlement may include repayment of gains, prejudgment interest, a civil penalty and compensation to investors. Different datasets may count all or only some of those amounts.
The fifth is non-financial enforcement. Imprisonment, industry bans, licence restrictions and public findings can have a greater deterrent or operational impact than the monetary penalty.
Finally, the published fine excludes remediation. A firm may need to rebuild surveillance systems, review years of historical activity, compensate customers, engage independent reviewers and respond to litigation. Reputational harm and management distraction can substantially exceed the regulatory payment.
Fine data should therefore be treated as evidence of enforcement outcomes, not a complete measure of market-abuse risk.
How enforcement priorities are changing
US authorities continue to emphasise individual accountability, cross-border misconduct and abusive trading supported by emerging technology. The SEC’s fiscal year 2025 cases included spoofing, social-media-driven manipulation, insider dealing and cross-border pump-and-dump activity. It also established a specialist unit focused on cyber and emerging technologies.
The Commodity Futures Trading Commission has identified insider trading, energy-market manipulation and disruptive trading as core priorities. Its stated market-abuse focus includes spoofing, wash trading and activity intended to distort closing prices.
Prediction markets have created a new enforcement frontier. Traders may possess non-public information about an event’s outcome because of their employment, official role or direct influence over the event. The product is different from a conventional equity or futures contract, but the underlying concern remains the misuse of informational advantage.
In the United Kingdom, enforcement increasingly reflects both primary misconduct and surveillance failure. The FCA fined an investment firm £338,000 in 2026 after transactions from a new direct-market-access platform were not properly included within its surveillance environment. The case illustrates a recurring control weakness: a firm can invest in surveillance technology while leaving an entire product or data feed outside the system.
European reforms are also changing the management of inside information. Amendments connected with the EU Listing Act alter when issuers must disclose information arising during protracted processes and require existing policies, insider-list procedures and disclosure decisions to be recalibrated.
Australia has strengthened its focus on insider trading and market gatekeepers. In 2025, an Australian subsidiary of a global bank was fined A$3.88 million after clients placed suspicious orders near the close of electricity and wheat futures markets. The regulator criticised the failure to respond effectively despite earlier warnings and emphasised the potential effect on real-world energy and food prices.
Across these jurisdictions, the common priority is no longer only catching the trader after the profit has been made. Regulators are examining whether issuers, brokers, venues and advisers acted as effective gatekeepers.
Technology is changing both the abuse and the evidence
Electronic and algorithmic trading allows misconduct to occur at volumes and speeds that cannot be reviewed manually. A manipulative strategy can distribute orders across venues, accounts and instruments, making each component appear less significant in isolation.
Cross-product manipulation is particularly challenging. A trader may influence an underlying security to benefit a position in options, contracts for difference, swaps or another correlated instrument. Surveillance limited to one legal entity or trading venue may not identify the economic relationship.
Cryptoasset markets add pseudonymous wallets, decentralised exchanges and continuous trading. European rules under MiCA now extend market-abuse expectations to covered cryptoassets, while supervisors are developing methods to combine blockchain activity with exchange, issuer and social-media data.
Social media has altered how information and market sentiment are distributed. A person can build a position, promote an asset to a large audience and sell while followers continue purchasing. The promotional content, trading activity and financial relationship with the issuer may be held in separate systems.
Extended trading hours create further pressure. Markets operating for longer periods require surveillance, escalation and specialist staffing beyond conventional office hours. An alert generated overnight has limited value if no qualified analyst can review it before the activity continues.
Artificial intelligence can support detection by connecting communications, orders, market data and relationships. It can identify linguistic patterns, behavioural changes and coordinated activity that fixed rules may miss. However, AI also introduces model-risk, explainability and false-positive concerns. A sophisticated algorithm does not remove the need for reliable data or experienced human judgement.
Why surveillance programmes fail
The first failure mode is incomplete data. New platforms, products or message channels may not be captured, or timestamps and customer identifiers may not align across systems.
The second is weak change governance. A firm can launch a new trading service without confirming that the order and trade feeds reach surveillance. The control exists conceptually but does not cover the activity creating the risk.
The third is fragmented monitoring. Trade surveillance, employee dealing, issuer disclosure, conflicts management and electronic-communications review may be operated by separate teams that do not combine their evidence.
The fourth is poorly calibrated detection. Excessively broad scenarios generate high volumes of low-value alerts, while narrow thresholds fail to identify distributed or cross-market conduct.
The fifth is inadequate model testing. Firms may confirm that an alert engine is running without testing whether it detects the behaviour it was designed to identify. Historical cases, synthetic scenarios and controlled manipulation patterns should be used to assess performance.
The sixth is weak escalation. Analysts may identify unusual trading but lack the market expertise, authority or contextual information required to challenge the explanation and submit a suspicious transaction and order report.
Finally, governance can become focused on alert closure rather than risk coverage. A fast closure rate is not evidence of effectiveness where entire products, venues or typologies remain outside the programme.
What an evidence-led investigation looks like
The investigation should begin with a precise chronology. Analysts need to identify the relevant market event, when the information became price-sensitive, who had access to it and how the trading developed before and after publication.
Order-level evidence is essential. Investigators should review entries, amendments, cancellations, executions, positions, profits and the relationship between displayed orders and genuine trading intent.
Communications provide context. Voice calls, emails, messaging platforms and recorded meetings may show instructions, knowledge, coordination or attempts to conceal the purpose of a trade.
Relationship analysis can connect employees, customers, issuers, advisers and external traders. Shared addresses, devices, accounts or communication patterns may reveal links that are not apparent from names alone.
Legitimate explanations must also be tested. A trader may have acted on public research, maintained a documented hedging strategy or followed a consistent trading pattern established before the event.
The evidential standard should distinguish unusual activity from unlawful conduct. Surveillance identifies the question; investigation determines whether the available facts support suspicion, escalation or regulatory reporting.
What a resilient control stack looks like
The first layer is an enterprise market-abuse risk assessment covering products, venues, customers, employees, information flows and emerging technologies.
The second layer is complete and reconciled data. Every in-scope order, trade, communication and reference-data feed should be inventoried, tested and subject to change controls.
The third layer is event-based surveillance. Confidential transactions, issuer announcements, research publications and listing decisions should be connected with employee and customer trading.
The fourth layer is cross-market analytics. Firms need to assess related activity across cash securities, derivatives, cryptoassets, commodities and different execution venues.
The fifth layer is communications integration. Trading alerts should be assessed alongside relevant voice, email and messaging data rather than reviewed as separate conduct events.
The sixth layer is model validation. Scenarios should be tested against known cases, synthetic activity and changing market conditions. Overrides, missed cases and alert concentrations should be monitored.
The seventh layer is accountable escalation. Experienced reviewers must have clear authority to restrict activity, preserve evidence, investigate employees and submit regulatory reports promptly.
Finally, confirmed cases must improve the control environment. New behaviours, channels and relationships should feed back into risk assessments, models and staff training.

What this means for financial crime leaders
Market-abuse enforcement is moving beyond the misconduct of an isolated trader. Regulators increasingly assess the full control chain: who possessed the information, who traded, which institution transmitted the order and whether the gatekeeper detected and escalated the risk.
Leaders should resist using fine totals as the principal measure of regulatory intensity. A low annual figure may reflect unresolved investigations, individual prosecutions or differences in penalty design rather than lower risk.
The stronger questions concern coverage and evidence. Can the institution identify manipulation across related markets? Are new products included before launch? Can communications, access records and trading be reconstructed quickly? Do surveillance models detect the behaviour they claim to cover?
The future priorities are already visible: individual accountability, cross-border manipulation, social-media promotion, cryptoassets, prediction markets, energy and commodity pricing, algorithmic conduct and the use of AI in both trading and surveillance.
Market abuse evolves wherever information, technology and fragmented liquidity create an advantage. Institutions that connect those elements defensively will be better positioned to protect price formation, meet gatekeeper obligations and intervene before suspicious conduct becomes a regulatory case years later.
What Financial Institutions Should Consider
- Strengthen Trade Surveillance Frameworks
- Integrate Trade and Electronic Communications Surveillance
- Review Market Manipulation Detection Scenarios
- Strengthen Insider Dealing Controls
- Monitor Employee and Personal Account Dealing
- Improve Surveillance Data Quality and Completeness
- Apply Advanced Analytics to Trading Behaviour
- Strengthen Cross-Market and Cross-Asset Surveillance
- Review Surveillance Model Coverage and Effectiveness
- Maintain Robust Alert Investigation and Escalation Processes
- Strengthen Governance Over Surveillance Systems
- Conduct Regular Market Abuse Risk Assessments
- Improve Record-Keeping and Evidential Audit Trails
- Monitor Regulatory Enforcement Trends Across Jurisdictions
- Assess Conduct Risk Alongside Market Abuse Risk
- Invest in Modern eComms Surveillance Capabilities
- Strengthen Compliance Training and Accountability
- Test Controls Against Emerging Manipulation Typologies
Download the briefing
Market Abuse Enforcement: Global Trends, Surveillance Failures, and Institutional Risks




Market-abuse enforcement cannot be understood through regulatory fine totals alone. Penalties provide useful evidence of supervisory priorities, but they are shaped by enforcement delays, legal classifications, jurisdictional differences and the way authorities distinguish fines, disgorgement, restitution and individual sanctions.
The more important question is whether institutions can detect abusive conduct before it develops into a regulatory case. Insider dealing, spoofing, wash trading, pump-and-dump schemes and cross-market manipulation increasingly operate across multiple venues, instruments, legal entities and communications channels. Surveillance confined to one platform or asset class will struggle to reconstruct the complete economic strategy.
Regulators are also placing greater emphasis on gatekeeper responsibility. Exchanges, brokers, issuers, advisers and trading firms are expected to maintain complete data coverage, respond to suspicious activity and ensure that new products and execution channels are incorporated into surveillance from launch. A system that processes alerts efficiently is not effective if material trading activity remains outside its scope.
The strongest control frameworks will combine event-based monitoring, cross-product analytics, communications review, relationship intelligence and independent model validation. They will distinguish unusual activity from unlawful conduct while preserving the evidence needed to explain and escalate genuine concerns.
Ultimately, market abuse evolves wherever confidential information, fragmented liquidity and technology create an exploitable advantage. Institutions that connect those elements defensively—and convert confirmed cases into stronger controls—will be better positioned to protect market integrity, meet their gatekeeper obligations and intervene before suspicious conduct becomes a public enforcement action.