News

Luxembourg’s Financial Intelligence Unit authorized to share certain fraud data with PSPs

3min Read · 7 Aug 2026
luxembourg fraud data crf

After a few months of discussion, the new law aimed at strengthening the powers of the CRF (standing for Cellule de Renseignement Financier, the Financial Intelligence Unit in Luxembourg) in the fight against fraud, money laundering and terrorist financing has been adopted. It enters into force on 8 August 2026.

 

Background: more (sophisticated) frauds

Across the EU, a growing number of countries are starting to implement new measures to combat financial fraud. France, for example, introduced the FNC-RF in May 2026, a national register of accounts reported as presenting a fraud risk.

In Luxembourg, last year’s annual Police report highlighted a growing number of frauds, with 6 382 cases recorded in 2024. These cases revolved mainly around email/SMS/phone phishing, fake deliveries, fraudulent investments, charity scams, etc. The number of social engineering fraud schemes is also increasing, causing significant losses to companies, associations and other organizations. Examples include CEO fraud and Business Email Compromise (BEC) schemes.

While the CRF was receiving an increasing number of fraud reports and cooperating with law enforcement authorities, a specific legal basis was required to enable it to notify the PSPs. Moreover, this information could not be used proactively to help prevent similar fraud schemes.

In this respect, Luxembourg has decided to enhance its own anti-fraud, anti-money laundering and counter-terrorist financing framework. The proposal was first introduced in Bill No. 8722 in March 2026. This resulted in the Law of 22 July 2026 which was published in the Official Journal of the Grand Duchy of Luxembourg on 4 August 2026.

 

Modus operandi

In this context, the law notably enables the CRF to share alerts with credit institutions, professionals of the financial sector (PFS), payment and electronic money institutions as well as crypto asset-service providers (CASPs) established or authorized in Luxembourg. This communication happens through a secure communication channel, the financial intelligence unit’s “GoAML” platform.

Upon request by the companies mentioned previously, provided they comply with all legal requirements, the information shared may include:

  • account numbers brought to the attention of the CRF and identified as presenting a significant fraud risk – IBANs, but also virtual IBANs and any account number assigned under another numbering system that enables the account to be identified;
  • the fraud typologies associated with the use of those accounts.

The objective is to prevent further fraud involving accounts identified as presenting a significant fraud risk.

In addition, the CRF will organize meetings at least every six months to assess the relevance of the alerts and, where appropriate, refine its future communications. Regular exchanges between the CRF and the professionals concerned should help ensure the quality of the alerts and limit the information transmitted to what is strictly necessary.

 

Leveraging CRF data

The law emphasized that the companies remain solely responsible for the use made of the information received.

Once the Luxembourg Financial Intelligence Unit, the CRF, will start sharing data, the receiving entities will have the possibility to review their past transactions and notify Suspicious Activity Reports, where necessary. And leverage this data to prevent future fraud.

The data may in no event be disclosed to the customer concerned or to any third party. In terms of retention duration the law imposes a deletion by the no later than six months after receipt, which raises some questions as this timeframe is not necessarily aligned with other AML or payment legal retention durations.

 

Key takeaway

As of 8 August 2026, Luxembourg’s Financial Intelligence Unit (CRF) may share information on accounts identified as presenting a significant fraud risk with banks, payment institutions, electronic money institutions and crypto-asset service providers.

The objective is to help regulated entities detect, prevent and report fraud, money laundering and terrorist financing more effectively.