DOJ and DHS Issue Joint Trade Enforcement Guidance (08/11/2026)

August 11, 2026
DOJ and DHS Issue Joint Trade Enforcement Guidance (08/11/2026)
Key Intel / TL;DR
  • The Justice Department and DHS published joint trade enforcement guidance that changes what importers need to be able to show.
  • HIPAA-covered organizations received a specific warning about Gunra ransomware, which is exploiting Fortinet and Schneider Electric flaws and bypassing multi-factor authentication.
  • The FTC sent a warning letter to Mortgage Connect, signaling continued enforcement in the sector.
  • Sunshine Health and Health Payment Systems both reported data breaches.
  • Federal grant recipients face funding delays and new compliance uncertainty.

Two agencies issuing guidance together is worth more attention than either doing it alone, because it usually means a coordinated enforcement posture is already staffed behind it. The DOJ and DHS trade guidance is today’s lead for anyone importing. Underneath it, healthcare got a named ransomware warning with a specific set of flaws attached, which is the useful kind.

Top 5 Critical Compliance Alerts

1. DOJ and DHS Publish Joint Trade Enforcement Guidance

The Justice Department and the Department of Homeland Security issued new joint guidance on trade enforcement, setting out what companies need to know about their exposure. JD Supra

Operator Note: Joint guidance is a staffing signal. Two agencies aligning their position generally means referrals are already flowing between them, so the practical question is whether your import documentation would survive a request from either one without a scramble.

2. Healthcare Gets a Named Ransomware Warning

Healthcare organizations received a specific warning about Gunra ransomware, the operation exploiting Fortinet and Schneider Electric flaws and bypassing multi-factor authentication while targeting critical infrastructure. HIPAA Journal

Operator Note: A warning that names the actor and the flaws is directly actionable, which most are not. Check your Fortinet and Schneider Electric estate against it this week, and treat multi-factor authentication as insufficient rather than as the control that closes this.

3. The FTC Sends Mortgage Connect a Warning Letter

The FTC issued a warning letter to Mortgage Connect, which practitioners read as a signal of continued enforcement risk in the sector. JD Supra

Operator Note: A warning letter is the cheapest enforcement tool an agency has and the clearest notice you will get. If you operate in the same space, the letter is effectively free guidance on what they are looking at.

4. Two More Healthcare Breach Notifications

Sunshine Health and Health Payment Systems both reported data breaches. HIPAA Journal

5. Federal Grant Recipients Face Delays and New Uncertainty

Organizations receiving federal grants are dealing with funding delays alongside compliance uncertainty about what is now required of them. JD Supra

Operator Note: Nonprofits and research organizations feel this first and hardest, because a delayed disbursement lands on payroll while the compliance obligation stays fixed. Anyone with grant revenue should be modeling a gap now rather than when it arrives.

Additional Compliance Alerts

Regulatory Updates

  • The Justice Department’s Fraud Section gets a rebrand: Worth tracking for what the naming change signals about priorities. Radical Compliance
  • Agencies update the Community Bank Leverage Ratio guide: The compliance guide for the framework has been revised. JD Supra

Policy & Governance Updates

  • Minnesota’s earned sick and safe time rules land on employers: New obligations for anyone with Minnesota staff. JD Supra

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Dusten Trounce
Director of Physical Security
Dusten Trounce
The Growth Architect.

A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)