Skip to content
All issues

FinCrime Intelligence Weekly

Issue №12 · Aug 10 – 16, 2026

FinCEN finds banks file 3 percent of human smuggling reports but hold 61 percent of the money, Binance cuts off 16 platforms on its own timetable, and Lebanon charges a former central bank governor.

FinCrime Intelligence Weekly - Issue 12: The control moved to the intermediary. Your framework did not
MB

Marco’s Take

Marco Beranzoni

Welcome to Issue 12 of FinCrime Intelligence Weekly. Facts sourced, actions named, no filler. Here is what changed last week and what to do about it this week.

I kept noticing the same thing in five unrelated stories this week: the decisive actor sat between the institution and the risk.

FinCEN’s trend analysis on suspected human smuggling makes the point in numbers. Money services businesses filed roughly 97 percent of the reports. Depository institutions filed about 3 percent, and those few reports carried around 61 percent of the suspicious dollars. The small filer sees the pattern. The big filer holds the money.

The same shape repeats. The Block reported that Binance, not a supervisor, set the dates on which 16 named platforms stop being reachable. In the OFAC settlement with Rice Lake Weighing Systems, a distributor in the UAE is the step that turned an Italian sale into an Iran sale. In Lebanon, the man now facing charges was himself the layer between the state and the commercial banks.

Here is the observation I would keep. Most control frameworks are drawn around the institution, and almost none are drawn around the intermediary that institution depends on.

The uncomfortable thing to do this week: pull your top ten counterparties, correspondents, distributors, agents, or platforms, and ask who would tell you if one of them were cut off tomorrow. If the honest answer is the counterparty, eventually, you have found your gap.

See you next Monday.

Marco

The 5 stories that matter

Regulatory Radar

What changed this week, why it matters, and what to do about it.

US

FinCEN published a Financial Trend Analysis on 13 August showing financial institutions flagged nearly $5 billion linked to suspected human smuggling across 67,540 Bank Secrecy Act (BSA) reports filed between 2023 and 2025. Reports peaked in 2024 and fell 62 percent in 2025.

Why it matters:The filing profile is lopsided. Money services businesses (MSBs) filed approximately 97 percent of the reports, while depository institutions filed roughly 3 percent and accounted for about 61 percent of the suspicious amounts. That is a detection-coverage question for every bank in the dataset's footprint.

Action:Compare your own filing volume and dollar profile for the same three years against FinCEN's stated indicators: unverifiable originator to beneficiary relationships, transactions along common migration routes, and excessive cash activity along the southwest border. Document why your shape differs.

EU

The Block reported on 14 August that Binance will stop processing transactions involving 16 crypto-asset service providers, including HTX, on staged cutoffs of 7 August, 13 August, and 23 August. The move follows the EU's July sanctioning of HTX for allegedly helping Russia circumvent sanctions.

Why it matters:A private exchange is applying a sanctions list to its own users on a timetable it set. Binance said transactions involving the named entities after their cutoff date will trigger a compliance review that may result in wallet restrictions.

Action:Screen customer and counterparty exposure to the 16 named entities before the 23 August tranche, and check whether your crypto counterparty risk model tracks venue-level access decisions, not only designations.

Global

OFAC announced a $60,764 settlement with Rice Lake Weighing Systems, Inc. on 12 August over eight apparent violations of Iran sanctions, arising from its Italian subsidiary Dini Argeo S.r.l. exporting weighing equipment through a distributor in the UAE knowing the goods were destined for Iran between July 2019 and November 2021.

Why it matters:A US parent settled for the conduct of a non-US subsidiary, on a knowledge standard, through a third-country distributor. OFAC determined the apparent violations were voluntarily self-disclosed and non-egregious.

Action:Map which non-US subsidiaries sell through third-country distributors, and test whether your export controls capture knowledge of ultimate destination rather than only the invoiced ship-to address.

Other

OCCRP reported on 11 August that Judge Raja Hamouche filed proceedings on 10 August against former Lebanese central bank governor Riad Salame and Samir Hanna, former head of Bank Audi, over allegations including embezzlement, money laundering, bribery, and illicit enrichment. The Public Prosecutor of Appeal requested an arrest warrant against Salame. Salame has repeatedly denied all charges, and nobody has been convicted.

Why it matters:OCCRP describes this as the second indictment against Salame in Lebanon this year and the third in total, alongside allegations by European authorities in Switzerland, France, Germany, and Luxembourg. Politically exposed person (PEP) files tied to Lebanese banking need to reflect an active, multi-jurisdiction picture.

Action:Refresh adverse media and PEP screening on Lebanese central bank and commercial bank relationships, and check whether your escalation path distinguishes charges from convictions in the customer risk record.

Typology of the week

Third-country transshipment through a permissive distribution hub

How it works

Goods or value move from a supplier in a compliant jurisdiction to a distributor or intermediary in a permissive hub, and only then to the restricted destination. On paper, the transaction is clean: the invoice, the shipping documents, and the payment all name the intermediate country. The supplier's screening runs against that stated destination and returns nothing. The exposure sits in what the parties actually know rather than in what the paperwork says, and it often sits in a foreign subsidiary rather than in the group entity that owns the compliance programme. A knowledge standard does not require a sanctions match. It requires that someone in the chain understood where the goods were really going.

Red flags

  • A distributor whose order volume is far larger than the local market it nominally serves.
  • Purchase orders, technical specifications, or service requests that reference a language, voltage standard, or configuration common to the restricted destination rather than the shipping country.
  • Repeat orders routed through a single intermediary in a known transshipment hub, with no local installation, service, or warranty activity.
  • Payment terms, banking routes, or freight forwarders that do not match the stated destination of the goods.
  • Correspondence, email threads, or sales notes in which staff discuss the real end-user while the documentation names another country.

Sectors exposed

Industrial and precision equipment manufacturers with overseas subsidiaries Freight forwarding, logistics, and trade finance providers Electronics and dual-use component distributors Banks financing export receivables where the ship-to party is an intermediary rather than the end-user

Controls to review

  • Group-wide extraterritorial policy coverage: confirm that non-US subsidiaries operate under a sanctions policy the parent can evidence, not a local variant.
  • End-user verification for sales into transshipment hubs, including a documented end-use statement retained with the order file.
  • Screening that reaches beyond the ship-to field into the end-user, the forwarder, and the ultimate consignee.
  • Sales-side escalation and voluntary self-disclosure procedure, so a knowledge concern raised by a salesperson reaches compliance in days rather than years.

Example

Illustrative of a documented method, not a specific real case. A European subsidiary of a manufacturing group sells calibration equipment to a distributor in a regional trading hub. Volumes rise over two years, but the distributor never requests local service visits, and its technical queries reference operating conditions specific to a country under sanctions. Group screening clears every order because the ship-to party sits in the hub. The control gap is not the screening list. It is that nobody tested whether the stated destination was the real one.

Enforcement Watch

Recent actions and the control lessons behind them.

  • US parent settles for a subsidiary sale routed through a UAE distributor

    $60,764

    Rice Lake Weighing Systems, Inc.

    Control failure:OFAC's 12 August release states that Rice Lake's Italian subsidiary, Dini Argeo S.r.l., exported weighing equipment between July 2019 and November 2021 to a distributor in the UAE with the knowledge that the goods would be reexported to an end-user in Iran. Eight apparent violations followed. The screening on the shipping destination would have cleared each shipment, because the destination on the paperwork was not the destination in fact.

    Lesson:Do not read this one by its size. A US parent carried potential liability for a non-US subsidiary's sales, on a knowledge standard, through a third-country intermediary nobody had to screen against a list. OFAC determined the apparent violations were voluntarily self-disclosed and non-egregious, which is the other half of the lesson: the disclosure route matters. Test whether your subsidiaries can raise a destination concern to group compliance, and whether anyone would act on it.

  • Lebanon files fresh proceedings against a former central bank governor and a former bank chief

    Banque du Liban and Bank Audi (former officeholders)

    Control failure:OCCRP reported on 11 August that Judge Raja Hamouche filed proceedings on 10 August against Riad Salame, 76, and Samir Hanna, 88, the former head of Bank Audi. The allegations include the creation of shell companies, misappropriating central bank funds, and the fraudulent use of those funds to buy shares and bonds in commercial banks, alongside illicit enrichment, money laundering, and bribery. The Public Prosecutor of Appeal requested an arrest warrant against Salame. Nobody has been convicted, Salame has repeatedly denied all charges, and Hanna could not be reached for comment. OCCRP reports Hanna has already paid $1 million bail and is not in custody.

    Lesson:The control question is about the layer between the state and the banks. When the same office both sets monetary policy and transacts with the commercial banks it supervises, ordinary correspondent due diligence sees a sovereign counterparty and stops looking. European authorities allege Salame siphoned funds through a front company owned by his brother, and investigations in Switzerland, France, Germany, and Luxembourg allege stolen public funds moved into European property and accounts. Those are allegations, not findings. For a practitioner, the takeaway is that a central bank relationship deserves a named beneficial ownership and commission-flow review, not an institutional presumption of low risk.

Crypto, Fraud & AI

When an exchange, not a regulator, sets the date your counterparty disappears

The Block reported that Binance will stop processing transactions involving 16 named crypto-asset service providers across three cutoffs: 7 August, 13 August, and 23 August. The EU sanctioned HTX in July. Binance chose when, and for whom, access ends, and said breaches will trigger a compliance review that may restrict a wallet. Most counterparty risk models are built on designation dates published by a regulator. This one runs on a venue's own enforcement calendar, and it changes settlement risk before any list changes. Practical fix: add venue-level access events as a distinct data field in crypto counterparty monitoring, sourced from exchange announcements rather than sanctions feeds alone, and set an alert for customers with recent flows to a named entity ahead of its cutoff.

The filing asymmetry is a detection-coverage problem, not a compliance-culture story

FinCEN's 13 August trend analysis puts approximately 97 percent of suspected human smuggling reports with money services businesses and about 3 percent with depository institutions, while those depository institution reports hold roughly 61 percent of the suspicious dollar amounts. Read as a model problem, that is a coverage gap: the institutions holding the largest values are producing the fewest observations, so any bank model trained mainly on its own alert history has thin ground truth for this typology. The useful move is to import the typology descriptions FinCEN published, funnel accounts receiving funds from numerous individuals, suspected structuring of cash, and travel agencies arranging migrant travel, and run them as retrospective scenarios against your own data rather than waiting for the next alert to teach the model. The 62 percent drop in 2025 reports is a fact from FinCEN. Whether it reflects less activity or less detection is analysis, and it is worth stating that uncertainty out loud in your model documentation.

Career & Skills Corner

Read a trend analysis as a benchmark against your own filing data

FinCEN published something more useful than an advisory on 13 August. It published the shape of a typology as it appears in reported data: 67,540 Bank Secrecy Act reports across three years, nearly $5 billion in flagged value, roughly 97 percent of reports from money services businesses, about 3 percent from depository institutions carrying around 61 percent of the dollars, and a 62 percent fall in 2025. Most practitioners will read that, nod, and file it. The career move is to treat it as a benchmark. Pull your own numbers for 2023 to 2025 for the same typology. How many reports, what total value, what proportion of your total filings, and which indicators drove them. Then put your profile next to FinCEN's and write one page explaining the difference. Sometimes the answer is business model: you have no southwest border cash exposure, so of course your volume is low. Sometimes the answer is that your scenarios never looked. Two things make this exercise worth your time. First, it converts a public document into evidence about your own institution, which is the difference between reading regulation and using it. Second, when a supervisor or an internal auditor asks why your filing volume looks the way it does, you have a written answer with a date on it rather than an improvised one. Do it for one typology this quarter. Then do it again next time a trend analysis lands. Within a year you have a benchmarking habit that very few people in this profession actually maintain, and it shows in every conversation you have about coverage.

What I’m watching next week

Three things, and one open question. The 23 August Binance tranche is the big one, because that is when HTX and the rest of the list go dark for Binance users, and I want to see whether any customer flows visibly reroute before the date. In Lebanon, the Public Prosecutor of Appeal has requested an arrest warrant against Salame, so whether a judge issues it, and what happens given the reported hospital supervision, will shape how the case moves. In Dublin, the strategy is a plan rather than an instrument, so I am watching for the statutory instruments that turn the crypto Travel Rule elements, the private wallet checks, and the Limited Partnership disclosure requirements into binding obligations with dates attached. The open question sits under all of it: whether other exchanges follow Binance and publish their own cutoff calendars. If they do, counterparty access becomes something the market decides on its own timetable, and our models need a field for that.

Want to do this for a living?

Turn this weekly intelligence into a career. Marco’s AML & Financial Crime course takes you from curious to hireable.

AML & Financial Crime course →