A7 network moved $6.9 billion through global banks using forged trade documents
A Kremlin-backed payment network used forged invoices and altered goods codes to keep sanctioned funds flowing through correspondent banks.
FinCrime Intelligence Weekly
A7 moves 6.9 billion dollars on forged trade papers, Bitget loses 390 million to a spoofed backend, Europol busts a phone shop laundering ring, and the DOJ investigates Binance over Iran sanctions.
Marco’s Take
Marco Beranzoni
Three of this week’s five stories run the same play. A7 forged trade documents and stripped Cyrillic markings to keep correspondent banking access open. Europol’s network forged travel documents so migrants could cross borders undetected, then laundered the proceeds through mobile phone shops. Bitget’s attacker spoofed backend authorization data instead of stealing a private key.
None of this is fraud dressed up as sophistication. Each relies on the same bet: a screening step trusts the document or instruction in front of it rather than verifying what sits behind it. A stamped certificate of origin, a scanned passport, and a backend transaction request all get treated as ground truth once they clear the first check.
The other two stories are not about fakes. The DOJ is investigating whether Binance’s compliance program actually stopped Iran sanctioned trading after its 2023 settlement, or just existed on paper. The EU is deciding whether a real election needs a real consequence. Neither depends on anyone being fooled by a forged document. Both come down to whether a control does what it is supposed to do when nobody is hiding anything.
Here is this week’s uncomfortable task. Pick one document type your team accepts at face value: a certificate of origin, a passport scan, or a payment instruction. Ask when someone last verified it independently, rather than confirmed it was present. If the answer is never, you have found a gap before someone else does.
See you next Monday.
Marco
A Kremlin-backed payment network used forged invoices and altered goods codes to keep sanctioned funds flowing through correspondent banks.
Suspected North Korean hackers moved crypto out of Bitget's hot and warm wallets on September 24, with the confirmed figure later revised upward.
Six arrests across four countries expose a network that laundered smuggling proceeds through mobile phone shops after forging documents for migrants who entered on legitimate Schengen visas.
Manhattan prosecutors and the DOJ's criminal division are examining whether Binance knowingly allowed trading that violated US sanctions on Iran.
Kaja Kallas says Brussels will sanction election organizers and occupied territory candidates after Russia's State Duma vote, which barred OSCE observers.
What changed this week, why it matters, and what to do about it.
| Region | Update | Why it matters | Action |
|---|---|---|---|
| Global | A Financial Times investigation published on September 21, 2026 found that A7, a payment network founded by Moldovan oligarch Ilan Shor with backing from Russian state owned Promsvyazbank, moved 6.9 billion dollars through the global banking system between late 2024 and August 2025, using more than 200 shell entities and industrial scale document forgery. | A7 was placed under UK sanctions in May 2025, yet the network kept reaching SWIFT connected correspondent banks by forging certificates, stamps and goods codes rather than by evading sanctions screening directly. | Trade finance and correspondent banking teams should treat document authenticity, not just sanctions list matching, as its own control and revisit how forged certificates of origin or altered goods codes would actually be caught. |
| EU | Europol coordinated an action day on September 22, 2026 across Austria, Italy, Spain and the UK, with 17 countries involved, leading to six arrests and ten house searches tied to a network supplying forged travel documents from a Vienna hub. | Migrants entered the EU on genuine passports and valid Schengen visas, then switched to forged papers to travel undetected, while proceeds were laundered through ordinary looking mobile phone shops rather than through banks. | Money service business and retail sector compliance teams should review whether cash intensive small retailers, such as phone shops, sit inside their financial crime monitoring at all. |
| Global | Bitget disclosed a hack between September 24 and 25, 2026 in which attackers compromised a backend system to spoof transaction data, moving about 390 million dollars from hot and warm wallets across seven blockchain networks. | Elliptic and TRM Labs linked the intrusion to infrastructure used in the 2025 Bybit hack and the group known as TraderTraitor, and the theft pushed North Korea's 2026 crypto theft total above 1 billion dollars. | Exchanges should extend security reviews beyond private key custody and cold storage to the backend systems that authorize and validate withdrawal requests. |
| US | Bloomberg reported on September 22, 2026 that the Manhattan US Attorney's Office and the DOJ's criminal division are investigating whether Binance knowingly allowed trading that violated US sanctions on Iran, following a September 14 forfeiture action tied to a $1.5 billion Iranian oil money laundering network. | Binance's 2023 guilty plea and $4.3 billion settlement addressed past conduct. This investigation tests whether the exchange's compliance program actually stopped sanctioned activity afterward, not whether it exists on paper. | Institutions with any Binance exposure should treat the 2023 settlement as historical, not as evidence current controls work, and screen for ties to the wallet network named in the September 14 forfeiture action. |
| EU | On September 21, 2026, Kaja Kallas said the EU is preparing new sanctions after Russia's State Duma elections, held September 18 to 20, 2026, targeting election organizers, candidates who ran in occupied Ukrainian territory, and those undermining free elections inside Russia. | No formally adopted package or timeline exists yet, so this is a political signal of intent rather than an active designation that compliance teams need to screen against today. | Sanctions teams should monitor for a formal EU proposal rather than adjusting screening lists on the strength of the announcement alone. |
A Financial Times investigation published on September 21, 2026 found that A7, a payment network founded by Moldovan oligarch Ilan Shor with backing from Russian state owned Promsvyazbank, moved 6.9 billion dollars through the global banking system between late 2024 and August 2025, using more than 200 shell entities and industrial scale document forgery.
Why it matters:A7 was placed under UK sanctions in May 2025, yet the network kept reaching SWIFT connected correspondent banks by forging certificates, stamps and goods codes rather than by evading sanctions screening directly.
Action:Trade finance and correspondent banking teams should treat document authenticity, not just sanctions list matching, as its own control and revisit how forged certificates of origin or altered goods codes would actually be caught.
Europol coordinated an action day on September 22, 2026 across Austria, Italy, Spain and the UK, with 17 countries involved, leading to six arrests and ten house searches tied to a network supplying forged travel documents from a Vienna hub.
Why it matters:Migrants entered the EU on genuine passports and valid Schengen visas, then switched to forged papers to travel undetected, while proceeds were laundered through ordinary looking mobile phone shops rather than through banks.
Action:Money service business and retail sector compliance teams should review whether cash intensive small retailers, such as phone shops, sit inside their financial crime monitoring at all.
Bitget disclosed a hack between September 24 and 25, 2026 in which attackers compromised a backend system to spoof transaction data, moving about 390 million dollars from hot and warm wallets across seven blockchain networks.
Why it matters:Elliptic and TRM Labs linked the intrusion to infrastructure used in the 2025 Bybit hack and the group known as TraderTraitor, and the theft pushed North Korea's 2026 crypto theft total above 1 billion dollars.
Action:Exchanges should extend security reviews beyond private key custody and cold storage to the backend systems that authorize and validate withdrawal requests.
Bloomberg reported on September 22, 2026 that the Manhattan US Attorney's Office and the DOJ's criminal division are investigating whether Binance knowingly allowed trading that violated US sanctions on Iran, following a September 14 forfeiture action tied to a $1.5 billion Iranian oil money laundering network.
Why it matters:Binance's 2023 guilty plea and $4.3 billion settlement addressed past conduct. This investigation tests whether the exchange's compliance program actually stopped sanctioned activity afterward, not whether it exists on paper.
Action:Institutions with any Binance exposure should treat the 2023 settlement as historical, not as evidence current controls work, and screen for ties to the wallet network named in the September 14 forfeiture action.
On September 21, 2026, Kaja Kallas said the EU is preparing new sanctions after Russia's State Duma elections, held September 18 to 20, 2026, targeting election organizers, candidates who ran in occupied Ukrainian territory, and those undermining free elections inside Russia.
Why it matters:No formally adopted package or timeline exists yet, so this is a political signal of intent rather than an active designation that compliance teams need to screen against today.
Action:Sanctions teams should monitor for a formal EU proposal rather than adjusting screening lists on the strength of the announcement alone.
Typology of the week
A payment network builds a web of shell entities across multiple jurisdictions, then uses industrial scale document forgery, including thousands of corporate stamps, altered certificates of origin and replaced goods codes, to make sanctioned trade and payment flows look ordinary to the correspondent banks that process them. Documents are also stripped of markers that would tie a transaction back to a sanctioned jurisdiction, and goods can be mislabeled entirely, describing restricted equipment as a more mundane item, so the transaction clears standard trade finance and sanctions screening.
Example
A7, a payment network founded by Moldovan oligarch Ilan Shor with backing from Russian state owned Promsvyazbank, moved 6.9 billion dollars through the global banking system between late 2024 and August 2025 using more than 200 shell entities and forged trade documentation, according to a Financial Times investigation published on September 21, 2026, despite A7 itself being placed under UK sanctions in May 2025. The banks that processed payments, including Standard Chartered, First Abu Dhabi Bank, DBS Hong Kong, Citigroup clients, Deutsche Bank and JPMorgan Chase, are not alleged to have known the documentation was forged.
Recent actions and the control lessons behind them.
Europol coordinated action
Control failure:A network built around a Vienna forgery hub, alongside a Spanish cell that made more than 2 million euros selling over 1,000 false documents, needed a way to move its proceeds and chose ordinary mobile phone shops rather than banks. That choice worked because retail businesses selling handsets and airtime rarely sit inside anti money laundering monitoring the way regulated money service businesses do.
Lesson:A cash intensive retail shopfront can function as an informal value transfer point even without formal money service business registration. Due diligence teams and law enforcement liaison should not assume laundering risk stops at licensed MSBs, particularly where a shop's cash flows sit alongside turnover generated by document fraud at this scale.
Bitget's hack between September 24 and 25, 2026 came from attackers compromising a backend system to spoof transaction data, not from stealing a private key, and it drained hot and warm wallets across seven blockchain networks while cold storage stayed untouched. Elliptic and TRM Labs linked the laundering infrastructure to the 2025 Bybit hack and TraderTraitor, pointing to North Korea, and the theft pushed the group's 2026 crypto theft total above 1 billion dollars. Exchange security reviews built mainly around key custody and cold storage now need to cover the backend systems that validate and authorize withdrawal requests.
The A7 network reportedly used thousands of corporate stamps, altered certificates of origin and replaced goods codes to move 6.9 billion dollars and route it through banks including Standard Chartered, First Abu Dhabi Bank and DBS Hong Kong, none of whom are alleged to have known the documents were forged. The scale described, hundreds of shell entities across more than half a dozen jurisdictions, suggests forgery at a volume that automated goods code and sanctions list checks alone will not catch. Trade finance teams should treat physical document forensics as a control in its own right, not a formality behind the sanctions screen.
Career & Skills Corner
Binance paid over 4.3 billion dollars in 2023 and pleaded guilty to sanctions and Bank Secrecy Act violations. Three years later, prosecutors are investigating whether the same sanctioned activity continued anyway. The useful skill here is not schadenfreude about a competitor's exposure. It is noticing how easily a settlement gets filed away internally as a solved problem rather than read as a map of exactly where your own controls need to prove themselves going forward. When you next review a counterparty, vendor, or peer institution with a historical enforcement action on record, resist closing that line item once the fine is paid. Ask instead what specific control the settlement said was missing, and whether you have direct evidence, not an assumption, that the same control works today. Practitioners who treat old settlements as an open question rather than a closed chapter are the ones who catch the next version of the same failure before an investigator does.
Next week I'm watching whether the EU turns Kaja Kallas's pledge into a formally adopted sanctions package targeting Russia's Duma election organizers, since an announced intention is not yet a screening obligation. I'm also watching whether further reporting on A7's files names additional banks or surfaces new correspondent relationships beyond the ones already disclosed.
Turn this weekly intelligence into a career. Marco’s AML & Financial Crime course takes you from curious to hireable.
AML & Financial Crime course →