Skip to content
All issues

FinCrime Intelligence Weekly

Issue №19 · Sep 28 – Oct 4, 2026

The US targets A7's sub-agents, AMLA finalises three core EU standards, the UK sanctions shadow fleet and trust services, and Treasury hits Hamas charity fronts and an ATM laundering ring.

FinCrime Intelligence Weekly - Issue 19: Regulators are going after the plumbing, not just the people
MB

Marco’s Take

Marco Beranzoni

The five stories this week look unrelated. They are not. Regulators and enforcers are going after the plumbing, not just the people.

FinCEN, the US Financial Crimes Enforcement Network, describes A7 as a global wholesale sanctions evasion and money laundering service, and the US is now targeting its Sub-Agents. The UK package lists trust services sanctions and director disqualification sanctions, measures aimed at the corporate and trust service layer, and also hits vessels that provide bunkering to the shadow fleet. The Hamas network used charity fronts and cryptocurrency wallets as collection plumbing. Tren de Aragua moved jackpotting proceeds through crypto transfers and Mexico-based front companies. AMLA, the EU Anti-Money Laundering Authority, finalised a group-wide arrangements standard that sets rules for how a multi-entity firm shares information and controls risk.

Here is my read. A service layer that serves many customers is valuable to a launderer for exactly that reason, and enforcers now treat it as a target in its own right. Reach is the attraction, and reach is the exposure. Your own firm probably relies on intermediaries too.

Here is the uncomfortable task for this week. List every intermediary and sub-agent that moves other people’s payments through your institution. Next to each one, write the date it was last reviewed. A blank is a finding.

See you next Monday.

Marco

The 5 stories that matter

Regulatory Radar

What changed this week, why it matters, and what to do about it.

US

The US Office of Foreign Assets Control (OFAC) listed 21 individuals, primarily from Baja California and Sinaloa, and 30 or more entities tied to the Sinaloa Cartel's Los Mayos faction in its September 29, 2026 Recent Actions. The entities include real estate, financial services, and entertainment businesses, and the action focused on corruption networks.

Why it matters:The listed entities sit in ordinary commercial sectors, so a match can arrive through a business customer rather than an obvious criminal one.

Action:Rescreen your customer and counterparty base against the new listings, and check ownership of real estate, financial services, and entertainment customers with Baja California or Sinaloa links.

Global

OFAC's September 29, 2026 Recent Actions also designated 5 individuals linked to military procurement and defense logistics, including Iranian nationals and operatives from China and Pakistan. They added 1 Iranian entity, Kavoshcom Asia R&D Group, and 3 companies supporting Iranian defense procurement in Saudi Arabia, Pakistan, and Turkey.

Why it matters:The designated parties span Iran, China, Pakistan, Saudi Arabia, and Turkey, so exposure sits in trade and payment chains well outside Iran.

Action:Add the new names to screening, and check trade finance and correspondent flows touching those countries for links to the designated companies.

UK

On 30 September 2026 the UK Financial Conduct Authority (FCA) opened its new regulatory framework for crypto firms to apply for formal authorisation. Firms must apply by 28 February 2027, and the regime commences on 25 October 2027.

Why it matters:FCA Director of Authorisation Dominic Cashman said: "Firms can now apply for authorisation and start preparing for regulation." For counterparties, the two dates set a timetable to plan against.

Action:Map which crypto clients and counterparties intend to apply by 28 February 2027, and point them to the FCA's pre-application support meetings and on-demand webinars.

EU

The EU Anti-Money Laundering Authority (AMLA) press release gives 10 July 2029 as the application date of the standards for football agents and professional football clubs.

Why it matters:The date sits in July 2029, so this is a horizon item. Banks and payment providers that serve clubs and agents can use the lead time to understand what will change for those clients.

Action:Note 10 July 2029 in your regulatory calendar, and identify any football clubs or agents among your clients.

Typology of the week

Deceptive charity fronts with cryptocurrency collection wallets

How it works

In this terrorist financing (TF) method, fundraisers set up purported humanitarian charities, solicit public donations, and promote fundraising accounts on social media. Donors see ordinary charitable giving, and cryptocurrency wallets give the appeal a second payment route beside bank transfers. The money is collected for a terrorist group while the humanitarian label supplies the cover.

Red flags

  • A charity or nonprofit customer whose stated humanitarian purpose does not match where the funds ultimately go.
  • Donation inflows from many unrelated senders, followed by onward transfers that do not fit the stated programmes.
  • Social media fundraising appeals that point to payment details or wallet addresses held by the customer.
  • Donation volumes that spike after a major attack or conflict event.
  • Officers' personal accounts receiving or forwarding donation funds.
  • Wallets linked to a charity customer that also appear in sanctions designations or open source reporting.

Sectors exposed

Banks and payment providers serving charities and nonprofits Cryptocurrency exchanges and wallet providers Crowdfunding and online donation platforms Money services businesses handling cross-border giving

Controls to review

  • Customer due diligence on nonprofits: verify registration, stated programmes, and where funds are actually distributed.
  • Screening of charity names, officers, and wallet addresses against this week's OFAC designations.
  • Monitoring scenarios for donation inflows from many small senders with rapid onward movement.
  • Chain analytics on wallets tied to charity customers, with rules for exposure to designated wallets.
  • Adverse media and social media checks on the public fundraising appeals of charity customers.
  • Escalation path from a terrorist financing suspicion to a suspicious activity report (SAR).

Example

On October 2, 2026, OFAC designated a Gaza-based Hamas Al-Qassam Brigades battalion deputy, two France-based fundraisers, and their two charities, Association Baraka and Ensemble C Mieux. According to US Treasury, the network collected more than $2 million for Hamas from 2020 to 2026, with $1.5 million of that after October 7, 2023. It used purported humanitarian charities soliciting public donations and cryptocurrency wallets, with fundraising accounts promoted on social media.

Enforcement Watch

Recent actions and the control lessons behind them.

  • Indictment alleges false end-user paperwork and transshipment moved more than $300 million of export-controlled servers to China

    None imposed. This is an indictment, not a conviction. If convicted, the maximum terms are 20 years for export conspiracy, 20 years for money laundering conspiracy, and 10 years for smuggling.

    Earthmade Computer Inc., City of Industry, California (owner Greg Lui, 38, of San Gabriel, California)

    Control failure:Everything below is alleged. The defendant is presumed innocent. According to the US Department of Justice, Lui was arrested on October 1, 2026 on a three-count indictment returned September 29, 2026, charging conspiracy to violate the Export Control Reform Act, outbound smuggling, and conspiracy to commit money laundering. The indictment alleges that high-end computer servers containing export-controlled graphics processing units (GPUs) were bought from US manufacturers using false documentation claiming non-restricted end users. The servers allegedly shipped to Malaysia and Singapore, where no license is required, and were then transshipped to China. The release states that Earthmade received $176 million from Malaysian companies between January and October 2024. The FBI, the Commerce Bureau of Industry and Security, and the Defense Criminal Investigative Service investigated.

    Lesson:The alleged failure sits in two places: unverified end-user documentation, and a transit destination treated as the final one. Exporters and resellers should verify the end user independently of the buyer's paperwork and confirm where the goods end up, not just where they ship first. Freight forwarders should challenge consignments of controlled technology routed through Malaysia or Singapore, because a destination that needs no license is not proof of the final destination. Banks financing these sales should obtain the end-user documentation behind the trade, test it against the buyer's profile, and treat large inflows from transit-jurisdiction companies as a trigger for verification. These are allegations, and the court will decide the facts.

Crypto, Fraud & AI

A blocked ruble-backed token is a screening and chain analytics problem

Treasury's A7 action describes A7A5 as a blocked, ruble-backed token issued by Old Vector LLC. Blocked status makes any exposure a sanctions question, not just a risk score. Screening teams should confirm the token and its issuer sit in their lists and that wallet screening catches direct and indirect exposure. Chain analytics teams should check how many hops back their tools trace and whether the token is labelled correctly.

ATM malware cash-out shows the physical to digital laundering chain

In Treasury's designation of Tren de Aragua targets, malware forced ATMs to dispense cash without debiting accounts, with losses stated at $40.73 million as of August 2025 across more than 1,500 attacks. Proceeds then moved through crypto transfers and Mexico-based front companies. The control lesson is the chain: physical cash becomes crypto, then business accounts. Banks that run ATM fleets should route dispense-without-debit alerts to financial crime teams as well as fraud. Exchanges and banks should test whether corporate account activity matches the declared business.

Career & Skills Corner

Write one specific comment on the A7 Sub-Agents rule

The US Financial Crimes Enforcement Network (FinCEN) has proposed a rule under section 9714(a) of the Combating Russian Money Laundering Act that would prohibit transmittals of funds involving the A7 Network's Sub-Agents. The public comment period runs 30 days from Federal Register publication. A comment is a cheap way to build visibility, and operational detail is what a rule-writer can actually use. Budget about four hours in total. Step 1: read the notice and pick one question you can answer from your own work, for example how your firm would spot a Sub-Agent in a payment chain, or what a prohibition on transmittals would take to implement. Step 2: write one page that states what you have seen, what you cannot say, and one change you would make. Step 3: keep it factual and anonymised, and clear it with your compliance or legal team before sending. Step 4: submit within the window, then add it to your CV and share it with your network. The payoff is a dated, public record of reasoned expertise on a live rule. Hiring managers and regulators can both read it.

What I’m watching next week

Next week I'm watching the close of the FinCEN comment window on the A7 Sub-Agents rule and whether the European Commission adopts the three AMLA standards. Both are where this week's focus on intermediaries meets the rulebook.

Want to do this for a living?

Turn this weekly intelligence into a career. Marco’s AML & Financial Crime course takes you from curious to hireable.

AML & Financial Crime course →