OFAC hits Shamkhani network as it moves into container shipping
Treasury designated more than 50 individuals, entities, and vessels on 14 July 2026, and named a Danish CFO and an Italian CEO among them.
FinCrime Intelligence Weekly
OFAC designates a Danish CFO and an Italian CEO inside an Iranian shipping network, Dutch police disrupt a fraud operation run like a company, and the NCA charges five over a spoofing platform.
Marco’s Take
Marco Beranzoni
Welcome to Issue 8 of FinCrime Intelligence Weekly. Facts sourced, actions named, no filler. Here is what changed last week and what to do about it this week.
Look at what came across the desk this week. A shipping group whose global chief financial officer is Danish and whose global chief executive is Italian. A fraud operation with one head office, about twenty branch offices, and teams assigned by target country. A caller ID spoofing service sold on a six-month contract with 24/7 support. A weapons procurement chain running through an aviation transport company in Moscow, a supply firm in Nigeria, and a travel coordinator.
None of that looks like crime on a screen. It looks like business. Treasury said it plainly in the Shamkhani release: the We Freight group allows the blending of illicit and licit trade, with the proceeds of both ending up in the same place. That is the point. The corporate form is not a disguise laid over the crime, it is the operating system the crime runs on.
Here is the uncomfortable bit. Most screening logic is still tuned to find something that looks wrong. A European executive with a clean profile at a Dubai freight company does not look wrong.
So this week, do one small thing. Take your last five sanctions-related escalations and ask what tipped them: a name match, or a structure. If every one was a name match, your model is reading nameplates, not networks.
See you next Monday.
Marco
Treasury designated more than 50 individuals, entities, and vessels on 14 July 2026, and named a Danish CFO and an Italian CEO among them.
Politie arrested a main suspect and five others over an alleged investment fraud operation of more than 700 workers, with about 550 Dutch reports and nearly EUR 25 million in local losses.
The NCA has charged five London residents over Russian Coms, a caller ID spoofing service sold to criminals as both a handset and a web application.
Seven designations on 15 July reach a Moscow air transport firm, a Nigerian supply company, and a Milan-based individual, and OFAC warns foreign banks about correspondent account exposure.
The window to shape AMLA's business-wide risk assessment guidelines shut on 15 July, so the window to test your own assessment against the draft is now open.
What changed this week, why it matters, and what to do about it.
| Region | Update | Why it matters | Action |
|---|---|---|---|
| US | OFAC designated more than 50 individuals, entities, and vessels in Mohammad Hossein Shamkhani's illicit shipping network on 14 July under Executive Order 13902, and says it has now sanctioned more than 200 persons and vessels operating under that patronage. | The network has moved beyond oil into global containerized shipping and commodities trading, so exposure now reaches freight forwarders, container lines, and trade finance books that never considered themselves Iran-adjacent. | Rescreen container and freight counterparties, not just tanker exposure, and run the 50 percent ownership rule outward from every newly designated entity before assuming your book is clean. |
| US | OFAC designated seven individuals and entities on 15 July under Executive Order 13382 over IRGC weapons procurement, reaching a Moscow-based aviation transportation company, a Nigeria-based supply firm, and a Milan-based Italian national. | Treasury attached an explicit secondary sanctions warning: OFAC can prohibit or impose strict conditions on a foreign financial institution's US correspondent or payable-through account where that institution knowingly facilitates a significant transaction for a designated person. | Non-US banks should confirm the 15 July names are in screening now, and review any correspondent relationships with aviation, logistics, or travel-services clients in Russia, Nigeria, and Italy. |
| EU | AMLA's consultation on draft Guidelines on business-wide risk assessment, issued under Article 10(4) of Regulation (EU) 2024/1624, closed on 15 July 2026 at 23:59 CEST. AMLA says results will follow. | The draft proposes four minimum requirements applicable across all types of obliged entity, and stresses that the obliged entity owns its business-wide risk assessment and must make it proportionate to its own risks and complexity. | Read your last business-wide risk assessment against the consultation paper now, and note where you would struggle to evidence ownership rather than vendor-template compliance. |
| UK | The National Crime Agency announced on 13 July that five London residents have been charged following its investigation into Russian Coms, a caller ID spoofing platform the NCA says was established in 2020, sold first as a handset and then as a web application. | The NCA says spoofed numbers were often those of financial institutions, telecommunications companies, and law enforcement, used to steal funds and personal details. Your inbound number is the fraudster's product feature. | Review what your customer-facing scripts promise about caller identity, and pressure-test whether a customer can verify an inbound call through a channel the caller cannot influence. |
| Global | Dutch police announced on 15 July the disruption of an alleged international criminal organisation with more than 700 workers across roughly twenty call centres, with arrests in Poland, Cyprus, Belgium, and Greece, and information shared with other countries through Europol. | Police estimate the organisation took more than EUR 100 million per month across various countries. That estimate, not a confirmed figure, still describes a payout rate no single-institution fraud control was sized for. | Check whether your outbound payment alerting treats a first small transfer to a new crypto-adjacent destination as low risk. In this method, that transfer is the recruitment step. |
OFAC designated more than 50 individuals, entities, and vessels in Mohammad Hossein Shamkhani's illicit shipping network on 14 July under Executive Order 13902, and says it has now sanctioned more than 200 persons and vessels operating under that patronage.
Why it matters:The network has moved beyond oil into global containerized shipping and commodities trading, so exposure now reaches freight forwarders, container lines, and trade finance books that never considered themselves Iran-adjacent.
Action:Rescreen container and freight counterparties, not just tanker exposure, and run the 50 percent ownership rule outward from every newly designated entity before assuming your book is clean.
OFAC designated seven individuals and entities on 15 July under Executive Order 13382 over IRGC weapons procurement, reaching a Moscow-based aviation transportation company, a Nigeria-based supply firm, and a Milan-based Italian national.
Why it matters:Treasury attached an explicit secondary sanctions warning: OFAC can prohibit or impose strict conditions on a foreign financial institution's US correspondent or payable-through account where that institution knowingly facilitates a significant transaction for a designated person.
Action:Non-US banks should confirm the 15 July names are in screening now, and review any correspondent relationships with aviation, logistics, or travel-services clients in Russia, Nigeria, and Italy.
AMLA's consultation on draft Guidelines on business-wide risk assessment, issued under Article 10(4) of Regulation (EU) 2024/1624, closed on 15 July 2026 at 23:59 CEST. AMLA says results will follow.
Why it matters:The draft proposes four minimum requirements applicable across all types of obliged entity, and stresses that the obliged entity owns its business-wide risk assessment and must make it proportionate to its own risks and complexity.
Action:Read your last business-wide risk assessment against the consultation paper now, and note where you would struggle to evidence ownership rather than vendor-template compliance.
The National Crime Agency announced on 13 July that five London residents have been charged following its investigation into Russian Coms, a caller ID spoofing platform the NCA says was established in 2020, sold first as a handset and then as a web application.
Why it matters:The NCA says spoofed numbers were often those of financial institutions, telecommunications companies, and law enforcement, used to steal funds and personal details. Your inbound number is the fraudster's product feature.
Action:Review what your customer-facing scripts promise about caller identity, and pressure-test whether a customer can verify an inbound call through a channel the caller cannot influence.
Dutch police announced on 15 July the disruption of an alleged international criminal organisation with more than 700 workers across roughly twenty call centres, with arrests in Poland, Cyprus, Belgium, and Greece, and information shared with other countries through Europol.
Why it matters:Police estimate the organisation took more than EUR 100 million per month across various countries. That estimate, not a confirmed figure, still describes a payout rate no single-institution fraud control was sized for.
Action:Check whether your outbound payment alerting treats a first small transfer to a new crypto-adjacent destination as low risk. In this method, that transfer is the recruitment step.
Typology of the week
Workers posing as financial advisers or account managers make near-daily contact with people who are starting, or want to start, investing. Dutch police describe contact sustained over weeks and sometimes months, long enough to build a genuine bond of trust before any money moves. The first deposit is always a relatively low amount, and it immediately shows a profit on screen. The screen is the product. Politie describes an online platform on which victims can view their investments that is indistinguishable from a real one, while nothing is actually invested anywhere. The money, largely cryptocurrency, goes to the fraudsters. Behind it sits a professional company structure: about twenty offices, one head office directing the rest, multiple teams per office, and each team assigned a target country. Workers use pseudonyms and technical means to hide their true identity and location. The harvest happens twice. Politie warns that victims who stop because they grow suspicious may later be approached by a recovery company offering to retrieve their money, usually after a request to pay a deposit first. Police suspect those recovery firms belong to the same criminal organisations.
Example
Illustrative of the documented method, not a specific real case. A retail customer transfers EUR 400 to a new counterparty after several weeks of daily contact with a person presenting as an account manager. The customer's portal shows a gain within days. Over the following two months the customer sends progressively larger amounts, converting to cryptocurrency each time, and passes standard payment warnings by confirming she knows the recipient. Contact stops abruptly. Six weeks later she initiates another payment, this time a deposit to a firm offering to recover the earlier losses. That second payment is the point where a repeat-victim flag should have fired, and in most institutions it is the point where no rule exists.
Recent actions and the control lessons behind them.
OFAC, action of 14 July 2026 under Executive Order 13902
Control failure:The exposure sits in structure, not in nameplates. OFAC's designations include Danish national Martin Austin Kaalund, most recently global chief financial officer of sanctioned House of Shipping Investment FZCO, and Italian national Alessandra Ronco, most recently its global chief executive, described as co-founders and managers of a Dubai consulting firm. Screening tuned to nationality risk, jurisdiction risk, and adverse media on the customer name would not have surfaced either profile. Treasury also describes service providers doing ordinary work: a UAE company providing vessel management, including serving as a billing company, and a group of freight companies that allows the blending of illicit and licit trade.
Lesson:Read a designation list as an organisation chart. The useful question after 14 July is not whether any of these names hit your book, it is whether you can identify the billing companies, ship managers, inspectors, and consulting vehicles around a customer you already onboarded. OFAC applies civil penalties for sanctions violations on a strict liability basis, so the name was not listed at the time is not a control.
National Crime Agency, charges announced 13 July 2026
Control failure:The NCA says the platform let criminals appear to call from pre-selected numbers, often those of financial institutions, telecommunications companies, and law enforcement, to steal funds and personal details. Help Net Security reports the method as spoofing a bank's number to build trust before telling the victim their account was compromised, then persuading them to move money to a so-called safe account. The failing control is any customer verification path that treats a displayed inbound number as evidence of who is calling, and any internal process that lets a customer be walked from a phone call to a completed transfer without an independent confirmation step.
Lesson:Out-of-band verification only works if the second band is one the caller cannot occupy. All five charged, Ayoub Sehailia, Zakkaria Sehailia, Usman Din, Denis Ozmus, and Fadila Salem, are accused and will appear at Westminster Magistrates' Court on Friday, 14 August. Nothing here is a finding of guilt. The operational point stands regardless of the outcome: your bank's number is an asset the fraudster can wear, so build the verification step somewhere else.
Help Net Security reports Russian Coms pricing at GBP 1,200 to GBP 1,400 for a six-month handset contract, or GBP 350 a month for full web app access, paid in cryptocurrency, with features including voice changing, no call logs, encrypted calls, and 24/7 support. That is a product, with tiers and a support desk, marketed through Telegram, Snapchat, and Instagram. The practical consequence for controls: telephony identity is now a purchasable attribute, so any verification that resolves to the number looked right is worthless. Push the confirmation into a channel the caller cannot enter, and make the app or the branch the authority rather than the call. Then test whether your own outbound callers can pass your customers' verification, because if they cannot, customers will keep trusting whoever sounds more official.
Dutch police describe an investment portal victims could log into that was indistinguishable from a real one, with nothing invested behind it and settlement largely in cryptocurrency. Detection at the interface has effectively failed: a practitioner cannot expect a customer to spot a difference the police describe as absent. That moves the detection point upstream, to the first relatively low deposit that immediately shows a profit. Most monitoring treats a small first transfer as noise, which is precisely why the method opens with one. Score the sequence rather than the amount: a small transfer to a new counterparty, then an escalating ladder to the same destination within weeks, with a crypto on-ramp in the path. The signal is the shape of the curve, and it is visible well before the loss is.
Career & Skills Corner
Most people read a designation list the way a screening engine does: as names to match. That is the least valuable thing in the document. Take the 14 July Shamkhani action and read it a second time, looking only at roles. Treasury names a primary financier who beneficially owns a British Virgin Islands and Dubai holding company. A person described as effectively operating as the head of shipping. A senior vessel inspector. A manager coordinating shipments with network partners. A company providing vessel management services, including serving as a billing company. Two co-founders of a Dubai strategy consulting firm who most recently held the global chief financial officer and global chief executive roles at a sanctioned shipping business. That is not a list. That is a functional org chart: finance, operations, inspection, billing, and advisory. Every network of that type needs those functions filled, and the people filling them are usually not the ones you would flag on nationality or jurisdiction alone. Build the habit deliberately. After each significant OFAC or UK action, spend twenty minutes writing out the roles rather than the names, then ask which equivalent roles exist among your own customers. You will start recognising the shape of a network before its members are listed, which is the only version of this skill that has any predictive value. It also makes you noticeably better in front of a regulator, because you can explain why a customer is risky rather than only that they matched.
Four things. AMLA said results will follow on the business-wide risk assessment consultation that closed on 15 July, and I want to see how the four proposed minimum requirements survive contact with industry responses, because that text will end up shaping how every obliged entity in the EU has to evidence ownership of its own risk assessment. The five charged in the Russian Coms case are due at Westminster Magistrates' Court on 14 August, and what gets tested there about supplying articles for use in fraud matters to anyone building the argument that infrastructure providers sit inside the offence. On sanctions, Treasury says it has now designated more than 200 individuals, entities, and vessels under Shamkhani's patronage, across actions in July 2025, April 2026, and this month, so I am assuming there is more to come and watching which service functions get named next: billing, inspection, consulting. And Dutch police said further arrests in the investment fraud investigation are not ruled out. If arrests reach the roughly twenty call centres rather than the head office, that tells you something about how far the country-team structure can be unwound.
Turn this weekly intelligence into a career. Marco’s AML & Financial Crime course takes you from curious to hireable.
AML & Financial Crime course →