Lab Report #14

Lab Report #11

This week in financial Crime

Lab Report #11

This week in financial Crime

Lab Report #11 - This week in financial Crime

This week, the regulatory and enforcement architecture reached deeper into operational infrastructure. The US Treasury moved against the financial scaffolding of Hizballah in Lebanon; an international coalition dismantled the SocGholish malware distribution backbone in Operation Endgame’s third wave; the FATF Plenary recast its grey list and rewrote Recommendation 6 to carve out humanitarian space; Spanish and Italian authorities took down a clandestine Albanian-Italian banking network; and US regulators advanced the first stablecoin AML rulemaking under the GENIUS Act. The common thread is a shift in target geometry away from end-user transactions and toward the patronage, plumbing and protocols that make financial crime scalable.

1. OFAC targets Hizballah’s financial patronage network in Lebanon

On 18 June, the US Treasury designated five individuals and three companies accused of financing and laundering money for Hizballah. The action covers parliamentarian Jihad Frangieh, Hizballah finance officials Ali Qamati and Ali Costanteen, and the Lebanese firms Globe SARL, Al-Shafa and Tyke SAL, through which Treasury alleges hundreds of millions of dollars in real estate, construction contracts and front-company revenue moved into Hizballah’s coffers.

This is sanctions as an attack on patronage rather than on individual transactions. Trust exploitation frameworks help here: Hizballah’s effectiveness as a financial actor rests on its capacity to convert political legitimacy into commercial relationships that look ordinary from a banking perspective. By designating MPs and the firms that bridge state and movement, OFAC is targeting the layer where political authority is laundered into economic normality – the most consequential point in the chain for displacement effects.

2. Operation Endgame dismantles SocGholish malware infrastructure

In the third phase of Operation Endgame, an international coalition led by the Dutch National Police seized 106 servers and disrupted the SocGholish malware distribution network, the initial-access ecosystem operated by the threat group TA569 and tied to Evil Corp. Nearly 15,000 compromised websites were cleaned, and over 14,971 fake update lure sites were neutralised in coordinated action led by Eurojust and supported by US, UK, German, Canadian and Danish authorities.

SocGholish sat at the very top of the cybercrime value chain – selling initial access that downstream ransomware affiliates monetised. By removing such bottlenecks, we should produce disproportionate disruption because they are concentrated, low-redundancy and expensive to rebuild. Endgame’s evolution from servers, to administrators, to access brokers is a textbook example of vertical targeting moving up the abstraction stack.

3. FATF Plenary reshapes the grey list and rewrites Recommendation 6

At its June 2026 Plenary on 17–19 June, the FATF added Bosnia and Herzegovina and Iraq to the grey list while removing Algeria and Namibia. The Plenary also adopted a revised Recommendation 6, including a long-debated humanitarian exemption framework, and advanced mutual evaluation reports for Canada and Türkiye under the new effectiveness methodology.

The grey list churn is policy in motion: Algeria and Namibia’s removal signals that observable institutional uplift is being rewarded, while Bosnia and Iraq’s addition reflects the FATF’s appetite for using listing as a behavioural lever. The Recommendation 6 humanitarian carve-out is more interesting still, as it concedes that overbroad terrorism-financing controls were producing the very displacement effects (NGO debanking, humanitarian channel closure) that researchers have flagged for a decade. Effective regulation, as Tilley and Clarke have long argued, is regulation that anticipates its own displacement.

4. Spanish-Italian operation dismantles Albanian-Italian clandestine bank

On 19 June, Spain’s Tax Agency, the Guardia Civil and Italian carabinieri dismantled the Iberian cell of an Albanian-Italian clandestine banking network, with 40 arrests in Italy, four in Spain and more than €60 million in assets seized. The structure used currency exchange offices, hawala-style settlement and over-invoiced trade to move drug-trafficking proceeds across Europe.

The case is a clean illustration of Sutherland’s differential association applied to a transnational service economy: clandestine bankers learn techniques, justifications and trust signals from peers inside an ethnically bounded network, then sell those competencies to upstream drug traffickers. Dismantling the bank is more consequential than arresting any single trafficker because the bank is the enabler, and enablers concentrate operational expertise that takes years to rebuild.

5. UK Money Laundering Regulations 2026: the operational follow-on

A week after the SI 2026/621 amendments were laid, TLT’s published analysis is now the clearest practitioner read on what firms must do. The narrowed EDD trigger (FATF call-for-action only), the “unusually” qualifier on large/complex transactions, the threshold conversion to sterling, and the 9-month implementation runway for crypto counterparty CDD reposition the UK regime from rule-following to risk-proportionate judgement.

The amendments push UK AML closer to a genuinely risk-based approach, but, in doing so, transfer interpretive burden to firms. Where rules previously did the work of categorising risk, MLROs now must. That is a structural redistribution of compliance labour, and, predictably, the criminological evidence on bank compliance suggests it will surface variation in firm capability that is invisible under rule-based regimes.

6. AMLA consults on group-wide AML/CFT requirements

On 15 June the European Contact Group published its response to AMLA’s draft Regulatory Technical Standards on group-wide AML/CFT requirements. The RTS, required under Article 16 of AMLR, sets the architecture for how cross-border banking groups must manage consolidated AML oversight, including third-country branches operating under weaker local regimes.

Group-wide AML/CFT is where the EU’s centralisation logic meets the granular reality of correspondent banking. The ECG’s response flags the well-known problem that consolidated obligations create incentives for groups to retreat from high-risk jurisdictions rather than risk-manage in them, producing the same de-risking displacement that has hollowed out remittance corridors over the last decade. AMLA’s effectiveness will be judged on whether it can write rules that survive contact with that incentive.

7. FDIC publishes stablecoin AML NPRM under the GENIUS Act

Under the GENIUS Act passed earlier this year, the FDIC has published its NPRM setting AML/CFT obligations for permitted payment stablecoin issuers, with comments due 4 August. The proposal extends BSA-style customer identification, ongoing monitoring and SAR reporting to stablecoin issuers and brings them into a formal supervisory perimeter for the first time in US law.

Stablecoins have functioned for years as quasi-banking instruments outside the BSA perimeter. The FDIC’s move closes that gap by treating issuers as gatekeepers rather than technology providers. Routine activity theory predicts that this will reduce opportunity for one class of offender (using stablecoins as a transfer rail outside BSA reach) while displacing activity toward less-regulated jurisdictions or instruments, which is precisely why the international coordination question (FATF, EU MiCA, US GENIUS Act) matters more than any single national rule.

8. UK £23.4M crypto laundering convictions sentenced

On 12 June, four men from Ealing, Vincent Konnor, Ali Khan, Bilal Geddes and Marvin Zapata, were sentenced for laundering £23.4 million through cryptocurrency, receiving sentences of between five and nine years. The proceeds were drawn from large-scale fraud and drug trafficking and converted through a mix of crypto exchanges and over-the-counter desks.

This is interesting because the cell’s pathway was not technically sophisticated, but it relied on a small number of OTC chokepoints to convert volume. The case underlines a point the Joint Money Laundering Steering Group has been making for two years – that the UK’s exposure to crypto-enabled laundering is concentrated in OTC and informal exchange, not in the regulated VASP perimeter, and that enforcement asymmetry between the two is now a structural problem.

New Research Worth Reading

What I Am Watching

3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4N

Hello@FCResearchLab.com

© 2025. The Financial Crime Lab. All Rights Reserved

Privacy Policy 

The financial crime Lab | Financial Crime Prevention

turning evidence in to action against financial crime