Lab Report #14

Lab Report #12

This week in financial Crime

Lab Report #12

This week in financial Crime

Lab Report #12 - This week in financial Crime

This week, the architecture of enforcement turned, again, on infrastructure – but with a different emphasis. Where last week’s takedowns targeted patronage and protocol, this week’s targeted hubs: the cloud account underwriting the Huione Group’s payment rails, the Prince Group TCO leadership tier and its investors, the malware command-and-control servers behind Amadey and StealC, the South Korean mule-account network feeding Cambodian scam compounds, and the AML supervisory perimeter for UK lawyers and accountants. The Guo Wengui sentencing, thirty years, $889 million in forfeiture, closes a chapter on affinity fraud at industrial scale. The connective thread is that authorities are now routinely targeting the concentrations in illicit financial systems: the cloud accounts, the leadership tiers, the mule-network operators, the gatekeepers, and treating the rest as downstream.

1. DOJ seizes Huione Group cloud infrastructure in pig-butchering crackdown

On 23 June the Department of Justice announced the seizure of a cloud computing account used by the Cambodia-based Huione Group to operate the backend infrastructure of its money-laundering services. Huione has been the central conduit for pig-butchering, romance and investment-fraud proceeds out of Southeast Asia, processing what FinCEN has described as tens of billions of dollars of illicit flows. The next day, OFAC and FinCEN moved against the operating layer with a parallel action: sanctions on nine individuals and 26 entities linked to the Prince Group TCO, including alleged “second-in-command” Hu Xiaowei, and a FinCEN proposal to extend the October 2025 Huione Group Final Rule to H-Pay Service PLC.

Together, these two actions amount to a textbook situational crime prevention play applied to a transnational service economy. Cloud accounts are the modern equivalent of a clearing house – fewer, more concentrated, harder to substitute than any individual mule or money-launderer. By taking down the backend and simultaneously designating the leadership and front-company investor layer, US authorities are denying the Prince Group’s “co-offending opportunity structure” rather than chasing individual fraud streams downstream. Whether displacement follows to a less hardened jurisdiction is the question every fraud investigator should be watching.

2. Operation Endgame Phase 4 dismantles Amadey and StealC infrastructure

A week after the SocGholish takedown, Operation Endgame returned. On 24 June Europol, the German BKA and Microsoft announced the disruption of Amadey and StealC infrastructure, with totals across both phases of 326 servers neutralised, 142 domains seized, €41 million in crypto frozen and 27 million stolen credentials recovered. Investigators used AI-assisted analysis to demonstrate that Amadey and StealC, although developed separately, shared command-and-control infrastructure, enabling the simultaneous neutralisation of multiple malware families through a single coordinated strike.

Endgame is now operating not just as enforcement but as a methodology: vertical targeting of the malware-as-a-service “assembly line”, with each phase peeling another layer from the cybercrime value chain. The AI-assisted infrastructure attribution is the consequential novelty; it changes the evidentiary economics of cross-border takedowns and lowers the threshold for what counts as a coordinated cluster. The recurring problem, predictably, remains displacement: as security researchers noted within days, a new StealC build has already appeared. The empirical question, as I have argued before, is whether takedown cadence can outpace reconstitution cadence.

3. Guo Wengui sentenced to 30 years and $889M forfeiture

On 29 June, Judge Analisa Torres sentenced Chinese exile and media entrepreneur Guo Wengui (Miles Guo, Ho Wan Kwok) to 30 years in federal prison and $889 million in forfeiture, concluding the largest US affinity-fraud prosecution since Madoff. Guo was convicted in July 2024 on nine of twelve fraud and conspiracy counts, with prosecutors arguing he defrauded more than 1,000 victims of hundreds of millions of dollars through the GTV media platform, the Himalaya Farm Alliance and the Himalaya Exchange, and used the proceeds for a New Jersey estate, a Greenwich mansion and a $4.4 million Bugatti. Court records cited 235 victim statements, many describing the loss of life savings.

Guo is the cleanest contemporary case of affinity fraud weaponising a political identity rather than the more familiar religious or ethnic ones. His audience was not a congregation; it was a self-identified anti-CCP diaspora. The trust premium he extracted flowed from positioning himself as a dissident, a category in which sceptical financial scrutiny is socially expensive. Affinity fraud’s mechanism is the same regardless of the affinity used: shared identity displaces ordinary due diligence. The sentence is consequential because it reasserts that political legitimacy does not buy a discount on fraud liability.

4. South Korean police dismantle Cambodia-linked USDT mule network

On 24 June, South Korean police announced the arrest of 23 individuals in an $11 million USDT (Tether) laundering operation tied to Cambodian voice-phishing scam compounds. The cell operated as a recruitment-and-conversion service for mule accounts feeding scam-compound proceeds out of Cambodia into stablecoin pathways. In parallel, South Korean regulators announced legal action against 40 unregistered crypto firms operating outside the FSC’s VASP licensing perimeter.

The Korean cell is the missing link in the Southeast Asian scam economy: compounds in Cambodia produce the fraud, but the proceeds need a developed-market conversion layer to turn USDT into spendable fiat. That conversion layer is where mule recruitment, off-perimeter exchanges and informal value transfer concentrate. Korean enforcement targeting both the recruitment cell and the unregistered-exchange perimeter in the same week is a deliberate dual-attack on the bottleneck, and offers a useful comparative for the UK debate about regulated-VASP versus OTC enforcement asymmetry.

5. UK government confirms FCA as single AML/CFT supervisor for legal and accountancy sector

In a major structural shift, the UK government has confirmed that AML/CFT supervision of law firms and accountancy practices will transfer from professional body supervisors (SRA, Law Society of Scotland, Law Society of Northern Ireland, accountancy bodies) to the FCA. Treasury insists the transition will be smooth, with the FCA adopting a fit-and-proper test for the relevant firms and operating a new fee regime. The reform follows years of FATF criticism and OPBAS-documented variation in professional-body supervisory rigour.

This is the single most consequential change to UK AML supervision in a decade. Lawyers and accountants are now formally recognised as gatekeeper-equivalent for AML purposes, with the same supervisor as the banks they advise. The structural prediction from the gatekeeper-attribution literature is unambiguous: supervisory consolidation closes a known regulatory arbitrage where firms could choose the gentlest of their available regulators, and it shifts the firm’s compliance equilibrium from minimum-acceptable to bank-standard. The implementation will, predictably, be slow and uneven, but the policy position is now settled.

6. OFAC targets Cuba revenue network and DRC mineral smuggling

In a busy sanctions week, OFAC designated Cuban state-owned oil company Unión Cuba-Petróleo (CUPET) and additional financial institutions including Banco Financiero Internacional under E.O. 14404, and on 25 June sanctioned a network smuggling minerals from eastern DRC into Rwanda in coordination with the M23 armed group. Alongside these, OFAC removed multiple Russia-related designees from the SDN list and issued a new joint comparative overview with the UK’s OFSI.

The simultaneous Cuba-petroleum, DRC-minerals and TCO-leadership designations show OFAC reaching across three distinct typologies in a single week, each anchored to the commodity or infrastructure that generates the underlying illicit revenue. The UK/US joint comparative overview is the more durable change: dual-track sanctions enforcement is becoming structurally bilateral rather than parallel. For compliance functions, the practical consequence is that the OFAC/OFSI screening overlap is widening and the wind-down treatment under TCO General License 2 (for CCU Commercial Bank in Cambodia) demonstrates that sanctions are now being calibrated transactionally, not just imposed in bulk.

7. AMLA’s first conference and the EU’s centralisation in practice

The new EU Anti-Money Laundering Authority held its first official conference in Frankfurt earlier in June, with PwC and others publishing detailed conference recaps confirming AMLA now holds the EU’s AML/CFT guidance and direct-supervision powers. AMLA’s selection of its first cohort of directly-supervised institutions and its Article 26(5) AMLR consultation on ongoing monitoring (covered in Lab Report #9) continue in parallel.

AMLA’s first conference matters less for what was said than for what it signals: that the EU now has a single point of accountability for AML/CFT effectiveness across 27 member states, and that this point has chosen to make itself visible. The criminological literature on supranational supervision predicts that AMLA’s early credibility will be set by the handling of its first significant enforcement case, not by its rule-writing, and that case will likely come from one of the large, weakly-supervised national regimes that AMLA was created to bypass.

8. UK Money Laundering Regulations 2026 take effect 30 June

The substantive amendments to the UK Money Laundering Regulations covered in Lab Report #10 come into force today, 30 June 2026, with the principal exception of the new crypto counterparty CDD obligations under regulation 28A, which begin on 30 March 2027 to give VASPs the planned nine-month implementation runway. The remaining changes, narrowed EDD trigger, “unusually” qualifier, sterling threshold conversion and FCA reg 52A/52B information-sharing, apply from today.

This is the operational threshold for the largest change to UK AML rules since 2017. The risk-proportionate emphasis (EDD narrowed, “unusually” qualifier inserted) puts considerably more interpretive burden on MLROs, and the empirical evidence on UK bank compliance suggests that capability variance between firms will now become much more visible to the supervisor. The interplay with the FCA-as-single-supervisor reform announced this week is no accident: the two reforms are designed to be read together, and the FCA’s first round of supervisory dialogue under the new framework will set the tone for the next decade.

New Research Worth Reading

  • Moiseienko, A. (2024), Crime and Sanctions: Beyond Sanctions as a Foreign Policy Tool, German Law Journal (DOI: 10.1017/glj.2023.103). The clearest theoretical account to date of targeted sanctions being used not as foreign-policy instruments but as criminal-justice tools – directly relevant to this week’s OFAC Prince Group TCO designations and the broader trend of treating sanctions as a third layer alongside criminal prosecution and regulatory enforcement.
  • Sharma, A. & Bansal, C. (2026), The Vigilant Retailer: Analyzing the Awareness-Action Gap in India’s Capital Markets, International Journal for Multidisciplinary Research (DOI: 10.36948/ijfmr.2026.v08i03.82015). Published 21 June. Primary survey of 213 retail investors finds that two-thirds never use the SEBI Check or SCORES 2.0 tools designed to protect them, and that experienced investors rate SEBI 46% more effective than newer ones (ANOVA p<0.01). A useful empirical counterpoint to the Guo Wengui case: protective infrastructure is necessary but not sufficient when investors do not engage with it.
  • Acharya, B. & Holz, T. (2024), An Explorative Study of Pig Butchering Scams, arXiv (DOI: 10.48550/arXiv.2412.15423). Large-scale empirical study using more than 430,000 social media accounts and 770,000 posts collected across four platforms, plus 3,200 public abuse reports. Maps the full lifecycle of pig-butchering scams – directly relevant for understanding the upstream activity the Huione Group’s payment rails were enabling.
  • Zakaria, L. & Setiyono, J. (2026), Transnational Cybercrime Jurisdiction and International Criminal Law Enforcement Against Global Ransomware Attacks Threatening Critical Infrastructure, International Journal of Social Science and Human Research (DOI: 10.47191/ijsshr/v9-i6-30). Published 11 June. Doctrinal analysis of the jurisdictional architecture for transnational cybercrime enforcement and the structural constraints on takedowns of the kind Operation Endgame has now executed four times – a useful framework for thinking about the durability of infrastructure-level disruption.

What I Am Watching

3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4N

Hello@FCResearchLab.com

© 2025. The Financial Crime Lab. All Rights Reserved

Privacy Policy 

The financial crime Lab | Financial Crime Prevention

turning evidence in to action against financial crime