Lab Report #21

Lab Report #20

This week in financial Crime

Lab Report #20

This week in financial Crime

Lab Report #20 - This week in financial Crime

This week the enforcement lens widened along two axes at once. On the sanctions axis, the United States launched what Treasury has branded its largest single Iran action to date, layering secondary threats onto designations across five new sectors of the Iranian economy. On the individual accountability axis, the FCA closed the Dolfin Financial file with three bans over a scheme that used the UK’s now-defunct Tier 1 Investor Visa route as a laundering vehicle, and a US federal court handed a 15-year sentence to a Chinese national at the centre of a $92 million laundering conduit for Mexican drug proceeds. Around these two anchor stories a familiar pattern held: EPPO dismantling a VAT carousel, INTERPOL running down West African fraud networks, the SEC unpicking a Hong Kong-directed adviser impersonation operation, and Hong Kong’s SFC handing down a decade-long ban on a licensed regulated officer for falsifying financial resources. The connective tissue is the professionalisation of the enablement layer: visa architects, false-filing operators, licensed insiders, mirror-trade brokers, VAT front-companies. The state response, correspondingly, is shifting from institution-level penalties to individual disqualification and cross-border coordination.

Treasury launches Operation Economic Outcast against Iran.

On 24 August, the US Treasury announced its most extensive single Iran action to date under the banner Operation Economic Outcast, designating roughly 60 targets across the UAE, Hong Kong, mainland China, Singapore, Switzerland and Europe, and adding five new sectors to Executive Order 13902’s coverage: digital assets, technology, gold, aviation and shipping. Secretary Bessent explicitly framed the campaign in secondary-sanctions terms, warning that “any entity that facilitates money laundering on behalf of Iran will be removed from the US dollar system”, per the State Department fact sheet.

Reuters notes that no Chinese banks have yet been designated, leaving the most consequential lever unpulled. Rational choice theory reads this as a deliberate structuring of the incentive gradient: the extraterritorial threat is calibrated to raise the expected cost of Iran-adjacent business for third-country actors above the expected return, without triggering the geopolitical fallout of directly sanctioning Chinese state-owned banks. Whether the deterrent bites depends on the actor’s discount rate; for the marginal Gulf trading firm, dollar access is existential and the calculation is short. For a Chinese SOE with policy cover, it is not.

FCA closes the Dolfin Financial book with three bans over a golden-visa laundering scheme.

On 26 August, the FCA published final notices against former Dolfin Financial senior managers, fining Denisz Andras Nagy£324,800 and Sanjay Maraj £122,000, and referring Roman Joukovski to the Upper Tribunal, per AML Intelligence. Between 2016 and 2019 the firm processed roughly £35.5 million for at least 99 individuals seeking Tier 1 Investor Visas, taking £400,000 fees to nominally deploy £2 million per applicant while, in practice, hollowing out the investment substance the rules were designed to require.

This is a textbook case of “designed-in vulnerability”: the Tier 1 route created a settled procedural pathway for wealth-based residency, and Dolfin operated as the specialist intermediary that translated regulatory form into laundering substance. The bans matter because they attack the enablement layer directly; the deeper lesson, though, is that closing the scheme in 2022 did not close the exposure, and the professional infrastructure that grew around it remains available for the next investor-migration architecture that gets built.

Chinese money launderer sentenced to 15 years in Charlotte.

On 18 August, the Western District of North Carolina sentenced 31-year-old Jianfei Lu to 15 years and ordered forfeiture of $25 million, for laundering more than $92 million of Mexican drug-trafficking proceeds in under two years, per DOJ WDNC and the DOJ Office of Public Affairs. Lu operated inside a Chinese Money Laundering Organisation, running a mirror-trade architecture that settled cartel cash in the US against yuan transfers to Chinese nationals wanting dollar exposure, then repatriated value through trade-based flows.

The Opus Datum UK analysis points out the model does not need a US bank breach at any point: the laundering succeeds by matching two demand curves against each other. This is trust exploitation at network level: Chinese nationals seeking dollar liquidity trust the informal broker layer because it is embedded in diasporic community networks; cartels trust the CMLO because the settlement is fast and priced. UK exposure follows the same demand structure and the same absence of formal banking friction.

DOJ unseals superseding indictment against 17 Iranians in Mabna Institute campaign.

On 18 August, an SDNY grand jury unsealed a 14-count superseding indictment adding eight new defendants to the long-running Mabna Institute cyber-theft prosecution, per Reuters. The Iran-based company, acting on behalf of the IRGC, compromised roughly 8,000 professor accounts at 144 US and 178 foreign universities and exfiltrated approximately 31.5 terabytes between 2013 and 2017, plus intrusions into 42 US private companies, five federal or state agencies and the United Nations, per Iran International. The economic-crime dimension deserves emphasis: state-directed IP theft functions as a subsidy to sanctioned economies. Read together with Operation Economic Outcast, this week’s sanctions and cybercrime files converge on the same target: Iran’s ability to extract economic value from the international system without paying its dollar-clearing cost.

INTERPOL Operation Jackal IV dismantles West African fraud networks.

INTERPOL announced results of its eight-month Operation Jackal IV on 25 August: 58 arrests, 263 suspects identified, across 22 countries, with a specific focus on West African organised-crime networks running romance scams, crypto investment fraud and Business Email Compromise, per The Hacker News. South African authorities confiscated $2.67 million and blocked 257 accounts. A parallel 196-suspect crime-as-a-service network was identified running domain-registration and laundering infrastructure, with 17 arrests linked. PM News Nigeria frames this as pressure on the Black Axe confraternity ecosystem. This is what displacement theory predicts in an OCG environment: the operational core hardens as tools professionalise, so enforcement pressure at the disruption interface has to be permanent and coordinated to prevent regrowth rather than periodic and headline-driven.

EPPO arrests five in €20 million Czech AirPods VAT carousel.

On 26 August, the European Public Prosecutor’s Officeannounced Investigation Echo, with five arrests in Czechia and asset seizures across Czechia, Germany and Lithuania, targeting a VAT carousel scheme active since 2019 that used shell companies to fake cross-border wireless-headphone supply chains and generated roughly €20 million in fraudulent VAT reclaims.

Carousel fraud is one of the clearest situational-crime prevention case studies in the EU AML canon: the vulnerability is designed into the intra-community VAT rules, and the market response is a professional intermediary layer that industrialises the exploit. The consistent EPPO pattern this year is that the arrests target ringleaders rather than shell operators. The structural question is whether the reclaim architecture itself gets rebuilt post-VIDA, or whether enforcement remains the only functional deterrent.

SEC charges 38 entities in Hong Kong-directed fake-adviser scheme.

On 27 August, the SEC filed charges against 38 entities for allegedly submitting materially misrepresenting Forms ADV to feign registration as US investment advisers, targeting retail investors, per SEC press release 2026-78. The complaints describe fake Colorado addresses, disconnected phone numbers, non-existent audit firms and websites displaying fabricated “SEC RIA permission” certificates. Crypto Briefingreports the network traces back to a single alleged operator in Hong Kong who set up at least ten shell entities.

This exemplifies trust exploitation at regulatory infrastructure level: the mechanism weaponises retail investors’ rational assumption that a firm listed in an SEC database has cleared a diligence threshold. The Commission has now removed the offending filings and issued a companion investor alert warning that ERA registration is not an endorsement, but that clarification asks retail investors to sustain a level of regulatory literacy the design of the scam is calibrated to defeat.

Hong Kong SFC hands ten-year ban to former Keptain Securities RO.

On 24 August, the SFC revoked the licence of Ernest Chan Tsz Kin and banned him from re-entry to Hong Kong’s regulated markets until 23 August 2036, for window-dressing and misrepresenting Keptain Securities and Asset Management’s financial resources between June 2016 and March 2018, perSFC press release 26PR128. Individual accountability against Responsible Officers is the operational face of Hong Kong’s supervisory turn. Ten-year disqualification aligns with the deterrent theory that raises the reputational and lifetime-earnings cost of gatekeeper misconduct above the private-return calculation, which is where financial-services enforcement is most credible.

AUSTRAC finds systemic mortgage fraud across major Australian banks.

Bloomberg reported on 19 August that AUSTRAC’s supervisory review has identified widespread patterns of inflated income declarations, misrepresented employment status and fabricated business activity used to support mortgage applications across Australia’s major banks. This is a Sutherland-style differential-association finding in institutional dress: the fraud is normalised through broker-lender-borrower interactions that developed within a growth-oriented lending environment, and the AML architecture bolted on top of that environment has not, until now, been the natural site of enforcement. The interesting policy question is whether AUSTRAC treats this as a proceeds-of-crime typology rather than a prudential one. If it does, the reporting perimeter expands materially into originator networks.

FinCEN renews Minnesota Fraud GTO covering Hennepin and Ramsey Counties.

On 7 August, FinCEN renewed its Geographic Targeting Order requiring banks and money-services businesses in Hennepin and Ramsey Counties to report international funds transfers of $3,000 or more, effective 11 August through 6 February 2027. Davis Polk frames the renewal as evidence of FinCEN’s shift toward geographically targeted, harm-anchored reporting instruments as a complement to broader BSA obligations. GTOs are situational-crime-prevention instruments at their clearest: identify the specific point of exposure, raise reporting friction there without imposing it system-wide, and let the diverted flows surface elsewhere for follow-on investigation.

New Research Worth Reading

Button, Lazarus, Hock et al. (2025), Nigerian confraternities and mass cross-border fraud, in Trends in Organized Crime. Direct testimony-based analysis of Black Axe’s role in high-level BEC and cross-border laundering, arguing that confraternities are a specific transnational OCG form whose network structure explains why enforcement pressure at the disruption interface has to be sustained rather than episodic. Essential reading against this week’s Jackal IV results.

Ahrens, Hakelberg and Rixen (2020), A victim of regulatory arbitrage? Automatic exchange of information and the use of golden visas and corporate shells, in Regulation and Governance. Argues that automatic exchange of information regimes are systematically undermined by residency-by-investment routes and layered corporate opacity. The Dolfin final notices this week are the enforcement postscript to exactly the mechanism the paper describes.

Yoshimura (2026), Seeking a Convinced Touchstone in a Turbulent World: the Crossover of Secondary Sanctions and Extraterritorial Jurisdiction, in Journal of International Economic Law. A doctrinal reading of where secondary-sanctions authority sits in relation to customary international law on jurisdiction, published as the US launches its most extraterritorial Iran action to date. Reads the legal ceiling that Operation Economic Outcast is now pressing against.

What I Am Watching

  • Whether Operation Economic Outcast escalates to Chinese bank designations in September, or holds at the current threshold while third-country compliance is stress-tested.
  • If AUSTRAC’s mortgage-fraud finding triggers formal enforcement referrals rather than remaining a supervisory-review artefact.
  • Can the FCA’s Dolfin bans prompt movement on the Home Office review of the Innovator Founder route, given the structural resemblance to the Tier 1 architecture Dolfin exploited.
  • Whether the SEC investor alert is followed by broader ADV-filing gatekeeping reforms rather than post-hoc removal of fraudulent filings.
  • If September’s EPPO output continues the ringleader-focused pattern shown in Investigation Echo, or expands to prosecution of professional service enablers.

3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4N

Hello@FCResearchLab.com

© 2025. The Financial Crime Lab. All Rights Reserved

Privacy Policy 

The financial crime Lab | Financial Crime Prevention

turning evidence in to action against financial crime