Full analysis
This week, the regulatory and enforcement architecture reached deeper into operational infrastructure. The US Treasury moved against the financial scaffolding of Hizballah in Lebanon; an international coalition dismantled the SocGholish malware distribution backbone in Operation Endgame’s third wave; the FATF Plenary recast its grey list and rewrote Recommendation 6 to carve out humanitarian space; Spanish and Italian authorities took down a clandestine Albanian-Italian banking network; and US regulators advanced the first stablecoin AML rulemaking under the GENIUS Act. The common thread is a shift in target geometry away from end-user transactions and toward the patronage, plumbing and protocols that make financial crime scalable.
1. OFAC targets Hizballah’s financial patronage network in Lebanon
On 18 June, the US Treasury designated five individuals and three companies accused of financing and laundering money for Hizballah. The action covers parliamentarian Jihad Frangieh, Hizballah finance officials Ali Qamati and Ali Costanteen, and the Lebanese firms Globe SARL, Al-Shafa and Tyke SAL, through which Treasury alleges hundreds of millions of dollars in real estate, construction contracts and front-company revenue moved into Hizballah’s coffers.
This is sanctions as an attack on patronage rather than on individual transactions. Trust exploitation frameworks help here: Hizballah’s effectiveness as a financial actor rests on its capacity to convert political legitimacy into commercial relationships that look ordinary from a banking perspective. By designating MPs and the firms that bridge state and movement, OFAC is targeting the layer where political authority is laundered into economic normality – the most consequential point in the chain for displacement effects.
2. Operation Endgame dismantles SocGholish malware infrastructure
In the third phase of Operation Endgame, an international coalition led by the Dutch National Police seized 106 servers and disrupted the SocGholish malware distribution network, the initial-access ecosystem operated by the threat group TA569 and tied to Evil Corp. Nearly 15,000 compromised websites were cleaned, and over 14,971 fake update lure sites were neutralised in coordinated action led by Eurojust and supported by US, UK, German, Canadian and Danish authorities.
SocGholish sat at the very top of the cybercrime value chain – selling initial access that downstream ransomware affiliates monetised. By removing such bottlenecks, we should produce disproportionate disruption because they are concentrated, low-redundancy and expensive to rebuild. Endgame’s evolution from servers, to administrators, to access brokers is a textbook example of vertical targeting moving up the abstraction stack.
3. FATF Plenary reshapes the grey list and rewrites Recommendation 6
At its June 2026 Plenary on 17–19 June, the FATF added Bosnia and Herzegovina and Iraq to the grey list while removing Algeria and Namibia. The Plenary also adopted a revised Recommendation 6, including a long-debated humanitarian exemption framework, and advanced mutual evaluation reports for Canada and Türkiye under the new effectiveness methodology.
The grey list churn is policy in motion: Algeria and Namibia’s removal signals that observable institutional uplift is being rewarded, while Bosnia and Iraq’s addition reflects the FATF’s appetite for using listing as a behavioural lever. The Recommendation 6 humanitarian carve-out is more interesting still, as it concedes that overbroad terrorism-financing controls were producing the very displacement effects (NGO debanking, humanitarian channel closure) that researchers have flagged for a decade. Effective regulation, as Tilley and Clarke have long argued, is regulation that anticipates its own displacement.
4. Spanish-Italian operation dismantles Albanian-Italian clandestine bank
On 19 June, Spain’s Tax Agency, the Guardia Civil and Italian carabinieri dismantled the Iberian cell of an Albanian-Italian clandestine banking network, with 40 arrests in Italy, four in Spain and more than €60 million in assets seized. The structure used currency exchange offices, hawala-style settlement and over-invoiced trade to move drug-trafficking proceeds across Europe.
The case is a clean illustration of Sutherland’s differential association applied to a transnational service economy: clandestine bankers learn techniques, justifications and trust signals from peers inside an ethnically bounded network, then sell those competencies to upstream drug traffickers. Dismantling the bank is more consequential than arresting any single trafficker because the bank is the enabler, and enablers concentrate operational expertise that takes years to rebuild.
5. UK Money Laundering Regulations 2026: the operational follow-on
A week after the SI 2026/621 amendments were laid, TLT’s published analysis is now the clearest practitioner read on what firms must do. The narrowed EDD trigger (FATF call-for-action only), the “unusually” qualifier on large/complex transactions, the threshold conversion to sterling, and the 9-month implementation runway for crypto counterparty CDD reposition the UK regime from rule-following to risk-proportionate judgement.
The amendments push UK AML closer to a genuinely risk-based approach, but, in doing so, transfer interpretive burden to firms. Where rules previously did the work of categorising risk, MLROs now must. That is a structural redistribution of compliance labour, and, predictably, the criminological evidence on bank compliance suggests it will surface variation in firm capability that is invisible under rule-based regimes.
6. AMLA consults on group-wide AML/CFT requirements
On 15 June the European Contact Group published its response to AMLA’s draft Regulatory Technical Standards on group-wide AML/CFT requirements. The RTS, required under Article 16 of AMLR, sets the architecture for how cross-border banking groups must manage consolidated AML oversight, including third-country branches operating under weaker local regimes.
Group-wide AML/CFT is where the EU’s centralisation logic meets the granular reality of correspondent banking. The ECG’s response flags the well-known problem that consolidated obligations create incentives for groups to retreat from high-risk jurisdictions rather than risk-manage in them, producing the same de-risking displacement that has hollowed out remittance corridors over the last decade. AMLA’s effectiveness will be judged on whether it can write rules that survive contact with that incentive.
7. FDIC publishes stablecoin AML NPRM under the GENIUS Act
Under the GENIUS Act passed earlier this year, the FDIC has published its NPRM setting AML/CFT obligations for permitted payment stablecoin issuers, with comments due 4 August. The proposal extends BSA-style customer identification, ongoing monitoring and SAR reporting to stablecoin issuers and brings them into a formal supervisory perimeter for the first time in US law.
Stablecoins have functioned for years as quasi-banking instruments outside the BSA perimeter. The FDIC’s move closes that gap by treating issuers as gatekeepers rather than technology providers. Routine activity theory predicts that this will reduce opportunity for one class of offender (using stablecoins as a transfer rail outside BSA reach) while displacing activity toward less-regulated jurisdictions or instruments, which is precisely why the international coordination question (FATF, EU MiCA, US GENIUS Act) matters more than any single national rule.
8. UK £23.4M crypto laundering convictions sentenced
On 12 June, four men from Ealing, Vincent Konnor, Ali Khan, Bilal Geddes and Marvin Zapata, were sentenced for laundering £23.4 million through cryptocurrency, receiving sentences of between five and nine years. The proceeds were drawn from large-scale fraud and drug trafficking and converted through a mix of crypto exchanges and over-the-counter desks.
This is interesting because the cell’s pathway was not technically sophisticated, but it relied on a small number of OTC chokepoints to convert volume. The case underlines a point the Joint Money Laundering Steering Group has been making for two years – that the UK’s exposure to crypto-enabled laundering is concentrated in OTC and informal exchange, not in the regulated VASP perimeter, and that enforcement asymmetry between the two is now a structural problem.
New Research Worth Reading
- Lagarda, G. & Verastegui Lira, P. (2026), Do Warnings Change Behavior? Money-laundering, Grey-listing by the FATF, and Cross-border Financial Flows, Inter-American Development Bank Working Paper (DOI: 10.18235/0014029). Empirical study finds FATF grey-listing produces 1.3–2.6% of quarterly GDP contractions in banking and capital inflows, with only partial recovery (40–70%) on delisting – the most rigorous quantification yet of grey list market discipline effects, and directly relevant to this week’s Bosnia/Iraq listing decisions.
- Juvinski, L., Li, H. & Brini, A. (2026), StableAML: Machine Learning for Behavioral Wallet Detection in Stablecoin Anti-Money Laundering on Ethereum, arXiv (DOI: 10.48550/arXiv.2602.17842). Behavioural-feature ML framework for Ethereum stablecoin AML; explicitly aligned with the EU MiCA and US GENIUS Act compliance perimeter and demonstrates that tree ensembles outperform graph neural networks when transaction graphs fragment. Useful operational complement to the FDIC NPRM.
- Gaisina, A. & Finger, M. (2026), Anti-money laundering effectiveness and cryptocurrency regulations: an empirical analysis of the introduction of virtual asset service providers (VASPs) licensing and AML crypto laws, Journal of Financial Regulation and Compliance (DOI: 10.1108/jfrc-10-2025-0319). Event-study evidence from 2013–2023 shows that the introduction of VASP licensing produces the largest sustained AML effectiveness gains, while enforcement phases show weaker effects, an important nuance for jurisdictions still designing rather than refining their crypto AML perimeters.
- Naidon, Y., Naumiuk, S., Horyslavskiy, K., Peliukh, O. & Chernysh, R. (2026), Sanctions circumvention via private-law instruments: Ukrainian courts and legislative reform, Journal of Money Laundering Control (DOI: 10.1108/jmlc-11-2025-0205). Doctrinal analysis of seven Ukrainian court cases (2018–2025) develops a typology of how sanctioned actors use registry manipulation, asset transfers, claim assignment and arbitral enforcement to disguise circumvention as ordinary private-law transactions – a useful framework as OFAC moves against Hizballah’s commercial vehicles this week.
What I Am Watching
- The 4 August closing date for comments on the FDIC GENIUS Act stablecoin AML NPRM, and whether industry pushback yields meaningful carve-outs for non-custodial wallet flows.
- The FATF’s follow-up work on the Recommendation 6 humanitarian exemption framework, and whether the EU AMLA aligns its own ongoing-monitoring guidelines with the new carve-out.
- Whether Operation Endgame’s SocGholish takedown produces follow-on prosecutions of TA569 administrators, or whether the actors reconstitute under a new initial-access brand within the predictable 90-day window.
- The next move in the EU’s 21st sanctions package against Russia – particularly the proposed full third-country ban on crypto-asset service providers, which would be the first instrument of its kind globally.
Published by The Financial Crime Lab on 25 Jun 2026.
Cite as: The Financial Crime Lab (2026). Lab Report 11.
Put this evidence to work in your organisation.
Book a consultation with Dr Nicola Harding to translate these findings into prevention strategy, product design and frontline practice.

