This week, the architecture of enforcement turned, again, on infrastructure – but with a different emphasis. Where last week’s takedowns targeted patronage and protocol, this week’s targeted hubs: the cloud account underwriting the Huione Group’s payment rails, the Prince Group TCO leadership tier and its investors, the malware command-and-control servers behind Amadey and StealC, the South Korean mule-account network feeding Cambodian scam compounds, and the AML supervisory perimeter for UK lawyers and accountants. The Guo Wengui sentencing, thirty years, $889 million in forfeiture, closes a chapter on affinity fraud at industrial scale. The connective thread is that authorities are now routinely targeting the concentrations in illicit financial systems: the cloud accounts, the leadership tiers, the mule-network operators, the gatekeepers, and treating the rest as downstream.
On 23 June the Department of Justice announced the seizure of a cloud computing account used by the Cambodia-based Huione Group to operate the backend infrastructure of its money-laundering services. Huione has been the central conduit for pig-butchering, romance and investment-fraud proceeds out of Southeast Asia, processing what FinCEN has described as tens of billions of dollars of illicit flows. The next day, OFAC and FinCEN moved against the operating layer with a parallel action: sanctions on nine individuals and 26 entities linked to the Prince Group TCO, including alleged “second-in-command” Hu Xiaowei, and a FinCEN proposal to extend the October 2025 Huione Group Final Rule to H-Pay Service PLC.
Together, these two actions amount to a textbook situational crime prevention play applied to a transnational service economy. Cloud accounts are the modern equivalent of a clearing house – fewer, more concentrated, harder to substitute than any individual mule or money-launderer. By taking down the backend and simultaneously designating the leadership and front-company investor layer, US authorities are denying the Prince Group’s “co-offending opportunity structure” rather than chasing individual fraud streams downstream. Whether displacement follows to a less hardened jurisdiction is the question every fraud investigator should be watching.
A week after the SocGholish takedown, Operation Endgame returned. On 24 June Europol, the German BKA and Microsoft announced the disruption of Amadey and StealC infrastructure, with totals across both phases of 326 servers neutralised, 142 domains seized, €41 million in crypto frozen and 27 million stolen credentials recovered. Investigators used AI-assisted analysis to demonstrate that Amadey and StealC, although developed separately, shared command-and-control infrastructure, enabling the simultaneous neutralisation of multiple malware families through a single coordinated strike.
Endgame is now operating not just as enforcement but as a methodology: vertical targeting of the malware-as-a-service “assembly line”, with each phase peeling another layer from the cybercrime value chain. The AI-assisted infrastructure attribution is the consequential novelty; it changes the evidentiary economics of cross-border takedowns and lowers the threshold for what counts as a coordinated cluster. The recurring problem, predictably, remains displacement: as security researchers noted within days, a new StealC build has already appeared. The empirical question, as I have argued before, is whether takedown cadence can outpace reconstitution cadence.
On 29 June, Judge Analisa Torres sentenced Chinese exile and media entrepreneur Guo Wengui (Miles Guo, Ho Wan Kwok) to 30 years in federal prison and $889 million in forfeiture, concluding the largest US affinity-fraud prosecution since Madoff. Guo was convicted in July 2024 on nine of twelve fraud and conspiracy counts, with prosecutors arguing he defrauded more than 1,000 victims of hundreds of millions of dollars through the GTV media platform, the Himalaya Farm Alliance and the Himalaya Exchange, and used the proceeds for a New Jersey estate, a Greenwich mansion and a $4.4 million Bugatti. Court records cited 235 victim statements, many describing the loss of life savings.
Guo is the cleanest contemporary case of affinity fraud weaponising a political identity rather than the more familiar religious or ethnic ones. His audience was not a congregation; it was a self-identified anti-CCP diaspora. The trust premium he extracted flowed from positioning himself as a dissident, a category in which sceptical financial scrutiny is socially expensive. Affinity fraud’s mechanism is the same regardless of the affinity used: shared identity displaces ordinary due diligence. The sentence is consequential because it reasserts that political legitimacy does not buy a discount on fraud liability.
On 24 June, South Korean police announced the arrest of 23 individuals in an $11 million USDT (Tether) laundering operation tied to Cambodian voice-phishing scam compounds. The cell operated as a recruitment-and-conversion service for mule accounts feeding scam-compound proceeds out of Cambodia into stablecoin pathways. In parallel, South Korean regulators announced legal action against 40 unregistered crypto firms operating outside the FSC’s VASP licensing perimeter.
The Korean cell is the missing link in the Southeast Asian scam economy: compounds in Cambodia produce the fraud, but the proceeds need a developed-market conversion layer to turn USDT into spendable fiat. That conversion layer is where mule recruitment, off-perimeter exchanges and informal value transfer concentrate. Korean enforcement targeting both the recruitment cell and the unregistered-exchange perimeter in the same week is a deliberate dual-attack on the bottleneck, and offers a useful comparative for the UK debate about regulated-VASP versus OTC enforcement asymmetry.
In a major structural shift, the UK government has confirmed that AML/CFT supervision of law firms and accountancy practices will transfer from professional body supervisors (SRA, Law Society of Scotland, Law Society of Northern Ireland, accountancy bodies) to the FCA. Treasury insists the transition will be smooth, with the FCA adopting a fit-and-proper test for the relevant firms and operating a new fee regime. The reform follows years of FATF criticism and OPBAS-documented variation in professional-body supervisory rigour.
This is the single most consequential change to UK AML supervision in a decade. Lawyers and accountants are now formally recognised as gatekeeper-equivalent for AML purposes, with the same supervisor as the banks they advise. The structural prediction from the gatekeeper-attribution literature is unambiguous: supervisory consolidation closes a known regulatory arbitrage where firms could choose the gentlest of their available regulators, and it shifts the firm’s compliance equilibrium from minimum-acceptable to bank-standard. The implementation will, predictably, be slow and uneven, but the policy position is now settled.
In a busy sanctions week, OFAC designated Cuban state-owned oil company Unión Cuba-Petróleo (CUPET) and additional financial institutions including Banco Financiero Internacional under E.O. 14404, and on 25 June sanctioned a network smuggling minerals from eastern DRC into Rwanda in coordination with the M23 armed group. Alongside these, OFAC removed multiple Russia-related designees from the SDN list and issued a new joint comparative overview with the UK’s OFSI.
The simultaneous Cuba-petroleum, DRC-minerals and TCO-leadership designations show OFAC reaching across three distinct typologies in a single week, each anchored to the commodity or infrastructure that generates the underlying illicit revenue. The UK/US joint comparative overview is the more durable change: dual-track sanctions enforcement is becoming structurally bilateral rather than parallel. For compliance functions, the practical consequence is that the OFAC/OFSI screening overlap is widening and the wind-down treatment under TCO General License 2 (for CCU Commercial Bank in Cambodia) demonstrates that sanctions are now being calibrated transactionally, not just imposed in bulk.
The new EU Anti-Money Laundering Authority held its first official conference in Frankfurt earlier in June, with PwC and others publishing detailed conference recaps confirming AMLA now holds the EU’s AML/CFT guidance and direct-supervision powers. AMLA’s selection of its first cohort of directly-supervised institutions and its Article 26(5) AMLR consultation on ongoing monitoring (covered in Lab Report #9) continue in parallel.
AMLA’s first conference matters less for what was said than for what it signals: that the EU now has a single point of accountability for AML/CFT effectiveness across 27 member states, and that this point has chosen to make itself visible. The criminological literature on supranational supervision predicts that AMLA’s early credibility will be set by the handling of its first significant enforcement case, not by its rule-writing, and that case will likely come from one of the large, weakly-supervised national regimes that AMLA was created to bypass.
The substantive amendments to the UK Money Laundering Regulations covered in Lab Report #10 come into force today, 30 June 2026, with the principal exception of the new crypto counterparty CDD obligations under regulation 28A, which begin on 30 March 2027 to give VASPs the planned nine-month implementation runway. The remaining changes, narrowed EDD trigger, “unusually” qualifier, sterling threshold conversion and FCA reg 52A/52B information-sharing, apply from today.
This is the operational threshold for the largest change to UK AML rules since 2017. The risk-proportionate emphasis (EDD narrowed, “unusually” qualifier inserted) puts considerably more interpretive burden on MLROs, and the empirical evidence on UK bank compliance suggests that capability variance between firms will now become much more visible to the supervisor. The interplay with the FCA-as-single-supervisor reform announced this week is no accident: the two reforms are designed to be read together, and the FCA’s first round of supervisory dialogue under the new framework will set the tone for the next decade.
3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4N
© 2025. The Financial Crime Lab. All Rights Reserved