This was the presidential handover week. On 1 July the United Kingdom took over the Presidency of the Financial Action Task Force from Mexico and, on the same day, President Giles Thomson unveiled a two-year Fraud Roadmap that puts a $500 billion annual harm figure at the centre of the international standard-setter’s work. The same 72 hours saw the US Treasury run a multi-front sanctions programme against Brazilian PCC-linked laundering, Islamic State-Khorasan crypto financing and Mexican CJNG fuel smuggling, the DOJ close a nine-figure crypto Ponzi with a guilty plea, and the SEC punish a major broker-dealer for calibrating its SAR system to its own convenience. Underneath the enforcement noise, a quieter structural shift: stablecoin issuers are being pulled into the role of same-day operational co-enforcers of OFAC designations. Europe’s own transition matters too, with the MiCAR grandfather period closing and AMLA’s first implementation measures due in three days. The week did not produce a single blockbuster case, it produced a policy architecture visibly reconfiguring around fraud, sanctions and stablecoins as the three defining problem sets of the next enforcement cycle.
The Financial Action Task Force launched its 2026–2028 Fraud Roadmap on 1 July, coinciding with the UK’s assumption of the FATF Presidency from Mexico. New President Giles Thomson, opening his term, cited a $500 billion annual global fraud loss figure and noted that 90 per cent of mutual evaluation reports now identify fraud as a major predicate offence. The Roadmap creates a private-sector consultative group, a “Global Response Against Fraud” event scheduled for spring 2027, and commits FATF to publish concrete recommendations at its February 2027 Plenary. Forbes framed the initiative as an expansion of FATF’s remit into data-driven cross-border surveillance.
For twenty years, FATF has treated fraud largely as a predicate for money laundering rather than a first-order harm. Elevating it to a stand-alone strategic pillar is a shift in classification, not just resourcing. Routine activity theory helps explain why the shift was overdue: the digital environment has removed the guardianship that once contained retail fraud within local jurisdiction, and the offender population has industrialised faster than any single national response. What the Roadmap really tests is whether an international standard-setter can compress from consultation-to-recommendation in eighteen months, when its usual cycle is closer to five years. If it cannot, member states will keep out-running it with domestic instruments.
On 1 July Treasury’s OFAC designated two Brazilian nationals (Victor Granado Shimada and Stella Barreto de Oliveira) three Brazilian firms (Victory Trading Comércio, Pixwave, Wave Construções) and a Portuguese national (Avenidas Flutuantes) for laundering roughly $190 million in seven months on behalf of the Primeiro Comando da Capital using e-commerce marketplaces and electronics distribution. Two days later, Brazilian Federal Police ran Operation Exchange against the same targets and froze approximately R$10.4 billion (about $2 billion) across related accounts and assets in what Brazilian authorities described as one of the largest asset-freeze actions ever conducted against organised crime in the country.
The synchronisation matters more than the totals. PCC has for years operated at the frontier of what Zaluar called “the connective tissue” between prison-based organised crime and the licit economy, and its laundering apparatus has long been resilient to unilateral action. Displacement theory would predict that a US-only designation simply pushes activity to Brazilian correspondents; a Brazilian-only operation is defeated by cross-border settlement. Two jurisdictions acting on the same targets within 72 hours removes the classic escape route. It also signals a maturation of the OFAC–Brazil relationship that was not visible six months ago.
On 1 July OFAC designated 134 cryptocurrency addresses tied to Islamic State-Khorasan Province financing, 131 TRON addresses and 3 Monero addresses, through which TRM Labs traced roughly $2 million of throughput since 2023 (approximately $1.4 million inbound, $880,000 outbound). This is the second time OFAC has taken direct crypto action against ISKP; the first was the July 2023 designation of Ali Shafiu. Within hours of the OFAC action, Tether froze all 131 TRON addresses, pushing its cumulative volume of frozen USDT above $4.4 billion.
Situational crime prevention has a specific term for this: target hardening. Tether’s same-day compliance action is not new; it has been building this posture since 2023, but the operational speed here is different. A stablecoin issuer executing sanctions-linked freezes at the same tempo as the sanctions announcement effectively collapses the arbitrage window that terrorist financiers previously exploited between designation and enforcement. The awkward corollary is that a private issuer is now the operational choke point for a US foreign-policy instrument. It is efficient, but it moves accountability to a place where public law struggles to reach.
On 1 July the US Attorney’s Office for the Middle District of Florida announced that the CEO of Goliath Ventures pleaded guilty to conspiracy to commit wire fraud and securities fraud in a scheme that raised approximately $400 million from investors, with actual investor losses of around $250 million. Prosecutors described a business that marketed itself as a DeFi arbitrage and crypto-asset yield platform but whose on-chain footprint bore no relationship to the strategies pitched to investors, and where new-investor funds were used to pay purported returns to earlier participants in classic Ponzi structure. Law360 has the sentencing schedule and forfeiture particulars.
When we apply rational choice theory to fraud, we usually treat the offender’s calculus as a function of expected sanction times and probability of detection. What Goliath illustrates is a second variable: the deliberate manufacture of trust indicators that raise the perceived legitimacy of the enterprise. The “DeFi” and “arbitrage” wrappers were never operational – they were signalling. Cross’s work on trust exploitation in investment fraud is directly applicable: the DeFi vocabulary does the work that “hedge fund” did in an earlier decade, offering technical opacity as a substitute for verifiable performance.
Europol announced the takedown of First VPN, a criminal virtual private network service that had underpinned ransomware and cybercrime operations across multiple jurisdictions. The France–Netherlands-led operation was executed in May, seized 33 servers, conducted a house search in Ukraine, and took down the domains 1vpns.com, 1vpns.net and 1vpns.org. Europol reported the operation generated 83 intelligence packages covering 506 users and has already fed 21 downstream investigations across member states.
Bespoke criminal-VPN services are infrastructure in Levi and Soudijn’s sense: they are not themselves the crime, they enable it. The takedown model that worked here, seize infrastructure, extract user-base, package it into investigative leads, is the same architecture used against AudiA6 and Endgame in earlier weeks. Berlusconi’s work on criminal network adaptation after key-node removal suggests that the important question is not the immediate disruption but the migration path. If 506 users cannot easily reconstitute equivalent guardianship-defeating infrastructure, the disruption is durable. If they can, it is only a cost pass-through.
The Securities and Exchange Commission fined Merrill Lynch $7.5 million for a suspicious-activity-reporting programme that, between 2020 and 2024, was calibrated so that its enterprise-wide AML monitoring only reviewed alerts above an internal risk-score threshold, meaning that a category of lower-scoring alerts, which should have been individually reviewed and, in some cases, converted into SARs, was systematically excluded. The SEC found the calibration was known internally and not disclosed to regulators.
Differential association operates inside institutions as well as between them: risk teams that agree, over years, that “below-threshold” means “not worth our time” are transmitting a definition of appropriate behaviour that is favourable to violation. The individuals involved are not typologically deviant; they are absorbing a workplace norm. The $7.5 million penalty is, on those terms, not a deterrent to bad actors but a corrective to organisational culture. Whether it works depends less on the money than on whether the boardroom actually rewrites the scorecard.
The European Anti-Money Laundering Authority issued a supervisory advisory as the MiCAR transitional period ended on 1 July 2026, warning of the risks associated with unauthorised virtual-asset service provider exits and setting out expectations for orderly customer transfer to authorised crypto-asset service providers. Firms that failed to secure MiCAR authorisation by the grandfather deadline must wind down services or transfer client relationships under supervisory oversight.
Grandfather-clause expiry is a classic situational moment: the incentive to move client assets, obscure records, or exit quietly rises sharply, because the marginal cost of compliance has become permanent while the marginal cost of departure is time-limited. AMLA’s advisory is essentially a warning that supervisors will interpret unusual outflows in the transitional window through a fraud-and-disappearance lens rather than a legitimate wind-down lens. It is the correct instinct.
The 10 July 2026 deadline in the EU Anti-Money Laundering Regulation obliges AMLA to publish its first tranche of implementing guidelines and draft regulatory technical standards covering business-wide risk assessments, internal policies and controls, customer due diligence, ongoing monitoring, group-wide policies, third-country branches, and occasional/linked transactions. This is the first hard deadline in the AMLR calendar and the first substantive test of AMLA’s rulemaking capacity.
Institutions produce rules in response to political demand; rules produce compliance costs; compliance costs shape the geography of financial activity. What matters about this deadline is not whether AMLA publishes on time but whether the RTS take positions that meaningfully diverge from national regulators’ pre-existing texts. Divergence forces convergence over the medium term. Consolidation of AMLR guidance without divergence would be a missed opportunity – a signal that the new supervisor intends to be a coordinator rather than a rulemaker.
3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4N
© 2025. The Financial Crime Lab. All Rights Reserved