This we saw further evidence that enforcement is moving more decisively against enablers. In a 48-hour window OFAC designated the same criminal VPN service that European law enforcement had taken down in May, and paired it with a Belarusian cryptor vendor whose only function is to make ransomware invisible to defenders. DOJ closed the door on one Ponzi mastermind, quietly opened it on another, and secured a $600 million settlement from Alibaba over illegal pharmaceuticals sold through its US marketplace. Treasury named an Iranian financier whose real value proposition to the Supreme Leader’s office was not access to money but access to a St Kitts holding company, three shadow exchange houses and property portfolios across six European jurisdictions. AMLA finalised its first binding enforcement framework. Interpol closed Operation First Light with 5,811 arrests. And the FBI, using Elliptic intelligence, seized the cloud backbone of the largest illicit online marketplace ever recorded. The strategic frame is now visible: 2026 enforcement is not chasing predicate offenders – it is dismantling the professional service layer that keeps them operational.
On 13 July OFAC designated First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarusian national Yevgeniy Vladimirovich Silayev, the last of whom sells “cryptors” that disguise ransomware as legitimate software. Treasury described the trio as directly enabling ransomware groups that have caused billions of dollars in losses to US businesses and critical infrastructure. The designations were coordinated with the UK Foreign, Commonwealth and Development Office, which sanctioned other cybercriminal enablers on the same day. The action followed a May 2026 takedown of the 1VPNS infrastructure by European law enforcement, supported by the FBI’s Boston Field Office, which seized 33 servers, executed a Ukrainian house search, and produced 83 intelligence packages covering 506 users.
This is the professionalisation of what Levi and Reuter called “the crime commodity chain”, being met with the professionalisation of enforcement against it. The cryptor is not itself a ransomware attack; it is a service that reduces the marginal cost of every subsequent attack. Situational crime prevention has been clear for two decades that removing enabling services is more efficient than pursuing end offenders. Still, until this year, Western sanctions regimes have rarely operated at that level of the value chain. Coordinating OFAC and FCDO action on the same day against the same class of enabler signals a policy answer: if the enabler is transnational, the sanction must be too.
The FBI seized the cloud computing account used by Huione Group subsidiaries, part of a sustained campaign against what Elliptic characterises as a $134 billion criminal marketplace and money laundering operation. Huione Guarantee, the Telegram-based marketplace, received more than $31 billion in cryptoasset transactions during its life, more than 25 times larger than Silk Road and AlphaBay combined. Huione’s payments arm received at least $103 billion in cryptoasset payments over its lifetime and operated physical outlets across Cambodia. In parallel, South Korean prosecutors charged a suspect accused of helping launder more than ₩747.6 billion connected to Huione Pay through cryptocurrency, duty-free goods, gold trading and Chinese intermediary networks.
Huione is the most important test case yet of whether Southeast Asian scam infrastructure can be dismantled through targeted attacks on its shared services. Displacement theory would predict migration to alternative marketplaces, and there is early evidence of that. But the more interesting variable is depth: seizing the cloud account underneath the marketplace, rather than just the marketplace itself, is a move against the operational layer beneath the criminal-facing layer. That is the layer where legitimate professionals/organisations such as cloud providers, payment processors, and exchange operators become the meaningful choke-points. Enforcement against the marketplace teaches other marketplaces to be quieter. Enforcement against their cloud teaches their vendors to check their customers.
On 1 July Alibaba Group Holding Limited and its US payment affiliate AUS Merchant Services (formerly Alipay US) entered a non-prosecution agreement to pay $600 million to resolve DOJ allegations that they failed to prevent the sale and importation into the United States of illegal pharmaceuticals, controlled substances, listed chemicals and pill-press equipment through Alibaba.com and AliExpress.com. Alibaba will pay a $125 million criminal penalty and forfeit $200 million; AUS will pay $85 million and forfeit $190 million. CBS News subsequently reported that DOJ investigators had unearthed evidence Alibaba knowingly permitted dangerous drugs to be sold to US consumers but that DOJ did not prosecute the company itself.
This is the second-largest e-commerce marketplace liability resolution in US history, and it lands squarely in the ongoing academic debate about whether NPAs actually deter. De Franco, Small and Wahid’s recent work shows that firms subject to NPAs are more likely to commit subsequent violations than firms subject to plea deals. If that finding holds, DOJ has bought a very expensive undertaking about future compliance from a firm whose economic incentives to permit high-margin third-party trade have not fundamentally changed. Sutherland’s framework on differential association in organisations would predict exactly this: when the routine business practice reliably produces regulatory failures, individual sanction is displaced onto the corporate entity and internal norms rarely shift.
On 10 July OFAC designated Ali Ansari, a Dubai-based Iranian financial facilitator whom Treasury described as overseeing “a sprawling global network of assets benefitting Iran’s leader, Mojtaba Khamenei, and other regime elites.” Ansari’s holdings under the St Kitts and Nevis-based Smart Global Limited include real estate and commercial properties in Germany, Luxembourg, Spain, the UK, Cyprus and the UAE. Alongside Ansari, Treasury designated three Iranian exchange houses, Mohammad Darbani and Partners, Lavasani and Partners, and Mohsen Khandan and Partners, that move billions of dollars annually on behalf of sanctioned Iranian banks through shell company layers. TASS reported the action was framed by Treasury as a response to Iran’s resumption of attacks on international shipping in the Strait of Hormuz.
The pattern here is instructive. What Treasury actually punished was not the movement of funds, which had been going on for years, but the professional-service architecture that allowed those funds to hold value across jurisdictions – the offshore holding vehicle, the general-partnership exchange houses, and the linked shell company network. Chang and colleagues’ work on the offshore networks of oligarchs identifies exactly this class of secretive professional intermediary as the durable feature of sanctions evasion. Naming the intermediary layer rather than the ultimate beneficial owner changes the compliance calculus for every service provider that touches these structures.
Angelo Martino, 41, employed at a US cyber incident-response firm, was sentenced on 9 July to 70 months in prison in the Southern District of Florida for conspiring with BlackCat/ALPHV ransomware operators to sell out the confidential negotiating positions of the clients he was paid to protect. Beginning April 2023 Martino provided BlackCat with strategy and payment ceilings, and conspired with two other former cybersecurity professionals, Kevin Martin and Ryan Goldberg, sentenced to 48 months each in May, to deploy BlackCat ransomware against additional victims. After extorting one victim for approximately $1.2 million in Bitcoin, the three split the proceeds and laundered the funds. Law enforcement has seized approximately $10 million in scheme-linked assets, including a food truck and a luxury fishing boat.
Rational choice theory applied to trusted-intermediary crime is usually about opportunity structure: the incident-response engagement gives a defender direct visibility into what the victim will pay and when. Martino’s real innovation was not technical, it was informational. The case underlines Maimon and colleagues’ recent finding that ransomware “groups” are better understood as networked professional roles than as fixed organisations, and that the negotiator role is one of the most poorly guarded links in the chain. If insider-threat sentencing at this level becomes routine, one plausible effect is that reputable incident-response firms move to structured, cleared, non-anonymised staffing on ransomware engagements – a small but real hardening of the target.
Bloomberg Law reported on 10 July that DOJ is moving to dismiss all charges with prejudice against Matthew Goettsche, the alleged mastermind of the BitClub Network cryptocurrency mining fraud, which prosecutors had valued at approximately $722 million in deposits at the time of the 2019 indictment. The reversal, which cannot be refiled, comes after nearly seven years of pretrial litigation and days before the case was scheduled for trial. Independent coverage confirms the terms are being finalised.
Nothing about the underlying conduct alleged in 2019 has become less true. What has changed is the resource calculus inside DOJ and, in all likelihood, the evidentiary posture of the specific case. Rational choice theory here applies to the prosecutor: when the marginal cost of trial exceeds the marginal benefit of conviction, cases collapse. The signal to future crypto-Ponzi defendants is more troubling than the outcome itself: a nine-figure fraud case, with a co-defendant who cooperated, could not be brought to verdict inside seven years. That is a deterrence problem for the enforcement architecture that goes far beyond BitClub.
On 8 July AMLA published its final Regulatory Technical Standards establishing a harmonised EU framework for assessing and enforcing breaches of AML/CFT obligations, introducing a common methodology for supervisors to evaluate breach seriousness using shared indicators, duration, repetition, impact, classify breaches into four levels of gravity, and determine proportionate enforcement outcomes. Global Relay’s summary notes the RTS will apply directly across all member states once adopted by the Commission. Notably, AMLA left the calculation method for fines open. Separately, AMLA also opened a consultation on a common EU-wide suspicious transaction reporting format under Article 69(3) AMLR, with the response window closing 20 September 2026.
A harmonised methodology for classifying breach gravity is an institutional shift, because it converts what has been a national-discretion exercise into a comparative benchmarking exercise. The interesting choice is the deliberate silence on fine calibration. Situational crime prevention teaches that the certainty of sanction matters more than its magnitude – and by fixing the classification but leaving the magnitude open, AMLA has prioritised convergence on certainty while preserving flexibility on severity. Whether that trade-off works depends on whether national supervisors converge on similar magnitudes without a formal formula. Historically, they have not.
Interpol reported the closure of Operation First Light 2026, a 97-country coordinated action running from mid-January to end-April that produced 5,811 arrests, intercepted approximately $293 million in illicit assets, identified more than 142,000 victims, blocked 31,014 bank accounts and analysed over 152,000 cases. During the operation authorities used Interpol’s I-GRIP stop-payment tool to check and halt fiat and virtual-asset flows in real time. Investigators also identified a single crypto wallet, controlled by a 20-year-old, that had moved approximately $123 million in ten months of romance-scam-linked flows.
The interesting datum in Operation First Light is not the arrest count but the age of the wallet operator. Twenty-year-olds do not build $123 million money-laundering pipes without infrastructure. What we are looking at, in criminological terms, is a labour market: young, technically fluent, poorly guarded operators serving upstream criminal principals who have kept themselves off-chain and off-passport. The distribution of arrests to money movers rather than to scam-compound principals mirrors the pattern in every large romance-fraud enforcement operation of the past three years. Displacement is the correct frame, but so is career progression – this is the entry-level layer of a labour market that has professional grades all the way up.
Federal law enforcement announced the arrest of 24 defendants across the US, Canada and Europe in a coordinated action targeting three India-based transnational organised crime groups, including the Bishnoi network. The three unsealed indictments in the Central District of California charge 37 defendants collectively with racketeering, extortion, drug trafficking, and targeted killings – including the 2023 assassination in British Columbia of Hardeep Singh Nijjar. Investigators seized approximately 1,000 kilograms of cocaine, one kilogram of heroin, $40,000 in cash and a dozen firearms. The New York Times reported that the network operated from India using incarcerated masterminds coordinating international operatives through contraband cellphones.
The Bishnoi case is a particularly clean example of what happens when a state’s carceral system becomes a permissive environment for external operations. Cohen and Felson’s routine activity theory requires a suitable target, a motivated offender, and the absence of a capable guardian – and inside a prison system where cellphones are available for a bribe, the guardian is absent by design. The transnational dimension is a symptom, not a cause. Until state capacity inside the originating jurisdiction changes, extraterritorial enforcement against symptoms will keep producing 24-arrest operations without dislocating the leadership tier.
3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4N
© 2025. The Financial Crime Lab. All Rights Reserved