The past seven days should be read as a single, coordinated intervention against the service layer that keeps organised cybercrime and sanctions evasion running. Between 13 and 14 July the United States, United Kingdom and European Union imposed simultaneous designations against a bulletproof host, a criminal VPN operator, a cryptor vendor and Vitaly Kovalev – the Trickbot administrator whom Chainalysis links to over $300 million in ransomware payments. Two Russian FSB and GRU networks were sanctioned in the same 48-hour window. On the fraud side, DOJ pushed the Southeast Asian scam-compound frontier forward with Scam Center Strike Force disclosures pointing to more than $832 million in seized crypto and a fresh indictment against a $43 million pig-butchering laundering network in New York. Treasury opened its second front against Iranian financial infrastructure in eight days, sanctioning more than 50 individuals, entities and vessels tied to Mohammad Hossein Shamkhani, and freezing $130 million in digital wallets tied to the Central Bank of Iran. Coca-Cola disclosed a ransomware attack on its Fairlife dairy subsidiary. Two Scattered Spider members were sentenced to 5.5 years each for the Transport for London breach. Brazilian police ran Operation Hawala. The pattern is coherent: attacks against enablers, alongside enforcement against the labour markets and infrastructures those enablers serve.
On 13 July 2026 the US Treasury sanctioned First VPN Service, its administrator Dmytro Rashevskyi, and Belarusian cryptor vendor Yevgeniy Vladimirovich Silayev, and the UK Foreign, Commonwealth and Development Office designated a parallel set of enablers the same day. The following morning DOJ unsealed an indictment against three Russian nationals, Alexander Volosovik, Kirill Zatolokin and Yulia Pankova, and their companies Media Land LLC and ML.Cloud LLC for running bulletproof hosting used by LockBit, BlackSuit and Play; State’s Rewards for Justice is offering $10 million for information. Alongside, the EU sanctioned Vitaly Kovalev, the Trickbot administrator known as “Stern”, whom Chainalysis links to over $300 million in ransomware receipts across eight blockchains, together with Media Land, GRU Unit 29155, and pro-Russian hacktivist groups CARR and Z-Pentest.
When read as a single strategic move, this is a proof of concept for what the situational-prevention literature has been calling for since Clarke’s original programme – remove the enabling services before you chase the offenders, but what is genuinely new is the multi-jurisdictional synchronisation. Collier, Clayton, Hutchings and Thomas’s argument that cybercrime infrastructure is maintained by professional actors doing dull, routine service work is the theoretical underpinning of this campaign. Sanctioning that maintenance layer imposes a durable operating cost, because the professionals who run it cannot simply reconstitute their services under a different name if the Western financial and telecommunications perimeter treats them as radioactive.
On 14 July OFAC designated more than 50 individuals, entities and vessels tied to Mohammad Hossein Shamkhani’s illicit shipping and sanctions-evasion network, bringing the running total of sanctioned entities under Shamkhani’s patronage to more than 200. Treasury Secretary Bessent confirmed on X that OFAC had also sanctioned “multiple wallets tied to the Central Bank of Iran, resulting in the freeze of over $130 million”. The 14 July action targeted Sea Lead Shipping (Singapore), We Freight Shipping (Dubai) and 25 additional vessels; individuals designated included Asghar Aghili Dehkordi and Behzad Moghadas (full listing on the OFAC recent actions page). A separate 15 July action targeted seven entities in Iran, Nigeria, Italy and Russia supporting Islamic Revolutionary Guard Corps weapons procurement. The action followed Iran’s resumption of attacks on shipping in the Strait of Hormuz and the reimposition of the US naval blockade.
Danilov and Kostenko’s work on shadow-fleet resilience is directly on point: they show that vessel-, flag-, and intermediary-level sanctions raise costs and increase opacity but rarely disrupt export chains, because the systemic elements are payment channels, insurance and port access. The novelty of the 14 July action is that it went at the payment channel, freezing $130 million tied to the Central Bank of Iran, rather than the vessels. That is a move against a systemically important node, not a substitutable one. Whether it holds depends on whether cover payment infrastructure can be reconstituted through third-country correspondents; historically it has.
On 16 July DOJ unsealed an indictment against Zhuoying Chen and Haojie Zhang, two Chinese nationals resident in Brooklyn and Queens, alleged to have used approximately 45 shell companies and 140 bank accounts between 2020 and 2022 to launder at least $43 million in cyber-investment-fraud proceeds to accounts in China. According to BleepingComputer’s summary of the unsealed indictment, the network involved more than a dozen people across Queens and Brooklyn; each defendant faces up to 20 years. The prosecution sits alongside broader disclosures from the DOJ-led Scam Center Strike Force reporting more than $832 million in frozen cryptocurrency, 1.4 million malicious accounts neutralised, 500-plus fake investment domains seized, and coordinated action with Meta, Microsoft, and the Treasury and State Departments. Treasury also announced sanctions against a Burma-based armed group linked to organised crime targeting Americans.
The interesting fact about the Chen/Zhang indictment is the ratio of shell companies to individuals: 45 companies to a dozen operators. That is not a laundering network in the classical criminological sense; it is a mule-management business, with corporate registration used to fragment audit trails. Rational choice theory tells us why: shell registration is cheap, KYC on shell companies is uneven across US states, and the marginal cost of adding another entity is very close to zero. As long as the state-level company registry environment offers regulatory arbitrage, the professional service is worth running. The Strike Force’s $832 million figure suggests the enforcement architecture is beginning to match the professionalisation of the launderers, but the durable answer is upstream – company formation reform, not more downstream indictments.
On 16 July Thalha Jubair and Owen Flowers, both 19, were sentenced to five and a half years’ imprisonment each at Kingston Crown Court for the 2024 cyberattack on Transport for London that caused approximately £29 million in damages and forced the compromise of 5,000 customer accounts. It was the UK’s first conviction under Section 3ZA of the Computer Misuse Act, the “damage-causing” provision, and the sentencing judge noted the defendants had livestreamed portions of the attack. Both were members of the Scattered Spider cluster; Jubair had a documented history of TfL access dating back several months before the attack.
Scattered Spider is the closest current-generation illustration of Sutherland’s differential-association thesis operating at a very young age: English-speaking teenagers acquiring, transmitting and normalising a set of definitions favourable to intrusion inside encrypted-chat learning environments. The 5.5-year sentence is materially higher than sentences given to earlier generations of teenage intruders in the UK, and follows the pattern set by the Talos ransomware operator sentencing in 2023. Whether that changes the calculus at the recruitment layer, where Scattered Spider draws in new members, is doubtful. The literature on youth cybercrime pathways suggests that peer approval and status incentives dominate deterrence considerations. The more effective intervention is upstream disruption of the Telegram and Discord recruitment channels, not longer sentences after the fact.
Coca-Cola disclosed in an SEC 8-K filing dated 16 July that its Fairlife dairy subsidiary suffered a ransomware attack that resulted in the suspension of all US milk production at Fairlife facilities. No ransomware group has claimed the attack publicly; Coca-Cola has not confirmed data exfiltration or the size of any ransom demand. Fairlife is Coca-Cola’s approximately $4 billion premium-milk subsidiary.
Whether or not this attack proves to have been carried out by an entity tied to the sanctioned Media Land/1VPNS/Stern ecosystem, it belongs to the same category of harm. Guerette and Bowers’s work on the diffusion of benefits from crime prevention makes clear that hardening any one target, such as banks, hospitals, or energy, creates displacement pressure toward the next-softer target. Food-and-beverage manufacturers are systemically important but historically underinvested in operational-technology segmentation, and Fairlife is the second high-profile US dairy incident in twelve months. The regulatory implication is that critical-infrastructure designation frameworks need to broaden to include food-and-beverage OT, or the displacement pattern will continue.
On 15 July Rio de Janeiro Civil Police and the state Public Prosecutor’s Office launched Operation Hawala, executing 10 arrest warrants and 37 search warrants across Rio de Janeiro, São Paulo, Minas Gerais and Foz do Iguaçu against a laundering scheme that moved more than R$100 million (approximately $19 million) for Terceiro Comando Puro, Comando Vermelho and the PCC. Investigators identified a possible connection to a figure inside an Al Qaeda financing structure, and Financial Crime Matters confirmed the network’s activity in the tri-border area between Brazil, Paraguay and Argentina, where Lebanese intermediaries have historically operated financial services accessible to international terror-financing actors.
The convergence between domestic Brazilian organised crime and transnational terror-financing structures is not a new phenomenon in the tri-border area, Reuter and Truman documented similar patterns twenty years ago, but this case shows what modern convergence looks like operationally. The same intermediary can service PCC laundering flows and jihadist financing because both are dealing with the same problem: transferring value across borders in ways that survive Western AML architectures. That is functional, not ideological. From a policy standpoint, this argues for the treatment of the tri-border area as a shared sanctions and financial-integrity problem for all three home states, not a sequence of national actions.
Spanish national police announced the dismantling of a €140 million cybercrime and money-laundering network that ran business-email-compromise and investment-fraud schemes across Europe. Four arrests were made in Spain, Portugal and Panama; the operation had used approximately 800 bank accounts and 67 money mules, with €3 million frozen for victim restitution. 15 computers and 170 smartphones were seized. The operation ran in parallel with the OFAC/UK/EU action against ransomware enablers earlier the same week.
The ratio of 800 accounts to four principals mirrors the New York Chen/Zhang case: the professional layer is not people, it is accounts. What Spanish enforcement demonstrated is the same architecture the New York indictment revealed: a compact controlling group operating a very large financial-plumbing back end. The concentration of principals is an asset for prosecutors, because it means a small number of arrests can produce large operational disruption, at least temporarily. The vulnerability of the model, from the offender side, is that once discovered it is fragile. Displacement will send the accounts elsewhere, but the operator population that can run this architecture is finite.
The UK FCA published proposals on 17 July extending its conduct rules across approximately 37,000 additional financial firms as reported misconduct incidents rose by 70 per cent year-on-year, with Reuters noting the industry has begun sharpening staff scrutiny in anticipation of the new regime. Separately, the FCA on 16 July issued a Final Notice against Infinox Capital Limited for regulatory failings identified in the wake of the Financial Services Regulators Complaints Commissioner’s Annual Report 2025-26.
Extending conduct rules to a further 37,000 firms is a very large expansion of the regulated population, and it will only bite if enforcement follows scope. The FCA’s ongoing pattern, Enforcement Watch 2, higher market-abuse penalty thresholds and the Final Notice against Infinox, signals that scope expansion is intended to be accompanied by intensity, not diluted by it. Whether the resource base supports that is an open question. If the 70 per cent rise in reported misconduct is genuine and durable rather than a reporting artefact of the new regime, then the conduct architecture is measuring something real; if it is only reporting sensitivity, we will see the aggregate number normalise within a year.
The DOJ announced the extradition of Frederick Kumi, a Ghanaian influencer known online as “Abu Trica,” who was arraigned in the Southern District of Ohio on 10 July on charges of conspiracy to commit wire fraud and money laundering tied to an $8 million romance-scam operation using AI-generated fake identities against elderly Americans. The prosecution is being pursued under the Elder Abuse Prevention and Prosecution Act, with jury trial scheduled for 8 September 2026.
The Kumi indictment fits alongside the earlier Daren Li case (sentenced in absentia in February to 20 years for a $73 million pig-butchering-adjacent scheme) as evidence that AI-enabled synthetic identity fraud has moved from proof-of-concept to systematic criminal infrastructure. Generative AI removes one of the classic guardianship functions in cross-border romance fraud – the linguistic and visual asymmetries that once made scammers detectable. What is not yet clear is whether Western prosecutors’ extradition reach can be extended broadly enough to match the geographic distribution of the offender population, or whether we will end up with an enforcement regime that catches the recruiters and the couriers but not the platform operators.
3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4N
© 2025. The Financial Crime Lab. All Rights Reserved