This was the week the enforcement architecture began asking questions of itself. The Office of the Comptroller of the Currency delivered its first public denial of a fintech’s national trust bank charter in more than two dozen approvals, telling Wise US that its AML history and management team disqualified the application. DOJ made the largest single crypto seizure ever recorded in an investment-fraud case, $225 million in USDT, while filing five additional forfeiture actions worth another $25 million. Treasury opened a further Cuba-related sanctions front against Unión Cuba-Petróleo and a Rwandan gold refinery inside a DRC-related package. OFAC named an Iraqi Hamas OTC exchange operator in Istanbul and, in the same 24 hours, hit CJNG leadership across multiple Mexican states. German and Indonesian police dismantled the Kratos phishing-as-a-service platform. And an Armenian national extradited from Ukraine pleaded guilty to Ryuk ransomware attacks that generated roughly 1,160 bitcoin in ransoms. The strategic frame is now visible in two directions at once: enforcement is professionalising against the service layer, and it is beginning to be more selective about who gets to be part of the regulated perimeter in the first place.
On 21 July, in Corporate Decision #1381, the OCC denied Wise US Holdings’ application to charter Wise National Trust in Austin, Texas, on the ground that the applicant could not demonstrate an effective AML/CFT compliance program and that its proposed directors had shown a “persistent inability” to manage money-laundering and illicit-finance risk. The denial rested on a live July 2025 multistate consent order covering California, Massachusetts, Minnesota, Nebraska, New York and Texas, under which Wise had agreed to pay $4.2 million over late SAR filings, transaction-monitoring data-integrity issues and a missing independent review of its AML programme. American Banker described the decision as “a rare move” and the OCC’s first public denial of a fintech’s bank charter application following more than two dozen approvals in recent years. Wise announced it would refile under a GENIUS Act stablecoin framework; its shares fell approximately 11 per cent within 24 hours of the letter.
This is a shift in how the regulated perimeter itself is being drawn. For twenty years, the debate over AML enforcement has framed the problem as one of conduct – how do we punish firms that fail? The OCC’s Wise decision reframes the problem as one of entry, should firms with unresolved AML failures be allowed into new, higher-risk regulatory categories at all? Sutherland’s insight was always that white-collar norms are transmitted inside organisations; you cannot fix a broken firm by giving it a bigger perimeter. Denying the charter turns the OCC’s routine gatekeeping function into a situational control on the labour market for compliance. If it is applied consistently, it will change the calculus for fintech applicants at the drawing-board stage, not the enforcement stage.
On 21 July the DOJ filed a civil forfeiture complaint targeting 225,364,961 USDT traced to Southeast Asian pig-butchering operations, more than doubling the department’s previous single-case high-water mark of $112 million and taking the DC Scam Center Strike Force’s cumulative recoveries past $580 million. The investigation was opened in November 2023 by the US Secret Service’s San Francisco Field Office and reached across virtual-currency addresses linked to Chinese transnational criminal organisations. In parallel, the US Attorney’s Office for DC and the Secret Service filed five additional civil forfeiture cases seizing $25 million more, including one $12.1 million marriage-scam case with 200-plus victims and a $10.4 million Canadian-victim case with more than 270 suspicious transactions. Cumulatively, 2026 US enforcement against pig-butchering now stands at 276 arrests and $701 million in frozen assets.
The interesting comparison is with this week’s Wise decision. On the entry side, the OCC has narrowed the perimeter. On the enforcement side, DOJ is running the largest forfeiture pipeline in its history against transnational scam infrastructure. Both actions are directed at the same broad problem, the movement of criminal money across regulated financial architecture, but they operate at different points in the crime lifecycle. Situational crime prevention would predict that the enforcement volume by itself is not sufficient to change the offender population’s calculus, because the marginal cost of shifting to a fresh set of accounts is very low. What might change the calculus is the combination – narrower entry into the regulated perimeter, aggressive downstream forfeiture.
On 25 June (announced this week alongside a further package) OFAC sanctioned Gasabo Gold Refinery Ltd, its Chairman Jean Malic Kalima and General Manager Bosco Kayobotsi, plus three associated mining firms, Bugambira Mines, Wolfram Mining and Processing, and Rwinkwavu Mining Corporation, for laundering conflict gold from eastern DRC into Rwandan supply chains under armed escort by Rwandan Defence Force soldiers and M23 rebels. Treasury noted at least 60 kilograms of gold had been smuggled from eastern Congo to Gasabo earlier in the year. On 23 July OFAC further sanctioned networks fuelling Sudan’s civil war and additional entities and individuals accused of trafficking conflict minerals in eastern DRC, under an executive framework aligned with the Washington Accords ceasefire signed in December 2025.
Pirrie and Donnelly’s recent survey of crimes associated with geological materials is the necessary starting point for reading this action. Their key observation, that criminal activity in the minerals sector runs from illegal mining and smuggling through fraud, adulteration and substitution to environmental crime, points directly at the operational vulnerability of a refinery. A gold refinery is a chokepoint in the value chain. It is where illegally sourced material becomes fungible with legally sourced material. Sanctioning the refinery, its principals and the co-operating mining firms in a single action is a criminologically coherent move against the point at which routine activity theory’s convergence actually happens: illicit supply meets legitimate demand at the refinery gate. The measure of success is whether the sanctions produce refinery-level shifts in provenance-testing practice, not whether they change the volume of eastern-DRC mining.
On 23 July OFAC designated Zaid Issam Ahmed al-Jebouri, an Iraqi national based in Istanbul, along with two associates, for operating El-Kahira for General Trading, a Turkey-registered over-the-counter exchange that Israel’s National Bureau for Counter Terror Financing had already placed under a seizure order in January 2026 for transferring hundreds of thousands of dollars for Hamas. OFAC added seven TRON cryptocurrency addresses as identifiers; Chainalysis has traced approximately $38.6 million through those addresses. Treasury simultaneously designated Mahmoud al Abyari, the UK-based secretary general of the Muslim Brotherhood’s General Secretariat, for helping raise funds for Filistin Vakfi and Hayat Yolu, two Turkey-based charities previously blocked for Hamas support. Treasury noted that the exchange’s operators separately laundered funds for organised-crime networks, including the Swedish Foxtrot network.
Two things are worth noticing here. Firstly, the same OTC exchange is servicing terror-financing and Northern European organised-crime laundering flows – El-Kahira is not a specialist, it is a general-purpose criminal payment provider. That is the routine-activity structure Cohen and Felson described: a suitable target (untracked value transfer) meets a motivated offender (Hamas, Foxtrot) in the absence of a capable guardian (Turkish AML supervision). Second, the seven TRON addresses are exactly the same category of technical identifier that Tether’s July 2026 same-day freeze programme has begun to act on. If the Hamas-linked wallets are frozen at the issuer level with the same speed, we are looking at a working template for issuer-mediated sanctions enforcement in the terror-financing space, not just the sanctions-evasion space.
On 21 July German BKA and Frankfurt ZIT announced the dismantling of Kratos, one of the most widespread phishing-as-a-service platforms globally, following a coordinated operation with US and Indonesian authorities. The developer and technical administrator was arrested in Indonesia, more than 200 servers were rendered inoperable, and BKA identified approximately 1,800 criminal customers running about 15,000 phishing campaigns per month primarily using fake Microsoft authentication pages. The operation, labelled Olympus Blade, produced 850 confirmed victims across 35 countries directly identified from seized infrastructure. Kratos generated at least €300,000 in subscription revenue since 2024 and had evolved through three product generations (V0, V1, V2), the most recent of which offered a Node.js adversary-in-the-middle mode capable of relaying logins to Microsoft in real time and capturing session tokens to bypass MFA.
Kratos is a textbook illustration of what Collier, Clayton, Hutchings and Thomas meant by cybercrime as boring maintenance work. There is one developer, a modest revenue line, and 1,800 downstream franchisees producing 15,000 campaigns a month against half a million potential victims. The value the platform delivered to its customers was not innovation but reliability – a working AiTM proxy that captured session cookies with high fidelity. Taking the platform down does not remove the customers, but it removes the maintenance function they were paying for. The proof point will be how quickly a functionally equivalent service reconstitutes itself, and whether the seized customer data enables downstream prosecutions. On both metrics, Vu, Collier and colleagues’ recent DDoS-for-hire aftermath work is the honest benchmark: without sustained influence operations, half of takedowns are back within days.
On 9 July, in an announcement made public this week, Karen Serobovich Vardanyan, an Armenian national extradited from Ukraine, pleaded guilty in the District of Oregon to computer fraud and conspiracy to commit fraud and extortion for his role in Ryuk ransomware attacks on US organisations between November 2019 and April 2020. Prosecutors said Vardanyan and co-conspirators, Ukrainian nationals Oleg Lyulyava and Andrii Prykhodchenko and Armenian national Levon Avetisyan, received approximately 1,160 bitcoin, valued at more than $15 million at the time, in ransom payments from victims that included a Michigan-based company that paid nearly $1.2 million in January 2020, a Watsonville-based technology firm and a Texas-based school. Vardanyan agreed to pay $1.2 million in restitution and faces up to 15 years in prison; his sentencing is set for 22 September.
This case only became possible because the specific operator physically moved into a jurisdiction from which he could be extradited. Ryuk, and its successor Conti, sat inside a Russia-adjacent operating environment that made prosecution effectively impossible for years. What this week’s plea illustrates is the durability of the FBI’s model, under Operation Cronos and its adjacent investigative streams, of building charge packages ready to run whenever geography changes. Dark Reading’s reporting this week that LockBit’s US attacks have fallen 79 per cent since Operation Cronos is consistent with the Cartwright and Cartwright framing of ransomware groups as trust-dependent enterprises. Once the operator’s trust with affiliates and victims collapses, so does the business.
Europol announced Operation Compass, a yearlong crackdown against The Com network of English-speaking cybercriminals, with 30 arrests, 179 identified suspects and 4,340 URLs flagged for platform removal across 28 countries. The June–July 2026 Referral Action Days, coordinated by Europol’s EU Internet Referral Unit and Spain’s Intelligence Centre against Terrorism and Organised Crime with nine EU member states, focused specifically on the Cyber Com sub-group – the part of The Com that runs network intrusions and ransomware deployment. The 30 arrests and 179 identified suspects are cumulative across the full yearlong operation, not the single week.
The Com is close to the ideal-typical illustration of Sutherland’s differential-association thesis operating in encrypted-chat learning environments. Its Cyber Com sub-group is the same sociological population (English-speaking Anglo-North-American teenagers) that produced the self proclaimed Scattered Spider members sentenced last week for the TfL attack. The choice by Europol to prioritise URL-referral against The Com’s public content platforms is a supply-side intervention on the recruitment layer, targeting the media environment in which criminal identity formation happens. It is a less spectacular intervention than the arrests, but it is where the causal work is.
Treasury designated additional Cuban regime revenue-generation networks and Cuba’s state-owned oil and gas company Unión Cuba-Petróleo on 22 July, in an action that also included the issuance of a new TCO-related General License and the publication of a first-of-its-kind OFAC-OFSI Comparative Overview detailing operational parallels between US and UK sanctions programmes. Same-day actions removed a set of Russia-related designations that had been superseded and added updated Iran-related and Hong Kong Autonomy Act entries.
The Unión Cuba-Petróleo designation matters less as an enforcement action against Cuba specifically than as the second time in a month that a state-owned commodity company has been placed at the centre of a US sanctions programme; the CJNG-linked fuel-theft alert from FinCEN in early July was the first. What is being tested is whether hydrocarbons sanctions can be built onto the same infrastructure that has proved effective against terrorist financing and cyber enablers. The OFAC-OFSI comparative document is the more consequential deliverable, because it signals institutional convergence on operational method – the joint working assumption that US and UK sanctions programmes should be interoperable at the enforcement layer, not merely aligned in policy.
Also on 23 July OFAC sanctioned more than 50 individuals and entities linked to CJNG, targeting the cartel’s leadership, financiers and criminal operations across multiple Mexican states. The action follows the FinCEN supplemental alert issued at the start of July concerning cartel-linked fuel smuggling and tax-evasion schemes.
Cartel-level designations tend to produce discussion of two questions: whether they change organisational structure, and whether they displace revenue. The evidence from the past decade points reasonably clearly to the second answer being yes and the first being no. What is different in this action is the pairing with the FinCEN fuel-smuggling advisory and the parallel Unión Cuba-Petróleo designation: for the first time, US enforcement is treating the upstream commodity side of cartel operations as the primary financial pressure point, rather than laundering channels alone. Whether that produces measurable revenue disruption at the CJNG level is a testable question. It will show up first in customs and fuel-flow data at the US–Mexico border.
3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4N
© 2025. The Financial Crime Lab. All Rights Reserved