This week the bill for compliance failure came due, and it came due multilaterally. FinCEN issued its largest ever Bank Secrecy Act penalty against a broker-dealer, hitting UBS with $125 million and, crucially, treating it as a recidivist. The EU imposed its first-ever sanctions against Southeast Asian scam-centre operators, formally adopting a doctrine the US and UK moved to last year. INTERPOL revealed the results of Operation First Light 2026: 5,811 arrests across 97 jurisdictions and $293 million intercepted. Europol and Eurojust dismantled a €50 million Albanian call-centre network. The through-line is not simply “more enforcement.” It is that regulators and police forces are increasingly acting on the infrastructureof financial crime (the mules, the accounts, the compounds, the correspondent chains) rather than the individual predicate offences.
Reuters reported that FinCEN announced a $125 million Bank Secrecy Act penalty against UBS Financial Services on 3 August, the largest ever imposed on a broker-dealer, with the firm admitting willful violations of AML program, transaction monitoring, and SAR requirements. Between January 2019 and June 2023 UBS failed to adequately monitor more than 60,000 foreign currency wires totalling over $10 billion, including flows linked to the US southwest border, Iran, Russia and Venezuela. Investment News noted that FinCEN coordinated with FINRA ($20M), the SEC ($20M) and the CFTC ($8M), all credited against the total, and UBS must now undertake a third-party lookback and independent compliance review. Critically, as Fincrime Central set out, this is the second BSA action against the firm: a $14.5 million penalty in 2018 covered similar failures.
The pricing here is deliberate. Under a rational choice framework, the calculus for a firm considering compliance investment turns on the expected cost of failure (probability of detection multiplied by penalty severity, discounted by the time value of avoided compliance spend). A $14.5M penalty in 2018 for materially similar failures was, in effect, priced in as a cost of doing business. The $125M, nearly nine times higher, is regulators signalling that the earlier price was wrong, and that recidivism itself is now a distinct aggravating factor. This is situational crime prevention applied at the institutional level: raising the effort and cost of the offending behaviour by making the penalty scale with prior conduct. Whether firms internalise the lesson depends less on the headline number than on whether shareholders and boards read the coordinated FINRA, SEC and CFTC choreography as a permanent shift in enforcement posture.
On 30 July the EU adopted its first sanctions targeting scam-centre networks in Southeast Asia, as The Diplomat set out, designating seven individuals and three entities under the Global Human Rights Sanctions Regime. Global Sanctions confirmed that the targets include the Prince Holding Group and its chairman Chen Zhi, linked to more than ten scam compounds across Cambodia, the Jin Bei Group and chairman Zhu Zhongbiao, and the Democratic Karen Benevolent Army (DKBA) with five senior figures including Chief of Staff Saw San Aung and the operator of the Deeko Park compound. Asset freezes and travel bans apply across the bloc.
This is the EU formally adopting a trust exploitation and forced-labour framing the US and UK moved to in 2024. What matters is that the compounds are being treated not as ordinary organised crime but as human-rights violators: the criminal enterprise is defined by the coerced labour used to run the scams, not by the scam revenue. The compounds work because they industrialise learning, replicating scripts, targeting techniques and coercion practices across a coerced workforce that has no exit. Sanctions on the patronage layer (Chen Zhi, DKBA leadership) reflect the recognition that these are not spontaneous criminal markets but franchised systems requiring protection. The open question is enforcement outside the EU perimeter, since most exposed assets sit in jurisdictions the sanctions cannot directly reach.
INTERPOL’s Operation First Light 2026 disclosure covered a campaign that ran from 15 January to 30 April, delivering 5,811 arrests, $293 million in criminal proceeds intercepted, over 142,000 victims identified, and 31,014 bank accounts blocked across 97 countries and territories. The operation relied heavily on I-GRIP (INTERPOL’s Global Rapid Intervention of Payments network), and in one flagship case reported by ThreatVectr, Singapore and Omani authorities stopped a $6.6 million business email compromise transfer. Compared with the 2024 operation (3,950 arrests across 61 countries), the 2026 numbers represent an approximately 50% expansion.
The interesting number is not 5,811 arrests but 31,014 blocked accounts. Under routine activity theory, the fraud offence requires a suitable target, a motivated offender and the absence of a capable guardian. What I-GRIP does is manufacture guardianship at the exact chokepoint where the offence completes: the payment. Historically the payment layer was the least policed part of the fraud value chain because it crossed jurisdictional boundaries faster than any cooperation mechanism could function. A rapid-intervention network that can freeze funds in hours rather than days converts payment settlement from an offender advantage into a defender advantage. The follow-on risk is displacement. Offenders will migrate to instruments and rails not yet covered by I-GRIP, including stablecoin off-ramps and non-cooperating jurisdictions. The measure of success is whether coverage grows faster than the displacement.
Europol and Eurojust announced on 31 July the dismantling of an Austrian-Albanian fraud operation with losses over €50 million and victims across Italy, Germany, Greece, Spain, Canada and the UK. A coordinated action day on 17 April resulted in 10 arrests, €891,735 in cash seized, and the search of three call centres and nine homes, alongside the seizure of 443 computers, 238 phones, and 6 laptops.
The Albanian call-centre model is the European sibling of the Southeast Asian compound, the same industrialised, script-driven, cross-jurisdictional structure, but with a different labour regime and a shorter victim-to-caller latency. The effective interventions here are the same as against the SEA compounds: raise the effort (physical infrastructure raids), raise the risk (JIT coordination compresses evidence timelines), reduce the rewards (cash and equipment seizure), and remove excuses (public prosecutions in destination jurisdictions). What is notable is the operational tempo. Between the 17 April action day and the 31 July disclosure, Europol is treating the announcement itself as a general deterrence instrument, not just a case report.
AML Intelligence reported that the UK FCA’s freeze of approximately $24 million in Euro Exchange Securities UK’s accounts has cascaded into a liquidity crisis at Banex International Bank in Puerto Rico, owned by Luis A. Gasparini. El Nuevo Día’s investigation added that Puerto Rico’s Office of the Commissioner of Financial Institutions (OCIF) appointed an independent compliance monitor on 26 June, and Banex was already under an October 2025 OCIF Consent Order for AML deficiencies.
This is the cross-border AML supervisory contagion effect that has been theorised for two decades and rarely observed in the open. When one national supervisor freezes correspondent-tier assets, the counterparty bank’s liquidity is impaired before any AML case is proven, because the funds are not fungible during the freeze. The interesting policy question is not whether the FCA was right to freeze (it clearly was) but whether the supervisory system has any coherent mechanism for loss allocation when a probe in one jurisdiction impairs a regulated entity in another. Under existing frameworks, the losses fall on Banex’s depositors, not on any offender. That is a structural weakness in the multilateral perimeter: the enforcement gains are pooled, the collateral damage is not.
On 30 July, as JURIST reported, OFAC designated six entities and individuals across China, India, Russia and Iran for supporting Iran’s Mahan Air, including Tang Xin (Shanghai Wings Logistics and Shanghai Elite), Skiez Travels in India, Air Cargo Pro in Russia, and DadeNegar Startup Studio, an IRGC-linked front alleged to be crowdsourcing the locations of US and Israeli defence equipment. The ABA Banking Journal’s OFAC update confirmed all actions were taken under EO 13224.
Mahan Air designations are now a regular OFAC output, but the geographic distribution here is what matters. Sanctioning general sales agents in China, India and Russia in a single action reflects a shift from targeting the sanctioned entity to targeting its service layer: the travel agents, logistics brokers and front companies that convert designated airlines into operational networks. This mirrors the correspondent-banking approach to AML. Instead of chasing individual bad actors, dry up the infrastructure they rely on. Whether the service providers rationally price the reputational and secondary-sanctions risk depends heavily on their home jurisdiction’s willingness to enforce.
Treasury announced the results of its OFAC modernisation initiative launched in June. Global Sanctions reported that Treasury has delisted 84 people and entities from the SDN list, the largest single administrative delisting in years, and resolved 18 duplicate entries. Removals covered deceased persons and designations more than 20 years old that were no longer national security priorities. A new Reconsideration Portal accelerates future delisting requests.
A well-maintained sanctions list is not just an enforcement instrument but a signalling instrument. When the list contains dead people and 20-year-old designations, screening false-positive rates rise, and every legitimate transaction paused for review is a small tax on legitimate commerce, a cost that ultimately weakens the political case for sanctions as a policy tool. Modernisation is therefore not deregulatory. It is the sanctions equivalent of calibrated situational prevention, keeping the intervention narrow enough to remain credible.
Two elder-fraud prosecutions closed this week. In Arizona, according to the DOJ USAO-AZ press release, Ajay Kumar, 24, pleaded guilty on 28 July to conspiracy to commit money laundering in a “phantom hacker” scheme targeting elderly victims, facing up to 20 years and a $500,000 fine. Separately, Verdice reported that Yaroslav Shilkloper, 50, a Ukraine-Israel dual citizen, was sentenced to four years for a fake-brokerage scheme (K6 Investing, Neotron Holding, Goldex Technology) that laundered proceeds across Ukraine, Georgia, Hungary, Israel and Czech Republic, with $2.8M already recovered plus $1.43M restitution.
Both cases involve the same offence architecture (remote impersonation, trust exploitation of vulnerable victims, layered laundering across cooperative and semi-cooperative jurisdictions) but very different offender profiles. Kumar is a domestic mule operator; Shilkloper is a principal running an international laundering pipeline. The sentencing gap (a plea with 20-year exposure versus a completed 4-year sentence for a principal) is a running tension in fraud prosecution: the network’s exposure to justice is inversely correlated with the offender’s centrality. Mules face harsher headline exposure because they are easiest to prosecute; principals face lower exposure because prosecutions typically settle for what can be proved, not what was done. Until this asymmetry closes, the deterrent effect of prosecution against the network principal remains weak.
The DOJ USAO-SDFL announcement confirmed that prosecutors in the Southern District of Florida charged four defendants on 30 July in a $19 million SNAP fraud and money-laundering scheme operating out of a Miami convenience store. The charges are part of a broader DOJ National Fraud Enforcement Division action across the Southeast with $90M+ in intended losses and 12 defendants across the region.
SNAP fraud is a textbook routine activity case. The benefits program creates a large, geographically distributed base of low-value transactions where the guardian (the retailer) is often the offender. What has changed is that DOJ is now prosecuting these cases as money-laundering conspiracies rather than benefit fraud, which raises the offence class from misdemeanour retail fraud to a federal felony with 20+ year exposure. The doctrinal reclassification is doing the deterrence work. The underlying scheme has not become more sophisticated, but the legal frame around it has hardened.
3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4N
© 2025. The Financial Crime Lab. All Rights Reserved