Lab Report #21

Lab Report #21

This week in financial Crime

Lab Report #21

This week in financial Crime

Lab Report #21 - This week in financial Crime

The theme this week is operationalisation. Last month’s declarations become this month’s memoranda, and this month’s memoranda become operating structures. FinCEN quantified the digital-asset scam problem at nearly $13 billion and formalised the concept of “guarantee marketplaces” as an infrastructure category in its own right. Days later, the US Attorney for the District of Columbia signed a memorandum of understanding with the UK’s National Crime Agency and Crown Prosecution Service that turns last month’s Five Eyes rhetoric into parallel-investigation architecture. Treasury designated a Turkish bank and two subsidiaries under its Iran authorities, the first NATO-ally institution hit under the current pressure campaign. Eurojust extended judicial cooperation into a €4.5 million sports-grant laundering scheme. The European Commission proposed nearly doubling Europol’s budget to €3 billion. The NCA extended into sports crypto with a £10 million freeze on a Premier League Barclays account. And the FCA’s new non-financial misconduct rule came into force on 1 September, formally extending conduct-rule scope to bullying, harassment and violence. The connective tissue is the same: enforcement is building the operating layer that discourse has been demanding for two years.


FinCEN quantifies the scam-center economy at $12.7 billion. On 3 September, FinCEN issued Alert FIN-2026-Alert005 alongside a Financial Trend Analysis drawing on 33,904 Bank Secrecy Act reports filed between September 2023 and December 2025. The analysis introduces the concept of “Guarantee Marketplaces”: online markets where scam operators buy modular services (account creation, phishing kits, laundering pathways) from professional providers. This is the language of an industrialised criminal supply chain, not an ad hoc typology. The framing matters because it reorients enforcement toward the intermediaries who service every scam rather than the individual scams themselves. Read through Sutherland’s differential association, this is a formal recognition that criminal technique is being taught, priced and sold as a professional service across a supplier network, and that regulatory attention needs to move to the market layer that reproduces the offending, not just to the offenders.

The DOJ and NCA sign a first-of-its-kind scam-center MOU. On 3 September, US Attorney Jeanine Pirro signed a memorandum of understanding with Stephen Parkinson of the Crown Prosecution Service and Graeme Biggar of the National Crime Agency, committing the two systems to parallel investigations, intelligence sharing, and joint decisions on jurisdiction for cases involving Southeast Asian scam compounds. The DOJ figures that anchor the document are stark: cyber-enabled fraud accounted for almost 85% of losses reported to IC3 in 2025; reported cryptocurrency investment fraud losses rose from $4.57 billion in 2023 to $8.65 billion in 2025, an 89% increase in two years. A joint disruption event with private-industry partners is scheduled for early October in London. Situational crime prevention has always insisted that transnational offenders adapt faster than institutions can respond, and that meaningful disruption requires shared operating routines rather than one-off summits. The MOU is a rare piece of infrastructure built to that standard: it does not create a new offence or a new institution, it standardises how two existing systems will move together.

OFAC severs Iran’s Turkish banking corridor. On 4 September, Treasury designated Golden Global Yatirim Bankasi and two related entities, issuing Iran General License CC to authorise wind-down. Reuters characterised Golden Global as the first NATO-ally bank sanctioned under the current pressure campaign, and Treasury Secretary Scott Bessent signalled a second bank could be designated the following week. The strategic logic is textbook secondary-sanctions doctrine: cut correspondent-account access to make dollar clearing untenable, and let compliance-driven derisking do the rest. What is worth watching is the political economy of what happens next. Sanctions research repeatedly shows that this kind of pressure produces displacement into offshore-financial-centre lenders rather than genuine reduction of illicit flows; the question is whether Türkiye’s regulatory response will match the enforcement signal or whether the corridor will simply move.

NCA freezes £10 million linked to Sorare’s Premier League deal. The National Crime Agency obtained a Westminster Magistrates’ Court freezing order in January 2025 covering £10,024,041.33 held in a Barclays account belonging to Football Association Premier League Limited, funds identified as the first payment under a four-year Sorare-Premier League partnership reportedly worth around $140 million. The Premier League is not accused of wrongdoing and has asked the court to modify the order; the freeze was reportedly valid until 14 September. The investigation focuses on unlicensed gambling concerns and follows a Gambling Commission inquiry into Sorare that has been running since 2024. The criminological point is not the underlying gambling question but the enforcement posture. Under a rational-choice reading, sports rights holders and their bankers have historically treated crypto-native partners as accretive revenue with minimal downstream compliance exposure. That expected-cost calculation changes the moment a proceeds-of-crime freeze reaches the receiving institution’s account rather than the counterparty’s balance sheet. This is displacement working in the other direction: enforcement following the money into the institutions that host it.

FCA non-financial misconduct rules come into force. From 1 September, the FCA’s amended Code of Conduct sourcebook (COCON 1.1.7FR) explicitly extends the conduct rules to serious non-financial misconduct in all FSMA Part 4A firms, with associated guidance on the fit and proper test. Bullying, harassment and violence are now framed as conduct-rule breaches, not culture-and-values matters left to HR. The intellectual move here is the collapse of the boundary between “how you treat colleagues” and “how you treat clients”. A conduct regime built on trust exploitation frameworks has to concede that patterns of predatory or coercive behaviour toward colleagues are also signals of fitness, and that firms which tolerate them are absorbing a governance liability the regulator now expects to see managed.

Eurojust exposes €4.5 million sports-grant laundering scheme. On 4 September, Eurojust announced coordinated action by Italian and German authorities against a group that used a sham sports association to divert grants intended for universities, public organisations and national sports bodies, with roughly €2.5 million reinvested in Germany. Preventive seizures include 83 bank accounts, two luxury vehicles, 21 real estate properties and four businesses, with a €7 million restraint executed the day before the announcement. This is a textbook routine-activity target: recurring, low-scrutiny grant flows to bodies that sit outside the anti-money-laundering gaze that governs banking. It is also a reminder that the most productive anti-money-laundering wins increasingly come from cross-border judicial cooperation on scheme-level typologies, not from suspicious transaction reports on individual accounts.

AUSTRAC removes 45 businesses from its remittance and digital-currency registers. On 7 September, AUSTRAC published a notice announcing that 45 businesses had been removed from the remittance and digital-currency exchange registers as scrutiny of high-risk payments intensified. This follows the regulator’s announcement one week earlier of a formal investigation into Western Union and last month’s $35 million Federal Court penalty against HSBC Bank Australia for systemic scam-response failures. Read through situational crime prevention, the significance is the register itself. Removing an operator from a register is a very low-cost, very high-friction disruption technique: it does not require prosecution, but it materially raises the effort involved in continuing to operate. Regulators are learning that the register is a lever, not a filing cabinet.

FBI charges two in $1.3 million pig-butchering scheme targeting 26 women. On 7 September, Forbes reported that Daejon Love and Taylor Jamie Chan were charged with conspiracy to commit wire fraud and wire fraud over a romance-investment scheme that scammed 26 women across California, Idaho, Washington and Oregon out of approximately $1.3 million, with prosecutors indicating the FBI believes the true victim pool is significantly larger. Under Sutherland’s differential association, the fact that two US-domiciled defendants can operate at industrial scale is not an anomaly but a natural consequence of the guarantee marketplaces FinCEN described earlier in the week: scripts, dashboards and laundering rails are not proprietary knowledge held only in Southeast Asian compounds. They are commodity inputs, available to any offender willing to pay for them.

European Commission proposes doubling Europol’s budget. On 3 September, the European Commission proposed increasing Europol’s budget to nearly €3 billion and broadening its mandate to address AI-enabled, encryption-enabled and technology-enabled crime. Whether the funding survives the trilogue process is a political question. The criminological question is whether more resource at the coordinating hub actually shifts the arithmetic of transnational enforcement, or whether it reproduces the same national-agency bottlenecks at higher spend. The MOU signed in Washington the same day is a test case in miniature for what happens when the coordinating body has less to do because two big agencies are already talking directly.


Research Worth Reading

Gujarathi, Verma and Nair (2026), Pig Butchering Scams as Cyber-Enabled Financial Crime: A Scoping Review of Dimensions, Modus Operandi, and Victim-Offender Dynamics, in Deviant Behavior. A synthesis of the fragmented pig-butchering literature into five themes covering dimensions, modus operandi, victim characteristics, offender characteristics and outcomes. The paper’s most useful contribution is its insistence that victims are not defined by financial illiteracy but by relational susceptibility, and that some offenders are themselves trafficked persons, a framing that maps directly onto how the FinCEN and DOJ documents this week describe the ecosystem.

Han and Button (2025), An Anatomy of ‘Pig Butchering Scams’: Chinese Victims’ and Police Officers’ Perspectives, in Deviant Behavior. A rare bilateral qualitative study drawing on both victim and law-enforcement accounts inside China, structured around the three-stage script of hunting, nurturing and harvesting. The paper’s account of how organised crime groups industrialise what began as opportunistic romance fraud provides the theoretical grounding for the “guarantee marketplace” concept FinCEN adopted this week.

Asyalı, Frank and Hölzmer (2026), Fake it till you make it: the psychological and communication tactics behind ‘Pig Butchering’ scams, in Journal of Cybersecurity, 12(1). A close reading of 26 scam manuals used inside pig-butchering operations, identifying seven core theories that scammers systematically deploy: impression management, social penetration, attachment, Sternberg’s triangular theory of love, interdependence, Maslow, and self-determination. The paper is essential reading for anyone still treating these scams as opportunistic. The manuals themselves are the strongest evidence yet that the technique is professionalised, transferable and trained.

What I Am Watching

The second Turkish bank Treasury Secretary Bessent signalled could be designated as early as this week, and whether Ankara’s response absorbs or resists the pressure.

The early-October London disruption event planned under the DOJ-NCA MOU, which will be the first test of whether the memorandum produces coordinated operational output rather than parallel press releases.

The Premier League’s application to modify the NCA freezing order before the 14 September expiry, and what it signals to other sports rights holders about hosting institutional risk in their bank accounts.

The FCA’s first enforcement action under the new non-financial misconduct rule, which will define what “serious” means in practice and how quickly the guidance is tested.

Whether the European Commission’s proposed Europol budget increase survives the Council and Parliament negotiations intact, and how much of the new resource is directed at coordination capacity rather than national-agency subsidy.

3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4N

Hello@FCResearchLab.com

© 2025. The Financial Crime Lab. All Rights Reserved

Privacy Policy 

The financial crime Lab | Financial Crime Prevention

turning evidence in to action against financial crime