FinCEN Typology Reference

A cross-linked encyclopedia of money laundering, fraud, and illicit-finance typologies drawn from FinCEN advisories, alerts, notices, and Financial Trend Analyses — organized by pattern rather than publication date, with every entry tagged to the 2021 AML/CFT National Priorities and linked to related typologies.

Compiled from fincen.gov · current through August 2026 Not legal advice. An indictment or complaint is merely an allegation — all defendants are presumed innocent until proven guilty.

FinCEN AML/CFT National Priorities

On June 30, 2021, FinCEN issued its first government-wide AML/CFT National Priorities under the Anti-Money Laundering Act of 2020. Every typology article below is tagged to one or more of these eight priorities, listed here in no particular order (per FinCEN's own framing):

Cross-checked against Treasury's 2026 National Money Laundering Risk Assessment (March 2026, 5th edition) — the fifth-iteration risk assessment confirms fraud, drug trafficking, cybercrime, human trafficking/smuggling, and corruption remain the top proceeds-generating threats, names Chinese Money Laundering Networks (CMLNs) as the dominant global professional money-laundering infrastructure, and flags AI-enabled fraud, digital-asset investment scams, and illicit trade/tariff evasion as the fastest-growing vectors.

The Vulnerabilities layer (below) follows the FFIEC BSA/AML Examination Manual's structure — Financial Institutions, Persons & Entities, Products & Services, Legal Entities, Gatekeepers, and High-Value Goods — pairing each with a numbered examination checklist the way the manual pairs its own risk-factor narratives with examination procedures. Note: in February 2026, the FFIEC removed references to "reputational risk" from several manual sections pursuant to Executive Order 14331 (Aug. 2025); this reference reflects that current framing.

Sourcing status — read this first

✓ SOURCE-VERIFIED — the red-flag list is transcribed from the primary FinCEN document, and the named indicators are FinCEN's own. 62 articles currently carry this.

⚠ EDITORIAL SUMMARY — the red flags are a good-faith summary drawn from secondary sources and general knowledge of the typology, not transcribed from the underlying advisory. They are a starting point for orientation, not a substitute for the source document. 1 article currently carries this.

Every article links to the underlying FinCEN publication. For any compliance, filing, or advisory purpose, work from the primary document.

COR Corruption CYB Cybercrime TF Terrorist Financing FRD Fraud TCO Transnational Criminal Orgs. DRG Drug Trafficking HT Human Trafficking & Smuggling PF Proliferation Financing
State & Sanctions Threats

Terrorist Financing✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2026-Alert002 + FIN-2025-A001. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

TFPFTerrorist financing covers the movement of funds to designated foreign terrorist organizations (ISIS, Hamas, Hizballah) and to state actors that sponsor or shelter them (Iran, and historically North Korea). FinCEN's advisories in this space typically follow a specific geopolitical trigger — a Treasury/OFAC designation, an escalation in a conflict zone, or a sanctions-evasion scheme uncovered through BSA data — and pair a narrative on the group's financing model with SAR key terms financial institutions should use when filing.

Mechanics

Common financing channels include front companies and trading networks (often layered through trade-based money laundering), exploitation of informal value transfer systems, digital-asset infrastructure used to move funds around sanctioned banking channels, and, for Iran specifically, "shadow banking" networks that mimic correspondent banking relationships using unlicensed money changers.

Red flags — as published in FIN-2026-Alert002

Fourteen indicators in three groups, supplementing (not replacing) those in the June 2025 Iran advisory. Unusually for a FinCEN product, each indicator carries a paired suggested control action. These are set out separately below rather than buried in the indicator text, since they read as de facto supervisory expectations. Note the source itself varies its phrasing — most read "consider," but one uses the stronger "should consider," flagged in gold below.

Oil smuggling (4)
  • Shipping companies with Iranian counterparties — a petroleum or shipping company doing business with Iran-tied counterparties, or transporting goods on "shadow fleet" vessels tied to Iran or shown by maritime databases to have called at Iranian ports. Suggested control actionConsider ensuring correspondent account holders conduct due diligence on their customers for prior Iranian connections.
  • Shipping documentation irregularities — bills of lading or shipping invoices with no consignees, apparently falsified, or omitting key information to obscure an Iranian nexus. Suggested control actionConsider requiring review of shipping documentation for falsified or missing information where practical.
  • Disguised vessel information and ownership — vessels with recent or multiple name or flag changes, or ownership transferred after OFAC designated the owner/operator, where the designated party appears to retain an interest. Suggested control actionConsider requiring vessel due diligence for recent name, flag, or ownership changes, including transfers from sanctioned persons.
  • Disguised oil origin — documentation referencing "Malaysian blend" oil, particularly where the vessel is China-bound via Southeast Asia and maritime databases show AIS irregularities during the voyage or a ship-to-ship transfer in an area of concern or without commercial need. Suggested control actionConsider heightened due diligence on any transaction referencing “Malaysian blend” oil.
Shadow banking and front company abuse (4)
  • Unclear sources of funds — wires or deposits with missing or incomplete source-of-funds information, or that don't match the customer's line of business, involving entities in a high-risk jurisdiction for Iranian illicit finance. Suggested control actionConsider reviewing relationships showing a pattern of opaque dealings in jurisdictions at high risk for IRGC abuse.
  • High-risk company types and jurisdictions — a general trading company with opaque ownership registered in a UAE (or similar) commercial free trade zone, whose counterparties sit mostly in Singapore and Hong Kong, holding accounts at multiple institutions in China, Hong Kong, Oman, or the UAE. Suggested control actionConsider heightened due diligence on company types at high risk for IRGC abuse.
  • Front company transaction patterns — a Hong Kong-registered company banking through a Chinese non-resident account with little or no web presence, co-located with numerous similar companies, or recently incorporated yet transmitting large round-dollar payments with no adequate source-of-funds explanation, or making numerous large payments to UAE general trading companies or free-trade-zone intermediaries with no clear business purpose. Suggested control action — stronger phrasing in sourceShould consider heightened due diligence on recently formed companies transacting in unusually high amounts with Iranian shadow banking payment patterns.
  • Unusual use of exchange houses — transactions moving through multiple exchange houses and/or trading companies, accumulating fees as they progress, where the fees, transaction count, or pattern don't reflect standard commercial practice. Suggested control actionConsider heightened due diligence on customers making frequent or unusual use of exchange houses in high-risk jurisdictions.
Digital assets (6)
  • Unusual digital asset payments by petroleum, shipping, trading, or trust companies — a company with potential Iranian oil exposure deviating from normal business practice to send or receive payment in digital assets. Suggested control actionConsider heightened due diligence where the underlying transaction could relate to Iranian oil.
  • Stablecoin payments with unclear source of funds — a customer in a high-risk jurisdiction receiving a stablecoin payment inconsistent with their line of business, failing to provide source-of-funds information or providing documentation suggesting an Iranian link.
  • Unusual stablecoin account activity — a stablecoin issuer's customer, particularly a foreign entity such as an overseas purported trust company, opening an account then engaging in minting activity requiring multiple rate or limit increases in a short period, or otherwise transacting inconsistently with its reported profile.
  • Payments to or from an Iran-located DASP — blockchain analysis showing a customer account transacted directly or indirectly with an address attributed to an Iranian entity. Suggested control actionConsider using blockchain analytics to identify transactions connected to known Iranian entities.
  • Iran-related cyber indicators — activity logs showing connections from Iranian IP addresses; shared IPs or devices with users previously identified as having an Iranian nexus; authentication via an Iranian email service or telephone number; or device time zone, language, and settings consistent with Iran. FinCEN notes VPN, residential proxy, or Tor exit node use combined with other Iran-location evidence may indicate geofencing circumvention — and asks institutions to supply technical detail (IP addresses with timestamps, device identifiers, indicators of compromise) in the report.
  • Unregistered P2P exchangers, foreign-located MSBs, and nested DASPs — e.g. a DASP customer in a high-risk jurisdiction appearing to use the DASP's own liquidity to execute large numbers of offsetting transactions.

Regulatory history

FIN-2026-Alert002 — IRGC Front Companies, Financial Facilitators, and Digital Asset Infrastructure
Issued May 11, 2026 · Full PDF · IRGC designated an FTO April 2019

The structural point: entities function as IRGC instruments — moving funds, converting assets, acting on behalf of sanctioned actors — even where the companies themselves are not formally identified as IRGC-owned. Front company accounts outside Iran let sanctioned entities transact through the international financial system without ever repatriating funds to Iran. That's the detection problem in one sentence.

Scale from the October 2025 Iranian Shadow Banking FTA: oil companies potentially linked to Iran transacted roughly $4 billion in 2024; dozens of shipping companies (mostly Iraq, UAE, Hong Kong) moved approximately $707 million through U.S. correspondent accounts in the same year; and likely shell companies matching both shell and Iranian indicators moved $5 billion in 2024, primarily from non-resident accounts at Chinese banks operated by Hong Kong companies into the UAE.

The oil chain: shadow/ghost/dark fleet vessels — old, poorly maintained, operating outside standard maritime regulation, owned or leased by non-Iranian front companies — carry oil blended with third-country product or relabeled by forged documents, most commonly as "Malaysian blend," with the overwhelming majority sold to small independent Chinese refineries ("teapot refineries").

"Rahbar" companies: Iranian banks establish these to manage clients' international transactions; they use Iranian exchange houses to set up third-country front companies, exploiting permissive jurisdictions and free trade zones.

Digital assets: Iranian digital asset activity now runs to billions of dollars per year. Stablecoins are favored for liquidity, settlement ease, and rate stability — and Iran's abuse now includes minting, moving between large-volume issuers, and creating proprietary stablecoins such as USDZ, tied to OFAC-designated issuer Zedxion. Iran has also stated intent to use digital assets to collect payments from tankers transiting the Strait of Hormuz. FinCEN specifically flags that new digital asset businesses may incorporate in Iran with little notice or footprint, making recency itself a risk factor.

Named enforcement example: Zedcex Exchange Ltd. and Zedxion Exchange Ltd., UK-registered exchanges designated by OFAC in January 2026, connected to an Iranian businessman and sanctions evader; multiple addresses attributed to them processed funds for IRGC-linked wallets. Separately, the September 2025 designation of Derakhshan and Alivand — who facilitated purchase of over $100 million in digital assets for oil sales, moving them through front companies across multiple jurisdictions, with Alivand brokering for the Syria-based Al-Qatirji Company, a primary IRGC-QF oil partner.

Jurisdictional posture: Iran is subject to a Section 311 fifth special measure (2019) barring U.S. correspondent accounts for Iranian financial institutions. FATF has long listed Iran as high-risk and in February 2026 reiterated its call for countermeasures — including prohibiting Iranian DASPs from establishing a presence in other jurisdictions or forming relationships with their DASPs.

SAR filing instruction: key term in SAR field 2 and the narrative; select SAR field 33(a) (Terrorist Financing – known or suspected terrorist/terrorist organization). FinCEN expressly invites feedback on the alert's utility and on control limitations — a rare solicitation.

SAR key term: FIN-2026-Alert002 · SAR Field 33(a)

Red flags: ISIS financing — as published in FIN-2025-A001

Eleven indicators covering both organizational ISIS financing and homegrown violent extremist (HVE) activity. FinCEN notes there are limited financial indicators unique to HVE activity, which is precisely why the behavioral-change indicators below matter.

Fundraising and remittance patterns
  • One credit card or bank account used to book travel, accommodation, or transportation in an area of known ISIS activity for several unrelated people at the same time with no legitimate purpose
  • Fundraisers attached to social media profiles showing ISIS support or iconography, or referring to supporting the "mujahideen" or the "war against kufar" — especially soliciting travel funds to areas of ISIS activity, or referencing aid to imprisoned women and children in Iraq or Syria
  • Collecting small amounts via P2P, social media, or virtual currency over a short period, then sending a lump sum to an individual in a region where ISIS is prevalent
  • Remittances with no legitimate purpose to multiple unrelated individuals in jurisdictions known for ISIS facilitation, such as Türkiye
Pre-travel and pre-attack behavioral changes
  • Attempting to purchase travel tickets after abruptly liquidating assets, closing accounts, cancelling subscriptions, or receiving large unexplained cash. FinCEN adds that a period of account dormancy following these behaviors should also be regarded as suspicious, even if the customer eventually resumes transactions within the United States
  • Abruptly seeking as many lines of credit as possible — several credit cards, one or more loans — for unclear reasons, especially with no prior credit history. Especially suspicious where new cards are used almost exclusively for cash advances and virtual currency purchases, then payments are never made
  • A sudden influx of unexplained cash deposits, especially where the customer is unemployed or the deposits supplement a regular paycheck, or come from ATMs in ISIS-prevalent locations where the customer isn't known to reside or travel
  • Sudden adoption or increased use of methods concealing source or end use — P2P transfers, ATM withdrawals, third-party processors, prepaid cards, virtual currency, wire transfers
Geographic mismatch indicators
  • Local deposits withdrawn from other locations, including abroad, where the customer isn't known to reside or travel but where ISIS is prevalent
  • Virtual currency placed in a wallet from one IP address, then withdrawn at kiosks or converted to fiat by users at IP addresses in ISIS-prevalent locations unconnected to the customer
  • An account accessed in multiple countries simultaneously or within a very short window, particularly where ISIS is prevalent
FIN-2025-A001 — Financing of ISIS and its Global Affiliates
Issued April 1, 2025 · Full PDF · ISIS designated an FTO (via AQI, 2004) and SDGT under E.O. 13224

Verified against the primary document: funding figures, red-flag count, and case-study detail below match the FinCEN advisory.

Why the funding model changed: at its 2015 height ISIS funded itself from territory — oil, taxation, extortion, kidnapping, looted antiquities. After the 2019 loss of territory, organizational funds dwindled to $10–20 million, mostly cash and liquid assets. Treasury assesses ISIS generated around $8 million in 2024 from kidnapping for ransom, extortion, zakat, and international donations.

Current revenue by region: ISIS-Somalia raised $2 million from extortion in the first half of 2022 alone; ISIS in West Africa runs a proto-state enforcing religious taxes; ISIS-DRC taxes illegal gold mines and runs artisanal mining; ISIS-Sahel relies on "spoils of war" — plundered goods — possibly up to $6 million annually but unstable.

Decentralization is the structural point: ISIS now operates through affiliates receiving guidance and funding from four regional offices of its General Directorate of Provinces. Despite decentralization, better-resourced branches financially subsidize poorer offshoots — so affiliate-to-affiliate flows matter.

The camps: roughly 43,000 people with ISIS links remained in the open-air al-Hol camp as of 2024, mostly women and children, plus ~9,000 fighters in detention. Supporters in over 40 countries have sent money to ISIS-linked individuals in these camps, with al-Hol alone receiving up to $20,000 per month via hawalas, mostly originating outside Syria or transiting Türkiye. Funds are used to finance prison escapes and recruitment.

Fraudulent humanitarian appeals: ISIS supporters disguise fundraising as disaster or conflict relief, mimicking NPO campaigns — most commonly without any registered NPO involved. Campaigns avoid overt ISIS support, instead using specific religious terminology and imagery to signal affiliation, promoted primarily in Arabic and English but also Russian, German, and French (see Charities & NPOs).

Movement channels: cash couriers remain frequent, alongside banks in weak-AML jurisdictions, registered and unlicensed MSBs — especially hawalas, several sanctioned and ISIS-operated — online payment providers including some social media companies operating as unregistered U.S. MSBs, and digital asset exchanges. ISIS-K published QR codes in its magazine Voice of Khorasan enabling virtual currency donations; the UN reported ISIS's al-Karrar office sending up to $25,000 monthly to ISIS-K in virtual currency, and ISIS-K reportedly transferred at least $2,000 in virtual currency to the 2024 Crocus Hall attackers in Moscow. Assets used include Bitcoin, Tether (USDT), Ethereum, Monero, and Tron.

HVE financing: homegrown violent extremist activity is typically funded through legal means — personal savings, asset sales — which is why FinCEN emphasizes behavioral change over transaction type. Registered MSBs appear to be the preferred channel for domestic FTO supporters, sending low dollar amounts to avoid suspicion.

SAR filing instruction: key term in SAR field 2 and the narrative; select SAR field 33(a) (Terrorist Financing – known or suspected terrorist/terrorist organization).

SAR key term: ISIS-2025-A001 · SAR Field 33(a)
Case study — material support to ISIS
E.D. Va., convicted December 13, 2024

A Springfield, Virginia man convicted of providing material support to ISIS. From October 2019 to October 2022 he raised funds online across social media accounts, received electronic transfers and travelled hundreds of miles to collect funds by hand, converted the money to cryptocurrency, and sent it to Türkiye where it was smuggled to ISIS members in Syria — financing escapes of female ISIS members from prison camps and supporting fighters. Over $185,000 in cryptocurrency across the conspiracy. His primary co-conspirator was a British-born ISIS member residing in Syria.

Red flags: Iranian oil, shadow banking & procurement — as published in FIN-2025-A002

Fifteen indicators in three groups. Some carried forward from the rescinded 2018 advisory and remain valid. The 2026 IRGC alert supplements these rather than replacing them — both sets apply.

Illicit oil smuggling and sales (6)
  • Shipping documentation inconsistent with maritime database entries used for due diligence — FinCEN's example: the database shows the vessel called at an Iranian port, but that stop is absent from the shipping documents submitted for payment processing
  • Documentation referencing vessels that have undergone recent or multiple name or flag changes, or ownership transferred after OFAC designated the owner/operator where the designated party appears to retain an interest
  • Vessels claiming an IMO number that belongs to a different vessel, or to one previously scrapped
  • Documentation referencing "Malaysian blend" oil, particularly where the vessel is China-bound via Southeast Asia and databases show AIS irregularities or a ship-to-ship transfer near Southeast Asia
  • A petroleum or shipping company doing business with Iran-tied counterparties, or transporting goods on vessels tied to Iran or shown to have called at Iranian ports
  • Oil-related transactions and wires involving vessels previously linked to suspicious activity, or documentation — bills of lading, shipping invoices — with no consignees, apparently falsified, or omitting key information to hide the Iranian nexus
Shadow banking networks (5)
  • Transactions moving through multiple exchange houses and/or trading companies, accumulating fees as they progress, where the fees, transaction count, and pattern don't reflect standard commercial practice
  • An exchange house or trading company in close geographical proximity to Iran using forged or falsified documents to conceal parties, in order to use regional banks' correspondent relationships with U.S. institutions to access dollars
  • Wires or deposits with missing or incomplete source-of-funds information, or that don't match the customer's line of business, especially involving entities in high-risk jurisdictions for Iranian illicit finance
  • A general trading company registered in a UAE commercial free trade zone with opaque ownership, counterparties mostly in Singapore and Hong Kong, holding accounts at multiple UAE institutions
  • A Hong Kong company banking through a Chinese non-resident account with little to no web presence, co-located with numerous similar companies, or recently incorporated yet transmitting large payments with no adequate source-of-funds explanation — making numerous large payments to UAE general trading companies with no clear business purpose
Weapons procurement networks (4)
  • Transactions originating with or directed to general trading companies, suspected front companies, or companies with an Iran nexus. Front company indicators: opaque ownership, obscurely named directing individuals or entities, or business addresses that are residential or co-located with other companies — especially previously sanctioned ones
  • A customer declaring business information inconsistent with other available information such as prior transaction history — particularly where trade data shows a history of shipments to and from Iran, and where they transact predominantly with technology companies or chemical suppliers
  • Transactions directed to companies in unrelated businesses that don't align with CDD information. FinCEN's specific example: customers primarily receiving funds from commodities trading companies but sending funds primarily to electronics suppliers
  • Multiple companies incorporated at roughly the same time sharing counterparties, addresses, owners, or name similarities and showing similar transaction profiles — often with little web presence, transacting in large recurring amounts. Related pattern: a Middle East company with Iran links receiving payments primarily from petroleum companies then paying primarily to electronics companies in Hong Kong and China
FIN-2025-A002 — Iranian Regime's Illicit Oil Smuggling, Shadow Banking, and Weapons Procurement
Issued June 6, 2025 · Full PDF · rescinded and replaced FIN-2018-A006 · SAR key term IRAN-2025-A002

Verified against the primary document: NSPM-2 trigger, MODAFL/AFGS/IRGC-QF oil allocation, and the concurrent OFAC shadow-banking designation match the FinCEN advisory.

Policy trigger: NSPM-2 (February 4, 2025), the maximum pressure campaign. Issued the same day as OFAC's first shadow-banking designation under that memorandum.

The oil economics: Iran's budget allocates billions in oil to MODAFL, the Armed Forces General Staff, and the IRGC-Qods Force to sell on the international market to supplement their budgets — recent estimates point to a four-fold increase exceeding $10 billion annually and over 500,000 barrels per day. FinCEN's stark framing: by end-2025, over half of Iran's total oil proceeds will be allocated to its armed forces while its population faces economic hardship. Iran sells below market to entice buyers; as of April 2025 it exported ~1.6 million barrels/day, nearly all to China, overwhelmingly to small independent "teapot refineries."

Shadow fleet: Treasury and State have blocked over 350 vessels for carrying Iranian oil since 2018. These are often uninsured, underinsured, or covered by previously sanctioned or untested insurers — FinCEN notes the resulting environmental exposure, since national and port authorities may be left covering clean-up costs after a spill. Tactics include false flags, flagging by registries not authorised for that jurisdiction, AIS manipulation, and ship-to-ship transfers.

Why "Malaysian blend" is the tell: smugglers receive falsified documents in Southeast Asia relabelling product as Malaysian despite Malaysia producing relatively little oil, before onward transport to Chinese refineries. FinCEN notes institutions may see traces of this in international wires, payment requests, and letters of credit, and recommends maritime databases and International Maritime Bureau reports for verification.

Definitional distinction worth keeping: exchange houses are licensed to deal in foreign exchange and transmit funds; trading companies are not licensed to transmit funds but operate as exchange houses in practice, relying on their bank accounts to move funds for third parties.

Case study — the Zarringhalam network: on June 6, 2025 OFAC designated over 40 individuals and entities tied to brothers Mansour, Nasser, and Fazlolah Zarringhalam, who through Iranian exchange houses (GCM Exchange, Berelian Exchange) laundered billions via front companies largely in the UAE and Hong Kong, serving Iran's main oil and petrochemical exporters and the military.

Case study — Sahara Thunder: MODAFL's main front company for clandestine UAV sales, designated April 2024. Central to Iran's sale of thousands of UAVs, many transferred to Russia — including under an approximately $1.75 billion contract to produce Iranian-designed one-way attack UAVs at the Alabuga facility in Russia.

SAR filing instruction: key term in field 2 and the narrative; select field 33(a) where there is a suspected nexus to an Iran-backed terrorist organisation, plus relevant fields 36 and 38. Immediate telephone notification to law enforcement is required for violations requiring urgent attention; terrorist-activity hotline 866-556-3974.

SAR key term: IRAN-2025-A002 · Field 33(a)

Red flags: Hamas financing — as published in FIN-2023-Alert006

Seven indicators, issued thirteen days after the October 7, 2023 attacks.

  • A customer or counterparty transacts with OFAC-designated entities/individuals, or transactions contain a nexus to their listed identifiers — email, physical address, phone number, passport number, or virtual currency address
  • Information in a transaction between customers indicates support for terrorist campaigns
  • A customer transacts with an MSB or other institution — including one offering virtual currency services — operating in a higher-risk jurisdiction tied to Hamas activity, reasonably believed to have lax CDD, opaque ownership, or otherwise fail AML/CFT best practices
  • Transactions originate with, are directed to, or involve shell corporations or general "trading companies" with a nexus to Iran or other Iran-supported groups such as Hizballah and PIJ
  • A charitable organization or NPO solicits donations but shows no discernible charitable activity, or openly supports Hamas — sometimes via social media or encrypted apps, including in virtual currency
  • A charity or NPO receives large donations from an unknown source over a short period, then sends significant wires or checks to other charities/NPOs — a pass-through pattern
  • A customer transacts with known or suspected virtual currency addresses tied to terrorism or terrorist-financing donation campaigns
FIN-2023-Alert006 — Countering Financing to Hamas and its Terrorist Activities
Issued October 20, 2023, thirteen days after the October 7 attacks · Full PDF

Verified against the primary document: the $300M peak / tens-of-millions baseline Iranian support estimate and the eight funding streams match.

Iran's baseline support: historically estimated as high as $300 million/year in peak periods, more typically assessed in the tens of millions annually.

Eight named funding streams: Iranian state support; private donations; a global investment portfolio; diverting aid from legitimate charities; control of Gaza border crossings and commerce; racketeering business frameworks; extortion of local populations; and fundraising campaigns — including via fictitious charities collecting both fiat and virtual currency. Movement channels: physical currency smuggling, plus a regional network of complicit money transmitters, exchange houses, and Hizballah-affiliated banks.

Immediate context: issued alongside OFAC's designation of numerous Hamas members, operatives, and financial facilitators located in Gaza and abroad — Sudan, Türkiye, Algeria, and Qatar. FinCEN notes Treasury had by then targeted nearly 1,000 individuals and entities connected to Iranian-regime terrorism financing across Hamas, Hizballah, and other proxies.

Cyber-indicator instruction: financial institutions are asked to include chat logs, suspicious IP addresses, suspicious email addresses, and suspicious digital asset addresses in the SAR's structured cyber fields, and to cite or clearly explain the source of any external information that triggered the suspicious determination.

SAR filing instruction: key term in field 2 and the narrative; select field 33(a).

SAR key term: FIN-2023-TFHAMAS · Field 33(a)

Red flags: Hizballah financing — as published in FIN-2024-Alert003

Seven indicators, in addition to those in FIN-2024-A001, all of which remain relevant.

Designation and jurisdiction linkage
  • A customer or counterparty transacting with OFAC-designated Hizballah-connected entities, or with transactions containing a nexus to OFAC-listed identifiers — email addresses, physical addresses, phone numbers, passport numbers, or convertible virtual currency addresses
  • Use of foreign financial institutions identified as of "primary money laundering concern" under §311 referencing association with or use by Hizballah
  • Transactions with an MSB or other institution — including one offering CVC services — operating in jurisdictions at high risk for Hizballah financing (the tri-border region of South America, the Middle East, or West Africa) that has opaque ownership or beneficial owners who are known Hizballah associates
  • Transactions originating with, directed to, or involving known or suspected front companies whose beneficial ownership suggests a Hizballah nexus — indicators being opaque ownership structures or business addresses that are residential or co-located with other companies
Trade-based indicators — unusually specific
  • Invoices — particularly for electronics shipped from the U.S. to the tri-border region or the PRC, or used cars shipped from the U.S. to West Africa — that over- or under-charge the recipient, especially where goods don't match the counterparty's stated line of business and/or payment is facilitated by a Lebanese or Hizballah-connected financial firm or its foreign branch
  • Transactions referencing commercial activity involving bills of lading with no consignees, or vessels previously linked to suspicious activity or registered to sanctioned entities connected with Hizballah, the Houthis, the IRGC-QF, or the Syrian regime — with documentation apparently falsified, omitting key information, or inconsistent with maritime database entries
Sector and account-behaviour pattern
  • A customer with businesses in real estate, import/export, construction, diamonds and precious stones, or high-value art with numerous international counterparties in high-risk jurisdictions, making an unusually high number of cash deposits into business accounts, moving funds between business and personal accounts, or using personal accounts or personal credit cards to make business payments
FIN-2024-Alert003 — Countering Financing of Hizballah and its Terrorist Activities
Issued October 23, 2024 · Full PDF · supplements FIN-2024-A001

Verified against the primary document: the $700M/year Iranian sponsorship estimate and revenue-model detail match the FinCEN alert.

Scale of Iranian sponsorship: historical estimates put Iranian support at approximately $700 million per year. Hizballah also acts as a conduit for funds flowing from Iran to other Iran-aligned groups.

Four regional revenue models. Oil smuggling — a large share of revenue from smuggling Iranian oil and LPG to Asia and the Middle East alongside IRGC-QF and Houthi networks, mostly sold to the PRC with Syria a major buyer, using front-company-owned vessels under flags of convenience and the full deceptive-shipping toolkit. Middle East — smuggling gold, electronics, and foreign currency out of Iran, with proceeds returned via bulk cash or laundered through front companies. West Africa — financiers using diamonds and precious stones, import/export, and high-value art businesses, sometimes bribing law enforcement to facilitate bulk-cash movement. Latin America — the External Security Organization's Business Affairs Component has close ties to South American drug trafficking organisations, laundering through the Black Market Peso Exchange, hawala, and intercontinental bulk-cash networks.

Why it reaches U.S. institutions: Treasury's 2024 National Terrorist Financing Risk Assessment found Hizballah continues to use the U.S. financial system for laundering, smuggling, and trafficking — transferring funds through it and attempting to purchase military or export-controlled equipment through front companies. Designated financiers may open accounts in family members' names, or use unrelated nominees who profit from holding accounts on their behalf.

TBML commodities named: electronics and used cars are the common value-transfer vehicles. Hizballah has also historically controlled banks — Bayt al-Mal in Lebanon (OFAC-sanctioned 2006) and Lebanese Canadian Bank SAL (identified as a §311 primary money laundering concern in 2011) — and uses trusts and NGOs in Lebanon to provide financial services, plus unlicensed MSBs it controls. FinCEN notes recent CVC use but stresses the group "continues to rely extensively on more traditional methods like bulk cash smuggling."

SAR filing instruction — note the shared key term: this alert does not create its own. Use the existing IRANTF-2024-A001 in field 2 and the narrative, select field 33(a), and additionally include the term "Hizballah" in SAR field 33(z) where a link is known or suspected.

SAR key term: IRANTF-2024-A001 · Field 33(a) · "Hizballah" in Field 33(z)

Red flags: Iran-backed terrorist organizations — as published in FIN-2024-A001

Eight indicators — in addition to those in the 2018 Iran advisory and the October 2023 Hamas alert, all of which remain relevant.

  • A customer or counterparty transacts with OFAC-designated entities/individuals, or transactions contain a nexus to their listed identifiers — email addresses, physical addresses, phone numbers, passport numbers, or CVC addresses
  • A transaction or P2P transfer memo includes key terms known to be associated with terrorism or terrorist organizations
  • A customer transacts with an MSB or other institution — including a VASP — operating in a jurisdiction known or high-risk for terrorist activity, reasonably believed to have lax customer identification, opaque ownership, or otherwise fail AML/CFT best practices
  • Transactions originate with, are directed to, or involve front companies or general "trading companies" with unclear business purposes whose beneficial ownership suggests an Iran nexus — indicators: opaque ownership, obscurely named directing individuals/entities, or residential/co-located business addresses
  • A customer that is or purports to be a charitable organization or NPO solicits donations but provides no discernible charitable services, or openly supports terrorist activity — sometimes soliciting via social media or encrypted apps, including in CVC
  • A customer receives numerous small CVC payments from many wallets, then transfers to another wallet, particularly if logged in from an IP based in a jurisdiction known or high-risk for terrorist activity
  • Money transfers to a high-risk jurisdiction inconsistent with the customer's stated occupation, with vague purposes such as "travel expenses," "charity," "aid," or "gifts"
  • An account receives large payouts from social media fundraisers or crowdfunding platforms and is then accessed from an IP in a high-risk jurisdiction, particularly where the contributing social-media accounts contain content supportive of terrorist campaigns

An additional indicator worth flagging on its own: a U.S. or third-country incorporated company whose activities occur solely in high-risk jurisdictions with no relationship to its stated business purpose.

FIN-2024-A001 — Advisory to Counter the Financing of Iran-Backed Terrorist Organizations
Issued May 8, 2024 · Full PDF · SAR key term IRANTF-2024-A001

Verified against the primary document: proxy roster, key term, and the $40B NIOC 2021 sales figure match the FinCEN advisory.

Scope: the parent advisory covering the full proxy network — Hamas, the Houthis (Ansarallah), Hizballah, Palestinian Islamic Jihad, and Iran-aligned militias in Iraq (Kata'ib Hizballah, Kata'ib Sayyid al-Shuhada, Asa'ib Ahl al-Haq, Harakat al-Nujaba) and Syria. Establishes the IRANTF-2024-A001 key term reused by the later Hizballah alert.

Iran's own oil-to-terror pipeline: the National Iranian Oil Company sold ~$40B in products in 2021 alone, with crude/condensate exports reaching 1.3 million barrels/day to the PRC by 2023, some proceeds financing IRGC-QF and proxy activity. Funds move via front companies (often "trading companies") and exchange houses forming a shadow banking network, and via cultural/religious foundations as fronts — e.g. the Reconstruction Organization for the Holy Shrines in Iraq (ROHSI), ostensibly restoring Shiite shrines, actually an IRGC-QF conduit.

Case study — the $108M China Oil & Petroleum seizure (S.D.N.Y., Feb. 2024): seven defendants including a senior IRGC-QF official and Turkish energy executives indicted for an illicit billion-dollar network selling Iranian oil to PRC/Russia/Syria buyers. The U.S. seized $108M that a Hong Kong-based IRGC front company attempted to launder through U.S. correspondent accounts. Techniques: front companies to disguise Iran's role; falsified documentation deceiving unwitting banks; ship-to-ship transfers and AIS manipulation. A related D.D.C. indictment shows the same playbook — fraudulent documents masking origin, and a U.S. company used as a "trust" to hold profits for the IRGC.

Hamas: lost its Gaza tax/fee revenue base after October 7, 2023, leaving it dependent on Iran (~$100M/year since 2018), crowdfunding, and its investment portfolio (once ~$500M before May 2022 sanctions). Uses sham NPOs and crowdfunding under humanitarian cover — donations often landing in third-country accounts (Lebanon, Qatar, Türkiye) later accessed from Gaza. CVC fundraising since at least 2019: ~$165M in Hamas/CVC-linked SARs between Jan 2020–Oct 2023 across 200+ unique addresses (FinCEN cautions this is likely an overestimate, since filers often attribute a customer's entire transaction value to Hamas). Notably, al-Qassam Brigades announced in April 2023 it would stop accepting Bitcoin donations, warning donors could be targeted.

Houthis: funded substantially through IRGC-QF-backed facilitator Said Al-Jamal's smuggling network, generating tens of millions annually from Iranian commodity sales, plus port customs revenue and asset seizures from political opponents.

PIJ: shares Hamas's funding channels, including via the Hamas-controlled Islamic National Bank of Gaza and sham charities (Al-Ansar Charity Foundation, Muhjat al-Quds Foundation).

Virtual currency exchange cross-reference: the advisory notes the $3.4B FinCEN/OFAC settlement against the world's largest virtual currency exchange (Nov. 2023) was in part due to failure to identify and report transactions involving PIJ and Hamas's al-Qassam Brigades — directly tying the CVC/MSB vulnerability layer to terrorist financing enforcement (see Convertible Virtual Currency).

SAR filing instruction: key term in field 2 and the narrative; select field 33(a). Cyber indicators requested: email/IP addresses with timestamps, login location/timestamps, virtual currency addresses, device IMEI, and communication timing.

SAR key term: IRANTF-2024-A001 · Field 33(a)
FIN-2024-A001 — Countering the Financing of Iran-Backed Terrorist Organizations
Issued May 8, 2024

Verified against the primary document.

Covers the proxy layer — Hamas, Hizballah, Ansarallah (Houthis) — including Hamas soliciting digital asset donations since at least 2019, and Hizballah laundering through West African, European, and South American business networks, Lebanon-based trusts and NGOs, controlled unlicensed MSBs, and hawala.

Financial Trend Analysis — Iranian Shadow Banking
Issued October 23, 2025

The quantitative basis for the 2026 alert's scale claims, and source of the shell company indicator set: recent incorporation with limited or no internet presence; large transactions with unclear business purpose; and shared addresses, financial activity, counterparties, or name similarities with OFAC-designated Iranian companies.

State & Sanctions Threats

Proliferation Financing & Export Control Evasion ✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2023-NTC2 (joint FinCEN/BIS notice). The 22 additional indicators in FIN-2022-Alert003 remain operative and are not reproduced here. Verified ≤2026-07 (see changelog)

PFProliferation financing refers to funding the acquisition of weapons of mass destruction or their delivery systems; the adjacent typology of export-control evasion covers efforts to route controlled dual-use goods (electronics, machine tools, semiconductors) around U.S. and allied export licensing regimes. FinCEN's post-2022 output in this area is dominated by joint alerts issued with the Commerce Department's Bureau of Industry and Security (BIS) tracking Russian and, more recently, Iranian evasion networks.

Mechanics

Shell companies and freight-forwarder front companies in third countries (frequently in Central Asia, the Caucasus, Hong Kong, or the UAE) re-route restricted goods; payment is often structured through layered intermediary accounts or CVC to obscure the ultimate purchaser.

The two-key-term structure

FinCEN and BIS run two parallel SAR key terms, and choosing correctly matters: FIN-2022-RUSSIABIS for Russia-related evasion, and FIN-2023-GLOBALEXPORT for everything else. FinCEN's explicit instruction: where an institution suspects export-control evasion but is unsure whether it is Russia-related, it should use both codes.

Practitioner note, not from FinCEN: unlike the millions of SARs filed annually, every SAR bearing these key terms is reviewed by law enforcement. Filing institutions should anticipate follow-on investigative contact and potential grand jury subpoenas.

Red flags — as published in FIN-2023-NTC2

Thirteen indicators. These are in addition to the 22 indicators in the June 2022 Russia alert, which remain operative.

Documentation and disclosure
  • Purchases under a letter of credit consigned to the issuing bank rather than the actual end-user, with supporting documents such as the commercial invoice also omitting the true end-user
  • A customer lacks or refuses to provide details to banks, shippers, or third parties about end-users, intended end-use, or company ownership
  • Transactions involving entities with little to no web presence — no website, no domain-based email account
  • Customer phone numbers with country codes that don't match the destination country
  • Parties listed as ultimate consignees, or in the "consign to" field, that appear to be mail centres, trading companies, or logistics companies
End-user and listing linkage
  • The item — commodity, software, or technology — does not fit the purchaser's line of business
  • Customer name or address similar to a party on a proscribed list: BIS Entity List, Unverified List, Denied Persons List; OFAC's SDN List; or State's Statutorily Debarred Parties List. FinCEN adds that the basis for listing matters — WMD or military-intelligence linkages trigger broader controls regardless of whether the item is itself subject to the EAR
  • A purported civil end-user where basic research shows the address is a military facility, or co-located with military facilities in a country of concern
  • Companies physically co-located with, or sharing ownership with, an Entity List or SDN List entity
Payment and routing
  • Open accounts or open lines of credit used where payment services run through known transshipment jurisdictions, and/or products in payment memos align with BIS-designated disruptive technologies or the Commerce Control List
  • The customer is significantly overpaying relative to known market prices
  • A last-minute change in payment routing — previously scheduled from a country of concern, now routed through a different country or company
  • Payments made from entities at potential transshipment points, or atypical shipping routes to reach a destination

Disruptive technologies to scrutinise in commodity descriptions

The notice names six categories the Disruptive Technology Strike Force prioritises, which double as a checklist for reviewing payment memos and trade documentation:

  • Advanced semiconductors — logic/AI chips, fabrication equipment, electronic design automation software, and novel materials for production below 14 nanometres
  • Supercomputing hardware — including GPUs — and modelling/simulation software
  • Quantum technologies
  • Hypersonic technologies
  • Military bioscience — e.g. human performance enhancements such as brain-computer interfaces
  • Advanced aerospace technology

Regulatory history

FIN-2023-NTC2 — Joint FinCEN/BIS Notice: Global Evasion of U.S. Export Controls
Issued November 6, 2023 · Full PDF

Verified against the primary document: the FIN-2023-GLOBALEXPORT key term and the "beyond Russia" scope-extension framing match.

What changed: the two prior joint alerts were Russia-specific. This notice extends the framework to export-control evasion "in support of other nation-state adversaries and illicit actors globally," with a stated focus on advanced and critical technologies used to enhance adversaries' military capabilities or support mass surveillance programmes enabling human rights abuses.

Disruptive Technology Strike Force: announced February 16, 2023 by BIS and DOJ. Cells sit in the twelve U.S. cities with BIS Office of Export Enforcement field offices, each combining OEE agents, FBI, HSI, and an Assistant U.S. Attorney, supported by an interagency intelligence cell in Washington.

Penalties under ECRA: criminal exposure reaches 20 years' imprisonment and $1 million per violation. Administrative penalties — available without any showing of willfulness, so applicable far more broadly — reach $353,534 per violation or twice the transaction value, whichever is greater, plus denial of export privileges and listing on restricted-party lists.

Where the evidence lives: FinCEN notes institutions providing trade financing may hold end-use certificates, export documents, contracts, and letter-of-credit documentation — material that ordinary transaction monitoring never surfaces.

SAR filing instruction: key term in field 2 and the narrative; check box 38(z) (Other Suspicious Activity) noting "Export Evasion"; where known, indicate the relevant NAICS code in field 45(z) and the payment mechanism in field 46.

Parallel reporting channel: institutions may also report directly to BIS via its confidential Enforcement Lead/Tip form, EELEAD@bis.doc.gov, or the BIS Enforcement Hotline at 800-424-2980.

SAR key term: FIN-2023-GLOBALEXPORT · Field 38(z) "Export Evasion"

Red flags: Russia/Belarus supplemental — as published in FIN-2023-Alert004

Nine additional indicators, read together with the 22 in FIN-2022-Alert003 — this alert doesn't replace them.

  • Payments for defense or dual-use products from a company incorporated after February 24, 2022 (the invasion date) and based in a non-GECC country
  • A new customer trading in products tied to the nine High Priority Items List HS codes (below), based in a non-GECC country and incorporated after February 24, 2022
  • An existing customer who received none of the nine HS-code items before February 24, 2022, but is receiving them now
  • An existing foreign customer who received some of the nine HS-code items before the invasion date and requested or received a significant increase in those same items afterward
  • A customer lacks or refuses to provide details about end users, intended end-use, or company ownership
  • Smaller-volume payments from the same end-user's foreign bank account to multiple, similar suppliers of dual-use products — deliberately staying under the radar rather than one large payment
  • Parties listed as ultimate consignees or in the "consign to" field who don't typically consume or use commodities themselves — other financial institutions, mail centers, or logistics companies
  • The customer significantly overpays relative to known market prices for a commodity
  • The customer or its address resembles a party on the BIS Entity List, the OFAC SDN List, or State's Statutorily Debarred Parties List

The High Priority Items List

Nine HS codes developed with the EU, UK, and Japan by studying Russian weapons systems recovered on the Ukrainian battlefield — components found in the Kalibr and Kh-101 cruise missiles and the Orlan-10 UAV. A license is required for shipment of any of these to Russia, Belarus, Crimea, or Iran.

HS CodeDescription
8542.31Processors and controllers (e.g. microcontrollers)
8542.32Memories (e.g. SRAM)
8542.33Amplifiers (e.g. op amps)
8542.39Other integrated circuits (e.g. FPGAs)
8517.62Reception/transmission machines (e.g. wireless transceiver modules)
8526.91Radio navigational aid apparatus (e.g. GNSS modules)
8532.21Tantalum capacitors
8532.24Multilayer ceramic capacitors
8548.00Electrical parts n.e.s. (e.g. EMI filters)

BIS identified three diversion-risk fact patterns among non-GECC importers: the company never received exports before the invasion; it received exports but none of the nine HS codes before the invasion; or it received the nine-code items before the invasion and saw a significant spike afterward.

FIN-2023-Alert004 — Supplemental Alert: Continued Vigilance for Russian Export Control Evasion
Issued May 19, 2023 · Full PDF · joint with BIS · reuses key term FIN-2022-RUSSIABIS (no new code)

Verified against the primary document and secondary reporting: the 10,000-pieces-of-equipment figure and 9 new red flags (atop the original 22) match.

Context: issued on the one-year anniversary of the invasion. Per U.S. Government assessment, Russia had lost over 10,000 pieces of battlefield equipment and was tasking its intelligence services to circumvent controls to replace them. The Global Export Control Coalition (GECC) — 39 nations across North America, Europe, and the Indo-Pacific — maintains substantially similar controls.

The layering mechanics described in detail: an SDN or Entity List party creates a shell company that legally owns a front company; both may hold foreign bank accounts used to route funds back to the supplier, sometimes through a U.S. correspondent bank. A further obfuscation: an SDN uses a non-designated Russian supplier to procure through a subsidiary of an authorized reseller — "some authorized reseller subsidiaries may be less likely to conduct as much customer due diligence as their parent entities." Procurement agents may also split volume across multiple similar suppliers in smaller amounts specifically to attract less attention than one large transaction would.

Case study — KanRus Trading Company (D. Kan., arrests March 2, 2023): two U.S. citizens ran a years-long scheme supplying Western avionics to Russian companies. They received avionics bearing an FSB sticker for "repair" in the U.S., then concealed the true destination with a fraudulent invoice listing Germany. After a February 2022 export attempt was detained and a license requirement explained, one defendant wrote to a Russian customer that "things are complicated in the USA" and this was "NOT the right time" for more paperwork — then transshipped avionics through Armenia and Cyprus without a license in the months that followed.

Enforcement infrastructure named: Task Force KleptoCapture and the Disruptive Technology Strike Force (DOJ National Security Division + BIS, announced Feb. 16, 2023), spanning 14 U.S. Attorney's Offices across 12 metro regions.

Explicit anti-de-risking language, again: reasonable risk-based steps "should not... put into question a financial institution's ability to maintain or continue appropriate relationships with customers... and should not be used as the basis to engage in wholesale or indiscriminate de-risking of any class of customers or financial institutions."

SAR filing instruction: continues to use FIN-2022-RUSSIABIS (no new key term); check field 38(z) noting "Russia Export Restrictions Evasion"; NAICS code in field 45(z), payment mechanism in field 46.

SAR key term: FIN-2022-RUSSIABIS (reused) · Field 38(z)

Red flags: Russia/Belarus — as published in FIN-2022-Alert003

All 22 indicators from the foundational joint alert, still fully operative. FinCEN opens with the evasion logic: illicit actors deliberately target EAR99 items — low-tech consumer goods not on the Commerce Control List that normally need no licence — and engage complicit shippers or customs brokers to obscure the goods or their destination.

Customer profile and vessels
  • A maritime-industry customer transporting commodities of concern using trade corridors known as transshipment points for Russia and Belarus
  • The nature of the customer's underlying business — specifically military or government-related work — its products or services, and its geographical presence pose added risk of unintentional involvement in evasion
  • A customer acquires new vessels for no apparent economic or business purpose, or for use in shipping corridors involving identified transshipment countries
  • A customer buys or sells vessels, properties, or goods identified as having been involved with, or being blocked property under, U.S. or partner-country sanctions
  • New or existing accounts and transactions by individuals with previous convictions for violating U.S. export control laws, particularly involving export/import activity
Routing, timing, and address anomalies
  • Transactions involving entities with little to no web presence
  • A change in shipments or payments previously scheduled for Russia or Belarus now going to a different country or company
  • Payments from entities in third-party countries not otherwise involved in the transaction and known as potential transshipment points
  • Last-minute changes to transactions with an originator or beneficiary in Russia or Belarus
  • Parties with addresses inconsistent with the business or otherwise problematic — the physical address does not exist, or is residential
  • Atypical shipping routes for the product and destination
  • Freight-forwarding firms also listed as the product's final end customer, especially for items heading to traditional Russian transshipment hubs
Luxury goods rerouting
  • Consolidated shipments of luxury goods previously destined for Russia or Belarus, now routed to a transshipment country or a country without re-export restrictions
  • Rapid shifts to new purchasers of transactions involving restricted luxury goods
Russian state and military linkage — the most distinctive set
  • Entities whose website or business registration states they work on "special purpose projects" — a Russian designation that typically means military use
  • Companies displaying a certificate from the Federal Security Service of the Russian Federation (FSB RF), permitting work on projects classified as a state secret — typically shown only on the Russian-language version of the site
  • Companies physically co-located with, or sharing ownership with, a BIS Entity List or OFAC SDN List entity
  • Companies or individuals linked to Russian state-owned corporations — shared ownership, branches, subsidiaries, or shareholders — involved in export-related transactions or services. FinCEN supplies the naming conventions to watch for: RAO (joint stock company), FGUP/FSUE (Federal State Unitary Enterprise), GK (State Corporation), SPRE/NIPP (Scientific Research Production Enterprise), and NPO/GNPO (State Research and Production Center)
  • Export transactions identified through correspondent banking involving non-U.S. parties sharing owners or addresses with Russian state-owned or designated companies
  • Correspondent banking transactions connected to Russian petroleum-related firms, or firms reselling electronics and similar items to Russian firms
Purchasing patterns
  • When combined with other derogatory information, large-dollar or high-volume purchases of EAR99 items — including via business credit cards, or at wholesale electrical/industrial merchants and electronic parts providers — especially if paired with purchases at shipping companies
  • Use of business checking or foreign exchange accounts by U.S. merchants importing/exporting electronic equipment, transacting with third-country electronics and aerospace firms that also have offices in Russia or Belarus

Commodities of concern (BIS, 2022 alert)

All require a BIS licence before export or reexport to Russia or Belarus. Useful as a screening list against payment memos and trade documentation.

ItemECCNItemECCN
Aircraft parts/equipment9A991Sonar systems6A991
Antennas7A994Spectrophotometers3A999
Breathing systems8A992Test equipment3B992
Cameras6A993Thrusters8A992
GPS systems7A994Underwater communications5A991
Inertial measurement units7A994Vacuum pumps2B999
Integrated circuits3A001, 3A991, 5A991Wafer fabrication equipment3B001, 3B991
Oil field equipmentEAR99Wafer substrates3C00x

BIS-identified transshipment points (non-exhaustive): Armenia, Brazil, China, Georgia, India, Israel, Kazakhstan, Kyrgyzstan, Mexico, Nicaragua, Serbia, Singapore, South Africa, Taiwan, Tajikistan, Turkey, United Arab Emirates, Uzbekistan. FinCEN notes controlled items may be legally exported to these jurisdictions as production inputs — it is onward export of the finished goods to Russia or Belarus that may be prohibited.

FIN-2022-Alert003 — Russian and Belarusian Export Control Evasion
Issued June 28, 2022 · Full PDF · joint with BIS · established the FIN-2022-RUSSIABIS key term

Verified against the primary document: the "37 allies/partners" and "most comprehensive application" language matches verbatim.

Scope: controls aligned with 37 U.S. allies and partners, described as the most comprehensive application of Commerce's export authorities ever targeted at a single country. Primary targets: Russia's defense, aerospace, and maritime sectors, plus energy production and luxury goods used by Russian elites.

Where financial institutions actually see this: the alert enumerates the visibility points — the exporter receiving a letter of credit from the importer, the institution issuing a line of credit to the exporter, and the importer's wire payment arriving at the exporter's institution or passing through correspondent banking. Trade-finance providers may hold end-use certificates, export documents, and letter-of-credit documentation, plus SWIFT messages associated with open-account trade.

Explicit anti-de-risking language: FinCEN states that risk-based steps "should not... put into question a financial institution's ability to maintain or continue appropriate relationships with customers or other financial institutions and should not be used as the basis to engage in wholesale or indiscriminate de-risking of any class of customers or financial institutions."

SAR filing instruction: key term in field 2 and the narrative; check box 38(z) noting "Russia Export Restrictions Evasion"; NAICS code in field 45(z) and payment mechanism in field 46 where known. Expedited hotline: 866-556-3974.

SAR key term: FIN-2022-RUSSIABIS · Field 38(z) "Russia Export Restrictions Evasion"
Financial Trend Analysis — Suspected Evasion of Russian Export Controls
Issued September 8, 2023

Measures the response to both joint alerts. FinCEN notes BSA reports filed in response have given BIS "critical insight into Russian procurement activities that tips Special Agents about potential violations." The 2023 supplemental alert added the High Priority Items List — nine HS codes covering critical U.S. components Russia relies on for weapons systems, developed with the EU, UK, and Japan.

See alsoTerrorist Financing · Corruption & Kleptocracy (Russian elite sanctions overlap)
State & Sanctions Threats

Corruption & Kleptocracy ✓ SOURCE-VERIFIED

Commercial real estate red flags transcribed from FIN-2023-Alert002. Indicators in FIN-2022-Alert001/002 and the Venezuela, Nicaragua, and South Sudan advisories remain operative and are not reproduced here. Verified ≤2026-07 (see changelog)

CORFinCEN treats corruption — bribery, misappropriation of state assets, and the laundering of proceeds by senior foreign political figures (PEPs) — as a distinct national-security priority, reflecting a 2021 White House national security memorandum. Advisories in this category name specific jurisdictions (Venezuela, Nicaragua, South Sudan) or specific asset classes favored by sanctioned elites (luxury real estate, high-value goods).

Mechanics

Proceeds typically move through shell companies and trust structures in secrecy jurisdictions, then into high-value, hard-to-trace assets — real estate (see Real Estate Laundering), art and antiquities, and luxury goods — often using professional intermediaries (lawyers, real estate agents, art dealers) as unwitting or complicit gatekeepers.

Sanctions evasion in commercial real estate

FinCEN's January 2023 alert is the most detailed treatment of how sanctioned elites exploit a specific asset class. The core insight is that CRE's legitimate features are the vulnerability: transactions almost always involve private companies or institutional investors, so trusts, shell companies, and pooled investment vehicles are standard on both sides — used for ordinary legal, tax, and liability reasons — with several layers of entities frequently involved and often domiciled offshore.

The threshold-gaming problem, stated plainly by FinCEN. Because a fund may have many investors, an individual's stake commonly falls below the CDD Rule's 25% beneficial ownership threshold and escapes screening entirely. FinCEN goes further: even where a bank lowers its threshold to 10% for high-risk customers, investors seeking to evade sanctions may lower their interest to just below that. And critically — such an investor may be a general partner with actual control of the fund while sitting under the bank's ownership threshold. Control and ownership come apart, and the rule only catches ownership.

Four typologies named: pooled investment vehicles including offshore funds; shell companies and trusts across multiple jurisdictions; third parties — relatives, friends, business associates — setting up the entities or holding assets in trust; and deliberately inconspicuous investments. On that last point FinCEN is emphatic: the properties need not be luxury or high-end, and can be multifamily housing, retail, office, industrial, or hotel. There are no central geographic hubs — evasion is as likely in small- and mid-size urban centres as in major cities.

Trust analysis point: where a sanctioned person was at any time the grantor/settlor, trust protector, trustee, or beneficiary, institutions should take particular care to confirm they hold no present, future, or contingent property interest (per 31 CFR §589.331).

Red flags — as published in FIN-2023-Alert002

  • An offshore private investment vehicle used to purchase CRE that includes PEPs or other foreign nationals as investors — particularly family members or close associates of sanctioned Russian elites
  • Customers decline to provide information when asked about ultimate beneficial owners or controllers of a legal entity or arrangement
  • Multiple LLCs, corporations, partnerships, or trusts in a transaction with ties to sanctioned Russian elites, where the entities have slight name variations
  • Legal entities or arrangements such as trusts used to purchase CRE involving friends, associates, family members, or others closely connected to sanctioned Russian elites
  • Ownership of CRE through legal entities in multiple jurisdictions — often involving a trust based outside the U.S. — without a clear business purpose
  • Transfers of assets from a PEP or Russian elite to a family member, business associate, or associated trust in close temporal proximity to a legal event such as an arrest or OFAC designation
  • Legal instruments such as deeds of exclusion intended to transfer a CRE interest from a PEP or Russian elite to a family member, associate, or trust following such a legal event
  • Private investment funds or companies submitting revised ownership disclosures showing sanctioned individuals or PEPs who previously owned more than 50% of a fund reducing their stake to under 50%
  • There is limited discernible business value in the CRE investment, or it falls outside the client's normal business operations

Regulatory history

FIN-2023-Alert002 — Potential U.S. Commercial Real Estate Investments by Sanctioned Russian Elites
Issued January 25, 2023 · Full PDF · Fourth Russia-related FinCEN alert since the invasion

Verified against the primary document: the CRE definition (including multifamily housing) matches verbatim.

Definition note: "commercial real estate" here means property used for investment or income generation rather than owner occupancy — which expressly includes multifamily apartment buildings, not just offices, retail, and hotels.

Which institutions are in scope: banks (with CDD and beneficial ownership obligations) but also insurance companies, which held $556.7 billion in CRE debt at year-end 2021. FinCEN specifically flags loan syndication — spanning banks, life insurers, and other BSA-regulated institutions — and strongly encourages §314(b) information sharing during the process in which loans are developed and structured, not only after suspicion arises.

PEP framing worth noting: FinCEN reiterates that "PEP" excludes U.S. public officials and covers foreign individuals entrusted with prominent public functions plus immediate family and close associates — and that PEPs should not automatically be viewed as higher risk; the level and type of CDD should be commensurate with the actual risk presented (see Politically Exposed Persons).

Longstanding FinCEN attention: the alert notes FinCEN has tracked CRE laundering risk since at least its 2006 SAR-based assessment, followed by a 2011 CRE financing fraud study and the 2021 real estate ANPRM.

SAR filing instruction: key term in field 2 and the narrative. Expedited reporting via the 24/7 Financial Institutions Toll-Free Hotline (866-556-3974). Form 8300: Box 1b plus the key term in Comments.

SAR key term: FIN-2023-RUSSIACRE
Case cited in the alert — foreign bank ownership civil forfeiture
DOJ civil forfeiture complaint, January 2022

Two individuals who owned one of Ukraine's largest banks allegedly embezzled and defrauded it of billions of dollars, then used anonymous shell companies to launder the misappropriated funds into commercial real estate and businesses across the United States. FinCEN cites it as demonstrating that vulnerable properties include not only luxury CRE in large cities but ordinary commercial property throughout the country.

FIN-2022-A001 — Advisory on Kleptocracy and Foreign Public Corruption
Issued April 14, 2022 · Full PDF · SAR key term FIN-2022-KLEPTOCRACY · the anchor advisory for this typology

Verified against the primary document: the four corruption typologies and Russia-focused framing match.

The most substantive FinCEN treatment of corruption as a standalone typology, issued under the U.S. Strategy on Countering Corruption (December 2021), which elevated anti-corruption to a core national security interest. Where the Russia alerts address a specific actor set and asset class, this advisory frames the general problem.

Four corruption typologies FinCEN identifies: bribery — payments to obtain contracts, licences, or favourable treatment; embezzlement and misappropriation of state assets and public funds; extortion by officials; and abuse of public office for private gain, including directing state contracts to family-controlled entities.

Laundering channels named: shell and front companies concealing beneficial ownership; real estate, especially all-cash purchases through legal entities; luxury goods; the use of attorneys, accountants, formation agents, and other professional gatekeepers; and correspondent banking relationships that give foreign proceeds access to the U.S. system.

Regulatory hooks reiterated: §312 enhanced due diligence for private banking accounts held by senior foreign political figures (31 CFR §1010.620), requiring institutions to ascertain whether nominal or beneficial owners are senior foreign political figures and to apply enhanced scrutiny reasonably designed to detect proceeds of foreign corruption — see Politically Exposed Persons.

Red flags for this advisory have not been transcribed from the primary document in this reference. The CRE indicators above are source-verified; consult FIN-2022-A001 directly for its own indicator set.

FIN-2022-Alert002 — Real Estate, Luxury Goods, and Other High-Value Assets
Issued March 16, 2022 · Full PDF · SAR key term FIN-2022-RUSSIALUXURY · red flags remain operative

Verified against the primary document: the luxury-goods definition (watches, vehicles, yachts/planes, apparel, alcohol, jewelry) matches verbatim.

The predecessor covering both residential and commercial real estate plus luxury goods — high-end watches, vehicles, yachts and planes, apparel, alcohol, jewellery — and other high-value assets including artwork, precious stones such as diamonds, and metals such as gold (see Luxury Goods, PMSJ, Art). Among its indicators: use of legal entities with a nexus to sanctioned elites to hide the ultimate beneficiary; and changes without apparent business reason to the transaction patterns of a firm outside the U.S., Russia, Belarus, and Ukraine where new transactions involve convertible virtual currency and Russian-related investments.

FIN-2022-Alert001 — Increased Vigilance for Potential Russian Sanctions Evasion
Issued March 7, 2022 · Full PDF · the first of the four Russia alerts

Verified against the primary document: 13 red flags, CVC provisions, and the March 7 issuance date (days after the invasion) match.

Issued days after the invasion; establishes the baseline sanctions-evasion framework the subsequent three alerts build on.

Laundering Mechanisms

Trade-Based Money Laundering (TBML)✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2010-A001. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

TCODRGTBML disguises the movement of illicit proceeds as legitimate international trade. FinCEN's foundational SAR-filing guidance on this typology dates to 2010, but it recurs constantly as an overlay technique inside cartel financing, terrorist financing, and sanctions-evasion cases.

Mechanics

The classic technique is over- or under-invoicing: goods are shipped with an invoice value that doesn't match their true worth, and the difference settles an unrelated debt. Related sub-techniques include multiple invoicing of the same shipment, phantom shipments with no goods at all, and misrepresenting the quantity or quality of goods. In the Mexico-U.S. corridor, TBML frequently intersects with funnel accounts and the Black Market Peso Exchange.

Red flags — as published in FIN-2010-A001

FinCEN developed these with the National Drug Intelligence Center and ICE's El Dorado Task Force. FinCEN's own caveat applies: no single indicator alone signals TBML, and each must be weighed against expected activity for that customer. These are strongest when seen alongside shipments of high-value merchandise (electronics, auto parts, precious metals and gems) into duty-free trade zones such as Panama's Colón Free Trade Zone.

Documentary discrepancies
  • Third-party payments for goods or services made by an intermediary apparently unrelated to the buyer or seller — often used to obscure the true origin of funds
  • Amended letters of credit without reasonable justification
  • A customer unable to produce appropriate documentation (invoices) to support a requested transaction
  • Significant discrepancies between descriptions of goods on the bill of lading, invoice, certificate of origin, or packing list
Monetary instruments & structuring
  • Negotiable instruments (traveler's checks, cashier's checks, money orders) in round denominations under $3,000 used to fund domestic accounts or smuggled abroad — often sequentially numbered, purchased at multiple locations, missing payee information, or bearing visible broker markings
  • Checking accounts receiving cash deposits under $1,000 several times monthly, followed by foreign ATM withdrawals — "micro-structuring" by smurfs
  • Sequentially numbered checks drawn on U.S. accounts negotiated through foreign MSBs (casas de cambio), sometimes payable directly to the casa rather than a named business
  • CTRs generated for accounts with multiple same-day cash deposits, especially across branches in different states
Wire transfer patterns
  • International wires received as payment for goods where the ordering party doesn't reside in the country the wire originated from
  • Wires originating from BMPE-associated jurisdictions: Mexico, Guatemala, Argentina, Brazil, Paraguay, Uruguay, Venezuela
  • Payment destinations tied to duty-free trade zones: United States, Hong Kong, China, South Korea, Taiwan, Spain, Panama, Curaçao
  • No apparent business relationship between originator and beneficiary; inadequate originator/beneficiary/purpose information; or frequent round or whole-dollar amounts
  • Funds transferred into U.S. accounts then out again in the same or nearly the same amounts, with high-risk origin and destination jurisdictions
  • Sudden onset and equally sudden cessation of wire activity within a short window — possible temporary laundering conduit
Account and entity structure
  • A foreign import business with U.S. accounts receiving payments from outside its customer base's geography
  • U.S. companies operating out of foreign countries where ownership or controlling persons can't be determined, or the business purpose isn't apparent (see Shell Companies)
  • Multiple deposits in various locations while the account owner resides elsewhere
  • A customer with multiple accounts, or accounts held by closely related family members across several institutions — used to place and layer illicit funds
  • Straw-party account networks: foreign visitors opening multiple U.S. accounts, then returning home after signing blank checks and relinquishing checkbooks and ATM cards to a beneficial owner. Tell-tale signs: over-the-counter deposit slips (because pre-printed slips left the country), deposits across multiple U.S. jurisdictions, foreign ATM withdrawals, and checks where signature handwriting differs from the payee handwriting
  • Unusual activity in established U.S. accounts for non-resident aliens — structured cash and monetary-instrument deposits, checks to foreign businesses unrelated to the account holder, wires to unrelated entities

Regulatory history

FIN-2010-A001 — Filing SARs Regarding Trade-Based Money Laundering
Issued February 18, 2010 · Full text · Developed with NDIC and ICE El Dorado Task Force

The foundational U.S. TBML advisory. Frames TBML as one of three FATF-identified methods for moving criminal proceeds (alongside the financial system itself and physical cash movement), and situates it against an estimated $15.7 trillion in global merchandise exports (2008) — the volume that makes illicit trade hard to isolate. Explains the Colombian Black Market Peso Exchange as the archetypal complex scheme, and notes analogous systems in Venezuela and the Argentina/Brazil/Paraguay tri-border region.

Notable finding: filers clearly identified activity as TBML or BMPE in only 24% of relevant SAR narratives — the other 76% had to be surfaced by complex keyword queries. FinCEN also documented a substantial reporting lag: 30% of suspected 2004 activity wasn't reported until the first half of 2009. Over 17,000 SARs covering January 2004–May 2009 reported roughly $276 billion in aggregate suspect transactions.

Geographic trend data: Mexico and China were most frequently named, but China-linked narratives rose across 2004–2008 while Mexico-linked narratives began falling. Panama ranked third (Colón Free Trade Zone). The Dominican Republic and Venezuela showed the fastest growth.

SAR filing instruction: check the appropriate box in the Suspicious Activity Information section and include the abbreviation in the narrative, with an explanation of why the institution suspects this activity.

SAR narrative term: TBML or BMPE
FIN-2014-A005 — Update on U.S. Currency Restrictions in Mexico: Funnel Accounts and TBML
Issued May 28, 2014 · FinCEN page

Updates the 2010 advisory in light of Mexico's restrictions on U.S. dollar deposits, which pushed cartel proceeds toward funnel accounts and trade-based settlement rather than direct cash repatriation. Read alongside the earlier Mexico currency-restriction advisories (FIN-2010-A007, FIN-2012-A006, FIN-2013-A007).

FEND Off Fentanyl Act Orders — CIBanco, Intercam Banco, Vector Casa de Bolsa
Issued June 25, 2025 · First-ever use of FinCEN's "sixth special measure"

Orders finding three Mexican financial institutions to be of primary money laundering concern for facilitating cartel fentanyl proceeds, prohibiting all U.S. funds transmittals involving them. Mexico's banking regulator responded by installing government overseers; FinCEN twice extended the effective date (ultimately to September 4, 2025) citing "significant measures" by the Mexican government — illustrating how a §311-style action functions as diplomatic leverage as much as a laundering cutoff.

Note: Mexico's banking regulator responded by installing government overseers at the three institutions; FinCEN extended the orders' effective date twice (to September 4, 2025) citing "significant measures" by the Mexican government, illustrating how a §311-style action can function as diplomatic leverage as much as a laundering cutoff.

Laundering Mechanisms

Structuring (Smurfing)✓ SOURCE-VERIFIED

Illustrative scenarios transcribed from FIN-2009-A003. This advisory targets casino-sector collusion specifically; FinCEN's broader casino red-flags list lives in FIN-2008-G007 (see Casinos). Verified ≤2026-07 (see changelog)

TCOStructuring is the practice of breaking a large cash transaction into smaller deposits, each below the $10,000 Currency Transaction Report (CTR) threshold, to avoid triggering federal reporting. FinCEN's 2009 advisory responded to law-enforcement reports that casino personnel were colluding with patrons to structure chip purchases and cash-outs.

Mechanics

A single depositor — or a network of "smurfs" acting on one organizer's behalf — makes a series of deposits at or under the reporting threshold across multiple branches, accounts, or days. FinCEN's own $5,000 threshold applies for the SAR obligation on structured transactions (lower than the $10,000 CTR trigger being evaded).

Illustrative scenarios — as published in FIN-2009-A003

  • A premium player induces casino personnel to break up a transaction into multiple transactions to fall below the $10,000 CTR threshold
  • A patron persuades casino personnel to alter or omit transaction or identification information on casino records (e.g. a player rating record)
  • A cage cashier tells a player holding chips worth more than $10,000 that reducing the redemption amount to $10,000 or below will avoid reporting, and the player complies
  • A patron obtains a pit boss's help coordinating buy-ins around the casino's gaming-day cutoff, splitting cash transactions across different gaming days

Penalties: up to $25,000/day for an inadequate BSA compliance program (a separate violation each day it continues); up to the greater of the transaction amount (capped at $100,000) or $25,000 per reporting violation; and up to the full amount of currency involved for structuring itself or assisting in it.

Regulatory history

No.DateSubject
FIN-2009-A00307/01/2009Structuring by casino patrons and personnel
Laundering Mechanisms

Funnel Accounts✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2014-A005. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

TCODRGFinCEN's official definition: "An individual or business account in one geographic area that receives multiple cash deposits, often in amounts below the cash reporting threshold, and from which the funds are withdrawn in a different geographic area with little time elapsing between the deposits and withdrawals." FinCEN's 2014 update linked the pattern to Mexico-based drug trafficking proceeds moving north-to-south, following Mexico's 2010 restrictions on USD cash deposits at Mexican banks and exchange houses.

Mechanics

A colluding business owner opens an account at a bank or credit union with multi-state branch/shared-branching reach. Individuals acting for a criminal organization deposit narcotics cash at branches geographically distant from the account's home branch, each deposit kept below $10,000. An intermediary then wires or checks the funds to a U.S. or foreign business to purchase goods, which are shipped abroad and sold; the sale proceeds — now in local currency — flow back to the trafficking organization, laundered through TBML. A "peso broker" variant lets a cartel exchange U.S. cash for clean Mexican pesos entirely through apparently legitimate trade.

Red flags — as published in FIN-2014-A005

  • An account opened in one state (typically along the Southwest border) receives multiple cash deposits under $10,000 by unidentified persons at branches outside the account's home geographic region — individual or business accounts alike
  • For a business account, out-of-state deposits occur in a region where the business doesn't actually operate (e.g. a Southern California produce company's account receiving small cash deposits in Chicago, Indianapolis, and Minneapolis)
  • Individuals opening or depositing to the account show no detailed knowledge of the account holder, its stated business, or the source of the cash — consistent with criminal organizations paying students, itinerant workers, or the underemployed to conduct funnel transactions
  • Debits from a business account receiving out-of-state deposits don't match the stated business activity (e.g. a produce company's checks made payable to a leather-goods business, or wires to a Chinese textile manufacturer)
  • Checks issued from the account show different handwriting on the payee/amount lines than the signature line — suggesting pre-signed blank checks handed to a criminal organization to complete
  • Wire transfers or checks from the account are deposited into, or cleared through, a Mexican bank's U.S. correspondent account

Regulatory history

No.DateSubject
FIN-2014-A00505/28/2014Currency restrictions in Mexico — funnel accounts and TBML
Laundering Mechanisms

Informal Value Transfer Systems (Hawala)✓ SOURCE-VERIFIED

Definition and case examples transcribed from FIN-2010-A011 (updated 2022). Note: this advisory is a reminder/case-example bulletin — it reaffirms and points back to FinCEN's original March 2003 IVTS Advisory rather than restating a standalone red-flag list. Verified ≤2026-07 (see changelog)

TCOTFFinCEN's definition: IVTS is "any system, mechanism, or network of people that receives money for the purpose of making the funds or an equivalent value payable to a third party in another geographic location, whether or not in the same form," generally operating outside the conventional banking system. Hawala, hundi, and similar networks are IVTS variants. IVTS is a type of money transmitter (a Money Services Business) and must register and comply with AML program, recordkeeping, and reporting obligations like any other MSB; FinCEN notes continuing indications that IVTS has been used to help fund attempted terrorist attacks, including against the U.S.

Mechanics

A customer gives cash to a broker in one country; the broker instructs a counterpart broker elsewhere to pay the recipient in local currency, and the two brokers settle their mutual balance later, often through trade invoicing (overlapping with TBML).

Case examples — as published in FIN-2010-A011

  • Abad's Carnival French Ice Cream (Brooklyn) was convicted of operating as a money transmitter without a state license; $22.2 million in structured deposits (kept below reporting thresholds) were consolidated into a central U.S. account, then $21.9 million was wired to accounts in 25 other countries, where recipient IVTS operators converted the funds to local currency for distribution
  • Mauricio Alfanso Mazza-Alaluf was convicted of providing unlicensed IVTS services after physically carrying millions of dollars through LAX and depositing them in U.S. accounts to relay payments between Chilean businesses/individuals and U.S. customers

SAR filing instructions — as published in FIN-2010-A011

Check the appropriate SAR box for the suspicious activity type and note the abbreviation "IVTS" in the narrative, along with an explanation of why the institution knows, suspects, or has reason to suspect IVTS involvement.

Regulatory history

No.DateSubject
FIN-2010-A01109/01/2010Informal Value Transfer Systems (revised 07/05/2022)
Laundering Mechanisms

Bulk Cash Smuggling✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2025-Alert001. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

TCODRGBulk cash smuggling is the physical transport of large volumes of U.S. currency across borders — most prominently southbound into Mexico — to repatriate drug-trafficking proceeds outside the banking system entirely. FinCEN's 2025 alert tied this directly to Mexico-based cartels reacting to tightened Mexican banking restrictions on U.S. dollars.

Mechanics

Cash is concealed in vehicles, commercial cargo, or on couriers and moved across land borders or through ports, then reintroduced into the financial system abroad through complicit exchange houses or casas de cambio.

Red flags — as published in FIN-2025-Alert001

Ten indicators split between depository institutions and armored car services (ACSs) — the two points where this typology becomes visible.

For depository institutions (5)
  • Large cash volume delivered by an ACS on behalf of a customer operating a Mexico-based business, a business near the southwest border, or a U.S. company with an affiliated Mexican business — followed by rapid movement of funds to a Mexican institution, transfer to another business the customer owns, or a large goods purchase
  • Large cash volumes transported by ACS or passenger vehicle to a U.S. MSB along the southwest border and rapidly transferred to Mexico
  • A customer owning or affiliated with a Mexico-based business receiving a large credit from a U.S.-based ACS into their U.S. account
  • A customer receiving a large credit after depositing bulk cash into the institution's own vault space rented at an ACS secure storage facility
  • A customer owning a Mexico-based business receiving a large cross-border wire from a Canada-based institution
For armored car services (5)
  • A Mexican business near the border organizing transport of large cash volumes to multiple U.S. locations with no apparent lawful purpose before final delivery to a financial institution or Federal Reserve Bank
  • Reluctance or inconsistency in identifying the currency originator or destination in Part II of FinCEN Form 105 (CMIR)
  • A non-bank Mexican business organizing transport of USD volumes not commensurate with its size or business profile
  • A bulk cash shipment arriving from a Mexico- or Canada-based ACS without accompanying instructions or explanation, followed by a request to move it onward to a financial institution
  • A Mexican business or individual requesting bulk cash transport or acceptance without a clear explanation of source of funds

Regulatory history

FIN-2025-Alert001 — Bulk Cash Smuggling and Repatriation by Mexico-Based TCOs
Issued March 31, 2025 · Full PDF

Verified against the primary document: the smuggle-south/repatriate-north cycle via complicit Mexican businesses and armored car services matches the FinCEN alert.

The full cycle, which is the point: this isn't simply cash leaving the U.S. — it's a round trip. Cash is smuggled south into Mexico, delivered to complicit border-area businesses (some operating, some shells), then repatriated northward under the guise of legitimate Mexican businesses depositing USD in the United States. Currency declarations get presented as proof of import/export profits. That laundering-by-re-importation structure is what distinguishes this alert from generic cash-smuggling guidance.

Outbound methods: concealed on a person, in private vehicles, or commercial tractor-trailers, moved by cash couriers, "financial supply chain specialists," or Cartel-employed currency handlers. U.S. law enforcement estimates smuggled cash could average at least hundreds of thousands of USD daily. A rising trend: TCOs establishing shell companies to purchase and register private aircraft in order to circumvent certain U.S. aviation regulations.

Three repatriation routes: (1) air from Mexico to the U.S., where a U.S. ACS retrieves currency post-CBP inspection and delivers it to an MSB, bank, credit union, or directly to a Federal Reserve Bank; (2) land across the southwest border, sometimes with a Mexican ACS delivering directly to a U.S. institution — and FinCEN notes some Mexican and U.S. ACSs share ownership; (3) the Canada route — flown from Mexico to Canada, retrieved by a Canadian ACS, driven south across the northern border, or deposited in a Canadian institution and wired to the U.S.

Two credit mechanisms worth knowing: some ACSs "purchase" bulk cash from the customer and credit their U.S. bank account for the value rather than physically delivering it. Separately, smaller U.S. institutions may rent vault space at an ACS storage facility, letting a customer's cash be transported there and the account credited via the ACS — cash that never touches the bank's own premises.

Critical CMIR caveat: FinCEN states plainly that institutions "should not conflate the presentation of a CMIR as an indication that the source of the funds is legitimate; the obligation to declare bulk cash entering the United States is not a justification of its origins." A filed declaration is not diligence.

Regulatory status of ACSs: ACSs and common carriers of currency must generally report cross-border physical transport exceeding $10,000, and may themselves be engaged in money transmission requiring MSB registration and full BSA compliance.

SAR filing instruction: key term in SAR field 2 and the narrative; select SAR field 36(z) (Money Laundering – Other) with "BULKCASH" in the text box.

SAR key term: FIN-2025-BULKCASH · Field 36(z) "BULKCASH"
Enforcement companion — Brink's Global Services USA
Consent order February 6, 2025 · cited directly in the alert

FinCEN assessed a civil money penalty for willful BSA violations, and the alert states the consent order "details similar behavior as described in this Alert" — including transmission of hundreds of millions of dollars in bulk currency shipments across the southwest border on behalf of high-risk entities, among them a Mexican currency exchanger that later pleaded guilty to violating the BSA. One of the alert's red flags cites the consent order directly. See FinCEN Enforcement Actions Index.

Southwest Border Geographic Targeting Order
Issued March 11, 2025, three weeks before the alert

A GTO targeting cartel money laundering along the southwest border. Treasury's National Money Laundering Risk Assessment has identified the southwest border as an area of significant bulk cash smuggling risk every year since 2015.

Laundering Mechanisms

Fentanyl Precursor Chemicals & Manufacturing Equipment ✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2024-A002. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

DRGTCOSHELLMSBCVCThe financial layer of the illicit fentanyl supply chain. Mexico-based TCOs — principally the Sinaloa Cartel and CJNG — buy precursor chemicals, pill presses, and die molds primarily from PRC-based suppliers, synthesise fentanyl in clandestine Mexican labs, and traffic it north. FinCEN's framing of why banks matter here is unusually direct: BSA reporting lets law enforcement "follow the money behind the illicit fentanyl supply chain… and ultimately aid in the effort to save American lives."

The supply-chain shift that created this typology

Before 2019, complicit PRC-based chemical and pharmaceutical companies shipped finished fentanyl directly to U.S. buyers or to Mexican networks. After the PRC scheduled all fentanyl-related substances as a class in May 2019, that direct trade fell sharply — and the market restructured around precursors instead. Mexico-based TCOs became the predominant traffickers, buying inputs rather than product. Many current PRC suppliers are the same firms that previously made fentanyl itself.

Mechanics

Procurement. TCOs buy direct from PRC suppliers or through chemical brokers — middlemen based in Mexico, the PRC, or elsewhere who represent multiple suppliers and multiple cartels, and whose function is precisely to obscure the diversion. Suppliers and brokers advertise openly in English on company websites, e-commerce marketplaces, social media, and the darknet, marketing precursors by CAS number for easy reference. Listings may tout "exit and entry customs clearance" — which FinCEN identifies as a euphemism for mislabelling shipments to evade customs and law enforcement.

Payment. Negotiated by email, phone, text, or encrypted messaging; paid in single or multiple transactions from Mexico or the U.S., often structured across multiple senders and beneficiaries. FinCEN makes an important point about scale: these payments are frequently low-dollar — but they convert into very large trafficking proceeds downstream. A monitoring programme calibrated only to large transfers will miss this entirely.

Three financial channels: shell and front companies posing as legitimate Chinese exporters or Mexican importers (and sometimes as textiles, food, or electronics businesses); money transfers through banks, MSBs, and online payment processors — much of it cleared in U.S. dollars through U.S. correspondent banks and U.S.-affiliated agents even when neither party is American; and virtual currency, increasingly, in bitcoin, ether, monero, and tether to supplier-affiliated wallets or secondary transmitters.

Red flags — as published in FIN-2024-A002

Fourteen indicators, in addition to those in the 2019 Fentanyl Advisory, which FinCEN states all remain relevant.

Customer and counterparty profile
  • A customer or counterparty with previous drug-related convictions, or open-source reporting indicating connections to clandestine lab operations
  • A chemical or pharmaceutical company in the PRC, Hong Kong, or elsewhere with a residential address, an address shared with similar businesses, or no physical presence — or other shell company indicators
  • A counterparty with no apparent PRC affiliation using a PRC-based phone number or IP address tied to a Chinese chemical or pharmaceutical company's website
  • A customer or counterparty vending on an e-commerce or darknet marketplace advertising precursors by chemical name, abbreviation, or CAS number
  • A Mexican company importing precursors and equipment without the appropriate Mexican import licences and registrations, per open-source or commercial reporting
  • A Mexican company with little or no online presence importing the same precursors and equipment used in fentanyl synthesis
  • Multiple seemingly unrelated Mexican importers sharing phone numbers, email addresses, or physical addresses while transacting with the same PRC chemical companies
  • A Mexican importer transacting predominantly or only with PRC or Hong Kong chemical/pharmaceutical companies, where comparable importers use suppliers across multiple jurisdictions
Transactional
  • Low-dollar or virtual currency payments with no apparent legitimate purpose to beneficiaries in the PRC/Hong Kong chemical or pharmaceutical industries
  • Many-to-one: multiple customers sending funds with no apparent legitimate purpose to the same such beneficiary
  • A Mexico-based entity from an unrelated industry transacting with a PRC chemical or pharmaceutical company — or the reverse
  • Behaviour suggesting CTR evasion: altering or cancelling a transaction when told of the filing requirement, or structuring multiple cash transactions under $10,000, plus avoiding recordkeeping requirements
  • Virtual currency sent to an address linked by blockchain analytics to PRC chemical-industry beneficiaries or to individuals and entities named in DOJ indictments or OFAC designations
  • A Mexican company with no apparent involvement in chemicals or pharmaceuticals whose transaction activity nonetheless indicates precursor and equipment procurement

Regulatory history

FIN-2024-A002 — Supplemental Advisory on Precursor Chemicals and Manufacturing Equipment
Issued June 20, 2024 · Full PDF · Issued under §3202(a) of the FEND Off Fentanyl Act

Verified against the primary document: CDC overdose figures (107,000/74,000) and DEA seizure figures (80M pills, 12,000 lbs, 381M lethal doses) match exactly.

Human scale: per CDC provisional data, over 107,000 Americans died of drug overdoses in the 12 months ending December 2023, with over 74,000 involving synthetic opioids, principally illicit fentanyl. Many were poisonings — victims unaware their drugs or counterfeit pills contained lethal doses. In 2023 the DEA seized over 80 million fentanyl-laced counterfeit pills and 12,000 pounds of powder, equating to more than 381 million lethal doses.

Enforcement backdrop: under E.O. 14059, OFAC has sanctioned over 290 foreign nationals and entities across the supply chain — PRC suppliers, chemical brokers, Mexican manufacturers and traffickers, and the money launderers sustaining it.

Adaptation warning: FinCEN closes with an explicit caution that TCOs and suppliers "have demonstrated an ability to adapt rapidly" to regulatory and enforcement changes, and may leverage global networks to evade new restrictions — producing unanticipated shifts in the supply chain. The indicators here should be read as a snapshot, not a fixed profile.

Cyber detail requested: email addresses, IP addresses with timestamps, login information with location and timestamps, virtual currency addresses, mobile device identifiers including IMEI numbers, and descriptions and timing of suspicious electronic communications.

SAR filing instruction: key term in SAR field 2 and the narrative. For Form 8300, select Box 1b and include the key term in Comments.

SAR key term: FENTANYL FIN-2024-A002
FIN-2019-A006 — Illicit Financial Schemes Related to Fentanyl Trafficking
Issued August 21, 2019 · remains fully operative

The original fentanyl advisory, covering the pre-2019 model in which PRC suppliers shipped finished product directly to U.S. buyers. FinCEN states its typologies and red flags "all remain relevant" and that the 2024 advisory supplements rather than replaces them.

Financial Trend Analysis — Fentanyl-Related Illicit Finance, 2024
Issued April 9, 2025 · under AMLA §6206

Quantifies the pattern. Notes cartel financial footprints concentrated in Sinaloa and Jalisco, and documents an evolution the advisory anticipated: one filer identified a Mexico-based company that had previously paid PRC precursor suppliers directly, then began routing payments through a U.S.-based company owned by a Chinese national as an intermediary. Also flags Canada-based precursor and lab-equipment purchasing, primarily British Columbia and Ontario.

Laundering Mechanisms

Real Estate as a Laundering Vehicle✓ SOURCE-VERIFIED

Suspicious-transaction factors and case studies transcribed from FIN-2017-A003. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

CORTCOREReal property — especially luxury residential real estate purchased through legal entities — offers a stable store of value with historically thin beneficial-ownership disclosure. Real estate appreciates in value, "cleans" large sums in a single transaction, and shields gains from market instability and exchange-rate fluctuations. FinCEN's 2017 advisory extended SAR-filing expectations directly to real estate firms and professionals (who are BSA-defined financial institutions but exempted from mandatory program requirements), and later alerts named sanctioned Russian elites as specific purchasers of concern.

Mechanics

An all-cash purchase — nearly one in four residential sales nationally, roughly half in Miami-Dade circa 2015–16 — is made through an LLC, trust, or other opaque entity, severing the direct link between the beneficial owner and the property and avoiding the AML scrutiny that accompanies mortgage financing. FinCEN's GTOs (2016–17) required title insurers to report beneficial ownership on non-financed high-value residential purchases in seven major metro areas; as of May 2017, over 30% of GTO-reported transactions involved a beneficial owner or purchaser's representative previously named in an unrelated SAR.

Case studies — as published in FIN-2017-A003

  • DOJ sought forfeiture of $1B+ in assets tied to the 1MDB Malaysian sovereign-wealth-fund theft, including ~$315M in luxury real estate (a hotel, homes, and a mansion in Beverly Hills; a home in LA; a condo, two apartments, and a penthouse in NYC; a London townhouse)
  • OFAC designated then-Venezuelan VP Tareck El Aissami and frontman Samark Lopez Bello for narcotics trafficking, along with shell companies tied to Lopez Bello used to hold real estate
  • Real estate agent Anthony Keslinke used straw buyers and altered records to buy Northern California real estate with cash (2011–2014), then resold at a gain — jailed and ordered to forfeit $3.8M plus $1.4M in restitution

Suspicious-transaction factors — as published in FIN-2017-A003

  • The transaction lacks economic sense or an apparent lawful business purpose — generates little to no revenue, or proceeds with no regard to high fees or monetary penalties
  • The purchase disregards the property's condition, location, assessed value, or sale price
  • Funding far exceeds the purchaser's apparent wealth, comes from an unknown origin, or flows to/from unrelated individuals or companies
  • The transaction is deliberately irregular — e.g. property purchased under an unrelated party's name, or records such as assessed value altered

SAR filing instruction

Key term "ADVISORY REAL ESTATE" in the SAR narrative and field 33(z) (Money Laundering – Other). Real estate professionals (brokers, escrow agents, title insurers) are not required to file but are encouraged to do so voluntarily and receive the same safe-harbor protection as mandatory filers.

Regulatory history

No.DateSubject
FIN-2017-A00308/22/2017Advisory to financial institutions and real estate firms/professionals
FIN-2023-Alert00201/25/2023Sanctioned Russian elites — U.S. commercial real estate
FTA03/30/2023Business Email Compromise in the Real Estate Sector
See alsoCorruption & Kleptocracy · Business Email Compromise (title/escrow wire fraud)
Laundering Mechanisms

Correspondent Banking & Nested Accounts✓ SOURCE-VERIFIED

Statutory/regulatory detail transcribed from the Section 312 Fact Sheet and FFIEC BSA/AML Manual. Note: FIN-2008-G001's actual scope is narrower than the article topic — it interprets whether presenting a negotiable instrument for payment to a foreign bank creates a "correspondent account"; it is cited here for completeness but is not itself a nested-accounts red-flag source. Verified ≤2026-07 (see changelog)

TCOCORCorrespondent banking lets a U.S. bank process transactions on behalf of a foreign bank that lacks direct access to the U.S. financial system. "Nested" (downstream) correspondent banking occurs when that foreign respondent bank, in turn, provides its own downstream customers — including other banks — access to the U.S. correspondent account without the U.S. bank ever knowing those downstream customers exist. Section 312 of the USA PATRIOT Act built enhanced due diligence (EDD) requirements around exactly this risk.

When EDD is statutorily required — per the Section 312 Fact Sheet

Section 312 requires enhanced due diligence for a correspondent account maintained for a foreign bank operating: (1) under an offshore license; (2) in a jurisdiction found non-cooperative with international AML principles; or (3) in a jurisdiction designated of primary money-laundering concern under §311. For such accounts, the U.S. institution must take reasonable steps to (1) conduct appropriate enhanced scrutiny, (2) determine whether the foreign bank itself offers correspondent accounts to other foreign banks — i.e. nested accounts — and identify and conduct additional due diligence on those downstream customers as appropriate, and (3) identify the owners of the foreign bank if its shares aren't publicly traded.

Mechanics

A U.S. bank opens a correspondent account for Foreign Bank A. Foreign Bank A then allows Foreign Banks B, C, and D — or even individual high-risk customers — to transact through that same account by "nesting" underneath it. The U.S. bank's due diligence covers Bank A, but has no visibility into who is actually moving money, defeating the purpose of screening and monitoring.

Regulatory history

No.DateSubject
Section 312 Fact Sheet12/2005Enhanced due diligence for foreign correspondent accounts, including identification of nested relationships
FIN-2008-G00101/30/2008Application of correspondent account rules to presentment of negotiable instruments
Laundering Mechanisms

Chinese Money Laundering Networks (CMLNs)✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2025-A003. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

TCODRGTreasury's 2026 National Money Laundering Risk Assessment (NMLRA) names CMLNs as "the dominant" professional money laundering service providers for drug trafficking organizations and other TCOs worldwide — not just a Mexico-cartel-specific tool but the leading horizontal, decentralized laundering infrastructure globally. CMLNs are "professional money launderers" (PMLs): third parties who launder for a fee rather than perpetrating the underlying crime themselves, drawing on sustained demand among PRC nationals for informal channels to move capital out of China.

Mechanics

CMLNs collect bulk cash from U.S.-based drug sales (often through funnel accounts), using U.S.-based Chinese nationals — sometimes unwittingly — to deposit cash of unknown origin into the U.S. financial system. They settle balances via mirror transfers, underground remittance, and trade-based money laundering, avoiding cross-border cash movement entirely, then repatriate value to China or launder it further through digital assets. Some networks operate CVC exchanges and marketplaces directly, blending traditional and crypto laundering rails.

Red flags — as published in FIN-2025-A003

FinCEN splits its indicators into two sets. Its standard caveat applies with unusual force here: many of these reference Chinese nationality or a Chinese passport, and FinCEN is explicit that no single red flag is determinative — surrounding facts, historical activity, prevailing business practice, and whether multiple flags co-occur all matter before concluding activity is suspicious.

Indicators of CMLN-affiliated money mules (9)
  • A customer — especially one who presented a Chinese passport at onboarding — regularly receives funds not commensurate with reported occupation or income, where the source can't be attributed to payroll or other legitimate income (unexplained wealth)
  • At onboarding, a customer presents a Chinese passport and a visa bearing the same photograph despite being issued years apart — an indicator of counterfeit Chinese passport use
  • A customer reporting their occupation as student then regularly deposits cash or receives wires notated "tuition" or "living expenses" inconsistent with that profile, and subsequently sends wires or P2P transfers to unknown individuals unrelated to the stated purpose, or makes credit/debit card payments
  • A customer reporting occupation as student, retiree, housewife, or another low-income occupation, but showing unexplained wealth
  • A customer with unexplained wealth initiates a wire for a real estate purchase or buys cashier's checks payable to a real estate company — sometimes accompanied by a real estate agent while purchasing the cashier's checks
  • Regular large-volume cash or cashier's check deposits, or multiple wire/ACH/P2P transfers with no business or apparent lawful purpose, followed by cashier's check purchase or dispersal to others via P2P and wire, often to high-risk jurisdictions
  • An account receiving numerous transfers or deposits with a significant number of withdrawals or transfers, none appearing related to routine payroll, living expenses, or stated expected activity
  • Large amounts of cash funding cashier's checks that are then deposited at a different financial institution
  • Reluctance or refusal to explain source of funds, or evasiveness when questioned about a transaction's purpose — sometimes explained as "repayment of a loan"
  • A U.S.-based escrow company receiving funds from an unaffiliated foreign shell company in a disparate line of business, used to purchase U.S. real estate
Indicators of CMLN-affiliated TBML schemes (8)
  • A business owned by a Chinese national regularly receives deposits from online marketplaces but rarely or never transacts to purchase inventory
  • A business owned by a Chinese national regularly receives wires indicating export of goods to Mexico, China, Hong Kong, or the UAE, but rarely or never purchases inventory
  • A small U.S. business in the electronics or real estate industry receives wires from Mexico, China, Hong Kong, or the UAE with no known nexus to those countries
  • A customer regularly receives P2P or wire transfers from unknown individuals then uses the funds for a substantial credit card payment — if questioned, may claim the transfers are from U.S.-based family of Chinese citizens sending money to buy goods
  • A customer regularly uses a credit card to purchase large volumes of electronics or luxury goods
  • A business selling electronics or luxury goods has income not commensurate with its size and scale
  • A business selling electronics or luxury goods makes payments on multiple credit cards belonging to various individuals seemingly unrelated to the business
  • Hong Kong-registered trading companies with shell-like characteristics sending funds to U.S.-resident Chinese nationals, real estate escrow or title insurance companies, and other international destinations with no apparent business or economic purpose

Per BSA reporting cited in the advisory, CMLN-linked businesses commonly appear in shipping, transportation, freight, logistics, industrial supplies, food, and technology sectors.

Regulatory history

FIN-2025-A003 — Use of Chinese Money Laundering Networks by Mexico-Based TCOs
Issued August 28, 2025 · Full PDF · Names CJNG, Sinaloa Cartel, and Gulf Cartel

Verified against the primary document: cartel names (CJNG, Sinaloa, Gulf) and the pricing/currency-control mechanics below match the FinCEN advisory. Companion Financial Trend Analysis (Aug. 28, 2025) puts the aggregate scale at $312 billion in suspicious CMLN-linked transactions across 137,153 SARs, Jan. 2020–Dec. 2024.

Why CMLNs win cartel business: speed, effectiveness, and a willingness to absorb financial losses and assume risk for clients. FinCEN notes CMLNs undercut other professional money launderers on price because most of their revenue doesn't come from the cartel fee at all — it comes from reselling the illicit USD to Chinese citizens at a high rate.

The two-sided driver: Mexico's 2010 currency restrictions (revised 2014) cap USD deposits at roughly $4,000/month for individuals and $14,000/month for border/tourist-area businesses, blocking cartel repatriation. Meanwhile the PRC caps citizens at roughly $50,000/year in currency conversion and bars direct RMB transfers abroad without SAFE approval. The result is a mutualistic market: cartels need to shed USD, Chinese citizens need to acquire it.

Mirror transactions: a U.S. CMLN receives cartel USD; a Mexico-based counterpart transfers equivalent pesos to cartel accounts minus a fee — near-instant, with no cross-border cash movement. The U.S. side then advertises the USD on social media or through personal networks to Chinese buyers, who transfer RMB internal to China to a China-based operator. CVC is used as an alternative mirror rail. FinCEN notes what beneficiaries are told versus what actually happens: customers say they paid a service to move money out of China, but the CMLN keeps their funds in China and pays them with laundered illicit funds in the U.S.

Recruitment: CMLNs increasingly recruit Chinese students at U.S. universities — targeted specifically because student visas restrict lawful employment — with some continuing after graduation. FinCEN notes many recruits may not understand their actions are illegal. CMLNs also supply counterfeit Chinese passports and, per DHS testimony, recruit financial institution employees as complicit insiders or place their own members inside institutions (see Complicit Insiders).

The daigou channel: "buying on behalf of" — witting or unwitting straw buyers, often current or former Chinese nationals in the U.S., given cash or a P2P transfer and instructed to purchase goods and ship them to China or to a U.S.-based daigou operator who exports onward.

Scope beyond cartels: CMLNs also launder proceeds of marijuana trafficking, human trafficking, and fraud, and engage in health care fraud and illicit gaming themselves. They coordinate with other professional launderers including shadow banking networks and Colombian peso brokers.

SAR filing instruction: include the key term in SAR field 2 and the narrative, and select SAR field 38(n) (Suspicious Use of Informal Value Transfer System), 38(s) (Unlicensed or Unregistered MSB), and 36(l) (Trade Based Money Laundering/Black Market Peso Exchange), plus any other applicable box.

SAR key term: CMLN-2025-A003 · Fields 38(n), 38(s), 36(l)
Financial Trend Analysis — Chinese Money Laundering Networks, 2020–2024
Issued August 28, 2025, alongside the advisory

Analyzed 137,153 SARs filed January 2020 – December 2024 describing suspected CMLN activity, totaling approximately $312 billion in suspicious transactions. Supplies the underlying data on student-mule recruitment, real estate purchases, and the daigou channel that the advisory summarizes.

Huione Group — Section 311 Final Rule and successor-entity amendment
Final rule October 15, 2025 · NPRM extending to H-Pay Service PLC June 23, 2026 · comment period extended July 22, 2026

Section 311 special measure severing the Cambodia-based Huione Group from the U.S. financial system for laundering $4B+ between August 2021 and January 2025, including DPRK cyber-heist and pig-butchering proceeds. When Huione attempted to route around the order via a rebranded entity, FinCEN proposed extending the severance to cover "any successor entity" — a demonstration of the cat-and-mouse dynamic in sanctions-style financial designations.

FEND Off Fentanyl Act Orders — three Mexican financial institutions
Issued June 25, 2025 · first-ever use of the "sixth special measure"

Orders finding CIBanco, Intercam Banco, and Vector Casa de Bolsa of primary money laundering concern for facilitating cartel fentanyl proceeds. Referenced in the CMLN advisory's own framing of Treasury's multi-pronged enforcement approach. See TBML for detail.

Laundering Mechanisms

Fiscal Fuel Theft (Huachicol Fiscal) HIGH RISK✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2026-Alert003. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

TCODRGTFFRDCORSHELLFuel smuggled from the U.S. into Mexico without paying Mexican import tax, then sold on the black market. FinCEN states that fiscal fuel theft and traditional fuel/oil theft together have become the most significant non-drug illicit revenue source for the Cartels — public reporting estimates a quarter to a third of all fuel sold in Mexico may be illicit. This typology carries an unusually broad priority tag set because CJNG and other cartels are now designated Foreign Terrorist Organizations, so material support exposure attaches.

Why the arbitrage exists

Mexico produces crude but can't refine enough of its own sour, heavy crude — it imports nearly 2 million barrels/day of refined fuel, over 70% of national consumption. Those imports carry a substantial excise tax (IEPS), making Mexican fuel far more expensive than U.S. fuel. A 2013 reform split permitting in two: SENER permits allow importing fuel but not selling it inside Mexico; CNE permits allow buying and selling inside Mexico but not importing. Companies generally hold one, not both. After 2019 rescinded and restricted many permits to prioritize Pemex, supply tightened and actors concentrated — producing exactly the price gap and bottleneck a black market fills.

Mechanics

Cartels use Mexican brokers holding CNE permits (not SENER) to buy fuel directly from complicit U.S. fuel traders — which is itself unlawful under Mexican law and is the structural tell. Those U.S. traders are typically otherwise-legitimate Texas companies with longstanding refinery relationships, concentrated around Houston, San Antonio, South Texas, and the Lower Rio Grande Valley. Fuel bought at a U.S. terminal for export is diverted through networks of U.S. and Mexican front and shell companies in oil/gas, freight, and logistics, then moved by tanker truck, railcar, and sometimes shadow-fleet vessels into Tamaulipas, Nuevo León, and Coahuila. Customs documents misclassify it as "waste oils," "lubricants," "additives," "petroleum residues," or "hazardous waste" — categories not subject to the import tax — aided by bribed customs and tax officials, or the fuel is concealed in nonstandard containers entirely.

Inside Mexico, brokers generate fraudulent invoices claiming purchase from SENER-permitted importers to launder the fuel's provenance, then sell to cartel-controlled front distributors who retail it through affiliated gas stations and unregulated roadside stops (cachimbas) — sometimes forcing legitimate distributors to buy under threat of violence.

Payment back to the U.S. runs through international wires and digital asset payments — particularly stablecoins — from Mexican brokers to complicit U.S. traders, often as many large non-descriptive payments per day, sometimes routed through pass-through shell companies in unrelated sectors or registered to residential addresses. Alternatively cartels pay U.S. traders directly via structured cash deposits of drug proceeds at border-area branches, a TBML variant. U.S. traders then launder receipts into luxury goods, real estate, and investment assets.

The corruption loop: FinCEN reports cartels use fuel profits to make cash payments to Mexican political campaigns and media outlets to elect officials who protect the trade, then use those officials to control administrative posts and access state contracts for further laundering.

Red flags — as published in FIN-2026-Alert003

Twenty-two indicators, building on (not replacing) the May 2025 Cartel Oil Smuggling Alert. FinCEN singles out one as the highest-value screen: assess whether oil and gas customers are receiving payments directly from Mexican companies without SENER permits — not customary practice in the legitimate trade, and therefore highly indicative. FinCEN suggests requesting export documentation and counterparty SENER-permit documentation, which may be attached to SAR filings.

Counterparty permit status and known links
  • A U.S. oil/gas company receiving wire transfers for fuel purchases from a Mexico-based company without a SENER permit
  • A U.S. oil/gas company receiving wires from a Mexico-based company with a CNE permit
  • A U.S. oil/gas company receiving multiple wire transfers per day from a single Mexico-based company
  • A U.S. company (or its nominal/beneficial owners) connected to huachicol activity per U.S. or Mexican media reporting
  • A U.S. oil/gas, freight, or logistics company transacting with Mexican companies linked to huachicol activity per open-source reporting, indictments, or OFAC designations
Business profile inconsistencies
  • A small U.S. border-state oil/gas, freight, or logistics company with transactional activity and profit margins exceeding the typical profile for its industry
  • Significant operations at ports of entry despite those areas being subject to bridge closures per Mexican media reporting
  • A U.S. company operating in Mexico with no Mexican subsidiary (e.g., ABC Fuel without ABC Fuel S.A. de C.V.)
  • A U.S. or Mexican oil/gas, freight, or logistics company with little to no business expenses, operations, or online presence
  • Registered to a residential address
  • Significant transactional activity but no apparent infrastructure to store or transport fuel
  • A recently established U.S. LLC or sole proprietorship in these industries sharing a name with a Mexican company, sending large same-day wires to U.S. refineries and later receiving commensurate wires from Mexican companies
  • The same name-sharing profile combined with margins exceeding industry norms
Payment flow patterns
  • Large same-day wire volume to a major U.S. distributor or refinery for export to Mexico, later matched by commensurate wires from a non-SENER Mexican company or small recently established U.S. companies
  • Receiving wires from U.S. or Mexican companies registered to a residential address
  • Receiving significant wire volume from companies in unrelated industries
  • Receiving significant wire volume from Mexico then immediately transferring to U.S. oil/gas companies — acting as a pass-through account
  • Receiving significant wire volume from Mexico but transacting with only one or a small number of U.S. companies
  • Receiving significant wire volume from Mexico with little to no memo-line information
  • Receiving digital asset payments from Mexican companies where similar energy transactions would normally run through fiat wires and standard trade finance
  • A U.S. oil/gas company receiving cash deposits
  • A border-state oil/gas company with outgoing transactions to companies with no industry nexus — luxury goods (high-end vehicles, jewelry, exclusive travel), investment management, or residential real estate

Regulatory history

FIN-2026-Alert003 — Supplemental Alert on Fuel Smuggling and Tax Evasion Schemes
Issued June 30, 2026 · Full PDF · Issued alongside an OFAC sanctions action

Measured impact of the predecessor alert: in the 12 months after the May 2025 Cartel Oil Smuggling Alert, financial institutions reported over $7 billion in suspicious activity across 160+ SARs, and federal law enforcement observed a significant decrease in northbound illicit Mexican crude smuggling — one of the few places FinCEN quantifies an advisory's effect.

Paired OFAC action: designation of Oscar Guillermo Juraidini Silva — an accountant described as the mastermind behind certain CJNG financial operations, who created and operated shell companies and falsified customs documents, with gas station companies as his main clients, generating tens of millions annually — plus J. Refugio Ruiz Villagomez and entities Jomadi Logistics and Ahavat Logistics, which transacted tens of millions through the U.S. financial system with CJNG-linked parties.

Explicit anti-de-risking caveat: FinCEN states these risks "should not be used as the basis for wholesale or indiscriminate de-risking of customers involved in the U.S. and Mexican oil and natural gas, freight, and logistics industries," citing the 2022 interagency joint statement on risk-based CDD.

SAR filing instruction: key term in SAR field 2 and the narrative. For Form 8300, select Box 1b ("suspicious transaction") and include the key term in the Comments section.

SAR key term: FIN-2026-FISCALFUELTHEFT

The predecessor scheme: northbound crude smuggling — FIN-2025-Alert002

The May 2025 alert addresses the mirror image of fiscal fuel theft: crude flowing north. Mexico can't refine enough of its own sour, heavy crude, so it exports unrefined crude to higher-capacity U.S. refineries and imports refined fuel back. Cartels exploit that legitimate flow by stealing crude from Pemex — bribing employees and officials, drilling illegal pipeline taps, hijacking tanker trucks — and smuggling it north through Mexican brokers, mislabelled as "waste oil" or other hazardous materials, to complicit small U.S. importers who sell it at a steep discount as WTI and other crude.

Once across, the crude goes to vacant lots fitted with mobile storage tanks before delivery to the importer. Trade documentation lists U.S. companies as importers and ultimate consignees to make the "waste oil" import look legitimate — some of those supposed consignees are registered to residential addresses. Law enforcement estimates U.S. importers can clear over $5 million profit per tanker shipment, with multiple tankers monthly. Proceeds return to Mexico via wires whose instructions falsely reference invoices for waste oil or hazardous materials.

Red flags: northbound crude smuggling — as published in FIN-2025-Alert002

Fourteen indicators. FinCEN's anti-de-risking caveat applies here too: "no customer type presents a single level of uniform risk" and these should not justify wholesale de-risking of the oil, gas, or freight industries.

Business profile and pricing
  • A small U.S. oil/gas, importing, or freight company in a southwest border state with transactional activity and profit margins exceeding the typical profile for its industry
  • A small U.S. oil/gas company selling WTI and other crude significantly below market rate
  • A small U.S. oil/gas company selling millions of dollars of crude monthly but with no online presence — or a basic website designed to closely resemble a major U.S. oil company's to make the sales appear legitimate
The "waste oil" contradiction — the core detection logic
  • A company whose website says it only buys or sells crude, yet it is wiring Mexican or U.S. companies for purported waste oil or hazardous materials
  • Sudden purchases of waste oil or hazardous materials from a single or small number of Mexican and U.S. companies
  • Wiring for waste oil or hazardous materials without holding the appropriate EPA registrations — FinCEN points institutions to the EPA's ECHO search tool to verify
  • Wiring for waste oil or hazardous materials to companies that don't appear related to the oil and gas industry at all
  • Receiving domestic and international wires for invoices on crude oil sales while sending wires for invoices on waste oil purchases — the two halves of the same laundering leg
Counterparty and consignee structure
  • Sudden significant transaction volume with one or a few Mexican or U.S. companies with little to no online presence and other shell company indicators
  • A U.S. importing company receiving wires from U.S. oil/gas companies and wiring Mexican companies for waste oil purchases despite lacking EPA registration
  • A U.S. importing company receiving wires from a small U.S. oil/gas company for waste oil, then wiring those funds to a single or small number of Mexican companies
  • A purported U.S. waste-oil importer that on review appears to be a shell company of a Mexican company
  • A U.S. company listed as ultimate consignee for waste oil purchases but registered to a residential address
  • A small U.S. oil/gas, importing, or freight company on the border transacting with Mexican and U.S. companies or beneficial owners linked to Cartel activity per open-source reporting, indictments, or OFAC designations
FIN-2025-Alert002 — Oil Smuggling Schemes on the U.S. Southwest Border
Issued May 1, 2025 · Full PDF · with OFAC, DEA, FBI, HSI · Spanish translation June 2025

Verified against the primary document: interagency coordination, Pemex sourcing, and CJNG/Sinaloa/Gulf Cartel involvement match the FinCEN alert.

Geography of the complicit importers: Lower Rio Grande Valley, Eagle Ford Shale in South Texas, the Permian Basin in West Texas and southeastern New Mexico, plus Houston and Dallas. FinCEN notes the banking institutions involved include small, mid-size, and large banks and credit unions — especially those specialising in oil and gas services and holding correspondent relationships in Mexico.

Front vs. shell, as FinCEN defines them here: front companies are fully functioning businesses, often with a physical location, used to commingle illicit proceeds with legitimate earnings; shell companies have no physical presence beyond a mailing address and generate little independent economic value.

Case study — Cesar Morfin Morfin ("Primito"): CJNG cell leader for Tamaulipas, designated May 1, 2025. Notable detail: he controls port-of-entry bridges between Tamaulipas and Texas and charges fees on any truck moving crude across them. His subordinates falsify customs documents and operate front companies, some used to sell stolen fuel to retail gas stations. Two brothers and two hazardous-materials transport companies were designated alongside him.

Cross-border information sharing: FinCEN encourages institutions to use and expand processes for sharing with foreign financial institutions, and clarifies an important point — sharing underlying account or transaction information does not violate SAR confidentiality unless it would reveal the existence of a SAR itself.

SAR filing instruction: key term in field 2 and the narrative. FinCEN encourages voluntary SARs below the monetary threshold, noting any filing including a voluntary one carries liability protection. Form 8300: Box 1b plus key term in Comments.

SAR key term: FIN-2025-OILSMUGGLING
Fraud Typologies

Elder Financial Exploitation✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2022-A002. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

FRDElder financial exploitation covers the illegal or improper use of an older adult's funds or assets, by a trusted caregiver, family member, or an outside scammer. FinCEN first issued SAR-filing guidance on this in 2011 and refreshed it substantially in 2022 as reported incidents and dollar losses climbed.

Mechanics

Two broad patterns recur: exploitation by someone in a position of trust (a caregiver or family member gradually draining accounts or misusing a power of attorney), and scams by outside actors (romance scams — see Romance & Investment Scams — grandparent scams, and government-imposter schemes) that persuade a victim to send money directly, typically routed onward through money mules.

Red flags — as published in FIN-2022-A002

FinCEN publishes twelve behavioral and twelve financial indicators, building on (not replacing) the 2011 advisory's list. FinCEN's caveat: no single red flag is determinative — weigh historical activity, prevailing business practice, and whether multiple flags co-occur. Note that victims may be perpetrators' unwitting money mules, and a customer may be a perpetrator, facilitator, or victim.

Behavioral red flags (12)

Critical because for isolated older adults, a branch, check-cashing counter, or MSB visit may be their only outside contact. FinCEN specifically asks that behavioral flags and the names of staff who witnessed them be recorded in the SAR narrative.

  • Sudden, unusual changes in contact information, or new connections to emails, phone numbers, or accounts that may originate overseas
  • An older customer with known physical, emotional, or cognitive impairment shows unexplainable or unusual account activity
  • The customer appears distressed, submissive, fearful, anxious to follow others' directions about their accounts, or unable to answer basic questions about their own account activity
  • The customer mentions an online friend or romantic partner asking them to receive and forward money, or to open an account for a "business opportunity" (a money mule recruitment pattern)
  • During a transaction the customer appears to be taking direction from someone on a cell phone, and seems nervous, leery, or unwilling to hang up
  • The customer is agitated or frenzied about sending money immediately for a loved one's purported emergency, but the destination is a seemingly unconnected third-party business or individual
  • A caregiver or other individual shows excessive interest in the customer's finances, doesn't allow them to speak for themselves, or is reluctant to leave their side during conversations
  • The customer shows unusual fear or submissiveness toward a caregiver, or expresses fear of eviction or nursing-home placement if money isn't given to a caretaker
  • The institution is unable to speak directly with the older customer despite repeated attempts
  • A new caretaker, relative, or friend suddenly begins conducting transactions on the customer's behalf without proper documentation
  • Financial management changes suddenly — power of attorney, trust, or estate-planning vehicle transferred to a different family member or new individual — particularly where undue influence, coercion, or forgery is suspected, or the customer's cognitive abilities are diminished
  • The customer lacks knowledge about their own financial status, or shows sudden reluctance to discuss financial matters
Financial red flags (12)
  • Dormant accounts with large balances begin to show constant withdrawals
  • An older customer purchases large numbers of gift cards or prepaid access cards
  • An older customer suddenly begins discussing and buying CVC
  • Multiple checks or wire transfers with memo-line descriptors such as "tech support services," "winnings," or "taxes"
  • Uncharacteristic, sudden, abnormally frequent, or significant cash withdrawals or asset transfers
  • Money received and transferred interstate or abroad to recipients the customer has no in-person relationship with, where the explanation suggests a scam or mule scheme
  • Frequent large withdrawals, including daily maximum ATM currency withdrawals
  • Sudden or frequent non-sufficient funds activity
  • Uncharacteristic nonpayment for services — may indicate loss of funds or loss of access to funds
  • Debit transactions inconsistent for that customer
  • Uncharacteristic attempts to wire large sums
  • Closing CDs or accounts without regard to penalties

Regulatory history

FIN-2022-A002 — Advisory on Elder Financial Exploitation
Issued June 15, 2022 (World Elder Abuse Awareness Day) · Full PDF

Verified against the primary document: the 62,000/$3.4B (2020) and 72,000+ (2021) SAR figures match exactly.

Scope: defines EFE as the illegal or improper use of an older adult's funds, property, or assets, and defines "older adult" as 60 or over. Splits EFE into two structurally different halves — elder theft (by a known, trusted person) and elder scams (by a stranger, frequently overseas).

Scale cited: elder abuse affects at least 10% of older adults annually; over 62,000 EFE-related SARs in 2020 (~$3.4B in suspicious transactions, up from $2.6B in 2019 — the largest year-over-year jump since 2013), rising to over 72,000 SARs in 2021. Older adults account for 35% of fraud-report victims where age was provided. In FinCEN's sampling of 2013–2019 elder theft cases, a family member was involved 46% of the time.

Five named scam typologies: government imposter (SSA, HHS/CMS, IRS), romance/confidence ($547M in reported 2021 losses, a record), emergency/person-in-need ("grandparent scams"), lottery and sweepstakes (an advance-fee variant — see Advance-Fee Fraud), and tech/customer support. FinCEN details the tech-support refund sub-scheme: after the initial payment, perpetrators call back offering a refund, claim to have over-refunded, and induce the victim to send back the difference.

Payment channel shift: scammers historically requested MSB wires but increasingly ask for prepaid access cards, gift cards, money orders, tracked USPS delivery of cash and high-value items, ATM deposits, cash pick-up at the victim's home, and CVC. Top foreign subject countries in MSB SAR filings: Nigeria, Jamaica, Ghana, India, the Philippines, and the PRC.

Money mule warning: a victim can themselves be turned into a mule — persuaded to open a bank account or LLC in their own name to receive and forward third-party payments from other victims. FinCEN notes such victims may be prosecuted and held liable for repayment.

SAR filing instruction: include the key term in SAR field 2 ("Filing Institution Note to FinCEN") and the narrative, and check SAR Field 38(d) "Elder Financial Exploitation." For Form 8300, select Box 1b ("suspicious transaction") and put the key term in the Comments section. FinCEN also lists non-mandatory best practices: document the victim's age and county/city, describe the institution's own response, note amounts refunded, reference photos or video footage, cross-report to local law enforcement and Adult Protective Services, and supply a named point of contact — EFE investigations are time-sensitive because victims may lose cognitive capacity or die before an investigation completes.

SAR key term: EFE FIN-2022-A002 · SAR Field 38(d)
FIN-2011-A003 — Filing SARs Regarding Elder Financial Exploitation
Issued February 22, 2011 · Full text

The original EFE advisory, and still operative — FinCEN states the 2011 red flags "all remain relevant" and that the 2022 list builds on rather than replaces them. Its framing rationale: financial institutions are often quick to suspect EFE precisely because branch staff know their older customers personally.

Financial Trend Analysis — Elder Financial Exploitation
Issued April 18, 2024 · covers BSA reports June 15, 2022 – June 15, 2023

Quantitative follow-up to the 2022 advisory, analyzing reports that either used the EFE key term or checked the Elder Financial Exploitation box. An earlier December 2019 FTA ("Elders Face Increased Financial Threat from Domestic and Foreign Actors") supplied the 46% family-member statistic cited in the advisory.

Fraud Typologies

Business Email Compromise (BEC) & Email Account Compromise (EAC)✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2016-A003 (developed with FBI and USSS input); trend updates from FIN-2019-A005, which FinCEN states complements rather than replaces the 2016 red flags. Verified ≤2026-07 (see changelog)

FRDCYBBEC targets a financial institution's commercial customers; EAC targets an individual's personal accounts — both use a compromised or spoofed email account to induce a fraudulent but seemingly-legitimate wire transfer. Since 2013, FinCEN counted roughly 22,000 reported BEC/EAC cases totaling $3.1 billion (as of the 2016 advisory); FinCEN's 2019 update put cumulative possible losses since 2016 at over $9 billion and broadened the definition beyond wire transfers to include CVC payments, ACH transfers, and gift-card purchases, and beyond commercial victims to high-net-worth individuals and non-traditional entities (the 2019 advisory specifically flagged colleges and universities as emerging targets, given large tuition/endowment/grant flows).

Mechanics — three stages

(1) Criminals unlawfully access a victim's email via social engineering or intrusion, then mine it for information on the victim's financial institution, accounts, and contacts. (2) Using the compromised account — or a lookalike fake one — they email fraudulent wire instructions appearing to come from the victim. (3) They trick the victim's employee or financial institution into executing a wire transfer that appears legitimate but sends funds to a criminal-controlled account, often at a bank in Asia (China and Hong Kong are common destinations). BEC scenarios include impersonating the customer directly, impersonating an executive to mislead an employee into authorizing payment, or impersonating a supplier to redirect invoice payments to a new account. EAC scenarios extend the same technique to brokers, realtors/escrow companies, and attorneys handling client funds.

Red flags — as published in FIN-2016-A003

  • Emailed transaction instructions contain different language, timing, or amounts than previously verified authentic instructions
  • Instructions originate from an email address closely resembling a known customer's — altered by adding, changing, or deleting one or more characters (e.g. john-doe@abc.com → john_doe@abc.com or john-doe@bcd.com)
  • Instructions direct payment to a known beneficiary but with different account information than previously used
  • Instructions direct a wire to a foreign account previously documented in customer complaints as a fraud destination
  • Instructions direct payment to a beneficiary with no payment history or documented relationship, in an amount similar to or exceeding what the customer has historically paid other beneficiaries
  • Instructions are marked "Urgent," "Secret," or "Confidential"
  • Instructions are delivered in a way that gives the institution limited time to confirm authenticity
  • Instructions come from an employee newly authorized on the account, or one who hasn't previously sent wire instructions
  • A customer's employee relays instructions based solely on email from executives/attorneys but states they were unable to verify the request directly with them
  • A customer requests additional payments immediately after a successful payment to a previously-unused account — consistent with a criminal probing how far a successful fraud can be pushed
  • An incoming wire names a beneficiary who is not the account holder of record — visible to the receiving institution when a victim was tricked into paying a "new" account they believed belonged to a known supplier

Regulatory history

No.DateSubject
FIN-2016-A00309/06/2016Advisory to financial institutions on e-mail compromise fraud schemes
FIN-2019-A00507/16/2019Updated BEC/EAC advisory
FTA03/30/2023Business Email Compromise in the Real Estate Sector
Fraud Typologies

Romance & Investment Scams ("Pig Butchering") ✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2023-Alert005. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

FRDCYB"Pig butchering" describes a long-con romance or friendship scam that culminates in the victim being persuaded to invest — usually in fraudulent virtual-currency platforms — with the scammer building trust over weeks or months before the ask. FinCEN's 2023 alert named the term directly, reflecting law enforcement's adoption of an originally Chinese-language slang term for the pattern.

Mechanics

Contact typically begins via social media, dating apps, or a "wrong number" text; the scammer cultivates a relationship, then introduces a purportedly lucrative investment opportunity on a fake trading platform — often operated through shell companies — that the victim can watch "grow" before being blocked from withdrawing.

Mechanics: the four phases

1. Contact. Text, social media DM, professional networking site, or dating app — typically framed as a wrong number or an attempt to reconnect with an old friend. The scammer may claim to be an investor or money manager and maintain a profile showcasing wealth. FinCEN notes plainly that a significant number of scammers are themselves victims of human and labour trafficking, coerced into the work (see SE Asia Scam Compounds).

2. The pitch. The victim is directed to fraudulent trading websites or apps the scammer controls — or to legitimate apps with third-party plugins that let the scammer falsify what the victim sees. Scammers may request remote access to the victim's device to open VASP accounts on their behalf, or walk them through purchases via screenshots. Newer variants use fake "play-to-earn" games. Victims are also directed to wire overseas, buy prepaid cards, or use virtual currency kiosks.

3. Fabricated returns. The platform displays extraordinary gains. Crucially, the scammer may permit a small withdrawal to cement confidence before urging larger investment. FinCEN documents victims liquidating tax-advantaged accounts and taking out HELOCs and second mortgages. Victims are sometimes encouraged to recruit friends and family.

4. The point of no return. When investment slows, tactics escalate — supposed losses the victim must cover, or, if they try to withdraw, demands for "taxes" or "early withdrawal fees." Once the victim can't or won't pay more, contact ceases entirely.

Red flags — as published in FIN-2023-Alert005

Sixteen indicators across behavioural, financial, and technical categories.

Behavioural
  • A customer with no history of using or interacting with virtual currency attempts to exchange a high amount of fiat — from an existing or newly opened account — for virtual currency, or to initiate high-value transfers to VASPs
  • A customer mentions an investment opportunity in virtual currency with significant returns, learned about from a new contact who reached out unsolicited online or by text
  • A customer says they were instructed by someone who recently contacted them to exchange fiat for virtual currency at a kiosk and deposit it to an address that person supplied
  • A customer appears distressed or anxious to access funds to meet the demands or timeline of a virtual currency investment
Financial
  • Uncharacteristically liquidating savings before maturity — a CD, for instance — then wiring the proceeds to a VASP or exchanging for virtual currency
  • Taking out a HELOC, home equity loan, or second mortgage and using the proceeds to buy virtual currency
  • A deposit of virtual currency at or slightly above an amount the customer previously transferred out, followed by outgoing transfers in substantially larger amounts — the signature of the confidence-building test withdrawal
  • Large-balance accounts that were inactive or barely used suddenly showing constant, sudden, or abnormally frequent large withdrawals moving to a VASP or into virtual currency
  • Multiple EFTs or wires to a VASP noting the transaction is for "taxes," "fees," or "penalties"
  • A customer with a short history of several small EFTs to a VASP who abruptly stops and begins sending multiple high-value wires to holding companies, LLCs, and individuals with no prior transaction history — indicative of trial transactions preceding the real commitment
Technical
  • Logs showing the customer's account accessed repeatedly by unique IP addresses, device IDs, or geographies inconsistent with prior patterns; or VASP logins from varied device IDs and names inconsistent with the customer's usual
  • The customer mentions a service whose website or app has poor spelling or grammar, dubious testimonials, or amateurish design
  • The site or app purports to be a legitimate VASP but shows a misspelled domain resembling another business, a recently registered domain, no physical street address, international contact information, or contact only via chat or email — and is not registered with FinCEN as an MSB
  • The customer downloaded the app directly from a third-party website rather than an established app store
  • Receiving a large amount of virtual currency such as ether at an exchange, converting to a lower-fee currency such as TRX, then abruptly sending it off-exchange

Regulatory history

FIN-2023-Alert005 — Prevalent Virtual Currency Investment Scam Known as "Pig Butchering"
Issued September 8, 2023 · Full PDF

Verified against the primary document: the $3.31B/$2.57B 2022 loss figures and 183% increase match exactly.

The term: from the Chinese Sha Zhu Pan — scammers call victims "pigs," "fatten" them with fabricated returns, then "butcher" them. FinCEN uses the perpetrators' own vocabulary deliberately.

Scale: in 2022 investment fraud caused the highest losses of any scam reported to FBI IC3 — $3.31 billion — with cryptocurrency fraud including pig butchering the majority of it, up 183% from 2021 to $2.57 billion. Multiple U.S. law enforcement sources estimate American losses in the billions.

Beyond crypto: while most instances use virtual currency, FinCEN notes increasing reliance on electronic funds transfers, wire transfers, and foreign currency and dollar-gold (Forex) contracts — so a purely crypto-focused monitoring rule will miss part of the population.

Cyber indicators requested: chat logs, phone numbers, and social media usernames used by the scammer; suspicious email addresses; the type of virtual currency involved; wallet addresses and transaction hashes native to the blockchain; apps used; and the URL, domain, and IP address of the service the victim was told to deposit into.

SAR filing instruction: key term in SAR field 2 and the narrative; select "Fraud-Other" under field 34(z) with the description "Pig Butchering." For Form 8300, Box 1b plus the key term in Comments.

Referral channels: FBI IC3; the SEC's tips, complaints and referrals system for investment fraud; and for elder victims, DOJ's National Elder Fraud Hotline (833-372-8311).

SAR key term: FIN-2023-PIGBUTCHERING · Field 34(z) "Pig Butchering"
Case study in the alert — seizure of seven spoofed domains
E.D. Va., announced November 2022

Between May and August 2022, scammers used seven domains spoofing the Singapore International Monetary Exchange to convince five U.S. victims they were making legitimate crypto investments. Once funds hit the deposit addresses, they were immediately moved through numerous private wallets and swapping services to obscure origin. Victims lost over $10 million.

Follow-on FinCEN activity
February 2025 reminder notice

FinCEN reissued a reminder on relationship investment scams, noting FBI-reported romance and confidence scam losses exceeded $650 million in 2023, alongside the CFTC's #DatingOrDefrauding public awareness campaign.

Fraud Typologies

Impersonation Scams ✓ SOURCE-VERIFIED

FinCEN-impersonation red flags transcribed from FIN-2024-Alert005. The tech-support, gold-bar-courier, and foreign-student material is summarised from the 2026 NMLRA and FBI/IC3 reporting. Verified ≤2026-07 (see changelog)

FRDTreasury's 2026 NMLRA groups impersonation schemes — tech support scams, government/law-enforcement impersonation, and the increasingly prominent "gold bar courier" scam — under its broader confidence-scam category. These primarily originate from India-based call centers (tech support) or spoofed government caller-ID numbers, but rely on U.S.-based money mules to actually receive and launder funds. Roughly 98% of government-impersonation losses are reported by victims over 60.

Variant: Foreign/International Student Targeting

A distinct strand of this typology targets international students directly rather than the general public. The FBI and IC3 issued a public alert (May 2025, still active as of January 2026) on scammers impersonating U.S. or foreign government/immigration officials who contact students lawfully in the U.S. on F-1 visas — confirmed targets include nationals of the UAE, Saudi Arabia, Qatar, and Jordan — falsely claiming a visa-status violation and threatening deportation or prosecution unless the student pays an "immigration processing," "registration," or "legal" fee. In 2024, government-impersonation schemes overall (including this variant) cost the public $405M+ across 17,000+ complaints. Victims are directed to pay via CVC, prepaid/gift cards, or wire transfer.

Mechanics

Tech support scams open with a fake pop-up or unsolicited call claiming a computer problem, walking the victim through purchasing gift cards to "fix" it. Government impersonation scams spoof law-enforcement or agency caller ID, use an urgent tone to claim the victim's identity was used in a crime (or, in the student variant, that their visa status is invalid), and direct them to withdraw retirement savings and convert them to cash or gold bars for a courier — a money mule — to collect in person, or to wire/CVC payment directly. In 2024, victims reported 525 gold-bar-courier incidents to IC3 totaling $219M, averaging over $417,000 per victim.

Red flags

  • An older customer making large, urgent withdrawals or asset liquidations shortly after describing a call from "the government" or "the bank's fraud department"
  • Purchase of gold bars, precious metals, or large gift-card volumes inconsistent with the customer's ordinary pattern
  • Customer describing a courier who will personally collect cash, gold, or other assets — a mule pickup, not a wire or bank channel
  • An international student account holder making an urgent wire, CVC, or gift-card payment tied to a claimed "visa" or "immigration" fee, especially outside normal tuition/fee payment channels

Variant: Schemes impersonating FinCEN itself

FinCEN's December 2024 alert addresses scams that abuse its own name, insignia, and authorities. Three distinct typologies, all source-verified from FIN-2024-Alert005:

Fraudulent BOI forms and websites. Scammers contact companies by text, email, or U.S. Mail demanding a "filing fee" to submit beneficial ownership information — then never file, or falsely claim a fee exists at all. They use names close to "FinCEN" or invent agencies like a "United States Business Regulations Department" or "Annual Records Service," and send fictitious forms — secretary-of-state offices have reported a "Form 4022," a "Form 5102," a "2024 Beneficial Ownership Information Reporting Form," and an "Important Compliance Notice" — threatening fines and legal action. Payment is solicited by mailed check or money order, or via links, URLs, and QR codes to fraudulent domains.

Fraudulent MSB registration. Scammers register as MSBs with FinCEN using false information, then leverage their appearance on the public MSB Registrant Search Page to claim they are "vetted," "approved," or "licensed" by FinCEN. FinCEN states flatly that registration confers no approval of any kind, and FinCEN does not license MSBs to operate in the United States. These claims frequently support pig butchering schemes, where victims are told to buy virtual currency and send it to the fraudulent MSB. FinCEN's analysis found such registrants generally share street addresses, hold no state licences where they purport to operate, and don't comply with BSA reporting.

FinCEN imposter scams. Spoofed calls, texts, emails, and mail — often using stolen PII so the caller already knows the victim's name, SSN, and account numbers. Scammers demand payment for supposed AML/CFT violations or outstanding debts, supply fictitious documents purportedly from the FinCEN Director or Deputy Director, and threaten arrest or account seizure. A variant claims the victim is owed a Treasury grant but must first pay a release fee. In one recent scheme, scammers sent victims of their own investment fraud a fake "FinCEN Alert" via Telegram claiming accounts were frozen pending an AML/CFT investigation and demanding a "self-certification" fee as a percentage of investments.

FinCEN's own rebuttals, stated plainly in the alert: it does not have authority to freeze assets or block funds transfers; it does not offer grants or collect debts; it does not charge to file reports; it will never demand immediate payment by email, call, or text; and it never contacts the public to request payment. Between November 2023 and October 2024, the FTC logged 1,154 fraud reports mentioning "FinCEN" with over $69 million in reported losses.

Red flags: FinCEN-impersonation schemes — as published in FIN-2024-Alert005

BOI reporting scams
  • A customer intending to file their BOI directly with FinCEN makes an online payment — filing directly is free
  • A customer makes an online payment to file BOI through a third-party provider via a website domain registered in a foreign location
  • A customer pays a third-party filing company with little to no online presence, or a name similar to legitimate companies or government entities
  • A customer uncharacteristically sends a payment and tells the institution funds must go to FinCEN immediately or risk a fine, penalty, or legal action for failure to file BOI
Fraudulent MSB schemes
  • A company announces its "license" or "approval" from FinCEN as an MSB via press release, website, or social media
  • A company has been flagged by a state financial regulator as potentially fraudulent or as having exploited victims
  • A company is registered as an MSB with FinCEN but holds no state or territorial licence where it claims to operate
  • A company with limited online presence prominently highlights its FinCEN MSB registration alongside unverified testimonials and promotions of risk-free high returns
  • An MSB registered with FinCEN shares a street address with other recently registered MSBs
  • A VASP or other institution provides a virtual currency deposit address flagged as potentially fraudulent by blockchain explorers or analytics tools
  • An MSB claims its AML programme or KYC controls have been formally approved or vetted by FinCEN
  • An individual or entity claims their MSB registration is a "recommendation," "certification of legitimacy," "approval," or "endorsement" by FinCEN, Treasury, or the U.S. government
  • An individual or entity claims MSB registration equates to U.S. government approval to operate in the United States
  • An MSB suggests users must pay an AML-related processing "fee" or a "FinCEN fee" to deposit or withdraw
  • A company is registered as an MSB using the same or a very similar name to a large, well-known institution that wouldn't require MSB registration — a bank, credit union, or broker-dealer — with no actual affiliation
FinCEN imposter schemes
  • A customer sends a payment purportedly to FinCEN, or for a penalty owed to FinCEN, with the memo line denoting "tax," "fee," "debt," "prize," "lien," or "grant"
  • A customer uncharacteristically pays a new counterparty and says funds must go immediately to FinCEN for a supposed "AML/CFT violation," "outstanding debt," or "Treasury grant"
  • A customer says they received a phone call, text, email, or U.S. Mail from FinCEN demanding immediate payment
  • A customer presents a letter supposedly from the FinCEN Director, Deputy Director, or another FinCEN or Treasury official requesting immediate payment

Regulatory history

FIN-2024-Alert005 — Fraud Schemes Abusing FinCEN's Name, Insignia, and Authorities
Issued December 18, 2024 · Full PDF

Verified against the primary document: the three named typologies (BOI exploitation, MSB Registration misuse, impersonation) match the FinCEN alert.

Context that dates the document: issued two weeks after the Eastern District of Texas enjoined the Corporate Transparency Act nationwide (Texas Top Cop Shop v. Garland, Dec. 3, 2024), so the alert states BOI filing was not then required. Update: FinCEN's March 26, 2025 interim final rule exempted all U.S.-formed entities and their beneficial owners from BOI reporting, and a final rule issued August 11, 2026 (effective August 14, 2026) made that exemption permanent — domestic companies and U.S. persons no longer have any BOI filing obligation, and FinCEN is deleting previously submitted U.S.-person data from its database. Only foreign entities registered to do business in a U.S. state or tribal jurisdiction remain in scope. This makes the underlying scam even easier to spot going forward: any "BOI filing fee" demand aimed at a domestic company is now fraudulent on its face, not merely suspicious — there is no domestic filing to pay a fee for. The scam typology itself survives regardless, since fraudsters exploit confusion about the requirement rather than the requirement's actual status.

Penalties for fraudulent MSB registration: filing false or materially incomplete registration information — including registering an MSB that does not exist — violates the BSA. Civil penalties for willful violations run to $10,289 per day the violation continues; criminal exposure under 18 U.S.C. §1960 for operating an unlicensed money transmitting business reaches five years' imprisonment per violation. FinCEN notes an MSB that fails to comply with registration requirements is itself an "unlicensed money transmitting business."

Reporting channels: abuse of FinCEN's name or impersonation of employees goes to Treasury OIG and the FTC. Cyber-enabled imposter scams go to FBI IC3 and the nearest field office. For victims aged 60 or older, DOJ's National Elder Fraud Hotline (833-372-8311).

SAR filing instruction: key term in SAR field 2 and the narrative; select SAR field 34(z) (Fraud – Other) and include the applicable sub-term — "BOI Scam," "MSB Scam," and/or "FinCEN Imposter Scam" — in the text box.

SAR key term: FIN-2024-FINCENSCAMS · Field 34(z)
No.DateSubject
FBI/IC3 PSA05/13/2025Impersonation scheme targeting foreign students in the U.S. on F-1 visas
2026 NMLRA03/2026Impersonation scams as a confidence-scam subtype; gold-bar courier data

Note: the FBI/IC3 alert is a law-enforcement public safety announcement, not a FinCEN advisory — included here because it documents the identical government-impersonation mechanism against a named victim population, and financial institutions serving international student populations may want the specific red flag.

Fraud Typologies

Advance-Fee & Timeshare Fraud ✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2024-NTC2 (joint FinCEN/OFAC/FBI notice). General advance-fee material is summarised. Verified ≤2026-07 (see changelog)

FRDTCOAdvance-fee scams tell victims they're entitled to a large sum — an inheritance, lottery win, or exclusive business deal — but must pay upfront "taxes" or "fees" to unlock it, sometimes in escalating rounds. A prominent and heavily cartel-linked variant targets U.S. owners of Mexican timeshares: CJNG, Cartel del Golfo, and the Sinaloa Cartel have run timeshare-fraud call centers for over a decade, with CJNG the dominant player. Between 2019 and 2024, roughly 6,000 U.S. victims reported about $350M in timeshare-fraud losses.

Mechanics

Cartel-run call centers obtain U.S. timeshare owners' information from complicit resort insiders, then contact victims posing as ready buyers, renters, or investors for a timeshare "exit" or resale, requesting upfront taxes or fees to expedite a sale that never happens. A common follow-up scam then has the same network pose as a U.S. law firm or government authority offering to recover the victim's lost funds — for another fee.

Mechanics: the Mexico timeshare scheme

Sourcing the targets. TCOs obtain U.S. timeshare owners' PII from complicit insiders at timeshare resorts — and FinCEN notes the price paid for a record corresponds to the value of that owner's timeshare interest. Scammers then call or email posing as U.S.-based brokers, attorneys, or sales representatives, sometimes impersonating well-known U.S. companies, using real or fabricated websites, business names, addresses, and trade-group registrations, and citing the victim's stolen property details to establish credibility.

Three pitch variants: exit/resale (a ready buyer at or above market), re-rent (a ready renter, often pegged to an upcoming holiday or tourism event near the property), and investment (the victim supposedly holds stock associated with the timeshare, brokered to ready investors). Each comes with fraudulent offer letters and high-pressure time-sensitivity, then a demand for upfront "taxes" (capital gains, income) and "fees" (closing costs, earnest money, escrow, transfer, maintenance, attorney's, title insurance) purportedly held in escrow pending completion.

The escalation. After initial payment, scammers usually don't disappear — they demand further sums, sometimes supplying a spoofed online bank dashboard showing a false escrow balance. Demands continue until the victim liquidates everything including retirement accounts, maxes out credit, or recognises the scam.

Re-victimisation. The same victims are targeted again, often for years. Scammers reappear impersonating U.S. law firms claiming the original fraudsters were charged and a settlement is owed — payable after "legal fees." Then they impersonate government authorities — including OFAC itself, Mexico's UIF, and INTERPOL — claiming the earlier payments were flagged as suspicious or blocked for money laundering or terrorism links, demanding more money to release funds and clear the victim's name, with threats of imprisonment.

Laundering path. Victims wire via U.S. correspondent banks to Mexican shell companies at banks or brokerage houses (casas de bolsa) — accounts typically opened in the preceding six months. Funds then move through further Mexican shells and trusts (fideicomisos) controlled via cartel members, family, or complicit accountants, before financing drug operations or buying luxury real estate and constructing new timeshare resorts to feed future fraud.

Red flags — as published in FIN-2024-NTC2

Victim-side indicators
  • A customer uncharacteristically wiring funds to Mexico who indicates the funds must go immediately to pay "taxes" or "fees" to apparent timeshare brokers, or risk losing an urgent opportunity
  • A customer uncharacteristically sending international wires from retirement or trust accounts to Mexican institutions — directly, or by first routing through their own checking/savings account (internally or from another institution) and then immediately wiring onward
  • Multiple, structured, or repetitive wires to Mexican institutions with the same memo line denoting "taxes" or "fees" regarding a timeshare
  • A customer suddenly sending an unusual volume of wires to Mexican banks or brokerage houses with no previous related activity
Counterparty indicators
  • A new or recently formed Mexican company in the timeshare, travel, real estate, or financial services industries with minimal to no online presence
  • A new or recently formed Mexican company showing shell company indicators
  • A new or recently formed Mexican company with an account opened within the previous six months at a Mexican bank or brokerage house
  • A new or recently formed Mexican company receiving repeated or unusual volumes of wires from U.S. personal, retirement, or trust accounts with memo lines describing timeshare "taxes" or "fees"
  • A company that appears to do timeshare business but previously operated under a name associated with consumer protection or law enforcement complaints
  • A Mexican company with beneficial owners associated with timeshare fraud or drug-related DOJ indictments or OFAC designations

Regulatory history

FIN-2024-NTC2 — Joint Notice on Timeshare Fraud Associated with Mexico-Based TCOs
Issued July 16, 2024 · Full PDF · Joint with OFAC and the FBI · Spanish translation issued October 2024

Verified against the primary document and Treasury press materials: ~6,000 victims/$300M figure, 2012 start date, and CJNG attribution all match.

Scale, with an important caveat: roughly 6,000 U.S. victims reported nearly $300 million in losses between 2019 and 2023. The FBI believes this substantially understates the total — an estimated 80% of victims never report, from embarrassment, lack of resources, or other reasons.

Who is targeted: CJNG and other Mexico-based TCOs have run these schemes since at least 2012 from English-fluent call centres, CJNG's generally in Jalisco. Older adults — defined here as 60 or over, per the Elder Abuse Prevention and Prosecution Act — with high-end timeshares they no longer use are described as especially vulnerable. FinCEN notes some call-centre telemarketers were hired under false pretences and continued working after realising it was a scam.

Why Treasury cares beyond the fraud: proceeds diversify cartel revenue and finance "the manufacturing and trafficking of illicit fentanyl and other deadly synthetic drugs into the United States." CJNG is among the TCOs primarily responsible for fentanyl entering the U.S.

Concurrent OFAC action: published the same day as designations of three Puerto Vallarta-based Mexican accountants — Arredondo, Foubert, and Sanchez — plus four companies, under E.O. 14059. The familial structure is notable: Arredondo is the half-sister of a designated senior CJNG member; Foubert is the sister of a Mexican attorney designated in November 2023. This built on three prior 2023 actions against CJNG timeshare networks.

Rapid Response Program: the notice urges victims and institutions to file with FBI IC3 to activate FinCEN's RRP, which works FIU-to-FIU — including with Mexico's UIF — to freeze and recall funds. At publication the RRP had been used across 88 foreign jurisdictions, reaches over 160, and had assisted in freezing over $1.4 billion.

SAR filing instruction: key term in SAR field 2 and the narrative; select SAR field 34(z) (Fraud – Other) with "TimeshareMX" in the text box. For Form 8300, select Box 1b and put the key term in Comments.

Filing tips worth noting (FinCEN states these are best practices, not supervisory expectations): explain why the SAR is being filed; do not list the victim as the SAR subject — put their information in the narrative instead; document the victim's age and county/city; describe the institution's own response and any refunds; lay out all recipient accounts and beneficiaries; and use the law enforcement contact field to note referrals to law enforcement or Adult Protective Services.

SAR key term: FIN-2024-NTC2 · Field 34(z) "TimeshareMX"
Case study in the notice — timeshare-fraud telemarketing conspiracy
E.D. La., indicted October 3, 2019 · six Mexican nationals

Conspiracy to commit wire fraud through a telemarketing scheme targeting timeshare owners in the U.S., Canada, and South America from at least January 2016. Defendants misrepresented the existence of buyers and solicited "closing costs" wired from U.S. banks to Mexican banks; no buyers existed and no closings occurred. Of the U.S. victims, 40 were aged 60 or older; estimated loss at least $10 million. The operation cycled through at least 18 business names — Planet Travel, Newport International Investments, Advance Travel, All American Real Estate, Bear Claw Travel, Champion Properties, Equity Closing Services Group, Peach Title, Sandia Title, and others — which is itself the pattern behind the "previously did business under a name associated with complaints" red flag. Multiple guilty pleas and sentences followed through 2021.

Fraud Typologies

Health Care Fraud✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2026-A001. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

FRDHealth care fraud advisories target schemes that bill federal and state programs (Medicare, Medicaid, and pandemic-era relief programs) for services never rendered, medically unnecessary, or billed at inflated rates. FinCEN's 2026 advisory is its most comprehensive treatment of the topic to date, following two COVID-19-specific advisories in 2021.

Mechanics

Shell medical billing companies, complicit or "captured" providers, and patient recruiters ("marketers") who pay kickbacks for beneficiary identifiers feed fraudulent claims through the system; proceeds are then laundered through shell company accounts.

Red flags — as published in FIN-2026-A001

Twenty-four indicators. FinCEN supplies the key detection insight up front: health care reimbursements follow standardized, predictable payment patterns, so deviations in volume, timing, or credit/debit behavior after enrollment or a change in ownership are especially indicative. Payments often carry the issuing MAC or state agency name in the payment field — FinCEN asks institutions to review whether customers receive MAC or state-agency payments at all, and assess consistency with the customer profile. The advisory includes a full appendix mapping every MAC jurisdiction by state.

Ownership and identity indicators
  • A customer with neither U.S. legal permanent residence nor significant health care industry experience attempting to open an account as owner or employee of a recently established or purchased registered provider/supplier
  • Beneficial owners with prior health care or government benefits fraud convictions
  • Nominal or beneficial owners with familial or business affiliations to individuals with such convictions
  • The account is accessed via an IP address or Device ID linked to multiple accounts at the same or other institutions, or connected to foreign jurisdictions
  • Nominal and beneficial owners who also appear on accounts for other separate and distinct providers/suppliers
  • Changes to individuals listed as beneficiaries of the corporate account without a change to the account name or TIN
Reimbursement pattern anomalies
  • A recently established or purchased provider receiving significant reimbursements then immediately transferring funds to other recently established companies sharing owners, with little online presence and other shell company indicators
  • A recently established provider receiving a significant number of reimbursements soon after starting operations
  • A significant increase in reimbursements soon after a change in beneficial ownership
  • A sudden significant increase in reimbursements generally
  • Reimbursements inconsistent with the customer profile — e.g. Part A/Part B MAC payments beyond expected activity for comparable providers
  • Significant reimbursement volume but little to no legitimate business expenses associated with actually providing the goods or services — e.g. receiving DME MAC reimbursements without purchasing DME
  • Significant reimbursements from a single program where comparable customers draw from multiple — e.g. one MAC, one good or service type
  • Spike billing — consistently low-to-moderate billing for a year or more, then suddenly a large number of claims
Kickback and payout indicators
  • Significant transactional activity consisting of "consulting fees," "marketing fees," and other nondescriptive repetitive invoices
  • A pattern of significant cash withdrawals with no readily apparent business reason
  • A significant increase in cash withdrawals correlating to a significant increase in billings — FinCEN flags this as potential kickback payment
  • Transferring significant volumes of funds to individuals via high-value checks
  • Routinely cashing high-value checks drawn on provider/supplier accounts without credible explanation
  • Behavior suggesting CTR evasion — altering or cancelling a transaction when advised a CTR would be filed, or structuring multiple cash transactions under $10,000 — as well as avoiding recordkeeping requirements
Outbound laundering indicators
  • Transferring significant reimbursement volume to another company registered to a residential address
  • Outgoing transactions or expenditures to companies with no apparent health care nexus — residential real estate and luxury goods such as art or jewelry
  • A recently established or purchased provider sending significant wire volume to individuals and companies in foreign jurisdictions
  • Sending money transfers to VASPs, brokerage accounts, and online betting platforms with no legitimate business reason

Regulatory history

FIN-2026-A001 — Health Care Fraud Schemes Targeting Medicare, Medicaid, and Other Programs
Issued March 30, 2026 · Full PDF · Coordinated with the FBI and HHS-OIG

The headline number: from 2020 through 2025 FinCEN observed a 330% increase in BSA reporting on health care fraud, peaking in 2025 with a record of over 3,800 initial SARs checking SAR field 34(g). FinCEN adds the caveat that this "likely represents only a small fraction" of actual illicit activity.

Three-stage scheme architecture: (1) straw owners — including non-resident aliens and stolen identities of retired physicians — establish shell companies to obscure beneficial ownership and register as providers, using fraudulent BOI, false store fronts, and stolen or fictitious documentation to open bank accounts. Alternatively illicit actors purchase companies already registered and fail to notify CMS of the ownership change. Favored sectors: DME suppliers, home and hospice care, pharmacies, telemedicine, laboratories, adult day care. (2) File false claims. (3) Launder the reimbursement.

Five named billing fraud methods: billing for exploitative, substandard, or unnecessary goods/services; double billing (multiple claims, same service); phantom billing (never provided); unbundling (separate claims for bundled services); and upcoding (billing a more expensive service than delivered).

Kickback layer: recruiters and marketers pay complicit doctors, nurses, and pharmacists for referrals, prescriptions, and doctors' orders — in some cases authorized where a doctor never evaluated the patient — plus telemarketers and in-person recruiters enlisting witting or unwitting patients into unnecessary DME or genetic testing.

Seven laundering channels named: wires to controlled individual and shell company accounts domestic or foreign; wires to U.S. VASPs for digital assets then on to unhosted wallets or foreign VASPs in weak-AML jurisdictions; wires to broker-dealers; wires to online betting platforms; check deposits to money mule accounts; cash withdrawals through banks and MSBs including check cashers; and purchases of real estate, luxury goods, and high-value property. FinCEN also notes illicit actors may recruit complicit insiders within financial institutions to circumvent AML controls (see Complicit Insiders).

Unusual operational request: because illicit actors sometimes physically accompany straw owners to open accounts, FinCEN encourages institutions to include surveillance footage as supporting documentation in health care fraud SAR filings.

SAR filing instruction: key term in SAR field 2 and the narrative; select SAR field 34(g) (Healthcare/Public or Private Health Insurance) plus any other applicable box.

SAR key term: HCF-2026-A001 · SAR Field 34(g)
Case study in the advisory — "Operation Gold Rush"
E.D.N.Y., indicted June 2025 · largest health care fraud case by loss amount ever charged by DOJ

Eleven defendants, members of a TCO based in Russia and elsewhere, submitted over $10.6 billion in fraudulent Medicare DME claims. The Organization purchased dozens of DME companies with claim-submission ability, paid foreign nationals to serve as nominee owners, and created fictitious corporate records showing nominee control while foreign-based leadership actually ran them. It stole the identities and PII of more than one million Americans, including older and disabled people.

Nominee owners — many unlawfully present in the U.S. — used false documentation to open accounts, letting the Organization benefit from "the illusion of legitimate commercial activity," then funnel proceeds in as seemingly clean money before siphoning to shell companies and banks in China, Singapore, Pakistan, Israel, and Türkiye, with digital assets used to further conceal the trail. HHS-OIG and CMS blocked the vast majority of the intended theft; roughly $900M was nonetheless paid by Medicare Supplemental Insurers and ~$41M by Medicare. Four defendants were arrested in Estonia; seven remain at large.

Part of the June 30, 2025 National Health Care Fraud Takedown — 324 defendants, over $14.6B in intended loss. DOJ, FBI, and HHS-OIG subsequently established a Health Care Fraud Data Fusion Center applying cloud computing and AI to detect emerging schemes.

FIN-2021-A001 — COVID-19 Health Insurance- and Health Care-Related Fraud
Issued February 2, 2021 · SAR key term FIN-2021-A001, field 34(g)

The pandemic-era predecessor covering Medicare, Medicaid/CHIP, TRICARE, Labor and VA programs, private insurers, and fraud against COVID-19 provider relief funds under the PPP-HCEA. The post-2020 surge it documented is the baseline against which the 330% increase is measured.

Fraud Typologies

Pandemic & Government Benefits Fraud✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2026-Alert001. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

FRDThis typology cluster covers fraud against government relief and benefits programs — COVID-19 stimulus (EIP), unemployment insurance, the Employee Retention Credit, and, most recently, federal child nutrition and student aid programs. FinCEN issued a wave of COVID-specific advisories in 2020–2021 and has continued the pattern for subsequent benefit programs.

Mechanics

Fraud rings file claims using stolen or synthetic identities, sometimes at industrial scale across multiple states; proceeds are deposited into mule accounts, quickly withdrawn as cash, or converted to virtual currency.

Red flags — as published in FIN-2026-Alert001

Thirteen indicators from the Minnesota child nutrition alert. Although drawn from one state's scheme, they are written generically around "a company or NPO enrolled in a government benefit program" and transfer readily to other benefit-program fraud.

Enrollment and profile anomalies
  • A company or NPO serving as a sponsor that suddenly receives and disburses a significant number of reimbursements in a short timeframe, inconsistent with comparable entities
  • A recently established company or NPO receiving significant federal payments soon after starting operations
  • A recently established enrolled entity receiving payments inconsistent with its customer profile
  • An enrolled entity unable to verify its status to the financial institution, or whose profile isn't commensurate with comparable entities
  • An enrolled entity receiving significant reimbursements despite limited operations
  • A recently established enrolled entity with limited online presence
Expense and payout patterns
  • Minimal to no operating costs other than payments for "consulting fees" and nondescriptive repetitive invoices (i.e. food supplies)
  • An enrolled entity making a significant amount of cash withdrawals
  • An employee of an enrolled entity with previous fraud convictions
  • An employee frequently purchasing or redeeming cashier's checks for no clear purpose
  • The entity or its employee engaging in behavior suggesting CTR evasion — altering or cancelling a transaction when told a CTR would be filed, or structuring multiple cash transactions under $10,000 — plus avoiding recordkeeping requirements
Outbound flows
  • An entity enrolled in a program meant for U.S. citizens and lawful permanent residents sending significant wire volume to individuals and companies in foreign jurisdictions
  • Sending payments abroad for residential and commercial real estate, vehicles, aircraft, airline tickets, and designer clothing

Regulatory history

FIN-2026-Alert001 — Fraud Rings Exploiting Federal Child Nutrition Programs in Minnesota
Issued January 9, 2026 · Full PDF · At least $300 million defrauded

The structural vulnerability: USDA's Food and Nutrition Service allocates funds to state agencies — in Minnesota, the Department of Education — which contracts with Sponsors (schools, child care centers, NPOs) to enroll and monitor Sites that serve free meals, and to file reimbursement claims on Sites' behalf. Sponsors can also operate as Sites themselves. That sponsor-files-for-site structure is what the fraud exploited.

What COVID changed: USDA temporarily lifted certain Site enrollment requirements — allowing for-profit restaurants to participate and permitting meal distribution to children outside educational programs. Fraud rings exploited exactly those relaxations.

The mechanics: rings operated as Sponsors and recruited co-conspirators to enroll recently established shell companies as Sites — typically purporting to be restaurants, food suppliers, or social-service NPOs. Sponsors then filed documentation falsely claiming Sites were feeding thousands of children, beyond any plausible capacity. FinCEN's detail is striking: within days of enrolling, these entities would purport to serve tens of thousands of children daily across Minnesota — from Minneapolis to small rural areas, every day of the week — often submitting fictitious participant names. Sponsors retained administrative fees, disbursed the rest to Site operators, who then paid Sponsor employees in cash and "consulting fees" by wire and check.

Four laundering channels: wires to U.S. and foreign individuals and controlled shell companies; wires to VASPs for digital assets; international wires ostensibly for personal remittances via MSBs; and purchase and redemption of cashier's checks. Proceeds bought residential and commercial real estate, luxury goods, vehicles, planes, and international flights to resorts.

Reporting posture: file SARs as soon as possible regardless of threshold, to support identification and recovery of defrauded funds.

Wider Treasury action, same day: the alert accompanied a Geographic Targeting Order requiring banks and money transmitters in Hennepin and Ramsey Counties to report transactions of $3,000 or more to beneficiaries outside the U.S. (effective February 12 – August 10, 2026), four notices of investigation to Minnesota MSBs, and IRS audits plus a dedicated task force.

SAR key term: FIN-2026-MNFRAUD · SAR Field 34(z) "Federal Child Nutrition Programs"
The underlying prosecution — "Feeding Our Future"
D. Minn. · charges announced September 2022, continuing through 2025

Forty-seven defendants initially charged in a $250 million scheme, later expanded — a 78th defendant was charged in November 2025. In August 2025 the scheme's leaders received a landmark 28-year sentence in what by then was described as a $300 million scheme, with one defendant having personally pocketed $8 million. A Kenyan national was separately charged with international money laundering in September 2025. FinCEN notes DOJ investigations have identified potentially billions stolen from child nutrition and other benefit programs in the state, including Medicaid and a parallel autism services fraud scheme.

Other benefits-fraud issuances
Pandemic-era cluster, all still operative

FIN-2023-Alert007 verified against the primary document: 323 investigations / $2.8B figure, IRS-CI coordination, and third-party promoter ("ERC mill") framing match.

No.DateSubject
FIN-2023-Alert00711/22/2023COVID-19 Employee Retention Credit fraud — issued with IRS Criminal Investigation. Targets fraudulent ERC claims filed by ineligible businesses and by "ERC mills" charging contingency fees, often after aggressive marketing. SAR key term FIN-2023-ERC. See also Accountants — percentage-of-refund fee structures are a recurring indicator.
FIN-2021-A00202/24/2021Financial crimes targeting COVID-19 Economic Impact Payments
FIN-2020-A00710/13/2020COVID-19 unemployment insurance fraud
Fraud Typologies

Federal Student Aid Fraud (Ghost & Straw Students)✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2026-Alert004. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

FRDFinCEN's newest alert (issued this week, July 24, 2026) targets fraud against the Department of Education's Federal Student Aid (FSA) programs — which disburse $120B+ a year to ~13 million students. Issued jointly with ED's Inspector General and the FBI, it describes both foreign- and domestic-based fraud rings using stolen or purchased identities to enroll fake "students," collect refund disbursements, and in some cases lock real students out of oversubscribed open-enrollment classes.

Mechanics: three distinct schemes

Ghost students — a fraudster steals someone's PII (sometimes a minor's) to impersonate them as a legitimate enrollee, then uses AI chatbots or paid accomplices to complete just enough coursework (60% of the term is the refund threshold) to keep the refund flowing. The identity-theft victim usually has no idea until they're hit with surprise loan debt or aid ineligibility.

Straw students — a complicit individual sells their own real PII to a fraudster for a fee, is enrolled in their own name, does no coursework, and the organizer collects and keeps most of the refund.

Insider-assisted fraud — corrupt school staff recruit straw students, guarantee their acceptance, doctor academic records to preserve refund eligibility, and either steal the refund outright or take a cut.

Laundering follows a now-familiar pattern: money mules with no connection to the "student" receive refund ACH deposits (transaction references often read like "LCC REFUND John Doe"), then forward funds via P2P transfer, wire, or CVC purchase; foreign-based rings increasingly pay criminal brokers — advertised on the dark web or encrypted messaging apps — to open bank accounts on a "one-to-one" model (one account, one refund, one victim) specifically to defeat pattern detection.

Red flags — as published in FIN-2026-Alert004

Eight indicators. FinCEN's caveat applies: no single flag is determinative — weigh historical activity, prevailing business practice, and whether multiple related flags co-occur.

  • A customer with no prior history or profile information consistent with school enrollment receives a student aid refund — especially where the recipient named in the transaction reference has no known connection to the customer — with funds then rapidly moved out via P2P or wire, converted to digital assets, or sent through online MSBs that typically process international transfers
  • A customer uses student aid refund funds to quickly purchase digital assets, then rapidly transfers them to another wallet for no business or apparent lawful purpose
  • Multiple unrelated students use the same account for student aid refund deposits
  • An account receives multiple student aid refunds for no apparent lawful purpose, especially where the named recipients are unrelated individuals with no known connection to the customer, followed by rapid outbound P2P/wire, digital asset purchase, or online MSB activity
  • A newly established account is funded solely by student aid refunds and shows no other financial activity, with funds then rapidly moved out
  • A business account receives multiple student aid refunds — especially where named recipients have no known connection to the customer — then rapidly transfers funds to other business-entity accounts or online MSBs
  • A customer receives multiple P2P or wire transfers from accounts that recently received student aid refunds, for no apparent lawful purpose
  • Multiple accounts receiving student aid refunds are accessed from the same out-of-state or international IP address, or the same device
  • Multiple accounts created online at one institution within a short window, each receiving a student aid refund on a strict one-to-one basis (one account, one refund), with funds rapidly moved out

Detection tip from the alert: intermediary-processed refunds typically arrive as ACH transfers whose transaction references include "refund" plus the institution's name or abbreviation — e.g. "Local Community College Refund," "LCC REFUND" — and sometimes the purported student's name ("LCC REFUND John Doe"). That name-versus-accountholder mismatch is the single most tractable screening signal in this typology.

Regulatory history

FIN-2026-Alert004 — Fraud Schemes Targeting Federal Student Aid
Issued July 24, 2026 · Full PDF · Issued in consultation with ED-OIG and the FBI

Program scale and the mechanism being abused: FSA awards $120B+ annually to roughly 13 million students. Aid goes first to the school; whatever remains after tuition and fees is refunded to the student. The 60% rule is the hinge of the entire typology — a student must remain enrolled for 60% of the enrollment period to receive a full refund, which is why fraudsters need coursework completed at all.

Ghost students: stolen PII used to impersonate an identity theft victim, or AI-generated synthetic identities blending stolen PII with fabricated details to defeat identity verification. To satisfy the 60% threshold, rings use AI-powered chatbots to complete coursework; the FBI is also aware of paid human accomplices doing the same. Victims — including minors — typically discover the fraud only when they find themselves ineligible for aid or holding debt in their name.

Straw students: complicit individuals who sell their PII for a fee, are enrolled, never attend, and keep a cut of the refund while the fraudster completes the coursework.

Insider-assisted fraud: corrupt institutional staff recruit straw students, guarantee acceptance and enrollment, sometimes complete coursework themselves, and manipulate educational records to preserve full-refund eligibility — then either steal refunds outright or demand a share (see Complicit Insiders).

Target selection: rings deliberately exploit institutions with open admissions and online programs — typically community colleges and smaller schools designed to widen access. The alert notes real students have faced difficulty enrolling in classes because of the volume of fraudulent enrollments.

Four laundering channels named: money mules with no discernible connection to the named beneficiaries; shell companies (often foreign-created, used to move funds abroad and into real estate); fraudulent accounts opened with fake identities; and digital assets — with criminal brokers layering funds through controlled accounts, buying digital assets at smaller exchanges, then moving them to a larger exchange where perpetrators convert to home-country currency.

The "one-to-one" broker model: as rings matured, they began paying criminal brokers advertising on the dark web and encrypted messaging platforms to open many accounts online, each receiving exactly one refund tied to a single applicant — specifically to defeat the "multiple refunds, one account" detection pattern. Brokers take a percentage before forwarding via P2P, wire, or digital assets.

Policy context: E.O. 14249 (March 25, 2025), Protecting America's Bank Account Against Fraud, Waste, and Abuse. ED announced it had prevented $1 billion in student aid fraud during calendar 2025.

SAR filing instruction: include the key term in SAR field 2 and the narrative; select SAR field 34(z) (Fraud – Other) and enter "Federal Student Aid Fraud" in the text box.

Whistleblower note: unusually, this alert closes by promoting FinCEN's whistleblower program — awards available where information leads to enforcement action exceeding $1,000,000 in monetary penalties, with confidentiality and anti-retaliation protections under 31 U.S.C. §5323, and the option to submit anonymously through an attorney.

SAR key term: FIN-2026-FSAFRAUD · SAR Field 34(z) "Federal Student Aid Fraud"
Guidance for victims (reproduced from the alert)
Worth surfacing because identity theft victims here often don't know they're victims

If someone has used your information to apply for federal student aid: (1) contact Federal Student Aid and the loan servicer; (2) contact the credit reporting agencies and freeze your file so no new credit accounts can be opened — contact details at identitytheft.gov; (3) report suspicious education-related emails, texts, or calls to the ED-OIG Hotline.

Fraud Typologies

Payroll Fraud & Unlawful Employment Schemes HIGH RISK✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2026-A002. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

FRDTCOHTSHELLMSBA joint FinCEN/FDIC/OCC/NCUA advisory, issued in coordination with the IRS, addressing identity theft and off-the-books payroll schemes used to conceal employment of workers lacking authorization. FinCEN frames the financial-crime harms as: unfair advantage over compliant businesses, depressed wages, identity theft against authorized workers, and evasion of federal and state payroll taxes. The advisory is the first FinCEN issuance to treat ITIN use as a potential risk factor warranting enhanced due diligence, and it carries a multi-agency imprimatur that ordinary FinCEN advisories don't.

Editorial note: this article reports the advisory's published content and FinCEN's own caveats. The underlying immigration-enforcement policy is politically contested; the compliance obligations it creates for financial institutions are not, and that is what is summarized here.

Mechanics: two mechanisms

Identity theft. Workers obtain SSNs and other PII belonging to citizens and lawful permanent residents and submit it so Form I-9s appear legitimate — gaining employment, wages, health benefits, and (per BSA reporting) access to credit and auto loans. Identity theft victims can face higher taxes and denial of health, disability, and tuition benefits. Complicit employers sometimes assist in obtaining fraudulent documentation, which FinCEN notes can itself become a mechanism of exploitation and, at the extreme, forced labor (see Human Trafficking).

Payroll fraud via labor brokers. The structurally significant half. A complicit employer contracts a labor broker who sets up a shell company — directly or via a nominee — purporting to operate in agriculture, construction, domestic service, hospitality, or staffing. Per the IRS, these often carry generic names (ABC Construction, XYZ Logistics) that may match the broker's initials. The shell typically operates as an unregistered MSB providing off-the-books payroll services. Brokers may open the account with a foreign passport or ITIN listing themselves as "self-employed" or "laborer," and may use a Commercial Mail Receiving Agency instead of a real address to evade CIP requirements.

Employers write checks to the shell for purported trade services (framing, drywall, stucco, masonry, painting). The broker cashes them in structured transactions through banks and check cashers or deposits them, takes a 4–10% fee, and pays workers via cash couriers, checks, or P2P platforms — repetitive transactions designed to fall below BSA reporting thresholds ("structuring" and "microstructuring"), often correlating to payroll cycles outside standard processing systems. Neither party withholds payroll taxes. Brokers may also buy a minimal workers' compensation policy covering a handful of nominal employees and "rent" or sell access to it to employers running hundreds of workers — insurance fraud on top of tax evasion.

FinCEN notes these schemes are often embedded in broader global laundering networks that insert cash into the U.S. financial system in small amounts across many cities, then collect checks from the involved businesses — and that brokers may use the same shell for DTO/TCO laundering.

Red flags — as published in FIN-2026-A002

Eighteen indicators in three groups, building on the 2023 Payroll Tax Fraud Notice. FinCEN's caveats are unusually emphatic here and worth reading as part of the guidance: no single red flag should be taken in isolation; "no customer type presents a single level of uniform risk"; and the indicators "do not convey or alter any independent regulatory obligations or supervisory expectations."

Individual customers (8)
  • Uses an SSN that, on verification, doesn't match or is inconsistent with SSA records
  • Opens an account with a non-U.S. passport or ITIN claiming self-employment or a small business in agriculture, construction, domestic service, hospitality, or staffing, receiving significant recurring check deposits from multiple companies, then making repetitive structured cash withdrawals or issuing low-dollar checks to many individuals
  • Cashes significant recurring volumes of checks drawn on company accounts in those industries at an MSB or check casher
  • Receives recurring P2P payments from a small, recently established company in those industries
  • Works in those industries and opens an account with an ITIN showing little activity besides remittances to foreign jurisdictions
  • Attempts to use a Commercial Mail Receiving Agency instead of a business address when opening a company account
  • Has no known prior involvement in those industries but provides a non-U.S. passport or ITIN when opening an account for a new company in them
  • States to tellers or check cashers that withdrawals or check-cashing are "for payroll" where volume and frequency are uncharacteristic for a company with few employees
Large companies in those industries (5)
  • Identified in ICE worksite enforcement releases or open-source reporting as having a history of worksite compliance violations
  • Significant business operations and transactional activity but little to no commensurate payroll activity
  • Federal and state payroll tax deposits significantly below what operations and workforce size would predict
  • Issuing significant, repetitive checks to a single or small number of recently established companies with little to no online presence
  • Recently acquired a workers' compensation policy covering a small number of workers, inconsistent with its profile and activity
Small companies in those industries (5)
  • Beneficial owners with no known prior involvement in the company or industry, who may have prior fraud convictions
  • Minimal or no tax/payroll payments to the IRS, state and local authorities, or a third-party payroll company despite large client deposits
  • Large or unusual cash withdrawals or check negotiation when accompanied by another person or using an armored car service to deliver bulk cash — i.e., conducting off-the-books payroll
  • Issuing recurring large volumes of checks under $1,000 payable to many separate individuals who cash them
  • A new customer (under two years old) with minimal online presence and shell company indicators

ITIN due diligence — what actually changed

Under CIP rules a bank must collect an identification number; for U.S. persons that means a TIN, which by cross-reference includes ITINs. ITINs are nine digits beginning with "9" with fourth/fifth digits in defined ranges (9XX-7X-XXXX), issued to resident and nonresident aliens ineligible for an SSN solely for federal tax purposes — they don't establish legal status, authorize work, or serve as identification outside the tax system. The advisory, per E.O. 14406, states the agencies "note that the use of an ITIN in lieu of an SSN or valid employment authorization document may be identified as a risk factor requiring enhanced due diligence," and expresses particular concern about ITIN use to obtain credit products or open depository accounts where legal presence isn't verified. The operative language is encouraged to consider as part of risk-based CDD, assessed "in light of the totality of other factors" — not a mandate to decline. Where a bank has risk-based concerns about SSN authenticity, FinCEN encourages verification against SSA records.

Regulatory history

FIN-2026-A002 — Joint Advisory on Non-Work Authorized Populations and Their Employers
Issued June 5, 2026 · Full PDF · Joint with FDIC, OCC, NCUA; coordinated with IRS

Origin: the first concrete deliverable under E.O. 14406, Restoring Integrity to America's Financial System (May 19, 2026), which directed Treasury to issue an advisory on red flags and typologies within 60 days — delivered ahead of deadline. Also references E.O. 14159 (January 20, 2025).

Scale: financial institutions reported over $2.5 billion in suspicious activity in 2025 tied to labor-broker payroll schemes. The IRS employment tax gap was $127 billion in 2022. Named target industries: agriculture, construction, domestic service, hospitality, staffing.

Statutory frame: IRCA (1986), 8 U.S.C. §1324a, prohibits knowingly hiring or recruiting unauthorized workers; employers must verify eligibility via Form I-9, which ICE inspects.

Definitional scope: the advisory expressly excludes U.S. citizens and nationals, lawful permanent residents, and any alien whose employment is authorized by statute, regulation, or specific authorization.

Priorities mapped: Fraud, Terrorist Financing, DTO activity, TCO activity, and Human Trafficking & Smuggling.

SAR filing instruction: key term in SAR field 2 and the narrative. FinCEN additionally encourages reporting tips about employers to ICE's tip form or (866) 347-2423 — a referral channel outside the SAR system.

SAR key term: FINANCIALINTEGRITY-2026-A002
FIN-2023-NTC1 — Payroll Tax Evasion and Workers' Compensation Fraud in the Construction Sector
Issued August 15, 2023 · Full PDF · red flags remain fully operative · SAR key term FIN-2023-CONSTRUCTION

Verified against the primary document: the shell-company/workers'-comp mechanism and IRS-CI coordination match.

Established the architecture the 2026 joint advisory later extended across additional industries: a complicit contractor engages a labor broker who forms a shell company, obtains a minimal workers' compensation policy, and operates as an unregistered money services business cashing contractor checks and paying workers off the books. FinCEN states these red flags "remain relevant" and are not superseded by FIN-2026-A002.

Why construction first: the sector's reliance on layered subcontracting makes it structurally easy to insert a broker between the contractor and the workforce, and workers' compensation premiums scale with reported payroll — creating a direct financial incentive to understate headcount, which is what makes the "rented" certificate of insurance variant profitable.

FIN-2025-Alert003 — Cross-Border Funds Transfers Involving Illegal Aliens
Issued November 28, 2025 · Full PDF · directed at MSBs · SAR key term FIN-2025-Alert003

Verified against the primary document: this alert contains no red-flag indicators. At two pages it is among FinCEN's shortest issuances — it establishes a SAR key term and restates the existing MSB reporting threshold rather than supplying detection guidance. The operative indicators for this typology live in FIN-2026-A002 and the 2023 payroll tax notice.

What it does say: MSBs must generally file a SAR for a transaction involving at least $2,000 that they know, suspect, or have reason to suspect relates to a possible violation — including cross-border transfer of funds derived from unlawful employment. Issued under E.O. 14159.

Definitional scope, which matters: "illegal aliens" as used here expressly excludes U.S. citizens and nationals, lawful permanent residents, aliens present under a valid visa or permission who haven't exceeded it, and aliens whose employment is authorised by statute or regulation.

Context: personal remittances from U.S. resident immigrants totalled over $72 billion in 2024. FinCEN states plainly that "the vast majority of remittances from the United States are legitimate and can provide critical financial support to family members abroad." Companion measures include southwest-border Geographic Targeting Orders requiring MSBs in certain Arizona, California, and Texas counties and ZIP codes to file CTRs at a lowered dollar threshold — though, per court orders, MSBs under the S.D. Cal. jurisdiction and certain Texas-based MSBs are not currently required to report under them.

Industry response worth noting: the Defense Credit Union Council wrote to Treasury raising concern that the alert could disrupt lawful transfers by deployed U.S. service members and their families, and requested a clarifying FAQ.

FIN-2025-G001 — Cross-Border Information Sharing and SAR Confidentiality
Issued September 5, 2025 · guidance, not an alert

Verified: this is interpretive guidance and contains no red-flag indicators. It addresses sharing with foreign financial institutions and clarifies that sharing underlying account or transaction information does not violate SAR confidentiality unless it would reveal the existence of a SAR. The language encouraging institutions to "use, and potentially expand" cross-border sharing processes now recurs verbatim across FinCEN's 2025–2026 products. See the SAR Key Terms Glossary for the §314(b) treatment.

Fraud Typologies

Mortgage & Foreclosure Fraud✓ SOURCE-VERIFIED

Red-flag lists transcribed from FIN-2010-A006 (foreclosure rescue) and FIN-2010-A005 (HECM/reverse mortgage). FIN-2009-A001 is the original April 2009 advisory these two update. Verified ≤2026-07 (see changelog)

FRDThis cluster covers fraud in loan origination and modification, and predatory "foreclosure rescue" scams that target homeowners in distress. FinCEN's guidance here dates to the 2008–2012 foreclosure crisis and remains the baseline SAR-filing framework for mortgage-related fraud typologies.

Mechanics — foreclosure rescue

Perpetrators contact financially distressed homeowners promising to negotiate a loan modification, insist on an advance fee (sometimes thousands of dollars), and caution the homeowner against discussing the arrangement with their lender "to avoid jeopardizing negotiations." The perpetrator never actually contacts the lender, and the loan proceeds to foreclosure. FinCEN's 2010 mortgage loan fraud report (analyzing 3,500+ SARs from 2004–2009) found perpetrators also use straw borrowers, deceive homeowners into signing over title while promising a leaseback, and run "equity skimming" via equity lines of credit or false quit-claim deeds.

Red flags — foreclosure rescue — as published in FIN-2010-A006

  • Since most states criminalize advance mortgage-modification fees, schemes relabel the fee — "file review fee," "forensic review/audit fee," "attorney fee," "fraud detection fee," or "membership fee"
  • Perpetrators style themselves as "associations," "counseling agencies," or non-profits to project legitimacy
  • A notary public is used as an agent to deliver documents and collect the fee in cash, cashier's check, or personal check
  • Advance-fee schemes are frequently bundled with debt-elimination, credit-card-debt, or refinance schemes
  • Advertising (websites, mailings, TV/radio, roadside signs) offers free foreclosure help, loan modifications, short sales, "forensic audits," or credit/debt relief
  • Multiple, structured, or sequential money orders are sent to a loan-modification/foreclosure-rescue business, sometimes with the perpetrator instructing the customer that structuring was "required"
  • The trade name of an entity includes "foreclosure rescue"
  • A false claim of being listed on official government-approved-counselor or HUD-approved-housing-counseling-agency rolls

Mechanics — HECM/reverse mortgage fraud

The FHA's Home Equity Conversion Mortgage (HECM) program lets seniors access home equity as a reverse mortgage; the housing-market downturn increased its attractiveness as a fraud target. FinCEN, working with HUD-OIG, identified a common "cross-selling" scheme: theft of a senior's HECM loan proceeds through the sale of other financial products in violation of HUD rules. Other patterns include theft by family members, loan officers, or appraisers, and use of unsuspecting seniors in property-flipping schemes — with the constant thread being that HECM proceeds are funneled to the perpetrator(s), sometimes via multiple complicit actors (loan officers, processors, appraisers, notaries).

Regulatory history

No.DateSubject
FIN-2009-A00104/06/2009Filing SARs regarding loan modification/foreclosure rescue scams
FIN-2010-A00606/17/2010Updated advisory, foreclosure rescue scams
FIN-2010-A00504/27/2010Home Equity Conversion Mortgage (HECM) fraud schemes
FIN-2012-A00908/16/2012Suspicious activity related to mortgage loan fraud
Fraud Typologies

Mail Theft-Related Check Fraud ✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2023-Alert003. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

FRDThis scheme starts with stolen U.S. Mail — often checks pulled from residential mailboxes or blue collection boxes using stolen "arrow keys" — which are then altered (washed) or counterfeited and deposited or cashed. As of September 30, 2025, the federal government stopped issuing paper checks for most federal payments (Executive Order 14247), which the 2026 NMLRA expects to sharply cut government-check-related fraud going forward — though private check volume, already down to 3% of consumer payments in 2024 from 7% in 2016, remains a target.

Mechanics

The theft. Criminals target USPS blue collection boxes, unsecured residential mailboxes, and cluster box units at apartment complexes and commercial buildings — by forced entry, by "fishing devices" (makeshift adhesive-tipped tools that pull mail back out of a collection box), and increasingly with authentic or counterfeit USPS master keys known as Arrow Keys. A single Arrow Key opens every blue box and cluster unit in a geographic area, which is why FinCEN documents organised groups violently robbing mail carriers to obtain them, corrupt postal employees supplying them, and stolen keys being copied and sold on the dark web and encrypted platforms for convertible virtual currency.

The alteration. "Check washing" uses chemicals to strip the original ink so the payee can be replaced — and the amount is often increased at the same time, sometimes by hundreds or thousands of dollars. Washed checks may be copied and printed for later use or sold on to third-party fraudsters. Alternatively the check is counterfeited outright using the routing and account numbers from the stolen original.

The cash-out. Deposits go in person, through ATMs, or by remote deposit into accounts the criminals control — frequently opened specifically for the scheme — or through money mules using pre-existing accounts. Funds are then rapidly withdrawn via ATM or wired onward. FinCEN adds a grim detail about recruitment: mail-theft mules are generally younger and witting, but criminal organisations also prey on homeless individuals and people with addictions, giving them a small cut of the cashed checks.

The secondary harm. PII harvested from the same stolen mail feeds later identity-theft and credit-account fraud against the same victims.

Why business checks are prized: business accounts tend to be well funded, and it takes longer for the victim to notice.

Red flags — as published in FIN-2023-Alert003

Ten indicators developed with USPIS. FinCEN notes many overlap with general check fraud indicators.

  • Non-characteristic large withdrawals on a customer's account via check to a new payee
  • A customer complains that a check or checks were stolen from the mail and then deposited into an unknown account
  • A customer complains that a check they mailed was never received by the intended recipient
  • Checks used to withdraw funds appear to be of a noticeably different check stock than that used by the issuing bank or in the customer's known legitimate transactions
  • An existing customer with no history of check deposits suddenly shows new check deposits followed by withdrawal or transfer of funds
  • Non-characteristic, sudden, abnormal deposit of checks — often electronically — followed by rapid withdrawal or transfer
  • Examination reveals faded handwriting underneath darker handwriting, indicating the original was overwritten — the direct physical signature of check washing
  • Suspect accounts show indicators of other suspicious activity, such as pandemic-related fraud
  • A new customer opens an account seemingly used only for check deposits, followed by frequent withdrawals and transfers
  • A non-customer attempting to cash a large check or multiple large checks in person who, when questioned, gives an explanation that is suspicious or potentially indicative of money mule activity

Regulatory history

FIN-2023-Alert003 — Nationwide Surge in Mail Theft-Related Check Fraud
Issued February 27, 2023 · Full PDF · Issued with USPIS · Spanish translation December 2024

Verified against the primary document: the 299,020 mail theft complaints / 161% increase figure matches exactly.

The paradox the alert opens with: check use is declining in the U.S., yet check fraud is surging. From March 2020 through February 2021 USPIS received 299,020 mail theft complaints — a 161% increase year over year. Check-fraud SAR volume tracked it: over 350,000 SARs in 2021 (up 23% on 2020), then over 680,000 in 2022, nearly double again. Context for scale: USPS delivers roughly 130 billion pieces of mail a year to over 160 million addresses.

Division of labour: FinCEN describes organised groups with distinct roles — organisers, recruiters, check washers, and money mules — noting that while there have been cases of postal employees stealing from sorting facilities, the activity is increasingly committed by non-USPS actors.

Expedited channel: unusually, the alert supplies a 24/7 Financial Institutions Toll-Free Hotline (866-556-3974) for institutions wanting to expedite reporting, and directs victims to USPIS at 1-877-876-2455 or uspis.gov/report.

SAR filing instruction: key term in SAR field 2 and the narrative, and mark the check-fraud box at SAR field 34(d).

SAR key term: FIN-2023-MAILTHEFT · Field 34(d)
Financial Trend Analysis — Mail Theft-Related Check Fraud
Issued September 9, 2024 · covers the six months following the alert

Measures the response to the alert. Key finding: criminals most frequently alter and then negotiate stolen checks; the second most common use is creating counterfeit checks from a stolen check's details. Spanish translation issued December 2024.

Fraud Typologies

Tax Refund Fraud & Identity Theft✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2012-A005 (identified in consultation with the IRS and law enforcement); FIN-2013-A001 reaffirms the same indicators. Verified ≤2026-07 (see changelog)

FRDStolen personal identifying information is used to file fraudulent tax returns claiming refunds, which are then directed to accounts controlled by the fraudster or a money mule. FinCEN issued back-to-back advisories in 2012 and 2013 as this pattern surged alongside the growth of direct-deposit refund distribution.

Mechanics

Fraudsters file early in the tax season — before the legitimate taxpayer files — using stolen Social Security numbers/TINs obtained via phishing or fraudulent tax-preparation businesses, and route refunds to prepaid cards, mule accounts, or accounts newly opened for this sole purpose. Schemes frequently exploit returns for the elderly, minors, prisoners, the disabled, or the recently deceased.

Red flags — as published in FIN-2012-A005

  • Multiple direct-deposit tax refund payments, directed to different individuals, from Treasury or state/local revenue offices are made to a demand deposit or prepaid access account held in the name of a single accountholder
  • A suspicious account is opened on behalf of individuals who are not present, with the fraudulent actor named as having signatory authority, and the account's only funding source is direct-deposited tax refunds
  • One individual opens multiple prepaid card accounts in different names using valid TINs, mails the cards to the same address, then shortly after activation the account receives an ACH tax-refund credit followed quickly by ATM withdrawals or POS purchases
  • A business or personal account processes third-party tax refund checks in a manner or volume inconsistent with its stated business model, or with no apparent lawful purpose
  • A business account shows tax-refund-check activity inconsistent with normal practice — a large volume of Treasury/bank checks relative to other deposits (e.g. payroll), out-of-state customer addresses, sequential or near-sequential check numbers, repeated identical or near-identical dollar amounts, or withdrawal amounts not commensurate with deposited check amounts
  • Multiple prepaid cards share the same physical address, phone number, email address, or IP address, with tax refunds as their primary or sole funding source (fraudsters may also request an address change on a "permanent" card shortly after opening a "temporary" one online)
  • A check-cashing business account is opened and subsequently shows a high volume of tax refund checks issued to individuals nationwide
  • An existing check-cashing service sees a sudden volume increase involving tax refund checks issued to individuals across the United States

Regulatory history

No.DateSubject
FIN-2013-A00102/26/2013Update on tax refund fraud and related identity theft
FIN-2012-A00503/30/2012Tax refund fraud and related identity theft
Fraud Typologies

Money Mule Networks✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2020-A003. Correction from an earlier draft of this article: FinCEN does have a dedicated money-mule advisory (paired with imposter scams, issued in a COVID-19 context but cited generally by later FinCEN products as the reference document for money-mule methodology). Verified ≤2026-07 (see changelog)

FRDMoney mules are the individuals who receive fraud proceeds into accounts they control and forward the funds on — usually overseas — keeping a cut for themselves. They are the connective layer underneath nearly every typology on this page: elder exploitation, BEC, romance scams, and pandemic fraud all rely on mules to actually move stolen money. FinCEN's advisory adopts the FBI's three-part typology: an unwitting mule is unaware they're part of a criminal scheme (motivated by trust in a romance, job, or proposition); a witting mule ignores obvious red flags or acts willfully blind (motivated by financial gain or unwillingness to acknowledge their role); a complicit mule is fully aware and motivated by financial gain or loyalty to the criminal group. DOJ, the FBI, and USPIS separately run an annual interagency "Money Mule Initiative."

Mechanics

A mule opens or uses a personal bank account to receive wires, checks, or unemployment-insurance-style deposits, then withdraws cash, buys money orders, or wires the funds onward to organizers — often abroad — retaining a percentage as compensation. Recruitment commonly happens through good-Samaritan, romance, or work-from-home schemes, where a "recruiter" under a false company or charity label offers home-based employment and then instructs the target to move funds "for the business."

Red flags — as published in FIN-2020-A003

  • A customer's personal account starts receiving transactions inconsistent with their transactional history — overseas transactions, large CVC purchases, large fiat amounts — or a previously low-balance account suddenly sees activity
  • When asked about the change, the customer declines to provide KYC documents or explain the source of funds, and may cite COVID-19, relief work, or a "work-from-home" opportunity
  • A customer opens a new account in a business's name, and shortly after, someone (the accountholder or a third party) transfers the funds back out
  • A customer opens accounts in their own name at multiple banks to receive money from various individuals or businesses, then moves it onward per a purported employer's instructions
  • A customer's account receives multiple state unemployment-insurance payments within the same disbursement window, from one or several states
  • An account receives UI payments for numerous employees, or the accountholder name doesn't match the ACH "remit to" name
  • Deposited funds are quickly wired out to foreign accounts in jurisdictions known for weak AML controls
  • The customer states that an individual they hadn't previously known — claiming to be a U.S. service member stationed abroad, a U.S. citizen working/traveling abroad, or a U.S. citizen quarantined abroad — asked them to send or receive funds through their personal account

Regulatory history

No.DateSubject
FIN-2020-A00307/07/2020Imposter scams and money mule schemes related to COVID-19

The primary federal enforcement response is the interagency Money Mule Initiative (DOJ, FBI, USPIS, Secret Service, and others), now in its fifth-plus annual cycle.

Fraud Typologies

PPP / COVID-19 Relief Loan Fraud✓ SOURCE-VERIFIED

SAR keyword content transcribed from FIN-2021-NTC1. Confirmed: FinCEN never issued a red-flag advisory specific to PPP/EIDL fraud (unlike the parallel unemployment-insurance and money-mule advisories) — its only PPP/EIDL-specific product is this SAR-keyword table. The red flags below remain an editorial summary grounded in DOJ/SBA-OIG case patterns rather than FinCEN's own language. Verified ≤2026-07 (see changelog)

FRDDistinct from the broader pandemic benefits fraud cluster, this typology covers fraud specifically against SBA-guaranteed forgivable loan programs — the Paycheck Protection Program (PPP) and Economic Injury Disaster Loan (EIDL) program — which together generated one of the largest waves of federal fraud prosecutions in U.S. history, including fraud by the lender-side "fintech" companies that processed applications, not just borrowers.

Mechanics

Applicants submit fabricated payroll records, tax documents, or business formation paperwork for shell or nonexistent businesses to qualify for forgivable loans, then spend proceeds on personal luxury goods, real estate, or gambling rather than payroll. On the lender-service-provider side, fintech intermediaries have been prosecuted for knowingly processing loan applications containing fabricated documentation to inflate their own fee revenue.

SAR keywords — as published in FIN-2021-NTC1's government-program table

  • PPP: keyword "Paycheck protection," cite "FIN-2021-NTC1" in field 2, select suspicious-activity field 34(z) (Fraud – Other)
  • EIDL: keyword "Economic injury disaster," cite "COVID19 EIDL FUNDS FRAUD" in field 2, select field 34(z)

FinCEN explicitly discourages generalized key terms like "stimulus," "CARES Act," or "benefit" in favor of these program-specific ones, to speed identification of relevant SARs.

Red flags — editorial, not FinCEN-authored

  • PPP/EIDL proceeds deposited into an account with no history of payroll disbursements, immediately spent on non-payroll items (real estate, vehicles, casino chips)
  • Multiple related businesses or individuals applying for loans using similar or templated supporting documentation
  • Loan proceeds forwarded to accounts unrelated to the borrowing entity shortly after disbursement

Regulatory history

No.DateSubject
FIN-2021-NTC102/24/2021Consolidated COVID-19 SAR key terms and filing instructions (PPP/EIDL keyword table)

PPP/EIDL-specific investigative and enforcement guidance was led primarily by the SBA Office of Inspector General and DOJ's National Center for Disaster Fraud, not a standalone FinCEN red-flag advisory. See Pandemic & Government Benefits Fraud for FinCEN's general pandemic-fraud typologies.

Fraud Typologies

Ponzi & Investment Adviser Fraud✓ SOURCE-VERIFIED

Findings and case examples transcribed from Treasury's 2024 Investment Adviser Risk Assessment (coordinated with FinCEN, FBI, DOJ Criminal Division, and SEC). Confirmed: no FinCEN advisory addresses Ponzi schemes as a discrete typology — the assessment and the SAR form's built-in characterization are the closest primary sourcing available. Verified ≤2026-07 (see changelog)

FRDPonzi schemes pay purported "returns" to earlier investors using money collected from newer investors, rather than from any genuine underlying investment activity. "Ponzi scheme" is one of the standard characterizations of suspicious activity financial institutions can select directly on the FinCEN SAR form. Treasury's assessment found investment advisers defrauding their own clients — "often following a Ponzi or Ponzi-like scheme" — to be the single most common illicit-activity type identified involving the sector, ahead of the sector's use for laundering foreign-corruption or sanctions-evasion proceeds.

Mechanics

A promoter — sometimes a registered investment adviser representative, sometimes entirely unregistered — solicits investor funds promising high, steady returns, then pays earlier investors from newer investors' principal rather than from any genuine trading or asset activity, funding further recruitment until new investment can no longer cover redemptions.

Case examples — from Treasury's 2024 Investment Adviser Risk Assessment

  • Mark Scott, a former law-firm equity partner, was convicted for laundering ~$400 million in proceeds of the OneCoin pyramid-fraud scheme through fake private-equity "Fenero Funds" in the British Virgin Islands, telling banks the money came from wealthy European families; sentenced to 10 years in January 2024
  • Jason Rhodes of Sentinel Growth Fund Management was sentenced to 48 months for defrauding 25+ investors of $25M+, using later investors' funds for Ponzi-style repayments to earlier ones
  • A California-registered adviser was charged in 2019 with running a $7M Ponzi scheme against school-district and hospital employees, veterans, and neighbors, via fictitious "private placements" promising ~5% quarterly dividends

Red flags — editorial, consistent with SEC/Treasury case patterns

  • Consistently high, stable returns regardless of market conditions, with vague or unverifiable descriptions of the underlying strategy
  • Commingling of investor funds rather than segregated, individually tracked accounts
  • New investor deposits used to fund distributions to earlier investors rather than any external trading or asset activity
  • Promoter operating without required securities licenses, or continuing to solicit after license suspension/revocation

Regulatory history

No.DateSubject
Treasury02/20242024 Investment Adviser Risk Assessment

Investment advisers are not currently BSA-defined financial institutions and have no independent SAR/CDD/CIP obligations. FinCEN's rule imposing AML/SAR-filing obligations directly on registered investment advisers (finalized 2024) has been postponed — the effective date moved from January 1, 2026 to January 1, 2028.

Cyber & Digital Assets

Identity Theft & Synthetic Identity Fraud ✓ SOURCE-VERIFIED

Counterfeit passport card red flags transcribed from FIN-2024-NTC1; statistics from the January 2024 Identity FTA. Broader synthetic-identity material is summarised. Verified ≤2026-07 (see changelog)

CYBFRDTreasury's 2026 NMLRA treats identity theft as the largest single driver of money-laundering-relevant BSA filings: FinCEN's own analysis found roughly 1.6 million reports — 42% of all reports filed by reporting institutions — tied to identity, representing $212 billion in suspicious activity. Stolen identities let criminals open accounts, maximize loan draws, divert government benefits, or file false tax returns (see Tax Refund Fraud), while increasingly sophisticated synthetic identities — sometimes AI-generated — are used to open accounts that pass automated verification entirely.

Mechanics

FinCEN's typology work describes two distinct laundering archetypes built on identity theft: money mules, who receive and forward stolen funds through ACH, wire, or CVC, standing between the predicate crime and its final destination; and straw buyers/borrowers, who knowingly let their name, SSN, or credit file be used to open a bank, credit card, auto loan, mortgage, or MSB account for someone else, letting criminals bypass identity-verification controls entirely with genuine (if borrowed) credentials.

Variant: counterfeit U.S. passport cards

FinCEN's 2024 notice with the State Department's Diplomatic Security Service documents a specific, wholly in-person scheme — unusual in a field increasingly dominated by remote fraud. Actors obtain a victim's PII from stolen U.S. Mail or the darknet, then produce a counterfeit passport card carrying the victim's real data with the impostor's photograph, and walk into a branch.

Why passport cards specifically: FinCEN is explicit that they are chosen because they are a less familiar form of government ID — reducing the chance branch staff spot a fake — and are significantly cheaper to counterfeit than passport books.

Tradecraft: actors avoid the branch the victim actually uses, to evade staff who might recognise them. If asked for a second ID they may present a counterfeit credit card in the victim's name — usually also fake and tied to no account. DSS reports they commonly work in pairs, with a handler feeding answers by earpiece from a vehicle outside when the impostor can't answer identity questions.

Three transaction plays once past the branch's controls: (1) probe the account — ask about balances and withdrawal limits — then withdraw cash below the CTR threshold, buy cashier's checks or money orders, or send wires, repeating at other branches to stay under reporting thresholds; (2) cash stolen or forged checks against the account; (3) open a new joint account in person with a second actor as co-owner, move the victim's funds into it, then wire onward to accounts the conspirators fully control.

Red flags — as published in FIN-2024-NTC1

Seventeen indicators across technical, behavioural, and financial categories. The technical set is unusually concrete for a FinCEN product — these are physical inspection tests a teller can perform at the counter.

Technical — inspecting the card itself
  • The photo has a white blurry border, a dark grey square around it, or is in colour. Legitimate cards are laser-engraved, producing a crisp grayscale portrait
  • The photo of the account holder on file doesn't match the person presenting the card
  • The date of birth and other text areas are flat rather than raised — genuine cards have tactile, textured text
  • The holographic Department of State seal is missing or replaced with a seal from an unrelated agency
  • The smaller secondary portrait is blurry, lacks micro-printed bearer-specific text, or the two portraits are of different people
  • The signature doesn't match the customer's signature card on file

DSS's appendix adds further physical checks: a holographic feature over the lower-right of the portrait should animate when tilted; colour-shifting ink on the reverse should move gold-to-green; textured Great Seal artwork should intersect the upper-left of the portrait; under magnification the small portrait should carry legible bearer-specific microtext; and under UV light the invisible printing should be present and continuous across the portrait.

Behavioural — how the person acts
  • The customer cannot reference personal identifiers such as date of birth or SSN
  • Or they can recite identifiers but lack basic account knowledge while being excessively interested in balances and withdrawal limits
  • The customer appears to be following directions by phone from a third party
  • The customer opens a new joint account with a third party they have no prior relationship with
  • The customer transacts at branch locations outside their geographical footprint
Financial — what they attempt
  • Presenting the card then withdrawing cash, buying a cashier's check or money orders, or initiating wires for a large amount with no apparent lawful purpose
  • Attempting to negotiate an uncharacteristic, sudden, or abnormally large volume of checks made payable to cash
  • Asking for daily withdrawal and transfer limits, then withdrawing cash, wiring, or buying a cashier's check payable to a third party
  • Transferring funds from an existing account to a recently established joint account, with funds then rapidly withdrawn or wired to a separate unrelated account
  • Making withdrawals at multiple branch locations with no apparent lawful purpose
  • Behaviour suggesting CTR evasion — altering or cancelling a transaction when told of the filing requirement, or structuring multiple cash withdrawals under $10,000 in one business day

Regulatory history

FIN-2024-NTC1 — Counterfeit U.S. Passport Cards Used for Identity Theft and Fraud
Issued April 15, 2024 · Full PDF · with State Dept Diplomatic Security Service

Verified against the primary document: DSS loss figures ($10M actual/$8M attempted, 4,000+ victims, 2018–2023) match exactly.

Scale: DSS assesses that from 2018 to 2023 these schemes caused $10 million in actual losses and $8 million in attempted losses, with over 4,000 U.S. victims — and states plainly that real losses are likely significantly greater, explicitly asking for increased reporting from financial institutions to surface more.

The document: the U.S. passport card is a REAL ID-compliant identity and travel document issued since July 2008, valid for identity, proof of citizenship, domestic air travel, and land/sea border crossings from Canada, Mexico, the Caribbean, and Bermuda. Counterfeiting or knowingly using one is a federal crime under 18 U.S.C. §1543.

Reporting channel beyond the SAR: institutions are encouraged to refer victims to DSS directly — nearest DSS field office, or DS_DO_USPCFraud@state.gov.

SAR filing instruction: key term in SAR field 2 and the narrative; select SAR field 34(z) (Fraud – Other) with "Passport Card" in the text box. For Form 8300, select Box 1b and put the key term in Comments.

SAR key term: FIN-2024-NTC1 · Field 34(z) "Passport Card"
Case study in the notice — counterfeit passport card fraud
N.D. Tex. · pleaded guilty November 2022 · sentenced March 2023

The defendant received more than 13 years and $1.9 million restitution for conspiracy to commit bank fraud, passport fraud, and aggravated identity theft. He and co-conspirators selected Chase customers with sizeable balances, made counterfeit passport cards bearing those customers' identifying information but conspirators' photographs, used them to open fraudulent joint accounts with money mules, moved funds from the real account into the joint account, then out to a third account controlled solely by the conspirators — the exact three-step play the notice describes.

Financial Trend Analysis — Identity-Related Suspicious Activity: 2021 Threats and Trends
Issued January 2024 · the quantitative backbone for this typology

Identity-related suspicious activity accounted for roughly 42% of all BSA reports and $212 billion in activity, with approximately 69% of those reports indicating impersonation was used to defraud victims. Establishes the framework of exploitation at account opening, account access, and transaction stages that later products including the deepfake alert build on.

Cyber & Digital Assets

Ransomware✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2021-A004. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

CYBRansomware encrypts a victim's systems or data and demands payment — almost always in convertible virtual currency — for restoration or to prevent public release of stolen data. FinCEN's 2021 advisory updated and replaced an October 2020 version following the May 2021 Colonial Pipeline attack, and is supported by three Financial Trend Analyses quantifying ransomware-related BSA filings.

Mechanics

Attackers gain network access (often via phishing, exploited RDP endpoints, or "drive-by" malware), deploy encryption malware, and demand payment to a CVC address — increasingly with "double extortion," exfiltrating data first and threatening publication. Payments typically flow: victim → depository institution → CVC exchange → attacker's CVC address, then through mixers, tumblers, and chain-hopping to launder and cash out, often via foreign exchanges with weak AML/CFT controls. Digital forensic incident response (DFIR) firms and cyber insurance companies (CICs) sometimes directly facilitate payment on the victim's behalf — potentially triggering their own MSB registration obligations. FinCEN named ransomware-as-a-service (RaaS), fileless ransomware, and "big game hunting" of large enterprises as growing trends, and flagged rising use of anonymity-enhanced cryptocurrencies (AECs) such as Monero.

Red flags — as published in FIN-2021-A004

Twelve indicators. No single flag is determinative; financial institutions should weigh the surrounding facts and circumstances.

  • IT enterprise activity connected to ransomware cyber indicators or known threat actors, evident in system logs, network traffic, or file information
  • A customer discloses, at account opening or in other interactions, that a payment is in response to a ransomware incident
  • A customer's CVC address, or an address it transacts with, is connected to known ransomware variants, payments, or related activity
  • An irregular transaction between an organization — especially one in a high-risk sector (government, financial, education, healthcare) — and a DFIR firm or CIC known to facilitate ransomware payments
  • A DFIR or CIC customer receives funds from a counterparty and shortly after sends an equivalent amount to a CVC exchange
  • A customer shows limited CVC knowledge at onboarding yet inquires about or purchases CVC — particularly in large amounts or as a rush request — possibly indicating it is a ransomware victim
  • A customer with no or limited CVC transaction history sends a large CVC transaction outside its normal business practices
  • An unregistered customer appears to use a CVC exchange's liquidity to execute large numbers of offsetting transactions between CVCs, suggesting unregistered MSB activity
  • A customer uses a foreign-located CVC exchanger in a high-risk jurisdiction with inadequate AML/CFT regulation for CVC entities
  • A customer receives CVC from an external wallet and immediately initiates multiple rapid trades among CVCs — especially AECs — with no apparent purpose, followed by an off-platform transaction
  • A customer initiates a transfer of funds involving a mixing service
  • A customer uses an encrypted network (e.g., the onion router/Tor) or an unidentified web portal to communicate with the recipient of a CVC transaction

Regulatory history

No.DateSubject
FIN-2021-A00411/08/2021Ransomware and use of the financial system to facilitate ransom payments
FTA12/04/2025Ransomware trends in BSA data, 2022–2024
FTA11/01/2022Ransomware trends, July–December 2021
FTA10/15/2021Ransomware trends, January–June 2021
FTA12/2025Ransomware trends 2022–2024: ~4,200 incidents, ~$2.1B in payments, per 2026 NMLRA
Cyber & Digital Assets

Convertible Virtual Currency (CVC) Illicit Finance✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2025-NTC1. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

CYBFRDCVCCVC — Bitcoin and similar digital assets convertible to fiat currency — recurs as the payment rail across nearly every modern typology on this page: ransomware, pig-butchering scams, and sanctions evasion all lean on it. FinCEN's foundational 2019 advisory addressed peer-to-peer exchangers, mixers, and CVC kiosks as distinct risk points; the 2025 kiosk-specific notice responded to a rise in scam payments funneled through physical CVC ATMs.

Mechanics

Illicit actors use CVC for its pseudonymity and speed of cross-border movement, layering funds through mixing services, chain-hopping between different cryptocurrencies, and cashing out through exchangers with weak KYC or physical kiosks that accept cash for CVC with minimal identification.

Red flags — CVC kiosks, as published in FIN-2025-NTC1

Fifteen indicators, split by who is looking — kiosk operators, other financial institutions, and banks assessing kiosk-operator customers. That three-audience structure is unusual and useful: the same typology looks different from each vantage point.

For kiosk operators — scam payments (7)
  • Multiple payments just below the $2,000 MSB SAR threshold (or applicable state threshold) from multiple kiosk locations
  • Structuring cash deposits just under the CTR threshold or the kiosk daily limit, using multiple machines or accounts — "smurfing"
  • A customer with limited or no transaction history making a substantial deposit rapidly moved through multiple addresses, commingled with other deposits, or swapped into a different CVC
  • Multiple customers in geographically disparate locations depositing to the same CVC address over a short period while each certifying they own the destination address
  • Multiple customer accounts or transactions linked to the same phone number or wallet address
  • Blockchain analysis showing the destination wallet is associated with fraud or other illicit activity
  • Blockchain analysis showing the destination wallet is associated with an institution tied to TCOs running CVC investment scams
For other financial institutions (3)
  • A customer withdrawing substantial cash from a bank or retirement account in person and indicating they were directed by someone on the phone or internet to deposit it into a CVC kiosk — the single most interceptable moment in the entire scheme
  • An older customer with no CVC history conducting a high-value transaction or series with a kiosk operator
  • Using a debit card for multiple payments below the CTR limit to a kiosk operator
For banks assessing kiosk-operator customers (5)
  • The operator is not registered with FinCEN as an MSB or lacks applicable state licenses
  • The operator fails to collect required customer and transaction information
  • The operator advertises the ability to transact without identification, or with only a phone number or email address
  • Unusually high transaction fees relative to comparable operators, opaque rates and fees, or practices diverging significantly from legitimate operators
  • The operator itself structures cash transactions below the SAR or CTR threshold

Regulatory history

FIN-2025-NTC1 — CVC Kiosks Used for Scam Payments and Other Illicit Activity
Issued August 4, 2025 · Full PDF · Supplements FIN-2019-A003

Verified against the primary document: IC3 complaint/loss figures and kiosk-count growth (4,128 → 37,342) match the FinCEN notice.

Scale: in 2024 IC3 received 10,956+ complaints involving CVC kiosks with roughly $246.7 million in reported losses — a 99% increase in complaint volume and 31% in losses over 2023. U.S. kiosk count grew from 4,128 (January 2019) to 37,342 (January 2025).

Elder concentration: per FTC data, people 60+ were more than three times as likely as younger adults to report a kiosk loss, and more than two of every three dollars lost to kiosk fraud was lost by an older adult. Tech and customer support scams are the most common associated typology — 46% of kiosk-related IC3 crime reports in 2023. Phone calls were the initial contact in about 47% of reported cases, followed by online ads or pop-ups (16%) and email (9%).

The scam choreography: scammers give detailed step-by-step instructions — how to withdraw cash from the bank, locate a kiosk, and send funds using a QR code the scammer supplies encoding their own wallet address — and typically stay on the phone with the victim throughout. They may direct victims to split deposits across multiple lower-value transactions or across multiple different kiosks to defeat thresholds and limits. Scammers often escalate to new mechanisms afterward: wires, or handing cash or gold to a courier.

Why CVC suits scammers: transactions settle instantly and are effectively irreversible on permissionless blockchains, unlike bank or wire transfers pending one to two days. Kiosk fees run 7–20 percent — scammers accept that cost for speed. Proceeds from multiple victims are often aggregated into one wallet, then swapped into stablecoins via cross-chain bridges posing as DeFi services — "chain-hopping". FinCEN notes blockchain analytics can still connect kiosk scam payments made at different times or by different victims.

Non-compliant operators: a 2021 New Jersey investigation found more than a third of kiosk operators in the state weren't registered with FinCEN as MSBs. FinCEN reports scammers direct victims to specific kiosks — sometimes across state lines — likely to avoid operators with strong AML controls. Some operators falsely represent to banks that they're registered while running no AML program; some use personal accounts or accounts in fake business names. FinCEN also stresses that MSB registration is not a license, certification of legitimacy, or endorsement, and any claim otherwise may itself be part of a scam.

Drug nexus: DEA reports TCOs including CJNG increasingly adopt CVC for rapid international transfers, and in high-threat areas may use kiosks as an alternative to bulk cash smuggling. Illinois had roughly 1,626 kiosks with 1,167 in Chicago alone; law enforcement reports individuals traveling from other states to use them.

SAR key term: FIN-2025-CVCKIOSK
Case studies in the notice
Operator-side and victim-side

An unlicensed CVC exchange operator (C.D. Cal., sentenced May 2021) — 24 months for running an unlicensed CVC MSB exchanging up to $25 million through in-person transactions and a kiosk network, charging commissions up to 25%. Notably a former bank employee who had trained others on compliance, he intentionally declined to register. His machines required no identification and permitted multiple consecutive transactions of up to $3,000. After FinCEN contacted him in 2018 he registered but still didn't comply.

$1.49M San Diego retiree case (S.D. Cal., charged April 2024) — a 70-year-old was tricked out of $1.335 million. A pop-up told her to call for help; she was passed through co-conspirators posing as tech support, then as employees of her own financial institutions, told her assets were compromised and needed "securing." She deposited ~$55,700 through kiosks — then, once the scammers learned she had substantial savings, was convinced to buy gold bars and send them to the "U.S. Treasury" for a locker in her name. She lost her life savings.

FIN-2019-A003 — Illicit Activity Involving Convertible Virtual Currency
Issued May 9, 2019 · the foundational CVC advisory this notice supplements

Covers peer-to-peer exchangers, mixers, kiosks, and foreign-located MSBs as distinct CVC risk points. Its definitions of P2P exchanger and unregistered foreign MSB are the ones FinCEN still cites in current products including the 2026 IRGC alert.

Victim recovery: FinCEN's Rapid Response Program (RRP) works with law enforcement to freeze and interdict stolen funds — mostly CVC and wire transfers tied to cyber-enabled fraud — before they leave the traceable financial system. Since 2025, the RRP has interdicted $268M+, bringing its cumulative total to $1.8B+ recovered on behalf of victims.

FinCEN Enforcement Actions

  • The world's largest virtual currency exchange (Nov. 2023) — $3.4B civil money penalty, the largest FinCEN settlement in Treasury Department history, for willfully operating as an unregistered MSB and failing to maintain an effective AML program while serving 1M+ U.S. customers (2017–2023); five-year monitorship and complete exit from the U.S. market required. Part of a $4B+ combined DOJ/FinCEN/OFAC/CFTC resolution.
  • A Seychelles-registered cryptocurrency derivatives exchange (2021) — consent order resolving willful failures to implement a Customer Identification Program, an AML program, and to file SARs, alongside a parallel CFTC resolution.
Cyber & Digital Assets

Darknet Markets✓ SOURCE-VERIFIED

Red-flag list and case study transcribed from the darknet-marketplace section of FIN-2019-A003. FinCEN has not issued a standalone darknet-marketplace advisory — this is one of five typologies within its broader CVC advisory (see Convertible Virtual Currency). Verified ≤2026-07 (see changelog)

CYBDRGFinCEN defines darknet marketplaces as websites available only in anonymized overlay networks (the Tor network is the primary example) requiring specific software to access, some requiring additional vetting. They frequently offer illicit goods and services with CVC as a payment method — sometimes the sole one. CVC use tied to darknet market activity may indicate drug purchases or sales, child exploitation, cybercrime, or other criminal activity. Entities that facilitate CVC transmission on these platforms are required to register as MSBs with FinCEN.

Case study — as published in FIN-2019-A003

AlphaBay / Alexandre Cazes: in July 2017, a multinational law-enforcement effort dismantled AlphaBay, then the largest criminal darknet market, with Thai authorities arresting creator/administrator Alexandre Cazes (a.k.a. Alpha02) on U.S. charges including conspiracy to commit identity theft, narcotics distribution, and money laundering. AlphaBay operated as a Tor hidden service and was used by hundreds of thousands of people over two years to buy and sell fentanyl, heroin, and other illicit products, largely in bitcoin, monero, and ether — approximately 200,000 users, 40,000 vendors, 250,000 listings, and $1 billion+ in CVC transactions between 2015 and 2017.

Red flags — as published in FIN-2019-A003

  • A customer conducts transactions with CVC addresses that have been linked to darknet marketplaces
  • A customer's CVC address appears on public forums associated with illegal activity
  • A customer's transactions are initiated from IP addresses associated with Tor
  • Blockchain analytics indicate the wallet transferring CVC to the exchange has a suspicious transaction history or known-illicit connections
  • A transaction makes use of mixing and tumbling services, suggesting intent to obscure the transaction trail

Regulatory history

FIN-2019-A003's other typologies (unregistered P2P exchangers, unregistered foreign-located MSBs, CVC kiosks) are cross-referenced elsewhere on this page; the ransomware advisory (FIN-2021-A004) and the 2026 NMLRA both treat darknet markets as a related cybercrime-adjacent typology. Enforcement here has run heavily through OFAC designations and DOJ takedowns alongside BSA advisories.

Cyber & Digital Assets

Financial Sextortion✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2025-NTC2. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

CYBHTFinancially motivated sextortion coerces victims — increasingly minors and teens, especially boys aged 14–17 — into sending explicit images, then extorts them for money under threat of releasing the material. Between October 2021 and March 2023, the FBI and DHS received 13,000+ reports involving 12,600+ victims and linked to at least 20 suicides. Perpetrators are frequently based in West Africa and Southeast Asia.

Mechanics

A perpetrator poses as a peer using a stolen profile photo, builds trust (sometimes sending explicit images first), then either extracts explicit content from the victim or takes over their account to extort the victim's contacts too. Payment is demanded via P2P platforms (Apple Pay, Cash App, Zelle) or gift cards; U.S.-based money launderers collect the funds, keep a cut (commonly ~20%), convert the remainder to CVC, and send it to overseas organizers.

Red flags — as published in FIN-2025-NTC2

Nine indicators split into victim-side and mule-side sets. FinCEN's "Jurisdictions of Concern" — the top locations of subjects in sextortion-related BSA reporting, in rank order — are: Côte d'Ivoire, the United States, the Philippines, Monaco, Burkina Faso, the Dominican Republic, Kenya, Benin, and Nigeria.

Victim-side indicators (5)
  • A customer — including a minor with an account co-signed by a parent or guardian — making a series of P2P payments over a short period to a recipient in a Jurisdiction of Concern, especially with no discernible personal connection to that area
  • A minor or young adult making a series of P2P transfers in low, round dollar amounts (e.g. $10–50), totaling hundreds of dollars or less over a short period, to individuals with no prior transaction relationship — where the recipient then rapidly forwards the funds onward
  • Payment memos indicating extortion — "delete the pictures," "please stop" — typically occurring during late night and early morning hours
  • A customer (including a co-signed minor) purchasing CVC through a P2P platform then transferring it to an unhosted wallet with illicit-finance exposure per blockchain analytics, or to a wallet with no prior relationship
  • Multiple uncharacteristic purchases of prepaid access cards, typically redeemed in a different jurisdiction from where they were bought
Money mule account indicators (5)
  • A customer receiving multiple P2P payments from unrelated accounts with no prior interaction, then rapidly forwarding via P2P — FinCEN notes this may indicate a victim being coerced into acting as a mule
  • Many P2P deposits or transfers, often hundreds of dollars or less, over a short period, quickly withdrawn as cash or moved onward with no apparent lawful purpose
  • High volume of transfers to and from accounts in Jurisdictions of Concern with no apparent lawful purpose
  • Multiple P2P payments received then used to buy CVC, transferred to an unhosted wallet with illicit-finance exposure or a wallet hosted by an exchange in a Jurisdiction of Concern
  • Depositing or cashing multiple money orders, often hundreds of dollars or less, from individuals with no prior interaction who may be geographically distant

Regulatory history

FIN-2025-NTC2 — Notice on Financially Motivated Sextortion
Issued September 8, 2025 · Full PDF

Verified against the primary document and FinCEN Director Gacki's contemporaneous statement: the FBI, HSI, and NCMEC figures below match.

Scale and harm: in 2024 the FBI received nearly 55,000 reports of sextortion and extortion crimes with $33.5M in losses — a 59% increase in report volume over 2023. Between October 2021 and July 2025, HSI received 8,483 tips leading to 854 victim identifications, 232 arrests, 96 indictments, and 16 convictions. Most gravely: per NCMEC, at least 36 teenagers have died by suicide since 2021 in response to threatened release of their images. FinCEN notes many victims are over 18, but boys aged 14–17 are the most vulnerable population.

Mechanics: perpetrators create fake accounts or hack real ones, typically posing as an attractive person of the opposite sex around the target's age, researching the victim's social media before contact. Initial contact often occurs on social media or online video gaming platforms, then moves to private messaging or video chat. Extortion can happen within minutes of receiving material, and harassment for further payments usually continues.

Secondary victimization: victims report being targeted again by scammers falsely claiming to be recovery experts, attorneys, or law enforcement agents offering to retrieve the material or "go after the perpetrators," charging high fees.

Payment amounts: negotiation typically follows an initial large demand, since minors have little money. Per BSA reporting, minors typically pay $10–$50; adults typically $500–$2,500. FinCEN notes minor victims may steal from family members to meet demands.

The memo-language evolution — a genuinely important detection point: victim P2P memos historically referenced the extortion ("delete the photos," "please stop"), but law enforcement now observes perpetrators directing victims to use benign or charitable references such as "for orphans" or "for family" specifically to evade institutional scrutiny.

Mule economics and mechanics: mules are recruited via job ads for "transaction managers" or through social media, and criminal networks may leverage U.S. diaspora populations connected to the scammers. Complicit mules typically take a 20 percent fee. Funds are layered across multiple mule P2P and bank accounts, increasingly converted to CVC, sometimes withdrawn as cash, then aggregated and sent overseas either through a money transmitter paying out in local currency or as CVC to a wallet the perpetrator controls. Where victims paid via prepaid card, mules may be tasked with buying electronics or luxury clothing and shipping the goods abroad.

AI-enabled variant: generative AI now lets perpetrators insert a victim's likeness into realistic explicit deepfakes. Since April 2023 the FBI has seen an uptick in victims reporting fake images built from social media content, non-explicit photos the victim provided, or stills captured during video chats — meaning a victim who refuses to send material can be extorted anyway. BSA reporting indicates transactions for illicit AI-generated content often use CVC or prepaid cards.

TAKE IT DOWN Act (May 2025) criminalizes nonconsensual online publication — or the threat of publication — of intimate images including AI-generated deepfakes. NCMEC operates takeitdown.ncmec.org, a free service to remove explicit images of people under 18 from participating websites.

Victim guidance from the notice: report the account via the platform's safety feature; block the predator; save the profile, messages, and images for law enforcement; put the phone in airplane mode until law enforcement can review it; ask a trusted adult for help; and do not send money — cooperating rarely stops the blackmail. Reporting channels: FBI (1-800-CALL-FBI, tips.fbi.gov), DHS Know2Protect Tipline (833-591-KNOW), NCMEC CyberTipline (report.cybertip.org), and for minors directly gethelp@ncmec.org or 1-800-THE-LOST.

SAR filing instruction: key term in SAR Field 2 and the narrative; select SAR Field 38(z) (Other) with "SEXTORTION" in the text box; and if known, enter the subject's IP address in SAR Field 43.

SAR key term: FIN-2025-SEXTORTION · Field 38(z) "SEXTORTION" · IP in Field 43
Case studies in the notice
Both illustrate the offshore-perpetrator / U.S.-mule structure

Two brothers (W.D. Mich., sentenced September 2024) — two Nigerian nationals each received 210 months for conspiracy to sexually exploit minors. They purchased hacked social media accounts, posed as young women, researched victims' schools, workplaces, and family, then solicited explicit images and created collages combining the explicit image with photos of the victim's school, family, and friends as the threat vehicle. Over 100 victims including at least 11 identified minors; a 17-year-old died in March 2022.

A related case (D. Del., superseding indictment 2024) — six defendants, mostly Wilmington, Delaware residents plus a co-conspirator in Abidjan, Côte d'Ivoire, allegedly attempted to extort ~$6.9 million from thousands of potential victims and successfully extorted ~$1.9 million through P2P platforms alone, targeting primarily young men including minors in the U.S., Canada, and the UK. Four payment methods, four cash-out methods, and three separate mechanisms for moving proceeds to Côte d'Ivoire — including re-shipping purchased goods.

FIN-2021-NTC3 — Online Child Sexual Exploitation
Issued September 16, 2021 · see Online Child Sexual Exploitation

The broader OCSE notice. FATF classifies sextortion schemes victimizing minors as a form of OCSE, so the two typologies overlap where the victim is a child.

Cyber & Digital Assets

Deepfake-Enabled Fraud ✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2024-Alert004. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

FRDCYBGenerative-AI "deepfakes" — synthetic audio, video, or images impersonating a real person — are increasingly used to defeat identity-verification controls at account opening or to authorize fraudulent transactions by mimicking a customer's or executive's voice or likeness. FinCEN's 2024 alert was among the first from a U.S. regulator to name this typology directly.

Mechanics

Criminals use GenAI to lower the cost, time, and resources needed to defeat identity verification. Two distinct uses appear in BSA data. First, fraudulent identity documents — altering an authentic source image or generating a synthetic one, then combining it with stolen or entirely fabricated PII to build a synthetic identity. Accounts opened this way receive and launder proceeds of other schemes: check fraud, credit card fraud, authorized push payment fraud, loan fraud, unemployment fraud — and in some cases serve as funnel accounts. Second, social engineering — deepfake voice or video impersonating an executive (an evolution of BEC) or a family member in an emergency scheme, a pattern that targets older victims specifically.

DHS's framing, quoted in the alert, is worth keeping in mind: the threat comes "not from the technology used to create it, but from people's natural inclination to believe what they see" — deepfakes need not be advanced or especially believable to work.

Red flags — as published in FIN-2024-Alert004

Nine indicators. FinCEN's standard caveat applies: no single flag is necessarily indicative, and surrounding facts and circumstances govern.

Document and image indicators
  • A customer's photo is internally inconsistent — showing visual tells of alteration — or inconsistent with their other identifying information (e.g. a date of birth suggesting they are much older or younger than the photo indicates)
  • A customer presents multiple identity documents that are inconsistent with each other
  • A reverse-image lookup or open-source search matches the identity photo to an image in an online gallery of GenAI-produced faces
  • A customer's photo or video is flagged by commercial or open-source deepfake detection software
  • GenAI-detection software flags potential AI-generated text in a customer's profile or responses to prompts
  • A customer's geographic or device data is inconsistent with their identity documents
Verification-avoidance behaviours
  • A customer uses a third-party webcam plugin during a live verification check — which can feed pre-recorded video in place of a live feed
  • A customer attempts to change communication methods during a live verification check, citing excessive or suspicious technological glitches
  • A customer declines to use multifactor authentication to verify their identity
Post-onboarding transaction patterns
  • A newly opened account, or one with little prior transaction history, showing rapid transactions; high payment volumes to potentially risky payees such as gambling websites or digital asset exchanges; or high volumes of chargebacks or rejected payments

Detection and mitigation guidance

FinCEN notes institutions most often catch deepfake documents by re-reviewing account-opening documents after the fact, or through enhanced due diligence triggered by unrelated suspicious activity — rarely at the point of onboarding. Additional scrutiny is warranted where there are inconsistencies among multiple submitted documents, an inability to satisfactorily authenticate identity or source of income, or mismatches between the document and the rest of the customer profile.

Recommended controls: multifactor authentication, particularly phishing-resistant MFA, and live verification checks prompting audio or video confirmation. FinCEN's reasoning is that even where an actor can respond to live prompts or generate synthetic responses, the responses may reveal inconsistencies — which is precisely why deepfake users try to avoid live checks, making the avoidance itself the signal.

Regulatory history

No.DateSubject
FIN-2024-Alert00411/13/2024Fraud schemes involving deepfake media targeting financial institutions
Human Impact Crimes

Human Trafficking & Human Smuggling✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2026-NTC1. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

HTHuman trafficking (compelled labor or commercial sex through force, fraud, or coercion) and human smuggling (facilitating unauthorized border crossing, generally consensual) are distinct crimes with overlapping financial footprints. FinCEN's 2014 guidance was the first to separate financial red flags for each; a 2026 notice extended coverage to the 2026 FIFA World Cup given historical spikes in trafficking risk around major sporting events.

Mechanics

Smuggling proceeds typically move as structured cash payments to smuggling-network facilitators, often through informal remittance channels (see Hawala/IVTS); trafficking proceeds can appear as suspiciously regular deposits inconsistent with a legitimate business (nail salons, massage parlors, agricultural labor contractors) that in fact functions as a front.

Red flags — as published in FIN-2026-NTC1

Ten indicators from the most recent trafficking issuance. FinCEN is explicit that the transactional and behavioral red flags in the 2014 and 2020 advisories remain valid and should be applied alongside these. FinCEN also stresses that customer-facing staff training matters disproportionately here: a trafficking victim may have no contact with anyone outside their trafficker except when visiting a financial institution.

Travel and essential-needs patterns
  • Unusually large local travel expenses in a short period near a major-event host city — multiple hotel rooms, taxi or rideshare fares, train tickets — especially during late night and early morning hours, with no apparent lawful purpose
  • An account with few or no transactions for essential needs (housing, personal products, nourishment, travel), receiving only third-party credits or a paycheck immediately transferred to a single individual or business account — the signature of a trafficker controlling a victim's finances
  • The inverse: an unusually high number of essential-needs transactions — multiple lodging payments, bulk purchases of personal products and food, travel expenses — or bulk purchases of prepaid access cards with no apparent lawful purpose
  • A business account without normal or expected payroll expenditures — payroll nonexistent or extremely low versus comparable businesses in the same industry
Cash and ATM patterns
  • Deposits made somewhere other than where the customer resides, quickly withdrawn in a separate location, with no apparent lawful purpose
  • Frequent ATM cash deposits or withdrawals, especially at gas station ATMs between 10:00pm and 5:00am, often followed by rapid P2P transfer to a separate account. FinCEN notes victims are commonly instructed to deposit cash into easily accessible ATMs and then move the funds onward
P2P transfer patterns
  • Regular P2P transfers from accounts with no prior transactional relationship and no apparent lawful purpose, where payment memos use vague euphemisms disguising payment for commercial sex — "link," "services," "donation," "personal care," "wellness," "advertisements" — with funds then forwarded onward via P2P
  • Frequent P2P transfers from multiple accounts where the customer appears to be consolidating funds others received via P2P, with no apparent lawful purpose
  • Three rapid sequential P2P transfers to three separate accounts — a specific illicit massage business signature, where a customer is expected to pay a door fee, a service fee, and a tip separately
Open-source correlation
  • The phone number associated with an account is listed as a contact method in online commercial sex advertisements — potentially indicating either a victim's or a trafficker's account

Regulatory history

FIN-2026-NTC1 — Notice on the Threat of Human Trafficking During the 2026 FIFA World Cup
Issued May 11, 2026 · Full PDF · Developed with the White House Task Force on the FIFA World Cup 2026

Why a major event changes the risk picture: the tournament ran June 11 – July 19, 2026 across 16 host cities — Atlanta, Boston, Dallas, Houston, Kansas City, Los Angeles, Miami, New York/New Jersey, Philadelphia, San Francisco Bay Area, and Seattle in the U.S.; Toronto and Vancouver in Canada; Guadalajara, Mexico City, and Monterrey in Mexico. FinCEN's framing is that major events don't create trafficking so much as concentrate demand for both licit and illicit services, alongside an influx of visitors, increased anonymity, and surging hotel and lodging activity.

Sex trafficking settings named: public streets and truck stops, illicit massage businesses, escort services, residential brothels, strip clubs, hostess clubs, hotels and motels — with recruitment and advertising running through websites, social media, and other digital platforms.

Payment channels: cash predominates, but also P2P transfers, credit card transactions, and digital assets. Law enforcement and BSA data identified a distinct trend of prepaid access cards being used to pay for commercial sex acts beginning in 2020.

Labor trafficking framing: seemingly legitimate businesses may use exploitative employment to meet surging event demand. Victims are lured by recruiters or misled into believing employment is lawful. The financial signature is wages withheld entirely or partially — showing up as an absence or deviation in expected payroll expenses — or wages transferred from the victim's account to the trafficker, plus minimal transactions for essential needs given the trafficker's financial control.

No victim profile: FinCEN states plainly that there is no specific profile for a trafficked victim — traffickers exploit anyone who can generate illicit profit — while noting DHS-identified higher-vulnerability groups including people who experienced childhood abuse or neglect, youth in foster care and juvenile justice systems, people experiencing homelessness or poverty, survivors of intimate partner violence, unaccompanied children, people displaced by war or disaster, and workers in industries with fewer legal protections.

Reporting posture — important operational instruction: file SARs regardless of threshold and as soon as possible. And critically: if you suspect a customer is a trafficker or a victim, do not approach them with those concerns — contact law enforcement immediately. Report via the National Human Trafficking Hotline (1-888-373-7888, text 233733, or humantraffickinghotline.org/chat), with as much detail about the suspected victim or trafficker as possible.

SAR filing instruction: key term in SAR field 2 and the narrative; select SAR field 38(h) (human trafficking).

SAR key term: FIN-2026-HTWORLDCUP · SAR Field 38(h)
FIN-2020-A008 — Supplemental Advisory on Identifying and Reporting Human Trafficking
Issued October 15, 2020 · remains fully operative

The substantive expansion of FinCEN's trafficking guidance, and the primary source for behavioral indicators (as distinct from transactional ones). FinCEN's 2026 notice explicitly directs institutions back to it rather than superseding it.

FIN-2014-A008 — Recognizing Activity Associated with Human Smuggling and Human Trafficking
Issued September 11, 2014 · remains fully operative

The foundational advisory, and the first to separate financial red flags for smuggling (facilitating unauthorized border crossing, generally consensual) from trafficking (compelled labor or commercial sex through force, fraud, or coercion) — a distinction that still governs how the two are reported.

Human Impact Crimes

Human Smuggling ✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2023-Alert001; trend statistics added from FinCEN's August 13, 2026 Financial Trend Analysis. Document details drawn from the primary FinCEN publications. Verified 2026-08-23

HTTCOFinCEN draws a legal line between this typology and human trafficking that governs how each is reported: smuggling is transporting unauthorized persons into or within the U.S., harboring them, or encouraging entry, knowingly or in reckless disregard of illegal status (8 U.S.C. §1324) — generally a transaction the migrant consents to and pays for. Trafficking requires force, fraud, or coercion (or a minor for sex trafficking). A smuggling case can become a trafficking case once inside the U.S. if the migrant can't pay and is coerced into labor or sex work instead.

Scale and mechanics

Border Patrol encounters at the southwest border rose from under 500,000 in FY2020 to 2.3 million in FY2022. Smuggling generates an estimated $2–6 billion annually along the SW border alone, with per-migrant fees from hundreds of dollars to over $10,000 — about two-thirds of migrants transiting Mexico hire a guide, per FATF. Networks divide into specialized roles (travel arrangements, lodging, border crossing) and typically pay a "protection tax" to whichever TCO controls the territory, sometimes escalating to direct TCO operational control (MS-13 and the 18th Street Gang have run smuggling operations directly).

Two operational phases: solicitation — smugglers pose as travel agencies or work recruiters, typically sharing the migrant's national or ethnic origin to build trust, increasingly via social media; and transportation — coordinated over encrypted platforms, sometimes recruiting unaffiliated U.S.-based truck drivers specifically because they have no knowledge of the network's structure, insulating the organizers from the border-crossing leg's arrest risk.

Three payment structures: full payment in advance; partial payment with the balance due on arrival; or full payment by relatives only after successful arrival. Migrants unable to pay may enter work agreements with smugglers — precisely the point at which smuggling can convert into trafficking.

Laundering channels: primarily cash — bulk cash smuggling and cash purchases of real estate and businesses; funnel accounts at institutions with branches on both sides of the border, receiving smuggling fees disguised as family remittances; and increasingly mobile payment apps and P2P networks to collect fees directly from migrants.

Red flags — as published in FIN-2023-Alert001

Eight indicators, building on the 2014 and 2020 human trafficking advisories.

  • Multiple wires, cash deposits, or P2P payments from different geographic originators across the U.S. or Mexico/Central America, converging on one beneficiary on or around the SW border with no apparent business purpose
  • Deposits by multiple individuals in multiple locations into a single account not affiliated with the account holder's area of residence or work, with no apparent business purpose
  • Unexplained currency deposits followed by rapid wires to high-migrant-flow countries (Mexico, Central America), inconsistent with expected customer activity
  • Frequent exchange of small-denomination for larger-denomination bills by a customer not in a cash-intensive industry
  • Multiple customers wiring the same beneficiary — who is not a relative and may be in the sender's home country — inconsistent with the customer's stated occupation
  • A customer making significantly greater deposits, including cash, than peers in similar professions
  • Cash deposits inconsistent with the customer's line of business
  • Extensive use of cash to purchase assets such as real estate

Financial Trend Analysis — FinCEN, August 13, 2026

FinCEN's most recent analysis of BSA data — 67,540 reports filed between 2023 and 2025 — found financial institutions flagged nearly $5 billion in suspicious activity potentially linked to human smuggling over that three-year span. Reports peaked in 2024, then fell 62% in 2025; the U.S. ranked first for subject locations by country, followed by Mexico, Guatemala, Honduras, and Colombia. MSBs filed about 97% of the reports, most commonly citing transactions outside a customer's usual pattern, money sent along common migration routes, and suspected structuring — with 59% of MSB reports citing no verifiable familial connection between originator and beneficiary as the basis for filing. Depository institutions filed only 3% of reports but accounted for 61% of the total dollar value ($3B+), flagging structuring, funnel accounts, and travel agencies — ranging from sham operations to legitimate businesses potentially facilitating smuggling unwittingly — as their most common typologies.

Regulatory history

FIN-2023-Alert001 — Human Smuggling Along the Southwest Border
Issued January 13, 2023 · Full PDF · builds on the 2014 and 2020 human trafficking advisories

Verified against the primary document: it builds on the 2014 and 2020 advisories as stated, and the SW border encounter/migration context matches.

SAR filing instruction: key term FIN-2023-HUMANSMUGGLING in field 2 and the narrative; select field 38(g) (human smuggling); if trafficking is also suspected, additionally select field 38(h) and note it in the narrative.

SAR key term: FIN-2023-HUMANSMUGGLING · Field 38(g)
Financial Trend Analysis: Human Smuggling
Issued August 13, 2026 · Full PDF · trend/statistics report, not a red-flag advisory

Verified against the primary press release: reports/dollar figures, filer-type breakdown, and top typologies transcribed above match the FinCEN publication.

Human Impact Crimes

Online Child Sexual Exploitation✓ SOURCE-VERIFIED

Content transcribed from FIN-2021-NTC3. Note: this notice is a trend/filing-instruction bulletin rather than a standalone red-flag list — it explicitly directs filers to FIN-2020-A008 (see Human Trafficking) for OCSE-specific financial red flags. Both are primary FinCEN publications. Verified ≤2026-07 (see changelog)

HTFinCEN's 2021 notice calls attention to a sharp rise in online child sexual exploitation (OCSE) — including the funding, production, and distribution of child sexual abuse material (CSAM) — and to the growing role of convertible virtual currency (CVC) in related payments. A distinct 2024 Financial Trend Analysis quantified this activity using BSA data covering January 2020–December 2021.

What the notice documents

FinCEN attributes the pandemic-era rise to increased unsupervised child internet use, more offenders online during travel restrictions, and wider availability of CVC and anonymizing tools. FinCEN's SAR review found a 147% increase in OCSE-related filings between 2017 and 2020, including a 17% year-over-year increase in 2020. CVC is increasingly the payment method of choice for offenders paying for access to CSAM-hosting sites, and facilitators have also been observed using third-party payment processors to obscure illicit file-sharing and streaming activity.

Financially motivated sextortion of minors — a related but financially distinct scheme where the minor is coerced into paying rather than merely victimized — is covered in its own article; see Financial Sextortion.

SAR filing instructions — as published in FIN-2021-NTC3

  • Reference the notice using key term "OCSE-FIN-2021-NTC3" in SAR field 2 and the narrative
  • Select SAR field 38(z) (Other) and include "OCSE" in the text box
  • Include relevant technical/cyber indicators in the narrative where known (e.g. IP addresses, timestamps, CVC addresses) — these materially aid law enforcement investigations

Regulatory history

No.DateSubject
FIN-2021-NTC309/16/2021FinCEN calls attention to online child sexual exploitation crimes
FTA02/13/2024Use of CVC for suspected OCSE and human trafficking, Jan 2020–Dec 2021
Human Impact Crimes

Wildlife Trafficking & Environmental Crime✓ SOURCE-VERIFIED

Content transcribed from FIN-2021-NTC4 and the December 2021 wildlife-trafficking Financial Threat Analysis. FinCEN's notice is structured as five illicit-activity descriptions plus SAR filing instructions rather than a discrete red-flag list. Verified ≤2026-07 (see changelog)

TCOFinCEN treats wildlife trafficking and four related environmental crimes as transnational-organized-crime-adjacent typologies: they are low-risk, high-reward (limited enforcement, high demand, comparatively light penalties), frequently involve transnational organized crime and corruption, and commonly co-occur with money laundering, bribery, forgery, tax evasion, and human or drug trafficking. FinCEN cites wildlife trafficking's estimated $7–23 billion/year in illicit proceeds — roughly a quarter of the legal wildlife trade's value.

The five categories — per FIN-2021-NTC4's appendix

  • Wildlife trafficking — poaching and illegal trade in protected species, parts, and products (ivory, big cats, reptiles, turtles among the most commonly referenced in SAR data)
  • Illegal logging — commingled with legal timber trade; may involve corporate structures and shell companies across jurisdictions to move proceeds through the international financial system
  • Illegal fishing — unreported or unregulated fishing activity laundered through seafood trading businesses
  • Illegal mining — often commingled with legal mining trade; involves corporate structures and shell companies, providing both a proceeds source and a laundering channel for proceeds of other crimes
  • Waste and hazardous substances trafficking — illicit disposal or cross-border movement of waste and hazardous materials

Proceeds from these crimes are laundered through front companies (import/export, timber, or seafood trading firms) using over/under-invoicing techniques seen in TBML.

SAR filing instructions — as published in FIN-2021-NTC4

  • Reference the notice using key term "FIN-2021-NTC4" in SAR field 2 and the narrative
  • Select SAR field 38(z) (Other) and include the most relevant keyword — "wildlife trafficking," "illegal logging," "illegal fishing," "illegal mining," or "waste trafficking" — noting all that apply if multiple offenses are involved
  • Provide all available details on how the wildlife product, plant, or waste was solicited, acquired, stored, transported, financed, and paid for
  • §314(b) information sharing is encouraged for suspected environmental-crime offenses

Regulatory history

No.DateSubject
FTA12/20/2021Illicit finance threat involving wildlife trafficking
FIN-2021-NTC411/18/2021Environmental crimes and related financial activity
Human Impact Crimes

Southeast Asia Scam Compounds✓ SOURCE-VERIFIED

Content transcribed from FinCEN's Huione Group §311 final rule (Oct. 16, 2025) — FinCEN's own most direct action against this ecosystem's laundering infrastructure. Confirmed: FinCEN has not issued a standalone scam-compound red-flag advisory; the CMLN advisory below addresses parallel (Mexico-cartel-facing) laundering infrastructure rather than this typology directly, and behavioral/financial red flags for the scam methodology itself live in the Pig Butchering article (FIN-2023-Alert005). Verified ≤2026-07 (see changelog)

HTFRDTCOA distinct and rapidly growing typology sits at the intersection of human trafficking and romance/investment scams: large, often walled compounds — concentrated in Cambodia, and also found in Myanmar and Laos — where trafficked workers are held under threat of violence and forced to run online fraud schemes against victims worldwide. Treasury estimated Americans lost over $10 billion to Southeast Asia-based scams in 2024 alone.

FinCEN's Huione Group action — as published in the §311 final rule

On October 16, 2025, FinCEN finalized a rule under §311 of the USA PATRIOT Act finding Huione Group — a Phnom Penh, Cambodia-based financial services conglomerate — to be a foreign financial institution of primary money laundering concern, and imposed the fifth special measure: covered U.S. financial institutions are prohibited from opening or maintaining a correspondent account for, or on behalf of, Huione Group (effective November 17, 2025). FinCEN found Huione Group serves as a critical laundering node both for DPRK cyber-heist proceeds and for Southeast Asia-based TCOs running CVC investment ("pig butchering") scams, operating through components including Haowang Guarantee, Huione Pay PLC, and Huione Crypto that together form a self-contained exchange/payment/marketplace ecosystem. FinCEN assessed Huione Group laundered at least $4 billion in illicit proceeds between August 2021 and January 2025.

Mechanics

Organized crime groups recruit workers abroad with fake job offers, then confiscate passports and hold them in guarded compounds under threat of violence, isolation, arbitrary fines, and threats of sexual exploitation. Workers are forced to run pig-butchering and other online scams against victims globally; proceeds are laundered through shell companies, CVC, and Chinese underground banking networks — including marketplace vendors that openly advertise fiat-to-crypto-and-back laundering services — before flowing back to compound operators.

Regulatory history

No.DateSubject
§311 Final Rule10/16/2025Huione Group found a primary money laundering concern; correspondent account prohibition
FIN-2025-A00308/28/2025Chinese money laundering networks used by Mexico-based TCOs (parallel laundering infrastructure)
FTA08/28/2025Chinese Money Laundering Networks: 2020–2024 threat pattern & trend information
Sector Guidance

Casinos & Card Clubs MODERATE RISK✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2008-G007. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

TCOCASINOCasinos are treated as financial institutions under the BSA. FinCEN's earliest sector-specific red-flag guidance (2008) and the 2009 structuring advisory remain the foundational texts, describing how patrons and, at times, complicit personnel use chip purchases and redemptions to structure or launder funds. FinCEN drew the 2008 guidance's examples from actual SARs, examiner observations, and law-enforcement experience.

Red flags — as published in FIN-2008-G007

Evading BSA reporting/recordkeeping thresholds
  • Two or more customers each buy chips with $3,000–$10,000 in currency, gamble minimally, combine chips to exceed $10,000, and one redeems the combined total for a casino check
  • A customer cashing out chips worth $10,000+ reduces the amount below $10,000 when asked for ID to complete a CTRC
  • A customer pays off a $20,000+ credit debt (markers, bad checks) within about a week through a series of currency transactions each kept under $10,000/gaming day
  • A big winner enlists an unrelated third party to cash out part of their winnings to avoid a CTRC or tax form
  • A customer attempts to bribe or conspire with an employee not to file a CTRC
Using the cage as a bank
  • A customer wires non-gaming-derived funds to/through a bank or nonbank financial institution in a country that isn't their residence or place of business
  • A customer treats a casino deposit account as a temporary repository — frequent deposits, then transfers of nearly the full balance to domestic or foreign accounts within 1–2 days
Minimal gaming activity without explanation ("chip walking")
  • Large chip purchase with currency, minimal play, redemption for a casino check
  • Casino markers drawn ($5,000–$10,000), used to buy chips, minimal play, marker paid off in currency, chips redeemed for a check
  • Large deposit in small bills, withdrawn as chips, minimal play, remaining chips exchanged for large bills, a check, or a wire
  • Player-rating records show frequent $5,000–$10,000 currency chip purchases with minimal play and the customer walking away with the chips
  • A slot club customer feeds just-under-threshold cash (e.g. $2,990) into a bill acceptor across multiple machines with minimal play, then redeems the tickets for large bills or checks at different cashiers/times
  • A customer deposits $5,000+ into a front-money account, converts to chips, plays minimally, and exchanges remaining chips for a casino check
Unusual transaction characteristics
  • Paired bettors cover both sides of an even bet (e.g. red/black roulette, with/against the bank in baccarat, pass/don't-pass in craps) with combined wagers over $5,000
  • A customer routinely hedges by betting both teams in sporting events
  • Requests for multiple casino checks under $3,000 each, payable to third parties or with no specified payee
  • ID presented for a CTRC or account opening doesn't match the customer's appearance, or is altered/false
  • CTRC information conflicts across gaming days — different address, driver's license number, or SSN
  • Large deposits or marker payoffs via multiple instruments (cashier's checks, money orders, traveler's checks, foreign drafts) each under $3,000
  • A $30,000+ withdrawal requested as multiple casino checks each under $10,000
  • Large international money transfers paid for via multiple under-$10,000 cashier's checks from different institutions
Criminal activity
  • Transactions the casino believes stem from illegal activity (e.g. narcotics trafficking)
  • Forged signatures or counterfeit checks used to obtain currency, chips, or tokens
Examination Checklist CORE
  1. Confirm chip-walking and minimal-play redemption patterns generate an automated alert, not just manual pit-boss observation.
  2. Test whether casino agents (third-party representatives bringing in high-roller patrons) are themselves subject to CDD as a distinct risk category.
  3. EXPANDED For casinos with a significant international patron program, verify enhanced due diligence traces funding sources for large credit lines extended to foreign players.

Regulatory history

No.DateSubject
FIN-2009-A00307/01/2009Structuring by casino patrons and personnel
FIN-2008-G00707/31/2008Recognizing suspicious activity — red flags for casinos and card clubs

FinCEN Enforcement Actions

  • Trump Taj Mahal Casino Resort (March 2015) — $10M civil money penalty, the largest ever against a casino at the time, for willful and repeated BSA violations dating to 2003: an ineffective AML program, unreported suspicious transactions, and CTR/recordkeeping failures that persisted through two prior examination cycles without remediation. FinCEN had separately fined the same casino $477,700 in 1998.
Sector Guidance

Money Services Businesses (MSBs) HIGH RISK✓ SOURCE-VERIFIED

Regulatory content transcribed from FIN-2012-A001. Note: this advisory sets out registration/compliance obligations rather than a discrete red-flag list — no FinCEN MSB advisory provides one. Corrected an earlier draft, which had borrowed a payment-processor red flag that belongs on the Third-Party Payment Processors page instead. Verified ≤2026-07 (see changelog)

TCOMSBMoney transmitters, currency exchangers, check cashers, and issuers/sellers of traveler's checks, money orders, or stored value face heightened AML obligations given their cash-intensive, often cross-border business. FinCEN's 2012 advisory addressed a specific gap: following a July 2011 final rule amending the MSB definition at 31 CFR §1010.100(ff), a person can qualify as an MSB based on its activities within the United States even if none of its agents, agencies, branches, or offices are physically located here — closing a loophole that let internet- and technology-enabled foreign money transmitters operate in the U.S. market without registering.

What changed — as published in FIN-2012-A001

  • To qualify as an MSB, a person — wherever located — must do business wholly or in substantial part within the United States in one of the seven capacities listed at 31 CFR §1010.100(ff)(1)–(7); a relevant factor is whether the foreign-located person provides services to U.S.-located customers
  • Foreign-located MSBs are BSA financial institutions and, for their U.S. activities, must comply with recordkeeping, reporting, and AML program requirements, and must register with FinCEN
  • They face the same civil/criminal penalties for BSA violations as domestically-located MSBs
  • The final rule requires each foreign-located MSB to appoint a U.S.-resident agent for service of legal process
  • Effective September 19, 2011 (registration/agent-appointment requirements followed once the revised registration form was released in March 2012)

Financial institutions that provide banking services to MSBs should file a SAR if they become aware a customer is operating as an unregistered or unlicensed MSB, and may find FinCEN's 2005 Interagency Guidance and the IVTS advisory (FIN-2010-A011) useful for determining whether a customer is operating as an unregistered money transmitter.

Examination Checklist CORE
  1. Confirm the institution screens MSB customers against FinCEN's MSB registration database, not solely self-reported registration status.
  2. For agent-based MSB relationships (money transmitter agent networks), test whether agent-level SAR filing patterns are monitored for anomalies (an agent with zero SARs despite high volume, or complicit agents facilitating known fraud schemes).
  3. EXPANDED For MSBs with material foreign-located transaction volume, verify enhanced due diligence assesses the foreign counterpart's own AML program adequacy.

Regulatory history

No.DateSubject
FIN-2012-A00102/15/2012Foreign-located money services businesses
FIN-2012-A01010/22/2012Risk associated with third-party payment processors

FinCEN Enforcement Actions

  • A global money-transfer company (Jan. 2017) — $184M civil money penalty (fully credited against a $586M DOJ/FTC forfeiture) for willfully failing to maintain an effective AML program prior to 2012 and failing to file timely SARs, including agent complicity in wire-fraud schemes against consumers.
  • A U.S. money-transfer company (Nov. 2012) — $100M forfeiture under a DOJ deferred prosecution agreement for failing to discipline agents who colluded with fraudsters despite repeated internal warnings. FinCEN later assessed a $1M individual penalty against that company's former Chief Compliance Officer — the first time FinCEN sought a personal penalty against an AML compliance officer — settled in 2017 for $250,000 and a three-year industry injunction.
  • A money-transfer company (2008) — $12M penalty and DOJ deferred prosecution agreement for failing to maintain an effective AML program as a money transmitter.
Sector Guidance

Marijuana / Cannabis Banking Guidance✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2014-G001. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

Unlike most entries on this page, this is compliance-enabling guidance rather than a fraud typology: FinCEN's 2014 guidance tells banks how they *can* serve state-licensed marijuana businesses despite marijuana remaining federally illegal under the Controlled Substances Act. Paired with DOJ's now-rescinded 2013 "Cole Memo" enforcement priorities, it created the practical framework that makes cannabis banking possible at all, and it remains in effect even though the Cole Memo itself was rescinded in January 2018.

The eight Cole Memo priorities — as published in FIN-2014-G001

Preventing: (1) distribution to minors; (2) revenue flowing to criminal enterprises, gangs, and cartels; (3) diversion from legal to illegal states; (4) state-authorized activity as cover for other drug trafficking/illegal activity; (5) violence and firearms in cultivation/distribution; (6) drugged driving and other adverse public-health effects; (7) growing on public lands; (8) possession or use on federal property.

Mechanics

Because marijuana remains federally illegal, financial transactions involving a marijuana-related business technically involve proceeds of illegal activity — so FinCEN created three specific SAR categories to let banks report on these customers routinely rather than exit the relationship entirely: Marijuana Limited (customer appears compliant with state law and implicates no Cole priority), Marijuana Priority (due diligence surfaces a red flag or possible Cole-priority/state-law violation), and Marijuana Termination (the bank exits the relationship for BSA reasons, with the narrative stating the basis; FinCEN urges §314(b) sharing to alert a second institution the business may move to). Banks do not need to treat every cannabis dollar as inherently suspicious — the guidance instead calibrates ongoing due diligence and continuing-activity SAR filings.

Red flags to distinguish Priority SARs — as published in FIN-2014-G001

Using the business as a front to launder other proceeds
  • Revenue substantially exceeds what the state's limitations would reasonably allow, or exceeds local competitors'/demographic expectations
  • Cash deposited exceeds the marijuana revenue reported for tax purposes
  • The business can't show its revenue comes exclusively from state-compliant marijuana sales, versus other illicit drugs, non-compliant marijuana sales, or other illegal activity
  • Excessive cash deposits/withdrawals over a short period relative to local competitors or expected activity
  • Deposits apparently structured to avoid CTR requirements; rapid cash deposit-then-withdrawal cycling
  • Deposits by third parties with no apparent connection to the accountholder
  • Excessive commingling with an owner/manager's personal accounts or with seemingly unrelated businesses' accounts
  • Individuals transacting for the business appear to act on behalf of other, undisclosed parties
  • Financial statements provided are inconsistent with actual account activity
  • A surge in third-party equipment suppliers or shipping servicers doing business with marijuana-related businesses
Other red flags
  • Unable to produce satisfactory documentation of due state licensure and compliant operation
  • Unable to demonstrate the legitimate source of significant outside investment
  • Uses a non-descript entity name ("consulting," "holding," "management") to conceal marijuana-business involvement — e.g. depositing cash that smells like marijuana
  • Public-record checks on the business/owners/managers reveal a criminal record, illegal drug purchase/sale involvement, violence, or other illicit connections
  • The business or related parties are/have been subject to state or local marijuana-regulatory enforcement action
  • International or interstate activity — out-of-state cash deposits, frequent/large interstate transfers, cross-border transacting
  • The business's owner(s)/manager(s) reside outside the state where it's located
  • Located on federal property, or its marijuana was grown on federal property
  • School-proximity rules under state law aren't met
  • A purported "non-profit" engages in inconsistent commercial activity or pays excessive manager/employee compensation

Regulatory history

No.DateSubject
FIN-2014-G00102/14/2014BSA expectations regarding marijuana-related businesses
2020sAdditional FinCEN guidance extending the same framework to hemp-related businesses

Note: because this guidance is designed to enable legitimate banking access rather than flag typical criminal typologies, there is no equivalent "notable prosecutions" list — the relevant enforcement risk runs against banks that fail to file the required Marijuana-category SARs, not against compliant cannabis businesses themselves.

Vulnerability: Financial Institutions

Banks HIGH RISK✓ SOURCE-VERIFIED

Program-adequacy requirements transcribed from the FFIEC BSA/AML Examination Manual, "Assessing the BSA/AML Compliance Program." Note: this is a program-requirements source, not a transactional red-flag list — the institutional indicators below are drawn from its stated pillars and from the enforcement findings cited beneath them. Verified 2026-08-10

BANKBanks sit at the center of every typology on this page — they're where illicit funds ultimately have to land, move, or exit the traceable financial system. Unlike the narrower vulnerabilities elsewhere on this page, "Banks" as a risk category is really about program adequacy: does the institution's AML program actually scale to its transaction volume, and does it act on what its own systems already flag? The single largest FinCEN enforcement action in history answers that question the hard way.

Why it's exploited

A bank with an under-resourced, static, or willfully under-tuned transaction-monitoring program can let enormous volumes of suspicious activity pass entirely unmonitored — not through some novel evasion technique, but simply because the bank stopped updating its detection scenarios as its business and risk profile changed.

The program requirements — as set out in the FFIEC Manual

Every bank's BSA/AML compliance program must be written, board-approved, and — critically — commensurate with the bank's own ML/TF risk profile. The Manual requires the program to provide for: (1) a system of internal controls to assure ongoing compliance; (2) independent testing, by bank personnel or an outside party; (3) designation of an individual responsible for day-to-day compliance (the BSA compliance officer); and (4) training for appropriate personnel — plus risk-based CIP, CDD, and beneficial-ownership procedures. Examiners are told that written policies alone are not sufficient: practices have to correspond with them in fact.

Institutional red flags examiners look for

  • Transaction-monitoring scenarios that haven't been updated or revalidated despite material growth in transaction volume or new product lines
  • A BSA Officer function without the authority, staffing, or budget commensurate with the institution's risk profile — the Manual assigns ultimate responsibility for internal controls to the board of directors acting through senior management
  • A persistent backlog of unresolved or unreviewed alerts, particularly when the backlog itself doesn't trigger an internal escalation
  • Independent testing that doesn't evaluate whether prior violations and deficiencies were actually remediated, not merely represented as complete
Examination Checklist CORE
  1. Confirm transaction-monitoring scenarios and thresholds have been revalidated within the institution's own risk-assessment cycle, not left static for multiple years.
  2. Test whether the BSA Officer has direct, unimpeded escalation authority to senior management and the board — not subordinated to a business-line budget mandate.
  3. Sample the alert-resolution backlog and assess whether volume/age triggers any internal escalation or resourcing response.
  4. EXPANDED For institutions under a prior consent order or MRA, verify the current exam tests whether the specific remediation commitments were actually completed, not merely represented as complete.

FinCEN Enforcement Actions

  • A Canadian-headquartered financial institution (Oct. 2024) — $1.3B FinCEN civil money penalty, the largest ever against a depository institution, part of a $3B+ total resolution with DOJ/OCC/Federal Reserve. From 2018–2024, 92% of that institution's U.S. transaction volume (~$18.3 trillion) went effectively unmonitored because scenarios were left static; the bank facilitated $400M+ in cash transactions for a convicted narcotics-money launderer without limiting his activity. Four-year independent monitorship imposed.
  • Shinhan Bank America (2023) — $15M penalty for willfully disregarding known AML program deficiencies dating to 2015, including failure to timely report suspicious transactions.
  • USAA Federal Savings Bank (2022) — $140M combined penalty ($80M FinCEN + $60M OCC) for failing to scale its AML program as its customer base and revenue grew, missing two remediation deadlines over four years.
  • Capital One (2021) — see Cash-Intensive Businesses: $390M penalty tied to its Check Cashing Group, acquired via a 2006 bank purchase and shut down in 2014 after facilitating $160M+ in transactions for a customer later convicted of money laundering.
  • A large U.S. bank holding company (2018) — ~$600M combined DOJ/FinCEN resolution for capping the number of alerts its transaction-monitoring software could generate, suppressing suspicious-activity review; a former risk officer was individually penalized $450,000 in a related 2020 action — one of the only times FinCEN has penalized an individual bank officer personally.
  • A U.S. bank (March 2010) — $110M penalty (deemed satisfied by a matching DOJ forfeiture), the largest FinCEN action to that date, for AML program failures spanning correspondent banking, remote deposit capture, and — most notably — failing to control $378.4B in transfers connected to Mexican/Colombian casas de cambio, including $10B in bulk cash repatriated from Mexico between 2004–2007.
  • American Express Bank International (Aug. 2007) — $20M penalty (with a separate $5M penalty against its MSB affiliate, American Express Travel Related Services), an early example of FinCEN pairing bank-level and MSB-level penalties against affiliated entities of the same institution.
  • United Bank for Africa, NY Branch (2008) — $15M combined FinCEN/OCC penalty for correspondent-banking program failures persisting despite a prior 2007 cease-and-desist order.
Vulnerability: Financial Institutions

Broker-Dealers & Investment Advisers HIGH RISK✓ SOURCE-VERIFIED

Vulnerabilities and case patterns transcribed from Treasury's February 2024 Investment Adviser Risk Assessment (coordinated with FinCEN, FBI, DOJ, and SEC). Note: this is a sectoral risk assessment with real case examples, not a discrete red-flag list — no FinCEN advisory of that kind exists yet for the IA sector, consistent with advisers sitting outside direct BSA program requirements until 2028. Verified 2026-08-10

BD-IABroker-dealers have been BSA-covered financial institutions for years, but investment advisers are a newer and still-unsettled frontier: FinCEN finalized a rule in 2024 imposing AML/CFT program and SAR-filing obligations directly on registered investment advisers (RIAs) and exempt reporting advisers, but the effective date has since been postponed from January 1, 2026 to January 1, 2028. Until then, advisers sit largely outside direct BSA program requirements even though — as the Ponzi & Investment Adviser Fraud article shows — this is exactly the professional layer through which affinity fraud, Ponzi schemes, and "ramp-and-dump" securities fraud routinely run.

Why it's exploited — as documented in Treasury's IA Risk Assessment

Treasury's risk assessment identifies the core problem as a lack of comprehensive, uniform AML/CFT obligations: investment advisers are not "financial institutions" under the BSA, so — short of a bank or broker-dealer affiliation — they carry no AML program, CDD, CIP, or independent SAR-filing duty. A related vulnerability is that the AML/CFT-obligated entity in the chain (a custodian bank or broker-dealer) often has no direct relationship with the adviser's underlying client, while the adviser who does have that relationship has no duty to look for or report illicit activity. The assessment separately flags nominee arrangements and layered LLC/trust structures that can make it impossible for anyone in the chain to identify the ultimate beneficial owner.

Case patterns identified — as documented in Treasury's IA Risk Assessment

  • Private funds used to pool and launder illicit proceeds tied to foreign corruption, fraud, and tax evasion — Treasury cites cases moving criminal proceeds from the Black Market Peso Exchange, an international pyramid-fraud scheme (OneCoin), and foreign bribery schemes through adviser-formed funds
  • Wealthy Russian individuals and their proxies using advisers and offshore wealth-management structures to invest in U.S. companies, particularly technology firms, while obscuring beneficial ownership
  • Foreign state actors, notably the PRC and Russia, using private funds — especially venture capital vehicles — as a route to equity stakes in U.S. companies developing critical or emerging technologies
  • Advisers defrauding their own clients through Ponzi or Ponzi-like schemes, the most common illicit-activity pattern Treasury identified among IA-related SARs and federal criminal cases

Related typologies

Ponzi & Investment Adviser Fraud is the primary typology exploiting this vulnerability; also see the "ramp-and-dump" securities fraud pattern (China-affiliated VIE stocks pumped via social media, then dumped) that the 2026 NMLRA flags as a fast-growing variant — IC3 logged a 300% year-over-year increase in complaints in H1 2025.

Examination Checklist CORE
  1. Confirm whether the firm is a broker-dealer (fully BSA-covered) versus an RIA/ERA (AML program not yet mandatory pre-2028) and calibrate testing accordingly.
  2. Review new-account documentation for verifiable, independently sourced identity and source-of-funds information, not solely client-supplied representations.
  3. Test whether unusually consistent or high advertised returns trigger any internal escalation, given this is a documented Ponzi-scheme indicator.
  4. EXPANDED For firms voluntarily maintaining AML controls ahead of the 2028 deadline, assess whether SAR-worthy activity (e.g., affinity-group-only solicitation, unverifiable adviser credentials) is being identified and escalated.

FinCEN Enforcement Actions

  • Global broker-dealer (March 6, 2026) — $80M civil money penalty, the largest BSA enforcement action ever against a broker-dealer, for willful failure to implement an effective AML program from 2018–2024, coordinated with parallel SEC and FINRA settlements ($20M each, credited against the FinCEN penalty).
  • Canaccord Genuity LLC (2026) — civil money penalty and disgorgement exceeding $1.2M combined for failing to detect shell-company red flags (see Shell Companies) in a customer relationship.
Vulnerability: Financial Institutions

Complicit Insiders HIGH RISK✓ SOURCE-VERIFIED

Insider-recruitment language transcribed from FIN-2025-A003 (see CMLNs); internal-control mitigations drawn from the FFIEC Manual's BSA/AML Internal Controls section. Note: complicit insiders are a cross-cutting vulnerability, not a typology with its own dedicated FinCEN red-flag advisory — no single document anchors the full list below, so each bullet is sourced separately rather than presented as one advisory's output. Verified 2026-08-10

Every control described elsewhere on this page assumes the people operating it are acting in good faith. Complicit insiders — bank employees, school financial-aid staff, timeshare-resort employees, casino agents, notaries — are the recurring exception, and the 2026 NMLRA treats insider complicity as its own distinct vulnerability rather than folding it into any single typology. FinCEN's most recent explicit statement on the pattern comes from the CMLN advisory (FIN-2025-A003), which warns that Chinese money laundering networks "may recruit financial institution employees to act as complicit insiders or infiltrate and place CMLN members within a financial institution to assist in CMLN operations."

Recurring patterns across this wiki

  • A bank manager or teller disabling account alerts or approving transactions outside normal authority (see BEC, check fraud cases)
  • School financial-aid or admissions staff recruiting straw students and doctoring academic records (see Federal Student Aid Fraud)
  • Timeshare resort employees selling U.S. owner contact information to cartel-run call centers (see Advance-Fee & Timeshare Fraud)
  • A registered casino agent operating an unlicensed money-transmitting side business for high-roller patrons (see Casinos)
  • A recruited or infiltrated financial institution employee facilitating account opening or transaction processing for a laundering network (see Chinese Money Laundering Networks)

Red flags

  • An employee whose personal financial activity is inconsistent with their salary, especially cash-heavy
  • Unusual overrides, waived documentation requirements, or disabled account-monitoring alerts traceable to a specific staff member — the FFIEC Manual assigns the board and senior management ultimate responsibility for internal controls that would catch this
  • An employee consistently handling the same small set of external accounts or customers outside normal rotation
Examination Checklist CORE
  1. Confirm dual-control or maker/checker requirements exist for account overrides, alert dismissals, and documentation waivers.
  2. Sample a set of dismissed or overridden alerts and trace each to the employee who actioned it, checking for concentration in a small number of staff.
  3. Review whether employee accounts themselves are subject to the same transaction-monitoring scrutiny as customer accounts.
  4. EXPANDED For institutions with elevated insider-risk indicators, test whether HR/compliance receive and act on referrals when an employee's lifestyle appears inconsistent with compensation.

FinCEN Enforcement Actions: Individual Accountability

FinCEN has, on rare occasion, penalized individual compliance and risk officers personally rather than only the institution — a notable escalation from institution-level penalties:

  • A former Chief Compliance Officer at a U.S. money-transfer company — the first individual ever penalized personally by FinCEN for AML program mismanagement; initially assessed $1M, ultimately settled for $250,000 plus a three-year industry injunction (2017), after that company itself had already forfeited $100M for agent-complicit fraud (2012).
  • A former risk officer at a large U.S. bank holding company — individually penalized $450,000 (2020) in connection with the bank's "alert-capping" scheme that suppressed suspicious-activity monitoring output; one of the only cases where FinCEN has penalized someone other than an AML/BSA officer specifically.
Vulnerability: Persons & Entities

Politically Exposed Persons (PEPs) HIGH RISK✓ SOURCE-VERIFIED

Red flags transcribed from FIN-2018-A003; regulatory framing drawn from the FFIEC manual's PEP section and 31 CFR §1010.605(p)/§1010.620. Correction from an earlier draft: "PEP" and "senior foreign political figure" (SFPF) are not interchangeable — see below. Verified ≤2026-07 (see changelog)

GATEKEEPER"PEP" is industry shorthand, not a defined BSA term — FinCEN's regulations don't define it. The actual regulatory term is senior foreign political figure (SFPF), a narrower subset of PEP defined at 31 CFR §1010.605(p): a current or former senior official in a foreign government's executive, legislative, administrative, military, or judicial branch; a senior official of a major foreign political party; a senior executive of a foreign government-owned commercial enterprise; an entity formed by or for such a person's benefit; their immediate family; or a known close associate. Section 312 of the USA PATRIOT Act requires enhanced due diligence specifically for SFPF-held private banking accounts (31 CFR §1010.620). Broader "bank-identified PEPs" — the FFIEC's term for anyone a bank chooses to treat as a PEP — are subject only to general risk-based CDD, with no PEP-specific BSA regulation and no FinCEN-defined red-flag list of their own; examiners are explicitly reminded no customer type is automatically higher-risk.

Why it's exploited

An SFPF or PEP relationship gives a corrupt official's family member or associate ordinary-looking banking access; the illicit nature of the funds only becomes apparent when the customer's actual government salary is compared against the scale of assets moving through the account — exactly the mismatch central to every corruption case in this wiki. FIN-2018-A003 documents three typologies specifically: misappropriation of state assets (e.g. falsified national-security disbursement orders funneled through shell entities), use of shell companies to obscure ownership, and exploitation of real estate's opacity and value-laundering properties.

Red flags — as published in FIN-2018-A003

  • Use of third parties in a transaction where that is unusual for the customer or business type
  • Use of third parties that appears designed to shield the identity of a PEP
  • Use of family members or close associates as the legal/registered owners of accounts or entities on a PEP's behalf
  • Use of corporate vehicles (shell companies, LLCs, trusts) to obscure beneficial ownership
  • Engagement with designated non-financial businesses and professions (DNFBPs — real estate agents, precious-metals dealers, attorneys, accountants, company formation agents) that would not normally cater to foreign or high-value clients

FinCEN notes it will update these red flags and typologies as investigation of PEP-facilitator methodologies continues, and explicitly cautions against wholesale or indiscriminate de-risking of PEPs as a class — the bulk are dedicated public servants.

Risk factors for bank-identified PEPs generally — per the FFIEC manual (not red flags; risk-profile inputs)

  • Type of products/services used, and volume/nature of transactions
  • Geographies associated with the customer's activity and domicile
  • The customer's official government responsibilities and level of authority/influence over government activities or officials
  • The customer's access to significant government assets or funds
Examination Checklist CORE
  1. Confirm the institution's CDD program includes a documented process for identifying PEPs at onboarding and on an ongoing basis (not solely at account opening).
  2. For identified SFPF private banking relationships, verify enhanced due diligence per 31 CFR §1010.620 is applied, including source-of-wealth and source-of-funds documentation.
  3. Test whether PEP status is re-screened periodically (e.g., a customer who becomes a PEP after onboarding).
  4. EXPANDED Sample PEP-designated accounts for transaction monitoring calibrated to the elevated risk (lower thresholds, more frequent review) versus standard retail thresholds.
Vulnerability: Persons & Entities

Nonresident Aliens & Foreign Individuals MODERATE RISK✓ SOURCE-VERIFIED

Risk factors transcribed from the FFIEC BSA/AML Examination Manual, "Nonresident Aliens and Foreign Individuals." Note: this section sets out risk factors and CDD risk-mitigation inputs rather than a discrete red-flag list — the Manual does not publish one for this customer type specifically. Verified 2026-08-10

Nonresident alien (NRA) and foreign-individual accounts pose an examiner-recognized risk not because foreign customers are inherently suspect, but because U.S. institutions have structurally weaker tools to verify foreign identity documents, foreign income sources, and foreign tax status than they do for domestic customers. This is a customer-type risk category distinct from any single typology — it recurs as an underlying vulnerability inside student aid fraud "fraudulent accounts" schemes and foreign-student impersonation scams alike. An NRA is defined as a non-U.S. citizen who is not a lawful permanent resident and does not meet the IRS's substantial-presence test, or who has not been issued a green card; the Manual notes NRA deposits in the U.S. banking system have been estimated at hundreds of billions to roughly $1 trillion.

Risk factors — as published in the FFIEC Manual

  • Banks may find it more difficult to verify and authenticate an NRA accountholder's identification, source of funds, and source of wealth
  • The NRA's home country may heighten account risk depending on that country's secrecy laws
  • Because the NRA is expected to reside outside the United States, funds transfers or the use of foreign ATMs may be more frequent
  • BSA/AML risk may be further heightened if the NRA is also a politically exposed person — see PEPs

Factors banks are told to weigh in risk-rating an NRA account — as published in the FFIEC Manual

  • Accountholder's home country
  • Types of products and services used
  • Forms of identification
  • Source of wealth and funds
  • Unusual account activity

Foreign identity documents that cannot be independently verified, and multiple NRA accounts opened in a short window using similar or templated documentation, remain the practical tells examiners look for on top of these Manual-listed factors — consistent with the criminal-broker "one-to-one" account-opening scheme documented in Student Aid Fraud.

Examination Checklist CORE
  1. Confirm CIP procedures specify an alternative, risk-based verification method for foreign identity documents that cannot be checked against a domestic database.
  2. Review NRA account-opening volume for clustering (same IP address, device, or documentation template) consistent with criminal-broker activity.
  3. EXPANDED For NRA accounts with no plausible U.S. nexus, verify a heightened ongoing-monitoring tier applies rather than standard retail thresholds.
Vulnerability: Persons & Entities

Charities & Nonprofit Organizations MODERATE RISK✓ SOURCE-VERIFIED

Risk factors transcribed from the FFIEC BSA/AML Examination Manual, "Charities and Nonprofit Organizations," and the Joint Fact Sheet on BSA Due Diligence for Charities and NPOs. Correction from an earlier draft: the primary source explicitly states the U.S. government does not view the charitable sector as a whole as presenting a uniform or unacceptably high ML/TF risk — this article's earlier framing overstated inherent-sector risk, which the correction below fixes. Verified 2026-08-10

Charities and nonprofits combine three features that make them a distinct examiner-recognized risk category: they often move funds internationally (including to higher-risk jurisdictions) for legitimate humanitarian reasons, they're subject to lighter public financial-disclosure requirements than commercial entities, and donor funds can be diverted or the organization itself can be a knowing front — all without the underlying charitable mission necessarily being fake. This sits adjacent to, but distinct from, terrorist financing typologies, which is the primary predicate risk this vulnerability enables. The FFIEC Manual is explicit that no specific customer type automatically presents higher risk, and that Treasury's 2018 National Terrorist Financing Risk Assessment does not view the charitable sector as a whole as presenting a uniform or unacceptably high risk of ML/TF or sanctions exploitation — banks that reasonably manage the risk are neither prohibited nor discouraged from banking charities and NPOs.

Risk factors — as published in the FFIEC Manual

  • The risk to a bank depends on the facts and circumstances specific to the relationship — transaction volume, type of activity, and geographic locations — not the charity/NPO customer type itself
  • U.S. charities operating and funding solely domestic recipients generally present lower ML/TF risk
  • U.S. charities that operate abroad, fund overseas affiliates, or have affiliated organizations in conflict regions can face potentially higher ML/TF risk

Information the Manual says helps a bank understand the relationship — as published in the FFIEC Manual

  • Purpose and nature of the charity/NPO, including mission, stated objectives, and programs
  • Geographic locations served, particularly higher-risk areas where terrorist groups are most active
  • State incorporation/registration and IRS tax-exempt status, including required regulatory filings
  • General information about donor base, funding sources, and fundraising methods
  • General information about beneficiaries and disbursement criteria, including any intermediaries involved
  • Affiliation with other charities, NPOs, governments, or groups

Within that framing, the practical tells examiners still watch for include a charity's stated program activity bearing no relationship to its actual international wire pattern, cash donations disproportionate to its public visibility or donor base, and overlapping board members, addresses, or accounts across nominally unrelated nonprofits.

Examination Checklist CORE
  1. Confirm CDD for nonprofit customers documents the actual program activity and geography, not just the entity's stated charitable purpose.
  2. Test whether international wire activity is compared against the organization's public filings (e.g., IRS Form 990, including Schedule F for overseas activity) for plausibility.
  3. EXPANDED For nonprofits transacting with higher-risk jurisdictions, verify enhanced monitoring distinguishes legitimate humanitarian/NGO activity from unexplained fund flows.
Vulnerability: Persons & Entities

Independent ATM Owners/Operators MODERATE RISK✓ SOURCE-VERIFIED

Risk factors transcribed from the FFIEC BSA/AML Examination Manual, "Independent Automated Teller Machine Owners or Operators," with the MSB-status point from FIN-2007-G006. Note: the Manual states outright that there are no BSA regulations specific to this customer type, and provides risk factors and CDD inputs rather than a discrete red-flag list. Verified 2026-08-10

Independently owned (non-bank) ATMs are typically serviced with cash the operator sources and loads themselves, then reimbursed by the ATM network — a structure that lets an operator introduce illicit cash into the "load" and have it reimbursed as clean funds through ordinary network settlement. FFIEC treats independent ATM owner/operators as a distinct customer-risk category given how little visibility a bank has into where the cash loaded into a given machine actually came from — though the Manual is explicit that no specific customer type automatically presents higher risk, and that banks reasonably managing the relationship are neither prohibited nor discouraged from banking these customers. FinCEN separately concluded in 2007 that a nonbank ATM owner/operator offering only balance inquiries and cash withdrawals on a depository institution's own customer accounts is not itself an MSB, so most independent ATM operators fall outside AML-program requirements entirely.

Risk factors — as published in the FFIEC Manual

  • Operators who fund ATM replenishment solely with cash withdrawn from their own bank account pose relatively lower risk, since the bank knows the cash source and can compare cash usage to EFT settlements
  • Operators who replenish ATMs from other or unknown cash sources may present higher risk, since the source of that cash is difficult for the bank to verify
  • Commingling cash from illicit and legitimate sources in the ATM can make all transactions in the operator's account appear legitimate, with "clean" ACH settlement funds flowing back to the operator
  • Many states do not register, monitor, or examine independent ATM owner/operators, and — outside the MSB-status determination above — they are generally not required to have AML compliance programs

Information the Manual says helps a bank understand the relationship — as published in the FFIEC Manual

  • Organizational structure, including key principals and management
  • ATM currency-servicing arrangements, contracts, and responsibilities
  • Source of funds if the bank account is not used to replenish the ATM
  • Locations where owned or operated ATMs are placed
  • Expected versus actual ATM activity levels, including currency transactions

Within that framing, the practical tells remain cash-reimbursement requests inconsistent with a machine's location, foot traffic, or historical withdrawal volume, and operators controlling an unusually large machine network relative to the scale of their apparent business — particularly where those machines sit in cash-intensive corridors already elevated by the Cash-Intensive Businesses risk factors.

Examination Checklist CORE
  1. Confirm the institution identifies and separately risk-rates independent ATM owner/operator customers rather than treating them as standard retail business accounts.
  2. Test reimbursement volume against machine location and historical withdrawal data for plausibility.
  3. EXPANDED For operators controlling a large machine network, verify enhanced due diligence covers the source of cash used to load each machine.
Vulnerability: Cash

Cash-Intensive Businesses HIGH RISK✓ SOURCE-VERIFIED

Risk factors transcribed from the FFIEC BSA/AML Examination Manual, "Cash-Intensive Businesses." Document details drawn from the primary publication. Verified 2026-08-10

CASHLegitimate cash-heavy businesses — restaurants, car washes, laundromats, nail salons, convenience stores — provide natural cover for laundering because their real revenue is genuinely hard to verify. Layering illicit cash into a business's reported receipts ("commingling") lets launderers deposit money that never has to answer to a wire transfer's paper trail. The Manual lists convenience stores, restaurants, retail stores, liquor stores, cigarette distributors, privately owned ATMs, vending-machine operators, and parking garages as common examples.

Mechanics — as described in the FFIEC Manual

A launderer buys or already controls a cash-intensive business, then deposits illicit cash alongside legitimate daily receipts; the deposits don't, on the surface, appear unusual because the business is legitimately cash-generating, but the volume of currency will most likely run higher than comparable businesses of the same type in the area. This overlaps heavily with bulk cash smuggling and the fronts used in human trafficking cases (massage parlors, agricultural labor contractors).

Risk factors banks are told to weigh — as published in the FFIEC Manual

  • Purpose of the account
  • Volume, frequency, and nature of currency transactions
  • Customer history, including length of relationship and CTR/SAR filings
  • Primary business activity, products, and services offered
  • Business or business structure
  • Geographic locations and jurisdictions of operations
  • Availability of information and the business's cooperation in providing it

Within that framing, cash deposits inconsistent with a business's apparent customer volume, staffing, or hours remain the core practical tell, together with revenue that runs disproportionately high relative to industry norms for the stated business type.

Examination Checklist CORE
  1. Benchmark cash deposit volume against publicly available industry revenue-per-square-foot or revenue-per-employee norms for the stated business type.
  2. Confirm the institution's risk rating methodology explicitly flags cash-intensive NAICS codes for enhanced monitoring.
  3. Test whether CTR aggregation logic correctly captures related deposits across multiple accounts/locations under common ownership.
  4. EXPANDED For higher-risk cash businesses, verify periodic on-site visits or interviews with management occur, not just document review — a sound practice the Manual specifically calls out.

FinCEN Enforcement Actions

  • Capital One (2021) — $390M penalty tied to its bank-owned Check Cashing Group, which served cash-intensive check-cashing businesses (including some linked to organized crime) from 2008–2014 without adequate SAR/CTR filing, continuing service to a customer even after learning of his pending criminal charges.
  • Brink's Global Services USA (Feb. 2025) — consent order addressing BSA compliance gaps in the armored-transport/cash-logistics business, a sector that sits directly at the intersection of bulk cash handling and institutional cash-intensive risk.
Vulnerability: Financial Products & Services

Credit Cards & Prepaid Access (Gift Cards) MODERATE RISK✓ SOURCE-VERIFIED

Program-level risk factors transcribed from the FFIEC BSA/AML Examination Manual, "Prepaid Access." Correction from an earlier draft: the Manual's prepaid-access risk content is about bank-issued/managed prepaid programs (program managers, GPR cards, load/velocity limits) — the consumer gift-card scam-facilitation angle below is a related but distinct pattern the Manual doesn't itself cover, so it's presented separately rather than blended into one sourced list. Verified 2026-08-10

PREPAIDPrepaid access is FinCEN's regulatory term for funds paid in advance and retrievable later through a card, code, or similar electronic vehicle. Banks often participate as the issuing bank while relying on third parties — program managers, distributors, marketers, and processors — to run the program day to day; some non-bank sellers/providers of prepaid access are themselves regulated as MSBs. Separately, gift cards specifically are the payment method of choice for lower-sophistication scams because they're anonymous, instantly liquid in the scammer's hands, and require no bank account — a victim buys a card at any retailer and reads the code over the phone. They recur constantly across this wiki's fraud articles: tech support scams close almost every call this way.

Risk factors — as published in the FFIEC Manual

  • Higher risk is associated with an anonymous holder, or a holder/purchaser who provides fictitious information
  • Higher risk is also associated with cash access (especially internationally) and the volume/velocity of funds that can be loaded or transacted
  • Funds may be transferred to or from an unknown third party, and cardholder identity verification may be done entirely remotely through third-party program managers, processors, or distributors
  • Prepaid access can be used internationally, avoiding border restrictions and reporting requirements applicable to cash and monetary instruments
  • Specific holder activity may be difficult to determine when reviewed through a pooled account, since underlying data may be held by third parties separate from the issuing bank

Product-feature mitigants — as published in the FFIEC Manual

  • Limits or prohibitions on cash loads, access, or redemption, particularly where holder information is not on file
  • Load/reload velocity limits and controls on the number of cards one individual can purchase
  • Maximum dollar thresholds on ATM and point-of-sale transactions, with velocity limits on each
  • Limits or prohibitions on certain merchant types and on geographic usage outside the United States

Gift-card scam mechanics — editorial, distinct from the Manual's program-risk content above

A scammer directs a victim to purchase gift cards (Apple, Google Play, Target, Amazon, etc.) at a retail store, then read the redemption codes over the phone or send photos of them. The scammer or an associate immediately drains or resells the card codes, often through online marketplaces, converting them to cash or CVC before the victim or retailer can react. FinCEN's Elder Financial Exploitation advisory (FIN-2022-A002) separately lists "an older customer purchases large numbers of gift cards or prepaid access cards" as a financial red flag of elder scams — see Elder Financial Exploitation.

Examination Checklist CORE
  1. Confirm the institution monitors for gift-card purchase patterns on its own credit/debit products (large or repeated same-day purchases).
  2. For prepaid-card program managers: verify KYC scaled to load/reload limits, and monitoring for rapid depletion after loading.
  3. Review staff training materials (if the institution operates retail locations) for scam-recognition scripts at point of sale.
Vulnerability: Financial Products & Services

Peer-to-Peer (P2P) Payments HIGH RISK⚠ EDITORIAL SUMMARY

Red flags here remain an editorial summary. Checked specifically for this verification pass: no FinCEN advisory/alert/notice and no FFIEC Manual section addresses consumer P2P apps (Zelle, Venmo, Cash App, Apple Pay) directly — the closest primary sources (the FFIEC Manual's Third-Party Payment Processors section, and FinCEN's Elder Financial Exploitation advisory FIN-2022-A002) cover adjacent but distinct ground: merchant payment processors and elder-scam payment methods, respectively, not consumer P2P transfers themselves. Consult those linked documents for what they do cover; the list below is not transcribed from any of them. Checked 2026-08-10 — no primary source found

P2PZelle, Cash App, Venmo, and Apple Pay move money instantly between individuals with minimal friction — exactly the property that makes them attractive for legitimate use and for laundering alike. Because transfers settle near-instantly and mimic ordinary peer transactions (splitting a bill, paying a friend back), P2P platforms are now a default settlement rail for financial sextortion, money mule payouts, and student aid fraud refund laundering.

Mechanics

A victim or a compromised account sends P2P funds to a mule-controlled account; the mule immediately forwards the balance onward (often converting to CVC) before the sending institution or victim can dispute the transaction — P2P transfers generally lack the same reversibility as ACH or card transactions.

Red flags

  • An account receiving numerous P2P transfers from unrelated senders with no apparent personal or business connection
  • P2P receipts immediately converted to CVC or forwarded to another account with no dwell time
  • A pattern of P2P payments matching a known extortion or scam cadence (e.g., escalating amounts to a single recipient)
Examination Checklist CORE
  1. Confirm P2P transaction monitoring is integrated with the institution's broader BSA/AML monitoring platform, not siloed as a separate consumer-product system.
  2. Test velocity rules for P2P receipts followed by rapid outbound transfer or CVC purchase.
  3. Review dispute/reversal data to assess whether P2P fraud losses are being captured and fed back into typology detection rules.
  4. EXPANDED For institutions offering P2P as a bank feature (vs. third-party app), verify SAR filings reference the P2P channel explicitly in the narrative.
Vulnerability: Financial Products & Services

Money Orders MODERATE RISK✓ SOURCE-VERIFIED

Regulatory thresholds and risk factors transcribed from the FFIEC BSA/AML Examination Manual ("Purchase and Sale of Certain Monetary Instruments Recordkeeping" and "Purchase and Sale of Monetary Instruments") and 31 CFR §1010.415. Note: this is a recordkeeping/risk-factor source, not a discrete red-flag list — the structuring-pattern red flags below are the practical tells built on top of the sourced thresholds, not a verbatim FinCEN list. Verified 2026-08-10

MOMoney orders offer many of cash's advantages — no bank account required, purchasable at post offices, retailers, and MSBs — with a veneer of an official instrument. They remain a persistent, lower-tech laundering channel, particularly for structuring (buying multiple money orders just under reporting thresholds) and for older victims accustomed to paying by mail.

Why the instrument persists

Money orders sit in an awkward regulatory position: they are prefunded and therefore cannot bounce, they require no bank account, they are sold at post offices, retailers, and MSBs with minimal friction, and they carry the visual authority of an official instrument. That combination makes them attractive both to the legitimately unbanked and to launderers, which is why they have never fully disappeared despite the shift to electronic payments.

Regulatory thresholds — as set out in 31 CFR §1010.415 and the FFIEC Manual

A bank may not issue or sell a money order (or other covered monetary instrument) for $3,000 or more in currency unless it records the purchaser's identity — the $3,000 MSB recordkeeping threshold most structuring around money orders is calibrated to, rather than the $10,000 CTR threshold. The FFIEC Manual notes that customers have been known to purchase monetary instruments in amounts below $3,000 specifically to avoid providing identification, then deposit those instruments to circumvent CTR filing. USPS separately applies its own $3,000 daily purchase limit per customer and a $1,000 domestic per-order cap, so structuring patterns tend to cluster just under $3,000 and across multiple retail locations.

Policy elements the Manual says banks should define — as published in the FFIEC Manual

  • Acceptable and unacceptable monetary-instrument transactions, including noncustomer transactions, blank payees, unsigned instruments, and identification requirements for structured transactions
  • The purchase of multiple sequentially numbered monetary instruments for the same payee, which the Manual flags by name as a pattern to define policy around
  • Procedures for reviewing unusual or suspicious activity and elevating concerns to management
  • Criteria for closing relationships with noncustomers consistently or egregiously involved in suspicious activity

Practical red flags built on the above

  • Sequential or same-day purchases of multiple money orders just under the $3,000 MSB recordkeeping threshold, or under the $10,000 CTR threshold in aggregate
  • Sequentially numbered money orders — indicating single-transaction purchase — later deposited by unrelated parties or at geographically distant locations
  • A single payee or remitter name appearing across money orders bought at different locations by different individuals, the classic smurfing signature
  • Money orders deposited with the payee line blank, incomplete, or completed in different handwriting from the purchaser's
  • Elderly customers purchasing money orders in response to a phone instruction, especially for "fees," "taxes," "bail," or prize claims (see Elder Financial Exploitation)
  • A business account receiving recurring third-party money order deposits inconsistent with its stated customer base
  • Money orders purchased in one jurisdiction and consistently negotiated in another with no apparent connection to either party
  • A customer purchasing money orders immediately after a cash deposit or withdrawal of a similar aggregate value — a conversion pattern with no economic rationale
Examination Checklist CORE
  1. Confirm the $3,000 recordkeeping threshold for money order/traveler's check sales is properly implemented in the MSB's recordkeeping systems.
  2. Sample same-day, multi-location money order purchases for common payee names indicative of structuring.
  3. Verify frontline staff training addresses elder-targeted scam scripts involving money order purchases.
Vulnerability: Financial Products & Services

Insurance MODERATE RISK✓ SOURCE-VERIFIED

Red-flag list transcribed from the FFIEC BSA/AML Examination Manual, "Insurance." Document details drawn from the primary publication; AML program obligations for insurers cited at 31 CFR §1025.210/.320. Verified 2026-08-10

INSLife insurance and annuity products offer a distinctive laundering path: a launderer overfunds a policy (paying more in premium than needed, often in cash or structured deposits), then surrenders it early or borrows against the cash value, receiving a "clean" check from a reputable insurer. Insurance products are also a direct fraud target in their own right — staged accidents, fabricated claims, and elder-targeted annuity churning. FinCEN regulations impose AML program and SAR obligations on insurance companies (not independently on brokers/agents) for a limited set of covered products: permanent life insurance (other than group life), any annuity contract (other than a group annuity), and any other insurance product with cash-value or investment features.

Red flags — as published in the FFIEC Manual

  • Currency used to purchase one or more life insurance policies, subsequently canceled quickly ("early surrender") for a penalty, with the insurer refunding the money by check
  • Submission of inflated or false claims to an insurance carrier — even on a policy without cash value or investment features — to recover part or all of the originally invested payments
  • Borrowing against the cash surrender value of a permanent life insurance policy
  • Selling units in investment-linked products such as annuities
  • Using proceeds from an early policy surrender to purchase other financial assets
  • Buying policies that allow transfer of beneficial interests without the issuer's knowledge or consent (e.g., secondhand endowment and bearer insurance policies)
  • Purchasing insurance products through unusual methods such as currency or currency equivalents
  • Buying products with termination features without concern for the product's investment performance
Examination Checklist CORE
  1. Review premium payment sources for consistency with the policyholder's known income/asset profile.
  2. Test for early-surrender or policy-loan patterns shortly after large or unusual premium funding.
  3. EXPANDED For annuity products marketed to older adults, confirm suitability review procedures flag third-party involvement in the decision process (see Elder Financial Exploitation).
Vulnerability: Legal Entities & Arrangements

Shell Companies HIGH RISK✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2006-G014. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

SHELLFinCEN's definition: non-publicly-traded corporations, LLCs, and trusts that typically have no physical presence beyond a mailing address and generate little to no independent economic value. A shell company is the single most common laundering vehicle on this entire page: it appears inside TBML, CMLN, student aid fraud, health care fraud (nominee-owned DME companies), and correspondent banking schemes alike. As of 2004, GAO counted ~8.9 million corporations and ~3.8 million LLCs registered nationwide (more new LLCs formed that year — 1,068,989 — than corporations, 869,693), and most states don't require disclosure of ownership information at formation or afterward.

Mechanics — nominee services

Agents/nominee incorporation services (NIS) organize entities in any state and can preserve a client's anonymity through nominee officers/directors (public-record placeholders), nominee stockholders (privacy maintained via an irrevocable proxy agreement), and a nominee bank signatory (a fiduciary — e.g. a lawyer or accountant — who opens accounts and relays beneficial-owner instructions to the bank without disclosing their identity). Many states allow corporations, partnerships, and trusts to own and manage LLCs, letting an individual layer ownership until the relationships among individuals and companies become nearly indiscernible even when an owner is known.

Red flags — as published in FIN-2006-G014

  • Inability to obtain information identifying the originator or beneficiary of a wire transfer — via internet search, commercial database, or direct inquiry to the foreign correspondent bank
  • A foreign correspondent bank exceeds its client profile's anticipated wire volume, or a company shows sporadic activity inconsistent with normal business patterns
  • Payments have no stated purpose, don't reference goods or services, or cite only a contract/invoice number
  • A company's goods or services don't match the profile previously provided to the institution
  • Transacting businesses share the same address, list only a registered agent's address, or show other address inconsistencies
  • An unusually large number and variety of beneficiaries receive wire transfers from one company
  • Frequent involvement of beneficiaries in high-risk, offshore financial centers
  • Multiple high-value payments or transfers between shell companies with no apparent legitimate business purpose
Examination Checklist CORE
  1. Confirm CDD file documents a plausible business purpose for the entity and that it's corroborated (website, licensing, physical location) rather than merely asserted.
  2. Screen registered-agent/mailing addresses against other customer entities for common-address clustering.
  3. Test whether beneficial-ownership information collected at onboarding is refreshed on a risk basis, not only at account opening.
  4. EXPANDED For entities with layered or foreign ownership structures, verify enhanced due diligence traces to an identified natural person, not just the immediate corporate owner.

SAR narratives involving suspected shell-company misuse should use the term "shell" and identify originators, beneficiaries, shell entities, and any registered agents or third parties involved.

FinCEN Enforcement Actions

  • Canaccord Genuity LLC (2026-01) — penalty and disgorgement for failing to detect red flags that a customer entity ("ONPH") had the appearance of a shell company, despite indicators available in the firm's own account records.
Vulnerability: Legal Entities & Arrangements

Front Companies HIGH RISK✓ SOURCE-VERIFIED

Red flags transcribed from FIN-2025-A002 (Iranian shadow banking) and FIN-2022-Alert003/FIN-2023-NTC2 (export control evasion) — the FinCEN documents with genuine front-company-specific indicators. No single dedicated FinCEN advisory covers front companies as a standalone typology the way FIN-2006-G014 does for shell companies; the FFIEC manual's Trade Finance section treats them as a TBML sub-topic. Verified ≤2026-07 (see changelog)

SHELLUnlike a pure shell (which does nothing), a front company conducts some genuine business — enough to look legitimate — while its primary purpose is laundering or facilitating illicit activity. This distinction matters operationally: fronts have real invoices, real shipments, and sometimes real employees, making them harder to flag on activity alone. The FFIEC manual's Trade Finance Activities section notes an applicant's true identity may be disguised via "shell companies or offshore front companies," reducing transparency and increasing money-laundering/terrorist-financing risk. The export-control evasion cases in this wiki almost all run through front companies (electronics distributors, freight forwarders) rather than pure shells.

Red flags — as published in FIN-2025-A002 and FIN-2022-Alert003/FIN-2023-NTC2

  • Transactions originate with or are directed to general trading companies, suspected front companies, or entities with an Iran nexus — indicators include opaque ownership structures, individuals/entities with obscure names directing the company, or business addresses that are residential or co-located with other companies, especially previously sanctioned ones (FIN-2025-A002)
  • A customer declares a business purpose inconsistent with other available information — particularly if trade data shows a history of facilitating shipments to and from Iran, or the customer transacts predominantly with technology companies or chemical suppliers (FIN-2025-A002)
  • Multiple companies incorporated around the same time share counterparties, addresses, owners, or name similarities and show similar transaction profiles, often with little to no web presence and large recurring transactions (FIN-2025-A002)
  • A company based in the Middle East with Iran links or front-company indicators receives payments primarily from petroleum companies and pays out primarily to Hong Kong/China electronics companies (FIN-2025-A002)
  • A newly incorporated company, based in a non-GECC country, makes payments for defense or dual-use products (FIN-2022-Alert003/FIN-2023-NTC2)
  • A new customer trades in products tied to the nine High Priority Items List HS codes with no clear commercial rationale (FIN-2022-Alert003/FIN-2023-NTC2)
Examination Checklist CORE
  1. Compare transaction volume against the entity's stated business scale (staffing, facility size, industry norms).
  2. Screen ownership/management against sanctions and export-control enforcement lists, not just the entity name itself.
  3. EXPANDED For entities engaged in cross-border trade in dual-use or export-controlled goods, verify end-use certifications are independently corroborated.
Vulnerability: Legal Entities & Arrangements

Trusts MODERATE RISK✓ SOURCE-VERIFIED

EDD circumstances transcribed from the FFIEC BSA/AML Examination Manual, "Trust and Asset Management Services." Document details drawn from the primary publication. Verified 2026-08-10

Trusts add a further layer of separation between a beneficial owner and their assets — a trustee holds legal title, and depending on the trust's structure and jurisdiction, the actual beneficiary can be extremely difficult for a financial institution to identify. This matters most where real estate or corruption proceeds are placed into a trust-owned property or investment vehicle specifically to defeat beneficial-ownership due diligence. For CIP purposes, the Manual treats the trust itself as the bank's customer, but risk-based procedures may still require gathering information on the settlor, grantor, trustee, or others with authority to direct the trustee.

Circumstances warranting enhanced due diligence — as published in the FFIEC Manual

  • Bank is entering into a relationship with a new customer
  • Account principals or beneficiaries reside in a foreign jurisdiction, or the trust or its funding mechanisms are established offshore
  • Assets or transactions are atypical for the type and character of the customer, or for the bank
  • International funds transfers are conducted, particularly through offshore funding sources
  • Accounts are funded with easily transportable assets such as gemstones, precious metals, coins, artwork, rare stamps, or negotiable instruments
  • Accounts or relationships are maintained in which the identities of the principals, beneficiaries, or sources of funds are unknown or cannot easily be determined
  • Accounts benefit charitable organizations or NGOs that may be used as a conduit for illegal activities (see Charities & NPOs)
  • Account assets include private investment companies (PICs) or asset protection trusts (APTs) — a special form of irrevocable trust typically settled offshore to preserve wealth against creditors
  • Interest on lawyers' trust accounts (IOLTA) holding and processing significant dollar amounts (see Attorneys)
  • Politically exposed persons are parties to any accounts or transactions (see PEPs)
Examination Checklist CORE
  1. Confirm CDD identifies both the trustee and, where obtainable, the settlor and beneficiaries — not the trustee alone.
  2. Screen professional trustees for concentration risk (an unusually high volume of unrelated trusts under one individual).
  3. EXPANDED For foreign or multi-jurisdictional trust structures, verify enhanced due diligence documents a legitimate non-tax, non-secrecy rationale for the structure.
Vulnerability: Gatekeepers

Attorneys MODERATE RISK✓ SOURCE-VERIFIED

Risk factors transcribed from the FFIEC BSA/AML Examination Manual, "Professional Service Providers." Note: this section covers lawyers, accountants, and investment brokers together as bank-account intermediaries — it addresses the bank's own account-relationship risk, not attorney conduct rules; the IOLTA content below is squarely on point for attorneys. Verified 2026-08-10

GATEKEEPERAttorneys occupy a uniquely privileged position: client trust accounts (IOLTA accounts) can move large sums with a professional's imprimatur, and attorney-client privilege can complicate law enforcement's ability to see through the relationship. Unlike banks, attorneys are not themselves BSA-covered financial institutions in most contexts, which is precisely why they're identified as a gatekeeper vulnerability rather than a typology in their own right — the 2017 FinCEN advisory extending SAR-filing expectations to real estate professionals was a direct response to this gap. The FFIEC Manual describes a professional service provider as an intermediary between its client and the bank — an attorney may perform services for a client or arrange services on the client's behalf, such as settling real estate transactions, transferring assets, managing client monies, or handling trust arrangements. A typical IOLTA account holds funds for a lawyer's various clients and functions as a standard bank account, with the interest earned ceded to the state bar association or another public-interest entity.

Risk factors — as published in the FFIEC Manual

  • Unlike an escrow account set up for an individual client, a professional service provider account allows ongoing business transactions with multiple clients — the bank generally has no direct relationship with or knowledge of the account's beneficial owners, who may be a constantly changing group of individuals and entities
  • As with any account presenting third-party risk, the bank could be more vulnerable to potential abuse, including laundering illicit currency, structuring currency deposits and withdrawals, or opening a third-party account for the primary purpose of masking the underlying client's identity
  • Professional service providers cannot be exempted from currency transaction reporting requirements

Within that framing, the practical tells remain an attorney trust account receiving large, unexplained third-party deposits unrelated to any identifiable client matter, real estate or corporate closings structured specifically to avoid a bank's own beneficial-ownership diligence, and an attorney serving as registered agent or nominee for an unusually large number of shell entities.

Examination Checklist CORE
  1. Where the institution itself banks IOLTA/trust accounts, confirm monitoring treats them as elevated-risk given the difficulty of seeing through to the underlying client.
  2. Test whether closing/settlement transactions involving attorney trust accounts receive the same beneficial-ownership scrutiny as a direct customer relationship would.
Vulnerability: Gatekeepers

Accountants MODERATE RISK✓ SOURCE-VERIFIED

Bank-account intermediary risk factors transcribed from the FFIEC BSA/AML Examination Manual, "Professional Service Providers." Note: that section's actual scope is narrower than this article — it addresses accountants only as bank-account intermediaries (alongside lawyers and investment brokers), not as tax-preparer fraud originators. The tax/benefits-fraud-specific red flags below are not transcribed from it; they reflect patterns drawn from the broader DOJ/IRS tax-fraud case record and are labeled as such rather than attributed to the FFIEC source. Verified 2026-08-10

GATEKEEPERAccountants and tax preparers can lend legitimacy to fraudulent business records, prepare fabricated financial statements to support fraudulent loan or grant applications, or actively originate the fraud themselves — publicly reported cases have involved schemes filing thousands of false returns and seeking well over $100M in fraudulent tax credits. The FFIEC Manual separately treats accountants, alongside lawyers and investment brokers, as "professional service providers" when they hold client-pooled accounts at a bank — intermediary accounts the bank generally cannot see through to the underlying client.

The gatekeeper problem

Accountants and tax preparers are not BSA-covered financial institutions, so they carry no independent SAR obligation — yet they produce the documents on which lenders, insurers, and government programmes rely. That asymmetry is the vulnerability: a fabricated financial statement or a falsified return carries a professional's implicit endorsement into a process that has no way to test it.

Three distinct roles recur across the typologies in this reference. Unwitting — the preparer accepts client-supplied figures without scrutiny. Reckless — the preparer sees implausible figures and files anyway, common in the ERC and pandemic-credit cases. Complicit or originating — the preparer designs and drives the scheme, as in the $170M COVID-19 tax credit case involving 1,900+ false returns, and in the fiscal fuel theft OFAC designation of an accountant described as the architect of a cartel's shell-company and customs-document apparatus.

Bank-account intermediary risk factors — as published in the FFIEC Manual

  • Unlike an escrow account for an individual client, a professional service provider account allows ongoing transactions with multiple clients whose identities the bank generally has no direct visibility into
  • Potential abuse includes laundering illicit currency, structuring currency deposits and withdrawals, or opening a third-party account for the primary purpose of masking the underlying client's identity

Tax/benefits-fraud red flags — from the DOJ/IRS case record, not the FFIEC source above

  • A preparer whose clients show implausibly similar or templated financial statements, income figures, or deduction patterns
  • Refunds or programme reimbursements routed to accounts controlled by the preparer rather than the client
  • Fees charged as a percentage of a refund or claim rather than a flat professional fee — a recurring indicator across benefits-fraud cases and generally prohibited for federal tax return preparation
  • A preparer associated with a volume of client filings disproportionate to a practice of that size
  • Client entities sharing a preparer, a registered agent, and a common address — see Shell Companies
  • A preparer or accountant serving as nominee officer, registered agent, or signatory on client entity accounts
  • Amended returns or restated financials filed shortly after a lending or programme decision that depended on the original figures
  • Reluctance to provide workpapers, source documents, or engagement letters supporting statements already relied upon by a lender
Examination Checklist CORE
  1. Screen for refund/benefit deposits routed to a preparer's or accountant's account rather than the client's own account.
  2. Identify preparers associated with a disproportionate volume of client refund filings relative to a typical practice size.
Vulnerability: Gatekeepers

Third-Party Payment Processors HIGH RISK✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2012-A010. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

GATEKEEPERTPPPThird-party payment processors (TPPPs) aggregate payment processing for many merchants under a single relationship with a bank, meaning the bank itself may never see the individual merchants generating the risk. FinCEN's 2012 advisory addressed exactly this blind spot: a single TPPP relationship can quietly onboard fraudulent or high-risk merchants — including health care fraud shell billing companies and student aid fraud criminal brokers — that would never individually pass a bank's own underwriting. TPPPs process credit card payments, ACH debits, and remotely created checks (RCCs)/"demand drafts" on behalf of merchant clients, sometimes via deposit accounts opened in the merchant's own name. Telemarketing, internet sales, and RCC-related merchants carry a comparatively higher fraud/illegal-activity profile.

Red flags — as published in FIN-2012-A010

  • Fraud: high numbers of consumer complaints and/or unusually high return or chargeback rates suggest a merchant is engaged in unfair or deceptive practices, including unauthorized RCCs/ACH debits
  • Accounts at multiple institutions: the processor maintains accounts at more than one institution, or moves between institutions quickly — often to stay ahead of a bank recognizing suspicious activity and terminating the relationship; watch for "check consolidation accounts" used to obscure true return/error rates
  • Money laundering: the processor is used to mask illegal transactions, or to place illegal funds via ACH credits originating from foreign sources
  • Enhanced risk relationships: foreign-located processors serving telemarketers, online businesses, and other merchants
  • Solicitation of distressed banks: the processor targets financially troubled or under-resourced community banks — sometimes even offering to buy the bank's stock — to secure a willing relationship for high-risk merchants
  • Elevated unauthorized-return rate: the processor's aggregate return rate looks normal, but the rate spikes when calculated per individual originator/merchant rather than across the whole book

SAR filing instruction

Check the appropriate suspicious-activity-type box and include the term "Payment Processor" in both the narrative and subject-occupation portions of the SAR.

Regulatory history

No.DateSubject
FIN-2012-A01010/22/2012Risk associated with third-party payment processors
Examination Checklist CORE
  1. Confirm the institution maintains merchant-level (not just TPPP-level) risk visibility, including periodic look-through review of sub-merchants.
  2. Test whether merchant onboarding/offboarding velocity through a given TPPP triggers any automated review.
  3. EXPANDED For TPPPs processing for higher-risk categories (health care billing, government-refund-adjacent services), verify enhanced ongoing monitoring beyond initial underwriting.
Vulnerability: High-Value Goods & Property

Precious Metals, Stones & Jewels (PMSJ) MODERATE RISK✓ SOURCE-VERIFIED

Risk factors transcribed from FIN-2008-G003. Document details drawn from the primary FinCEN publication. Verified ≤2026-07 (see changelog)

HVGGold, gemstones, and jewelry hold value densely, cross borders with far less scrutiny than cash, and can be liquidated globally with minimal documentation — dealers in precious metals, stones, or jewels are themselves defined as BSA-covered "financial institutions" once certain purchase/sale thresholds are met (over $50,000 purchased and $50,000 sold in covered goods in the prior calendar/tax year, for retailers specifically). The "gold bar courier" variant of impersonation scams — where elderly victims are talked into converting savings to physical gold for a mule to collect — is the most visible current example, but PMSJ dealing is also a classic vehicle for corruption and cartel proceeds.

Foreign-supplier risk factors — as published in FIN-2008-G003

  • Whether the supplier's jurisdiction requires AML policies/procedures/internal controls, "know your customer" measures, suspicious- or large-cash-transaction reporting, pre-transaction reporting of suspected ML/TF, procedures for refusing/terminating suspect transactions, or a designated compliance officer
  • Whether the jurisdiction requires industry membership, registration, or licensing, or has a central AML supervisory agency for the sector
  • The dealer's own history and trust with the supplier — longevity alone isn't sufficient; it should be paired with actual knowledge of the supplier's lawful practices and AML compliance

Red flags for identifying a suspicious transaction — as published in FIN-2008-G003

  • Unusual payment methods — large cash amounts, multiple or sequentially numbered money orders, traveler's checks, or cashier's checks, or third-party payments
  • The customer or supplier is unwilling to provide complete and accurate contact information
  • The customer or supplier attempts to maintain an unusual degree of secrecy
  • The transaction is unusual for that particular customer/supplier or type of customer/supplier
  • The transaction doesn't accord with established industry norms

Dealers aren't obligated — or encouraged — to automatically refuse or terminate a transaction just because it raises suspicion; the guidance calls for procedures to identify and reasonably mitigate the risk instead. PMSJ dealers aren't currently required to file SARs but are encouraged to do so voluntarily.

Examination Checklist CORE
  1. Confirm the institution's BSA program correctly scopes PMSJ dealers as covered financial institutions once threshold purchase/sale activity is met.
  2. Test frontline training for gold-bar-courier scam recognition given the sharp rise in this specific pattern.

FinCEN Enforcement Actions

  • A&S World Trading (d/b/a Fine Fragrance) — $275,000 penalty, FinCEN's first enforcement action for violating a Geographic Targeting Order (GTO); the firm failed to report $2M+ in high-risk currency transactions in the Los Angeles Fashion District, an area subject to heightened BSA reporting requirements for trade businesses given its history of TBML and precious-goods laundering.
Vulnerability: High-Value Goods & Property

Art MODERATE RISK✓ SOURCE-VERIFIED

Content transcribed from FIN-2021-NTC2. Note: this notice is a regulatory-update/trend bulletin — it names crime categories and gives SAR filing instructions rather than a standalone red-flag list; the editorial red flags below remain the best available synthesis pending FinCEN's still-unfinished antiquities/art rulemaking (an ANPRM issued Sept. 24, 2021 remains unimplemented as of this writing). Verified ≤2026-07 (see changelog)

HVGHigh-value art sits outside most of the BSA's core coverage — dealers aren't traditionally treated as financial institutions the way banks or PMSJ dealers are — while individual works can be worth tens of millions and change hands with limited standardized provenance or beneficial-ownership disclosure. Section 6110(a) of the AML Act of 2020 amended the BSA's "financial institution" definition to include persons "engaged in the trade of antiquities" and directed FinCEN to issue implementing regulations; FinCEN's March 2021 notice announced this effort and reminded institutions of existing SAR obligations while rulemaking was pending.

Crime categories — as published in FIN-2021-NTC2

Crimes relating to antiquities and art may include looting or theft, illicit excavation of archaeological items, smuggling, and the sale of stolen or counterfeit objects — as well as money laundering and sanctions violations. FinCEN notes links to transnational criminal networks, international terrorism, and the persecution of individuals or groups on cultural grounds.

SAR filing instructions — as published in FIN-2021-NTC2

  • Reference "FIN-2021-NTC2" in SAR field 2 and the narrative; select field 36(z) (Money Laundering – Other) and note whether the activity relates to "Antiquities," "Art," or both
  • Provide available details identifying the object(s) connected to the transaction, and any other related or proposed transactions
  • Include names, identifiers, IP addresses, emails, and phone numbers for the actual purchasers/sellers and their intermediaries or agents
  • Provide the volume and dollar amount of transactions involving the dealer, and any beneficial owner(s) of entities (e.g. shell companies) involved
  • For stolen items, give a detailed description and note whether photographs are available

Red flags — editorial, not FinCEN-authored

  • High-value art purchases paid via wire transfer from an account with no clear connection to art collecting or the buyer's known wealth profile
  • Repeated private sales (versus auction/dealer-brokered) with limited documentation of provenance or true beneficial buyer
  • Use of freeports or bonded storage facilities specifically to avoid import/export scrutiny

Regulatory history

No.DateSubject
FIN-2021-NTC203/09/2021Trade in antiquities and art
Examination Checklist EXPANDED
  1. For institutions financing high-value art purchases, confirm underwriting documents the funding source and cross-checks against the customer's known wealth/CDD profile.
  2. Where the institution provides private banking to art collectors, verify enhanced due diligence covers provenance and the true beneficial purchaser, not only the payer of record.
Vulnerability: High-Value Goods & Property

Luxury Goods & Electronics MODERATE RISK✓ SOURCE-VERIFIED

Red-flag list transcribed from FIN-2022-Alert002. Note: that alert's red flags are scoped specifically to sanctioned Russian elites, oligarchs, and their proxies — it is the closest dedicated FinCEN product on luxury-goods red flags, but it is not a general-purpose luxury-goods laundering list, so that scope is preserved rather than generalized. Verified 2026-08-10

HVGWatches, vehicles, yachts, and consumer electronics serve two laundering functions at once: they store value in an easily resold, portable form, and — as with high-end electronics — they can themselves be the export-controlled commodity at the center of a sanctions-evasion scheme. Fraud proceeds across nearly every typology in this wiki eventually surface as luxury purchases (watches, cars, real estate) — it's one of the most consistent "lifestyle" tells in federal fraud and money-laundering cases generally. FinCEN's dedicated luxury-goods alert (March 2022) defines luxury goods as high-end watches, luxury vehicles, yachts and planes, high-end apparel, high-end alcohol, and jewelry — issued alongside a matching Commerce Department export ban and OFAC's expanded Russia/Belarus sanctions program.

Select red flags — other high-value assets — as published in FIN-2022-Alert002

  • The sudden transfer, including through sales, of ownership in high-value assets and goods by sanctioned Russian elites and their proxies
  • The involvement of legal entities, such as shell companies, with a nexus to sanctioned Russian elites and their proxies, falsely posing as well-known entities and operating in jurisdictions other than that entity's actual jurisdiction and business sphere
  • The involvement of a common set of financial institutions, individuals, or addresses to facilitate luxury goods-related transactions with a nexus to sanctioned Russian elites and their proxies
  • The involvement of law firms based in global and offshore financial centers historically specializing in Russian clientele or transactions associated with sanctioned Russian elites and their proxies
  • The involvement of transportation service companies owned by or with a nexus to sanctioned Russian elites and their proxies, potentially used to transport luxury goods and obfuscate their movement

Select red flags — precious metals, stones & jewelry (PMSJ) — as published in FIN-2022-Alert002

  • Transactions involving PMSJ trading companies, particularly in Asia, and firms with a nexus to sanctioned Russian elites and their proxies
  • High-value or frequent transactions involving mining operations with opaque and complex corporate structures owned or controlled by sanctioned Russian elites or their proxies

Outside that sanctions-specific scope, luxury purchases funded by wire transfers with no correlation to the purchaser's known income, and high-end electronics purchases inconsistent with a buyer's stated business (especially when destined for export), remain the general practical tells for the broader typology described above.

Examination Checklist EXPANDED
  1. For private-banking or wealth customers, confirm large luxury-asset purchase financing is cross-checked against known income/CDD profile.
  2. Where the institution finances vehicle/electronics dealers, test for export-destination red flags on high-value shipments.

Vulnerabilities Index

Mirroring the 2026 NMLRA's own structure, this table cross-references each product, sector, or entity type against the typologies that most commonly exploit it — the reverse view of the typology articles above. Click any vulnerability chip in the sidebar filter to see matching articles highlighted directly. Each vulnerability article also follows the FFIEC BSA/AML Examination Manual's convention of pairing narrative risk factors with a numbered Examination Checklist (tagged CORE for baseline procedures every institution should have, or EXPANDED for risk-triggered enhanced procedures) and a risk rating reflecting the manual's "Quantity of Risk" convention. Note: the risk ratings and examination checklists in this reference are drafted in the FFIEC manual's style but are editorial inferences drawn from the underlying FinCEN/NMLRA source material — they are not official FFIEC or FinCEN designations, and should not be cited as such.

VulnerabilityTypologies most commonly exploiting it
Politically Exposed PersonsCorruption & Kleptocracy
Nonresident Aliens & Foreign IndividualsStudent Aid Fraud, Impersonation Scams
Charities & Nonprofit OrganizationsTerrorist Financing
Independent ATM Owners/OperatorsCash-Intensive Businesses, Structuring
BanksEffectively all typologies — see Correspondent Banking, CMLNs, Bulk Cash Smuggling, BEC
Broker-Dealers & Investment AdvisersPonzi Schemes, ramp-and-dump securities fraud
Complicit InsidersStudent Aid Fraud, Timeshare Fraud, Casinos, BEC
Cash-Intensive BusinessesBulk Cash Smuggling, Human Trafficking, TBML
Credit Cards & Prepaid AccessImpersonation Scams, Elder Exploitation, Tax Refund Fraud
Peer-to-Peer PaymentsFinancial Sextortion, Money Mules, BEC, Student Aid Fraud
Money OrdersStructuring, Elder Exploitation
InsuranceElder Exploitation, Ponzi Schemes
Shell CompaniesTBML, CMLNs, Pig Butchering, Student Aid Fraud, Health Care Fraud
Front CompaniesProliferation Financing
TrustsReal Estate Laundering, Corruption
AttorneysReal Estate Laundering, Shell Companies
AccountantsTax Refund Fraud, Benefits Fraud
Third-Party Payment ProcessorsHealth Care Fraud, MSBs
Precious Metals, Stones & JewelsImpersonation Scams (gold-bar couriers), TBML
ArtCorruption & Kleptocracy
Luxury Goods & ElectronicsProliferation Financing, Corruption
Banks / Correspondent BankingCorrespondent Banking, BEC, TBML, Ransomware
MSBsHawala/IVTS, CMLNs
CasinosStructuring
Real EstateCorruption, BEC (closing fraud)
Cash (bulk/funnel)Bulk Cash Smuggling, Funnel Accounts
Digital Assets (CVC)Ransomware, Pig Butchering, Money Mules, Financial Sextortion

FinCEN Enforcement Actions Index (2006–2026)

These are FinCEN's own civil enforcement actions (consent orders and civil money penalties) against financial institutions themselves for BSA/AML program failures — not against the criminals who exploited the typology, but against the institution whose controls failed to catch it. FinCEN's authority here derives from 31 U.S.C. §5321 and 31 C.F.R. Chapter X; penalties can apply for recordkeeping violations (31 CFR §1010.415), CTR reporting failures (31 CFR §1010.311), or SAR filing failures (31 CFR §1021.320), among others. This index spans the last 20 years, in reverse chronological order.

InstitutionDatePenaltyVulnerability / Typology
Global broker-dealer03/2026$80M (largest ever vs. a broker-dealer)Broker-Dealers & Investment Advisers
Canaccord Genuity LLC2026$1.2M+ (penalty + disgorgement)Shell Companies, Broker-Dealers & IA
Brink's Global Services USA02/2025Consent orderCash-Intensive Businesses, Bulk Cash Smuggling
A Canadian-headquartered financial institution10/2024$1.3B (largest ever vs. a depository institution)Banks, CMLNs, Bulk Cash Smuggling
Shinhan Bank America2023$15MBanks
The world's largest virtual currency exchange11/2023$3.4B (largest FinCEN settlement ever)Convertible Virtual Currency, MSBs
A&S World Trading2022$275,000 (first-ever GTO enforcement action)Precious Metals, Stones & Jewels, TBML
USAA Federal Savings Bank03/2022$140M ($80M FinCEN + $60M OCC)Banks
A Seychelles-registered cryptocurrency derivatives exchange08/2021Consent order (CIP/AML/SAR failures)Convertible Virtual Currency
Capital One (Check Cashing Group)01/2021$390M ($290M net of OCC credit)Cash-Intensive Businesses, Banks
A large U.S. bank / individual risk officer2020$450,000 (individual penalty — first against a bank risk officer)Banks, Complicit Insiders
A large U.S. bank holding company2018~$600M combined (DPA + FinCEN)Banks (alert-capping to suppress SAR volume)
A money-transfer company / its former Chief Compliance Officer2017$250,000 (individual — first CCO ever penalized by FinCEN)MSBs, Complicit Insiders
A global money-transfer company01/2017$184M (credited against $586M DOJ/FTC forfeiture)MSBs, Elder Exploitation (agent-complicit fraud)
Trump Taj Mahal Casino Resort03/2015$10M (largest ever vs. a casino at the time)Casinos, Structuring
A U.S. money-transfer company11/2012$100M forfeiture (DOJ DPA)MSBs, agent-complicit fraud
A money-transfer company2008$12M (DPA)MSBs
United Bank for Africa (NY Branch)2008$15M ($15M FinCEN + $15M OCC, single payment)Banks, Correspondent Banking
Doha Bank (NY Branch)2009$5M ($5M FinCEN + $5M OCC, single payment)Banks, Correspondent Banking
American Express Bank International / American Express Travel Related Services08/2007$20M (bank) + $5M (MSB unit)Banks, MSBs
A U.S. bank03/2010$110M (largest-to-date at the time; deemed satisfied by $110M DOJ forfeiture)Banks, Correspondent Banking, Bulk Cash Smuggling

Full authoritative, continuously updated list: fincen.gov — Enforcement Actions. Earlier actions exist in FinCEN's record before 2007, but civil money penalties were historically rare and smaller in scale prior to the post-2008 financial-crisis and post-9/11 correspondent-banking enforcement buildout reflected here.

SAR Key Terms Glossary

FinCEN maintains an official, continuously updated list of narrative key terms tied to specific advisories (last updated June 2026). A sample of the most-used terms, cross-linked to their typology article above:

Key termUsed for
FUNNEL ACCOUNTFunnel Accounts / TBML
IVTSInformal Value Transfer Systems
BEC FRAUD / EAC FRAUDBusiness Email Compromise
CVCConvertible Virtual Currency
ELDER FINANCIAL EXPLOITATIONElder Financial Exploitation
ACCOUNT TAKEOVER FRAUDBEC/EAC
HECM / FHAMortgage & Foreclosure Fraud
CREFReal Estate Laundering
FIN-2023-PIGBUTCHERINGRomance & Investment Scams
FIN-2026-FSAFRAUDFederal Student Aid Fraud
FIN-2025-OILSMUGGLINGFiscal Fuel Theft (northbound crude)
FIN-2026-FISCALFUELTHEFTFiscal Fuel Theft
FINANCIALINTEGRITY-2026-A002Payroll Fraud & Unlawful Employment
FIN-2022-KLEPTOCRACYCorruption & Kleptocracy
FIN-2023-TFHAMASTerrorist Financing (Hamas)
FIN-2023-ERCBenefits Fraud (Employee Retention Credit)
FIN-2023-CONSTRUCTIONPayroll Fraud (construction)
FIN-2023-RUSSIACRECorruption & Kleptocracy (CRE)
FIN-2022-RUSSIALUXURYCorruption / Luxury Goods
FIN-2023-GLOBALEXPORTProliferation Financing (non-Russia)
FIN-2022-RUSSIABISProliferation Financing (Russia)
FIN-2023-HUMANSMUGGLINGHuman Smuggling
FIN-2023-MAILTHEFTMail Theft-Related Check Fraud
FENTANYL FIN-2024-A002Fentanyl Precursors
FIN-2024-NTC1Identity Theft & Synthetic Identity
FIN-2024-NTC2Advance-Fee & Timeshare Fraud
FIN-2024-FINCENSCAMSImpersonation Scams
FIN-2024-DEEPFAKEFRAUDDeepfake-Enabled Fraud
IRANTF-2024-A001Terrorist Financing (Iran-backed / Hizballah)
IRAN-2025-A002Terrorist Financing (Iran oil/shadow banking)
ISIS-2025-A001Terrorist Financing (ISIS)
FIN-2025-BULKCASHBulk Cash Smuggling
FIN-2025-CVCKIOSKConvertible Virtual Currency
FIN-2025-SEXTORTIONFinancial Sextortion
FIN-2026-MNFRAUDPandemic & Government Benefits Fraud
HCF-2026-A001Health Care Fraud
FIN-2026-HTWORLDCUPHuman Trafficking (World Cup)
FIN-2026-Alert002Terrorist Financing (IRGC)
CMLN-2025-A003Chinese Money Laundering Networks
EFE FIN-2022-A002Elder Financial Exploitation

Full authoritative list: fincen.gov — SAR Advisory Key Terms.

Section 314(b) information sharing. Financial institutions may share suspicious-activity information with one another under a liability safe harbor (USA PATRIOT Act §314(b), 31 C.F.R. §1010.540). The scope is broader than often assumed: FinCEN states institutions may share regarding activities that may involve possible terrorist activity or money laundering, including information about fraud and other specified unlawful activities. FinCEN's stated rationale is that 314(b) lets institutions counter "repeat actors moving across financial institutions to evade detection" — the gap-exploitation problem that appears in the student aid, sextortion, and fiscal fuel theft typologies alike.

Two recent issuances matter operationally: FIN-2025-G001, "Cross-Border Information Sharing by Financial Institutions and SAR Confidentiality" (September 5, 2025), which addresses sharing with foreign financial institutions — FinCEN now routinely encourages U.S. institutions to "use, and potentially expand" those processes in cross-border investigations, language that recurs verbatim across the 2026 advisories; and an updated 314(b) Fact Sheet (June 12, 2026) on fraud information-sharing. Registration is through FinCEN's Financial Institutions portal.

FinCEN Whistleblower Program. Recent alerts increasingly close by promoting it — the student aid, fiscal fuel theft, payroll fraud, and health care fraud advisories all do. Awards are available where information leads to an enforcement action with monetary penalties exceeding $1,000,000, under 31 U.S.C. §5323, with confidentiality protections, anti-retaliation protections, and the option to submit anonymously through an attorney. Its repeated appearance across 2026 products is itself a signal about FinCEN's enforcement posture.

Full Source Index

Primary FinCEN.gov pages consulted for this reference:

Document Citation Registry

Every specific FinCEN advisory/alert/notice/guidance ID cited anywhere in this reference, cross-linked to the article(s) that cite it. Built for auditing: a document cited by more than one article (marked ★) is worth a quick consistency check on each pass, since it's the likeliest place for scope drift between articles to creep in. Where this wiki links directly to the document elsewhere, that link is included here too; unlinked IDs can be looked up in the FinCEN advisories archive.

Document IDCited by
FIN-2006-G014 ★Front Companies, Shell Companies
FIN-2007-G006Independent ATM Owners/Operators
FIN-2008-G001Correspondent Banking & Nested Accounts
FIN-2008-G003Precious Metals, Stones & Jewels (PMSJ)
FIN-2008-G007 ★Casinos & Card Clubs, Structuring (Smurfing)
FIN-2009-A001Mortgage & Foreclosure Fraud
FIN-2009-A003Casinos & Card Clubs, Structuring (Smurfing)
FIN-2010-A001Trade-Based Money Laundering (TBML)
FIN-2010-A005Mortgage & Foreclosure Fraud
FIN-2010-A006Mortgage & Foreclosure Fraud
FIN-2010-A007Trade-Based Money Laundering (TBML)
FIN-2010-A011Informal Value Transfer Systems (Hawala), Money Services Businesses (MSBs)
FIN-2011-A003Elder Financial Exploitation
FIN-2012-A001Money Services Businesses (MSBs)
FIN-2012-A005Tax Refund Fraud & Identity Theft
FIN-2012-A006Trade-Based Money Laundering (TBML)
FIN-2012-A009Mortgage & Foreclosure Fraud
FIN-2012-A010Money Services Businesses (MSBs), Third-Party Payment Processors
FIN-2013-A001Tax Refund Fraud & Identity Theft
FIN-2013-A007Trade-Based Money Laundering (TBML)
FIN-2014-A005Funnel Accounts, Trade-Based Money Laundering (TBML)
FIN-2014-A008Human Trafficking & Human Smuggling
FIN-2014-G001Marijuana / Cannabis Banking Guidance
FIN-2016-A003Business Email Compromise (BEC) & Email Account Compromise (EAC)
FIN-2017-A003Real Estate as a Laundering Vehicle
FIN-2018-A003Politically Exposed Persons (PEPs)
FIN-2018-A006Terrorist Financing
FIN-2019-A003 ★Convertible Virtual Currency (CVC) Illicit Finance, Darknet Markets
FIN-2019-A005Business Email Compromise (BEC) & Email Account Compromise (EAC)
FIN-2019-A006Fentanyl Precursor Chemicals & Manufacturing Equipment
FIN-2020-A003Money Mule Networks
FIN-2020-A007Pandemic & Government Benefits Fraud
FIN-2020-A008 ★Human Trafficking & Human Smuggling, Online Child Sexual Exploitation
FIN-2021-A001Health Care Fraud
FIN-2021-A002Pandemic & Government Benefits Fraud
FIN-2021-A004Darknet Markets, Ransomware
FIN-2021-NTC1PPP / COVID-19 Relief Loan Fraud
FIN-2021-NTC2Art
FIN-2021-NTC3Online Child Sexual Exploitation, Financial Sextortion
FIN-2021-NTC4Wildlife Trafficking & Environmental Crime
FIN-2022-A001Corruption & Kleptocracy
FIN-2022-A002 ★Elder Financial Exploitation, Peer-to-Peer (P2P) Payments, Credit Cards & Prepaid Access (Gift Cards)
FIN-2022-ALERT001Corruption & Kleptocracy
FIN-2022-ALERT002 ★Corruption & Kleptocracy, Luxury Goods & Electronics
FIN-2022-ALERT003 ★Front Companies, Proliferation Financing & Export Control Evasion
FIN-2023-ALERT001Human Smuggling
FIN-2023-ALERT002Corruption & Kleptocracy, Real Estate as a Laundering Vehicle
FIN-2023-ALERT003Mail Theft-Related Check Fraud
FIN-2023-ALERT004Proliferation Financing & Export Control Evasion
FIN-2023-ALERT005 ★Romance & Investment Scams ("Pig Butchering"), Southeast Asia Scam Compounds
FIN-2023-ALERT006Terrorist Financing
FIN-2023-ALERT007Pandemic & Government Benefits Fraud
FIN-2023-NTC1Payroll Fraud & Unlawful Employment Schemes
FIN-2023-NTC2 ★Front Companies, Proliferation Financing & Export Control Evasion
FIN-2024-A001Terrorist Financing
FIN-2024-A002Fentanyl Precursor Chemicals & Manufacturing Equipment
FIN-2024-ALERT003Terrorist Financing
FIN-2024-ALERT004Deepfake-Enabled Fraud
FIN-2024-ALERT005Impersonation Scams
FIN-2024-NTC1Identity Theft & Synthetic Identity Fraud
FIN-2024-NTC2Advance-Fee & Timeshare Fraud
FIN-2025-A001Terrorist Financing
FIN-2025-A002 ★Front Companies, Terrorist Financing
FIN-2025-A003Chinese Money Laundering Networks (CMLNs), Complicit Insiders, Southeast Asia Scam Compounds
FIN-2025-ALERT001Bulk Cash Smuggling
FIN-2025-ALERT002Fiscal Fuel Theft (Huachicol Fiscal)
FIN-2025-ALERT003Payroll Fraud & Unlawful Employment Schemes
FIN-2025-G001Payroll Fraud & Unlawful Employment Schemes
FIN-2025-NTC1Convertible Virtual Currency (CVC) Illicit Finance
FIN-2025-NTC2Financial Sextortion
FIN-2026-A001Health Care Fraud
FIN-2026-A002Payroll Fraud & Unlawful Employment Schemes
FIN-2026-ALERT001Pandemic & Government Benefits Fraud
FIN-2026-ALERT002Terrorist Financing
FIN-2026-ALERT003Fiscal Fuel Theft (Huachicol Fiscal)
FIN-2026-ALERT004Federal Student Aid Fraud (Ghost & Straw Students)
FIN-2026-NTC1Human Trafficking & Human Smuggling

Changelog

Last updated 2026-08-31. Each article's own ✓ SOURCE-VERIFIED note carries a Verified date; articles verified before per-article dating began carry Verified ≤2026-07.