Terrorist Financing✓ SOURCE-VERIFIED
TFPFTerrorist financing covers the movement of funds to designated foreign terrorist organizations (ISIS, Hamas, Hizballah) and to state actors that sponsor or shelter them (Iran, and historically North Korea). FinCEN's advisories in this space typically follow a specific geopolitical trigger — a Treasury/OFAC designation, an escalation in a conflict zone, or a sanctions-evasion scheme uncovered through BSA data — and pair a narrative on the group's financing model with SAR key terms financial institutions should use when filing.
Mechanics
Common financing channels include front companies and trading networks (often layered through trade-based money laundering), exploitation of informal value transfer systems, digital-asset infrastructure used to move funds around sanctioned banking channels, and, for Iran specifically, "shadow banking" networks that mimic correspondent banking relationships using unlicensed money changers.
Red flags — as published in FIN-2026-Alert002
Fourteen indicators in three groups, supplementing (not replacing) those in the June 2025 Iran advisory. Unusually for a FinCEN product, each indicator carries a paired suggested control action. These are set out separately below rather than buried in the indicator text, since they read as de facto supervisory expectations. Note the source itself varies its phrasing — most read "consider," but one uses the stronger "should consider," flagged in gold below.
Oil smuggling (4)
- Shipping companies with Iranian counterparties — a petroleum or shipping company doing business with Iran-tied counterparties, or transporting goods on "shadow fleet" vessels tied to Iran or shown by maritime databases to have called at Iranian ports. Suggested control actionConsider ensuring correspondent account holders conduct due diligence on their customers for prior Iranian connections.
- Shipping documentation irregularities — bills of lading or shipping invoices with no consignees, apparently falsified, or omitting key information to obscure an Iranian nexus. Suggested control actionConsider requiring review of shipping documentation for falsified or missing information where practical.
- Disguised vessel information and ownership — vessels with recent or multiple name or flag changes, or ownership transferred after OFAC designated the owner/operator, where the designated party appears to retain an interest. Suggested control actionConsider requiring vessel due diligence for recent name, flag, or ownership changes, including transfers from sanctioned persons.
- Disguised oil origin — documentation referencing "Malaysian blend" oil, particularly where the vessel is China-bound via Southeast Asia and maritime databases show AIS irregularities during the voyage or a ship-to-ship transfer in an area of concern or without commercial need. Suggested control actionConsider heightened due diligence on any transaction referencing “Malaysian blend” oil.
Shadow banking and front company abuse (4)
- Unclear sources of funds — wires or deposits with missing or incomplete source-of-funds information, or that don't match the customer's line of business, involving entities in a high-risk jurisdiction for Iranian illicit finance. Suggested control actionConsider reviewing relationships showing a pattern of opaque dealings in jurisdictions at high risk for IRGC abuse.
- High-risk company types and jurisdictions — a general trading company with opaque ownership registered in a UAE (or similar) commercial free trade zone, whose counterparties sit mostly in Singapore and Hong Kong, holding accounts at multiple institutions in China, Hong Kong, Oman, or the UAE. Suggested control actionConsider heightened due diligence on company types at high risk for IRGC abuse.
- Front company transaction patterns — a Hong Kong-registered company banking through a Chinese non-resident account with little or no web presence, co-located with numerous similar companies, or recently incorporated yet transmitting large round-dollar payments with no adequate source-of-funds explanation, or making numerous large payments to UAE general trading companies or free-trade-zone intermediaries with no clear business purpose. Suggested control action — stronger phrasing in sourceShould consider heightened due diligence on recently formed companies transacting in unusually high amounts with Iranian shadow banking payment patterns.
- Unusual use of exchange houses — transactions moving through multiple exchange houses and/or trading companies, accumulating fees as they progress, where the fees, transaction count, or pattern don't reflect standard commercial practice. Suggested control actionConsider heightened due diligence on customers making frequent or unusual use of exchange houses in high-risk jurisdictions.
Digital assets (6)
- Unusual digital asset payments by petroleum, shipping, trading, or trust companies — a company with potential Iranian oil exposure deviating from normal business practice to send or receive payment in digital assets. Suggested control actionConsider heightened due diligence where the underlying transaction could relate to Iranian oil.
- Stablecoin payments with unclear source of funds — a customer in a high-risk jurisdiction receiving a stablecoin payment inconsistent with their line of business, failing to provide source-of-funds information or providing documentation suggesting an Iranian link.
- Unusual stablecoin account activity — a stablecoin issuer's customer, particularly a foreign entity such as an overseas purported trust company, opening an account then engaging in minting activity requiring multiple rate or limit increases in a short period, or otherwise transacting inconsistently with its reported profile.
- Payments to or from an Iran-located DASP — blockchain analysis showing a customer account transacted directly or indirectly with an address attributed to an Iranian entity. Suggested control actionConsider using blockchain analytics to identify transactions connected to known Iranian entities.
- Iran-related cyber indicators — activity logs showing connections from Iranian IP addresses; shared IPs or devices with users previously identified as having an Iranian nexus; authentication via an Iranian email service or telephone number; or device time zone, language, and settings consistent with Iran. FinCEN notes VPN, residential proxy, or Tor exit node use combined with other Iran-location evidence may indicate geofencing circumvention — and asks institutions to supply technical detail (IP addresses with timestamps, device identifiers, indicators of compromise) in the report.
- Unregistered P2P exchangers, foreign-located MSBs, and nested DASPs — e.g. a DASP customer in a high-risk jurisdiction appearing to use the DASP's own liquidity to execute large numbers of offsetting transactions.
Regulatory history
The structural point: entities function as IRGC instruments — moving funds, converting assets, acting on behalf of sanctioned actors — even where the companies themselves are not formally identified as IRGC-owned. Front company accounts outside Iran let sanctioned entities transact through the international financial system without ever repatriating funds to Iran. That's the detection problem in one sentence.
Scale from the October 2025 Iranian Shadow Banking FTA: oil companies potentially linked to Iran transacted roughly $4 billion in 2024; dozens of shipping companies (mostly Iraq, UAE, Hong Kong) moved approximately $707 million through U.S. correspondent accounts in the same year; and likely shell companies matching both shell and Iranian indicators moved $5 billion in 2024, primarily from non-resident accounts at Chinese banks operated by Hong Kong companies into the UAE.
The oil chain: shadow/ghost/dark fleet vessels — old, poorly maintained, operating outside standard maritime regulation, owned or leased by non-Iranian front companies — carry oil blended with third-country product or relabeled by forged documents, most commonly as "Malaysian blend," with the overwhelming majority sold to small independent Chinese refineries ("teapot refineries").
"Rahbar" companies: Iranian banks establish these to manage clients' international transactions; they use Iranian exchange houses to set up third-country front companies, exploiting permissive jurisdictions and free trade zones.
Digital assets: Iranian digital asset activity now runs to billions of dollars per year. Stablecoins are favored for liquidity, settlement ease, and rate stability — and Iran's abuse now includes minting, moving between large-volume issuers, and creating proprietary stablecoins such as USDZ, tied to OFAC-designated issuer Zedxion. Iran has also stated intent to use digital assets to collect payments from tankers transiting the Strait of Hormuz. FinCEN specifically flags that new digital asset businesses may incorporate in Iran with little notice or footprint, making recency itself a risk factor.
Named enforcement example: Zedcex Exchange Ltd. and Zedxion Exchange Ltd., UK-registered exchanges designated by OFAC in January 2026, connected to an Iranian businessman and sanctions evader; multiple addresses attributed to them processed funds for IRGC-linked wallets. Separately, the September 2025 designation of Derakhshan and Alivand — who facilitated purchase of over $100 million in digital assets for oil sales, moving them through front companies across multiple jurisdictions, with Alivand brokering for the Syria-based Al-Qatirji Company, a primary IRGC-QF oil partner.
Jurisdictional posture: Iran is subject to a Section 311 fifth special measure (2019) barring U.S. correspondent accounts for Iranian financial institutions. FATF has long listed Iran as high-risk and in February 2026 reiterated its call for countermeasures — including prohibiting Iranian DASPs from establishing a presence in other jurisdictions or forming relationships with their DASPs.
SAR filing instruction: key term in SAR field 2 and the narrative; select SAR field 33(a) (Terrorist Financing – known or suspected terrorist/terrorist organization). FinCEN expressly invites feedback on the alert's utility and on control limitations — a rare solicitation.
SAR key term: FIN-2026-Alert002 · SAR Field 33(a)Red flags: ISIS financing — as published in FIN-2025-A001
Eleven indicators covering both organizational ISIS financing and homegrown violent extremist (HVE) activity. FinCEN notes there are limited financial indicators unique to HVE activity, which is precisely why the behavioral-change indicators below matter.
Fundraising and remittance patterns
- One credit card or bank account used to book travel, accommodation, or transportation in an area of known ISIS activity for several unrelated people at the same time with no legitimate purpose
- Fundraisers attached to social media profiles showing ISIS support or iconography, or referring to supporting the "mujahideen" or the "war against kufar" — especially soliciting travel funds to areas of ISIS activity, or referencing aid to imprisoned women and children in Iraq or Syria
- Collecting small amounts via P2P, social media, or virtual currency over a short period, then sending a lump sum to an individual in a region where ISIS is prevalent
- Remittances with no legitimate purpose to multiple unrelated individuals in jurisdictions known for ISIS facilitation, such as Türkiye
Pre-travel and pre-attack behavioral changes
- Attempting to purchase travel tickets after abruptly liquidating assets, closing accounts, cancelling subscriptions, or receiving large unexplained cash. FinCEN adds that a period of account dormancy following these behaviors should also be regarded as suspicious, even if the customer eventually resumes transactions within the United States
- Abruptly seeking as many lines of credit as possible — several credit cards, one or more loans — for unclear reasons, especially with no prior credit history. Especially suspicious where new cards are used almost exclusively for cash advances and virtual currency purchases, then payments are never made
- A sudden influx of unexplained cash deposits, especially where the customer is unemployed or the deposits supplement a regular paycheck, or come from ATMs in ISIS-prevalent locations where the customer isn't known to reside or travel
- Sudden adoption or increased use of methods concealing source or end use — P2P transfers, ATM withdrawals, third-party processors, prepaid cards, virtual currency, wire transfers
Geographic mismatch indicators
- Local deposits withdrawn from other locations, including abroad, where the customer isn't known to reside or travel but where ISIS is prevalent
- Virtual currency placed in a wallet from one IP address, then withdrawn at kiosks or converted to fiat by users at IP addresses in ISIS-prevalent locations unconnected to the customer
- An account accessed in multiple countries simultaneously or within a very short window, particularly where ISIS is prevalent
Verified against the primary document: funding figures, red-flag count, and case-study detail below match the FinCEN advisory.
Why the funding model changed: at its 2015 height ISIS funded itself from territory — oil, taxation, extortion, kidnapping, looted antiquities. After the 2019 loss of territory, organizational funds dwindled to $10–20 million, mostly cash and liquid assets. Treasury assesses ISIS generated around $8 million in 2024 from kidnapping for ransom, extortion, zakat, and international donations.
Current revenue by region: ISIS-Somalia raised $2 million from extortion in the first half of 2022 alone; ISIS in West Africa runs a proto-state enforcing religious taxes; ISIS-DRC taxes illegal gold mines and runs artisanal mining; ISIS-Sahel relies on "spoils of war" — plundered goods — possibly up to $6 million annually but unstable.
Decentralization is the structural point: ISIS now operates through affiliates receiving guidance and funding from four regional offices of its General Directorate of Provinces. Despite decentralization, better-resourced branches financially subsidize poorer offshoots — so affiliate-to-affiliate flows matter.
The camps: roughly 43,000 people with ISIS links remained in the open-air al-Hol camp as of 2024, mostly women and children, plus ~9,000 fighters in detention. Supporters in over 40 countries have sent money to ISIS-linked individuals in these camps, with al-Hol alone receiving up to $20,000 per month via hawalas, mostly originating outside Syria or transiting Türkiye. Funds are used to finance prison escapes and recruitment.
Fraudulent humanitarian appeals: ISIS supporters disguise fundraising as disaster or conflict relief, mimicking NPO campaigns — most commonly without any registered NPO involved. Campaigns avoid overt ISIS support, instead using specific religious terminology and imagery to signal affiliation, promoted primarily in Arabic and English but also Russian, German, and French (see Charities & NPOs).
Movement channels: cash couriers remain frequent, alongside banks in weak-AML jurisdictions, registered and unlicensed MSBs — especially hawalas, several sanctioned and ISIS-operated — online payment providers including some social media companies operating as unregistered U.S. MSBs, and digital asset exchanges. ISIS-K published QR codes in its magazine Voice of Khorasan enabling virtual currency donations; the UN reported ISIS's al-Karrar office sending up to $25,000 monthly to ISIS-K in virtual currency, and ISIS-K reportedly transferred at least $2,000 in virtual currency to the 2024 Crocus Hall attackers in Moscow. Assets used include Bitcoin, Tether (USDT), Ethereum, Monero, and Tron.
HVE financing: homegrown violent extremist activity is typically funded through legal means — personal savings, asset sales — which is why FinCEN emphasizes behavioral change over transaction type. Registered MSBs appear to be the preferred channel for domestic FTO supporters, sending low dollar amounts to avoid suspicion.
SAR filing instruction: key term in SAR field 2 and the narrative; select SAR field 33(a) (Terrorist Financing – known or suspected terrorist/terrorist organization).
SAR key term: ISIS-2025-A001 · SAR Field 33(a)A Springfield, Virginia man convicted of providing material support to ISIS. From October 2019 to October 2022 he raised funds online across social media accounts, received electronic transfers and travelled hundreds of miles to collect funds by hand, converted the money to cryptocurrency, and sent it to Türkiye where it was smuggled to ISIS members in Syria — financing escapes of female ISIS members from prison camps and supporting fighters. Over $185,000 in cryptocurrency across the conspiracy. His primary co-conspirator was a British-born ISIS member residing in Syria.
Red flags: Iranian oil, shadow banking & procurement — as published in FIN-2025-A002
Fifteen indicators in three groups. Some carried forward from the rescinded 2018 advisory and remain valid. The 2026 IRGC alert supplements these rather than replacing them — both sets apply.
Illicit oil smuggling and sales (6)
- Shipping documentation inconsistent with maritime database entries used for due diligence — FinCEN's example: the database shows the vessel called at an Iranian port, but that stop is absent from the shipping documents submitted for payment processing
- Documentation referencing vessels that have undergone recent or multiple name or flag changes, or ownership transferred after OFAC designated the owner/operator where the designated party appears to retain an interest
- Vessels claiming an IMO number that belongs to a different vessel, or to one previously scrapped
- Documentation referencing "Malaysian blend" oil, particularly where the vessel is China-bound via Southeast Asia and databases show AIS irregularities or a ship-to-ship transfer near Southeast Asia
- A petroleum or shipping company doing business with Iran-tied counterparties, or transporting goods on vessels tied to Iran or shown to have called at Iranian ports
- Oil-related transactions and wires involving vessels previously linked to suspicious activity, or documentation — bills of lading, shipping invoices — with no consignees, apparently falsified, or omitting key information to hide the Iranian nexus
Shadow banking networks (5)
- Transactions moving through multiple exchange houses and/or trading companies, accumulating fees as they progress, where the fees, transaction count, and pattern don't reflect standard commercial practice
- An exchange house or trading company in close geographical proximity to Iran using forged or falsified documents to conceal parties, in order to use regional banks' correspondent relationships with U.S. institutions to access dollars
- Wires or deposits with missing or incomplete source-of-funds information, or that don't match the customer's line of business, especially involving entities in high-risk jurisdictions for Iranian illicit finance
- A general trading company registered in a UAE commercial free trade zone with opaque ownership, counterparties mostly in Singapore and Hong Kong, holding accounts at multiple UAE institutions
- A Hong Kong company banking through a Chinese non-resident account with little to no web presence, co-located with numerous similar companies, or recently incorporated yet transmitting large payments with no adequate source-of-funds explanation — making numerous large payments to UAE general trading companies with no clear business purpose
Weapons procurement networks (4)
- Transactions originating with or directed to general trading companies, suspected front companies, or companies with an Iran nexus. Front company indicators: opaque ownership, obscurely named directing individuals or entities, or business addresses that are residential or co-located with other companies — especially previously sanctioned ones
- A customer declaring business information inconsistent with other available information such as prior transaction history — particularly where trade data shows a history of shipments to and from Iran, and where they transact predominantly with technology companies or chemical suppliers
- Transactions directed to companies in unrelated businesses that don't align with CDD information. FinCEN's specific example: customers primarily receiving funds from commodities trading companies but sending funds primarily to electronics suppliers
- Multiple companies incorporated at roughly the same time sharing counterparties, addresses, owners, or name similarities and showing similar transaction profiles — often with little web presence, transacting in large recurring amounts. Related pattern: a Middle East company with Iran links receiving payments primarily from petroleum companies then paying primarily to electronics companies in Hong Kong and China
Verified against the primary document: NSPM-2 trigger, MODAFL/AFGS/IRGC-QF oil allocation, and the concurrent OFAC shadow-banking designation match the FinCEN advisory.
Policy trigger: NSPM-2 (February 4, 2025), the maximum pressure campaign. Issued the same day as OFAC's first shadow-banking designation under that memorandum.
The oil economics: Iran's budget allocates billions in oil to MODAFL, the Armed Forces General Staff, and the IRGC-Qods Force to sell on the international market to supplement their budgets — recent estimates point to a four-fold increase exceeding $10 billion annually and over 500,000 barrels per day. FinCEN's stark framing: by end-2025, over half of Iran's total oil proceeds will be allocated to its armed forces while its population faces economic hardship. Iran sells below market to entice buyers; as of April 2025 it exported ~1.6 million barrels/day, nearly all to China, overwhelmingly to small independent "teapot refineries."
Shadow fleet: Treasury and State have blocked over 350 vessels for carrying Iranian oil since 2018. These are often uninsured, underinsured, or covered by previously sanctioned or untested insurers — FinCEN notes the resulting environmental exposure, since national and port authorities may be left covering clean-up costs after a spill. Tactics include false flags, flagging by registries not authorised for that jurisdiction, AIS manipulation, and ship-to-ship transfers.
Why "Malaysian blend" is the tell: smugglers receive falsified documents in Southeast Asia relabelling product as Malaysian despite Malaysia producing relatively little oil, before onward transport to Chinese refineries. FinCEN notes institutions may see traces of this in international wires, payment requests, and letters of credit, and recommends maritime databases and International Maritime Bureau reports for verification.
Definitional distinction worth keeping: exchange houses are licensed to deal in foreign exchange and transmit funds; trading companies are not licensed to transmit funds but operate as exchange houses in practice, relying on their bank accounts to move funds for third parties.
Case study — the Zarringhalam network: on June 6, 2025 OFAC designated over 40 individuals and entities tied to brothers Mansour, Nasser, and Fazlolah Zarringhalam, who through Iranian exchange houses (GCM Exchange, Berelian Exchange) laundered billions via front companies largely in the UAE and Hong Kong, serving Iran's main oil and petrochemical exporters and the military.
Case study — Sahara Thunder: MODAFL's main front company for clandestine UAV sales, designated April 2024. Central to Iran's sale of thousands of UAVs, many transferred to Russia — including under an approximately $1.75 billion contract to produce Iranian-designed one-way attack UAVs at the Alabuga facility in Russia.
SAR filing instruction: key term in field 2 and the narrative; select field 33(a) where there is a suspected nexus to an Iran-backed terrorist organisation, plus relevant fields 36 and 38. Immediate telephone notification to law enforcement is required for violations requiring urgent attention; terrorist-activity hotline 866-556-3974.
SAR key term: IRAN-2025-A002 · Field 33(a)Red flags: Hamas financing — as published in FIN-2023-Alert006
Seven indicators, issued thirteen days after the October 7, 2023 attacks.
- A customer or counterparty transacts with OFAC-designated entities/individuals, or transactions contain a nexus to their listed identifiers — email, physical address, phone number, passport number, or virtual currency address
- Information in a transaction between customers indicates support for terrorist campaigns
- A customer transacts with an MSB or other institution — including one offering virtual currency services — operating in a higher-risk jurisdiction tied to Hamas activity, reasonably believed to have lax CDD, opaque ownership, or otherwise fail AML/CFT best practices
- Transactions originate with, are directed to, or involve shell corporations or general "trading companies" with a nexus to Iran or other Iran-supported groups such as Hizballah and PIJ
- A charitable organization or NPO solicits donations but shows no discernible charitable activity, or openly supports Hamas — sometimes via social media or encrypted apps, including in virtual currency
- A charity or NPO receives large donations from an unknown source over a short period, then sends significant wires or checks to other charities/NPOs — a pass-through pattern
- A customer transacts with known or suspected virtual currency addresses tied to terrorism or terrorist-financing donation campaigns
Verified against the primary document: the $300M peak / tens-of-millions baseline Iranian support estimate and the eight funding streams match.
Iran's baseline support: historically estimated as high as $300 million/year in peak periods, more typically assessed in the tens of millions annually.
Eight named funding streams: Iranian state support; private donations; a global investment portfolio; diverting aid from legitimate charities; control of Gaza border crossings and commerce; racketeering business frameworks; extortion of local populations; and fundraising campaigns — including via fictitious charities collecting both fiat and virtual currency. Movement channels: physical currency smuggling, plus a regional network of complicit money transmitters, exchange houses, and Hizballah-affiliated banks.
Immediate context: issued alongside OFAC's designation of numerous Hamas members, operatives, and financial facilitators located in Gaza and abroad — Sudan, Türkiye, Algeria, and Qatar. FinCEN notes Treasury had by then targeted nearly 1,000 individuals and entities connected to Iranian-regime terrorism financing across Hamas, Hizballah, and other proxies.
Cyber-indicator instruction: financial institutions are asked to include chat logs, suspicious IP addresses, suspicious email addresses, and suspicious digital asset addresses in the SAR's structured cyber fields, and to cite or clearly explain the source of any external information that triggered the suspicious determination.
SAR filing instruction: key term in field 2 and the narrative; select field 33(a).
SAR key term: FIN-2023-TFHAMAS · Field 33(a)Red flags: Hizballah financing — as published in FIN-2024-Alert003
Seven indicators, in addition to those in FIN-2024-A001, all of which remain relevant.
Designation and jurisdiction linkage
- A customer or counterparty transacting with OFAC-designated Hizballah-connected entities, or with transactions containing a nexus to OFAC-listed identifiers — email addresses, physical addresses, phone numbers, passport numbers, or convertible virtual currency addresses
- Use of foreign financial institutions identified as of "primary money laundering concern" under §311 referencing association with or use by Hizballah
- Transactions with an MSB or other institution — including one offering CVC services — operating in jurisdictions at high risk for Hizballah financing (the tri-border region of South America, the Middle East, or West Africa) that has opaque ownership or beneficial owners who are known Hizballah associates
- Transactions originating with, directed to, or involving known or suspected front companies whose beneficial ownership suggests a Hizballah nexus — indicators being opaque ownership structures or business addresses that are residential or co-located with other companies
Trade-based indicators — unusually specific
- Invoices — particularly for electronics shipped from the U.S. to the tri-border region or the PRC, or used cars shipped from the U.S. to West Africa — that over- or under-charge the recipient, especially where goods don't match the counterparty's stated line of business and/or payment is facilitated by a Lebanese or Hizballah-connected financial firm or its foreign branch
- Transactions referencing commercial activity involving bills of lading with no consignees, or vessels previously linked to suspicious activity or registered to sanctioned entities connected with Hizballah, the Houthis, the IRGC-QF, or the Syrian regime — with documentation apparently falsified, omitting key information, or inconsistent with maritime database entries
Sector and account-behaviour pattern
- A customer with businesses in real estate, import/export, construction, diamonds and precious stones, or high-value art with numerous international counterparties in high-risk jurisdictions, making an unusually high number of cash deposits into business accounts, moving funds between business and personal accounts, or using personal accounts or personal credit cards to make business payments
Verified against the primary document: the $700M/year Iranian sponsorship estimate and revenue-model detail match the FinCEN alert.
Scale of Iranian sponsorship: historical estimates put Iranian support at approximately $700 million per year. Hizballah also acts as a conduit for funds flowing from Iran to other Iran-aligned groups.
Four regional revenue models. Oil smuggling — a large share of revenue from smuggling Iranian oil and LPG to Asia and the Middle East alongside IRGC-QF and Houthi networks, mostly sold to the PRC with Syria a major buyer, using front-company-owned vessels under flags of convenience and the full deceptive-shipping toolkit. Middle East — smuggling gold, electronics, and foreign currency out of Iran, with proceeds returned via bulk cash or laundered through front companies. West Africa — financiers using diamonds and precious stones, import/export, and high-value art businesses, sometimes bribing law enforcement to facilitate bulk-cash movement. Latin America — the External Security Organization's Business Affairs Component has close ties to South American drug trafficking organisations, laundering through the Black Market Peso Exchange, hawala, and intercontinental bulk-cash networks.
Why it reaches U.S. institutions: Treasury's 2024 National Terrorist Financing Risk Assessment found Hizballah continues to use the U.S. financial system for laundering, smuggling, and trafficking — transferring funds through it and attempting to purchase military or export-controlled equipment through front companies. Designated financiers may open accounts in family members' names, or use unrelated nominees who profit from holding accounts on their behalf.
TBML commodities named: electronics and used cars are the common value-transfer vehicles. Hizballah has also historically controlled banks — Bayt al-Mal in Lebanon (OFAC-sanctioned 2006) and Lebanese Canadian Bank SAL (identified as a §311 primary money laundering concern in 2011) — and uses trusts and NGOs in Lebanon to provide financial services, plus unlicensed MSBs it controls. FinCEN notes recent CVC use but stresses the group "continues to rely extensively on more traditional methods like bulk cash smuggling."
SAR filing instruction — note the shared key term: this alert does not create its own. Use the existing IRANTF-2024-A001 in field 2 and the narrative, select field 33(a), and additionally include the term "Hizballah" in SAR field 33(z) where a link is known or suspected.
SAR key term: IRANTF-2024-A001 · Field 33(a) · "Hizballah" in Field 33(z)Red flags: Iran-backed terrorist organizations — as published in FIN-2024-A001
Eight indicators — in addition to those in the 2018 Iran advisory and the October 2023 Hamas alert, all of which remain relevant.
- A customer or counterparty transacts with OFAC-designated entities/individuals, or transactions contain a nexus to their listed identifiers — email addresses, physical addresses, phone numbers, passport numbers, or CVC addresses
- A transaction or P2P transfer memo includes key terms known to be associated with terrorism or terrorist organizations
- A customer transacts with an MSB or other institution — including a VASP — operating in a jurisdiction known or high-risk for terrorist activity, reasonably believed to have lax customer identification, opaque ownership, or otherwise fail AML/CFT best practices
- Transactions originate with, are directed to, or involve front companies or general "trading companies" with unclear business purposes whose beneficial ownership suggests an Iran nexus — indicators: opaque ownership, obscurely named directing individuals/entities, or residential/co-located business addresses
- A customer that is or purports to be a charitable organization or NPO solicits donations but provides no discernible charitable services, or openly supports terrorist activity — sometimes soliciting via social media or encrypted apps, including in CVC
- A customer receives numerous small CVC payments from many wallets, then transfers to another wallet, particularly if logged in from an IP based in a jurisdiction known or high-risk for terrorist activity
- Money transfers to a high-risk jurisdiction inconsistent with the customer's stated occupation, with vague purposes such as "travel expenses," "charity," "aid," or "gifts"
- An account receives large payouts from social media fundraisers or crowdfunding platforms and is then accessed from an IP in a high-risk jurisdiction, particularly where the contributing social-media accounts contain content supportive of terrorist campaigns
An additional indicator worth flagging on its own: a U.S. or third-country incorporated company whose activities occur solely in high-risk jurisdictions with no relationship to its stated business purpose.
Verified against the primary document: proxy roster, key term, and the $40B NIOC 2021 sales figure match the FinCEN advisory.
Scope: the parent advisory covering the full proxy network — Hamas, the Houthis (Ansarallah), Hizballah, Palestinian Islamic Jihad, and Iran-aligned militias in Iraq (Kata'ib Hizballah, Kata'ib Sayyid al-Shuhada, Asa'ib Ahl al-Haq, Harakat al-Nujaba) and Syria. Establishes the IRANTF-2024-A001 key term reused by the later Hizballah alert.
Iran's own oil-to-terror pipeline: the National Iranian Oil Company sold ~$40B in products in 2021 alone, with crude/condensate exports reaching 1.3 million barrels/day to the PRC by 2023, some proceeds financing IRGC-QF and proxy activity. Funds move via front companies (often "trading companies") and exchange houses forming a shadow banking network, and via cultural/religious foundations as fronts — e.g. the Reconstruction Organization for the Holy Shrines in Iraq (ROHSI), ostensibly restoring Shiite shrines, actually an IRGC-QF conduit.
Case study — the $108M China Oil & Petroleum seizure (S.D.N.Y., Feb. 2024): seven defendants including a senior IRGC-QF official and Turkish energy executives indicted for an illicit billion-dollar network selling Iranian oil to PRC/Russia/Syria buyers. The U.S. seized $108M that a Hong Kong-based IRGC front company attempted to launder through U.S. correspondent accounts. Techniques: front companies to disguise Iran's role; falsified documentation deceiving unwitting banks; ship-to-ship transfers and AIS manipulation. A related D.D.C. indictment shows the same playbook — fraudulent documents masking origin, and a U.S. company used as a "trust" to hold profits for the IRGC.
Hamas: lost its Gaza tax/fee revenue base after October 7, 2023, leaving it dependent on Iran (~$100M/year since 2018), crowdfunding, and its investment portfolio (once ~$500M before May 2022 sanctions). Uses sham NPOs and crowdfunding under humanitarian cover — donations often landing in third-country accounts (Lebanon, Qatar, Türkiye) later accessed from Gaza. CVC fundraising since at least 2019: ~$165M in Hamas/CVC-linked SARs between Jan 2020–Oct 2023 across 200+ unique addresses (FinCEN cautions this is likely an overestimate, since filers often attribute a customer's entire transaction value to Hamas). Notably, al-Qassam Brigades announced in April 2023 it would stop accepting Bitcoin donations, warning donors could be targeted.
Houthis: funded substantially through IRGC-QF-backed facilitator Said Al-Jamal's smuggling network, generating tens of millions annually from Iranian commodity sales, plus port customs revenue and asset seizures from political opponents.
PIJ: shares Hamas's funding channels, including via the Hamas-controlled Islamic National Bank of Gaza and sham charities (Al-Ansar Charity Foundation, Muhjat al-Quds Foundation).
Virtual currency exchange cross-reference: the advisory notes the $3.4B FinCEN/OFAC settlement against the world's largest virtual currency exchange (Nov. 2023) was in part due to failure to identify and report transactions involving PIJ and Hamas's al-Qassam Brigades — directly tying the CVC/MSB vulnerability layer to terrorist financing enforcement (see Convertible Virtual Currency).
SAR filing instruction: key term in field 2 and the narrative; select field 33(a). Cyber indicators requested: email/IP addresses with timestamps, login location/timestamps, virtual currency addresses, device IMEI, and communication timing.
SAR key term: IRANTF-2024-A001 · Field 33(a)Verified against the primary document.
Covers the proxy layer — Hamas, Hizballah, Ansarallah (Houthis) — including Hamas soliciting digital asset donations since at least 2019, and Hizballah laundering through West African, European, and South American business networks, Lebanon-based trusts and NGOs, controlled unlicensed MSBs, and hawala.
The quantitative basis for the 2026 alert's scale claims, and source of the shell company indicator set: recent incorporation with limited or no internet presence; large transactions with unclear business purpose; and shared addresses, financial activity, counterparties, or name similarities with OFAC-designated Iranian companies.