Introduction

The payment doesn't end the story, it starts a different one

A scam compound may look like a fraud operation. Financially, it is better understood as the front end of a much larger criminal value chain. The person messaging a victim may never control the bank account that receives the money. The holder of that account may never meet the person controlling the next account. The company buying cryptocurrency may have no visible connection to the original scam. By the time the proceeds reach a stablecoin wallet, several institutions, identities, legal entities and jurisdictions may sit between the victim and the criminal organisation. That fragmentation is not incidental. It is part of the laundering architecture.

FATF has described cyber-enabled fraud syndicates as organised structures with specialised functions, including dedicated money laundering capabilities. The resulting laundering networks can involve individual money mules, legal persons, banks, payment providers, remittance providers and virtual asset service providers. Proceeds may move rapidly across accounts, institutions and jurisdictions [2][3].

A note on how FATF material is used throughout this guide: FATF Recommendations are international standards addressed to countries. FATF guidance and typology reports, cited repeatedly below, can inform risk analysis, but they do not themselves create UK firm-level obligations; any binding UK duty must come from applicable domestic legislation, regulation or regulatory rules, see Section 17.

This guide follows that movement:

The objective is not to memorise a single scam typology. It is to understand what each node is trying to achieve, what information disappears at every handoff, and which signals can reconnect the chain. Every pill above is a live link, and stays reachable from the sidebar contents throughout the guide.

Section 1

First, keep the numbers separate

The scale of scam activity is frequently described using figures that measure different things. They should not be combined.

FATF global estimate

At the launch of FATF's 2026 to 2028 Roadmap on Combatting Fraud on 1 July 2026, FATF President Giles Thomson put the global scale at nearly USD 500 billion lost to scams across 2024 and 2025. This guide attributes that figure solely to Thomson's Roadmap launch and treats it as FATF's own global estimate. It is not a UK Fraud Strategy figure and should not be presented as one [1].

UNODC regional estimates

Separately, UNODC estimated financial losses of USD 18 billion to USD 37 billion from scams targeting victims across East and Southeast Asia during 2023, published in its October 2024 report on the region's cyber-enabled fraud economy [8].

UNODC's follow-up report, published 21 July 2026, put 2025 losses across East Asia, Southeast Asia, Australia and New Zealand at USD 88.3 billion to USD 114.1 billion, nearly triple the 2023 figure, which UNODC itself describes as reflecting the dramatic scaling of this criminal economy [8b].

Both are regional estimates, for different years and slightly different regional scope. Neither validates, reproduces, or forms the basis of the FATF global figure above, and the two UNODC figures should not be averaged or treated as directly comparable without noting the scope difference.

Chainalysis crypto tracking

Chainalysis reported that addresses it had identified as associated with cryptocurrency scams received at least USD 14 billion on chain during 2025. It describes this as a lower bound that increases as additional illicit addresses are identified [12]. That is observed or attributed cryptocurrency flow. It is not an estimate of total global scam losses.

TRM Labs crypto tracking

TRM Labs reported at least USD 10.7 billion in cryptocurrency sent to fraud in 2024 within its observed dataset. TRM similarly cautions that fraud attribution increases over time as additional activity becomes known [10]. Again, this is crypto-specific tracked activity, not total scam losses.

Why this distinction matters

A victim loss survey and an analytics firm's attributed blockchain inflow are measuring different things. Putting them in the same chart without explaining the denominator creates false precision. For investigators, the more useful question is not how big is the scam economy, it is what happens to the victim's money after the payment succeeds.

Section 2

Scam compounds are only one part of the machine

INTERPOL describes transnational scam centres as criminal hubs associated with large-scale fraud, trafficking and abuse. People inside compounds may be forced to conduct romance scams, investment fraud, cryptocurrency scams, impersonation fraud and other schemes. INTERPOL also cautions that not everybody working in a scam centre is necessarily a trafficking victim [9].

The laundering function can sit elsewhere entirely. A useful analytical model is to separate two machines. The fraud machine acquires victims. The laundering machine acquires, moves, converts and ultimately makes usable the proceeds generated from those victims. FATF has found that the place where the fraud occurs and the place where the laundering occurs are frequently different. Proceeds can move through networks spanning multiple jurisdictions and financial institutions [3].

This means an analyst in Birmingham may be looking at one UK bank account without seeing the compound, recruiter, controller, overseas broker or wallet sitting further along the chain. The analytical challenge is therefore reconstruction.

How to use this guide

Work through the nine nodes in order, each has its own red flags, open the disclosure under each node before moving on. Then work both worked scenarios for the reasoning, not just the answer. The knowledge check pulls from across the whole chain, and the FAQ closes out the most common edge cases.

1
Node One

The victim payment

The laundering chain begins before the receiving account moves anything. The first observable event is usually a payment authorised or initiated by the victim. Depending on the scam, the victim may believe they are investing money, paying an invoice, helping a romantic partner, moving money to a supposedly safe account, paying tax or withdrawal fees, funding a cryptocurrency investment, completing paid online tasks, or responding to an impersonated business or authority.

FATF has identified patterns including unusual beneficiary information, small successful payments followed by larger payments, urgent instructions and transaction details inconsistent with previously verified behaviour [3].

Red flags at the victim node
  • A newly introduced beneficiary
  • A small test payment followed quickly by a substantially larger payment
  • Unusual investment-related payment descriptions
  • Beneficiary account details inconsistent with an expected recipient
  • Sudden deviation from the customer's normal transaction pattern
  • Repeated payments following apparent successful receipt of the first payment
  • Customer communications indicating urgency, secrecy or external instruction
  • Payments to recently established companies with no obvious connection to the customer
  • Payments inconsistent with the customer's historic economic activity
One indicator is a prompt, not a conclusion

FATF itself cautions that the presence of one indicator may not independently warrant suspicion. Indicators are prompts for further examination, not automatic conclusions [3]. That principle applies to every node in this chain.

2
Node Two

The receiving account

This is the first account controlled, directly or indirectly, by the criminal ecosystem. For some fraud types FATF has observed individual mule accounts as common first-layer accounts. For other typologies, particularly certain trading and business email compromise schemes, corporate accounts including newly registered or shell companies may be used at the first layer [3]. The account's job is simple: receive the victim's money without immediately exposing the controller.

The account may previously have behaved normally. Then something changes. Salary credits of £1,500 a month become £15,000 of incoming transfers from unrelated people. A student account starts processing business-sized turnover. A dormant company begins receiving consumer payments. Incoming funds leave almost immediately. The account holder cannot explain who the payers are. FATF has documented mule structures in which participants hand over credentials, cards or other access mechanisms, allowing the criminal syndicate to exercise direct control over the account [3].

Red flags at the receiving account
  • Sudden transaction velocity inconsistent with historical use
  • Incoming transfers from multiple unrelated individuals
  • Immediate or rapid onward movement
  • Near-complete depletion of the received balance
  • Turnover inconsistent with the customer's economic profile
  • Customer unable to explain the source or purpose of incoming payments
  • Assertion that the account is being used on behalf of somebody else
  • New account followed quickly by significant transaction activity
  • Account details or identity information changing soon after onboarding
  • Multiple accounts linked through common devices, credentials, telephone numbers or IP infrastructure
  • Remote access indicators inconsistent with normal account usage
  • Fraud recalls or reports received from sending institutions

The NCA defines money mule networks as people or accounts used to launder criminal funds, with controllers organising transactions while attempting to retain their own anonymity [6].

3
Node Three

The mule network

One receiving account is vulnerable. A network is resilient. The criminal organisation distributes proceeds across multiple accounts so that losing one account does not necessarily disrupt the entire payment chain. Some mules knowingly participate. Some are deceived. Some may understand that something is wrong without understanding the underlying offence. FATF recognises this variation in mule culpability and notes that online recruitment can be scaled through social media and messaging platforms [3].

The UK threat is not theoretical. In one NCA-reported fraud case concluded around Operation Henhouse activity, more than 300 victims were targeted through fraudulent vehicle advertisements. Investigators identified more than 90 money mules, many recruited through social media with offers of quick cash [7].

Red flags across the mule network

Do not analyse each account in isolation. Look for network features:

  • Multiple accounts receiving from apparently unrelated victims
  • Common destination accounts
  • Common device identifiers
  • Common IP infrastructure
  • Repeated transaction amounts or timing patterns
  • Similar account opening characteristics
  • Similar payment narratives
  • Common cash withdrawal locations
  • Shared cryptocurrency counterparties
  • Shared company beneficiaries
  • Repeated fraud recalls across apparently unrelated account holders
  • Movement that becomes increasingly concentrated as funds progress through the network
The analytical shift

A transaction monitoring alert asks is this account suspicious? A network investigation asks what role is this account performing? The second question is more useful.

4
Node Four

The aggregator

For this guide, aggregator is an analytical label rather than a statutory or FATF-defined category. It describes an account, wallet or entity that receives funds from multiple first-layer or intermediate accounts and concentrates them before further movement. FATF describes cyber-enabled fraud proceeds being rapidly layered through pass-through transactions across domestic and foreign accounts, and documents patterns in which numerous companies and individual accomplices circulate proceeds through structured networks [3].

The aggregator is where apparently separate scams can begin to look like one financial operation. Imagine twelve mule accounts, each receiving between £2,000 and £9,000 from different victims. All twelve send most of their balances to the same company account. That company may never have contacted a victim. Yet from a network perspective it may be more important than any individual mule.

Red flags at the aggregator
  • Many unrelated originating accounts converging on one beneficiary
  • Counterparties concentrated around known or suspected mule activity
  • High inbound transaction count followed by fewer high-value outbound transfers
  • Extremely short holding periods
  • Turnover far beyond the customer's expected activity
  • Transactions with no credible commercial relationship between counterparties
  • Repeated balance sweeping
  • Multiple fraud-exposed accounts feeding one destination
  • Rapid conversion into another asset class
  • Onward transfers to VASPs, money service businesses or overseas entities
  • Movement patterns inconsistent with the stated nature of the business

The analytical value of the aggregator is concentration. The criminal has reduced hundreds of victim relationships into a smaller number of controllable financial relationships. That creates efficiency for the criminal organisation. It can also create an investigative choke point.

5
Node Five

The shell company

Not every shell company is criminal. Not every newly incorporated company is suspicious. The risk arises from the relationship between the corporate profile and the movement of money. FATF has documented cyber-enabled fraud laundering structures involving shell companies controlled through straw persons or nominee directors, and cases where mules were used to open corporate accounts or act as nominal company representatives [3].

One FATF case study described an online trading fraud network involving 209 companies. Investigators identified common accountants, companies created around similar dates, rapid liquidation and movement of proceeds between the companies. Some funds subsequently moved to VASPs [3]. The NCA's 2026 National Strategic Assessment separately states that criminals continue to exploit UK corporate structures for fraud and illicit finance [5].

Red flags at the corporate node
  • Company recently established before high transaction volumes begin
  • Vague or extremely broad stated business activity
  • Payment flows inconsistent with the declared industry
  • Large numbers of unrelated retail payers
  • Common directors, addresses, accountants or contact information across apparently separate entities
  • Limited evidence of genuine operating activity
  • Rapid transfer of most incoming funds
  • Frequent transactions with other recently formed companies
  • Merchant activity inconsistent with the company's business model
  • Unexplained payments to cryptocurrency businesses
  • High turnover unsupported by reasonable commercial documentation
  • Customer or director unable to explain material counterparties
  • Virtual address combined with other indicators of opacity

The important question is not is this a shell company? It is does the economic behaviour of this legal entity make sense?

6
Node Six

The OTC broker or offshore VASP

At some point, fiat proceeds may need to cross into virtual assets. That can occur through regulated exchanges, peer-to-peer activity, OTC brokers, cryptoasset businesses, offshore VASPs, or combinations of these channels. OTC activity is not inherently illicit. Offshore VASPs are not inherently criminal either. The risk comes from opacity, regulatory gaps, nested relationships, customer profile mismatch and exposure to known illicit flows.

FATF defines an offshore VASP as a VASP created under the laws of one jurisdiction, with or without a physical presence there, that provides services to customers in another jurisdiction. Its March 2026 report found that uneven oversight can create exploitable gaps, and specifically identified dispersal across multiple addresses, layered intermediary wallets, multiple blockchains and nested relationships as methods relevant to illicit finance through some offshore VASP structures. FATF also documented cases where offshore VASPs were used to convert proceeds associated with scam compounds [4].

Red flags at the conversion node
  • Customer activity inconsistent with declared crypto experience or business model
  • Sudden high-value conversion following large fiat inflows
  • Funds originating from newly formed or opaque companies
  • Third-party funding with no credible economic explanation
  • Repeated use of counterparties with limited transparency
  • Exposure to unlicensed or unregistered providers where registration would be expected
  • Transactions involving nested service relationships
  • Rapid conversion followed by movement to unhosted wallets
  • Transfers across several platforms without credible investment or commercial rationale
  • Source-of-funds documentation inconsistent with transaction volume
  • Customer explanation focused on transaction mechanics rather than economic purpose
  • Recurring exposure to known scam-related wallets or entities
UK scope point

As at August 2026, a business providing cryptoasset services within Regulation 14A while acting in the course of business in the United Kingdom must register with the FCA before beginning those services. The new FSMA cryptoasset regime starts on 25 October 2027 [13]. An overseas provider is not automatically within the MLR registration perimeter merely because it permits a UK resident to become a customer; the assessment depends on the activities undertaken and whether the provider acts in the course of business in the United Kingdom. This does not determine the separate UK financial promotions position, which can apply to marketing directed at UK consumers regardless of where the provider is based.

Real Case Study

Huione Group: what a Section 311 finding actually establishes

United States jurisdiction only. This case study concerns a United States Section 311 measure and does not establish any obligation under UK law.

On 14 October 2025, FinCEN issued a final rule, effective 17 November 2025, after finding reasonable grounds to conclude that Huione Group, a Cambodia-based (Phnom Penh) financial services conglomerate, was a foreign financial institution of primary money laundering concern. Three distinct dates attach to this rule and are not interchangeable: FinCEN's own issuance date is 14 October 2025; the Federal Register public-inspection filing is dated 15 October 2025; the Federal Register publication date is 16 October 2025. This guide uses FinCEN's own issuance date as the primary date. The rule prohibits covered US financial institutions from opening or maintaining a correspondent account in the United States for, or on behalf of, Huione Group. It also requires those institutions to take reasonable steps to prevent their covered correspondent accounts from processing transactions involving Huione Group, and requires specified special due diligence on their foreign correspondent accounts [16].

FinCEN based its finding on several matters, kept separate here rather than blended into one: services Huione Group provided that DPRK government entities used to launder proceeds of cyber heists; use of Huione Group by Southeast Asian criminal organisations to launder proceeds of cyber scams, including convertible virtual currency investment scams such as so-called "pig butchering" schemes; and Huione Group's operation of an illicit online market. FinCEN's analysis identified that, in the aggregate, Huione Group received at least USD 4 billion worth of illicit proceeds between August 2021 and January 2025, a figure stated directly in FinCEN's own primary text. This is FinCEN's assessment, not a criminal conviction of any individual [16].

The final rule's definition of Huione Group includes Haowang Guarantee (formerly Huione Guarantee), Huione Pay PLC, and Huione Crypto. Huione Pay PLC had previously been registered as a Cambodian payment services institution, but by 2025 its Cambodian licence had been rescinded by the National Bank of Cambodia and it no longer appeared in the Ministry of Commerce's business registration database [16]. In June 2026, FinCEN proposed amending the definition to include H Pay Service PLC and successor entities; as at August 2026 that remains a proposed amendment, not part of the operative 2025 final rule, and this guide does not present it as such.

This guide cites the finding at Node Six deliberately, and the mapping below is this guide's own analytical application of FinCEN's findings, not wording used by FinCEN itself: Haowang Guarantee illustrates an online marketplace functioning as a conversion and off-ramp point for scam proceeds, the same functional role this guide describes at Nodes Six and Nine, not an isolated or hypothetical pattern.

What this case study does and does not establish: a Section 311 special measure is a finding that an entity is a foreign financial institution of primary money laundering concern, followed by US correspondent-banking restrictions of the scope described above. It is not a criminal conviction of any individual, and it creates no UK obligation.

7
Node Seven

Stablecoin conversion

Stablecoins solve a problem for legitimate commerce and criminal finance alike. They permit digital value to move quickly across borders while avoiding much of the price volatility associated with assets such as Bitcoin. That does not make stablecoins inherently suspicious.

TRM Labs estimates that approximately 99 per cent of stablecoin activity in the period it analysed was licit. At the same time, stablecoins represented around 60 per cent of the illicit crypto activity observed by TRM during the first quarter of 2025 [11]. Those two facts can coexist: large legitimate usage alongside significant criminal adoption. Chainalysis likewise reported that stablecoins represented a large share of identified illicit cryptocurrency transaction volume during 2025; that measurement covers illicit crypto activity broadly and should not be presented as a scam loss figure [12].

Red flags at the stablecoin node

FATF's cyber-enabled fraud risk indicators include:

  • Large volumes or high-frequency transactions involving unhosted wallets
  • Exposure to addresses associated with scammers or other illicit services
  • Inability to evidence the origin of virtual assets or the fiat used to acquire them
  • Use of several types of virtual asset without reasonable explanation
  • Abnormal peer-to-peer wallet activity lacking logical business purpose
  • Rapid onward transfers following acquisition
  • Interaction with high-risk jurisdictions or services when combined with other indicators

Source: FATF, Illicit Financial Flows from Cyber Enabled Fraud [3].

Blockchain transparency can make this stage more observable than the criminal may expect. The challenge is connecting blockchain evidence to the identities and fiat accounts that preceded it.

8
Node Eight

Layering

Layering is where investigative context is deliberately degraded. FATF describes cyber-enabled fraud proceeds moving through pass-through transactions involving domestic and foreign accounts, with techniques including movement through different financial institutions, payment providers and remittance providers, smurfing, and conversion into different forms of value, including virtual assets [3]. Within virtual assets, FATF's 2026 offshore VASP work describes dispersal across multiple addresses, intermediary wallets and multiple blockchains as relevant obfuscation patterns [4].

The objective is not necessarily to make tracing impossible. It is to increase the cost, time and jurisdictional complexity of reconstruction.

Red flags during layering
  • Repeated rapid transfers with minimal holding periods
  • Multiple intermediate accounts with no clear commercial function
  • Repeated asset conversion without economic justification
  • Transfers across several exchanges or wallets in short succession
  • Fragmentation followed by reconsolidation
  • Movement involving numerous jurisdictions
  • Wallet activity inconsistent with the customer's stated investment strategy
  • Transactions crossing several service providers without clear purpose
  • Related entities transferring funds amongst themselves
  • Payment paths that appear economically circular
  • Counterparties whose only apparent function is receiving and forwarding value
A useful analytical test

What economic purpose did this intermediate transaction achieve? If the only observable purpose is to make the trail longer, risk increases. That is still an analytical inference, not proof of criminal intent.

9
Node Nine

The off ramp

Eventually the organisation needs usable value. That does not always mean cash: the endpoint may involve fiat withdrawal, bank transfer, cash, goods, property, another business, settlement with another criminal network, reinvestment into the fraud operation, or payment for criminal infrastructure.

The NCA's 2026 National Strategic Assessment describes professional money laundering networks servicing multiple organised crime groups and notes models involving collection, consolidation and conversion of criminal value into cryptocurrency. It also describes international controller networks capable of arranging value movement across borders without every stage relying on the conventional banking system [5]. The criminal objective is therefore better understood as usable value, not simply cash.

Red flags at the off ramp
  • Large fiat withdrawals following complex inbound crypto activity
  • Third-party bank accounts receiving exchange withdrawals
  • Multiple unrelated beneficiaries
  • Crypto conversion followed immediately by fiat withdrawal
  • Customer activity inconsistent with stated wealth or business profile
  • Repeated use of accounts whose principal function appears to be value conversion
  • Funds leaving towards newly established companies
  • Unusual payments into sectors or assets unrelated to the customer's normal activity
  • Withdrawal counterparties connected to known mule or laundering networks
  • Repeated conversion activity with little evidence of legitimate trading rationale

This is where the laundering cycle can reconnect with apparently legitimate economic activity.

Section 12

The real control gap: every institution sees a different crime

The sending bank may see an unusual victim payment. The receiving bank may see a young customer with incoming transfers. A second bank may see a company receiving money from multiple individuals. A VASP may see a company purchasing USDT. A blockchain analytics platform may see wallet exposure. An overseas exchange may see a customer selling stablecoins.

Each institution can therefore hold a fact that appears weak alone. The network can become obvious only when those facts are connected. This is why FATF's current fraud programme places significant emphasis on information sharing, payment transparency, asset recovery and cross-border cooperation [1][2]. The laundering machine benefits from organisational fragmentation. Detection improves when investigators reconstruct the chain rather than stopping at the alert.

🏦
Scenario 01 · Nodes Two and Three
The Receiving Account That Looked Ordinary Yesterday
First-Layer Mule

A UK current account belongs to a 23-year-old customer. Historic behaviour shows monthly salary credits of approximately £1,600, rent, groceries, and occasional transfers between savings accounts. During one afternoon the account receives eleven Faster Payments from unrelated individuals, total value £18,640. Within three hours, £17,900 is transferred to a recently incorporated UK company described as a digital marketing business. The customer retains £740 and states: "Friends owed me money and I forwarded it to someone helping us invest." Two sending institutions subsequently submit fraud-related recalls.

Decision Point One

⚖️
What is the strongest classification at this stage?Make the call

Decision Point Two

⚖️
What is the most valuable next analytical step?Make the call
🏢
Scenario 02 · Nodes Four, Five and Six
The Company That Became a Crypto Gateway
Aggregation Layer

A UK-incorporated business states that it provides software consultancy, with expected annual turnover of £280,000 given at onboarding. The business has historically received payments from four commercial clients. Over six weeks, behaviour changes: the account receives approximately £410,000 from more than 60 individuals, with payment references including "investment," "trading account," "deposit," "membership" and "recharge." Approximately £360,000 is transferred to cryptoasset service providers, and a further £32,000 goes to another recently incorporated company. Blockchain analysis available to the VASP shows much of the purchased USDT moving rapidly through intermediary wallets, with one destination showing exposure to addresses previously associated with scam activity. The director says the business recently began "handling payments for overseas partners" but provides no contracts supporting that explanation.

Decision Point One

⚖️
What is the strongest analytical conclusion?Make the call

Decision Point Two

⚖️
Which fact would most strengthen the hypothesis that this company is functioning as an aggregation and conversion layer, not genuine software consulting?Make the call
Screening a counterparty across this chain?Run a free sanctions and PEP check before proceeding, no account required.
Screen an entity →
Section 15

The investigator's mental model

When analysing a suspected scam laundering structure, do not ask only who received the victim's money? Ask nine questions, one per node.

  1. Victim payment: Why did the victim send it?
  2. Receiving account: Who first received it?
  3. Mule network: Which other accounts behave the same way?
  4. Aggregator: Where do apparently separate flows converge?
  5. Shell company: Which legal entity gives the money a commercial appearance?
  6. OTC or offshore VASP: Where does fiat become virtual asset value?
  7. Stablecoin: Which asset becomes the transport mechanism?
  8. Layering: What transactions degrade the original context?
  9. Off ramp: Where does the organisation obtain usable value?

That turns transaction review into financial network analysis.

Section 16

What should trigger escalation?

No universal numerical threshold works for every institution or customer. This ladder is an internal analytical prioritisation model only. Neither the number nor the combination of indicators creates a statutory suspicion or SAR reporting threshold. Indicators must be assessed in context against the applicable law and the firm's procedures.

Lower signal

One unusual payment.

Medium signal

Unusual payment plus profile mismatch plus rapid onward transfer.

Higher signal

Multiple unrelated originators plus rapid onward transfers plus common beneficiaries plus fraud recalls.

Strong network signal

Multiple suspected victim or mule accounts converge on an entity that rapidly moves funds into another financial sector or asset type, with weak economic explanation and additional counterparty intelligence.

The key principle is convergence of independent indicators, not a count against any threshold.

Section 17

UK legal context

This section deliberately stays narrow because operational AML decisions depend on the firm's regulatory status, facts and applicable law.

Sections 327, 328 and 329 of the Proceeds of Crime Act 2002 create separate principal money laundering offences. Section 327 covers concealing, disguising, converting or transferring criminal property, or removing it from the relevant UK jurisdiction. Section 328 covers entering into or becoming concerned in an arrangement that the person knows or suspects facilitates another person's acquisition, retention, use or control of criminal property. Section 329 covers acquiring, using or possessing criminal property. Each offence is subject to its own statutory exceptions and defences [14].

Section 330 creates a failure to disclose offence only where all its statutory conditions are satisfied, including the applicable knowledge, suspicion or reasonable-grounds condition, receipt of the relevant information during regulated-sector business, the further identification-or-assistance condition, and failure to disclose as soon as practicable. Statutory defences and exceptions may apply [14].

Where customer due diligence is required, Regulation 28 of the Money Laundering Regulations 2017 requires the relevant person to identify the customer and verify the customer's identity using information from a reliable and independent source. It also contains measures concerning beneficial owners and persons acting for customers, and requires the relevant person to assess and, where appropriate, obtain information on the purpose and intended nature of the business relationship or occasional transaction. Ongoing monitoring applies to business relationships and includes scrutiny of transactions for consistency with the relevant person's knowledge of the customer, business and risk profile, including source of funds where necessary, together with keeping customer due diligence information current [15]. Regulation 33 requires a relevant person to apply enhanced customer due diligence and enhanced ongoing monitoring, in addition to the applicable Regulation 28 and 29 measures, in every case falling within Regulation 33(1). These include cases the relevant person identifies as high risk, specified relationships or transactions involving a FATF call-for-action country, specified correspondent relationships, PEP cases, certain false or stolen identification cases, defined unusual transactions, and other cases that by their nature present a higher risk of money laundering or terrorist financing. Regulations 34, 34A and 35 prescribe additional measures for particular categories [15].

A suspicious pattern therefore should not automatically be translated into "file a SAR because a red flag exists." Neither the number nor the combination of indicators creates a statutory suspicion or SAR reporting threshold; the facts must be assessed in context against the applicable legal and regulatory threshold and the firm's reporting procedures. FATF Recommendations are international standards addressed to countries; FATF guidance and typology reports can inform risk analysis, but they do not themselves create UK firm-level obligations, any binding UK duty must come from applicable domestic legislation, regulation or regulatory rules.

Section 18

The central lesson

The biggest analytical mistake is to think the scam ends when the victim presses Send. For the criminal organisation, that payment is the beginning of another process. The money must be received, separated from the victim, moved through controlled accounts, concentrated, placed behind individuals or companies, converted, transferred across institutions or jurisdictions, layered, and ultimately made useful.

The organisations running scam compounds can therefore be understood not only as fraud enterprises but as producers of illicit financial flows feeding a broader professional laundering ecosystem. FATF, UNODC and the NCA all describe elements of this convergence, although each source examines the problem from a different geographic and methodological perspective [2][3][5][8].

The investigator's advantage is that the machine leaves traces at every handoff. The challenge is recognising that nine weak signals across nine different systems may describe one strong network.

Legal Note

Legal note

This guide is educational content for financial crime and compliance professionals. It is not legal advice and should not be relied on as a substitute for independent legal or regulatory advice. Regulatory and statutory citations reflect the law as understood at the time of publication (25 August 2026) and should be independently verified against current primary sources before being relied upon. References to United States regulatory action, including the FinCEN Section 311 case study, describe United States law only and do not establish any obligation under UK law.

Sources and Methodology

Sources and methodology

Sources were last reviewed on 25 August 2026. This guide is an educational resource for financial crime and compliance professionals. It does not constitute legal advice. The scenarios are fictional composites created to teach analytical judgement; they do not reproduce a specific investigation or allege criminal conduct by any real individual or business.

  1. [1]GlobalFinancial Action Task Force, 1 July 2026, UK takes over Presidency of Financial Action Task Force (2026-2028). fatf-gafi.orgOfficialReviewed 25 Aug 2026. Supports: nearly USD 500bn global scam-loss estimate for 2024-2025. This is the sole attribution used in this guide for that figure; not a UK Fraud Strategy figure.
  2. [2]GlobalFinancial Action Task Force, 24 February 2026, Cyber Enabled Fraud: Digitalisation and Money Laundering, Terrorist Financing and Proliferation Financing Risks. fatf-gafi.orgOfficialReviewed 25 Aug 2026. Supports: scam centres, shell companies, virtual assets, payment transparency and cross-border cooperation framing.
  3. [3]GlobalFATF, INTERPOL and Egmont Group, November 2023, Illicit Financial Flows from Cyber Enabled Fraud. fatf-gafi.orgOfficialReviewed 25 Aug 2026. Supports: the payment chain, mule accounts, legal entities, rapid pass-through transactions, VASP conversion and cyber-enabled fraud risk indicators throughout Nodes One through Nine.
  4. [4]GlobalFinancial Action Task Force, 11 March 2026, Understanding and Mitigating the Risks of Offshore Virtual Asset Service Providers. fatf-gafi.orgOfficialReviewed 25 Aug 2026. Supports: offshore VASP definition, nested relationships, layered intermediary wallets, and scam-compound proceeds conversion.
  5. [5]UKNational Crime Agency, National Strategic Assessment 2026, Serious and Organised Crime Finance section. nationalcrimeagency.gov.ukOfficialReviewed 25 Aug 2026. Supports: UK corporate abuse, professional money laundering networks, international controllers, and cryptocurrency conversion.
  6. [6]UKNational Crime Agency, Money Mules: Don't Be Used. nationalcrimeagency.gov.ukOfficialReviewed 25 Aug 2026. Supports: UK definitions of mule networks, controllers and common mule functions.
  7. [7]UKNational Crime Agency, 2026, Operation Henhouse reporting. nationalcrimeagency.gov.ukOfficialReviewed 25 Aug 2026. Supports: the UK fraudulent-vehicle-advertisement case involving more than 90 recruited money mules.
  8. [8]SE AsiaUnited Nations Office on Drugs and Crime, October 2024, Transnational Organized Crime and the Convergence of Cyber-Enabled Fraud, Underground Banking and Technological Innovation in Southeast Asia. unodc.orgOfficialReviewed 25 Aug 2026. Supports: USD 18bn-37bn regional 2023 loss estimate for East and Southeast Asia. Explicitly a regional estimate, not combined with S8b or the FATF global figure.
  9. [8b]Asia-PacificUnited Nations Office on Drugs and Crime, 21 July 2026, An Interconnected Criminal Ecosystem: Transnational Organized Crime Threat Assessment for Southeast Asia 2026. unodc.orgOfficialReviewed 25 Aug 2026. Supports: USD 88.3bn-114.1bn 2025 regional loss estimate, described by UNODC as nearly tripling the 2023 figure. Cited strictly as a regional figure for a different year than S8, not combined with it.
  10. [9]GlobalINTERPOL, 26 November 2025, Growing Threat of Transnational Scam Centres Highlighted at INTERPOL General Assembly. interpol.intOfficialReviewed 25 Aug 2026. Supports: scam-centre links to large-scale fraud and forced criminal activity, and INTERPOL's own caution that not every worker is necessarily a trafficking victim.
  11. [10]IndustryTRM Labs, 2025 Crypto Crime Report. trmlabs.comSecondaryReviewed 25 Aug 2026. Supports: at least USD 10.7bn tracked cryptocurrency sent to fraud during 2024, with TRM's own caveat that attribution rises as more activity is identified. Not used as a total scam-loss figure.
  12. [11]IndustryTRM Labs, 2025 Stablecoin Usage Report. trmlabs.comSecondaryReviewed 25 Aug 2026. Supports: approximately 99% of stablecoin activity assessed as licit, while stablecoins represented 60% of observed illicit crypto activity in Q1 2025.
  13. [12]IndustryChainalysis, 2026 Crypto Crime Report: Scams. chainalysis.comSecondaryReviewed 25 Aug 2026. Supports: at least USD 14bn of on-chain inflows to identified cryptocurrency scam addresses during 2025, an explicit lower bound. Not used as a total scam-loss figure.
  14. [13]UKFinancial Conduct Authority, updated 30 June 2026, Cryptoasset Firms: Registration under the Money Laundering Regulations Ahead of the New FSMA Regime. fca.org.uk; territorial-scope point additionally supported by FCA, Cryptoassets: who needs to register, fca.org.ukOfficialReviewed 25 Aug 2026. Supports: current FCA cryptoasset registration requirement (Regulation 14A perimeter), planned FSMA regime commencement 25 October 2027, and the overseas-provider territorial scope point.
  15. [14]UKProceeds of Crime Act 2002: section 327, section 328, section 329, section 330.PrimaryReviewed 25 Aug 2026. Supports: the separate statutory structure of ss.327-329 (concealing/disguising/converting/transferring/removal; arrangement facilitating another's acquisition, retention, use or control; acquiring/using/possessing) and s.330's full conditions (regulated-sector information, the further identification-or-assistance condition, failure to disclose as soon as practicable), each subject to its own statutory exceptions and defences.
  16. [15]UKMoney Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017: Regulation 28, Regulation 33; 2026 amendment narrowing the Regulation 33 country trigger to FATF call-for-action countries, legislation.gov.uk.PrimaryReviewed 25 Aug 2026. Supports: Regulation 28's full CDD content (identification/verification, beneficial owners, persons acting for customers, purpose and intended nature, ongoing monitoring) and Regulation 33's mandatory ("requires", not "can apply") enhanced due diligence trigger list, including the 2026 FATF call-for-action narrowing effective from 30 June 2026.
  17. [16]USFinancial Crimes Enforcement Network (FinCEN), issued 14 October 2025, Imposition of Special Measure Regarding Huione Group, as a Foreign Financial Institution of Primary Money Laundering Concern, effective 17 November 2025; full text federalregister.gov, FinCEN release fincen.gov; June 2026 proposal to add H Pay Service PLC and successor entities, fincen.gov; corroborated by Money Laundering Watch (Ballard Spahr), FinCEN Bars Huione Group from Financial System, moneylaunderingnews.comPrimary FinCEN/Federal Register full text; Secondary law-firm commentary corroboration. Reviewed 25 Aug 2026. Supports: Huione Group case-study facts at Node Six (subsidiaries, US-only jurisdiction, three-part prohibition scope, stated grounds, Huione Pay PLC's lapsed Cambodian licence, the H Pay Service PLC proposal's non-operative status). Date note: FinCEN's own issuance date (14 October 2025) is distinct from the Federal Register public-inspection filing (15 October 2025) and the Federal Register publication date (16 October 2025); all three are real, different documents, not interchangeable. USD 4 billion figure: stated directly in FinCEN's own primary text: "FinCEN's analysis identified that, in the aggregate, Huione Group has received at least USD 4 billion worth of illicit proceeds, between August 2021 and January 2025."
Knowledge Check
Five questions across the numbers, the chain, and the worked scenarios.
1. True or false: FATF's nearly USD 500 billion figure and UNODC's regional estimates measure the same thing.
2. Which best describes the "aggregator" node in this guide's payment chain?
3. TRM Labs found that stablecoins were involved in what share of illicit crypto activity in Q1 2025, despite 99% of stablecoin activity overall being licit?
4. In Worked Scenario One, why is "investigate as a potential first-layer mule account" the strongest answer over "treat solely as APP fraud"?
5. True or false: a red flag indicator, on its own, is sufficient grounds to file a SAR.
0/5
Frequently Asked

FAQ

Is every newly formed company, or every shell company, a sign of money laundering?
No. A newly incorporated company is not inherently suspicious. Risk depends on whether its ownership, activity and financial behaviour are consistent with its stated purpose. The relevant question is whether the company's financial behaviour matches its declared business, not whether it is new or has a simple corporate structure.
Does using a stablecoin make a transaction suspicious?
No. The large majority of stablecoin activity is legitimate. Risk depends on the counterparties, the pattern, and the economic rationale, not the asset type itself.
If I see one red flag from this guide, should I file a SAR immediately?
Not automatically. A single indicator is a prompt for further examination, not proof, and neither the number nor the combination of indicators creates a statutory suspicion or SAR reporting threshold. Whether the facts meet your firm's actual reporting threshold is a legal and regulatory judgement, see Section 17, UK legal context.
Why does this guide separate the FATF, UNODC, TRM and Chainalysis figures instead of giving one headline number?
Because they measure different things: a global loss estimate, two different-year regional loss estimates, and two crypto-specific tracked-flow estimates. Combining them would overstate precision none of the individual sources actually claims.
Is a scam compound the same thing as a money laundering network?
No. A scam compound generates victims and proceeds. The laundering network that moves those proceeds may be a separate structure entirely, sometimes in a different jurisdiction, sometimes run by different people. Section 2, Scam compounds are only one part of the machine, covers this distinction directly.
Quick Reference

At a glance: the nine-node chain

Each node's full red-flag set lives in its own section above, reachable from the chain strip near the top or the contents list alongside.

💳
1. Victim Payment
The first observable event; unusual beneficiary, urgency, or a small test payment followed by a larger one.
🏦
2. Receiving Account
First account controlled by the network; sudden velocity, rapid outflow, unexplained source.
🕸️
3. Mule Network
Resilience through distribution; look for network features, not single-account anomalies.
🧲
4. Aggregator
An analytical label, not a FATF category; concentrates many victim relationships into one choke point.
🏢
5. Shell Company
Gives the money a commercial appearance; the question is economic behaviour, not newness.
💱
6. OTC / Offshore VASP
Where fiat becomes virtual asset value; risk comes from opacity and nested relationships, not the channel itself.
🪙
7. Stablecoin
Fast, global, low-volatility transport; 99% licit overall, still 60% of Q1 2025 illicit crypto activity.
🌀
8. Layering
Deliberately degrades investigative context; ask what economic purpose each hop actually served.
🚪
9. Off Ramp
Usable value, not just cash; where the cycle can reconnect with legitimate-looking economic activity.
Continue Reading

Related topics