The payment doesn't end the story, it starts a different one
A scam compound may look like a fraud operation. Financially, it is better understood as the front end of a much larger criminal value chain. The person messaging a victim may never control the bank account that receives the money. The holder of that account may never meet the person controlling the next account. The company buying cryptocurrency may have no visible connection to the original scam. By the time the proceeds reach a stablecoin wallet, several institutions, identities, legal entities and jurisdictions may sit between the victim and the criminal organisation. That fragmentation is not incidental. It is part of the laundering architecture.
FATF has described cyber-enabled fraud syndicates as organised structures with specialised functions, including dedicated money laundering capabilities. The resulting laundering networks can involve individual money mules, legal persons, banks, payment providers, remittance providers and virtual asset service providers. Proceeds may move rapidly across accounts, institutions and jurisdictions [2][3].
A note on how FATF material is used throughout this guide: FATF Recommendations are international standards addressed to countries. FATF guidance and typology reports, cited repeatedly below, can inform risk analysis, but they do not themselves create UK firm-level obligations; any binding UK duty must come from applicable domestic legislation, regulation or regulatory rules, see Section 17.
This guide follows that movement:
The objective is not to memorise a single scam typology. It is to understand what each node is trying to achieve, what information disappears at every handoff, and which signals can reconnect the chain. Every pill above is a live link, and stays reachable from the sidebar contents throughout the guide.
First, keep the numbers separate
The scale of scam activity is frequently described using figures that measure different things. They should not be combined.
FATF global estimate
At the launch of FATF's 2026 to 2028 Roadmap on Combatting Fraud on 1 July 2026, FATF President Giles Thomson put the global scale at nearly USD 500 billion lost to scams across 2024 and 2025. This guide attributes that figure solely to Thomson's Roadmap launch and treats it as FATF's own global estimate. It is not a UK Fraud Strategy figure and should not be presented as one [1].
UNODC regional estimates
Separately, UNODC estimated financial losses of USD 18 billion to USD 37 billion from scams targeting victims across East and Southeast Asia during 2023, published in its October 2024 report on the region's cyber-enabled fraud economy [8].
UNODC's follow-up report, published 21 July 2026, put 2025 losses across East Asia, Southeast Asia, Australia and New Zealand at USD 88.3 billion to USD 114.1 billion, nearly triple the 2023 figure, which UNODC itself describes as reflecting the dramatic scaling of this criminal economy [8b].
Both are regional estimates, for different years and slightly different regional scope. Neither validates, reproduces, or forms the basis of the FATF global figure above, and the two UNODC figures should not be averaged or treated as directly comparable without noting the scope difference.
Chainalysis crypto tracking
Chainalysis reported that addresses it had identified as associated with cryptocurrency scams received at least USD 14 billion on chain during 2025. It describes this as a lower bound that increases as additional illicit addresses are identified [12]. That is observed or attributed cryptocurrency flow. It is not an estimate of total global scam losses.
TRM Labs crypto tracking
TRM Labs reported at least USD 10.7 billion in cryptocurrency sent to fraud in 2024 within its observed dataset. TRM similarly cautions that fraud attribution increases over time as additional activity becomes known [10]. Again, this is crypto-specific tracked activity, not total scam losses.
Why this distinction matters
A victim loss survey and an analytics firm's attributed blockchain inflow are measuring different things. Putting them in the same chart without explaining the denominator creates false precision. For investigators, the more useful question is not how big is the scam economy, it is what happens to the victim's money after the payment succeeds.
Scam compounds are only one part of the machine
INTERPOL describes transnational scam centres as criminal hubs associated with large-scale fraud, trafficking and abuse. People inside compounds may be forced to conduct romance scams, investment fraud, cryptocurrency scams, impersonation fraud and other schemes. INTERPOL also cautions that not everybody working in a scam centre is necessarily a trafficking victim [9].
The laundering function can sit elsewhere entirely. A useful analytical model is to separate two machines. The fraud machine acquires victims. The laundering machine acquires, moves, converts and ultimately makes usable the proceeds generated from those victims. FATF has found that the place where the fraud occurs and the place where the laundering occurs are frequently different. Proceeds can move through networks spanning multiple jurisdictions and financial institutions [3].
This means an analyst in Birmingham may be looking at one UK bank account without seeing the compound, recruiter, controller, overseas broker or wallet sitting further along the chain. The analytical challenge is therefore reconstruction.
Work through the nine nodes in order, each has its own red flags, open the disclosure under each node before moving on. Then work both worked scenarios for the reasoning, not just the answer. The knowledge check pulls from across the whole chain, and the FAQ closes out the most common edge cases.
The victim payment
The laundering chain begins before the receiving account moves anything. The first observable event is usually a payment authorised or initiated by the victim. Depending on the scam, the victim may believe they are investing money, paying an invoice, helping a romantic partner, moving money to a supposedly safe account, paying tax or withdrawal fees, funding a cryptocurrency investment, completing paid online tasks, or responding to an impersonated business or authority.
FATF has identified patterns including unusual beneficiary information, small successful payments followed by larger payments, urgent instructions and transaction details inconsistent with previously verified behaviour [3].
Red flags at the victim node
- A newly introduced beneficiary
- A small test payment followed quickly by a substantially larger payment
- Unusual investment-related payment descriptions
- Beneficiary account details inconsistent with an expected recipient
- Sudden deviation from the customer's normal transaction pattern
- Repeated payments following apparent successful receipt of the first payment
- Customer communications indicating urgency, secrecy or external instruction
- Payments to recently established companies with no obvious connection to the customer
- Payments inconsistent with the customer's historic economic activity
FATF itself cautions that the presence of one indicator may not independently warrant suspicion. Indicators are prompts for further examination, not automatic conclusions [3]. That principle applies to every node in this chain.
The receiving account
This is the first account controlled, directly or indirectly, by the criminal ecosystem. For some fraud types FATF has observed individual mule accounts as common first-layer accounts. For other typologies, particularly certain trading and business email compromise schemes, corporate accounts including newly registered or shell companies may be used at the first layer [3]. The account's job is simple: receive the victim's money without immediately exposing the controller.
The account may previously have behaved normally. Then something changes. Salary credits of £1,500 a month become £15,000 of incoming transfers from unrelated people. A student account starts processing business-sized turnover. A dormant company begins receiving consumer payments. Incoming funds leave almost immediately. The account holder cannot explain who the payers are. FATF has documented mule structures in which participants hand over credentials, cards or other access mechanisms, allowing the criminal syndicate to exercise direct control over the account [3].
Red flags at the receiving account
- Sudden transaction velocity inconsistent with historical use
- Incoming transfers from multiple unrelated individuals
- Immediate or rapid onward movement
- Near-complete depletion of the received balance
- Turnover inconsistent with the customer's economic profile
- Customer unable to explain the source or purpose of incoming payments
- Assertion that the account is being used on behalf of somebody else
- New account followed quickly by significant transaction activity
- Account details or identity information changing soon after onboarding
- Multiple accounts linked through common devices, credentials, telephone numbers or IP infrastructure
- Remote access indicators inconsistent with normal account usage
- Fraud recalls or reports received from sending institutions
The NCA defines money mule networks as people or accounts used to launder criminal funds, with controllers organising transactions while attempting to retain their own anonymity [6].
The mule network
One receiving account is vulnerable. A network is resilient. The criminal organisation distributes proceeds across multiple accounts so that losing one account does not necessarily disrupt the entire payment chain. Some mules knowingly participate. Some are deceived. Some may understand that something is wrong without understanding the underlying offence. FATF recognises this variation in mule culpability and notes that online recruitment can be scaled through social media and messaging platforms [3].
The UK threat is not theoretical. In one NCA-reported fraud case concluded around Operation Henhouse activity, more than 300 victims were targeted through fraudulent vehicle advertisements. Investigators identified more than 90 money mules, many recruited through social media with offers of quick cash [7].
Red flags across the mule network
Do not analyse each account in isolation. Look for network features:
- Multiple accounts receiving from apparently unrelated victims
- Common destination accounts
- Common device identifiers
- Common IP infrastructure
- Repeated transaction amounts or timing patterns
- Similar account opening characteristics
- Similar payment narratives
- Common cash withdrawal locations
- Shared cryptocurrency counterparties
- Shared company beneficiaries
- Repeated fraud recalls across apparently unrelated account holders
- Movement that becomes increasingly concentrated as funds progress through the network
A transaction monitoring alert asks is this account suspicious? A network investigation asks what role is this account performing? The second question is more useful.
The aggregator
For this guide, aggregator is an analytical label rather than a statutory or FATF-defined category. It describes an account, wallet or entity that receives funds from multiple first-layer or intermediate accounts and concentrates them before further movement. FATF describes cyber-enabled fraud proceeds being rapidly layered through pass-through transactions across domestic and foreign accounts, and documents patterns in which numerous companies and individual accomplices circulate proceeds through structured networks [3].
The aggregator is where apparently separate scams can begin to look like one financial operation. Imagine twelve mule accounts, each receiving between £2,000 and £9,000 from different victims. All twelve send most of their balances to the same company account. That company may never have contacted a victim. Yet from a network perspective it may be more important than any individual mule.
Red flags at the aggregator
- Many unrelated originating accounts converging on one beneficiary
- Counterparties concentrated around known or suspected mule activity
- High inbound transaction count followed by fewer high-value outbound transfers
- Extremely short holding periods
- Turnover far beyond the customer's expected activity
- Transactions with no credible commercial relationship between counterparties
- Repeated balance sweeping
- Multiple fraud-exposed accounts feeding one destination
- Rapid conversion into another asset class
- Onward transfers to VASPs, money service businesses or overseas entities
- Movement patterns inconsistent with the stated nature of the business
The analytical value of the aggregator is concentration. The criminal has reduced hundreds of victim relationships into a smaller number of controllable financial relationships. That creates efficiency for the criminal organisation. It can also create an investigative choke point.
The shell company
Not every shell company is criminal. Not every newly incorporated company is suspicious. The risk arises from the relationship between the corporate profile and the movement of money. FATF has documented cyber-enabled fraud laundering structures involving shell companies controlled through straw persons or nominee directors, and cases where mules were used to open corporate accounts or act as nominal company representatives [3].
One FATF case study described an online trading fraud network involving 209 companies. Investigators identified common accountants, companies created around similar dates, rapid liquidation and movement of proceeds between the companies. Some funds subsequently moved to VASPs [3]. The NCA's 2026 National Strategic Assessment separately states that criminals continue to exploit UK corporate structures for fraud and illicit finance [5].
Red flags at the corporate node
- Company recently established before high transaction volumes begin
- Vague or extremely broad stated business activity
- Payment flows inconsistent with the declared industry
- Large numbers of unrelated retail payers
- Common directors, addresses, accountants or contact information across apparently separate entities
- Limited evidence of genuine operating activity
- Rapid transfer of most incoming funds
- Frequent transactions with other recently formed companies
- Merchant activity inconsistent with the company's business model
- Unexplained payments to cryptocurrency businesses
- High turnover unsupported by reasonable commercial documentation
- Customer or director unable to explain material counterparties
- Virtual address combined with other indicators of opacity
The important question is not is this a shell company? It is does the economic behaviour of this legal entity make sense?
The OTC broker or offshore VASP
At some point, fiat proceeds may need to cross into virtual assets. That can occur through regulated exchanges, peer-to-peer activity, OTC brokers, cryptoasset businesses, offshore VASPs, or combinations of these channels. OTC activity is not inherently illicit. Offshore VASPs are not inherently criminal either. The risk comes from opacity, regulatory gaps, nested relationships, customer profile mismatch and exposure to known illicit flows.
FATF defines an offshore VASP as a VASP created under the laws of one jurisdiction, with or without a physical presence there, that provides services to customers in another jurisdiction. Its March 2026 report found that uneven oversight can create exploitable gaps, and specifically identified dispersal across multiple addresses, layered intermediary wallets, multiple blockchains and nested relationships as methods relevant to illicit finance through some offshore VASP structures. FATF also documented cases where offshore VASPs were used to convert proceeds associated with scam compounds [4].
Red flags at the conversion node
- Customer activity inconsistent with declared crypto experience or business model
- Sudden high-value conversion following large fiat inflows
- Funds originating from newly formed or opaque companies
- Third-party funding with no credible economic explanation
- Repeated use of counterparties with limited transparency
- Exposure to unlicensed or unregistered providers where registration would be expected
- Transactions involving nested service relationships
- Rapid conversion followed by movement to unhosted wallets
- Transfers across several platforms without credible investment or commercial rationale
- Source-of-funds documentation inconsistent with transaction volume
- Customer explanation focused on transaction mechanics rather than economic purpose
- Recurring exposure to known scam-related wallets or entities
As at August 2026, a business providing cryptoasset services within Regulation 14A while acting in the course of business in the United Kingdom must register with the FCA before beginning those services. The new FSMA cryptoasset regime starts on 25 October 2027 [13]. An overseas provider is not automatically within the MLR registration perimeter merely because it permits a UK resident to become a customer; the assessment depends on the activities undertaken and whether the provider acts in the course of business in the United Kingdom. This does not determine the separate UK financial promotions position, which can apply to marketing directed at UK consumers regardless of where the provider is based.
Huione Group: what a Section 311 finding actually establishes
United States jurisdiction only. This case study concerns a United States Section 311 measure and does not establish any obligation under UK law.
On 14 October 2025, FinCEN issued a final rule, effective 17 November 2025, after finding reasonable grounds to conclude that Huione Group, a Cambodia-based (Phnom Penh) financial services conglomerate, was a foreign financial institution of primary money laundering concern. Three distinct dates attach to this rule and are not interchangeable: FinCEN's own issuance date is 14 October 2025; the Federal Register public-inspection filing is dated 15 October 2025; the Federal Register publication date is 16 October 2025. This guide uses FinCEN's own issuance date as the primary date. The rule prohibits covered US financial institutions from opening or maintaining a correspondent account in the United States for, or on behalf of, Huione Group. It also requires those institutions to take reasonable steps to prevent their covered correspondent accounts from processing transactions involving Huione Group, and requires specified special due diligence on their foreign correspondent accounts [16].
FinCEN based its finding on several matters, kept separate here rather than blended into one: services Huione Group provided that DPRK government entities used to launder proceeds of cyber heists; use of Huione Group by Southeast Asian criminal organisations to launder proceeds of cyber scams, including convertible virtual currency investment scams such as so-called "pig butchering" schemes; and Huione Group's operation of an illicit online market. FinCEN's analysis identified that, in the aggregate, Huione Group received at least USD 4 billion worth of illicit proceeds between August 2021 and January 2025, a figure stated directly in FinCEN's own primary text. This is FinCEN's assessment, not a criminal conviction of any individual [16].
The final rule's definition of Huione Group includes Haowang Guarantee (formerly Huione Guarantee), Huione Pay PLC, and Huione Crypto. Huione Pay PLC had previously been registered as a Cambodian payment services institution, but by 2025 its Cambodian licence had been rescinded by the National Bank of Cambodia and it no longer appeared in the Ministry of Commerce's business registration database [16]. In June 2026, FinCEN proposed amending the definition to include H Pay Service PLC and successor entities; as at August 2026 that remains a proposed amendment, not part of the operative 2025 final rule, and this guide does not present it as such.
This guide cites the finding at Node Six deliberately, and the mapping below is this guide's own analytical application of FinCEN's findings, not wording used by FinCEN itself: Haowang Guarantee illustrates an online marketplace functioning as a conversion and off-ramp point for scam proceeds, the same functional role this guide describes at Nodes Six and Nine, not an isolated or hypothetical pattern.
What this case study does and does not establish: a Section 311 special measure is a finding that an entity is a foreign financial institution of primary money laundering concern, followed by US correspondent-banking restrictions of the scope described above. It is not a criminal conviction of any individual, and it creates no UK obligation.
Stablecoin conversion
Stablecoins solve a problem for legitimate commerce and criminal finance alike. They permit digital value to move quickly across borders while avoiding much of the price volatility associated with assets such as Bitcoin. That does not make stablecoins inherently suspicious.
TRM Labs estimates that approximately 99 per cent of stablecoin activity in the period it analysed was licit. At the same time, stablecoins represented around 60 per cent of the illicit crypto activity observed by TRM during the first quarter of 2025 [11]. Those two facts can coexist: large legitimate usage alongside significant criminal adoption. Chainalysis likewise reported that stablecoins represented a large share of identified illicit cryptocurrency transaction volume during 2025; that measurement covers illicit crypto activity broadly and should not be presented as a scam loss figure [12].
Red flags at the stablecoin node
FATF's cyber-enabled fraud risk indicators include:
- Large volumes or high-frequency transactions involving unhosted wallets
- Exposure to addresses associated with scammers or other illicit services
- Inability to evidence the origin of virtual assets or the fiat used to acquire them
- Use of several types of virtual asset without reasonable explanation
- Abnormal peer-to-peer wallet activity lacking logical business purpose
- Rapid onward transfers following acquisition
- Interaction with high-risk jurisdictions or services when combined with other indicators
Source: FATF, Illicit Financial Flows from Cyber Enabled Fraud [3].
Blockchain transparency can make this stage more observable than the criminal may expect. The challenge is connecting blockchain evidence to the identities and fiat accounts that preceded it.
Layering
Layering is where investigative context is deliberately degraded. FATF describes cyber-enabled fraud proceeds moving through pass-through transactions involving domestic and foreign accounts, with techniques including movement through different financial institutions, payment providers and remittance providers, smurfing, and conversion into different forms of value, including virtual assets [3]. Within virtual assets, FATF's 2026 offshore VASP work describes dispersal across multiple addresses, intermediary wallets and multiple blockchains as relevant obfuscation patterns [4].
The objective is not necessarily to make tracing impossible. It is to increase the cost, time and jurisdictional complexity of reconstruction.
Red flags during layering
- Repeated rapid transfers with minimal holding periods
- Multiple intermediate accounts with no clear commercial function
- Repeated asset conversion without economic justification
- Transfers across several exchanges or wallets in short succession
- Fragmentation followed by reconsolidation
- Movement involving numerous jurisdictions
- Wallet activity inconsistent with the customer's stated investment strategy
- Transactions crossing several service providers without clear purpose
- Related entities transferring funds amongst themselves
- Payment paths that appear economically circular
- Counterparties whose only apparent function is receiving and forwarding value
What economic purpose did this intermediate transaction achieve? If the only observable purpose is to make the trail longer, risk increases. That is still an analytical inference, not proof of criminal intent.
The off ramp
Eventually the organisation needs usable value. That does not always mean cash: the endpoint may involve fiat withdrawal, bank transfer, cash, goods, property, another business, settlement with another criminal network, reinvestment into the fraud operation, or payment for criminal infrastructure.
The NCA's 2026 National Strategic Assessment describes professional money laundering networks servicing multiple organised crime groups and notes models involving collection, consolidation and conversion of criminal value into cryptocurrency. It also describes international controller networks capable of arranging value movement across borders without every stage relying on the conventional banking system [5]. The criminal objective is therefore better understood as usable value, not simply cash.
Red flags at the off ramp
- Large fiat withdrawals following complex inbound crypto activity
- Third-party bank accounts receiving exchange withdrawals
- Multiple unrelated beneficiaries
- Crypto conversion followed immediately by fiat withdrawal
- Customer activity inconsistent with stated wealth or business profile
- Repeated use of accounts whose principal function appears to be value conversion
- Funds leaving towards newly established companies
- Unusual payments into sectors or assets unrelated to the customer's normal activity
- Withdrawal counterparties connected to known mule or laundering networks
- Repeated conversion activity with little evidence of legitimate trading rationale
This is where the laundering cycle can reconnect with apparently legitimate economic activity.
The real control gap: every institution sees a different crime
The sending bank may see an unusual victim payment. The receiving bank may see a young customer with incoming transfers. A second bank may see a company receiving money from multiple individuals. A VASP may see a company purchasing USDT. A blockchain analytics platform may see wallet exposure. An overseas exchange may see a customer selling stablecoins.
Each institution can therefore hold a fact that appears weak alone. The network can become obvious only when those facts are connected. This is why FATF's current fraud programme places significant emphasis on information sharing, payment transparency, asset recovery and cross-border cooperation [1][2]. The laundering machine benefits from organisational fragmentation. Detection improves when investigators reconstruct the chain rather than stopping at the alert.
A UK current account belongs to a 23-year-old customer. Historic behaviour shows monthly salary credits of approximately £1,600, rent, groceries, and occasional transfers between savings accounts. During one afternoon the account receives eleven Faster Payments from unrelated individuals, total value £18,640. Within three hours, £17,900 is transferred to a recently incorporated UK company described as a digital marketing business. The customer retains £740 and states: "Friends owed me money and I forwarded it to someone helping us invest." Two sending institutions subsequently submit fraud-related recalls.
Decision Point One
Decision Point Two
A UK-incorporated business states that it provides software consultancy, with expected annual turnover of £280,000 given at onboarding. The business has historically received payments from four commercial clients. Over six weeks, behaviour changes: the account receives approximately £410,000 from more than 60 individuals, with payment references including "investment," "trading account," "deposit," "membership" and "recharge." Approximately £360,000 is transferred to cryptoasset service providers, and a further £32,000 goes to another recently incorporated company. Blockchain analysis available to the VASP shows much of the purchased USDT moving rapidly through intermediary wallets, with one destination showing exposure to addresses previously associated with scam activity. The director says the business recently began "handling payments for overseas partners" but provides no contracts supporting that explanation.
Decision Point One
Decision Point Two
The investigator's mental model
When analysing a suspected scam laundering structure, do not ask only who received the victim's money? Ask nine questions, one per node.
- Victim payment: Why did the victim send it?
- Receiving account: Who first received it?
- Mule network: Which other accounts behave the same way?
- Aggregator: Where do apparently separate flows converge?
- Shell company: Which legal entity gives the money a commercial appearance?
- OTC or offshore VASP: Where does fiat become virtual asset value?
- Stablecoin: Which asset becomes the transport mechanism?
- Layering: What transactions degrade the original context?
- Off ramp: Where does the organisation obtain usable value?
That turns transaction review into financial network analysis.
What should trigger escalation?
No universal numerical threshold works for every institution or customer. This ladder is an internal analytical prioritisation model only. Neither the number nor the combination of indicators creates a statutory suspicion or SAR reporting threshold. Indicators must be assessed in context against the applicable law and the firm's procedures.
One unusual payment.
Unusual payment plus profile mismatch plus rapid onward transfer.
Multiple unrelated originators plus rapid onward transfers plus common beneficiaries plus fraud recalls.
Multiple suspected victim or mule accounts converge on an entity that rapidly moves funds into another financial sector or asset type, with weak economic explanation and additional counterparty intelligence.
The key principle is convergence of independent indicators, not a count against any threshold.
UK legal context
This section deliberately stays narrow because operational AML decisions depend on the firm's regulatory status, facts and applicable law.
Sections 327, 328 and 329 of the Proceeds of Crime Act 2002 create separate principal money laundering offences. Section 327 covers concealing, disguising, converting or transferring criminal property, or removing it from the relevant UK jurisdiction. Section 328 covers entering into or becoming concerned in an arrangement that the person knows or suspects facilitates another person's acquisition, retention, use or control of criminal property. Section 329 covers acquiring, using or possessing criminal property. Each offence is subject to its own statutory exceptions and defences [14].
Section 330 creates a failure to disclose offence only where all its statutory conditions are satisfied, including the applicable knowledge, suspicion or reasonable-grounds condition, receipt of the relevant information during regulated-sector business, the further identification-or-assistance condition, and failure to disclose as soon as practicable. Statutory defences and exceptions may apply [14].
Where customer due diligence is required, Regulation 28 of the Money Laundering Regulations 2017 requires the relevant person to identify the customer and verify the customer's identity using information from a reliable and independent source. It also contains measures concerning beneficial owners and persons acting for customers, and requires the relevant person to assess and, where appropriate, obtain information on the purpose and intended nature of the business relationship or occasional transaction. Ongoing monitoring applies to business relationships and includes scrutiny of transactions for consistency with the relevant person's knowledge of the customer, business and risk profile, including source of funds where necessary, together with keeping customer due diligence information current [15]. Regulation 33 requires a relevant person to apply enhanced customer due diligence and enhanced ongoing monitoring, in addition to the applicable Regulation 28 and 29 measures, in every case falling within Regulation 33(1). These include cases the relevant person identifies as high risk, specified relationships or transactions involving a FATF call-for-action country, specified correspondent relationships, PEP cases, certain false or stolen identification cases, defined unusual transactions, and other cases that by their nature present a higher risk of money laundering or terrorist financing. Regulations 34, 34A and 35 prescribe additional measures for particular categories [15].
A suspicious pattern therefore should not automatically be translated into "file a SAR because a red flag exists." Neither the number nor the combination of indicators creates a statutory suspicion or SAR reporting threshold; the facts must be assessed in context against the applicable legal and regulatory threshold and the firm's reporting procedures. FATF Recommendations are international standards addressed to countries; FATF guidance and typology reports can inform risk analysis, but they do not themselves create UK firm-level obligations, any binding UK duty must come from applicable domestic legislation, regulation or regulatory rules.
The central lesson
The biggest analytical mistake is to think the scam ends when the victim presses Send. For the criminal organisation, that payment is the beginning of another process. The money must be received, separated from the victim, moved through controlled accounts, concentrated, placed behind individuals or companies, converted, transferred across institutions or jurisdictions, layered, and ultimately made useful.
The organisations running scam compounds can therefore be understood not only as fraud enterprises but as producers of illicit financial flows feeding a broader professional laundering ecosystem. FATF, UNODC and the NCA all describe elements of this convergence, although each source examines the problem from a different geographic and methodological perspective [2][3][5][8].
The investigator's advantage is that the machine leaves traces at every handoff. The challenge is recognising that nine weak signals across nine different systems may describe one strong network.
Legal note
This guide is educational content for financial crime and compliance professionals. It is not legal advice and should not be relied on as a substitute for independent legal or regulatory advice. Regulatory and statutory citations reflect the law as understood at the time of publication (25 August 2026) and should be independently verified against current primary sources before being relied upon. References to United States regulatory action, including the FinCEN Section 311 case study, describe United States law only and do not establish any obligation under UK law.
Sources and methodology
Sources were last reviewed on 25 August 2026. This guide is an educational resource for financial crime and compliance professionals. It does not constitute legal advice. The scenarios are fictional composites created to teach analytical judgement; they do not reproduce a specific investigation or allege criminal conduct by any real individual or business.
- [1]GlobalFinancial Action Task Force, 1 July 2026, UK takes over Presidency of Financial Action Task Force (2026-2028). fatf-gafi.org
- [2]GlobalFinancial Action Task Force, 24 February 2026, Cyber Enabled Fraud: Digitalisation and Money Laundering, Terrorist Financing and Proliferation Financing Risks. fatf-gafi.org
- [3]GlobalFATF, INTERPOL and Egmont Group, November 2023, Illicit Financial Flows from Cyber Enabled Fraud. fatf-gafi.org
- [4]GlobalFinancial Action Task Force, 11 March 2026, Understanding and Mitigating the Risks of Offshore Virtual Asset Service Providers. fatf-gafi.org
- [5]UKNational Crime Agency, National Strategic Assessment 2026, Serious and Organised Crime Finance section. nationalcrimeagency.gov.uk
- [6]UKNational Crime Agency, Money Mules: Don't Be Used. nationalcrimeagency.gov.uk
- [7]UKNational Crime Agency, 2026, Operation Henhouse reporting. nationalcrimeagency.gov.uk
- [8]SE AsiaUnited Nations Office on Drugs and Crime, October 2024, Transnational Organized Crime and the Convergence of Cyber-Enabled Fraud, Underground Banking and Technological Innovation in Southeast Asia. unodc.org
- [8b]Asia-PacificUnited Nations Office on Drugs and Crime, 21 July 2026, An Interconnected Criminal Ecosystem: Transnational Organized Crime Threat Assessment for Southeast Asia 2026. unodc.org
- [9]GlobalINTERPOL, 26 November 2025, Growing Threat of Transnational Scam Centres Highlighted at INTERPOL General Assembly. interpol.int
- [10]IndustryTRM Labs, 2025 Crypto Crime Report. trmlabs.com
- [11]IndustryTRM Labs, 2025 Stablecoin Usage Report. trmlabs.com
- [12]IndustryChainalysis, 2026 Crypto Crime Report: Scams. chainalysis.com
- [13]UKFinancial Conduct Authority, updated 30 June 2026, Cryptoasset Firms: Registration under the Money Laundering Regulations Ahead of the New FSMA Regime. fca.org.uk; territorial-scope point additionally supported by FCA, Cryptoassets: who needs to register, fca.org.uk
- [14]UKProceeds of Crime Act 2002: section 327, section 328, section 329, section 330.
- [15]UKMoney Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017: Regulation 28, Regulation 33; 2026 amendment narrowing the Regulation 33 country trigger to FATF call-for-action countries, legislation.gov.uk.
- [16]USFinancial Crimes Enforcement Network (FinCEN), issued 14 October 2025, Imposition of Special Measure Regarding Huione Group, as a Foreign Financial Institution of Primary Money Laundering Concern, effective 17 November 2025; full text federalregister.gov, FinCEN release fincen.gov; June 2026 proposal to add H Pay Service PLC and successor entities, fincen.gov; corroborated by Money Laundering Watch (Ballard Spahr), FinCEN Bars Huione Group from Financial System, moneylaunderingnews.com
FAQ
Is every newly formed company, or every shell company, a sign of money laundering?
Does using a stablecoin make a transaction suspicious?
If I see one red flag from this guide, should I file a SAR immediately?
Why does this guide separate the FATF, UNODC, TRM and Chainalysis figures instead of giving one headline number?
Is a scam compound the same thing as a money laundering network?
At a glance: the nine-node chain
Each node's full red-flag set lives in its own section above, reachable from the chain strip near the top or the contents list alongside.