10th July – 12th July 2026
Sanctions
OFAC Clarifies Specific Licensing Requirements for US Entities Paying Russia "Exit Taxes"
The US Department of the Treasury's Office of Foreign Assets Control (OFAC) has updated its Russia-related sanctions guidance to clarify that US persons divesting assets from the Russian Federation must obtain a specific licence prior to paying any Russian "exit tax". Under the updated Frequently Asked Questions, specifically FAQ 1118 and FAQ 999, OFAC indicated that these exit taxes involve payments to Directive 4 entities under Executive Order 14024, which include the Central Bank, the National Wealth Fund, and the Ministry of Finance of the Russian Federation. Because paying an exit tax is not considered "ordinarily incident and necessary to day-to-day operations," the regulator confirmed that such payments are not authorised under General Licence (GL) 13R and require a specific licence, which OFAC intends to review on an expedited, case-by-case basis. The guidance also noted that while the Russian commission reviewing these divestments may include blocked individuals, US persons do not need to seek OFAC authorisation for their prospective Russian buyers to submit divestment applications to that commission.
US Initiates Process to Rescind Syria’s Designation as a State Sponsor of Terrorism
The US Secretary of State Marco Rubio has announced that President Trump has formally notified Congress of the administration's intent to rescind Syria’s designation as a State Sponsor of Terrorism. This notification begins a mandatory 45-day pre-notification period, a step intended to eventually lift sanctions and open up international trade and investment. According to the official statement, the rescission follows a 30th June 2025 Executive Order directing sanctions relief, alongside recent counterterrorism actions and formal assurances from the Syrian government under President Ahmed al-Sharaa that Syria will not support international terrorism in the future.
HMRC Releases Annual Enforcement Data Detailing Billions Recovered from Tax Fraud and Sanctions Breaches
HM Revenue & Customs (HMRC) has published two technical notes detailing its enforcement outcomes for the 2025 to 2026 financial year, highlighting a combined multi-billion-pound yield across its tax fraud and trade sanctions divisions. The Fraud Investigation Service (FIS) reported a total compliance yield of £4,206 million, which was split nearly evenly between criminal investigations, delivering £2,114 million, and civil interventions, accounting for £2,092 million. This activity resulted in 260 criminal convictions with an 87% court success rate, alongside ongoing civil oversight of thousands of cases under Codes of Practice 8 and 9. On the sanctions front, HMRC, working in partnership with the newly established Office of Trade Sanctions Implementation (OTSI), secured 58 seizures of sanctioned goods, managed 22 ongoing criminal investigations, and issued a £1,160,725.76 compound settlement for breaches of the UK’s Russia sanctions regulations. To improve enforcement transparency, HMRC announced plans to seek new legislative powers in the 2026 to 2027 financial year to publish the identities of companies agreeing to compound settlements for strategic export and trade sanctions violations. HMRC’s Fraud Investigation Service: technical note is here, and the Sanctions enforcement: technical note is here.
UK Government Amends Sanctions Listing for ISIL Financial Mediator Hamidah Nabagala
The UK Foreign, Commonwealth and Development Office has updated its entry on the UK Sanctions List for Hamidah Nabagala under the Isil (Da'esh) and Al-Qaeda regulations. Nabagala, a Ugandan national who also uses the alias Hamidah Nabaggaka, remains subject to a UK asset freeze, travel ban, and arms embargo. According to official sanctions documentation, Nabagala operates as a mediator in financing channels for ISIL in Central Africa and stands charged with financing a 2021 bombing in the Ugandan capital of Kampala. The updated listing, which originally stemmed from a United Nations designation on 31st March 2026, also notes allegations that she attempted to coerce her three children to travel to ISIL camps in the Democratic Republic of Congo.
Money Laundering
Global Audit Points to Successes and Hidden Frictions in Anti-Money Laundering Coalitions
The Financial Action Task Force has published a global review detailing how governments and financial institutions pool data to trace dirty money. While the Paris-based watchdog identifies at least 84 partnerships worldwide, the reality on the ground appears uneven. Sharing basic strategic trends is relatively simple. Swapping active case files remains a different story. According to the report, only about 55 to 66 percent of surveyed jurisdictions actually exchange operational data, such as customer due diligence files.
This operational divide may suggest that deep structural barriers continue to limit the effectiveness of these joint ventures. Privacy regulations and strict banking secrecy laws, for instance, are cited by roughly half of the surveyed governments as persistent friction points. When banks receive alerts without clear guidance on how to manage the associated risks, some tend to simply shut down customer accounts. This defensive exit, known as de-risking, is likely to drive illicit activities into less regulated shadow networks rather than stopping them entirely. Some legal analysts suggest that without explicit safe-harbour protections, private firms will remain hesitant to share sensitive operational signals for fear of legal liability.
Yet results can be striking when the gears align. In one notable case, Singapore's Project FRONTIER+, which is a transnational alliance involving 13 jurisdictions, led to more than 2,100 arrests and the freezing of over 36,000 bank accounts linked to scams. Similarly, in the United Kingdom, bank-to-bank intelligence sharing under the Economic Crime and Corporate Transparency Act enabled two major institutions to uncover an underground banking network which had siphoned over £10 million.
However, scaling these successes globally is likely to require more than merely enthusiasm. Many lower-capacity nations struggle with basic technological limitations, often relying on slow, manual workarounds to pass information. Furthermore, differing legal rules across borders mean that evidence collected through a partnership in one country might not be admissible in the courts of another. Ultimately, the emerging consensus suggests that while public-private data sharing offers a potent weapon against modern financial crime, its long-term viability depends on whether regulators can resolve the delicate tension between aggressive policing and individual data privacy. The press release and infographic are here, and the report is here.
MONEYVAL Urges Armenia to Strengthen Money Laundering Prosecutions and Criminal Asset Recovery
The Council of Europe's anti-money laundering body, MONEYVAL, has released an evaluation report commending Armenia's solid understanding of financial crime risks and its effective implementation of targeted financial sanctions, while calling for significant improvements in prosecutions and asset recovery. The evaluation praised Armenia's Financial Intelligence Unit for expanding its resources and providing high-quality intelligence, as well as the country's proactive cooperation with foreign counterparts in corruption cases. However, the report noted that Armenia's legal framework remains predominantly driven by domestic predicate offences, with restrictive interpretations of money laundering laws contributing to low conviction rates. Additionally, the watchdog identified ongoing structural gaps, including the need to complete the beneficial ownership register, improve suspicious activity reporting by the private sector, and enhance supervision over newly regulated areas like virtual asset service providers. Consequently, Armenia has been placed in MONEYVAL’s enhanced follow-up process and issued a three-year roadmap of recommended actions to address these regulatory deficiencies.
EBA Publishes Final Technical Package for Reporting Framework 4.3 to Support Third-Country Branches and AMLA Risk Assessments
The European Banking Authority (EBA) has published the final technical package for version 4.3 of its reporting framework. This release establishes the standardised validation rules, data point models (DPM), and XBRL taxonomies necessary to implement new supervisory reporting requirements for Third-Country Branches (TCBs) under the Capital Requirements Directive (CRD). Furthermore, the package supports the Anti-Money Laundering Authority (AMLA) by introducing components to facilitate its data collection methodology for identifying obliged entities which will fall under its direct supervision. Incorporating industry feedback from an earlier draft published in April 2026, the final package sets a first reference date of 31st December 2026, for AMLA risk assessment reporting, followed by a 31st March 2027, reference date for TCB reporting. To ease implementation, the EBA also issued a new Glossary Usage Exploration file to help firms navigate the semantic model, while noting it may release a targeted "hotfix" update in late September to address any urgent technical adjustments.
Fraud
Former Puerto Rico Private Equity Fund Manager Indicted and Arrested for Alleged $11 Million Embezzlement
A federal grand jury in the District of Puerto Rico has indicted Gian C. Piovanetti, a certified public accountant and former private equity fund manager, on charges of bank fund embezzlement, conspiracy to commit money laundering, and five counts of money laundering. The indictment alleges that between 6th May 2024, and 1st July 2024, Piovanetti diverted approximately $11,266,493.00 from a private equity fund's deposit account under the custody of a local financial institution. According to court documents, he secretly used these unauthorised transfers to fund personal luxury purchases—including a 2024 Porsche Cayenne Coupe registered to his wife and options to acquire apartments outside of Puerto Rico—and to pay off credit card balances. Following an investigation by the FBI, Piovanetti was scheduled to make his initial appearance before US Magistrate Judge Héctor Ramos-Vega on 9th July 2026, and faces a maximum penalty of 30 years in prison if convicted.
OCC Highlights Updated FinCEN Guidance on Voluntary Fraud Information Sharing
The Office of the Comptroller of the Currency (OCC) has highlighted an updated Section 314(b) Fact Sheet issued by the Financial Crimes Enforcement Network (FinCEN) clarifying how financial institutions can share information regarding suspected fraud, money laundering, and terrorist financing. The updated guidance under Section 314(b) of the USA PATRIOT Act provides participating entities, including community banks, with a safe harbour which protects them from liability when exchanging operational intelligence. Specifically, the guidelines list shareable data types such as video surveillance footage, IP addresses, and key fraud indicators like geographically distant login activity or newly added payees followed by large transfers. Under this framework, registered financial institutions or associations can share these details even if the sending entity has no reason to believe the information relates to a specific customer, account, or transaction of the receiving institution. The OCC indicated that it continues to encourage voluntary information sharing under this safe harbor as part of a coordinated, whole-of-government effort to combat fraud.
INTERPOL-Coordinated "Operation First Light 2026" Results in Over 5,800 Arrests and Interception of $293 Million
A global anti-fraud campaign coordinated by INTERPOL across 97 countries has culminated in the arrest of 5,811 individuals and the interception of USD $293 million in illicit assets. Spanning from mid-January to late April 2026, "Operation First Light 2026" targeted transnational social engineering scams and their associated money laundering operations. The scale of the threat was vast. Investigators identified over 142,000 victims worldwide, analysed 152,808 cases, and blocked 31,014 bank accounts. To freeze these fast-moving digital and fiat assets, law enforcement relied heavily on INTERPOL’s Global Rapid Intervention of Payments (I-GRIP) stop-payment mechanism. While the intervention represents a substantial blow to transnational networks, the sheer volume of cases is likely to indicate that cyber-enabled fraud continues to expand faster than traditional domestic policing can easily manage on its own. Supported by regional policing bodies like Europol and funded by China’s Ministry of Public Security, the operation dismantled diverse criminal enterprises, ranging from a romance-scam money laundering ring in Thailand to an organised syndicate in Eswatini which used a realistic replica of a Brazilian police station to run impersonation scams.
Market Abuse
The FCA’s Tougher Stance on Market Abuse: A Busy First Year, but the Battle Is Far from Over
The UK’s financial watchdog is turning up the heat on market misconduct. According to the Financial Conduct Authority’s latest annual report, the first year of its five-year strategy yielded some heavy-hitting results, including 17 criminal convictions and a combined 11 years in prison for two insider dealing cases. This aggressive enforcement is not just statistics on a page; it is actively translating into real-world prosecutions.
Consider the recent case of Richard Bloomfield, a 38-year-old solicitor charged just this week with five counts of insider dealing. The regulator alleges that Bloomfield used sensitive, non-public details about the acquisition of Seraphine Group plc, which was information he obtained through his legal role, to trade in the company's shares on five occasions. He recently appeared before Westminster Magistrates' Court and has been sent to Southwark Crown Court, where his next appearance is scheduled for 5th August 2026. The case illustrates the FCA’s willingness to go after professionals in trusted positions, though notably, neither the law firm itself nor Seraphine Group PLC are under investigation.
But traditional insider trading is only part of the problem. The watchdog has also been forced to open a new front on social media, targeting "finfluencers" who hawk financial products online without authorisation. A coordinated global sweep in June 2025 led to three arrests and 650 social media takedown requests. This digital crackdown may suggest that the nature of market abuse is shifting rapidly toward retail platforms. However, critics might wonder if 650 takedown requests are merely a drop in the ocean given the viral nature of modern social media.
Some market analysts argue that while high-profile prosecutions may get the headlines, the regulator's most significant challenge lies in prevention. The FCA highlights that its warning messages and tools like the "Firm Checker" are protecting hundreds of consumers weekly, yet the persistent rise in unauthorised firms, with warnings climbing to 2,329, appears to show that illicit operators are highly adaptable. Ultimately, these enforcement victories show a watchdog willing to fight, but the sheer volume of digital scams suggests that maintaining market integrity in an internet-first world remains an uphill battle.
Bribery and Corruption
OECD Issues Public Due Diligence Warning Over Türkiye’s Anti-Bribery Compliance Failures
The OECD Working Group on Bribery has issued a public due diligence warning concerning Türkiye's long-standing compliance failures under the OECD Anti-Bribery Convention. The Working Group highlighted repeated, serious shortcomings since Türkiye joined the convention in 2000, including key legislative gaps in corporate liability, an inability to fine individuals for foreign bribery, and a lack of public and private sector whistleblower protections. Additionally, the watchdog noted an absence of a national strategy to combat foreign bribery alongside a lack of meaningful efforts to investigate and prosecute actual allegations. Consequently, the international body took the exceptional step of advising commercial partners, multilateral development banks, and member nations that Türkiye's regulatory gaps may justify increased due diligence over Turkish companies. This public warning will remain in effect until the Working Group determines that the country has effectively addressed these underlying enforcement and legislative deficiencies.
Other Financial Crime
Anti-Corruption Analysts Warn Against Proposed Reintroduction of UK Investor Visa Scheme
Following reports that UK ministers are considering a new investor visa pathway, Transparency International has cautioned that reviving the programme could introduce significant national security and money laundering risks with minimal economic benefit. The warnings highlight that the previous Tier 1 (Investor) route was closed in February 2022 after a government review linked it to illicit finance, noting past structural failures where visas were granted to subsequently sanctioned individuals and transnational crime figures. While the proposed "invite-only" model aims to mitigate these vulnerabilities, policy advocates argue it may introduce new risks of undue influence, rely too heavily on private sector wealth managers for due diligence, and struggle to manage shifting security profiles. Additionally, critics warn that establishing a new investor visa pathway could compromise the UK's regulatory credibility during its current presidency of the Financial Action Task Force (FATF), especially ahead of its upcoming 18-month mutual evaluation and a scheduled global summit on illicit finance in December.
House of Commons Library Publishes New Research Briefing on SLAPPs Ahead of Parliamentary Debate
The UK House of Commons Library has published a new research briefing detailing the impact of strategic lawsuits against public participation (SLAPPs). Written by Ruth Lamont, Joanna Dawson, Lisa Rowland, and Harriet Samuel, the briefing outlines how these legal claims, often involving defamation, privacy, or data protection, are brought to silence critics through costly, meritless litigation. The publication highlights key legislative developments, including the early strike-out rules for economic crime-related SLAPPs introduced under the Economic Crime and Corporate Transparency Act 2023 (ECCTA) on 18th June 2025, alongside the first case to apply these measures, Kamal v Tax Policy Associates. Additionally, the briefing outlines the ongoing debate and legislative efforts to extend anti-SLAPP protections beyond financial crime, serving as a background resource for a House of Commons Chamber debate on the topic led by Alex Sobel MP on 9th July 2026.
Cybercrime
UK Treasury Study Challenges Boards to Reframe Cyber Resilience from an IT Expense to a Performance Multiplier
For years, corporate boards have treated cybersecurity as a tedious compliance exercise, regarding it as more of a defensive cost centre to be minimised rather than a strategic asset. A newly released UK Treasury report suggests this perspective is not only outdated but potentially dangerous. In an era of hyper-connected supply chains, cyber disruptions are no longer isolated technical glitches. Instead, they are increasingly behaving as material balance-sheet events which can depress a firm’s market value long after the initial breach is resolved. Recent data indicates that publicly listed companies suffering a major cyber incident underperform the market by an average of 5% for a year or more.
This vulnerability is likely to grow as the threat landscape shifts. In its first-half 2026 survey, the Bank of England found that 82% of UK financial institutions now rank cyber-attacks as a top-five risk to the financial system, a 10-percentage point increase from just two years ago. Yet, a deep disconnect persists between this systemic threat and boardroom attitudes. For instance, a recent survey of UK consumer-facing senior leaders revealed that 64% believe resilience investments yield few business benefits beyond basic risk reduction. Furthermore, nearly half of those surveyed expressed belief that their industries are already spending too much on security.
This corporate hesitation may stem from a fundamental misunderstanding of how cyber risk behaves. Standard risk assessments often rely on average annualised losses. This is a mistake. Modelling from KPMG Cyber Risk Insights suggests that ransomware losses are highly skewed. In a typical year, a firm might experience zero material losses. This quiet period can easily lull executives into a false sense of safety. However, the tail risk is massive. For a mid-sized financial firm, a plausible worst-case scenario could exceed £230 million, while large institutions face potential exposures approaching £466 million. Looking only at averages appears to obscure these catastrophic potential outcomes.
Still, critics of increased security spending frequently argue that the apparent link between high resilience and strong corporate performance is merely a matter of correlation. More profitable firms simply have deeper pockets to fund expensive security teams. While this perspective carries weight, recent academic research covering the years 2009 to 2023 suggests a more direct, causal relationship. The study found that implementing formal cybersecurity policies is statistically linked to subsequent gains in bank profitability, largely by mitigating operational risks and building trust with stakeholders.
The stakes are set to rise further with the emergence of frontier artificial intelligence models. Economic Secretary to the Treasury Rachel Blake cautioned that these advanced technologies are likely to increase the speed and automation of cyber threats. Ultimately, the Treasury's findings suggest that treating cyber resilience as an optional technical insurance policy is a losing strategy. Rather than holding businesses back, a proactive security posture appears to serve as a baseline requirement for scaling new digital systems with confidence.