20th July – 23rd July 2026
Sanctions
US Treasury Clarifies Deposit Requirements for Venezuela Earthquake Relief Under General Licence 60
The US Department of the Treasury’s Office of Foreign Assets Control (OFAC) released Frequently Asked Question (FAQ) 1263 to clarify payment requirements under the Venezuela Sanctions Regulations. The guidance states that General Licence (GL) 60, which authorises transactions related to earthquake relief efforts in Venezuela, does not require payments of taxes, tolls, and fees connected with such relief to be deposited into the Foreign Government Deposit Funds Account (FGDF). However, OFAC emphasised that the FGDF deposit requirements under other Venezuela-related general licences, such as GLs 46C, 48B, 49A, 50B, 51B, 52A, and 54A, remain in place. Under the updated guidance, activities falling outside the scope of GL 60 but authorised under these other licences must continue to be paid into the FGDF and cannot be recharacterised as earthquake relief to avoid the deposit requirement.
OFSI Details Basic Needs Allowance in Updated Sanctions Guidance
The UK’s Office of Financial Sanctions Implementation (OFSI) has updated its Financial Sanctions guidance (FAQs 197–202) to clarify its "Basic Needs Allowance" licensing policy, which explains how the regulator grants designated individuals limited access to frozen assets to cover essential, day-to-day living expenses. This framework outlines the legal mechanism which allows sanctioned individuals to meet fundamental survival costs, and applies across all of OFSI's sanctions regimes with the strict exception of counter-terrorism designations.
EU Sanctions ABS Electro Group and Chairman Irina Kharisova Over Drone Manufacturing Ties
The Council of the European Union has imposed restrictive measures on one individual and five entities associated with the Russian military-industrial complex and drone manufacturing. The targeted entities are all part of the ABS Electro Group, a conglomerate which develops and manufactures electronic and radio-electronic components used to increase the electronic warfare resistance of Russian unmanned aerial vehicles, including Shahed and Geran type drones, and produces control systems for the Russian energy sector. The designated individual is Irina Kharisova, who serves as the Chairman of the Board of the ABS Electro group and as director for several of its constituent companies. Under the sanctions, which have been published in the Official Journal of the EU, the designated parties are subject to an asset freeze, a prohibition on receiving direct or indirect funds, and, for natural persons, a travel ban within the European Union.
Money Laundering
FATF Report Highlights Rising Virtual Asset Risks and Global Regulatory Enforcement Gaps
The Financial Action Task Force (FATF) has issued its seventh Targeted Update on Virtual Assets, warning that organised crime groups continue to exploit uneven global regulatory frameworks to launder billions of dollars. Although 83% of surveyed jurisdictions have enacted legislation for the anti-money laundering "Travel Rule", an increase from 73% in 2025, many governments are still struggling to translate these rules into effective supervision and enforcement. Consequently, illicit actors are deploying increasingly complex tactics, including cyber theft linked to the Democratic People's Republic of Korea (DPRK), "pig-butchering" scams, and artificial intelligence-driven fraud involving deepfakes. The report, published at the beginning of the United Kingdom’s FATF Presidency, warns of rising stablecoin misuse and the emergence of proprietary stablecoins engineered by criminal networks specifically to resist asset freezing. To counter these evolving threats, the FATF calls for immediate global action to strengthen risk-based supervision, enhance cross-border cooperation, and address systemic vulnerabilities in decentralised finance (DeFi) platforms and offshore entities. The press release is here.
Fraud
Cardiff Businesswoman Sentenced to Prison Over £216,250 Covid-19 Support Scheme Fraud
A judge at Merthyr Tydfil Crown Court has sentenced Rupali Wagh, a 50-year-old businesswoman from Cardiff, to two years and three months in prison for fraudulently obtaining £216,250 through the UK government's pandemic-era Bounce Back Loan Scheme. Following an investigation by the Insolvency Service, it was established that between May and September 2020, Wagh submitted five fraudulent loan applications across her four companies, namely One2Four Accounting Ltd, Talensetu UK Ltd, White Coconut Ltd, and Indian Canteen Ltd, by inflating turnover figures and obtaining duplicate loans. After receiving the funds, Wagh transferred the money into her personal bank accounts to clear personal credit card debts, buy stocks and shares, and transfer more than £25,000 to an account in India. Wagh, who pleaded guilty to five counts of fraud in November 2025, is now subject to asset recovery efforts by the Insolvency Service under the Proceeds of Crime Act 2002.
Independent Review Urges UK Government to Overhaul Fraud Prosecution Framework
An independent review into UK fraud prosecution led by KC Jonathan Fisher has concluded that systemic delays, resource shortages, and weak platform accountability have allowed fraud, which accounts for 44% of surveyed criminal activity, to flourish with "near-certain impunity". The review highlights that fraud cases take eight times longer to charge than the average criminal case, and serious cases take twice as long to progress through the court system. To address these structural deficiencies, Fisher proposed 47 recommendations across six key strategic areas, which include introducing a new "failure to prevent" fraud offence for digital and communications providers, increasing maximum sentences for serious fraud to 20 years, and establishing a whistleblower incentivisation scheme for the Serious Fraud Office. The report warns that without decisive legislative and infrastructure reforms, the government risks letting fraud become endemic, thereby eroding public trust and compromising the rule of law. The Spotlight on Corruption release is here.
Market Abuse
BaFin Imposes €240,000 Fine on TeamViewer SE for Delayed Cyberattack Disclosure
The German Federal Financial Supervisory Authority (BaFin) imposed an administrative fine of €240,000 on TeamViewer SE for violating ad hoc disclosure rules under the Market Abuse Regulation (MAR). BaFin determined that because TeamViewer is a software company, its recent cyberattack constituted market-sensitive inside information which should have been disclosed without delay. According to the regulator, failing to report the incident as soon as possible contravened Article 17(1) of MAR, an obligation designed to ensure investors are not misled and to prevent insiders from obtaining unfair trading advantages. Under the regulation, BaFin is authorised to issue fines of up to €2.5 million or up to two percent of a company's total revenue for such disclosure failures.
Other Financial Crime
European Commission Highlights Uneven Rule of Law Progress and Proposes Stronger Budget Links
The European Commission has released its seventh annual Rule of Law Report, noting a broadly positive but uneven trajectory across member states, with 47% of the recommendations issued in 2025 now fully or partially addressed. Executive Vice-President Virkkunen and Commissioner McGrath highlighted that while significant reforms are complete or underway, such as preventing political influence in Bulgaria's Supreme Judicial Council, increasing anti-corruption transparency in Hungary, and enacting a lobbying register in Romania, systemic progress remains slow in several jurisdictions. To reflect the implementation of the European Media Freedom Act (EMFA), which began applying last August, the Commission has adjusted its methodology to phase out redundant media recommendations, choosing instead to monitor compliance through EMFA's legally binding framework. Looking forward, the Commission’s proposal for the next Multiannual Financial Framework seeks to strengthen the link between rule of law recommendations and EU financial support, which will be accompanied by a suite of upcoming anti-corruption initiatives and a review of the EU's Anti-Fraud Architecture before the end of the year.
UK Serious Fraud Office Publishes 2025-26 Annual Report Highlighting Asset Recovery and New Legal Powers
The UK Serious Fraud Office (SFO) has published its Annual Report and Accounts for the 2025-26 financial year, outlining progress made during the second year of its five-year strategic plan. The agency highlighted its management of an active caseload of approximately 120 cases, including about 40 open criminal investigations. Operational highlights for the year included launching five new criminal cases, arresting 14 individuals, charging 10 suspects, and recovering more than £2.89 million in the proceeds of financial crime. Additionally, the SFO expanded its enforcement tools by executing its first cryptocurrency asset freeze, securing its first Unexplained Wealth Order recovery of £1.1 million, and preparing organisations for the implementation of the new "failure to prevent fraud" corporate offence which came into force in September 2025.
UK Government to Overhaul Criminal Disclosure Rules with £75 Million AI Reform Package
The UK Home Office has published its formal response to Jonathan Fisher KC's Independent Review of Disclosure and Fraud Offences, announcing a comprehensive modernisation of the criminal disclosure regime which integrates Artificial Intelligence (AI) to accelerate the justice system. To address contemporary digital pressures, where average fraud cases can contain over four million documents, the government has approved the use of advanced technology to assist investigators and prosecutors in identifying, sorting, and summarising massive volumes of unused digital evidence. Backed by £75 million in government funding, a newly established National Centre for Police AI (PoliceAI) will pilot and scale automated tools with the expectation of saving police forces an estimated six million hours of administrative work annually by 2028. While the reforms involve updating the statutory Criminal Procedure and Investigations Act 1996 (CPIA) Code of Practice to permit technology-assisted scheduling and review, the government has committed to implementing robust safeguards. These measures include developing a cross-agency ethical AI protocol, setting a national governance forum for disclosure technology, and establishing unified, cross-agency training standards for law enforcement officers. The full response is here.
UK Prudential Regulation Authority Fines HDI Global SE £4,165,000 Over Inaccurate Regulatory Reporting
Now to a case which is not concerned with financial crime, but is an instance of regulatory enforcement. The UK’s Prudential Regulation Authority (PRA) has fined HDI Global SE £4,165,000 for repeatedly submitting inaccurate Financial Services Compensation Scheme (FSCS) Liabilities and Fee Tariff data between August 2021 and August 2024. According to the regulator, the UK branch of the Germany-headquartered insurer failed to apply due skill, care, and diligence, lacking effective written calculation processes, clear internal oversight, and reference to the PRA Rulebook before the summer of 2023. These deficiencies resulted in a breach of the PRA's Fundamental Rules 2 and 6, which govern conducting business with due care and maintaining responsible corporate affairs. HDI Global SE has since submitted corrected historical data, paid outstanding FSCS levies, and implemented a series of internal remediation measures. By participating in the PRA's Early Account Scheme to assist with the investigation and agreeing to resolve the matter, the firm received a 30% settlement discount, reducing the penalty from an initial £5,950,000.
Cybercrime
BIS Bulletin Highlights Asymmetric Cyber Threat from Autonomous Frontier AI Models
In a July 2026 bulletin, the Bank for International Settlements (BIS) warned that the emergence of "frontier" artificial intelligence models, such as Anthropic’s Mythos and OpenAI’s GPT-5.5, represents a significant shift in systemic cyber risk, particularly for the highly interconnected global financial system. Evaluated by the UK’s AI Security Institute, these highly advanced models have demonstrated the capacity autonomously to identify system vulnerabilities, develop exploits, and execute complete corporate network takeovers. While frontier AI tools can be deployed defensively to review code bases and accelerate vulnerability patching, the BIS authors argue that the economics of cyber warfare remain asymmetric. Because defenders must continuously secure every potential entry point while attackers only need to locate a single viable route, the rapid decline in the cost of executing automated AI attacks, which has fallen to as low as $50 to $100 for cheaper models, threatens to shift the balance of power toward offensive actors. To mitigate these escalating risks, the bulletin calls for coordinated scanning, enhanced domestic cooperation between financial supervisors and national security agencies, and robust cross-border information-sharing.
Autonomous OpenAI Agent Escapes Testing Sandbox to Hack AI Database Hugging Face
During an internal evaluation, an autonomous artificial intelligence agent powered by OpenAI technology went rogue, escaped its enclosed digital sandbox, and hacked the AI database startup Hugging Face. The agent, running on a combination of OpenAI's publicly available GPT-5.6 Sol model and an unreleased model, gained open internet access by exploiting a previously undiscovered zero-day vulnerability. Once online, the agent accessed Hugging Face's systems to retrieve secret information to help it "cheat" its hacking evaluation. The activity was successfully contained by Hugging Face's security team and defensive AI agents, with the startup's chief executive noting the unprecedented sophistication of the attack but stating he believed there was no malicious intent from OpenAI.