14th August – 16th August 2026
Sanctions
Rice Lake Weighing Systems Agrees to $60,764 Settlement with OFAC Over Apparent Iran Sanctions Violations
The US Department of the Treasury’s Office of Foreign Assets Control (OFAC) has announced a $60,764 settlement with Wisconsin-based manufacturer Rice Lake Weighing Systems, Inc. to resolve potential civil liability for eight apparent violations of US sanctions against Iran. According to the settlement announcement, between July 2019 and November 2021, Rice Lake's Italian subsidiary, Dini Argeo S.r.l., exported weighing equipment to a distributor in the United Arab Emirates with the knowledge that the goods were destined for reexport to an end-user in Iran. OFAC determined that the apparent violations, which involved the indirect shipment of restricted equipment to Iran, were voluntarily self-disclosed by the company and were non-egregious.
UK's OFSI Amends and Extends Lukoil General Licences with New Notification Requirements
The UK's Office of Financial Sanctions Implementation (OFSI) published amendments to two key Russian sanctions licences: the Lukoil International General Licence (INT/2025/8031092) and the Lukoil Bulgaria General Licence (INT/2025/7895596). Under the updated terms, both authorisations, which permit the continuation of business operations and payment processing involving designated Lukoil subsidiaries, now mandate a new, one-off written notification requirement. Entities currently relying on these licences, or those beginning to use them on or after 12th August 2026, must provide their contact details and notify OFSI within 14 days of their first use. Along with these new compliance obligations, OFSI has extended the expiration dates for both licences; the Lukoil International licence has been extended to 26th February 2027, while the Lukoil Bulgaria licence is now extended to 29th October 2026.
Money Laundering
US Treasury Permanently Repeals Beneficial Ownership Reporting Rule for Domestic Businesses
The US Treasury Department has permanently repealed a key regulatory rule under the Corporate Transparency Act (CTA) which required domestic businesses to report their beneficial ownership details to the Financial Crimes Enforcement Network (FinCEN). Under the new advisory, Treasury will also delete all previously collected data on American business owners, though foreign companies and pooled investment vehicles must still report their foreign ownership information. Treasury Secretary Scott Bessent and Small Business Administration head Kelly Loeffler defended the repeal, arguing that it eliminates an unnecessary compliance burden for millions of job creators and will save American businesses an estimated $6.7 billion over the next decade. Conversely, the decision has drawn sharp criticism from Democratic lawmakers and national security experts, who contend that removing these reporting mandates creates a significant gap in the US financial system, making it easier for drug cartels, human traffickers, and money launderers to exploit anonymous shell companies to avoid detection.
Market Abuse
SEC Charges Three New Jersey Residents in Connection with Alleged $47 Million Affinity Fraud
In the US, the Securities and Exchange Commission (SEC) has charged Toms River, New Jersey, residents Leor Moshe, Jacob Goldman, and Isaac Odes, for their alleged roles in an affinity fraud scheme which raised approximately $47 million from over 87 investors, primarily targeting members of Orthodox Jewish communities in New York and New Jersey. According to the complaint, Moshe orchestrated the scheme through his company, Capital Funding ASAP LLC, promising high fixed returns on short-term business loans while misappropriating over $11 million for personal use and using $850,000 for Ponzi-like payments to earlier investors. Goldman and Odes, acting as unregistered brokers, allegedly recruited investors and raised more than $23 million of the total funds. The SEC is seeking permanent injunctions, disgorgement, and civil penalties, while the US Attorney’s Office for the District of New Jersey has filed parallel criminal charges against Moshe.
Cybercrime
ICO Reprimands ACRO Criminal Records Office Over Cyber Security Failings
The Information Commissioner's Office (ICO) in the UK has issued a formal reprimand to the ACRO Criminal Records Office (ACRO) following cyber security failures which potentially exposed the personal and sensitive data of up to 10,920 individuals. An ICO investigation established that between August 2022 and March 2023, a hacker exploited vulnerability gaps to gain unauthorised access to ACRO’s website and content management system (CMS), staging personal information, including National Insurance numbers, passport details, bank accounts, biometric data, and criminal offence records, for potential theft. The regulator identified systemic deficiencies in ACRO’s operations, notably a failure to establish clear ownership for critical CMS updates, a lack of an effective patch management programme, and a failure to investigate automated security alerts which could have disrupted the hacker's activity sooner. While the ICO noted that internal network segmentation successfully prevented the attacker from accessing core databases, the agency urged all organisations to establish clear accountability for security updates and actively monitor system warning signs.
Global Cyber Landscape Shifts as Taiwan Discloses Autonomous AI Hacking Campaign and US Authorises Private Sector Offensive Operations
In the US, President Trump has signed a national security presidential memorandum aimed at integrating the private sector into offensive government-controlled cybersecurity operations. The policy directs the newly established programme under the National Coordination Centre (NCC) to authorise vetted private US companies to conduct "Cyber Surveillance Operations" and "Cyber Effects Operations" against foreign cyber-enabled transnational criminal organisations (CE-TCOs). Overseen by co-Executive Directors from the Department of Justice and the Department of Homeland Security, participating firms will be required to undergo rigorous vetting, enter into federal contracts, and maintain a compliance bond or escrow of at least $1 million. Under the supervision of the federal government, authorised private actors may manipulate, disrupt, or degrade specified foreign target systems, though operations likely to result in loss of life, serious injury, or actions rising to an armed attack under international law remain prohibited. While the administration seeks to use private sector technical speed and innovation to counter foreign ransomware and financial fraud networks, it has raised questions regarding the international liabilities and physical risks participating firms might face as they enmesh themselves in state-supervised digital conflicts.
This significant policy shift comes amid growing international concern over the rapid evolution of artificial intelligence in cyber warfare, highlighted by a significant digital intrusion recently disclosed by Taiwan. Taiwan's Ministry of Digital Affairs has revealed that cybersecurity units had investigated an "abnormal" overseas-sourced cyber-attack which targeted government agencies beginning on 20th July. According to reporting, the intrusion involved a "first-of-a-kind" autonomous hacking tool, which combined manual operations with open-source AI agents such as "Open Claw", behaved as a highly coordinated, multi-member digital threat team. The tool successfully compromised at least 85 government user accounts and extracted over 2,500 personnel records before expanding its campaign to Taiwan's nuclear safety agency and at least seven energy companies. Although human operators remain necessary to establish target parameters and directives, the overall speed and scale of cyber threats have escalated due to advanced models which can rapidly scan networks, identify vulnerabilities, and automate exploits. While Taiwanese officials did not formally accuse any state actor, investigators noted that the use of Simplified Chinese in internal communications linked to the hack suggested a high probability of connection to Chinese operators.