On September 2, 2026, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) reissued its Geographic Targeting Order (GTO) aimed at money services businesses (MSBs) along the U.S. southwest border. The GTO requires certain MSBs in designated border communities to file Currency Transaction Reports (CTRs) on cash transactions that would otherwise fall below the standard reporting threshold.

The full text of the reissued GTO is available here. FinCEN’s press release can be found here. We have covered prior iterations of this GTO on our blog and will continue to monitor developments in this area.

Here is what you need to know.

Why Another GTO?

FinCEN has been issuing and renewing these southwest border GTOs since early 2025.Under the Bank Secrecy Act (BSA), FinCEN can impose additional recordkeeping and reporting obligations on financial institutions and other businesses in a specific geographic area when it determines those requirements are necessary to carry out the BSA’s purposes or prevent evasion. Each GTO lasts up to 180 days, which is why we see periodic renewals.

The broader context here is the Administration’s ongoing campaign against Mexico-based drug cartels. Secretary of the Treasury Scott Bessent framed the reissued GTO as a tool to “ensure law enforcement has the actionable data they need to follow the money.” That language tracks with the Administration’s broader strategy: Executive Order 14157 (January 20, 2025) established a process for designating cartels as Foreign Terrorist Organizations and Specially Designated Global Terrorists, and in February 2025, Treasury and State designated eight organizations, including six major Mexican cartels, under those authorities.

FinCEN has observed that MSBs along the southwest border face heightened money laundering risks, given their proximity to regions where cartels are actively moving illicit cash connected to drug, human, and weapons trafficking. The GTO’s reporting requirements, shaped by law enforcement input, are designed to generate investigative leads and support prosecutions targeting cartel-linked financial activity.

What Does the GTO Actually Require?

The bottom line: if you are an MSB in one of the covered ZIP codes, you need to file CTRs with FinCEN for cash transactions between $1,000 and $10,000. That threshold is below the standard $10,000 CTR requirement.

The covered geographic areas include specific ZIP codes in:

A “Covered Transaction” is any deposit, withdrawal, currency exchange, or other payment or transfer in currency of $1,000 or more but not more than $10,000. One important limitation: the GTO applies only to transactions conducted in a business’s MSB capacity, i.e., foreign currency exchange, check cashing, money orders, prepaid access, and money transmission. It does not reach other services an MSB business may offer, like retail sales. The reissued GTO is effective September 3, 2026, through March 1, 2027 and reports must be e-filed through the BSA E-Filing System.

Existing BSA Obligations Remain in Effect

The GTO is additive and does not replace or modify any of the existing BSA requirements that already apply to Covered Businesses. Standard CTRs for transactions over $10,000 and Suspicious Activity Reports (SARs) still need to be filed as usual. FinCEN is also encouraging voluntary SAR filings for transactions that look like they are structured to duck the $1,000 GTO threshold.

Record Retention and Penalties

Covered Businesses must retain all GTO-related reports and records for at least five years from the last effective day of the order, including any renewals. These records must be stored in an accessible manner and made available to FinCEN or law enforcement upon request.

Penalties for noncompliance are significant. Willful violations may result in civil penalties of the greater of $71,545 or the transaction amount (up to $286,184), assessed separately for each violation. This liability extends to individual partners, directors, officers, and employees who participate in the violation. Criminal penalties may include fines of up to $250,000 and imprisonment for up to five years.

What Should You Be Doing?

If you are an MSB in one of the covered areas, key action items include:

  • Confirming whether your business falls within the covered ZIP codes and meets the definition of a Covered Business
  • Ensuring you can identify and report Covered Transactions (cash transactions of $1,000–$10,000) within 30 days
  • Registering for the BSA E-Filing System if you have not already done so
  • Updating record retention protocols to meet the five-year requirement
  • If newly covered, marking October 3, 2026, on the calendar as your compliance deadline

FinCEN has published a detailed set of FAQs alongside the order that address common questions about covered transactions, aggregation, filing procedures, and more. We recommend reviewing both the GTO itself and the FAQs carefully.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

The Financial Crimes Enforcement Network (“FinCEN”) has proposed to revoke Banque Misr UAE’s (the “Bank”) correspondent banking access to U.S. financial institutions, finding that that the Bank is a financial institution operating outside of the U.S. and is of primary money laundering concern (the “Proposed Rule”).

This proposal was in direct response to current Iran sanctions and the Treasury Department’s “Operation Economic Outcast,” that launched in late August and sought to sever “financial lifelines” that sustain the Iranian regime. The operation mapped financial channels that Iran uses to evade sanctions and fund terrorist activities.

Treasury Secretary Bessant noted that “Treasury promised to sever every economic lifeline Tehran has left and finally end the threat of the Iranian regime.” FinCEN utilizes their authority pursuant to Section 11 of the Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001 (“USA PATRIOT Act”).

Section 311 grants the Treasury Secretary the authority to make a finding that reasonable grounds exist a financial institution operating outside of the U.S. is “of primary money laundering concern.” 31 U.S.C. 531A.

Grounds for Designation as a Primary Money Laundering Concern

The Bank is a commercial bank with five UAE-based branches and, according to the Proposal Rule, serves as a “critical access node” to the U.S. dollar for Iranian illicit finance. The Bank provides correspondent banking services to customers through three correspondent relationships with U.S. financial institutions.

As grounds for the designation, FinCEN looked at the following statutory factors: the extent to which the Bank is used to facilitate or promote money laundering; the extent to which the Bank is used for legitimate purposes; and the extent to which the action is sufficient to ensure that against international money laundering and other crimes.

The Proposed Rule estimates between 2024 and 2026, the Bank processed approximately $1.8 billion as part of “shadow banking” operations on behalf of 103 companies. Overall, FinCEN estimates approximately $9 billion of potential Iranian shadow banking activity occurred through U.S. correspondent accounts in 2024.

Shadow banking networks consist of Iran-based exchange houses and front companies that enable Iran-sanctioned companies to access the U.S. financial system through correspondent accounts. The Proposed Rule notes that front companies are predominantly registered in third-country jurisdictions, including the UAE to obscure beneficial ownership, disguise the origin of funds, and enable the movement of money.

While acknowledging that the Bank is likely used for legitimate purposes as well, there is evidence of shadow banking activity through the Bank.

Implications of the Proposed Rule

The comment period is open until October 1, 2026. If finalized, U.S. financial institutions:

  • are prohibited from opening or maintaining any correspondent accounts for the Bank, or on the Bank’s behalf;
  • must take reasonable steps to not process any transactions for a correspondent account in the U.S. of a foreign banking institution if the transaction involve the Bank; and
  •  must apply special due diligence measures to their foreign correspondent accounts that are reasonably designed to guard against processing transactions involving the Bank.

As proposed, the prohibition is limited to the Bank’s five UAE-based branches. FinCEN estimates that the burden of the proposal on U.S. financial institutions exists, but is minimal and would most commonly involve adding the Bank to preexisting sanctions screening and money laundering tools.

Upon the release of the Proposed Rule, it was reported that UAE and Egyptian central banks were coordinating in connection with FinCEN’s Proposed Rule.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

Banks and their employees face a difficult balancing act when discussing suspected fraud or money laundering activity with a customer on whose account activity the bank has filed a suspicious activity report (SAR).  The bank must take practical steps to protect the customer and the institution (for example, verifying transactions, restricting account access, or requesting additional documentation) while strictly preserving SAR confidentiality. If a bank employee discloses—or even inadvertently implies—that a SAR has been filed, that law enforcement is involved, or even that internal investigations are ongoing, the bank can be exposed to regulatory findings, civil penalties, litigation risk, and reputational harm.  What’s more, the employees engaged in these conversations may face discipline or termination for violating policy and confidentiality requirements. At the same time, poorly chosen language or a refusal to provide a customer with information about his or her account, can cause customer disputes, prompt complaints, or create safety risks for frontline personnel.

On September 2, 2026, FinCEN and the federal banking agencies (the Federal Reserve, FDIC, NCUA, and OCC) issued a joint statement clarifying the application of SAR confidentiality requirements to communications with customers. The statement explains that SAR confidentiality requirements do not prohibit banks and credit unions from communicating with customers about potentially fraudulent transactions, suspicious activity, account restrictions, or account closures, provided those communications do not disclose the existence of a SAR.

The statement follows a June 2025 Request for Information regarding payments fraud, in which commenters identified questions concerning the extent to which financial institutions may discuss fraud-related matters with customers when a SAR has been or may be filed. It also references Executive Order 14331, Guaranteeing Fair Banking for All Americans.

The Guidance

The agencies reiterate that the Bank Secrecy Act (BSA) prohibits the disclosure of a SAR or information that would reveal the existence of a SAR. At the same time, the agencies note that FinCEN’s SAR confidentiality regulations permit the disclosure of the underlying facts, transactions, and documents upon which a SAR is based.

As a result, banks and credit unions may communicate with customers or third parties regarding potentially fraudulent transactions, suspicious activity, account restrictions, and account closures, so long as the communication does not disclose that a SAR has been filed.

The agencies also state that the fact that a customer or third party could potentially infer from the underlying facts that a SAR may have been filed does not, by itself, constitute a prohibited disclosure under the SAR confidentiality requirements.

Relationship to Prior Guidance

The joint statement builds on existing SAR confidentiality guidance. FinCEN’s 2010 final rule addressing SAR confidentiality established that the prohibition on disclosure does not apply to the underlying facts, transactions, and documents on which a SAR is based. More recently, FinCEN’s September 2025 guidance regarding cross-border information sharing (FIN-2025-G001) reiterated that principle in the context of information sharing among affiliated institutions.

The September 2026 joint statement focuses specifically on communications with customers and provides additional clarification regarding how financial institutions may apply existing SAR confidentiality requirements in customer-facing situations.

Examples of Permissible Communications

The statement provides a non-exhaustive list of communications that “would not typically” disclose the existence of a SAR. Examples include:

  • Requesting customer due diligence information to better understand the nature and purpose of a customer relationship;
  • Notifying a customer that a delay, limitation, or account closure may be related to suspected fraud or suspicious activity;
  • Notifying a customer that a deposit, such as an altered or counterfeit check, has been rejected due to suspected fraud;
  • Asking about the purpose of a transaction or the source of funds;
  • Providing educational materials or warnings regarding fraud schemes, typologies, and money mule activity;
  • Communicating account maintenance decisions, including declining transactions or closing accounts; and
  • Requesting information concerning the originator or beneficiary of a funds transfer.

The agencies emphasize that institutions should evaluate communications on a case-by-case basis and exercise caution to avoid revealing the existence of a SAR.

Practical Considerations

The statement does not modify existing legal or regulatory requirements and does not create new supervisory expectations. Instead, it provides additional clarification regarding how existing SAR confidentiality requirements apply in the context of customer communications.

Financial institutions may wish to review existing policies, procedures, and training materials relating to customer communications in situations involving fraud investigations, suspicious activity reviews, account restrictions, and account closures. Institutions should also consider whether additional guidance or training is appropriate to help personnel distinguish between discussing underlying facts and disclosing information that could reveal the existence of a SAR.

Because the agencies’ examples are non-exhaustive and emphasize a facts-and-circumstances analysis, institutions should continue to assess individual situations carefully and document decision-making where appropriate.

Looking Ahead

The joint statement provides additional clarification regarding the scope of SAR confidentiality requirements and confirms that institutions generally may discuss underlying facts, transactions, and documents with customers, provided they do not disclose the existence of a SAR. Financial institutions should consider the guidance when evaluating customer communication practices and related compliance procedures.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

On August 11, 2026, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (“FinCEN”) renewed its Geographic Targeting Order (“GTO”) Imposing Recordkeeping and Reporting Requirements on Certain Financial Institutions in Minnesota. The GTO requires financial institutions located in Hennepin and Ramsey Counties, Minnesota, to “retain and report records of certain payments of $3,000 or more.”

The initial GTO was announced on January 9, 2026, as part of the Trump Administration’s efforts to combat alleged “rampant government benefits fraud in Minnesota.” The first GTO went into effect on February 12, 2026, and was set to expire on August 10, 2026. The renewed GTO has extended this deadline and will remain in effect until February 6, 2027. FinCEN has released frequently asked questions in connection with the renewal that explain the requirements of the renewed GTO.

The renewed GTO is nearly identical to the initial order but, as explained in the Frequently Asked Questions, exempts certain Covered Businesses “that are banks from [the] GTO’s requirement to record or report fund transfers where the originator falls into certain categories[.]” The exemptions are consistent with the Exemptive Relief Order for the Geographic Targeting Order Imposing Recordkeeping and Reporting Requirements on Certain Financial Institutions in Minnesota, which granted “tailored exemptive relief” to “exempt certain categories [of] fund transfers that are lower risk for government benefits fraud, and to allow banks sufficient time to report certain information required by the GTO.”

The renewed GTO continues to exempt banks from funds transfers where the originator falls into one of the sixteen categories excluded under the Customer Due Diligence Rule, but, importantly, it does not extend the temporary relief that had limited banks’ obligations to information already covered by the Recordkeeping Rule.

The renewed GTO, as explained, is otherwise identical to the first GTO. It requires banks and money services businesses (MSBs) located in Hennepin and Ramsey Counties to report international fund transfers of $3,000 or more when the beneficiary or recipient is located outside of the United States. Banks and MSBs located in these counties are “covered businesses,” which is defined as any bank as defined in 31 CFR 1010.100(d), or any money transmitter, as defined in 31 CFR 1010.100(ff)(5), with a branch, subsidiary, or office located in the covered geographic area. The GTO requires covered businesses to report to FinCEN certain information required to be retained under “31 CFR 1020.410(a)(1) and (2), along with certain other additional information, regardless of whether the information is provided with the payment order[.]” This information, which is set forth in the Frequently Asked Questions, includes:

1. The name and employer identification number of the Covered Business;

2. The account number of the originator;

3. The name of the beneficiary; 

4. The address of the beneficiary;

5. The date of birth of the beneficiary;

6. A phone number of the beneficiary;

7. An email address of the beneficiary; 

8. The account number of the beneficiary; 

9. Whether the source of funds for the transfer includes payments that are from any federal,

state, or local government contract or benefit program; and,

10. If the answer to question (9) is yes, whether those payments are from government

agencies to entities in which the originator has any ownership interest.

If the Covered Business is a money transmitter, additional information concerning the form of the transmittal is required. If the renewed GTO is “willfully” violated, a business could be subject to civil penalties, with a separate penalty applied for each individual violation. Criminal fines are also available, as well as imprisonment for no more than five years.

This renewed GTO is part of Secretary of the Treasury Scott Bessent’s plan “to follow the money” and should serve as a reminder that the Trump Administration appears willing to impose strict reporting requirements and enforcement tools to further its goals.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

On July 13, a divided Ninth Circuit panel upheld a lower court order that barred enforcement of FinCEN’s border Geographic Targeting Order (“GTO”). The GTO would have forced money services businesses (“MSBs”) in 30 ZIP codes along the U.S.-Mexico border to report cash transactions of just over $200, a dramatic reduction from the longstanding $10,000 reporting threshold. The decision in Novedades Y Servicios, Inc. v. FinCEN, 181 F.4th 961, 967 (9th Cir. 2026)  is a significant procedural check on the administration’s anti-cartel enforcement agenda.

Cartels as a National Security Priority

The Trump administration has repeatedly framed cartel-linked money laundering as a national security threat. On January 20, 2025 – the first day of his second term – President Trump issued an executive order designating certain international cartels as Foreign Terrorist Organizations and Specially Designated Global Terrorists. The order declared that cartels “present an unusual and extraordinary threat to the national security, foreign policy, and economy of the United States,” and set its goal as “the total elimination of these organizations’ presence in the United States.”

The border GTO flowed directly from that priority. Issued by FinCEN in March 2025, the GTO targeted MSBs in 30 ZIP codes along the U.S.-Mexico border, requiring a Currency Transaction Report (“CTR”) filing for any cash transaction between $200 and $10,000. Treasury Secretary Scott Bessent made the administration’s priorities clear: “[f]or too long, cartels have abused the U.S. financial system to profit from poisoning Americans with deadly fentanyl. At Treasury, we are expanding our efforts to keep drug money out of the United States and to provide law enforcement with additional information to put these traffickers behind bars.”

The Ninth Circuit Holding

The panel’s decision turned on administrative procedure rather than the merits of AML enforcement.  

The majority concluded that the border GTO was likely a rule – rather than an order – under the Administrative Procedure Act (APA), because it applied to all unnamed and unspecified MSBs across a geographic area home to over one million people, rather than targeting specific identified businesses based on particularized findings. Because 31 U.S.C. § 5326 authorizes FinCEN to act only by “order,” the GTO likely exceeded the agency’s statutory authority.

The panel also found that FinCEN was required to conduct notice-and-comment rulemaking which it skipped entirely, and that the GTO was likely arbitrary and capricious because FinCEN “entirely failed to consider the cost of compliance to regulated parties.” On that point, the court noted that the only evidence the government offered on cost consideration was an internal FinCEN memorandum dated “March XX” that was undated, in draft form, and heavily redacted.

Who Challenged It

The case was brought by the Institute for Justice on behalf of Esperanza Gomez Escobar, who owns and runs Novedades y Servicios, a family-run MSB in San Diego. Escobar’s customers are largely people without bank accounts who come in to cash paychecks and wire money to family.

The compliance burden was, by Escobar’s account, impossible for her MSB to absorb. The $200 threshold swept in roughly 99% of Novedades’s monthly transactions, and the complaint alleged that filing the resulting CTRs would require an additional 14 to 17 hours per day. During the single week the order was in effect, Escobar alleges she lost between 50 and 60 percent of her customers after explaining the new reporting requirements. The Institute for Justice argued the lowered threshold amounted to “enlisting [small business owners] as surveillance agents of the government.”

The dynamic is not new. As the President of the National Small Business Association told the Wall Street Journal in 2024 when discussing a separate FinCEN rule, “FinCEN has never dealt with small businesses, and small businesses don’t know who FinCEN is and FinCEN doesn’t know how to regulate small businesses.”

Implications

The Ninth Circuit’s decision is a procedural check rather than a policy reversal. Nothing in the Ninth Circuit’s ruling calls into question the policy objective of targeting cartel finances. The panel’s concerns were exclusively procedural: FinCEN bypassed formal notice-and-comment rulemaking, and the record before the Circuit suggested the agency never accounted for the costs it was imposing on border MSBs.

Financial institutions and their compliance teams should consider the following:

  • The injunction does not reduce the underlying compliance imperative. The administration’s commitment to disrupting cartel cash flows has not wavered, and a formally noticed rule is the likely next step.
  • For institutions with border exposure, the question is not whether new requirements will come, but when and in what form. FinCEN has every incentive – both political and practical – to return with a formally noticed rule.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

In an alert issued this July, FinCEN urged banks and other financial institutions to increase their focus on detecting, preventing, and reporting fraud schemes targeting federal student aid (“FSA”) programs. The alert provides specific red flags for identifying suspicious activity—and signals that regulators expect proactive compliance efforts.

The United States Department of Education (“ED”) has launched a national effort to prevent student aid fraud, and estimates that it prevented about $1 billion in FSA-related fraud in 2025 alone. The scale of FSA funding—and the associated fraud risks—is enormous. Every year approximately $120 billion go out to around 13 million students for grants, work-study funds, and low-interest loans. The FSA office also oversees the Free Application for Federal Student Aid (FAFSA), through which students apply for financial aid for post-secondary education.

FinCEN’s alert identifies the three most common types of schemes to defraud the FSA program, explaining how in each case, fraudsters seek to divert funds intended for bona fide student-recipients of federal aid. FSA funds are paid directly to educational institutions, and once those institutions apply the funds to any tuition and fees the student-recipients owe, the institutions then issue a “refund” of the difference to the students for use toward living expenses. Students must be enrolled in the institutions for 60% of the enrollment period to receive these refunds, and it is these refunds that most FSA schemes target.

The three types of schemes FinCEN identifies are those using “ghost students,” “straw students,” and insider assistance.

  • Ghost Students: In ghost-student schemes, fraudulent actors either use personally identifying information (“PII”) of identity theft victims, or wholly fabricated information to create synthetic identities, in order to pose as legitimate students. They then enroll these “ghost students” in educational institutions and apply for federal student aid and collect the FSA refunds. To satisfy the requirement that students maintain enrollment for 60% of the enrollment period, the fraudulent actors often use AI chatbots to complete the coursework.
  • Straw Students: Straw-student schemes are similar to ghost-student schemes, except that the enrolled student is a willing participant. In these cases, individuals provide their PII to be used in the fraudulent scheme, and they are willingly enrolled in educational institutions. The straw students typically do not attend classes, with the fraudsters ensuring the completion of any coursework required to satisfy the 60% requirement.
  • Insider-Assisted Schemes: Lastly, FinCEN explained that in some cases, a staff member with insider access will facilitate the scheme, including by recruiting straw students and helping ensure they get approved for FSA funds. The insider staff member will then either steal the aid refund entirely or require the students to pay a portion of the funds as a kickback in exchange for facilitating the scheme.

Banks can spot these schemes by watching for red flags when stolen refunds are laundered. Entities can usually identify deposits as FSA refunds by the transaction references in ACH deposits—typically identifying an educational institution (either by name or a common abbreviation) and “refund.” Once entities identify incoming FSA refunds, they may be able to flag the common tools used to launder the fraudulently obtained proceeds, including the use of “money mules” to transfer the funds, shell companies, fraudulent accounts opened with fake customer identification materials, and abuse of digital assets.

As guidance to banks and financial institutions seeking to improve detection of FSA schemes, FinCEN identifies the following “red flags,” which either independently or in conjunction with other indicators—such as a customer’s historical financial activity, whether transactions are in line with prevailing business practices, and whether multiple red flags coexist—can indicate that an account or customer is involved in an FSA fraud scheme:

  • An account that receives FSA refunds where the account’s history and the customer’s profile are not consistent with enrollment at an educational institution, especially if the stated recipient of the refund has no known connection to the account.
  • A customer uses funds received from a student aid refund to quickly purchase digital assets, and then rapidly transfers them to a digital asset wallet for no apparent legitimate purpose.
  • Multiple unrelated students use the same account to deposit federal student aid refunds.
  • A newly established customer account is funded solely by student aid refunds and lacks other financial activity.
  • A customer receives multiple peer-to-peer or wire transfers from accounts that recently received student aid refunds, for no business or apparent lawful purpose.
  • Multiple accounts that receive a student aid refund are accessed from the same out-of-state or international IP address or the same device.
  • Multiple accounts are created online within a short timeframe at a financial institution and receive student aid refunds.

FinCEN also explains that often the funds deposited in these accounts are rapidly transferred through peer-to-peer or wire transfers to other accounts, used to purchase digital assets, or used in transactions with online money service businesses that typically process international funds transfers.

Finally, FinCEN’s alert emphasizes the obligations banks and other financial institutions owe under the BSA to implement appropriate due diligence procedures and report suspicious activity. It urges entities that may be used in furtherance of FSA fraud schemes to take steps to detect such schemes, and to report any suspicious activity they identify.

While FinCEN’s alert does not suggest that its enforcement focus is on legitimate businesses whose products are subverted for unlawful purposes, it makes clear that this administration expects them to take affirmative steps to prevent fraud. Especially given FinCEN’s increased focus on student aid fraud, financial institutions should review their fraud detection and prevention programs to ensure they account for the patterns and red flags FinCEN has identified and that they fulfill their obligations under the BSA to detect and report suspicious activity.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

On June 30, 2026, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (“FinCEN”) issued an alert (the “Alert”), alongside a press release, outlining efforts to combat fiscal fuel theft (known in Mexico as “huachicol fiscal”) along the U.S.-Mexico border.  In simplest terms, fiscal fuel theft occurs when fuel is smuggled from the U.S. to Mexico to evade Mexico’s import tax.

FinCEN’s action is part of U.S. law enforcement’s broader effort to curtail money laundering activities by Mexico-based cartels,” including the Jalisco New Generation Cartel (CJNG), the Sinaloa Cartel, and the Gulf Cartel— a subject we have previously covered. The Alert supplements FinCEN’s May 2025 alert on the topic and it provides updates in methodologies used in the operation and on new sanctions imposed by the Treasury’s Office of Foreign Assets Control (“OFAC”).  FinCEN’s alerts describe a scheme to bypass Mexican energy regulations, evade taxes, and undercut the fuel market, while relying on U.S. financial institutions to process transactions. In response, U.S. financial institutions operating in oil and gas markets along the southern border should remain vigilant in their due diligence and their reporting obligations.

Background: How Cartels Smuggle and Commercialize U.S. Fuel in Mexico

Mexico’s regulatory and economic programs have led to an expensive and concentrated market for fuel products. Cartels are taking advantage of rising costs by smuggling fuel across the southern border to evade Mexican import taxes while using the excess profits to advance their enterprises.

While Mexico produces oil, it depends on imports of refined petroleum to support its economy. The U.S. is a major trading partner in this sector, exporting refined fuel that accounts for over 70% of Mexico’s fuel consumption. Although foreign fuel is necessary, importing energy into Mexico is a highly regulated, multipart process.

Companies must have a permit from Mexico’s Secretariat of Energy (SENER) to import fuel. A SENER permit allows a company to pay the Special Tax on Products and Services (IEPS) through a licensed customs broker. After paying import taxes, companies with SENER permits can only sell their imports to companies with permits from Mexico’s National Energy Commission (CNE). A CNE permit allows a company to commercialize fuel products in Mexico, but without a SENER permit they are prohibited from importing fuel themselves. Mexico has made a concerted effort to separate importing and commercializing, as most companies are only permitted to have one of the permits.

Cartels bypass the regulations by using companies with CNE permits as fronts to broker foreign purchases, import products, and commercialize smuggled fuel without paying the IEPS. The Alert provides a general overview of the operation: Cartel- affiliated brokers with CNE permits—but without SENER permits—illegally purchase fuel directly from well-connected U.S. traders. These traders, primarily based in Texas, use industry connections to purchase products to source products from major refineries and distributors, diverting fuel designated for legitimate export to Mexico to cartel fronts and shell companies instead. After securing the products, cartels use a variety of methods to move fuel across the southern border, including falsifying customs documents to misrepresent products as those not subject to the IEPS import tax; bribing border officials; and using shipping containers to disguise and hide the fuel. Once in Mexico, the cartels legitimatize the smuggled fuel through forged invoices claiming the fuel was purchased in compliance with applicable regulations.

By significantly reducing costs to bring fuel to the commercial market in Mexico, cartels can sell fuel below market value at affiliated gas stations and unregulated roadside stops. The scheme both undercuts legitimate operators in the supply chain and deprives the state of significant tax revenue.

The Alert also details how Cartel-affiliated Mexican brokers pay their U.S. counterparts, primarily through international wire transfers and digital asset payments, including stablecoins, processed through U.S. and Mexican financial institutions and digital asset service providers, as well as through structured cash deposits along the southern border. U.S. traders then launder these illicit proceeds through purchases of luxury goods, real estate, and investment assets.

New Sanctions

In conjunction with the Alert, OFAC imposed sanctions on two individuals and nine associated entities involved with the scheme. These sanctions highlight the variety of roles necessary in the Cartel’s operation.

First, the government sanctioned Oscar Guillermo Juraidini Silva and his businesses for operating as an accountant and key planner of financial operations in the smuggling scheme. Second, the government sanctioned J. Refugio Ruiz Villagomez for knowingly smuggling fuel into Mexico. These sanctions were pursuant to Executive Order (“E.O.”) 14059, Imposing Sanctions on Foreign Persons Involved in the Global Illicit Drug Trade and E.O. 13224, Blocking Property and Prohibiting Transactions With Persons Who Commit, Threaten To Commit, or Support Terrorism, as amended by E.O. 13886, Modernizing Sanctions To Combat Terrorism.

In a sign of deepening cross-border coordination, Mexico’s Financial Intelligence Unit announced that it had blocked the domestic bank accounts of Juraidini, Ruiz Villagomez, and nine additional individuals identified through its own parallel financial analysis—underscoring that U.S. and Mexican authorities are pursuing these fiscal fuel theft networks in tandem.

Key Takeaways for U.S. Financial Institutions

U.S. financial institutions should do their best to discern whether a customer is a reputable company operating in a way that is typical in the oil and gas industry for a company of their size. A non-exhaustive list of red flags in due diligence for industry relevant customer behavior includes:

  • A customer engages in traditional money laundering typologies with transactions having no clear connection to the industry (e.g., the sale or purchase of luxury goods, real estate, and investment assets)
  • A customer receives payments directly from Mexican companies without a SENER permit or with a CNE permit
  • A customer receives payments from a company affiliated with the Cartel
  • A customer has little to no business expenses, operations, or online presence
  • A customer is a U.S.-based company operating in Mexico without a Mexican subsidiary
  • A customer receives funds from small, recently established U.S. companies
  • A customer sends or receives a significant volume of non-descript payments
  • A customer receives significant transaction activity with insufficient infrastructure to store or transport the fuel
  • A customer receives funds from companies registered to residential addresses

Financial institutions who uncover suspicious activity in their due diligence processes must follow reporting requirements under the Bank Secrecy Act (BSA), which includes filing a Suspicious Activity Report (SAR) if a transaction is related to criminal activity. In the twelve months following FinCEN’s May 2025 alert, financial institutions filed more than 160 SARs detailing over $7 billion in suspicious activity connected to these schemes, with Texas and Florida the most commonly implicated states. Financial institutions operating along the southern border should also consider joining voluntary information sharing programs amongst financial institutions. If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. Please click here to find out about our Anti-Money Laundering Team.

This Summer, the U.S. Department of Treasury’s Financial Crimes Enforcement Network (FinCEN) issued an advisory urging financial institutions to heighten their vigilance for risks tied to the unlawful employment of non-work-authorized individuals. The advisory highlights the increasingly prevalent role of labor brokers in facilitating fraudulent conduct and identifies several “red flags” that can alert banks and other institutions to potentially illicit activity on the part of their accountholders and customers.

Financial institutions report illicit or otherwise suspicious activity pursuant to the Bank Secrecy Act (“BSA”). Analyzing these reports, FinCEN has identified typical schemes: employers engage in unlawful activity by hiring low-wage, unlawful workers through off-the-book payments, which allow the employers to evade payroll taxes, insurance requirements, and employment benefit premiums.

These unlawful employment schemes often scale through third parties, particularly labor brokers. Labor brokers, staffing intermediaries, and “labor services” entities sit between businesses (and their banks) and workers, handling recruitment, onboarding, transportation and housing arrangements, payroll, and cash distribution. Broker services can be and often are legitimate, yet they also can be utilized to:

  • Obscure the true employer—payments flow to the intermediary, not to the employer or its employees, making it harder to identify the employing company, track headcount, and ensure compliance with tax obligations. Complicit labor brokers may evade easy verification of their identity and activities by opening accounts using a foreign passport or an Individual Taxpayer Identification Number, identifying as “self-employed” or some similar status, and using a Commercial Mail Receiving Agency instead of a real address.
  • Facilitate identity and document fraud—brokers may help employers in securing stolen or fake identities for their workers, or recycle identifying information across multiple individuals. This fraud helps the employer evade detection of its unlawful employment practices.
  • Enable cash-based or hard-to-detect payment practices—intermediaries can convert funds they receive into cash to pay workers off-the-books, or structure transactions to reduce detectability. For instance, brokers may send payments to employees through cash couriers, checks, or peer-to-peer platforms, using repetitive and small transactions that are designed to circumvent reporting thresholds under the BSA.
  • Create layering through multiple entities—brokers often form networks of shell companies (with overlapping owners, addresses, signers, or phone numbers) that can be used to move funds and frustrate due diligence. Brokers may also use these shell companies to obtain a minimal workers’ compensation policy for small numbers of employees and then “rent” access to complicit employers employing hundreds.

Identifying individuals or entities involved in these fraudulent schemes is not always easy, but FinCEN’s advisory lists “red flags” for financial institutions that could signal potential illicit activity. While legitimate account holders may lawfully engage in the conduct FinCEN identifies as a risk indicator, FinCEN’s “red flags” provide clues of possible unlawful employment, identity fraud, or related criminal conduct that should trigger heightened diligence and oversight on the part of financial institutions.

According to FinCEN, banks should be especially diligent when working with individuals who claim to be self-employed or operating a small business in high-risk industries like agriculture, construction, domestic service, hospitality, or staffing, or when working with companies in those industries that, for example:

  • Have high transactional activity but disproportionately insignificant payroll activity;
  • Issue recurring and large volumes of check for under $1,000 to many separate individuals; or
  • Are making payroll tax deposits that are significantly less than expected based on their reported business operations and workforce size.

Interested persons and organizations should review the advisory for a full list of potential red flags. Financial institutions should review their monitoring practices to ensure they can appropriately detect FinCEN’s red flags and have the processes in place to investigate suspected fraud.

With these risk indicators in hand, FinCEN is calling on financial institutions to monitor for, prevent, and report suspicious activity. Institutions submitting a Suspicious Activity Report (“SAR”) should use the term “FINANCIALINTEGRITY-2026-A002” in field 2 of the SAR and highlight the advisory when providing the narrative of the reason for the report.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

In May, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) issued Alert FIN-2026-Alert002, warning financial institutions about the use of front companies, financial facilitators, and digital asset infrastructure by Iran’s Islamic Revolutionary Guard Corps (IRGC) to evade sanctions and launder proceeds. The Alert represents an escalation in U.S. government guidance concerning Iranian illicit finance and underscores the expectation that covered institutions maintain robust controls capable of detecting increasingly sophisticated sanctions evasion typologies.

Background: The IRGC and the Policy of “Maximum Pressure”

The IRGC was created after the Iranian Revolution as a parallel military organization reporting directly to Iran’s Supreme Leader, and includes ground, naval, and air forces, the Basij internal security militia, and the IRGC-Qods Force (IRGC-QF), which conducts covert operations abroad and supports terrorism by supplying funding, training, and weapons to aligned groups. The IRGC is a designated Foreign Terrorist Organization (FTO) and is subject to comprehensive U.S. sanctions, including a prohibition on opening or maintaining correspondent accounts in the United States for Iranian financial institutions pursuant to Section 311 of the USA PATRIOT Act.

The Alert arrives in the context of renewed maximum pressure on Iran. On February 4, 2025, President Trump signed National Security Presidential Memorandum-2 (NSPM-2), imposing a whole-of-government approach to deny Iran all paths to a nuclear weapon and counter its influence. The Financial Action Task Force (FATF) has also reiterated that Iran remains a high-risk jurisdiction, calling on all jurisdictions to apply effective countermeasures—including prohibiting Iranian digital asset service providers from establishing a presence in their countries.

Key Typologies and Financial Activity Flagged by FinCEN

The Alert identifies several categories of illicit financial activity through which the IRGC generates and moves funds, along with corresponding red flag indicators designed to help financial institutions detect, prevent, and report potential suspicious activity connected to Iranian sanctions evasion. No single red flag is determinative; institutions should consider the totality of the circumstances.

  • Commodity Sales and Oil Smuggling

The IRGC supplements its budgets by smuggling oil to international buyers, with proceeds funding procurement, weapons development, and terrorist activity abroad. FinCEN’s 2025 Financial Trend Analysis found that oil companies potentially linked to Iran transacted approximately $4 billion in 2024, while shipping companies potentially related to the transport of sanctioned Iranian oil conducted transactions through U.S. correspondent accounts totaling approximately $707 million over the same period. The IRGC uses a “shadow fleet” of aging vessels operating outside standard maritime regulations, often owned or managed by front companies outside Iran, and engages in deceptive shipping practices including blending Iranian oil with oil from third countries or relabeling it with forged documents as “Malaysian blend.”

Red flags in this area include transactions involving petroleum or shipping companies with ties to Iran or “shadow fleet” vessels; irregularities in shipping documentation intended to obscure an Iranian nexus; documentation referencing vessels with recent or multiple name, flag, or ownership changes following OFAC designations; and transactions referencing “Malaysian blend” oil, particularly if the vessel is bound for China via Southeast Asia with automatic Information System (AIS) irregularities.

  • Front Companies and Shadow Banking Networks

The IRGC relies on multi-jurisdictional shadow banking networks comprised of exchange houses, trading companies, and front companies to sell oil and other commodities abroad, launder the proceeds, and procure weapons and materiel on the international market. Iranian banks have established “rahbar” companies to manage international transactions, using exchange houses to form front companies in third-country jurisdictions, often in permissive free trade zones, to obscure Iranian involvement. FinCEN found that likely shell companies matching indicators for shell and Iranian activity moved $5 billion in 2024, primarily from non-resident accounts at banks in China operated by Hong Kong-based companies to the UAE.

Red flags in this area include wire transfers with unclear sources of funds involving entities in high-risk jurisdictions; general trading companies with opaque ownership registered in commercial free trade zones in the UAE with counterparties in Singapore, Hong Kong, China, or Oman; likely front companies with little to no web presence transacting in unusually high amounts from non-resident accounts; and unusual use of multiple exchange houses with fees or transaction patterns that do not reflect standard commercial practices.

  • Facilitators and Service Providers

IRGC networks are bolstered by facilitators including money services businesses (MSBs), investment companies, and trust and company service providers that assist—wittingly or unwittingly—in orchestrating complex money laundering and sanctions evasion schemes. Purported trust companies based in Hong Kong and Eastern Europe have been identified as facilitating the transmission of value to the IRGC, including through the conversion of fiat currency to digital assets.

  • Digital Assets

Iranian digital asset activity has reached billions of dollars per year, with the IRGC conducting sanctions evasion as part of this activity. Digital assets enable Iranian facilitators to circumvent the traditional financial system by transferring value internationally without intermediary financial institutions. Iranian facilitators are likely to use stablecoins due to their relative liquidity, ease of settlement, and exchange rate stability, and Iran’s use of stablecoins includes minting, moving between large-volume stablecoin issuers, and creating proprietary stablecoins. FinCEN also notes that unregistered peer-to-peer exchangers, unregistered foreign-located MSBs, and nested digital asset service providers (DASPs) may offer digital asset-related services in Iran.

Red flags in this area include companies with exposure to Iranian oil smuggling deviating from normal business practices to send or receive payments using digital assets; stablecoin payments with unclear sources of funds in high-risk jurisdictions; unusual stablecoin mint activity requiring multiple rate or limit increases; transactions directly or indirectly with digital asset addresses attributed to Iranian entities; authentication activity from Iranian IP addresses, email services, or phone numbers; and customer accounts that may be operating as unregistered P2P exchangers or nested DASPs providing services in Iran.

Conclusion

The FinCEN IRGC Alert reflects the U.S. government’s intensified focus on disrupting Iranian sanctions evasion networks and its expectation that the private sector serve as a critical partner in this effort. Regulatory compliance teams should evaluate existing frameworks governing exposure to Iranian illicit finance and ensure that processes align with current reporting and blocking obligations under U.S. law.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. Please click here to find out about our Anti-Money Laundering Team.

President Trump’s May 19, 2026 executive order, Restoring Integrity to America’s Financial System, directs Treasury, FinCEN, the CFPB, and the federal banking agencies to reassess how financial institutions identify and manage risks associated with non-work authorized populations and related cross border financial activity. The order reflects a significant shift in federal expectations across BSA/AML compliance, customer identification, and consumer credit underwriting. It also establishes short deadlines that will drive rapid regulatory and supervisory developments through the remainder of 2026.

The order frames these issues as national security and public safety concerns. It cites analyses linking low dollar cross border transfers to terrorist financing, narcotics trafficking, and human trafficking. It highlights Chinese money laundering networks that allegedly used U.S. accounts held by foreign passport holders to launder more than $312 billion for criminal organizations. It also identifies fentanyl related financial activity tied to Mexico based cartels as a priority area for regulatory attention.

At the same time, the order directs regulators to treat lending to non-work authorized individuals as a structural safety and soundness concern. It characterizes potential deportation and loss of wages as creating a fundamental ability to repay deficiency. This framing signals a broader policy shift that will affect both consumer credit markets and fair lending supervision.

Key Directives and Deadlines

The order requires several regulatory actions on compressed timelines.

Treasury Advisory (60 Days)

Within 60 days, Treasury must issue an Advisory describing red flags and typologies associated with six categories of suspicious activity:

  • Payroll tax evasion by employers or labor brokers
  • Use of foreign identity documents or nominee structures to conceal beneficial ownership or payroll disbursements
  • Unregistered MSBs and third party processors used for off the books wage payments intended to bypass BSA reporting thresholds
  • Structuring and micro structuring correlated with payroll cycles
  • Labor trafficking indicators where illicit proceeds are commingled with legitimate revenue
  • Use of ITINs to obtain credit or open accounts without verified lawful immigration status

Although the Advisory will not be binding, examiners routinely treat Treasury Advisories as articulations of expected practice. Institutions should anticipate that the Advisory will influence SAR filing expectations and monitoring scenarios well before any rulemaking is complete.

BSA Due Diligence Regulations (90 Days)

Within 90 days, Treasury must propose amendments to strengthen risk-based customer due diligence. The proposal must ensure institutions collect and verify sufficient identity information to assess illicit finance, sanctions evasion, and fraud risks. It must also preserve institutional authority to obtain additional information, including information relevant to immigration status and employment authorization, when other risk indicators warrant it.

Customer Identification Program Requirements (180 Days)

Within 180 days, Treasury and the federal functional financial regulators must consider changes to CIP regulations, with specific attention to risks associated with foreign consular identification cards. Institutions that rely on these documents for account opening should prepare for potential verification or documentation changes.

Credit Risk Guidance (60 Days)

Within 60 days, the CFPB must consider clarifying that potential deportation and loss of wages may adversely affect a non-work authorized borrower’s ability to repay under Regulation Z. Each federal functional financial regulator must also issue guidance on managing credit risks associated with non-work authorized populations. This directive raises complex questions about how lenders may incorporate immigration related risk factors while managing fair lending obligations.

Practical Implications for Financial Institutions

BSA/AML Programs

Institutions should begin reviewing transaction monitoring scenarios and SAR filing practices against the six categories of suspicious activity identified in the order. The forthcoming Treasury Advisory will likely establish new expectations for how institutions identify and report activity involving non-work authorized populations and their employers. Institutions should evaluate whether existing monitoring rules capture payroll related structuring, funnel account activity, and patterns associated with unregistered MSBs or third-party processors.

Customer Identification and Due Diligence

The order’s focus on consular identification cards and ITINs signals heightened scrutiny of identification documents commonly used by noncitizens. Institutions that accept these documents should assess whether existing CIP and CDD procedures address the risk indicators identified and whether additional verification steps may become necessary. Potential enhancements include supplemental non documentary verification, additional beneficial ownership inquiries, and review of employment authorization where risk indicators are present.

Credit Underwriting

Lenders offering consumer credit, particularly mortgage, auto, and credit card products, should evaluate whether underwriting models and ability to repay analyses account for the immigration related risk factors highlighted in the order. The CFPB’s forthcoming guidance will determine how lenders may incorporate these factors while managing fair lending obligations. Institutions should prepare for potential adjustments to income stability assessments, treatment of ITIN based applications, and portfolio level risk reviews.

Employer Related Risks

The order’s treatment of employer immigration law violations as a financial system vulnerability is notable. Institutions that bank employers in industries with high concentrations of non work authorized labor should anticipate increased scrutiny of payroll irregularities, mismatched tax identification numbers, and unusual payment patterns. These considerations may affect risk rating methodologies and periodic reviews for certain commercial customers.

Fair Lending Considerations

Institutions should monitor how the CFPB and prudential regulators reconcile the order’s directives with existing fair lending requirements under the Equal Credit Opportunity Act and the Fair Housing Act. The intersection of immigration status considerations and prohibited basis discrimination will require careful navigation, particularly if regulators expect lenders to incorporate deportation risk into underwriting.

Looking Ahead

The compressed timelines in the executive order mean that financial institutions will face a rapidly evolving regulatory environment over the next two to six months. Institutions should begin assessing how their existing BSA/AML, CIP, CDD, and credit underwriting programs align with the issues highlighted in the order and prepare for increased supervisory attention as agencies issue Advisories, proposed rules, and credit risk guidance.

We will continue to monitor developments as agencies complete their reviews and begin implementing the Order. If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.