On August 11, 2026, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (“FinCEN”) renewed its Geographic Targeting Order (“GTO”) Imposing Recordkeeping and Reporting Requirements on Certain Financial Institutions in Minnesota. The GTO requires financial institutions located in Hennepin and Ramsey Counties, Minnesota, to “retain and report records of certain payments of $3,000 or more.”

The initial GTO was announced on January 9, 2026, as part of the Trump Administration’s efforts to combat alleged “rampant government benefits fraud in Minnesota.” The first GTO went into effect on February 12, 2026, and was set to expire on August 10, 2026. The renewed GTO has extended this deadline and will remain in effect until February 6, 2027. FinCEN has released frequently asked questions in connection with the renewal that explain the requirements of the renewed GTO.

The renewed GTO is nearly identical to the initial order but, as explained in the Frequently Asked Questions, exempts certain Covered Businesses “that are banks from [the] GTO’s requirement to record or report fund transfers where the originator falls into certain categories[.]” The exemptions are consistent with the Exemptive Relief Order for the Geographic Targeting Order Imposing Recordkeeping and Reporting Requirements on Certain Financial Institutions in Minnesota, which granted “tailored exemptive relief” to “exempt certain categories [of] fund transfers that are lower risk for government benefits fraud, and to allow banks sufficient time to report certain information required by the GTO.”

The renewed GTO continues to exempt banks from funds transfers where the originator falls into one of the sixteen categories excluded under the Customer Due Diligence Rule, but, importantly, it does not extend the temporary relief that had limited banks’ obligations to information already covered by the Recordkeeping Rule.

The renewed GTO, as explained, is otherwise identical to the first GTO. It requires banks and money services businesses (MSBs) located in Hennepin and Ramsey Counties to report international fund transfers of $3,000 or more when the beneficiary or recipient is located outside of the United States. Banks and MSBs located in these counties are “covered businesses,” which is defined as any bank as defined in 31 CFR 1010.100(d), or any money transmitter, as defined in 31 CFR 1010.100(ff)(5), with a branch, subsidiary, or office located in the covered geographic area. The GTO requires covered businesses to report to FinCEN certain information required to be retained under “31 CFR 1020.410(a)(1) and (2), along with certain other additional information, regardless of whether the information is provided with the payment order[.]” This information, which is set forth in the Frequently Asked Questions, includes:

1. The name and employer identification number of the Covered Business;

2. The account number of the originator;

3. The name of the beneficiary; 

4. The address of the beneficiary;

5. The date of birth of the beneficiary;

6. A phone number of the beneficiary;

7. An email address of the beneficiary; 

8. The account number of the beneficiary; 

9. Whether the source of funds for the transfer includes payments that are from any federal,

state, or local government contract or benefit program; and,

10. If the answer to question (9) is yes, whether those payments are from government

agencies to entities in which the originator has any ownership interest.

If the Covered Business is a money transmitter, additional information concerning the form of the transmittal is required. If the renewed GTO is “willfully” violated, a business could be subject to civil penalties, with a separate penalty applied for each individual violation. Criminal fines are also available, as well as imprisonment for no more than five years.

This renewed GTO is part of Secretary of the Treasury Scott Bessent’s plan “to follow the money” and should serve as a reminder that the Trump Administration appears willing to impose strict reporting requirements and enforcement tools to further its goals.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

On July 13, a divided Ninth Circuit panel upheld a lower court order that barred enforcement of FinCEN’s border Geographic Targeting Order (“GTO”). The GTO would have forced money services businesses (“MSBs”) in 30 ZIP codes along the U.S.-Mexico border to report cash transactions of just over $200, a dramatic reduction from the longstanding $10,000 reporting threshold. The decision in Novedades Y Servicios, Inc. v. FinCEN, 181 F.4th 961, 967 (9th Cir. 2026)  is a significant procedural check on the administration’s anti-cartel enforcement agenda.

Cartels as a National Security Priority

The Trump administration has repeatedly framed cartel-linked money laundering as a national security threat. On January 20, 2025 – the first day of his second term – President Trump issued an executive order designating certain international cartels as Foreign Terrorist Organizations and Specially Designated Global Terrorists. The order declared that cartels “present an unusual and extraordinary threat to the national security, foreign policy, and economy of the United States,” and set its goal as “the total elimination of these organizations’ presence in the United States.”

The border GTO flowed directly from that priority. Issued by FinCEN in March 2025, the GTO targeted MSBs in 30 ZIP codes along the U.S.-Mexico border, requiring a Currency Transaction Report (“CTR”) filing for any cash transaction between $200 and $10,000. Treasury Secretary Scott Bessent made the administration’s priorities clear: “[f]or too long, cartels have abused the U.S. financial system to profit from poisoning Americans with deadly fentanyl. At Treasury, we are expanding our efforts to keep drug money out of the United States and to provide law enforcement with additional information to put these traffickers behind bars.”

The Ninth Circuit Holding

The panel’s decision turned on administrative procedure rather than the merits of AML enforcement.  

The majority concluded that the border GTO was likely a rule – rather than an order – under the Administrative Procedure Act (APA), because it applied to all unnamed and unspecified MSBs across a geographic area home to over one million people, rather than targeting specific identified businesses based on particularized findings. Because 31 U.S.C. § 5326 authorizes FinCEN to act only by “order,” the GTO likely exceeded the agency’s statutory authority.

The panel also found that FinCEN was required to conduct notice-and-comment rulemaking which it skipped entirely, and that the GTO was likely arbitrary and capricious because FinCEN “entirely failed to consider the cost of compliance to regulated parties.” On that point, the court noted that the only evidence the government offered on cost consideration was an internal FinCEN memorandum dated “March XX” that was undated, in draft form, and heavily redacted.

Who Challenged It

The case was brought by the Institute for Justice on behalf of Esperanza Gomez Escobar, who owns and runs Novedades y Servicios, a family-run MSB in San Diego. Escobar’s customers are largely people without bank accounts who come in to cash paychecks and wire money to family.

The compliance burden was, by Escobar’s account, impossible for her MSB to absorb. The $200 threshold swept in roughly 99% of Novedades’s monthly transactions, and the complaint alleged that filing the resulting CTRs would require an additional 14 to 17 hours per day. During the single week the order was in effect, Escobar alleges she lost between 50 and 60 percent of her customers after explaining the new reporting requirements. The Institute for Justice argued the lowered threshold amounted to “enlisting [small business owners] as surveillance agents of the government.”

The dynamic is not new. As the President of the National Small Business Association told the Wall Street Journal in 2024 when discussing a separate FinCEN rule, “FinCEN has never dealt with small businesses, and small businesses don’t know who FinCEN is and FinCEN doesn’t know how to regulate small businesses.”

Implications

The Ninth Circuit’s decision is a procedural check rather than a policy reversal. Nothing in the Ninth Circuit’s ruling calls into question the policy objective of targeting cartel finances. The panel’s concerns were exclusively procedural: FinCEN bypassed formal notice-and-comment rulemaking, and the record before the Circuit suggested the agency never accounted for the costs it was imposing on border MSBs.

Financial institutions and their compliance teams should consider the following:

  • The injunction does not reduce the underlying compliance imperative. The administration’s commitment to disrupting cartel cash flows has not wavered, and a formally noticed rule is the likely next step.
  • For institutions with border exposure, the question is not whether new requirements will come, but when and in what form. FinCEN has every incentive – both political and practical – to return with a formally noticed rule.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

In an alert issued this July, FinCEN urged banks and other financial institutions to increase their focus on detecting, preventing, and reporting fraud schemes targeting federal student aid (“FSA”) programs. The alert provides specific red flags for identifying suspicious activity—and signals that regulators expect proactive compliance efforts.

The United States Department of Education (“ED”) has launched a national effort to prevent student aid fraud, and estimates that it prevented about $1 billion in FSA-related fraud in 2025 alone. The scale of FSA funding—and the associated fraud risks—is enormous. Every year approximately $120 billion go out to around 13 million students for grants, work-study funds, and low-interest loans. The FSA office also oversees the Free Application for Federal Student Aid (FAFSA), through which students apply for financial aid for post-secondary education.

FinCEN’s alert identifies the three most common types of schemes to defraud the FSA program, explaining how in each case, fraudsters seek to divert funds intended for bona fide student-recipients of federal aid. FSA funds are paid directly to educational institutions, and once those institutions apply the funds to any tuition and fees the student-recipients owe, the institutions then issue a “refund” of the difference to the students for use toward living expenses. Students must be enrolled in the institutions for 60% of the enrollment period to receive these refunds, and it is these refunds that most FSA schemes target.

The three types of schemes FinCEN identifies are those using “ghost students,” “straw students,” and insider assistance.

  • Ghost Students: In ghost-student schemes, fraudulent actors either use personally identifying information (“PII”) of identity theft victims, or wholly fabricated information to create synthetic identities, in order to pose as legitimate students. They then enroll these “ghost students” in educational institutions and apply for federal student aid and collect the FSA refunds. To satisfy the requirement that students maintain enrollment for 60% of the enrollment period, the fraudulent actors often use AI chatbots to complete the coursework.
  • Straw Students: Straw-student schemes are similar to ghost-student schemes, except that the enrolled student is a willing participant. In these cases, individuals provide their PII to be used in the fraudulent scheme, and they are willingly enrolled in educational institutions. The straw students typically do not attend classes, with the fraudsters ensuring the completion of any coursework required to satisfy the 60% requirement.
  • Insider-Assisted Schemes: Lastly, FinCEN explained that in some cases, a staff member with insider access will facilitate the scheme, including by recruiting straw students and helping ensure they get approved for FSA funds. The insider staff member will then either steal the aid refund entirely or require the students to pay a portion of the funds as a kickback in exchange for facilitating the scheme.

Banks can spot these schemes by watching for red flags when stolen refunds are laundered. Entities can usually identify deposits as FSA refunds by the transaction references in ACH deposits—typically identifying an educational institution (either by name or a common abbreviation) and “refund.” Once entities identify incoming FSA refunds, they may be able to flag the common tools used to launder the fraudulently obtained proceeds, including the use of “money mules” to transfer the funds, shell companies, fraudulent accounts opened with fake customer identification materials, and abuse of digital assets.

As guidance to banks and financial institutions seeking to improve detection of FSA schemes, FinCEN identifies the following “red flags,” which either independently or in conjunction with other indicators—such as a customer’s historical financial activity, whether transactions are in line with prevailing business practices, and whether multiple red flags coexist—can indicate that an account or customer is involved in an FSA fraud scheme:

  • An account that receives FSA refunds where the account’s history and the customer’s profile are not consistent with enrollment at an educational institution, especially if the stated recipient of the refund has no known connection to the account.
  • A customer uses funds received from a student aid refund to quickly purchase digital assets, and then rapidly transfers them to a digital asset wallet for no apparent legitimate purpose.
  • Multiple unrelated students use the same account to deposit federal student aid refunds.
  • A newly established customer account is funded solely by student aid refunds and lacks other financial activity.
  • A customer receives multiple peer-to-peer or wire transfers from accounts that recently received student aid refunds, for no business or apparent lawful purpose.
  • Multiple accounts that receive a student aid refund are accessed from the same out-of-state or international IP address or the same device.
  • Multiple accounts are created online within a short timeframe at a financial institution and receive student aid refunds.

FinCEN also explains that often the funds deposited in these accounts are rapidly transferred through peer-to-peer or wire transfers to other accounts, used to purchase digital assets, or used in transactions with online money service businesses that typically process international funds transfers.

Finally, FinCEN’s alert emphasizes the obligations banks and other financial institutions owe under the BSA to implement appropriate due diligence procedures and report suspicious activity. It urges entities that may be used in furtherance of FSA fraud schemes to take steps to detect such schemes, and to report any suspicious activity they identify.

While FinCEN’s alert does not suggest that its enforcement focus is on legitimate businesses whose products are subverted for unlawful purposes, it makes clear that this administration expects them to take affirmative steps to prevent fraud. Especially given FinCEN’s increased focus on student aid fraud, financial institutions should review their fraud detection and prevention programs to ensure they account for the patterns and red flags FinCEN has identified and that they fulfill their obligations under the BSA to detect and report suspicious activity.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

On June 30, 2026, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (“FinCEN”) issued an alert (the “Alert”), alongside a press release, outlining efforts to combat fiscal fuel theft (known in Mexico as “huachicol fiscal”) along the U.S.-Mexico border.  In simplest terms, fiscal fuel theft occurs when fuel is smuggled from the U.S. to Mexico to evade Mexico’s import tax.

FinCEN’s action is part of U.S. law enforcement’s broader effort to curtail money laundering activities by Mexico-based cartels,” including the Jalisco New Generation Cartel (CJNG), the Sinaloa Cartel, and the Gulf Cartel— a subject we have previously covered. The Alert supplements FinCEN’s May 2025 alert on the topic and it provides updates in methodologies used in the operation and on new sanctions imposed by the Treasury’s Office of Foreign Assets Control (“OFAC”).  FinCEN’s alerts describe a scheme to bypass Mexican energy regulations, evade taxes, and undercut the fuel market, while relying on U.S. financial institutions to process transactions. In response, U.S. financial institutions operating in oil and gas markets along the southern border should remain vigilant in their due diligence and their reporting obligations.

Background: How Cartels Smuggle and Commercialize U.S. Fuel in Mexico

Mexico’s regulatory and economic programs have led to an expensive and concentrated market for fuel products. Cartels are taking advantage of rising costs by smuggling fuel across the southern border to evade Mexican import taxes while using the excess profits to advance their enterprises.

While Mexico produces oil, it depends on imports of refined petroleum to support its economy. The U.S. is a major trading partner in this sector, exporting refined fuel that accounts for over 70% of Mexico’s fuel consumption. Although foreign fuel is necessary, importing energy into Mexico is a highly regulated, multipart process.

Companies must have a permit from Mexico’s Secretariat of Energy (SENER) to import fuel. A SENER permit allows a company to pay the Special Tax on Products and Services (IEPS) through a licensed customs broker. After paying import taxes, companies with SENER permits can only sell their imports to companies with permits from Mexico’s National Energy Commission (CNE). A CNE permit allows a company to commercialize fuel products in Mexico, but without a SENER permit they are prohibited from importing fuel themselves. Mexico has made a concerted effort to separate importing and commercializing, as most companies are only permitted to have one of the permits.

Cartels bypass the regulations by using companies with CNE permits as fronts to broker foreign purchases, import products, and commercialize smuggled fuel without paying the IEPS. The Alert provides a general overview of the operation: Cartel- affiliated brokers with CNE permits—but without SENER permits—illegally purchase fuel directly from well-connected U.S. traders. These traders, primarily based in Texas, use industry connections to purchase products to source products from major refineries and distributors, diverting fuel designated for legitimate export to Mexico to cartel fronts and shell companies instead. After securing the products, cartels use a variety of methods to move fuel across the southern border, including falsifying customs documents to misrepresent products as those not subject to the IEPS import tax; bribing border officials; and using shipping containers to disguise and hide the fuel. Once in Mexico, the cartels legitimatize the smuggled fuel through forged invoices claiming the fuel was purchased in compliance with applicable regulations.

By significantly reducing costs to bring fuel to the commercial market in Mexico, cartels can sell fuel below market value at affiliated gas stations and unregulated roadside stops. The scheme both undercuts legitimate operators in the supply chain and deprives the state of significant tax revenue.

The Alert also details how Cartel-affiliated Mexican brokers pay their U.S. counterparts, primarily through international wire transfers and digital asset payments, including stablecoins, processed through U.S. and Mexican financial institutions and digital asset service providers, as well as through structured cash deposits along the southern border. U.S. traders then launder these illicit proceeds through purchases of luxury goods, real estate, and investment assets.

New Sanctions

In conjunction with the Alert, OFAC imposed sanctions on two individuals and nine associated entities involved with the scheme. These sanctions highlight the variety of roles necessary in the Cartel’s operation.

First, the government sanctioned Oscar Guillermo Juraidini Silva and his businesses for operating as an accountant and key planner of financial operations in the smuggling scheme. Second, the government sanctioned J. Refugio Ruiz Villagomez for knowingly smuggling fuel into Mexico. These sanctions were pursuant to Executive Order (“E.O.”) 14059, Imposing Sanctions on Foreign Persons Involved in the Global Illicit Drug Trade and E.O. 13224, Blocking Property and Prohibiting Transactions With Persons Who Commit, Threaten To Commit, or Support Terrorism, as amended by E.O. 13886, Modernizing Sanctions To Combat Terrorism.

In a sign of deepening cross-border coordination, Mexico’s Financial Intelligence Unit announced that it had blocked the domestic bank accounts of Juraidini, Ruiz Villagomez, and nine additional individuals identified through its own parallel financial analysis—underscoring that U.S. and Mexican authorities are pursuing these fiscal fuel theft networks in tandem.

Key Takeaways for U.S. Financial Institutions

U.S. financial institutions should do their best to discern whether a customer is a reputable company operating in a way that is typical in the oil and gas industry for a company of their size. A non-exhaustive list of red flags in due diligence for industry relevant customer behavior includes:

  • A customer engages in traditional money laundering typologies with transactions having no clear connection to the industry (e.g., the sale or purchase of luxury goods, real estate, and investment assets)
  • A customer receives payments directly from Mexican companies without a SENER permit or with a CNE permit
  • A customer receives payments from a company affiliated with the Cartel
  • A customer has little to no business expenses, operations, or online presence
  • A customer is a U.S.-based company operating in Mexico without a Mexican subsidiary
  • A customer receives funds from small, recently established U.S. companies
  • A customer sends or receives a significant volume of non-descript payments
  • A customer receives significant transaction activity with insufficient infrastructure to store or transport the fuel
  • A customer receives funds from companies registered to residential addresses

Financial institutions who uncover suspicious activity in their due diligence processes must follow reporting requirements under the Bank Secrecy Act (BSA), which includes filing a Suspicious Activity Report (SAR) if a transaction is related to criminal activity. In the twelve months following FinCEN’s May 2025 alert, financial institutions filed more than 160 SARs detailing over $7 billion in suspicious activity connected to these schemes, with Texas and Florida the most commonly implicated states. Financial institutions operating along the southern border should also consider joining voluntary information sharing programs amongst financial institutions. If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. Please click here to find out about our Anti-Money Laundering Team.

This Summer, the U.S. Department of Treasury’s Financial Crimes Enforcement Network (FinCEN) issued an advisory urging financial institutions to heighten their vigilance for risks tied to the unlawful employment of non-work-authorized individuals. The advisory highlights the increasingly prevalent role of labor brokers in facilitating fraudulent conduct and identifies several “red flags” that can alert banks and other institutions to potentially illicit activity on the part of their accountholders and customers.

Financial institutions report illicit or otherwise suspicious activity pursuant to the Bank Secrecy Act (“BSA”). Analyzing these reports, FinCEN has identified typical schemes: employers engage in unlawful activity by hiring low-wage, unlawful workers through off-the-book payments, which allow the employers to evade payroll taxes, insurance requirements, and employment benefit premiums.

These unlawful employment schemes often scale through third parties, particularly labor brokers. Labor brokers, staffing intermediaries, and “labor services” entities sit between businesses (and their banks) and workers, handling recruitment, onboarding, transportation and housing arrangements, payroll, and cash distribution. Broker services can be and often are legitimate, yet they also can be utilized to:

  • Obscure the true employer—payments flow to the intermediary, not to the employer or its employees, making it harder to identify the employing company, track headcount, and ensure compliance with tax obligations. Complicit labor brokers may evade easy verification of their identity and activities by opening accounts using a foreign passport or an Individual Taxpayer Identification Number, identifying as “self-employed” or some similar status, and using a Commercial Mail Receiving Agency instead of a real address.
  • Facilitate identity and document fraud—brokers may help employers in securing stolen or fake identities for their workers, or recycle identifying information across multiple individuals. This fraud helps the employer evade detection of its unlawful employment practices.
  • Enable cash-based or hard-to-detect payment practices—intermediaries can convert funds they receive into cash to pay workers off-the-books, or structure transactions to reduce detectability. For instance, brokers may send payments to employees through cash couriers, checks, or peer-to-peer platforms, using repetitive and small transactions that are designed to circumvent reporting thresholds under the BSA.
  • Create layering through multiple entities—brokers often form networks of shell companies (with overlapping owners, addresses, signers, or phone numbers) that can be used to move funds and frustrate due diligence. Brokers may also use these shell companies to obtain a minimal workers’ compensation policy for small numbers of employees and then “rent” access to complicit employers employing hundreds.

Identifying individuals or entities involved in these fraudulent schemes is not always easy, but FinCEN’s advisory lists “red flags” for financial institutions that could signal potential illicit activity. While legitimate account holders may lawfully engage in the conduct FinCEN identifies as a risk indicator, FinCEN’s “red flags” provide clues of possible unlawful employment, identity fraud, or related criminal conduct that should trigger heightened diligence and oversight on the part of financial institutions.

According to FinCEN, banks should be especially diligent when working with individuals who claim to be self-employed or operating a small business in high-risk industries like agriculture, construction, domestic service, hospitality, or staffing, or when working with companies in those industries that, for example:

  • Have high transactional activity but disproportionately insignificant payroll activity;
  • Issue recurring and large volumes of check for under $1,000 to many separate individuals; or
  • Are making payroll tax deposits that are significantly less than expected based on their reported business operations and workforce size.

Interested persons and organizations should review the advisory for a full list of potential red flags. Financial institutions should review their monitoring practices to ensure they can appropriately detect FinCEN’s red flags and have the processes in place to investigate suspected fraud.

With these risk indicators in hand, FinCEN is calling on financial institutions to monitor for, prevent, and report suspicious activity. Institutions submitting a Suspicious Activity Report (“SAR”) should use the term “FINANCIALINTEGRITY-2026-A002” in field 2 of the SAR and highlight the advisory when providing the narrative of the reason for the report.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

In May, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) issued Alert FIN-2026-Alert002, warning financial institutions about the use of front companies, financial facilitators, and digital asset infrastructure by Iran’s Islamic Revolutionary Guard Corps (IRGC) to evade sanctions and launder proceeds. The Alert represents an escalation in U.S. government guidance concerning Iranian illicit finance and underscores the expectation that covered institutions maintain robust controls capable of detecting increasingly sophisticated sanctions evasion typologies.

Background: The IRGC and the Policy of “Maximum Pressure”

The IRGC was created after the Iranian Revolution as a parallel military organization reporting directly to Iran’s Supreme Leader, and includes ground, naval, and air forces, the Basij internal security militia, and the IRGC-Qods Force (IRGC-QF), which conducts covert operations abroad and supports terrorism by supplying funding, training, and weapons to aligned groups. The IRGC is a designated Foreign Terrorist Organization (FTO) and is subject to comprehensive U.S. sanctions, including a prohibition on opening or maintaining correspondent accounts in the United States for Iranian financial institutions pursuant to Section 311 of the USA PATRIOT Act.

The Alert arrives in the context of renewed maximum pressure on Iran. On February 4, 2025, President Trump signed National Security Presidential Memorandum-2 (NSPM-2), imposing a whole-of-government approach to deny Iran all paths to a nuclear weapon and counter its influence. The Financial Action Task Force (FATF) has also reiterated that Iran remains a high-risk jurisdiction, calling on all jurisdictions to apply effective countermeasures—including prohibiting Iranian digital asset service providers from establishing a presence in their countries.

Key Typologies and Financial Activity Flagged by FinCEN

The Alert identifies several categories of illicit financial activity through which the IRGC generates and moves funds, along with corresponding red flag indicators designed to help financial institutions detect, prevent, and report potential suspicious activity connected to Iranian sanctions evasion. No single red flag is determinative; institutions should consider the totality of the circumstances.

  • Commodity Sales and Oil Smuggling

The IRGC supplements its budgets by smuggling oil to international buyers, with proceeds funding procurement, weapons development, and terrorist activity abroad. FinCEN’s 2025 Financial Trend Analysis found that oil companies potentially linked to Iran transacted approximately $4 billion in 2024, while shipping companies potentially related to the transport of sanctioned Iranian oil conducted transactions through U.S. correspondent accounts totaling approximately $707 million over the same period. The IRGC uses a “shadow fleet” of aging vessels operating outside standard maritime regulations, often owned or managed by front companies outside Iran, and engages in deceptive shipping practices including blending Iranian oil with oil from third countries or relabeling it with forged documents as “Malaysian blend.”

Red flags in this area include transactions involving petroleum or shipping companies with ties to Iran or “shadow fleet” vessels; irregularities in shipping documentation intended to obscure an Iranian nexus; documentation referencing vessels with recent or multiple name, flag, or ownership changes following OFAC designations; and transactions referencing “Malaysian blend” oil, particularly if the vessel is bound for China via Southeast Asia with automatic Information System (AIS) irregularities.

  • Front Companies and Shadow Banking Networks

The IRGC relies on multi-jurisdictional shadow banking networks comprised of exchange houses, trading companies, and front companies to sell oil and other commodities abroad, launder the proceeds, and procure weapons and materiel on the international market. Iranian banks have established “rahbar” companies to manage international transactions, using exchange houses to form front companies in third-country jurisdictions, often in permissive free trade zones, to obscure Iranian involvement. FinCEN found that likely shell companies matching indicators for shell and Iranian activity moved $5 billion in 2024, primarily from non-resident accounts at banks in China operated by Hong Kong-based companies to the UAE.

Red flags in this area include wire transfers with unclear sources of funds involving entities in high-risk jurisdictions; general trading companies with opaque ownership registered in commercial free trade zones in the UAE with counterparties in Singapore, Hong Kong, China, or Oman; likely front companies with little to no web presence transacting in unusually high amounts from non-resident accounts; and unusual use of multiple exchange houses with fees or transaction patterns that do not reflect standard commercial practices.

  • Facilitators and Service Providers

IRGC networks are bolstered by facilitators including money services businesses (MSBs), investment companies, and trust and company service providers that assist—wittingly or unwittingly—in orchestrating complex money laundering and sanctions evasion schemes. Purported trust companies based in Hong Kong and Eastern Europe have been identified as facilitating the transmission of value to the IRGC, including through the conversion of fiat currency to digital assets.

  • Digital Assets

Iranian digital asset activity has reached billions of dollars per year, with the IRGC conducting sanctions evasion as part of this activity. Digital assets enable Iranian facilitators to circumvent the traditional financial system by transferring value internationally without intermediary financial institutions. Iranian facilitators are likely to use stablecoins due to their relative liquidity, ease of settlement, and exchange rate stability, and Iran’s use of stablecoins includes minting, moving between large-volume stablecoin issuers, and creating proprietary stablecoins. FinCEN also notes that unregistered peer-to-peer exchangers, unregistered foreign-located MSBs, and nested digital asset service providers (DASPs) may offer digital asset-related services in Iran.

Red flags in this area include companies with exposure to Iranian oil smuggling deviating from normal business practices to send or receive payments using digital assets; stablecoin payments with unclear sources of funds in high-risk jurisdictions; unusual stablecoin mint activity requiring multiple rate or limit increases; transactions directly or indirectly with digital asset addresses attributed to Iranian entities; authentication activity from Iranian IP addresses, email services, or phone numbers; and customer accounts that may be operating as unregistered P2P exchangers or nested DASPs providing services in Iran.

Conclusion

The FinCEN IRGC Alert reflects the U.S. government’s intensified focus on disrupting Iranian sanctions evasion networks and its expectation that the private sector serve as a critical partner in this effort. Regulatory compliance teams should evaluate existing frameworks governing exposure to Iranian illicit finance and ensure that processes align with current reporting and blocking obligations under U.S. law.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. Please click here to find out about our Anti-Money Laundering Team.

President Trump’s May 19, 2026 executive order, Restoring Integrity to America’s Financial System, directs Treasury, FinCEN, the CFPB, and the federal banking agencies to reassess how financial institutions identify and manage risks associated with non-work authorized populations and related cross border financial activity. The order reflects a significant shift in federal expectations across BSA/AML compliance, customer identification, and consumer credit underwriting. It also establishes short deadlines that will drive rapid regulatory and supervisory developments through the remainder of 2026.

The order frames these issues as national security and public safety concerns. It cites analyses linking low dollar cross border transfers to terrorist financing, narcotics trafficking, and human trafficking. It highlights Chinese money laundering networks that allegedly used U.S. accounts held by foreign passport holders to launder more than $312 billion for criminal organizations. It also identifies fentanyl related financial activity tied to Mexico based cartels as a priority area for regulatory attention.

At the same time, the order directs regulators to treat lending to non-work authorized individuals as a structural safety and soundness concern. It characterizes potential deportation and loss of wages as creating a fundamental ability to repay deficiency. This framing signals a broader policy shift that will affect both consumer credit markets and fair lending supervision.

Key Directives and Deadlines

The order requires several regulatory actions on compressed timelines.

Treasury Advisory (60 Days)

Within 60 days, Treasury must issue an Advisory describing red flags and typologies associated with six categories of suspicious activity:

  • Payroll tax evasion by employers or labor brokers
  • Use of foreign identity documents or nominee structures to conceal beneficial ownership or payroll disbursements
  • Unregistered MSBs and third party processors used for off the books wage payments intended to bypass BSA reporting thresholds
  • Structuring and micro structuring correlated with payroll cycles
  • Labor trafficking indicators where illicit proceeds are commingled with legitimate revenue
  • Use of ITINs to obtain credit or open accounts without verified lawful immigration status

Although the Advisory will not be binding, examiners routinely treat Treasury Advisories as articulations of expected practice. Institutions should anticipate that the Advisory will influence SAR filing expectations and monitoring scenarios well before any rulemaking is complete.

BSA Due Diligence Regulations (90 Days)

Within 90 days, Treasury must propose amendments to strengthen risk-based customer due diligence. The proposal must ensure institutions collect and verify sufficient identity information to assess illicit finance, sanctions evasion, and fraud risks. It must also preserve institutional authority to obtain additional information, including information relevant to immigration status and employment authorization, when other risk indicators warrant it.

Customer Identification Program Requirements (180 Days)

Within 180 days, Treasury and the federal functional financial regulators must consider changes to CIP regulations, with specific attention to risks associated with foreign consular identification cards. Institutions that rely on these documents for account opening should prepare for potential verification or documentation changes.

Credit Risk Guidance (60 Days)

Within 60 days, the CFPB must consider clarifying that potential deportation and loss of wages may adversely affect a non-work authorized borrower’s ability to repay under Regulation Z. Each federal functional financial regulator must also issue guidance on managing credit risks associated with non-work authorized populations. This directive raises complex questions about how lenders may incorporate immigration related risk factors while managing fair lending obligations.

Practical Implications for Financial Institutions

BSA/AML Programs

Institutions should begin reviewing transaction monitoring scenarios and SAR filing practices against the six categories of suspicious activity identified in the order. The forthcoming Treasury Advisory will likely establish new expectations for how institutions identify and report activity involving non-work authorized populations and their employers. Institutions should evaluate whether existing monitoring rules capture payroll related structuring, funnel account activity, and patterns associated with unregistered MSBs or third-party processors.

Customer Identification and Due Diligence

The order’s focus on consular identification cards and ITINs signals heightened scrutiny of identification documents commonly used by noncitizens. Institutions that accept these documents should assess whether existing CIP and CDD procedures address the risk indicators identified and whether additional verification steps may become necessary. Potential enhancements include supplemental non documentary verification, additional beneficial ownership inquiries, and review of employment authorization where risk indicators are present.

Credit Underwriting

Lenders offering consumer credit, particularly mortgage, auto, and credit card products, should evaluate whether underwriting models and ability to repay analyses account for the immigration related risk factors highlighted in the order. The CFPB’s forthcoming guidance will determine how lenders may incorporate these factors while managing fair lending obligations. Institutions should prepare for potential adjustments to income stability assessments, treatment of ITIN based applications, and portfolio level risk reviews.

Employer Related Risks

The order’s treatment of employer immigration law violations as a financial system vulnerability is notable. Institutions that bank employers in industries with high concentrations of non work authorized labor should anticipate increased scrutiny of payroll irregularities, mismatched tax identification numbers, and unusual payment patterns. These considerations may affect risk rating methodologies and periodic reviews for certain commercial customers.

Fair Lending Considerations

Institutions should monitor how the CFPB and prudential regulators reconcile the order’s directives with existing fair lending requirements under the Equal Credit Opportunity Act and the Fair Housing Act. The intersection of immigration status considerations and prohibited basis discrimination will require careful navigation, particularly if regulators expect lenders to incorporate deportation risk into underwriting.

Looking Ahead

The compressed timelines in the executive order mean that financial institutions will face a rapidly evolving regulatory environment over the next two to six months. Institutions should begin assessing how their existing BSA/AML, CIP, CDD, and credit underwriting programs align with the issues highlighted in the order and prepare for increased supervisory attention as agencies issue Advisories, proposed rules, and credit risk guidance.

We will continue to monitor developments as agencies complete their reviews and begin implementing the Order. If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

President Trump issued Executive Order 14405 (the “Order”) on May 19, 2026 titled Integrating Financial Technology Innovation into Regulatory Frameworks. The Order directs federal financial regulators to review and update regulations, guidance, and supervisory practices to support financial technology innovation and reduce barriers to entry for non‑bank fintech firms. It follows earlier actions establishing federal digital asset policy and a Strategic Bitcoin Reserve.

Stated Policy Objectives

The Order states that it is the policy of the United States to streamline regulatory processes, reduce unnecessary barriers to entry, and promote collaboration among fintech firms, federally regulated financial institutions, and federal financial regulators. It describes fintech firms as contributors to expanded access to financial services and economic opportunity. It also asserts that federal regulations should be updated to support the integration of digital assets and emerging technologies into traditional financial services and payment systems. The Order highlights concerns about fragmented or outdated regulatory requirements that may favor incumbent institutions.

Definition of “Fintech Firm”

The Order defines a fintech firm as any non‑bank company that uses or develops technology to offer or support financial products or services. The definition is broad and includes payment processing, lending, deposit‑taking, derivatives, investment management, brokerage services, underwriting, capital markets activities, custodial and fiduciary services, digital banking, digital asset services, securities and commodities activities, and blockchain‑based services. The Order incorporates by reference the financial activities listed in section 4(k)(4) of the Bank Holding Company Act.

Regulatory Review and Streamlining

Section 3 directs each federal financial regulator, including the CFPB, SEC, NCUA, CFTC, FDIC, and OCC, to conduct a review within 90 days of existing regulations, guidance, supervisory practices, and application processes. The review must identify items that could be updated to facilitate innovation and competition, including those that impede partnerships between fintech firms and federally regulated institutions. Agencies must also identify opportunities to streamline application processes for fintech firms seeking bank or credit union charters, deposit or share insurance, or other federal licenses and registrations.

The Order instructs agencies to balance innovation with safety and soundness, consumer and investor protection, market integrity, financial stability, and oversight. Within 180 days, each regulator is directed to take steps to encourage innovation based on the review, in consultation with the Assistant to the President for Economic Policy.

Access to Federal Reserve Payment Services

Section 4 requests that the Board of Governors of the Federal Reserve System conduct a comprehensive evaluation of the legal, regulatory, and policy framework governing access to Reserve Bank payment accounts and payment services by uninsured depository institutions and non‑bank financial companies, including firms engaged in digital assets and other novel activities. The Federal Reserve is asked to report within 120 days on:

  • the legal authority to extend direct access to such firms
  • options for expanding access subject to risk management requirements
  • legal impediments to direct access and potential legislative or regulatory solutions
  • whether individual Reserve Banks may act independently in granting or denying access and what policies should ensure consistent evaluation of applications

If the Federal Reserve determines that existing law permits expanded access, the Order requests that it establish transparent application procedures and make determinations on complete applications within 90 days.

Broader Context

The White House Fact Sheet describes the Order as part of a broader effort to position the United States as a global leader in financial innovation. It asserts that current rules governing access to payment services and third‑party risk management requirements may favor incumbents and that many financial regulations were designed for a brick‑and‑mortar environment. The Administration frames the Order as an attempt to modernize regulatory frameworks to reflect digital‑age financial services.

What This Means for Financial Institutions

Anticipated Regulatory Changes

The 90‑day review period means that by mid‑August 2026, each named regulator must complete its assessment. The 180‑day deadline for taking steps to encourage innovation extends into mid‑November 2026. Institutions should expect proposed rulemakings, updated guidance, or revised supervisory expectations to emerge on that timeline, particularly in areas involving bank‑fintech partnerships and chartering processes.

Third‑Party Risk Management and Bank‑Fintech Partnerships

The Order’s focus on regulations that impede partnerships suggests that existing interagency guidance on third‑party risk management, including the 2023 joint guidance issued by the OCC, FDIC, and Federal Reserve, may be revisited. Institutions with existing or planned fintech partnerships should anticipate potential adjustments to due diligence and oversight expectations. Current requirements remain in effect unless formally amended.

BSA/AML Considerations

Although the Order does not directly address Bank Secrecy Act or anti‑money laundering obligations, the potential expansion of Federal Reserve payment system access to non‑bank fintechs raises questions about the applicable AML/CFT framework for new direct participants. If non‑bank firms gain direct access, regulators will need to clarify whether and how BSA requirements apply. Institutions that currently serve as intermediaries for fintech payment flows should consider how their obligations may shift if those flows move to direct access models.

Federal Reserve Payment System Access

The Federal Reserve’s 120‑day report, expected by mid‑September 2026, will be a key milestone. The evaluation of whether individual Reserve Banks may act independently in granting access, and the emphasis on consistent evaluation standards, indicates concern about the current decentralized approach. Institutions that rely on privileged access to the Federal Reserve payment system as a competitive advantage should monitor this development closely.

Open Questions

Several issues remain unresolved. The Order does not specify what steps regulators must take after completing their reviews, leaving significant discretion to agency leadership. The Order states that it does not create enforceable rights and that implementation is subject to available appropriations. Any expansion of Federal Reserve access to non‑bank entities may require new legislation or a novel interpretation of existing authority under the Federal Reserve Act. Congressional engagement on these issues remains uncertain.

Conclusion

The Executive Order signals a significant policy direction for fintech regulation and the relationship between traditional financial institutions and non‑bank technology firms. Although the Order is primarily directive, the deadlines for regulatory review and Federal Reserve reporting create concrete milestones that will shape the regulatory landscape in the coming months. Financial institutions should evaluate how potential changes to third‑party risk management expectations, chartering processes, and payment system access may affect their operations and partnerships.

We will continue to monitor developments as agencies complete their reviews and begin implementing the Order. If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

On April 30, 2026, the Financial Crimes Enforcement Network (“FinCEN”) published a notice and request for comment (the “Notice”) in connection with its renewal of Form 107, which Money Services Businesses utilize for registration and renewal purposes. FinCEN’s Notice proposes a renewal without change to Form 107, and the comment period remains open until June 29, 2026.

The Bank Secrecy Act (“BSA”) and its implementing regulations require MSBs to file an initial registration form, to renew the registration every two years, and maintain a list of their agents (if applicable).

As part of the Paperwork Reduction Act, FinCEN is required to periodically review Form 107. FinCEN must justify the necessity of the collection form and intended use, as well as provide an estimate of the burden in completing the form.

According to FinCEN’s analysis of Form 107 filings from the past three years, the number of MSBs filing an initial or renewal form has increased. The estimated burden associated with the initial filing is 50 minutes, depending on the number of fields an MSB must complete, 40 minutes for renewal, and 30 minutes for maintaining an agent list. FinCEN acknowledged that maintaining an MSB agent list may require additional time for purposes of auditing and verifying the list; however, FinCEN does not account for this time in estimated burdens.

Efforts to Implement AMLA

The Notice asks for comments on the following questions related to FinCEN’s efforts to implement the Anti-Money Laundering Act (“AMLA”):

  • Is there publicly available data that went unmentioned in this Notice, but that FinCEN should consider when estimating the number of MSB agents? If possible, please comment on the generalizability and other usability feature of the data.
  • How would changes in the size or composition of the MSB population affect FinCEN’s estimated burden? Are there other assumptions that are more likely to contribute to substantive inaccuracies in the total burden and cost estimates? If so, please describe.
  • What changes to FinCEN Form 107 would reduce common errors or omissions?

Section 6216 of the AMLA directs FinCEN to review BSA regulations and guidance to ensure there are appropriate safeguards to protect the financial system from threats posed by various forms of financial crime. To meet this objective, FinCEN has previously sought input through formal requests for information (“RFI”) on regulations, reporting, and recordkeeping requirements that protect the U.S. financial system while also minimizing regulatory burdens posed. Although the previous RFI did not expressly mention burdens on MSBs, FinCEN is using this Notice as an opportunity to assess the regulatory burdens imposed on MSBs. 

Risks Posed by Unregistered MSBs

According to Treasury’s most recent National Money Laundering Risk Assessment, MSBs, like other financial institutions, continue to face money laundering risks. Treasury cited the large number of current MSB principals and agents and highlighted the “outsized risks” posed by unregistered MSBs. Unregistered MSBs may include individuals and entities acting as part of an informal value transfer system (“IVTS”) or may include individuals and entities using their personal or business accounts to engage in money transmission. Treasury highlighted a recent enforcement action against an unregistered MSBs that resulted in a $37 million civil money penalty.

Regulatory and Operational Impact

As a reminder, accurate and complete MSB registration and agent maintenance is part of the MSB examination procedures.

Second, the AMLA‑related questions highlight where FinCEN wants industry input. The agency is probing data sources for agent counts and recurring Form 107 errors. This is an opportunity to identify gaps between agent rosters and operations and fields prone to stale or mis‑keyed entries.

Third, banks serving MSBs should read the 2026 National Money Laundering Risk Assessment. Recent enforcement actions illustrate that registration is closely tied to BSA/AML program effectiveness. Onboarding and periodic reviews of MSB customers should confirm proper registration.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

On April 23, 2026, the Department of Justice announced charges against two Chinese Nationals, Huang Xing Shan and Jiang Wen Jie, for wire fraud, the seizure of $700 million in Cryptocurrency and the seizure of a Telegram Channel and 503 websites as part of the Department’s effort to combat foreign fraud schemes that target American citizens.

Huang and Jiang oversaw a cryptocurrency investment fraud operation at the Shunda compound in Burma. The Shunda compound is known to have operated from January 2025 to November 2025 and used scam websites and mobile applications designed to mimic legitimate investment platforms to convince its victims into draining their savings. 

The workers at the compound were trafficked individuals. Huang was a manager at the compound who reportedly used violence against the workers. Jiang was a supervisor who managed the workers’ efforts to defraud Americans.  The Shunda Compound was eventually seized by law enforcement, causing Huang and Jiang to attempt to replicate their scheme at a different compound in Cambodia.  In 2026, Huang and Jiang attempted to return to Burma but were arrested by Thai Law Enforcement for immigration violations. Their cases are currently being investigated by the FBI’s New York Field Office with assistance from Thai authorities.  The Complaint filed against Jiang Wen Jie can be found here. The Complaint filed against Huang Xing Shan can be found here.

The Scam Center Strike Force, which combines the powers of the U.S. Attorney’s Office with the Department of Justice’s Criminal Division, the FBI, and the U.S. Secret Service to secure America against Southeast Asian cryptocurrency-related fraud and scams, also announced the seizure of a Telegram Channel used to recruit workers.

The Telegram Channel had more than 6,0000 followers and was used to convince workers to travel to Cambodia with promises of high-paying employment. Once the workers arrived, they were held against their will and forced to participate in the fraud scheme. The workers specifically targeted Americans, imitating U.S. bank customer service agents and US law enforcement to convince victims to provide their bank account information. The Telegram seizure case is being investigated by FBI’s Miami Field Office, U.S. Secret Service Headquarters, and investigators at the U.S. Attorney’s Office for the District of Columbia. The Strike Force also announced that JPMorgan Chase, Microsoft, and Meta voluntarily took internal investigative measures to combat the fraud operating on their systems and occurring under their names.

Additionally, 503 dot-com web domains were seized. The domains were disguised as legitimate investment platforms. Victims reported to law enforcement that these platforms were causing them to unknowingly deposit cryptocurrency funds and view supposed “returns” on what they believed were legitimate investments.  In reality, the scammers received the investments and the returns. Now, when an individual visits these sites, they are informed the sites have been seized by law enforcement.

The Strike Force also announced that more than $701,962,392.15 in cryptocurrency has been identified as allegedly involved in laundering of funds stolen from victims of cryptocurrency investment fraud. The Strike Force aims to return the funds to victims.

In coordinated actions, the US Department of Treasury announced sanctions against individuals and entities perpetrating cryptocurrency investment fraud schemes against Americans using forced labor and violence in Cambodia, and Department of State announced an award of up to $10 million for anyone with information concerning the Tai Chang scam centers.

These actions are line with President’s Trump’s Executive Order Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens. Fighting fraud continues to be a top priority of this Administration’s Justice and State Departments.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.