In 2025, the Nevada Gaming Commission (Commission) and the Nevada Gaming Control Board (NGCB) launched one of the most significant enforcement waves in state history, imposing nearly $27 million in fines against three of the Las Vegas Strip’s largest operators: Caesars Entertainment, MGM Resorts, and Resorts World Las Vegas. Each case centered on failures to detect and prevent suspicious gambling activity tied to convicted bookmaker Mathew Bowyer, whose presence across multiple properties exposed systemic weaknesses in anti-money laundering (AML) programs. The enforcement actions highlight regulators’ growing insistence on robust compliance practices and a culture of vigilance within the gaming industry.

Caesars Entertainment Enforcement Action

The most recent fine, approved on November 20, 2025, ordered Caesars Entertainment to pay $7.8 million following a five-count NGCB complaint. The complaint alleged that Caesars permitted Bowyer to gamble freely across its properties for more than seven years, despite mounting red flags and evidence that other casinos had banned him as early as 2017. Caesars formally designated Bowyer as a “high risk” customer in 2019 yet failed to bar him until January 2024. Regulators described the company’s conduct as a systematic negligence, emphasizing that Caesars allowed Bowyer to win and lose millions without verifying his source of funds. The fine was set at roughly three times Bowyer’s net losses at Caesars, ensuring the company did not profit from its failures.

The Commission was notably frustrated by ongoing compliance issues across major operators, viewing Bowyer’s case as a clear example of broader weaknesses in oversight. The decision to impose penalties, supported by a vote of 4-to-1, underscored both the seriousness of the violations and a strong intent to prevent similar problems going forward.

MGM Resorts Enforcement Action

Earlier in the year, MGM Resorts faced its own enforcement action. In April 2025, the Commission approved an $8.5 million fine against MGM following a 10-count NGCB complaint. The complaint alleged that MGM permitted Bowyer and another illegal bookmaker, Wayne Nix, to gamble at MGM Grand and The Cosmopolitan between 2015 and 2018. Regulators noted that MGM executives had suspicions about Bowyer’s source of income as early as 2015, and in 2018 a customer warned MGM that Bowyer was attempting to poach gamblers from its casinos. Despite these warnings, MGM failed to act decisively. The complaint highlighted leadership failures under former MGM executive Scott Sibella, who allowed bookmakers to pay debts in cash and gamble millions without proper AML checks. MGM admitted wrongdoing and pledged reforms, with the Commission approving the fine unanimously.

Resorts World Las Vegas Enforcement Action

Resorts World Las Vegas faced the largest penalty of the three operators. In March 2025, the property agreed to pay $10.5 million following a 12-count NGCB complaint alleging severe AML deficiencies, and the Commission formally approved the fine. Regulators found that Resorts World allowed individuals with ties to illegal bookmaking and gambling-related felony convictions to gamble freely. The fine was the second-largest in Nevada history, behind Wynn Resorts’ $20 million penalty in 2019. The case was particularly notable given Resorts World’s status as a $4.2 billion property that opened in 2021 with modern infrastructure and the expectation of strong compliance systems. Regulators emphasized that even new properties with advanced technology are not immune from scrutiny if compliance programs fail to meet expectations.

Regulator Expectations

Taken together, the three fines illustrate regulators’ frustration with systemic AML failures across operators. Commissioners emphasized that operators must do more than maintain technical compliance programs; they must foster a culture of vigilance that prioritizes integrity over revenue. The Bowyer cases collectively demonstrate that regulators expect operators to proactively monitor high-risk patrons, escalate red flags promptly, and verify sources of funds. The enforcement trend also signals that regulators will not hesitate to impose multimillion-dollar penalties when operators fail to act decisively.

Industry Implications

The implications for the industry are significant. First, the fines underscore the importance of enhanced due diligence for high-risk patrons. Regulators expect operators to verify sources of funds, particularly when patrons engage in high-stakes play or exhibit patterns consistent with suspicious activity. Second, the cases highlight the need for clear escalation protocols. Caesars, MGM, and Resorts World each failed to act on red flags in a timely manner, allowing Bowyer to gamble millions over extended periods. Third, the enforcement actions demonstrate the value of independent audits. Regular reviews can help operators identify gaps in AML programs and remediate deficiencies before they attract regulatory attention.

Beyond technical compliance, the cases emphasize the importance of organizational culture. Regulators criticized operators for prioritizing revenue over compliance, suggesting that leadership must set the tone for vigilance and accountability. MGM’s case tied failures to specific executives, underscoring the role of leadership in shaping compliance outcomes. Caesars and Resorts World faced criticism for organizational cultures that allowed high-risk patrons to gamble freely despite clear warning signs.

The reputational damage associated with these fines is also significant. Caesars, MGM, and Resorts World each faced public embarrassment, with executives admitting their programs were “unacceptable.” The fines were widely reported in industry and mainstream media, reinforcing the perception that AML failures undermine the integrity of Nevada’s gaming industry. For operators, reputational harm can be as damaging as financial penalties, affecting relationships with regulators, investors, and customers.

Looking ahead, operators should expect continued scrutiny from regulators. The Bowyer cases suggest that regulators are focused not only on individual patrons but also on systemic weaknesses in compliance programs. Operators should anticipate more aggressive enforcement, particularly around high-stakes patrons and cash-intensive play. Regulators are likely to demand evidence that operators are proactively monitoring activity, escalating red flags, and verifying sources of funds.

Practical Steps for Operators

To mitigate regulatory risk and strengthen compliance programs, operators should implement enhanced due diligence protocols for high-risk patrons, including mandatory source-of-funds verification. They should establish clear escalation procedures to ensure red flags are acted upon promptly and consistently. Regular independent audits can help identify gaps and remediate deficiencies. Ongoing training for compliance staff and frontline employees is essential to reinforce vigilance and accountability. Finally, operators should benchmark AML practices against industry peers and regulatory expectations to ensure programs remain robust and adaptive.

The Bowyer-related fines against Caesars, MGM, and Resorts World underscore regulators’ intolerance for AML failures. Operators must treat compliance as a strategic priority, recognizing that lapses can trigger multimillion-dollar penalties and lasting reputational harm. The enforcement actions highlight regulators’ expectation that operators foster a culture of vigilance, where integrity is prioritized over revenue. For the gaming industry, the lesson is clear: AML compliance is not optional, and failure to act decisively on suspicious activity will carry significant consequences.

Ballard Spahr’s Gaming Industry Group and Anti-Money Laundering Practice provide comprehensive guidance to public and private sector clients navigating the evolving regulatory landscape. Our team advises on Bank Secrecy Act and anti-money laundering compliance, assists with governmental inquiries, investigations, enforcement proceedings, licensing matters, internal risk assessments, policy development, training programs, transactional due diligence, technology integration for compliance monitoring and reporting, and crisis management in response to active investigations.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch.  Please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

The U.S. Department of Treasury’s Financial Crimes Enforcement Network (FinCEN) released its latest Financial Trend Analysis (FTA) this month, reporting data from banks and other financial institutions showing that, following a recent surge, the number of reported ransomware incidents and payment amounts dipped slightly in 2024. High-profile ransomware attacks frequently appear in the news and the impact can be severe: in just the last month, news broke that an e-tailer company was knocked offline for 45 days following one attack, and cities and towns across the U.S. lost access to their emergency alert systems after another.

Data indicates reality matches the perception—ransomware attacks surged to their highest levels in 2023, with a total of 1,512 reported incidents and $1.1 billion in reported ransom payments, a staggering 77 percent increase in total payments from the prior year. This continued a trend of increased malicious activity that first appeared in 2021, in which FinCEN received reports of approximately 1,400 incidents and nearly $1 billion in payments, more than double the previous year. Indeed, the three-year review period for the FTA (January 2022–December 2024) saw a total of 7,395 ransomware-related reports, totaling more than $2.1 billion in payments, while during the entire previous nine-year period (2013 through 2021), FinCEN received only 3,075 reports totaling approximately $2.4 billion in ransomware payments.

One year does not make a trend but the latest data show signs for cautious optimism. In 2024, companies reported a total of 1,476 ransomware incidents, and approximately $734 million in ransomware payments. The median ransomware payment also decreased, from $175,000 in 2023 to $155,257 in 2024. FinCEN attributes this decrease in part to U.S. and U.K. law enforcement disrupting high-profile ransomware groups in December 2023 and February 2024.

No industry is immune from the threat of attack, but the FTA identified that financial services, manufacturing, and healthcare industries reported both the greatest number of incidents and highest amount of aggregate payments sent to ransomware actors during the review period. Retail and legal services reported the next highest amount of overall incidents; meanwhile, science and technology and retail rounded out the highest reported total payments.

Other key findings reported in the FTA include:

  • The data revealed 267 distinct ransomware variants used in attacks during 2022 – 2024, the most prevalent being Akira, ALPHV/BlackCat, LockBit, Phobos, and Black Basta.
  • Ransomware actors most often used The Onion Router (“Tor”) to communicate with their victims, reported in 67 percent of ransomware incidents during the reporting period. TOR uses encryption and layered network infrastructure to allow users to browse the internet anonymously and conceal their identity and point of origin.
  • Bitcoin (BTC) remains the prominent payment method of choice for ransomware actors, accounting for 97 percent of the reported ransomware transactions.

The financial threat to companies posed by ransomware is no secret. Data reported to FinCEN indicates that, although the vast majority of payments demanded by ransomware actors are below $250,000, individual demands can exceed $5 million. But the risk doesn’t end with the actual ransom payment—companies face increasing legal liability as well. According to one report from 2023, nearly one in five ransomware attacks resulted in a lawsuit against the victim company. Class actions against companies for failure to prevent or disclose ransomware breaches abounded in 2025, after several litigations arising from earlier breaches led to costly settlements.  

Therefore, it is as important as ever for companies to take steps to prevent, detect, and respond effectively to ransomware attacks. As FinCEN summarizes, “ransomware is a complex cybersecurity problem requiring a variety of preventive, protective, and preparatory best practices.” The FTA references several resources, including the Cybersecurity and Infrastructure Security Agency’s (CISA) website StopRansomware.gov, the National Security Agency’s (NSA) Ransomware Guide, and the National Institute of Standards and Technology’s (NIST) Data Integrity Project.

FinCEN publishes FTAs pursuant to section 6206 of the Anti-Money Laundering Act of 2020, 31 U.S.C. § 5318(g)(6)(B), which requires periodic reporting of threat pattern and trend information derived from data reported to FinCEN under the Bank Secrecy Act. The AML Blog has posted on previously-issued FTAs here and here.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

The prosecution of the developers behind Samourai Wallet illustrates how U.S. authorities are broadening their approach to privacy‑focused cryptocurrency tools. In April 2024, the U.S. Attorney’s Office for the Southern District of New York announced charges against Keonne Rodriguez, Samourai’s chief executive, and William Lonergan Hill, its chief technology officer. The indictment alleged that Samourai facilitated more than $2 billion in Bitcoin transactions, including $237 million in criminal proceeds, with over $100 million tied to darknet markets. By late 2025, both pleaded guilty: Rodriguez was sentenced to five years, Hill four, on conspiracy counts related to money transmission and money laundering.

Statutory Basis for the Charges

The convictions rested on two statutes traditionally applied to custodial financial services but now extended to non‑custodial crypto tools.

  • 18 U.S.C. § 1960 criminalizes operating an unlicensed money transmitting business. Historically, this applied to custodial services holding or transferring funds for customers. Samourai was different: users retained control of their private keys, while the software facilitated transactions. Prosecutors argued that features such as Whirlpool and CoinJoin, privacy techniques mixing coins from multiple users, amounted to money transmission by obscuring fund origins. They pointed to Samourai’s fee structure, promotional materials, and darknet outreach as evidence of intent.
  • 18 U.S.C. § 1956 covers conspiracy to commit money laundering. Prosecutors contended that Samourai’s design and marketing encouraged concealment of criminal proceeds, citing communications and promotional materials aimed at illicit users.

Enforcement Trends: Samourai vs. Tornado Cash

Samourai is part of a broader enforcement trend targeting privacy‑enhancing crypto tools. The Tornado Cash prosecution in 2023 raised parallel issues but in a different technological and legal context. (See our additional blog posts about Tornado Cash here, here, here, and here.)

Tornado Cash, built on Ethereum smart contracts, posed the challenge of immutability: once deployed, the code operated autonomously, and developers argued they lacked control over user activity. This immutability became central to defenses and civil litigation, with courts questioning whether autonomous code could be treated as “property” subject to sanctions. By contrast, Samourai’s active coordinator service and ongoing updates gave prosecutors a foothold to argue that its developers exercised meaningful operational control. This distinction allowed the government to frame Samourai’s conduct not as passive publication of code but as active facilitation of illicit finance.

Tornado Cash litigation tested the boundaries of OFAC’s sanctions authority under IEEPA, ultimately resulting in judicial limits on designating immutable smart contracts. Samourai, however, was pursued under traditional criminal statutes, extending their application to non‑custodial wallets and raising questions about fair notice given FinCEN’s prior guidance.

Legal Questions Raised

These prosecutions highlight unresolved constitutional and statutory issues. If Tornado Cash and Samourai represent two ends of the spectrum—immutable code versus actively maintained software—courts must now contend with how far existing law can extend to decentralized technologies. At stake are broader questions of liability, statutory interpretation, and constitutional protections such as speech and due process. The central question is whether publishing and maintaining privacy‑focused code remains speech under the First Amendment, or whether it becomes criminal conduct when paired with active promotion toward illicit use.

Tornado Cash Litigation: OFAC Sanctions and DOJ Charges

Tornado Cash faced a dual track of enforcement: criminal charges against its developers and administrative sanctions against its code.

In Van Loon v. Department of the Treasury (5th Cir. 2024), plaintiffs challenged OFAC’s authority. (See our blog post here.) The Fifth Circuit ruled that sanctioning immutable Tornado Cash smart contracts exceeded OFAC’s statutory authority under IEEPA, limiting designation of autonomous code as “property.” The decision underscored the difficulty of applying traditional law to decentralized technology, though it did not categorically immunize all crypto protocols from sanctions.

This judicial pushback illustrates the limits of sanctions law when applied to autonomous protocols. Parallel developments in FinCEN guidance further complicate matters, as longstanding custodial versus non‑custodial distinctions intersect uneasily with prosecutorial theories advanced in Samourai.

FinCEN Guidance

FinCEN has generally distinguished custodial from non‑custodial wallets. Its 2019 guidance (FIN 2019 G001) stated that entities providing only software without asset custody are not subject to registration or Bank Secrecy Act requirements applicable to money services businesses. In 2024, FinCEN withdrew proposed rules that would have imposed KYC obligations even for non‑custodial wallet providers, reinforcing earlier interpretations.

Yet during proceedings against Samourai’s founders, prosecutors reportedly asked FinCEN whether CoinJoin or non‑custodial wallets qualified as “money transmission.” FinCEN answered “no,” but charges proceeded regardless. This divergence raises constitutional questions about fair notice and the consistency of regulatory versus prosecutorial positions.

Comparative Analysis: Samourai and Tornado Cash

Placing Samourai and Tornado Cash side by side reveals how enforcement risks diverge depending on technological design, regulatory posture, and evidentiary focus. Tornado Cash’s defense rested on immutability, emphasizing that once deployed, developers lacked the ability to control user activity. This argument framed the project as autonomous code rather than an ongoing service. By contrast, prosecutors in Samourai highlighted the wallet’s active coordinator service, continuous updates, and targeted marketing as evidence of meaningful developer involvement.

Regulatory approaches also diverged. Tornado Cash was primarily challenged through OFAC’s sanctions authority under IEEPA, a strategy that met judicial resistance when courts questioned whether immutable smart contracts could be designated as “property.” Samourai, however, was pursued under traditional criminal statutes (§ 1960 and § 1956) despite FinCEN’s guidance suggesting such tools were outside money transmission rules.

Evidence in each case points to fundamentally different enforcement approaches. In Tornado Cash, the defense leaned on the impossibility of control, arguing that immutability precluded intent. In Samourai, prosecutors relied on direct evidence of intent, pointing to promotional materials, darknet outreach, and fee structures as proof that the wallet was designed to attract illicit use.

Taken together, the comparison demonstrates that enforcement is not uniform but highly contingent. Immutable protocols test the limits of sanctions law, while actively maintained wallets are subject to broader applications of criminal statutes. The broader lesson is that privacy‑preserving technologies, whether autonomous or developer‑driven, now face heightened scrutiny, with liability theories evolving to match the technical contours of each project.

Conclusion

The Samourai convictions signal a shift in how federal authorities apply existing statutes to decentralized and non‑custodial technologies. By extending provisions traditionally aimed at custodial services to privacy‑focused wallets, prosecutors demonstrated a willingness to reinterpret statutory language considering evolving technical design. This approach may deter illicit finance, but it also raises unresolved constitutional questions about fair notice, due process, and the boundary between protected speech and criminal conduct.

More broadly, the trajectory of enforcement against Samourai and Tornado Cash underscores that privacy‑preserving tools, whether autonomous protocols or actively maintained software, are now within the sights of regulators and prosecutors. Liability theories are likely to adjust to each project’s design, reflecting ongoing enforcement developments.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch.  Please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

We blogged earlier this year about Attorney General Pam Bondi’s February 5, 2025 memorandum focusing the U.S. Department of Justice’s attention squarely on Mexican cartels, and about subsequent steps the Trump Administration has taken to follow through on that prioritization.  In the latest such effort, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) has issued a Notice of Proposed Rulemaking (NPRM) pursuant to Section 311 of the USA PATRIOT Act, which would prohibit U.S. financial institutions from processing any transactions which involve any of ten specific Mexican casinos (referred to collectively in the NPRM as the “Gambling Establishments”).  The casinos in question, spread across four Mexican states, are owned by three separate Mexican companies; however, FinCEN states in the NPRM it “assesses that the Gambling Establishments are ultimately controlled by a criminal group with a longstanding and transactional financial relationship in which the Gambling Establishments facilitate money laundering for the benefit of the Cartel de Sinaloa (Sinaloa Cartel)” – a drug trafficking organization which President Trump designated as a terrorist group on the first day of his second term, and which the Drug Enforcement Administration (DEA), in its 2024 National Drug Threat Assessment, characterized as being one of two cartels “at the heart” of the U.S. synthetic opioid crisis.

In the NPRM, FinCEN declares that “reasonable grounds exist for concluding that transactions involving the Gambling Establishments are of primary money laundering concern” after considering certain relevant factors – that the casinos allegedly make monthly disbursements to the Sinaloa Cartel, as well as additional illicit payments to senior cartel members carefully arranged (in amounts and timing) “to prevent documentable connections” between the casinos; and that the money laundering allegedly facilitated by the casinos benefits the Sinaloa Cartel, which is (as framed in the NPRM) a major driver of the U.S. opioid crisis – thus constituting, in the words of the NPRM “a significant threat to U.S. national security.”

The “meat” of the NPRM is Section 1010.665(b) of the proposed rule, imposing a “special measure” to combat the instant problem. Section (b)(1) would impose a prohibition on covered financial institutions (e.g. banks, securities brokers and dealers, and mutual funds) “opening or maintaining in the United States any correspondent account for or on behalf of a foreign banking institution if such correspondent account is used to process a transaction involving any of the Gambling Establishments.” Section (b)(2) would require that a covered financial institution go beyond basic due diligence when assessing its foreign financial institution clients, as it calls for “apply[ing] special due diligence to its correspondent accounts that is reasonably designed to guard against such accounts being used to process transactions involving the Gambling Establishments[,]” and specifies that such enhanced due diligence must include both sending written notice to foreign financial institution customers that they must not provide the casinos with access to their correspondent accounts and implementing screening mechanisms to identify correspondent account transactions involving the casinos.

FinCEN notes in the NPRM that various alternatives were considered to the blanket prohibition on the opening or maintaining of correspondent accounts, but that “[b]ecause of the nature, extent, and purpose of the obfuscation engaged in” by the casinos, any efforts to require additional information collection – e.g., reporting obligations, beneficial ownership identification, or enhanced know-your-customer (KYC) requirements – would ultimately be inadequate in addressing the paired goals of (a) protecting the U.S. financial system from risk and (b) impacting the Sinaloa Cartel’s ability to profit from its illicit activities.

The press release announcing the NPRM stated that it was being promulgated “in coordination with the Government of Mexico” – importantly for cross-border relations, as implementation of this rule may severely deplete willingness of U.S. financial institutions to do business with Mexico-based financial institutions and businesses in light of the heightened scrutiny required.

            If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

On November 4, 2025, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) designated eight individuals and two entities for their involvement in laundering funds derived from illicit schemes originating in the Democratic People’s Republic of Korea (DPRK).  These activities included cybercrime operations and information technology (IT) worker fraud, both connected to revenue streams supporting North Korea’s nuclear weapons and ballistic missile programs.

North Korean Cybercrime, IT Worker Sanctions Evasion

The OFAC announcement identified cybercrime as a major mechanism for DPRK-affiliated actors to obtain funds outside legitimate financial channels.  Reports estimate that these actors have stolen over $3 billion—primarily in cryptocurrency—using, among other methods, advanced malware techniques and social engineering tactics.  OFAC’s November 4th announcement identified sanctioned individuals and financial entities pursuant to its authority under Executive Orders 13694 (as amended), 13810, as well as other relevant orders, for providing material assistance or support for illicit cyber activities, engaging in commercial conduct that generates revenue for the DPRK, and/or facilitating transactions involving the property or interests in property of designated entities.

Additionally, OFAC noted ongoing fraudulent activities involving North Korean IT workers operating abroad.  Despite prohibitions outlined in Paragraph 17 of United Nations Security Council Resolution 2375 against granting work authorizations to DPRK nationals absent UN approval, these individuals reportedly continue to earn income globally by obfuscating their identities when engaging with freelance platforms and employers.  According to the Multilateral Sanctions Monitoring Team report titled, “The DPRK’s Violation and Evasion of UN Sanctions Through Cyber and Information Technology Worker Activities,” at least a portion of the earnings generated by the IT teams are used in support of  DPRK objectives, including weapons development and production, domestic infrastructure projects, and the procurement of consumer goods.

Blocking Requirements and Financial Networks Targeted by OFAC Sanctions

Under the new sanctions, all property or interests in property belonging to the designated parties that are within the United States or under possession or control of U.S. persons are blocked and must be reported to OFAC.  Entities directly or indirectly owned (individually or collectively at least fifty percent) by one or more blocked persons also become subject to blocking requirements.  Unless specifically authorized by an OFAC license or exempted by regulation, transactions involving sanctioned individuals or entities are generally prohibited if conducted by U.S. persons or occur within, or transit through, the United States.

Financial institutions and other organizations may face secondary sanctions risk if they engage in certain transactions with sanctioned parties, including providing funds, goods, services (or receiving such contributions from those individuals or entities) even if not intentionally facilitating sanctionable conduct.

Among those recently designated by OFAC are key North Korean financial institutions along with several senior representatives. These include:

  • Jang Kuk Chol and Ho Jong Son, bankers at U.S.-designated First Credit Bank, managed funds, including $5.3 million in cryptocurrency, on behalf of the designated institution;
  • Korea Mangyongdae Computer Technology Company along with its current president U Yong Su, organizing IT worker delegations to China and employing Chinese nationals as banking proxies;
  • Ho Yong Chol facilitated $2.5 million transfer in U.S. dollars (USD) and Chinese yuan (CNY) on behalf of the U.S.-designated Korea Daesong Bank;
  • Han Hong Gil, employee at U.S.-designated Koryo Commercial Bank, facilitated $630,000 in transactions on behalf of U.S.-designated Ryugyong Commercial Bank;
  • U.S.-designated Foreign Trade Bank (FTB) chief representative Jong Sung Hyok;
  • Ri Jin Hyok, also a representative of FTB, facilitated transactions worth over $350,000 in USD, CNY, and euros through a front company;
  • Choe Chun Pom, official at U.S.-designated Central Bank of DPRK, facilitated transactions worth over $200,000; and
  • Ryujong Credit Bank engaged in sanctions evasion activities, including remitting North Korea’s foreign currency earnings, money laundering, and conducting financial transactions for overseas North Korean workers.

These designations illustrate methods employed by DPRK-linked networks such as deploying front companies abroad, leveraging international proxies for banking activity intended to obscure transaction originators/beneficiaries, moving earnings from overseas IT workforces into state channels via complex cross-jurisdictional arrangements, as well as utilizing digital assets for sanctions evasion purposes.

Compliance Implications for Financial Institutions and AML Practices

For industry practitioners focused on anti-money laundering compliance, including banks and fintech providers, this regulatory action highlights continued expectations regarding enhanced due diligence practices around high-risk geographies and typologies associated with state-sponsored illicit finance activity.  Monitoring customer onboarding processes for indicators like frequent use of freelance hiring platforms under suspicious circumstances is among several areas cited by authorities where vigilance is warranted given current trends.

In summary: The November 2025 designations reflect evolving approaches used in DPRK-related money laundering schemes across digital asset ecosystems and traditional financial systems alike.  Regulatory compliance teams should evaluate existing frameworks governing exposure risk assessment relative to updated guidance while ensuring processes align with current reporting/blocking obligations where applicable under U.S., UN-sanctioned measures, or similar regimes implemented elsewhere internationally.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch.  Please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

On November 6, 2025. Keonne Rodriguez, the co-founder of the cryptocurrency mixer Samourai Wallet, was sentenced for to 60 months in federal prison for the crime of conspiring to operate an unlicensed money-transmitting business in violation of 18 U.S.C § 371. The two-count indictment, filed on February 14, 2024, alleged that Defendants Rodriguez and William Lonergan Hill developed, marketed, and operated a cryptocurrency mixing service know as Samourai Wallet, an unlicensed money transmitting business that earned millions of dollars by laundering over $100 million dollars of crime proceeds originating from illegal dark web markets.

Defendant Rodriquez pled guilty to Count II (Conspiracy to Operate a Money transmitting Business) on July 29, 2025. The next day, Defendant Hill plead guilty to Count II. The defendants both entered to preliminary orders of forfeiture and money judgment to forfeit $237,832,360.55 (representing the amount of property involved in Count II of the indictment) and make a payment to the United States in the amount of $6,367,139.69 before the sentencing date. Count I (Conspiracy to Commit Money Laundering) was dismissed as a part of the plea deals.

At the sentencing, Defendant Rodriguez’s right, title and interest in $6,367,139.69 in U.S. currency, samouraiwallet.com and Samourai Wallet Google Play Application was forfeited to the United States. In addition to the 60 months prison sentence, the Court fined Defendant Rodriquez $250,000. Defendant Hill is scheduled to be sentenced on November 19, 2025.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch.  Please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

On October 23, 2025, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (“FinCEN”) issued a Financial Trend Analysis (“FTA”), identifying $9 billion of potential Iranian shadow banking activity in 2024, based on reporting from U.S. financial institutions. Treasury issues FTAs periodically with threat pattern and trend information derived from Bank Secrecy Act (BSA) filings, pursuant to section 6206 of the Anti-Money Laundering Act of 2020 (AMLA).

Background on Iranian Illicit Activity

The latest FTA expands on information in a June 6 FinCEN Advisory, which urged U.S. financial institutions to be vigilant in detecting the Iranian regime’s illicit activities and attempts to exploit the U.S. financial system. Replacing FinCEN’s 2018 Advisory on the Iranian regime’s illicit activities, the June Advisory provided updated red flags and current trends and typologies for Iranian sanctions evasion, oil smuggling, shadow banking networks, and weapons procurement, to assist financial institutions in identifying, preventing, and reporting suspicious activity connected with Iranian illicit financial activity.

The Advisory and recent FTA, which elaborates on how Iran evades sanctions and generates illicit revenue to support nuclear weapons, ballistic missile, and unmanned aerial vehicle (UAV) programs, support the U.S. “maximum pressure campaign” against Iran announced earlier this year in a February 4 National Security Presidential Memorandum (“NSPM-2”).

Concurrent with the June 6 Advisory, Treasury’s Office of Foreign Assets Control (OFAC) designated more than 30 individuals and entities with ties to Iranian brothers Mansour, Nasser, and Fazlolah Zarringhalam, who laundered billions through the international financial system via Iranian exchange houses and foreign front companies under their control as part of Iran’s shadow banking network. The full list of designations made as part of June 6 sanctions action is available here. The June 6 action was the first round of sanctions targeting Iranian shadow banking infrastructure since the issuance of NSPM-2. It was taken pursuant to Executive Order (E.O.) 13902, imposing sanctions on additional sectors of the Iranian economy in January 2020.

The FTA

To develop the recent FTA, FinCEN analyzed BSA information, including Suspicious Activity Reports (SARs), from transactions in 2024 that financial institutions or FinCEN had connected to potential Iranian shadow banking activities. FinCEN restricted the dataset to transactions valued at least $500,000 and removed transactions that BSA data and open source information could not corroborate were linked to Iran. The final data set contained 2,027 transactions, totaling $9 billion in activity.

According to FinCEN, its analysis revealed many aspects of the complex financial and corporate infrastructure that Iran uses to sell sanctioned oil and petrochemicals on the international market, launder the proceeds, and procure export-controlled technology for Iran’s military and nuclear program. The analysis shed further light on how shadow banking networks operate, expanding on prior findings about how Iran’s Ministry of Defense and Armed Forces Logistics (MODAFL) and Islamic Revolutionary Guard Corps (IRGC) gain access to the international financial system, launder billions of dollars, and engage in revenue-generating activities such as sale of oil and petrochemicals. MODAFL was designated most recently in 2019 for assisting IRGC Qods Force (IRGC-QF), which was designated in 2007 for supporting multiple terrorist groups.

Based on the latest trend analysis, Iranian shadow banking networks operate across continents to connect Iranian front companies, including oil, shell, shipping, investment, and technology procurement companies, which transact billions of dollars amongst themselves and with other companies. Iranian shadow banking has a prominent presence in United Arab Emirates (UAE), Hong Kong, and Singapore. The Iranian regime relies on these networks, which also include exchange houses, to gain access to the U.S. dollar and U.S. financial system through U.S. correspondence accounts. This access allows Iran to export oil and other commodities, launder the proceeds, and generate funds to advance its military weapons programs and support terrorist groups.

FinCEN made several significant findings as part of its analysis. Here are the key takeaways:

  • Foreign shell companies appear to play the largest role in Iranian shadow banking activities. Likely shell companies—exhibiting multiple indicators of shell activity like no verifiable business activity, little internet presence, or use of a shared address—transacted approximately $5 billion in 2024. These companies sent $4.2 billion, mostly from China-based non-resident accounts (NRAs) operated by Hong Kong-based entities. Likely shell companies received $4.3 billion, which was mostly received by UAE-based shell companies.  
  • FinCEN found dozens of oil companies to be likely Iranian front companies, which transacted $4 billion in 2024, potentially for illicit oil sales. These were primarily based on UAE and Singapore.  
  • Potential technology procurement companies received funds from Iran-linked entities. Companies suspected of facilitating Iran’s procurement of export-controlled technology engaged in an estimated $413 million in transactions in 2024.
  • International shipping companies may have transported sanctioned Iranian oil. FinCEN found that dozens of shipping companies transacted approximately $707 million, potentially to transport sanctioned Iranian oil and petrochemicals. Most of these companies were based in Iraq, UAE, or Hong Kong.
  • Foreign investment companies potentially gave Iran access to international investment markets. Based on its analysis, FinCEN determined that UK and UAE investment companies transacted about $665 million, potentially to provide Iranian entities with access to international investment trading.
  • Iranian entities potentially exploited U.S. financial institutions. FinCEN found that the approximately $9 billion of shadow banking funds in 2024 passed though correspondent accounts maintained at U.S.-based financial institutions. FinCEN identified two foreign companies that transferred $534 million from U.S. bank accounts to Iran-linked entities. It also found that foreign companies, including Iran-linked entities, transacted $361 million using accounts with foreign branches of U.S.-based financial institutions and $174 million using accounts with foreign subsidiaries of U.S.-based financial institutions.
  • FinCEN also found that the UK and Switzerland financial systems are potentially vulnerable to Iranian shadow banking. It found UK-based companies transacted $540 million using accounts at UK- or Switzerland-based financial institutions, and that Switzerland-based companies transacted $115 million and foreign companies transacted $503 million using accounts at Switzerland-based financial institutions and Swiss branches of foreign financial institutions.

FinCEN’s analysis also provides case studies and infographics to illustrate its findings, and can be accessed online here: https://www.fincen.gov/system/files/2025-10/FTA-Iranian-Shadow-Banking.pdf.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch.  Please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

On October 15, 2025, the Financial Crimes Enforcement Network (FinCEN) issued a final rule under Section 311 of the USA PATRIOT Act that prohibits U.S. financial institutions from conducting business with the Cambodia-based Huione Group, a financial services conglomerate based in Phnom Penh, Cambodia.  Huione Group is the parent company of, or otherwise controls, several subsidiaries, affiliates, and components, including, but not limited to: Haowang Guarantee, Huione Pay PLC, and Huione Crypto.  The rule targets all these entities as Huione Group for laundering proceeds of virtual currency scams on behalf of malicious cyber actors, among other criminal wrongdoing.  The final rule can be found here: https://www.fincen.gov/news/news-releases/fincen-issues-final-rule-severing-huione-group-us-financial-system.

In addition, the Department of the Treasury’s Office of Foreign Assets Control (OFAC) imposed sweeping sanctions on 146 targets within the Prince Group Transnational Criminal Organization (Prince Group TCO), a Cambodia-based network led by Cambodian national Chen Zhi that operates a transnational criminal enterprise through online investment scams targeting Americans and others worldwide.  Prince Group TCO is composed of Cambodia-based Prince Holding Group, Chen Zhi, his close associates and business partners, and their core commercial interests, all of which operate in furtherance of Prince Group TCO’s criminal enterprise.  Treasury’s news release can be found here: https://home.treasury.gov/news/press-releases/sb0278.

FinCEN’s Key Findings and Final Rule

FinCEN found that Huione Group is a foreign financial institution of primary money laundering concern, and its final rule imposes a prohibition on covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Huione Group.

  • Prohibition: Covered financial institutions are prohibited from opening or maintaining correspondent accounts for, or on behalf of, the Huione Group.  Such institutions much take reasonable steps to not process a transaction for the correspondent account of a foreign banking institution in the United States if that transaction involves Huione Group.
  • Enhanced Due Diligence: Covered financial institutions must employ special due diligence to all foreign correspondent accounts to prevent those accounts being used to process transactions involving Huione Group and provide notice to such account holders regarding these prohibitions.
  • Effective date: The final rule is effective November 17, 2025. 

Detailed Grounds for Action

Huione Group served as a crucial hub for laundering billions of dollars from a variety of illegal activities.  These activities include: 

  • North Korean cybercrimes: Laundering proceeds from cybercrimes carried out by the Democratic People’s Republic of Korea (DPRK), including the Lazarus Group.
  • Transnational fraud: Processing hundreds of millions of dollars in illicit proceeds from transnational criminal organizations, particularly those in Southeast Asia.
  • “Pig butchering” scams: Laundering funds from virtual currency investment scams that targeting individuals across the world.
  • Online marketplace for crime: Operating an online marketplace that offered illegal financial services and tools for trafficking.

Huione Group combined its substantial participation in worldwide criminality with an absence of, or a highly ineffective, anti-money laundering program, along with recent changes that served to further obscure Huione Group’s involvement in illicit activity.

Broader United States Government Activity

The FinCEN rule is part of a broader, coordinated enforcement action by United States and United Kingdom authorities to combat large-scale criminal networks operating in Southeast Asia.

  • Prince Group sanctions: OFAC and the U.K. Foreign, Commonwealth, and Development Office announced sanctions against the Cambodia-based Prince Group, which is accused of running a criminal empire through online investment scams and scam compounds that rely on human trafficking and forced labor.
  • Criminal charges: The United States Attorney’s Office in the Eastern District of New York unsealed an indictment against Chen Zhi, the founder of the Prince Group, on charges of wire fraud and money laundering conspiracy. The Department of Justice’s press release on the indictment can be found here: https://www.justice.gov/opa/pr/chairman-prince-group-indicted-operating-cambodian-forced-labor-scam-compounds-engaged.
  • Largest-ever bitcoin seizure: As part of the action, the Department of Justice seized approximately $15 billion in bitcoin, alleged proceeds of Chen Zhi’s fraud schemes.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. Please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

On October 9, 2025, the Financial Crimes Enforcement Network (“FinCEN”) jointly issued updated Frequently Asked Questions (“FAQs”) with the Federal Reserve Board of Governors, the Federal Deposit Insurance Corporation, the National Credit Union Administration, and the Office of the Comptroller of the Currency, clarifying the circumstances under which financial institutions must file suspicious activity reports (“SARs”).

Background

            For decades, SARs have been a useful tool for law enforcement agencies to detect money laundering and counter the financing of terrorism. However, regulatory guidance regarding when and how financial institutions must file these reports has at times been unclear. Financial institutions often expended significant organizational resources meeting supervisory expectations or best practices from examination manuals, even where not strictly required by law. The FAQs seek to clarify and simplify what is required of financial institutions under the Bank Secrecy Act (“BSA”).

Recent regulatory updates indicate a shift in philosophy regarding SARs, emphasizing efficiency and effectiveness in suspicious activity reporting. FinCEN has signaled an intent to pivot away from blanket expectations that can lead to duplicative work and information overload for both financial institutions and law enforcement. This marks a notable departure from previous practices where compliance obligations often resulted in substantial resource expenditures with limited incremental value for investigators.

What Do These FAQs Say?

            FinCEN and its partners identify four key areas: structuring SARs; continuing activity reviews; timelines for continuing activity SARs; and documentation requirements, clarifying both legal standards and practical expectations within the SAR regulatory scheme.

  1. SAR Filings for Potential Structuring-related Activity

    FinCEN writes that financial institutions are not required to file SARs for a transaction or series thereof with a value at or near the $10,000 Currency Transaction Report (“CTR”) threshold solely because it meets that amount, unless there is knowledge or suspicion that such transactions are designed specifically “to evade BSA reporting requirements.” In absence of any knowledge, suspicion, or reason to suspect, a financial institution is not required to file SARs simply because a transaction is at or above the CTR threshold.

    Similarly, financial institutions must file a SAR only when they know, suspect, or have reason to suspect transactions aggregating $5,000 or more are designed specifically “to evade BSA reporting requirements” such as CTRs.

    The FAQ also addresses structuring – an unlawful attempt to evade CTR reporting requirements under 31 C.F.R. § 103.18. FinCEN regulations define structuring as “a person, acting alone, or in conjunction with, or on behalf of, other persons, conducting or attempting to conduct one or more transactions in currency, in any amount, at one or more financial institutions, on one or more days, in any manner, for the purpose of evading CTR reporting requirements.” This definition is inclusive of attempts to evade requirements by breaking sums of currency above the CTR threshold into smaller sums below the threshold. The FAQs make clear that financial institutions should operate and maintain anti-money laundering and CFT protocols to detect and report structuring. The FAQs reflect FinCEN’s intention that institutions focus their efforts on high-value information rather than routine filings based solely on transaction amounts.

        2. Continuing Activity Reviews

    The FAQs also address ongoing or continuing suspicious activity by a single customer or account. Prior FinCEN guidance suggested that financial institutions are expected or required to monitor whether suspicious activity is ongoing after a SAR has been filed. This guidance expressly states that financial institutions are not required to independently review a customer or account to evaluate whether suspicious activity continues after the filing of a SAR. Financial institutions can fulfill their SAR compliance obligations by relying on their standard policies and protocols for monitoring suspicious activity, and reporting it as appropriate, provided that those internal policies are reasonably designed to identify and report suspicious activity.

    FinCEN stated in a prior guidance that financial institutions should file SARs for continuing suspicious activity after a 90-day period, with a filing deadline of 120 calendar days following the filing of a previous, related SAR. This FAQ now clarifies that financial institutions are not required to do so.

    The revised FAQs address longstanding industry concerns about ongoing reviews of customer activity after initial SAR filings. Historically, examiners have interpreted prior advisories as requiring frequent re-evaluations of previously flagged accounts on a set timetable. The new FAQs clarify that separate, post-SAR investigations need not be conducted unless dictated by risk-based internal processes or relevant facts emerge during routine monitoring. This move encourages institutions to leverage their own protocols rather than defaulting to rigid mandates, potentially allowing compliance teams greater flexibility while still meeting regulatory expectations.

        3. Timing of Reports

    If a financial institution elects to file a continuing activity SAR in accordance with FinCEN’s continuing suspicious activity guidance, they should do so within 120 calendar days of the filing of an initial SAR. This provides financial institutions a 90-day period after the filing of an initial SAR to evaluate continuing suspicious activity, and a 30-day period to file the subsequent SAR if the institution detects ongoing suspicious activity. In such a case, the institution should mark the date range of suspicious activity to include the entire 90-day period immediately following the filing of an initial or most recent SAR, on Item 30 of the SAR form. If a financial institution elects further reporting due to continued suspicion, the revised timeline allows up to 150 calendar days following detection, providing additional flexibility compared with prior practice.

        4. SAR Documentation

    FinCEN clarifies that neither the BSA nor its implementing regulations require a financial institution to document a decision not to file a SAR. Prior FinCEN guidance had encouraged financial institutions to document such a decision, but there is no requirement for them to do so. If a financial institution chooses to document the decision not to file a SAR, a short, concise statement documenting the decision, consistent with internal policies and procedures, is likely sufficient, though institutions may consider additional documentation in complex investigations.

    Documentation standards surrounding decisions not-to-file have shifted from “best practice” recommendations toward an explicitly optional stance. For many years, documenting “no-file” determinations was encouraged, and became ingrained as best practice, but this has now been reframed as optional rather than required by law. Financial institutions are advised that concise recordkeeping aligned with their risk-based policies will generally suffice; extensive narrative explanations should be reserved for especially complex matters or when warranted by specific circumstances.

    Conclusions and Practical Steps

    The recently issued FAQs clarify supervisory expectations without changing existing legal or regulatory requirements for suspicious activity reporting. They respond to feedback from financial institutions while streamlining prior guidance. By clarifying ambiguous areas and prioritizing efficiency, regulators aim to align compliance efforts with national security priorities while minimizing unnecessary operational burdens for filers. Financial institutions should monitor how this new guidance is implemented during examinations, including any changes to supervisory manuals, and proactively adjust their reporting policies as needed to leverage efficiencies without compromising vigilance against illicit finance.

    If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. Please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

    On October 9, 2025, the Financial Crimes Enforcement Network (“FinCEN”) issued a renewal of its Geographic Targeting Order (“GTOs”), which require U.S. title insurance companies, including their subsidiaries and agents, to collect, retain, and report specified information regarding certain non-financed residential real estate transactions involving legal entities. The new GTO is effective from October 10, 2025 through February 28, 2026.

    Access the new GTO here.  Read FinCEN’s press release here.  Read FinCENs FAQs about the GTOs here.  This is a topic on which we previously have blogged extensively.

    Context and Regulatory Background

    The renewal of the GTOs follows FinCEN’s September 30, 2025 announcement postponing implementation of its forthcoming Anti-Money Laundering Regulations for Residential Real Estate Transfers Rule (“RRE Rule”) until March 1, 2026. During this interim period, FinCEN states that the GTOs are intended to maintain transparency in residential real estate markets considered at higher risk for misuse by illicit actors. According to FinCEN’s accompanying press release, these orders continue to provide data on property purchases by persons who may be involved in various unlawful activities.

    Scope of Coverage

    There are no changes in geographic or monetary thresholds compared with previous orders. Covered transactions must meet all of the following criteria:

    • The property is located within designated metropolitan areas or counties that include locations such as Los Angeles County, Miami-Dade County, Cook County, King County and Seattle, New York City boroughs, and others.
    • The purchase price meets or exceeds $300,000 in most covered jurisdictions; Baltimore City and County retains a lower threshold at $50,000.
    • The buyer is a “legal entity” defined as a corporation, limited liability company, partnership or similar business structure not listed on an SEC-regulated exchange.
    • The transaction does not involve external financing from regulated financial institutions subject to Bank Secrecy Act (“BSA”) anti-money laundering obligations.
    • Payment is made using currency or cash equivalents, including checks, money orders, wire transfers and funds transfers or virtual currency.

    Reporting Requirements

    Title insurance companies handling covered transactions must file a Currency Transaction Report with FinCEN within thirty days after closing. Required data includes:

    • Identity details for both:
      • The individual primarily responsible for representing the purchasing entity;
      • Each beneficial owner holding at least twenty-five percent equity interest; and
      • Government-issued identification documents must be collected/described.
    • Confirmation that buyer qualifies under relevant “legal entity” definitions;
    • Property address(es);
    • Date(s) of closing;
    • Total purchase price(s);
    • Method(s) used for payment; and
    • Reporting party details, including notation “REGTO1025” indicating this specific GTO filing.

    When multiple properties are included in one transaction, both total purchase price and per-property addresses and prices must be reported individually.

    Record Retention & Compliance

    The Order requires retention of all relevant records, including identity documents collected, for five years from expiration date. They must be accessible promptly upon request by regulators such as FinCEN.

    Responsibility for compliance extends throughout each covered organization to officers, directors employees and agents alike; covered businesses are required to notify relevant personnel including executive management about these obligations. Noncompliance may result in civil or criminal penalties regardless of intent.

    Key Definitions

    Some important definitions under this Order include: 

    • Beneficial Owner: Any individual directly or indirectly owning twenty-five percent or more equity interests in a purchasing legal entity; and
    • Legal Entity: Includes corporations, limited liability companies, and partnerships, formed domestically or abroad; excludes those publicly listed with Securities Exchange Commission regulation.

    No Modification to Broader BSA Obligations

    This GTO supplements, but does not modify, other existing responsibilities imposed by the BSA.

    As the real estate industry awaits broader anti-money laundering regulations, compliance with FinCEN’s renewed GTOs remains essential for title insurance companies and their agents. By continuing to collect and report detailed transaction data on non-financed purchases by legal entities, FinCEN proports that these measures aim to strengthen market transparency and deter criminal abuse of residential real estate. Staying informed on these developments will be critical as regulatory expectations evolve ahead of the RRE Rule’s full implementation in 2026.

    If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. Please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.