FIU [IMN] ¦ FIU Monthly Typologies 2026

FIU [IMN] ¦ FIU Monthly Typologies 2026

From false representation to crypto obfuscation: financial crime typologies for 2026

Financial crime rarely presents as a single, isolated transaction. Fraud, corruption, sanctions evasion, terrorist financing and money laundering can overlap across accounts, corporate structures, digital platforms and jurisdictions. The most useful warning signs often appear when a customer’s stated circumstances do not align with transaction behaviour, ownership information or independent research.

Recent typologies illustrate how predicate offences generate proceeds, how those proceeds are moved or concealed, and how apparently ordinary activity can reveal a wider financial crime pattern.

Fraud by false representation and account compromise

A customer’s compromised banking application can provide a direct route from social engineering to money laundering. In one example, a fraudster posed as a bank employee and used knowledge of the customer’s previous transactions to create credibility. The customer was persuaded to approve a one-time passcode, believing it was required for an identity check. The fraudster then used access to the banking application to send a substantial payment to a third party.

The predicate offence was fraud by false representation. The false statement was the fraudster’s claim to be acting for the bank, combined with the misleading explanation for requesting the authentication code. The immediate financial loss was suffered by the customer, but the receiving account may represent the first stage of laundering. Funds obtained through fraud can be rapidly transferred onward, converted into virtual assets, withdrawn in cash or combined with legitimate funds.

The payment was particularly suspicious because it was significantly larger than the customer’s normal activity. Login data also showed access from another jurisdiction, corresponding with the destination account. Such evidence can help establish a connection between the compromised account, the fraudster and the movement of criminal property.

Banks should give weight to sudden changes in device identifiers, login locations and transaction patterns. A payment may appear authorised from a technical perspective, but that does not mean it was genuinely authorised by the customer. The circumstances in which an authentication factor was obtained remain critical.

Bastian Schwind-Wagner
Bastian Schwind-Wagner

"Financial crime risks increasingly emerge through connected patterns rather than isolated transactions. Fraud, corruption, sanctions evasion, terrorist financing and money laundering may intersect across bank accounts, corporate structures, fundraising platforms and virtual asset wallets.

Effective detection depends on linking the predicate offence to the movement and concealment of criminal property. Unexplained wealth, inconsistent customer information, manipulated documents, rapid transfers and opaque ownership structures should be assessed together and reported where they create a reasonable suspicion."

Corruption proceeds concealed through corporate and trust structures

Trust or Company Service Providers (TCSPs) face a different risk: the laundering of corruption proceeds through apparently legitimate ownership arrangements. A proposed relationship involving a company and a UK property raised concerns when the incoming service provider received limited explanations for the termination of the previous relationship and inadequate information about the source of wealth supporting the trust structure.

The trust had reportedly been settled using an interest-free loan from the settlor’s father. The father’s wealth was linked to a construction company holding a substantial government contract. Open-source research identified him as a commercially exposed person and connected him socially with a politician associated with international corruption. The contract had reportedly been awarded directly by that politician.

The suspected predicate offence was bribery of a foreign public official. The potential laundering mechanism involved the acquisition and holding of assets through a trust and corporate vehicle, creating distance between the alleged corrupt conduct and the property. The use of a loan rather than a straightforward gift or transfer may also make the funding appear commercially explainable while obscuring the true economic origin of the assets.

Source of funds and source of wealth enquiries must therefore examine more than whether documents have been supplied. The quality, completeness and consistency of the explanation matter. A customer or intermediary who avoids questions about a previous service provider, refuses to identify the origin of family wealth or provides only superficial evidence may be attempting to prevent scrutiny of criminal property.

A commercially exposed person is not automatically involved in corruption. However, public-sector contracts, unexplained wealth, close relationships with politically connected individuals and opaque ownership arrangements should be assessed together rather than in isolation.

Synthetic identities and the use of manipulated documents

Synthetic identity fraud combines genuine personal information with fabricated or digitally altered identity elements. This can allow a person who does not exist in the claimed form to pass onboarding controls and establish an account or investment product.

A life insurance application appeared credible because the applicants provided certified identity documents, proof of address and information about wealth and funds. The premium was paid from an account held in the applicants’ names. The risk became apparent when they sought to surrender the policy within two years, despite substantial charges and an expected loss.

Early surrender is not necessarily suspicious. It becomes more significant when the customer is unconcerned about a predictable financial penalty and the behaviour is accompanied by weaknesses in identity verification. Re-verification identified irregularities in fonts, spacing and formatting, together with signs of digital manipulation in identity photographs. Similar defects appeared across several documents, suggesting a coordinated process rather than an isolated clerical error.

The applicants also had little verifiable presence in reliable public or proprietary sources. The combination of plausible addresses and personal data with manipulated identity features suggested that the identities had been assembled to defeat customer due diligence.

The underlying predicate offence may not be immediately identifiable. The suspected conduct can nevertheless amount to money laundering where a synthetic identity is used to introduce, hold or withdraw criminal proceeds. It may also support further fraud, including fraudulent applications for financial products.

Firms should retain copies of the documents reviewed, record the specific anomalies identified and avoid relying solely on automated document verification. Generative and image-editing tools can produce convincing material, making inconsistencies across related documents and the absence of independent corroboration especially important.

Sanctions evasion through property acquisition

Sanctions evasion often depends on concealment rather than direct contact between a sanctioned person and a restricted transaction. A proposed high-value property acquisition involved a company whose beneficial owner was a national of a high-risk jurisdiction. The stated purpose was to provide occasional accommodation, but property records showed that the individual had recently acquired several nearby residential properties through different companies.

The customer’s known income did not appear sufficient to support the acquisitions. Further research identified a close business relationship with a senior government official who had been sanctioned over national security concerns. The suspected arrangement was that the beneficial owner would act as a professional enabler, acquiring property for the sanctioned individual or helping him retain control while avoiding direct exposure.

The relevant predicate or associated offence was sanctions evasion. The property and corporate vehicles could also become instruments for laundering funds if the acquisition proceeds originated from corruption, state-linked misconduct or another criminal source.

The stated purpose of a transaction should be tested against the asset acquired, the customer’s wider holdings and the economic rationale for the structure. Multiple companies are not inherently suspicious, but they can obscure beneficial ownership and make it more difficult to identify whether a sanctioned person retains control or benefit.

Sanctions screening should therefore extend beyond exact-name matching. Ownership, control, close associates, shared directorships, property holdings and adverse media may all be relevant to understanding the risk.

Cyber-enabled fraud followed by terrorist financing

Online marketplace fraud can generate a large number of apparently ordinary payments. A construction worker’s personal account received numerous low-value credits from unrelated individuals, with payment references suggesting purchases of mobile phones and other goods. The account holder claimed to have started selling items online and supplied screenshots of customer orders.

Subsequent reports from several customers indicated that goods had not been delivered. The screenshots showed multiple seller profiles, repeated product images, inconsistent order information and contact details that could not be verified. The proceeds were then rapidly sent to third-party accounts and an overseas virtual asset service provider (VASP).

The predicate offence was cyber-enabled fraud. The laundering indicators included the use of multiple seller identities, rapid dispersal of funds and conversion or transfer through a virtual asset intermediary. The risk escalated when some funds were used for flights, accommodation and electronic equipment, and when one recipient was linked through open-source information to online support for a terrorist organisation.

This pattern also raised terrorist financing concerns. Unlike money laundering, terrorist financing does not require the funds to originate from a criminal offence. Legitimate or low-value proceeds can be used to support terrorist travel, communications, equipment or living expenses. The suspected fraud proceeds therefore represented both criminal property and a possible source of terrorist financing.

Payment volume should not be the only focus. A large number of low-value transactions may be highly significant when combined with repeated advertising content, unverified seller details, customer complaints and rapid movement to unrelated accounts or overseas VASPs.

Fraudulently obtained credit and fundraising channels

Credit fraud can also function as a source of terrorist financing. A customer applied for a loan using payslips that appeared to support his stated employment. After the loan was credited, most of the funds were divided into smaller payments sent to a third party and several online fundraising appeals. The customer failed to make the first repayment.

The initial predicate offence was suspected fraud by misrepresentation in obtaining credit. The subsequent transactions suggested layering through fundraising channels. The different appeals used common contact and beneficiary information, and the person promoting them was connected to an overseas charity whose members had reportedly provided support to a terrorist organisation.

The transaction structure was important. Dividing a loan into smaller payments can make the movement of funds less conspicuous, while the use of humanitarian language can provide a legitimate-looking explanation. A customer’s early default, inconsistent employment information and unexplained onward payments should prompt a review of both the loan application and the destination of the funds.

Terrorist financing indicators should be assessed carefully and objectively. A connection to a higher-risk jurisdiction or a charity is not conclusive on its own. The concern arises from the combined evidence, including common control of fundraising appeals, unexplained financial flows, adverse information and the customer’s apparent inability or unwillingness to repay.

Virtual assets and unexplained source of wealth

Virtual assets present particular challenges for source of funds and source of wealth assessments. A prospective investor claimed to have generated substantial wealth by acquiring Bitcoin during the retail investment boom. The funds were held in a self-hosted wallet and were intended to be converted into fiat before investment.

The firm verified that the customer could cause a small amount of cryptocurrency to be returned to a specified address, commonly referred to as a Satoshi test. This provided some evidence of control, although the customer completed the test only shortly before the deadline. Control of a wallet, however, does not establish the lawful origin of its assets.

The customer could not provide transaction records showing the original purchase of Bitcoin or the subsequent trading gains. Blockchain analysis showed little historical trading activity, while the wallet had received substantial credits from other addresses. Those addresses had interacted with cryptocurrency mixers, which are designed to make tracing the source and destination of assets more difficult.

The predicate offence was unknown, but the risk of money laundering was substantial. The claimed wealth did not match the available transaction history, the source of incoming funds was unexplained and mixer exposure obstructed transparency. The wallet’s apparent control could not resolve those concerns.

A credible virtual asset source-of-wealth explanation should address how the assets were acquired, where they were held, what trading or investment activity generated the claimed gains and how the customer can evidence each stage. Wallet ownership tests are useful but limited. They should be treated as one control within a broader assessment, not as proof that the assets are legitimate.

Connecting the predicate offence to the laundering method

Across these scenarios, the central compliance question is not simply whether a transaction is unusual. It is whether the regulated business can identify a credible explanation for the customer’s wealth, funds, ownership and behaviour, and whether that explanation is consistent with independent evidence.

The predicate offence may be clear, as in false representation, fraudulent credit applications or online marketplace fraud. In other cases, such as the virtual asset example, the precise offence may remain unknown. Suspicion of money laundering does not depend on proving the underlying offence to a criminal standard. Material inconsistencies, concealment, unexplained wealth and the movement of funds through opaque channels may be sufficient to support a suspicious activity report (SAR).

Effective analysis should connect four elements:

  1. the origin of the funds,
  2. the behaviour that generated them,
  3. the method used to move or conceal them and
  4. the persons who ultimately benefit.

This approach helps distinguish a genuine unusual transaction from a broader financial crime pattern.

Reporting and investigative value

A suspicious activity report should explain the facts that generated the suspicion, the suspected predicate offence where known, the laundering or terrorist financing mechanism and the relevant parties, accounts, wallets and jurisdictions. Clear chronology is particularly valuable. The report should show when the relationship began, when the unusual activity occurred, what checks were completed and how the customer responded.

Where digital evidence is relevant, firms should preserve transaction records, login data, device information, blockchain analysis, communications, advertisements and document-verification results. Open-source findings should be recorded with their source, date and relevance.

The strongest cases often emerge from the combination of modest indicators. An unexplained IP change, a payment to a third party, an evasive response or a wallet linked to a mixer may be inconclusive alone. Together, they can reveal fraud proceeds, corruption assets, sanctions evasion or terrorist financing. Financial crime controls are most effective when they examine the full chain rather than treating each transaction as a separate event.

The information in this article is of a general nature and is provided for informational purposes only. If you need legal advice for your individual situation, you should seek the advice of a qualified lawyer.
Did you find any mistakes? Would you like to provide feedback? If so, please contact us!
Dive deeper
  • FIU [Isle o Man] ¦ Documents & Reports, FIU Monthly Typologies 2026, August 2026 ¦ Link
Bastian Schwind-Wagner
Bastian Schwind-Wagner Bastian is a recognized expert in anti-money laundering (AML), countering the financing of terrorism (CFT), compliance, data protection, risk management, and whistleblowing. He has worked for fund management companies for more than 24 years, where he has held senior positions in these areas.