In this week's episode of This Week in AML, John Byrne is joined by Joe McNamara, filling in for Elliot Berman, to flag a wide range of global and domestic developments. They open with OCCRP reporting on an Uzbek security official who secretly acquired Emirati citizenship and millions in Dubai real estate, then turn to New York Times reporting on conflict of interest questions in U.S.-Russia talks on Ukraine.
The conversation then shifts to FinCEN's unusual withdrawal of two proposed rules targeting unhosted wallet transactions and convertible virtual currency mixing, and what that means for institutions with crypto exposure whose SAR obligations remain unchanged. Additional topics include the Comptroller of the Currency's fraud roundtable with community bankers in Minneapolis, the Department of Justice's new memorandum on corporate fraud enforcement, and the first reported AI agent-powered intrusion into major South Korean banks. The episode closes with a preview of the October 22nd webinar on best practices in managing high-risk customers.
Resources Referenced in This Episode
Fraud Is Fraud - FinCEN Withdrawals, DOJ Enforcement Factors, and AI Bank Breaches - Transcript
Joe McNamara: Hey John, how are you doing this week?
John Byrne: I'm good, Joe. Good to see you. Our buddy Elliot is taking a break for a little bit, so once again you're filling in, and I really appreciate it when you do this. No doubt about it, I really appreciate your time. There's a lot of stuff going on. We're not diving deep into anything today, but I think it's a good week to flag a bunch of items, both globally and domestically. As always, whenever we mention these items, we're assuming that folks will read the specific reports or articles that we reference.
Joe McNamara: Absolutely. And just as a producer's note, we'll make all of the source material available. If you're listening to this, go to the website and check it out. We'll have all of the source material linked to the posting on the website. But John, like you mentioned, there's a ton we want to cover. Where do you want to start?
John Byrne: Good question. As we do most of the time, we're recording this in the middle of the week, and something just jumped out on my feed from our friends at OCCRP. These investigative journalists do tremendous work, and if you're not already subscribed to their updates, they're free, so you should do that. This one, again related to corruption, is worth referencing. The Uzbek president's son-in-law secretly acquired a UAE passport while serving as a top security chief.
Why does that matter? According to the reporting, leaked records show that the son-in-law was able to acquire Emirati citizenship, which in Uzbekistan is an explicit legal breach of his position at that time. He was the deputy head of presidential security. So what happened next? He went on to obtain millions in luxury Dubai real estate. Just for context, Uzbek officials are not required to disclose their income declarations to the public, so this Dubai real estate portfolio represents the first luxury assets that reporters have confirmed this individual holds in his own name. After he got that dual citizenship, he also became a top Uzbek Olympic official, and he was able to acquire thirteen luxury Dubai apartments valued at around seven million dollars.
So again, corruption globally, corruption domestically, you name it, it's going on, and we have to figure out ways to report and address it. Staying with that theme, The New York Times had an exclusive report earlier this week saying that U.S.-Russia talks on Ukraine now involve an oil deal tied to Jared Kushner and Steve Witkoff, which, according to the Times, raises questions about various conflicts of interest. Read the article on your own, it goes into detail. Kushner and Witkoff claim they have no connection, but it does present some issues relating to conflicts. According to the story, there's no indication that Kushner and Witkoff themselves stand to profit, but they are involved with some of these organizations. This is just another example where, when there's foreign policy and diplomacy, I think most of us believe there shouldn't be a financial connection. Any general thoughts, Joe, not about this particular case, but in terms of trying to identify corruption?
Joe McNamara: I appreciate it. In reality, John, I think there's unfortunately a correlation between the first story and the second one. If it looks like a duck and quacks like a duck, it's most likely not a goose. What I would advise folks is to do your homework. Open your eyes and realize that these things are happening right in front of us, and quite frankly, they should be concerning. Regardless of who the subjects of scrutiny are, at the end of the day, fraud is fraud. I think that's probably where I'll leave that.
John Byrne: I think that makes a lot of sense. And again, as we tell everybody, we urge you to read these stories on your own. Another thing that came up, which we talked about before recording, was a FinCEN announcement earlier this week withdrawing a regulation. This is pretty unusual. Usually when they go through a notice and comment process, they take the comments and make adjustments before the final rule. I can't remember the last time something like this happened, but FinCEN is actually withdrawing the following proposed rules because they believe they place regulatory requirements on financial institutions that are too burdensome.
The first was a proposal that would have imposed recordkeeping and reporting requirements on certain transactions involving convertible virtual currencies and unhosted wallets. The second was a proposal that would have imposed a special measure with regard to convertible virtual currency mixers. On the special measures, since it's been 25 years since the Patriot Act, that's the provision they're talking about, Section 311 of the Patriot Act. Both of these were withdrawn, and we'll send you the links in the show notes, as it were. This is a pretty dramatic change, and I know it's an area you're pretty involved in.
Joe McNamara: Yeah.
John Byrne: I'll just read this one section and get your thoughts. They're withdrawing the finding that international CVC mixing is a class of transactions of what they call primary money laundering concern. That's from the 311. And the proposed rule that was published during the Biden administration, seeking to impose special measures regarding mixing, is withdrawn. Then they go on to say that while FinCEN maintains that illicit actors continue to use mixers and other tools and methods to hinder law enforcement investigations, this withdrawal is informed by concerns from commenters that the expansive definition of CVC mixing in the rule could have, quote, "a chilling effect on legitimate activity and place a large reporting burden on covered financial institutions," unquote. I know this is a space you're familiar with. Any thoughts on this withdrawal?
Joe McNamara: I'm going to do my best to balance my thoughts, because I can see things, at least at the thirty-thousand-foot level, from both sides, and I think we saw both of those laid out. First, when we look at what this rule was proposed to be, quite frankly, it was probably one of the most aggressive tools Treasury had to point at crypto privacy. To see that rolled back can be disappointing, because we haven't seen anything replace it, at least up until now.
I think the obligation behind the rule still matters, as it always has. Mixer exposure, and crypto exposure overall, is still a big red flag, especially as it relates to reporting, whether you're filing SARs or taking into account the risk-based approach methodology that has really been hammered home in this past cycle. When you look at the risks posed by things like CVC mixers, it's hard to come to any conclusion other than high risk.
That being said, I can also see it from the commenters' side, and I don't disagree. At the end of the day, it's one thing to identify the risk, and a completely different thing to figure out a systemic way to actually report on it. If there were challenges identified, and I think they were legitimate challenges, such as "now we've got to split this out and it creates four new workflows instead of one, when we're already inundated from a traditional sense," it's never going to work. So for anybody listening who cares what this humble marketing guy thinks, I think it's worth at least revisiting the conversation and trying to come up with a more streamlined approach. One that splits the difference between addressing the risks associated with activity that FinCEN has essentially classified as having a high likelihood of money laundering, while also asking how we can actually get ahead of this. How can we bring the tools and solutions we have to bear in a meaningful way that allows folks to stay ahead of the game?
Ultimately, the biggest disappointment for me is not so much that it got taken off the table. It's that we haven't seen anything that's going to replace it in any meaningful way.
John Byrne: I should add that part of the FinCEN posting also says the following regarding continued attention in this space, and I'm quoting: "FinCEN will continue to monitor activity involving CVC mixers for indicia of money laundering, terrorist financing, and other illicit finance activities, and may take appropriate steps in the future to mitigate any such activity," unquote.
To your point, you can certainly argue there's valid context for the withdrawal because of what the commenters said. But what usually happens is they resubmit the proposal and say, if it's not going to work the way we crafted it, what are some recommendations to make it more reasonable, more practical, if you will. I have not read the entire withdrawal, so perhaps that's in there as well. But you always want to know that regulators are actively considering the comment process, and that's clearly what they did here. And if they're going to continue to monitor, for those of us who care about the law enforcement aspects of this, I think that's a good message going forward.
Joe McNamara: The last thing I would add, because I agree wholeheartedly, John, is that just because this proposed rule was withdrawn, and again, it's better to have a foot in the door than to try to reopen it, that doesn't necessarily change your reporting obligations. Especially if you're a VASP, or a bank with crypto exposure, your SAR obligations aren't going to change. If anything, it's a call to action. If you haven't already, take steps to make sure your typologies and what you're doing within your program actively reflect those risks as they relate to that customer base and those characteristics.
John Byrne: Turning to fraud issues in the States, there was a meeting held yesterday, prior to our recording this on Wednesday, where Comptroller of the Currency Jonathan Gould put together a panel of community bankers in Minneapolis. This administration has been tunnel-focused on fraud in Minnesota versus other types of fraud, in my opinion. But in any event, there's no question there have been fraud issues in Minnesota. Both sides of the aisle have pointed to that and the need for a better approach.
The Comptroller met with community banks to discuss the recent financial fraud and the role of banks in identifying and combating fraud. Quoting from his posting: "Billions of dollars intended for hungry children, housing for disabled seniors, and services for children with special needs were diverted to people who cheated the system, some of whom were not even American citizens. The OCC is committed to supporting community banks in the fight against fraud and participating in the whole-of-government effort to stop those who seek to exploit the system and prey on American families and taxpayers," unquote. Hopefully the focus on hungry children and disabled seniors goes beyond this one area. We'll leave that there.
They also released some fraud facts from the FTC: over 15,000 total fraud reports for 2026, a total loss of $86.5 billion, and a median loss of $288. There are related links in the posting, including the remarks from the Comptroller, the press briefing, and FinCEN guidance on reporting in this space. I just wanted to highlight that as a recent area of focus from the Comptroller.
Related to that, the Department of Justice issued a new memorandum on October 1st regarding corporate enforcement of fraud-related issues. This covers how they make decisions about going after corporations, and the memo lays out a whole host of areas they'll consider. There are 10 factors that Fraud Division personnel, quote, "must place great weight on in determining whether to bring charges or negotiate pleas or other agreements," unquote. Just referencing a few here: knowledge of or involvement in a fraud scheme by corporate management; conduct that furthers the scheme lasting three years or more, which, frankly, is an interesting factor; actions that threaten the safety and security of Americans, including military readiness; conduct that causes financial hardship to taxpayer-funded programs or government functions. Here's another interesting one: conduct that affects three or more federal districts. So I guess a corporation operating in fewer than three districts wouldn't be included here. Conduct that results in financial harm to 25 or more victims, or $25 million or more in loss. And the last one, of course, is conduct that involves immigration offenses. Take a look at the memo. It's posted on the DOJ website, and it lays out how they plan to enforce corporate fraud going forward.
Joe McNamara: You know, John, it's kind of full circle when we come back to where we started. Fraud is fraud is fraud. There are some very interesting characteristic qualifiers in there for sure, so I would echo those sentiments. And since this is audio only, I do need to give you a shout-out. You read that with a really straight face, so I applaud you for that.
John Byrne: Well, sometimes I do.
Joe McNamara: Yeah.
John Byrne: I also wanted to pull from another great source. The Wall Street Journal obviously does excellent reporting, but they also have the Risk & Compliance Journal and a Morning Risk Report. I wanted to reference something from this week's risk report that I had not seen elsewhere. Hackers used a Chinese AI agent to attack South Korea's biggest banks and stole the personal information of 68,000 people, officials said, marking what they described as the first such AI-powered intrusion into the global financial system.
Investigators in Seoul said the attacks hit at least seven financial firms and showed traces of a cybersecurity tool called ARTEX AI, developed in China, according to the National Police Agency's Cyber Terror Response Unit. The attacks are the latest to highlight the vulnerability of even hardened targets to hackers using freely available AI tools. In previous cases, government and non-financial corporations were hit, but they reported that it's unusual for banks to fall victim to hackers assisted by AI agents. Further analysis of that hack is available in the Wall Street Journal's Risk & Compliance Journal, which is a great supplement to the Journal in general and often focuses on our space: risk and compliance issues in the financial sector and adjacent industries.
Joe McNamara: In terms of dockets, that's what I had on my end. I would just add the usual shameless plug. We've spoken a lot about high-risk customers today, or at least high-risk situations, so I'd be remiss if I didn't remind folks that you're hosting this month's webinar panel on best practices in managing your high-risk customers. John, tell folks where they can find you on October 22nd at 1:00 PM Eastern.
John Byrne: Yes, this one will be on October 22nd, as you mentioned. Because of scheduling conflicts, we're actually going to record it a couple of days in advance, so it won't be live. That won't matter from a content standpoint, but it does affect questions. If you have any questions you'd like our panelists to address about how to bank high-risk customers, send them to Joe, to me, or to Elliot Berman, and we'll be happy to include them when we record in a couple of weeks.
Another aspect of this panel is that we've added a representative from the Charity & Security Network. We want them to talk about some of the challenges they've had getting support for humanitarian causes, given that in some cases, incorrectly in my view, nonprofits are considered high risk by financial institutions. They have to address that challenge, either by making clear that they're not high risk, or by having a more open conversation with the institution to explain the NPO's or NGO's due diligence processes. We wanted to add that to the broader conversation about who's high risk, how you bank them, and what challenges and recommendations our expert panel will have.
Joe McNamara: Sounds like a good wrap-up. For anybody looking to submit questions, you can send them directly to webinars@amlrightsource.com. Like John mentioned, he, Elliot, and I are always monitoring that inbox, so we're looking forward to it. John, anything else on your side?
John Byrne: Not at this point. I mentioned last week that I did a separate podcast for Marquette University on AI ethics, and that's still available, so it's out there if you want to listen. It's definitely relevant to the issues we cover in the technology space that touch on national security and financial crime. And we continue to look for people who want to be interviewed, so reach out to us. If you have a topic or recommendation you'd like us to follow up on for our AML Conversations series, we'd be more than happy to do that.
Joe McNamara: Well, I think that's it for this week, John. Obviously there's a lot going on. For everybody out there, keep your eyes open, keep reading, keep looking at the source material we've got for you, and keep showing up. We really appreciate you listening to us every week, and we can definitely see that on the numbers side. Tell your friends, tell your neighbors, tell your dogs. We're very inclusive over here. Turn us on and give us a listen.
John Byrne: Thanks, Joe. Stay safe. Talk soon.
Joe McNamara: You too, John. Bye-bye.