By the time suspicious money reaches a bank account, payment platform or business, the financial crime may already be several steps old.
The original crime might have happened online.
A victim may have handed over personal information.
An account may have been compromised.
A fake identity may have been created.
A fraudulent payment may have been made.
Only then does the money enter the financial system.
That creates an important AML reality.
The transaction may be the final layer of the crime, not the beginning of it.
A recent case shows how far upstream the problem can start
In September 2026, the U.S. Department of Justice announced that a man pleaded guilty to operating an illicit online marketplace used by cybercriminals to buy, sell and trade stolen personal information and tools used to carry out cybercrime and fraud.
The marketplace generated money by providing infrastructure to other criminals.
The case is significant because the underlying criminal activity was digital, but the proceeds still had to enter the financial system somewhere.
That creates an AML question that can easily be overlooked:
What kind of crime generated this money before it reached us?
Financial crime does not always look financial at the start
A cybercriminal does not necessarily begin with a bank account.
They may begin with stolen credentials.
Or personal information.
Or access to someone else's account.
Or a fraudulent online service.
Or a network that sells tools to other criminals.
The eventual proceeds may then appear as:
A customer payment.
Business revenue.
Consulting income.
Online sales.
Investment funds.
A transfer between accounts.
An asset purchase.
Once the money has entered an apparently legitimate commercial environment, the original crime can become much harder to see.
This changes how customer behaviour should be interpreted
Suppose a customer suddenly receives payments from many unrelated individuals.
That may have a legitimate explanation.
Suppose another customer operates an online business and experiences an unexpected increase in payment volume.
That may also be legitimate.
Suppose a third customer regularly receives funds and quickly sends them to other accounts.
Again, there may be a genuine reason.
The point is not that these activities are suspicious by themselves.
The point is that fraud proceeds can enter ordinary financial channels looking like ordinary commercial activity.
This is why customer behaviour sometimes needs to be considered together with the customer's business model.
Cyber risk and AML risk are becoming harder to separate
A company can have strong cybersecurity and still face AML exposure.
A financial institution can have strong AML controls and still encounter funds generated through cybercrime.
A payment business may process a legitimate merchant whose account has later been compromised.
An accountant may encounter revenue that was generated through fraudulent online activity without knowing how it originated.
A professional adviser may see the financial consequences of a cybercrime without ever seeing the original attack.
The functions are different.
The risks can overlap.
The warning may be in the change
A customer who has always received ten payments a month suddenly receives hundreds.
A business that normally deals with companies begins receiving large numbers of individual payments.
A customer begins moving money through accounts or services that were not part of the original business model.
A new digital activity appears without a clear commercial explanation.
None of this proves financial crime.
But a significant change can be more informative than a single unusual transaction.
The question becomes:
What changed, and why?
What should businesses do with that information?
They do not need to become cybercrime investigators.
They do need to understand their own exposure.
Customer profiles should reflect the actual business model.
Expected activity should be realistic.
Material changes should be capable of triggering review.
Where relevant, transaction monitoring should consider behaviour over time rather than relying only on one large payment.
Fraud teams and AML teams should also avoid operating in completely separate worlds where the same customer or account is creating concerns for both functions.
For DNFBPs, the same thinking can apply proportionately.
If a customer is using a professional service, acquiring assets, establishing companies or moving funds in a way that suddenly changes the risk profile, the underlying reason should be understood.
There is another important point
Not every victim is a money launderer.
A compromised account can belong to an innocent customer.
A business may unknowingly receive fraudulent funds.
A customer may be manipulated into making a payment.
This is why AML analysis needs context and should not automatically treat unusual behaviour as evidence of criminal intent.
The objective is to understand what may have happened.
The original crime can be invisible
A compliance team may see only the final payment.
The bank may see the account.
The payment provider may see the transfer.
The accountant may see the revenue.
The professional adviser may see the asset purchase.
The original cybercrime may be somewhere far behind all of them.
That is why modern AML cannot look only at money.
It also needs to understand the types of crime that generate the money.
Cybercrime is one of them.
Fraud is another.
And as criminal methods evolve, the financial trail may increasingly become the last visible part of a much longer chain.
The money may be what we can see.
It may not be where the crime began.
Reference
U.S. Department of Justice, Kosovar National Pleads Guilty to Operating Cybercrime Marketplace Offering Tools and Products to Cybercriminals, 24 September 2026. Official DOJ reference
Total Views : 2
Contributor
Related Posts

A customer can appear to have a normal bank account, a legitimate business and ordinary transactions...
Read More
A business does not have to be created for crime to become part of a money-laundering scheme.A legit...
Read More
One customer may not look suspicious.One company may not look suspicious.One payment may not look su...
Read More