#FinCEN

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-19

@hisold My bank stopped issuing #girocard cards with #magstrip 10+ years ago as magstrip was phased out and #NFC was phased in as well as #PSD1 being introduced.

  • Even before that merchants rarely accepted magstrips and those who did asked for #ID as soon as purchases [i.e. fuel at a gas station) exceeded like €100 because unlike #Chip + #PIN the payment processor does not guarantee them that the payment will be accepted and the amount guaranteed.

That's the main push factor: Alongside lower processing fees and faster processing, the Chip+PIN & #NFC systems actually request a blockage of the amount and will automatically decline without incuring fees if the balance / limit is below that amount - sometimes even before the PIN has been entered (it'll just not show it until the PIN is entered so fraudsters can't just abuse this as a means to check balance.

  • There's a nice podcast with #JohnBoseak where he explains how stuff used to [and allegeldy still does] work in the #USA re: #CreditCards. Given that I worked for a #PaymentProcessor in the past this is some basic knowledge re: #security, because one needs to understand how stuff like CNP ("Card not Present") works and how the system is architected to the point that even if someone were to hack the database of said payment processor, they'd never find any CCs or the CVVs stored there at all.

It's also insightful because #fraud would be way more rampant if the card issuer, payment processor and card system operator [i.e. AMEX, VISA, MasterCard] didn't all run their own AFE [Anti-Fraud Engine] each automatically assessing risks within less than a second for every transaction.

  • That's why one can get their #CC blocked when using a #VPN and why fraudsters need the location of their victims because if I had a CC and used it regularly and someone were to try to swipe a skilled copy of that at a Walmart or Best Buy on the East Coast of the USA less than 24 hours of my last use in Germany, that would automatically get declined as fraud and the person at the cashier will call security because noone is travelling that quickly that far.

But that's just some cold OSINT based off #TechSupport and peeking behind the curtains professionally...

  • There's way more but I can't go into details on that.

Rest assured if you have a CC you can be as certain that someone tried to abuse it as I'm certain my bank blocked fraudulent money orders against my account because of AFEs working - it's just > 99% of all fraud attempts get blocked instantly and merchants rate-limited or kicked off the system when they do something suspicious.

  • Same reason why one can't frame someone for a crime by just wiring obviously illicit funds to their account: AML (Anti-Money Laundering) will catch that and unless the account holder were to ask "Where's the money/transaction?" #FinCEN et. al. won't even bother calling the account holder up simply because "oops I wired money to the wrong account. Can you please send it back?"- #scam is a well-known method to turn unsuspecting people into money launderers.

So yeah, that "#magstrip" may be just lacquer but unless it's specifically advertised otherwise only holds the CC & CVV as well as service codes [i.e. chip+pin only] to tell the terminal "Don't accept magstrip, mandate Chip+PIN"]...

  • Outside the #USA, this is the norm due to #PSD2 exceeding #PCIDSS by quite a lot!

Only underdeveloped countries like the #US still use #Magstrips and #credit and not Chip+PIN & #debit!

If the feds wanted assistance in stemming the flow of illegal crude oil & gas from outside sources, they could name the US buyers (aka consignees) that purhcase the product from the cartels. #FinCen #Treasury #law

Kevin Karhan :verified:kkarhan@infosec.space
2025-02-09

@Boehler #Protip: ruhig mal das der @BaFin bzw. #FinCEN als "Verbreitung von #Falschgeld" melden damit jene, die diese #RassistischeKackshice abziehen ernsthafte #Konsequenzen bekommen!

#WeaponizeTheSystem

Vinoth (Mobile security)vinoth@infosec.exchange
2024-12-24

Businesses all over the country are learning a day before Christmas Eve that they have until New Year's day to file ownership info to FinCEN, on the threat of severe penalties.

To be clear, there was a stay on the reporting requirements which a Federal appeals code decided to remove today.

#CTA requires most businesses, including small businesses to file information of beneficial owners to #fincen. Fair enough, I guess. But it is written so stupidly broad that it covers fricking #hoa associations. They are a hard bit of money laundering or something, I don't know. It's hard enough to get them to launder gym towels.

cbsnews.com/news/corporate-tra

2024-12-12

Big win for billionaire money launderers, tax dodgers, drug cartels, and the banks who funnel their funds into the banking system.

jdsupra.com/legalnews/transpar
#fincen #boi #pandorapapers

Ellen Timmerellent@mastodon.nl
2024-12-08

#FInCEN has now posted on its website the following statement concerning the Texas federal court preliminary injunction:  fincen.gov/boi

Alert: Impact of Ongoing Litigation – Deadline Stay – Voluntary Submission Only
In light of a recent federal court order, reporting companies are not currently required to file beneficial ownership information with FinCEN (...)

linkedin.com/posts/kmatzlaw_fi

2024-12-06

Что такое AML, как очистить или купить чистую криптовалюту

Приватный кошелёк-миксер Wasabi Wallet AML (Anti-Money Laundering) — относительно новая часть регуляций KYC , которые разрослись с принятием USA PATRIOT Act после теракта 9/11. Как обычно, власти используют теракты для закручивания гаек и ущемления прав граждан на десятилетия вперёд (если не навсегда). Все уже забыли, зачем это вводилось, и начали раздеваться разуваться перед входом в самолёт, как будто так положено. Если вкратце, AML — набор мер для предотвращение отмывания денег, финансирования терроризма и другой незаконной деятельности. Изначально термин появился в банковской среде, но позже перекочевал в крипту. В криптоиндустрии AML встретили в штыки , потому что это явная угроза приватности. В современном цифровом мире приватность — синоним безопасности. У нас тут в интернете никаких терактов не было, к чему ваши банковские извращения? Предъявлять паспорт при покупке крипты, что дальше — бензин по паспорту?

habr.com/ru/articles/864050/

#KYC #AML #BTC #биткоин #Aifory #криптовалютный_кошелек #Chainalysis #CipherTrace #Elliptic #миксеры #приватность #коинджоин #Wasabi_Wallet #UTXO #FATF #FinCEN

2024-12-04
Andrew 🌻 Brandt 🐇threatresearch@infosec.exchange
2024-11-27

If you own or are part of a board of directors of a business of any size in the US, new regulatory filings are coming in to effect. By the end of the year you have to file what's called a "Beneficial Ownership Information Report" or #BOI / #BOIR with the US government agency, #FINCEN.

Filing the report costs nothing if you do it yourself, but there are pretty severe financial penalties for not doing it.

I've been getting notifications about it for about 48 hours that the deadline is fast approaching, and the #phishing #scammers are already jumping on this bandwagon.

This morning I got an email from the website boifilings[dot]co. The website and email claims to come from the "U.S Business Compliance Commission" which is...not a government agency, but a private company.

They do absolutely no validation on any information in the form they link to, other than the credit card number you enter to pay the $250 (!) they're asking you to pay for what is a free service.

Oh yeah, and they list a street address in their contact information, but a Google Street View of that address shows that it's the disused back door of a windowless warehouse or storage shed. You might call it the Four Seasons Total Landscaping of government agencies.

This may not be criminal, but it's still shady AF.

FINCEN has a FAQ about the process here: fincen.gov/boi-faqs

To sum up:

☑️ Named intentionally to sound like a government agency
☑️ Uses a logo on its email and webpage that makes it look like a US government agency
☑️ Wants to charge money for a service that is otherwise free
☑️ Does a terrible job at doing the service they are charging for
☑️ Business address corresponds to an unmarked, windowless storage warehouse back door
☑️ No guarantee that they won't just take the money and run

BOIR form from scam website points to address that is a warehouse in Boise, IDBOIR form asks for $250 to file something that is otherwise free to file, and does no validation on any of the form inputEmail from "US Business Compliance Commission" with official looking government-esque logo. It's all bullshit, all the way down.Google Street View of the headquarters of the "US Business Compliance Commission"
⚯ Michel de Cryptadamus ⚯cryptadamist@universeodon.com
2024-10-14

Just in case you were wondering why yes, there is a #crypto angle to the massive #TDBank money laundering scandal.

Turns out a big chunk of the fines levied by #FinCen for the massive drug money laundering facilitated by TD Bank was because "over $420 million [sent] to a financial institution offering cryptocurrency services in the high-risk jurisdiction of #Colombia."

Curious if anyone has any guesses as to what crypto company that is or was.

edit: my current guess is that the crypto company is #Kado, a Colombian company that trades crypto for cash and prepaid debit cards and uses #FortressTrust (FKA #PrimeTrust, a #Nevada company long rumoured to be connected to the italian mafia), to do (probably fake) KYC/AML.

#drugcartels #stockmarket #banking #banks #finance #moneylaundering #uspol #canada #canadapol #canadianpolitics #cryptocurrency #bitcoin #BTC #USDT #USD #crime #cartels #drugcartels #organizedCrime

from an international cryptocurrency exchange platform. where the purpose. ultimate originators, and source of funds were unknown to TD Bank. Despite this high volume of funds from unknown sources, TD Bank continued to ocess transactions for Customer Gmufi C. including the facilitation of over $420 million to a financial institution offering cryptocurrency services in the high-risk jurisdiction of Colombia. TD Bank Emcess:d these transactions on behalf of Customer G-ronfi C. due in part to a lack of clear controls applicable to customers dealing in cryptocurrency: the limited high- level written policies the Bank had in place relating to virtual assets alluded to the requirements for certain additional controls and monitoring. However. there is no evidence any enhanced controls were ever applied to Customer Group C’s extensive transactions with virtual asset service providers.

Despite the high volume of suspicious transactions and “red flags™ associated with high-risk jurisdictions and rapid movement of funds within a short timeframe. TD Bank failed to proactively report this suspicious activity until it received multiple law enforcement inquiries about Customer Group C. Furthermore. four months after Customer Group C was onboarded by the Bank. a financial regulator ordered an affiliate of Customer Group C to cease its operations. and its assets were ordered to be liquidated for the benefit of investors. TD Bank failed to conduct appropriate due diligence
⚯ Michel de Cryptadamus ⚯cryptadamist@universeodon.com
2024-10-14

"Extraordinary. Tether is in talks with commodity trading shops to help finance their trades, claiming they can offer a lower cost of capital and also be useful in trades involving sanctioned entities." - Joe Wiesenthal

Sanctioned entities means companies in countries like #Russia, #Iran, and #NorthKorea. Tether already has been proven to enable sanctions evasion in the first two of those and money laundering by the third.

Remember that if #Trump wins #Tether will get to hand pick who runs FinCen, the OCC, the FBI, the DOJ, and the Defense Dept. of the United States because the guy who manages Tether's money is the chairman of the Trump transition team (#HowardLutnick).

* BBG: bloomberg.com/news/articles/20
* archive: archive.ph/0zLde
* more on Lutnick/Tether/Trump connection: universeodon.com/@cryptadamist

#sanctions #fincen #OCC #FBI #uspol #election2024 #2024election #uspolitics #Maga #Magats #ukraine #ukrainewar #CantorFitzgerald #USDT #crypto #cryptocurrency #Tether

Crypto Company Tether Talking to Commodity Traders About Lending Them Its Billions
Commodity traders rely on credit lines to finance shipments
Tether CEO says any commodities work ‘in early stages’
⚯ Michel de Cryptadamus ⚯cryptadamist@universeodon.com
2024-10-12

"This is the #police chief of a town that straddles a major highway in and out of #Nashville completely lost to #QAnon obsession and #insanity. These guys have been using federal databases to investigate political campaigns and private citizens. The city council completely supports them and is doing nothing to stop them because they are down the insanity rabbit hole. We are in a very very dangerous place because these guys are not alone. Not even remotely." - Fred Wellman

newschannel5.com/news/newschan

#uspol #uspolitics #tennessee #cops #copaganda #magats #maga #conspiracycop #conspiracytheories #conspiracytheory #conspiracy #cops #FinCen #ShawnTaylor

'We already have the receipts.' Election denier says his group gained access to U.S. banking data
Arizona's Mark Finchem says Millersville, Tennessee's assistant police chief, Shawn Taylor, used Treasury Department's FinCen data in work for Finchem's Election Fairness Institute
⚯ Michel de Cryptadamus ⚯cryptadamist@universeodon.com
2024-09-26

@briankrebs i see Garantex (the favored #Moscow based #crypto exchange for ransomware gangs looking to cash out) and #Bitzlato (obscure exchange used by darknet market Hydra to launder money that was seized by the US govt early 2023) in the #FinCen order: fincen.gov/sites/default/files

(unsurprising but worth noting)

WSJ on #Garantex: wsj.com/finance/currencies/gar

Ellen Timmerellent@mastodon.nl
2024-09-22

US:
#FinCEN Adopts Reporting Requirement for Non-Financed Residential Real Estate Transfers | Goodwin - JDSupra #AML #CFT

jdsupra.com/legalnews/fincen-a

Ellen Timmerellent@mastodon.nl
2024-08-21

@ACAVoice has submitted comments on the #FinCEN proposed rule to strengthen and modernize financial institution #AML / #CFT Programs. Read more: americansabroad.org/aca_submit

#expats #AmericansAbroad #FinCEN #taxation #FATCA

⚯ Michel de Cryptadamus ⚯cryptadamist@universeodon.com
2024-08-19

Some extracts from my pinned toot concerning the ways in which #Uniswap is a particularly diabolical means of capital extraction devised by #TheNerdReich bros of #a16z, #SequoiaCapital, and the rest (and their obscenely well paid and equally obscenely dishonest lawyers) and how the capital being extracted is currently being funneled into the 2024 election.

(The specifics of the electoral corruption are better documented by @molly0xfff; this is more an in depth explainer of the mechanics of one of The Nerd Reich's more effective grifts.)

#MarcAndreessen #SequoiaCapital #BenHorowitz #crypto #COIN #Cryptocurrency #AndreessenHorowitz #ethereum #Sunswap #SwftSwap #LazarusGroup #moneylaundering #FinReg #FinCEN #sanctions #CryptoLobby #USpol #USpolitics #Republicans #politics #CraftVentures #GOP #TheNerdReich

⚯ Michel de Cryptadamus ⚯cryptadamist@universeodon.com
2024-08-16

#TheCryptocalypseChronicles: Of Tech Bros And Trumpers

The reason so many Silicon Valley billionaires suddenly decided to back #DonaldTrump is not the mystery the media is making it out to be.

tl;dr The billionaires backing #Trump are crypto bros and they want to continue profiting from committing various kinds of crimes.

This is a "follow the money" deep dive into how some of these bros profit by investing in companies like #Uniswap that create excellent tools for #NorthKorea to launder stolen money with a passing explanation of how #Coinbase facilitates the overall system.

Ω👇Ω
cryptadamus.substack.com/p/of-

#a16z #MarcAndreessen #SequoiaCapital #BenHorowitz #crypto #COIN #Cryptocurrency #AndreessenHorowitz #ethereum #Sunswap #SwftSwap #LazarusGroup #moneylaundering #FinReg #FinCEN #sanctions #CryptoLobby #USpol #USpolitics #Republicans #politics #CraftVentures #GOP #TheNerdReich

2024-05-28

#fincen #automobile #dealership (thread) 1/ Today I went to a dealership to buy a used car. We shook on a price, agreed that I would pay with a cashiers check, filled out paperwork and the whole deal. EXCEPT at the very end they wanted a copy of my driver's license.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst