caso de fraude A7
Analysis

The limits of document-based AML controls: a real money laundering case

A network of more than 100 shell companies moved at least $6.9 billion through international banks between late 2024 and August 2025, according to a Financial Times investigation based on leaked records.

The network, linked to A7, a Russian payment platform, used forged invoices and documents designed to make transactions look legitimate during banks’ compliance checks.

Data pointReported figure
Volume traced by the Financial Times$6.9 bn (late 2024 – August 2025)
Shell companies identifiedMore than 100 (Hong Kong, UAE, Kyrgyzstan, Indonesia, United Kingdom, Hungary)
Additional payments documentedMore than 17,500
Destination of many transactionsAccounts in China

The funds passed through accounts at several international banks with a presence in Hong Kong, the United Arab Emirates and Europe. Amounts per bank ranged from around $18 million to more than $1.8 billion.

It has not been confirmed whether the banks were aware of their involvement in this fraud scheme, and the institutions reiterated their commitment to preventing money laundering. Some confirmed that the identified accounts had already been closed or denied having any direct relationship with A7.

What is A7?

A7 is a Russian payment platform created in late 2024, following restrictions on access to SWIFT, to channel payments for Russia’s foreign trade.

According to coverage of the investigation:

  • It is backed by the Kremlin and was co-founded with a sanctioned Russian state-owned bank that serves the defence industry.
  • Its majority shareholder and top executive is a fugitive Moldovan businessman.
  • A7 claims to have processed $86 billion since its launch.
  • It is estimated to handle around 20% of Russia’s foreign trade payments, roughly $100 billion a year.

The limits of AML controls based on declarative documentation

The fraud scheme run by A7 relied on documentation prepared to pass banks’ compliance checks. The network used:

  • Forged invoices and fake corporate stamps.
  • False customs codes to classify sanctioned goods as ordinary merchandise.
  • Sanitised documents to remove any trace of Russia from the transactions.

For example, in February 2025 a transaction of around $510,000 for night-vision equipment was documented as a purchase of “tempered glass”.

The network also switched channels when suspicions arose. Funds first went through banks in Kyrgyzstan. When one of the correspondent banks detected warning signs in February 2025, the flows moved to institutions in the United Arab Emirates.

Banking analyst Zach Tvarozna said the data “should make us think again about how hard it is to keep traditional correspondent banking clean.”

The case shows the limits of controls based on declarative documentation. Reviewing documents makes it possible to check that they are consistent, but not that they describe the real transaction. An AML control that relies on documentation provided by the customer is only effective if that documentation is authentic. It loses effectiveness when forgery happens at scale.

How to detect fraud involving shell companies and forged documentation

Criminal networks increasingly use shell companies, fake corporate identities and synthetic documentation. Detecting them requires combining identity verification, fraud intelligence, behavioural analysis and entity traceability.

A synthetic identity combines real and fictitious information to build a profile that looks legitimate. In the A7 case, this pattern was applied to companies. Entities registered in six jurisdictions operated with forged documentation and, when reviewed one by one, could appear valid.

That is why verifying documents is not enough. Institutions also need to know who really controls each company, how its accounts behave and who they deal with. A scheme like this only becomes visible when the customer’s identity, activity and relationships with other accounts are connected, instead of analysing each piece in isolation.

Three lessons for fraud and compliance teams

Document-based compliance controls are not enough when identity and documentation are forged at scale.

The case offers three concrete lessons:

  • Consistent documentation does not guarantee a real transaction. In this case, invoices, stamps and customs codes passed the checks even though they described a different product from the real one: night-vision equipment declared as tempered glass.
  • Reviewing each customer separately does not reveal the network. Each individual review saw a single company. The scheme was in the whole picture: more than 100 companies across six jurisdictions.
  • One-off reviews give the network room to adapt. When a bank detected warning signs in February 2025, the network stopped using that route and kept operating through institutions in another country. If reviews are not continuous, the scheme changes channel before it can be traced.

Beyond knowing whether a document is authentic, fraud and compliance teams need to be clear about who controls the company presenting it, whether its activity matches what it declares, and which other accounts it is connected to. This requires continuous verification, not just checks at onboarding.

Ready to protect your users?

Discover how Facephi's biometric technology can safeguard your identity verification process.

Facephi Facephi Identity Platform Onboarding Authentication UX Consultancy Facephi Builder Facephi Central Services Fraud Intelligence Platform Identity Fabric KYB Platform Teseo Identity Wallet IDV Suite Cuentas Mula Behavioural Biometrics Linkedin YouTube X Facebook
Secret Link