Tuesday, April 30, 2019

IC3.gov: BEC Compromises and Romance Fraud 2018

The Internet Crime & Complaint Center, IC3.gov, publishes annual statistics about the crimes which have been reported to them during the previous calendar year.  The full report offers insights and analysis into current trends in cybercrime.  While it is widely acknowledged that cybercrime is dramatically under-reported, there are still some shocking trends when looked at on a state-by-state breakdown.

https://www.ic3.gov/media/annualreports.aspx
While the IC3 has been collecting Internet Crime complaints since 2000, starting in 2016, the IC3 provided a more detailed state-by-state breakdown than  ever before, allowing us to see how many victims experienced how much loss by crime type reported.  What is abundantly clear in the 2018 numbers is that the greatest dollar losses among the reports are coming from Business Email Compromise.

Previous reporting from IC3.gov called Business Email Compromise The $12 Billion Scam (July 12, 2018), although quite a bit of that figure is "exposed dollar value" - meaning how much the criminals COULD have lost.  Actually losses in the US in reports gathered by the IC3 included $1.3 Billion stolen from 21,723 domestic companies from October 2013 to May 2016, and $1.6 Billion stolen from 19,335 domestic companies from June 2016 to May 2018.

In the 2018 State by State breakdown, we find documentation of 19,140 companies losing $1.2 Billion stolen from companies in the 50 states, with millions more from DC, Puerto Rico, and other US territories.  That means on the average day in 2018, criminals stole $3.3 Million dollars from 52 US businesses per day.

StateBEC LossesBEC VictimsAverage Loss Per VictimVictims per 100,000 PopulationBEC Losses per 100,000
Alabama$7,542,651190$39,6983.89$154,314
Alaska$777,53966$11,7818.92$105,102
Arizona$19,364,749401$48,2915.72$276,008
Arkansas$3,187,56393$34,2753.09$105,765
California$190,033,2053032$62,6767.67$480,610
Colorado$16,742,410453$36,9598.08$298,598
Connecticut$23,879,979263$90,7987.33$665,551
Delaware$831,59843$19,3394.45$85,983
Florida$82,979,7681433$57,9066.73$389,589
Georgia$38,310,258446$85,8974.44$381,462
Hawaii$3,119,42678$39,9935.49$219,602
Idaho$3,001,04085$35,3064.85$171,077
Illinois$50,139,264745$67,3015.82$391,713
Indiana$19,845,399265$74,8883.96$296,559
Iowa$9,491,169126$75,3274.01$301,690
Kansas$11,152,097142$78,5364.88$383,035
Kentucky$3,399,040152$22,3623.41$76,314
Louisiana$6,785,75325$271,4300.54$145,618
Maine$767,59753$14,4833.97$57,455
Maryland$29,185,800414$70,4976.84$482,250
Massachusetts$46,339,422595$77,8818.67$675,502
Michigan$27,174,665451$60,2544.53$272,783
Minnesota$26,090,980312$83,6255.59$467,832
Mississippi$2,618,16357$45,9331.91$87,666
Missouri$13,191,920229$57,6073.75$215,766
Montana$1,793,38938$47,1943.58$168,821
Nebraska$5,419,13383$65,2914.3$280,891
Nevada$6,110,393217$28,1587.24$203,816
New Hampshire$2,783,48786$32,3666.4$207,259
New Jersey$54,132,347554$97,7126.22$607,647
New Mexico$3,158,731101$31,2754.84$151,280
New York$124,028,6391288$96,2966.59$634,671
North Carolina$29,829,247436$68,4164.25$290,450
North Dakota$427,37931$13,7864.08$56,228
Ohio$70,274,973539$130,3804.62$602,701
Oklahoma$5,425,276147$36,9073.74$138,013
Oregon$14,585,319272$53,6226.57$352,047
Pennsylvania$30,638,648715$42,8515.58$239,232
Rhode Island$3,543,031115$30,80910.85$334,248
South Carolina$8,077,180201$40,1854$160,772
South Dakota$836,73428$29,8833.17$94,843
Tennessee$16,072,195297$54,1154.42$239,312
Texas$117,017,1472094$55,8827.4$413,488
Utah $7,931,467201$39,4606.48$255,689
Vermont$687,93443$15,9986.89$110,306
Virginia$18,992,122662$28,6897.82$224,228
Washington$30,899,686507$60,9466.85$417,225
West Virginia$2,093,28050$41,8662.75$115,269
Wisconsin$10,588,528257$41,2004.43$182,718
Wyoming $1,637,11629$56,4525.02$283,367


The table above shows Business Email Compromise losses by state for calendar 2018, as based on complaints received by the team at IC3.gov.  These are losses experienced by BUSINESSES.  As you can see, the average loss by business varied greatly from state to state.  Alaska only lost $11,000 per BEC case, while Ohio had $130,000 lost per BEC case and the average BEC case in Kentucky lost $271,000!  The average loss from a BEC scam in the 50 states in calendar 2018 was $62,849 per business.  ($1,202,934,836 stolen from 19,140 businesses.)

The Top Ten states for BEC by the number of victims per 100,000 population are:
Rhode Island - 10.85
Alaska - 8.92
Massachusetts - 8.67
Colorado - 8.08
Virginia - 7.82
California - 7.67
Texas - 7.4
Connecticut - 7.33
Nevada -  7.24
Vermont - 6.89

The median number of BEC victims per 100,000 by state was 4.86.
(My home state of Alabama was #41 at 3.89)

The Top Ten states for BEC by average losses per victim are:
Louisiana - $271,430
Ohio - $130,380
New Jersey - $97,711
New York - $96,295
Connecticut - $90,798
Georgia - $85,897
Minnesota - $83,624
Kansas - $78,535
Massachusetts - $77,881
Iowa - $75,326

The median state for "average loss per victim was: $47,742.80
(Alabama was #33 at $39,689 average loss per victim)

The table below documents the category of fraud that the IC3.gov team labels as "Confidence Fraud / Romance".  We know that Romance scams tend to target the lonely and the elderly in a disproportionate way, and are often enabled by social media.  While the average losses per incident are lower, realize that these are often losses experienced by a senior citizen, often representing the loss of their entire life savings!  The average loss from a Romance scam in the 50 states in calendar 2018 was $19,114.14.  ($296,613,212 stolen from 15,518 individual victims.)


StateRomance LossesRomance VictimsAverage Loss Per VictimVictims per 100,000 PopulationRomance Losses per 100,000
Alabama$1,796,307235$7,6444.81$36,750
Alaska$1,077,48785$12,67611.49$145,647
Arizona$7,975,890429$18,5926.11$113,681
Arkansas$1,332,727135$9,8724.48$44,220
California$72,355,4752105$34,3735.32$182,993
Colorado$4,782,810376$12,7206.71$85,301
Connecticut$3,956,170143$27,6663.99$110,261
Delaware$927,25948$19,3184.96$95,873
Florida$20,555,5381191$17,2595.59$96,508
Georgia$6,626,814361$18,3573.59$65,984
Hawaii$1,207,60859$20,4684.15$85,013
Idaho$1,463,39788$16,6305.02$83,422
Illinois$6,342,425433$14,6483.38$49,550
Indiana$5,390,594273$19,7464.08$80,554
Iowa$3,321,947165$20,1335.24$105,593
Kansas$2,047,571161$12,7185.53$70,327
Kentucky$1,527,974210$7,2764.71$34,306
Louisiana$2,063,99965$31,7541.39$44,292
Maine$883,37268$12,9915.09$66,121
Maryland$4,180,307316$13,2295.22$69,073
Massachusetts$8,004,624346$23,1355.04$116,685
Michigan$9,487,821461$20,5814.63$95,240
Minnesota$5,737,051287$19,9905.15$102,870
Mississippi$464,302108$4,2993.62$15,547
Missouri$5,849,242319$18,3365.22$95,670
Montana$500,41542$11,9153.95$47,107
Nebraska$1,782,49792$19,3754.77$92,392
Nevada$6,282,784254$24,7358.47$209,566
New Hampshire$1,068,70468$15,7165.06$79,576
New Jersey$8,275,788332$24,9273.73$92,897
New Mexico$2,608,857140$18,6356.7$124,945
New York$16,867,421782$21,5704$86,313
North Carolina$2,686,807432$6,2194.21$26,162
North Dakota$1,303,70235$37,2494.6$171,522
Ohio$9,085,821424$21,4293.64$77,923
Oklahoma$2,339,940164$14,2684.17$59,525
Oregon$2,713,780266$10,2026.42$65,503
Pennsylvania$10,029,245577$17,3824.51$78,310
Rhode Island$1,389,85451$27,2524.81$131,118
South Carolina$3,439,585187$18,3943.72$68,463
South Dakota$99,74731$3,2183.51$11,306
Tennessee$5,101,479268$19,0353.99$75,960
Texas$20,635,5591238$16,6684.37$72,917
Utah $2,380,004172$13,8375.54$76,725
Vermont$129,32225$5,1734.01$20,736
Virginia$9,128,873480$19,0185.67$107,779
Washington$2,062,979493$4,1856.66$27,856
West Virginia$1,367,24774$18,4764.07$75,289
Wisconsin$5,603,169391$14,3306.75$96,690
Wyoming $370,92233$11,2405.71$64,203

The Top Ten states by the number of Romance Scam victims per 100,000 population are:

Alaska - 11.49 victims per 100,000
Nevada - 8.47
Wisconsin - 6.75
Colorado - 6.71
New Mexico - 6.7 
Washington - 6.66
Oregon - 6.42
Arizona - 6.11
Wyoming - 5.71
Virginia - 5.67 

The median number of victims per 100,000 population was 4.79.
(Alabama was #25 with 4.81 victims per 100,000 population) 

The Top Ten states by average loss per Romance Scam victim are:
North Dakota - $37,248
California - $34,373
Louisiana - $31,753
Connecticut - $27,665
Rhode Island - $27,252
New Jersey - $24,927
Nevada - $24,735
Massachusetts - $23,134
New York - $21,569
Ohio - $21,428 

The median average loss per state was $17,858.
(Alabama was #44 with average Romance Scam losses of $7,634 per victim.) 







Tuesday, April 02, 2019

Twitter Mystery Followers: ? GarBot ?

I'm one of those people who tends to review the people who are following me on Twitter and to block a great number of them.  Why?  Because many of them aren't real people!

Here are a few examples:

@Juliettemasker

Juliette only has one tweet and it says "Just setting up my Twitter.  #myfirstTweet"

Gosh, the pretty blonde whose random mashup of bio statement says "Author, Musician, Harry Potter Lover, Idea Agent, Troll King, You're beautiful" must be a cyber security fan who has read some of my tweets and was inspired to follow me, right?

More likely, she is part of the botnet that has been assigned to search for the three character string "GAR" and follow people who come up in the search results.  Like these folks:



This has been going on for some time . . . in fact, the shortcut for me is to look at the followers of "@gar" (the "communist socialist libertarian anarchist who likes tacos") on that last row.  Almost all of this guy's recent followers are part of this bot:


How can we be sure?  Well, they do have something in common . . . besides a desire to follow people with "Gar" in their name or bio.  See if you can spot the pattern?








Many of the images are coming from "royalty free stock images" sites, which might imply someone is trying to be "legal" with their bot ... not sure.




And lest you think this is just a "pretty girls who follow you" bot, there are male accounts as well, although recently the males seem to be primarily Spanish (or Catalan):



And these accounts also share their passion for people named "Gar"  . . . 


More Tweets of Wisdom

Over time, the accounts do tweet things other than "Just setting up my Twitter. #myfirstTweet".  They share great wisdom such as:

"Love sees no faults" ... "Hope is life"  ... "Every bird loves to listen to himself sing"


I don't know if you can call Shery's post "wisdom" -- "i hate #cats" and "i love #dogs" and "i don't think there is such thing as too much #coffee"



StonerBot Variant

One odd variation of this bot is something I think of as "StonerBot" ... it starts out the same way.  @Janecarrson started with "Just setting up my Twitter #myfirstTweet" and following a bunch of Gar accounts:




But then things quickly go off the tracks ... in a decidedly marijuana friendly way:





StonerBotJane has posted 20 photos, instead of just one liners, and expanded beyond her "Gar" following to follow many other accounts, several of which feature nudity in their profile pictures.  Also, unlike my "GarBot" followers, StonerBotJane has a cover photo.

Looking at some of the other people's accounts that were followed by "GarBot" it was easy to spot many other "StonerBot" variants.  These all follow "@ColegSirGar" 

Victoria, Deirdre, Maria, Jane, and Leah, all behave like StonerBotJane, while Sarah, Olivia, and Julia are all more like the original "GarBot" (which surely must follow people with other names as well, but the version I am most familiar with, for obvious reasons, I refer to in my head as "GarBot."

Actually, Sarah Black is a good bot going stoner ... she still hasn't gone to posting drug photos, but her two most recent follows were 'non-Gar' accounts of questionable topics, and although she still hasn't chosen a cover photo, she did post a photo in a tweet with a drug reference.


Sarah's path to corruption includes forsaking the following of "Gar" accounts and choosing to follow two pornographic Twitter accounts ... 


Her last tweet was "Gonna roll a jay before I eat this beauty."

I think I'll stop there ... but I would certainly be interested in hearing from you if you have found your own version of a "GarBot" following you and others with similar names.  I'm genuinely curious how far this thing goes.  If you happen to know what research team is behind this project, please feel free to send me a note about that as well!

Thanks! 

A few more of my "GarBots" . . . just in case more examples help anyone who is researching this trend themselves . . . 




















Thursday, March 28, 2019

Dissect Cyber wins major DHS S&T Award for their BEC Work

Congratulations to our great friends at Dissect Cyber for receiving the DHS S&T Global Award for their work on BEC scams!

The FBI has been warning companies for several years now of the growing prominence of Business Email Compromise (BEC) scams as being one of the top forms of cyber crime based on the volume of dollars stolen.  A single BEC scam can often lead to six-figure and even seven-figure losses!  According to a June 2018 BEC report from the Internet Crimes Complaint Center, so far the FBI has documented $12,536,948,299 in losses stolen from 78,617 businesses.

Dissect Cyber decided that the best way to attack these scams and help protect those at-risk companies was to create an early warning system called Cyber Notify, based on their analysis of the vulnerable (and detectable) points of a BEC scam that is ABOUT TO HAPPEN!  To understand why their solution is so powerful, let's look at how a BEC fraud group is structured.

BEC Org Charts

Some of the leading experts in Business Email Compromise have documented the significant role in these scams played by West African cyber criminals.  Experts such as John Wilson, Crane Hassold, and Ronnie Tokazowski at Agari are doing some great work Investigating BEC Scams actors to learn more about how they commit their crimes.  The SecureWorks experts are documenting the role of malware in BEC crimes, and produced a great chart explaining the roles of the various actors, reproduced here from their report "Golden Galleon: How A Nigerian Cybercrime Crew Plunders the Shipping Industry."

SecureWorks BEC Org Chart
In that document, American researchers assigned names to each of the roles that make up a BEC scam.  One of those roles in the SecureWorks report is "Cloner" which is described as the person who "Registers domain names for impersonating email addresses."

The West African fraud experts at AA419 (Artists Against 419) provide a similar chart, but label their content based on the names the fraudsters use themselves.  In their diagram, the "Cloner" role is called within the West African fraudster community, a "Faker Maker."  While they do create domain names that closely imitate real organization names to be used in email, they often are also responsible for creating entire fraudulent organizations, complete with corresponding web sites, in order to facilitate their fraud, including fake travel agencies, fake government organizations, fake shipping companies, fake job websites, and fake lotteries.

AA419 BEC Org Chart
The AA419 staff did an excellent blog post explaining the critical role of The Faker Maker in December 2017.

Enter Dissect Cyber and Cyber Notify

I've known and worked with April Lorenzen, the founder of Dissect Cyber and Zetalytics, and her staff and products for many years.  She has been passionate about building tools for law enforcement and investigators to quickly understand the relationships between domain names, their name servers, and the IP addresses which host them.  She's also been generous enough to share her tools with researchers in my lab, including sharing them with our UAB Cyber Detective Camp last summer!  Whether we are doing phishing investigations, malware investigations, or illicit pharmaceutical investigations, Dissect Cyber has been a great partner!

Based on the organizational charts above, what Dissect Cyber realized was that part of the PRECURSOR events to having a new BEC attack often involve the creation of a "look-alike domain" that will imitate the company being targeted.  We've blogged many times about how BEC attacks work, such as our article "Business Email Compromise: Putting a Wisconsin Case Under the Microsope." Often, such as in two of the victim cases described in the Wisconsin case, the criminals are monitoring the emails of key executives, having already planted email-stealing malware on their computers, watching for an opportunity when they are traveling or otherwise unavailable.  During that scheduled outage, an employee will receive an "urgent command" that they must quickly pay an invoice, wire some funds for a merger, or some other large financial transaction.  By having the email come from a domain that is VERY SIMILAR to the true email domain, the employee often does not realize that this is not really The Big Boss, and they will comply with the financial transfer order they receive.

This is where Dissect Cyber comes in.  Because they have full visibility of EVERY NEWLY CREATED DOMAIN ON THE INTERNET, they created the Cyber Notify system to check each new domain to see if it might be a counterfeit look-alike domain. If so, their team of highly trained and vetted professionals (at the moment, all members of the alert team are military veterans), reach out to the imitated organization to help them understand that they may be about to be targeted with a BEC attack.

According to the press release from Dissect Cyber, this work has helped 1,500 companies prevent themselves from losing $407 million dollars which was requested to be wire transferred by the scammers who had created these fake domains!  Priority notifications are given to those companies that are part of the nation's Critical Infrastructure as defined by DHS.  Why?  While the techniques that have been broadly been used to steal money by West African scammers are the majority of the financial losses as reported by the IC3.gov team, the scarier fake domain attacks may be foreign nation state actors who are using the techniques refined by the West Africans to send dangerous emails that could have an impact on anything from our power grids to our water supply to employees of those critical infrastructure companies!

Congratulations, Dissect Cyber!  I hope that Cyber Notify (cybernotify.org) will grow, expand, and continue to innovate in ways to help us all protect our vulnerable small and medium-sized businesses from fraud, while also protecting our Critical Infrastructure businesses from nation state espionage hackers!


Wednesday, March 27, 2019

FTC shutters four Robocalling services that made billions of calls in 2018


The Federal Trade Commission announced settlements this week that could result in many fewer of those annoying Robocalls we've all been receiving.  Who did they sanction and what were those companies doing?

NetDotSolutions (James Christiano)

James Christiano ran a company that provided and operated softwarea called "TelWeb," a call spamming platform.  His software violated several laws, including places marketing calls to people on the "Do Not Call" list, and using a spoofed caller id, intending to deceive call recipients.


Of 883 Million robocalls per year, on the average, 157 million of the calls placed by TelWeb went to numbers on the National Do Not Call Registry.  At least 54 Million calls, just in the first half of 2016, had spoofed caller ID numbers.  The FTC received almost 8,000 consumer complaints against this company, which contributed greatly to choosing to pursue this lawsuit!

His companies, NetDotSolutions and TeraMESH Networks, were both named in the suit.  Additionally, Aaron Michael Jones and Andy Salisbury, two resellers of TelWeb, are both also named in the suit.  Which brings up one problem with these types of suits.  Jones was already "permanently banned" from doing telemarketing.  Salisbury and World Connection were each fined $2.7 million dollars. Nine of his previous companies were also subject to the ban previously:   1) Allorey, Inc.; 2) Audacity LLC; 3) Data World Technologies, Inc.; 4) Dial Soft Technologies, Inc.; 5) Digital Marketing Solutions, Inc.; 6) Savilo Support Services, Inc.; 7) Secure Alliance, Inc.; 8) Velocity Information Corp.; and 9) World Access Media.
Jones was also one of those charged in the Point Break Media case, where callers were told to "Press 1 to speak to a Google Specialist" who told them they were about to be "unlisted" from Google and charged them at least $169 to not be deleted from Google search results.

Higher Goals Marketing

Have you had the Robocall about reducing your credit card interest rate?  It may have been coming from Higher Goals Marketing. " According to the FTC’s complaint, Higher Goals Marketing LLC, Sunshine Freedom Services LLC, Brandun L. Anderson, Lea A. Brownell, Melissa M. Deese, Gerald D. Starr, Jr., and Travis L. Teel, have engaged in a telemarketing scheme that has deceived financially distressed consumers nationwide by pitching bogus credit-card interest-rate-reduction services."
Unfortunately, this is another case demonstrating that to robocallers, a multi-million dollar fine is just a slap on the wrist.  The defendants were helped with setting up their service just weeks by Wayne Norris, just weeks after he was put out of business by a previous FTC settlement against the company he was working for,Life Management Services, back in 2016. He is charged with violating the Telemarketing Sales Rule by helping the other defendants organize the telemarketing infrastructure they used to bombard consumers with illegal robocalls, putting a team of managers together to oversee the entire robocall operation, and helping to set up a shell company to collect illegal up-front fees from consumers.

In the case of Life Management Services, Wayne was asked to handle registering the new company for his boss, Steven Guise, because Guise was permanently banned from telemarketing.  He did so by asking a friend of his wife's to register the company in Florida. (See p.6 of this 51 page order .. https://www.ftc.gov/system/files/documents/cases/life_management_order_and_permanent_injunction_kevin_guice.pdf )

Wayne is behind the calls that start "This is Rachel, from Cardholder Services?"  In 2012, the FTC Chairman Jon Leibowitz declared Rachel from Cardholder Services "public enemy number one."  Back then, Wayne worked for Ambrosia Web Services.

Travis Deloy Peterson

You'll probably also be familiar with Peterson's "Veteran scams".  Using many different fake charity names, including Veterans of America, Vehicles for Veterans LLC, Saving Our Soldiers, Donate Your Car, Donate That Car LLC, Act of Valor, and Medal of Honor, Peterson made millions of calls asking people to donate a vehicle to help a veteran. In addition to paying more than a $500,000 fine, Peterson also has to return 88 vehicles that he's stolen under the guise of a charitable donation.

Point Break Media

A fourth settlement by the FTC this week targeted people offering false Google Business services.  Point Break, and several related companies and "d/b/a" aliases, were calling customers to inform them that if they didn't take action immediately, their company would no longer be able to be found in Google searches.

Dustin Pillonato; Justin Ramsey; Aaron Michael Jones, a/k/a Michael Aaron Jones and Mike Jones; Ricardo Diaz; Michael Pocker; Steffan Molina, Vincent Yates, and Daniel Carver were all charged individually in the case.   Three primary defendants in this case have agreed to settle.

As part of the settlement, the defendants will pay the FTC $3,637,386.57 and agree to forego any further work in the telemarketing industry.

Tuesday, January 29, 2019

Money Laundering and Counter-Terrorist Financing: What is FATF?

Many cybercrime investigators seem narrowly focused on the bits and bytes of the crimes they investigate while not truly understanding or interacting with those who focus on where the money goes.  As we've been expanding our horizons, I've learned quite a bit and wanted to share some resources for others who may have been similarly limited in their focus.

The Financial Action Task Force (FATF) was established in 1989. It built a list of Forty Recommendations for countries to address Money Laundering, which were first issued in 1990, and revised in 1996, 2001, 2003, and 2012.  Their latest FATF Annual Report (2017-2018) addresses Terrorist financing as well as new methods and trends and announces a research project on financing of recruitment for terrorism.  Many of these Recommendations meet our lives in the form of regulations on financial institutions and interactions between international law enforcement agencies.
"Regardless of their size and complexity, the financial activities and channels of terrorists are an essential source of intelligence.  Financial investigation can identify terrorist cells, their associates and facilitators, and reveal the structure of terrorist groups, and their logistics and facilitation networks." -- FATF President Santiago Otamendi, 14DEC2017, NYC.
FATF also released an important report "Financing of Recruitment for Terrorist Purposes" in January 2018, and a second report "Concealment of Beneficial Ownership" in July 2018.
Beneficial Ownership (July 2018)
Terrorist Recruitment (January 2018)
FATF is composed of 38 member states, covering most of the major financial centers of the world. Each of these member states has pledged to come into compliance with the Forty Recommendations, and to measure its progress.

The FATF Forty Recommendations on Money Laundering and Counter Terrorism Finance

International Standards on Combating Money Launderingand the Financing of Terrorism& Proliferation (Oct 2018)
The Recommendations fall into seven major categories:

A - AML/CFT Policies and Coordination
  • R1. Asessing risks & applying a risk-based approach
  • R2. National cooperation and coordination


B - Money Laundering and Confiscation

  • R3. Money laundering offense 
  • R4. Confiscation and provisional measures


C - Terrorist Financing and Financing of Proliferation

  • R5. Terrorist financing offense
  • R6. Targeted financial sanctions related to terrorism and terrorist financing
  • R7. Targeted financial sanctions related to proliferation 
  • R8. Non-profit organizations


D - Preventative Measures

  • R9. Financial institution secrecy laws
  • R10. Customer due diligence 
  • R11. Record keeping 
  • R12. Politically exposed persons
  • R13. Correspondent banking
  • R14. Money or Value transfer services
  • R15. New technologies
  • R16. Wire transfers 
  • R17. Reliance on third parties 
  • R18. Internal controls and foreign branches and subsidiaries
  • R19. Higher-risk countries
  • R20. Reporting of suspicious transactions
  • R21. Tipping-off and confidentiality 
  • R22. Designated non-Financial Businesses and Professions: Customer due diligence
  • R23. Designated non-Financial Businesses and Professions: Other measures 


E - Transparency and Beneficial Ownership of Legal Persons and Arrangements

  • R24. Transparency and beneficial ownership of legal persons
  • R25. Transparency and beneficial ownership of legal arrangements 


F - Powers and Responsibilities of Competent Authorities and Other Institutional Measures

  • R26. Regulation and supervision of financial institutions
  • R27. Powers of supervisors
  • R28. Regulation and supervision of Designated non-Financial Businesses and Professions
  • R29. Financial intelligence units
  • R30. Responsibilities of law enforcement and investigative authorities 
  • R31. Powers of law enforcement and investigative authorities 
  • R32. Cash couriers 
  • R33. Statistics
  • R34. Guidance and feedback 
  • R35. Sanctions 


G - International Cooperation

  • R36. International instruments 
  • R37. Mutual legal assistance 
  • R38. Mutual legal assistance: freezing and confiscation
  • R39. Extradition 
  • R40. Other forms of international cooperation 


Mutual Evalution and Ranking of Members  

4th Round Ratings
In this chart, each member state, including the Associate members, is ranked on how well they comply with each of the 11 "Immediate Outcomes" and 40 Recommendations.  For example, the United States is currently not compliant with recommendations 22, 23, and 24 -- so, we don't do well in non-financial institutions, and our shell company games are impossible to monitor as of now, but we do generally do well in most others.  Clicking the "4th Round Ratings" label will take you to the full chart.  If you do international business, it may be a form of risk doing businesses in countries with poor ratings across the board here.

FATF Member Assessments

Each member is encouraged to perform regular assessments to measure themselves on how they are complying with the Forty Recommendations.  Here are example reports from the United States, but these reports are available for every country that participates in FATF or one of the Associate Members.  In the United States, these assessments are published by the Department of the Treasury.  These reports were issued in 2015 by the Treasury Undersecretary for Terrorism and Financial Intelligence, Adam Szubin.

2015 Money Laundering Risk Assessment

2015 Terrorist Financing Risk Assessment

The goal of sharing these examples is to serve as a reminder that from the FATF site, ALL such reports for all member states are available, by looking for the "Mutual Evalutions Publications." As of this writing the four newest ones are from Tunisia, Nicaragua, Panama, and Tajikistan.

FATF Associate Members

FATF also has 9 Regional Bodies, considered "FATF Associate Members" each of which put out specialized information for their portion of the world.  For those who are interested in that Region, following up on those specific regions reports from their representative task forces and groups will be worthwhile.

A Special Focus on Terrorist Financing Risks 

FATF issued their first special report offering guidance on Terrorist Financing in 2008:


Several more recent reports would be especially interesting regarding terrorist financing, stemming from an emergency meeting of 55 states, the United Nations, the Egmont Group of Financial Intelligence Units, the International Monetary Fund, the World Bank, and others specifically to address curbing the financing of ISIS/ISIL.



In the Paris meeting of 19OCT2018, FATF encouraged members to expand their focus from looking specifically at ISIL to more broadly include Al Qaeda and its Affiliates, issuing this guidance:



Regional Terrorist Financing Focuses

There have also been significant regional reports issued by sub-groups and associate members.

The Counter-Terrorism Financing Summit, hosted by Australia's Financial Intelligence Agency (AUSTRAC) and the Indonesian counterpart, Pusat Pelaporan dan Analisis Transaksi Keuangan (PPATK), issued the Regional Risk Assessment on Terrorism Financing 2016.  The following year, the event was repeated, adding Bank Negara Malaysia as a partner.  These events issued two small statements, and one more substantial report, addressing events in Philippines, Thailand, Malaysia, Singapore, Indonesia, and Australia, and how those events were funded.

A risk methodology for their region (p.22)

The Nusa Dua Statement - August 2016 
Kuala Lumpur Communique - November 2017 


West and Central Africa have very different concerns, and held a summit to discuss these differences, resulting in this excellent joint publication: 

"Terrorist Financing in West and Central Africa", October 2016
50 page joint report from FATF, GIABA, and GABAC


Particular Funding Methods for Terrorism Finance

Many other special reports have been issued, related to the trade in:

Virtual Currencies of Growing Concern

In the Paris meeting 19OCT2018, a special issue that was raised was the Regulation of Virtual Currencies.  This was deemed to be a matter of strategic interest that will be further evaluated, especially with regard to Initial Coin Offerings and their role in Money Laundering.  FATF has committed to work with the G20 to come up with new guidelines to update their previous report "Virtual Currencies: Key Definitions and Potential AML/CFT Risks" as well as their report "Guidance for a Risk-based Approach to Virtual Currencies" (June 2015 - 46 page PDF).  

The work so far is in the form of a report to the G20, which addresses many topics in addition to Virutal Currencies:


In part the report shares:

"Noting that virtual currencies/crypto-assets raise issues with respect to money laundering and terrorist financing, they committed to implement the FATF Standards as they apply to virtual currencies/crypto-assets.  They looked forward to the FATF review of those Standards, called on the FATF to advance global implementation, and asked the FATF to provide an update on this work in July 2018.  The FATF will take this work forward under the US presidency from 1 July 2018 to 30 June 2019."

This work begins with first reviewing laws and regulations regarding crypto-assets and virtual currencies in each of the G20 states.

More on this topic will certainly be forth-coming from FATF.