Case files

Pecunia non olet.

“Money doesn’t smell,” Emperor Vespasian is supposed to have said. Eight landmark cases show how wrong he was — and what each one teaches the people who onboard, monitor and report.

Supervision gap

BCCI

1972–1991 · Luxembourg, London, Karachi, Cayman Islands

One of the largest private banks in the world at its peak

The Bank of Credit and Commerce International was built so that no supervisor ever saw the whole: a holding company in Luxembourg, operating banks split between Luxembourg and the Cayman Islands, the head office in London. Behind the structure: secretly controlled banks, fictitious loans, hidden losses — and accounts used to launder money for drug traffickers and the regime of Manuel Noriega.

Outcome · Lessons for practitioners

Outcome

On 5 July 1991, regulators in several countries closed the bank in a coordinated operation. The scandal reshaped consolidated supervision of international banking groups.

Lessons for practitioners

  • A group nobody supervises as a whole is supervised by nobody.
  • Opaque ownership and nominee shareholders are a risk in themselves.
  • Home and host supervisors must talk to each other.
Monitoring failure

HSBC Mexico

2006–2010 · Mexico, United States

US$1.9 billion in penalties (2012)

Cartel cash deposited in Mexico flowed into HSBC's US bank, where Mexico was rated low risk and enormous volumes went unmonitored. US authorities found that at least US$881 million of drug proceeds was laundered through the group; sanctions violations were added to the file.

Outcome · Lessons for practitioners

Outcome

In December 2012 HSBC entered a deferred prosecution agreement with the US authorities and paid about US$1.9 billion, with a monitor imposed.

Lessons for practitioners

  • Country risk ratings must reflect reality, not commercial convenience.
  • An alert backlog is a risk, not an administrative detail.
  • Group standards must apply in every subsidiary.
Anonymity by design

Liberty Reserve

2006–2013 · Costa Rica, worldwide

More than US$6 billion laundered, according to US prosecutors

A digital currency service that let anyone open an account with nothing more than a name and an e-mail address — real or not. Funds moved through third-party exchangers, so the service never touched a bank account in its users' names. It became the bank of choice for cybercrime.

Outcome · Lessons for practitioners

Outcome

Shut down by US authorities in May 2013. Its founder was sentenced in 2016 to 20 years in prison.

Lessons for practitioners

  • No verified identity, no due diligence — whatever the technology.
  • Exchangers and on-ramps are gatekeepers.
  • The blueprint for today's crypto AML rules.
Branch out of control

Danske Bank — Estonia

2007–2015 · Estonia, Denmark

Around €200 billion of payments through non-resident accounts

The Estonian branch of Denmark's largest bank built a highly profitable portfolio of non-resident customers, mostly from Russia and other former Soviet states, on IT systems separate from the group. A whistleblower raised the alarm in 2013; the bank's own investigation later found that a large share of the payments was suspicious.

Outcome · Lessons for practitioners

Outcome

The chief executive resigned in 2018. In December 2022 Danske Bank pleaded guilty in the United States and agreed to pay about US$2 billion.

Lessons for practitioners

  • A branch's profitability is a question, not an answer.
  • Non-resident business needs its own risk appetite.
  • Listen to whistleblowers the first time.
Kleptocracy

1MDB

2009–2015 · Malaysia, Singapore, Switzerland, United States

More than US$4.5 billion misappropriated, according to the US Department of Justice

Money raised for Malaysia's sovereign development fund was diverted by officials and their associates through shell companies and bank accounts on several continents, then spent on luxury property, art, a superyacht and even the financing of a Hollywood film.

Outcome · Lessons for practitioners

Outcome

The US led the largest kleptocracy asset-recovery action in its history; Goldman Sachs paid more than US$2.9 billion in 2020 to resolve investigations into its role; Malaysia's former prime minister was convicted.

Lessons for practitioners

  • PEP risk includes those who act for the PEP.
  • Wealth that cannot be explained must be questioned.
  • Gatekeepers — bankers, lawyers, auditors — share the risk.
Fraud in plain sight

Wirecard

until 2020 · Germany, Asia

€1.9 billion of cash that did not exist

A payments company in Germany's blue-chip index reported revenue routed through third-party acquiring partners in Asia and cash held on trustee accounts in the Philippines. The cash was never there. Journalists and short-sellers who raised questions were targeted instead of heard.

Outcome · Lessons for practitioners

Outcome

Wirecard filed for insolvency in June 2020. Its former chief executive went on trial in Munich; the supervisory failure led to reforms of German financial oversight.

Lessons for practitioners

  • Confirm cash with the bank, not with the client.
  • Third-party business partners need due diligence too.
  • Whistleblowers and journalists are an early-warning system.
Growth before compliance

Binance

2017–2022 · Worldwide, United States

More than US$4.3 billion in US settlements (2023)

The world's largest crypto exchange let many users trade without identity checks, served US customers while claiming not to, and processed transactions with users in sanctioned jurisdictions.

Outcome · Lessons for practitioners

Outcome

In November 2023 Binance pleaded guilty in the United States to anti-money laundering, unlicensed money transmission and sanctions violations; its founder pleaded guilty to failing to maintain an effective AML programme.

Lessons for practitioners

  • KYC at onboarding is not optional, even in crypto.
  • Sanctions controls must work at the level of each transaction.
  • Compliance that slows growth costs less than enforcement.
Unmonitored volume

TD Bank

2014–2023 · United States

About US$3 billion in penalties (2024)

US authorities found that the bank's monitoring left the vast majority of its transaction volume unchecked for years, while budgets were kept flat. Laundering networks moved hundreds of millions of dollars through its branches, helped in some cases by bribed employees.

Outcome · Lessons for practitioners

Outcome

In October 2024 TD Bank pleaded guilty to Bank Secrecy Act violations, paid about US$3 billion and accepted a cap on the growth of its US retail assets.

Lessons for practitioners

  • Monitoring coverage is the first metric to check.
  • Compliance budgets must follow the business, not a flat line.
  • Insiders are part of the risk.

Sources: public enforcement records and official statements. Figures rounded.

The full story in FRAUD-LEAKS — The Book
Books →