Issue #13 | July 21, 2026 | 7 min read

SECTION 1: The Brief

On June 25, 2026, the Justice Department reopened the claims window on the Western Union victim compensation fund, nine years after the case that created it. Anyone with a fraudulent transfer between 2004 and 2020 can now file.

That's not a footnote. It's the clearest sign of how large this case actually was, and this issue covers what put $586 million into that fund in the first place: a compliance team that flagged the same high-fraud agent locations for years, and a company that kept most of them open anyway.

SECTION 2: Main Feature

ENFORCEMENT ACTION

Compliance Asked for the Agents to Be Cut Off. Western Union Kept Processing Anyway.

The 2017 settlement wasn't a detection failure — the fraud network was identified internally, repeatedly, years before regulators got involved

In January 2017, Western Union pleaded to a two-count criminal information in the Middle District of Pennsylvania: willfully failing to maintain an effective anti-money laundering program, and aiding and abetting wire fraud. The company forfeited $586 million, split between a DOJ-administered victim compensation fund and a FinCEN civil penalty deemed satisfied by that same payment. The conduct ran from 2004 to 2012.

What DOJ's statement of facts actually describes isn't a company that missed a fraud network operating through its agents. It's a company whose own U.S. compliance function identified specific problem locations, in writing, and recommended termination, while Western Union kept the relationships open. Between January 2006 and November 2010 alone, the company failed to cut off 124 agent locations in the UK, 56 in Nigeria, 18 in Ghana, and 16 each in Jamaica and Spain, every one of which had already paid out $100,000 or more in reported fraud. In one specific instance named in the statement of facts, U.S. Compliance recommended suspending two UK agents. Western Union didn't act on it.

$586 million — total forfeiture in the January 2017 settlement with DOJ, FTC, and FinCEN
214 — high-fraud agent locations across five countries that stayed open between Jan 2006 and Nov 2010 despite $100,000+ each in reported fraud
500,000+ — victims DOJ initially identified as eligible for compensation from the forfeited funds

Every money transmitter runs on an agent network it doesn't directly staff, and every agent network generates a fraud-complaint tail somewhere in its distribution. The finding here isn't that Western Union had fraud running through some of its agents. It's that the mechanism built to catch it worked exactly as designed, flagged the right locations, and got overridden anyway, because those agents were still generating revenue.

Red Flags in This Case

  • Agent locations with fraud-complaint volume wildly out of proportion to their transaction volume, left open past the point compliance recommended action

  • A documented internal recommendation to suspend or terminate specific agents that senior management didn't act on

  • Geographic concentration of high-fraud locations (UK, West Africa, the Caribbean) that never triggered a portfolio-level review, only individual flags

  • Fraud scripts consistently directing victims to specific agent locations rather than random ones, a pattern that should have been visible in complaint data years before DOJ's investigation

  • A compliance program with real detection capability paired with no enforceable authority to act on what it detected

If you're doing agent or correspondent oversight anywhere in a network model, the practitioner lesson isn't "monitor for fraud." Western Union already did that. It's that a compliance finding without termination authority is a paper trail, not a control. Track agent-level fraud metrics as a rolling portfolio, not a one-time onboarding score, and make sure whoever can see the red flag is also the person with the authority to close the account.

The case didn't end in 2017. It's still opening files nine years later, because that's how long it takes to find everyone a bad control actually hurt.

Source: DOJ, "Western Union Admits Anti-Money Laundering and Consumer Fraud Violations, Forfeits $586 Million," January 19, 2017 | Deferred Prosecution Agreement and Statement of Facts, DOJ, January 2017 | DOJ, "Justice Department Announces Phase Two of Compensation Process for Western Union Fraud Victims"SECTION 3: Intelligence Briefing

SECTION 3: Intelligence Briefing

INTELLIGENCE BRIEFING

FinCEN — On June 30, FinCEN issued a supplemental alert on fiscal fuel theft: cross-border gasoline and diesel smuggling schemes run by CJNG, Sinaloa, and Gulf Cartel-linked networks, using falsified customs paperwork and shell companies to evade Mexican fuel taxes while generating tens of millions annually. Institutions should cite key term FIN-2026-FISCALFUELTHEFT in SAR field 2 when filing on related activity. Source: FinCEN, "FinCEN Issues Supplemental Alert on Fuel Smuggling and Tax Evasion Schemes on the Southern Border Associated with Mexico-Based Cartels," June 30, 2026.

OFAC — On July 1, OFAC designated two Brazilian nationals and four companies (three Brazilian, one Portuguese) tied to Primeiro Comando da Capital, now the largest transnational criminal organization in the Western Hemisphere. The São Paulo-based node moved more than $30 million in US drug proceeds back to Brazil using cryptocurrency. Source: U.S. Department of the Treasury, "Treasury Sanctions Brazilian Criminal Network Exploiting U.S. Financial System to Launder Drug Proceeds," July 1, 2026.

SECTION 4: Career Intel

CAREER INTEL

Money services business and agent-network compliance is its own hiring lane, distinct from bank-side BSA/AML roles, and cases like Western Union are why. MSBs and remittance companies need people who can build and run agent-level risk scoring across hundreds or thousands of third-party locations, not just transaction monitoring at a single institution.

If you're building toward this specialization, look for roles titled "agent oversight," "third-party risk," or "money transmitter compliance" rather than generic BSA analyst postings. The skill set (portfolio-level risk scoring across a distributed network, plus the ability to actually get a termination decision enforced) is scarcer than standard transaction monitoring experience, and this case is a good illustration of why that authority gap matters more than the detection itself.

SECTION 5: Tip Line

TIP LINE

Got any idea for something you'd want to see covered here? Doesn't have to fit neatly into a category. If you think it's interesting, we probably will too.

Send it to [email protected].

SECTION 6: CTA Block

If someone forwarded this to you, welcome.

The AML Brief goes out every Tuesday. Subscribe for free and get the Top 10 AML Red Flags cheat sheet as a thank-you:

[BUTTON: Subscribe → theamlbrief.com]

Already subscribed? Forward this to one colleague who works in financial crimes. That's how we grow.

The AML Brief | theamlbrief.com

Disclaimer: The AML Brief is an independent financial crimes intelligence publication. All content is sourced from publicly available regulatory documents, enforcement actions, and published research. Nothing published here constitutes legal, compliance, or regulatory advice. The AML Brief is not affiliated with any financial institution, regulator, law firm, or employer. For advice specific to your situation, consult a qualified attorney or compliance professional.

Keep reading