U.S. Tightens Net Around Russia, Iran Sanctions Evasion with Shadow Bank Network Crackdown
The fight against sanctions evasion has become an increasingly important front in the broader effort to disrupt illicit finance on the global scale. In recent years, the United States government has characterized sanctions evasion and associated illicit financial activity as legitimate threats to our national security interests, with the financial infrastructure used to move sanctioned funds historically supporting weapons procurement, illicit asset sales, cybercrime and other activities that challenge the defenses of the U.S. government as well as that of its allies. Embattled countries such as Russia and Iran have spent years adapting to staunch economic restrictions imposed at the international level by developing alternative payment channels, utilizing third-country intermediaries and front companies, and employing other mechanisms designed to circumvent sanctions and maintain access to global markets to allow their destabilizing activities to continue. As these networks become more sophisticated and widespread, U.S. authorities have placed greater onus on banks to help snuff out illicit transactions and hinder the ability of shadow financial institutions and intermediaries to enable sanctioned funds to move across international borders, while also increasingly targeting not only the governments, companies and individuals that are themselves subjected to these sanctions, but also the financial networks that help them keep money moving.
Illustrating the evolution of modern sanctions enforcement that now includes the use of financial intelligence alongside more robust AML controls, late last week, the U.S. government took unprecedented action against a major illicit banking network with direct ties to Russia that was being used by the Iranian government to evade sanctions. On October 1st, the U.S. Department of the Treasury announced a coordinated enforcement action against the A7 Network, a global shadow banking and cryptocurrency payment platform created in 2024 by Russian defense-sector bank Promsvyazbank (PSB) and fugitive Moldovan-Israeli oligarch Ilan Shor that has reportedly handled billions of dollars’ worth of cross-border transactions, emerging as a major alternative payment conduit for Russian foreign trade.1
The action, coined Operation Economic Outcast, brought together three major components of the Treasury Department’s financial crime program. In the effort, the Financial Crimes Enforcement Network (FinCEN), the agency responsible for collecting and analyzing information about financial transactions to combat domestic and international money laundering, terrorist financing, and other financial crimes proposed a rule that would prohibit the transmittal of funds involving A7 Network sub-agents. FinCEN also issued an alert highlighting specific indicators that could help financial institutions identify transactions associated with the network.2 At the same time, the Office of Foreign Assets Control (OFAC), the agency which administers and enforces economic and trade sanctions in support of U.S. national security and foreign policy objectives designated the A7 Network as a significant transnational criminal organization, blocking its property and interests in property subject to U.S. jurisdiction and imposing restrictions on U.S. persons’ dealings with the network.2 These moves are viewed as a major step forward in isolating both Russia and Iran as well as the financial enablers still granting them access to the U.S. financial system.
In their investigation leading up to the actions taken, the Treasury found that the A7 were quickly able to develop significant criminal architecture over only a roughly two-year time period, with a network that grew to operate through a “constellation of companies in third country jurisdictions” termed “sub-agents” whose sole purpose was to receive and remit payments while obscuring the connection between the underlying transaction and the sanctioned parties.2 The Treasury discovered that the network used a myriad of mechanisms to conceal their activity, including falsified trade documents and import-export records, as well as misleading descriptions of goods to make payments associated with sanctioned activity appear to be legitimate commercial transactions. This form of obscurement has historically created significant problems for financial institutions attempting to weed through suspicious activity, as transactions of this variety contain less obvious details about those behind the payments, with risk purposely being buried inside this complex network of counterparties, jurisdictions, beneficial owners, and payment flows. The scope of these transactions is also eye-opening. A Treasury press release issued following the enforcement action writes that by its own account as of January 2026, the A7 Network claimed to process more than 2,000 transactions a day with a total transaction volume of more than 7.5 trillion rubles, the U.S. dollar equivalent of $91.5 billion or approximately 13 percent of the Russian Federation’s 2025 foreign trade transactions.2
Beyond state actors, the Treasury found that the A7’s sub-agents that were initially designed to facilitate illicit financial activity on behalf of Russia also established provided pathways for other bad actors, including Iranian entities, to access the international financial system, finding a direct connection between these entities and Iran’s Islamic Revolutionary Guard Corps, Iran’s central bank and other Tehran-backed organizations. The activities of these sub-agents ultimately grew to include facilitation of Iranian oil sales and weapons procurement in wake of the U.S.-Iran military conflict. The investigation details multiple instances where A7 agents transacted directly with entities involved in Iran’s infamous “shadow fleet” of oil tankers, shipping companies and front companies used to transport and sell Iranian oil while working around international sanctions. The A7 Network sub-agents also reportedly catered to international cybercriminals, including ransomware and procurement actors seeking to obtain restricted goods and/or to move funds through the international financial system. All told, FinCEN’s investigation identified that the A7 Network’s sub-agents processed more than $17 billion in global transactions between January 2025 and June 2026 alone.2
OFAC and other American anti-crime agencies have continuously warned that sanctioned Russian actors continue to develop a variety of methods to circumvent sanctions, including virtual currencies and other mechanisms designed to obscure prohibited transactions. The government’s response to these findings, as well as the discovery of the direct link between Russia and Iran in this sense, may ultimately grow to reflect a broader shift in how sanctions evasion is detected and enforced moving forward. This case reinforces the importance of ongoing transaction and network-level monitoring for domestic financial institutions, though this is far from the end-all be-all in today’s complex financial and political state. Today, sanctions enforcement is much more than simply identifying prohibited names and blocking individual transactions. Enforcement agencies are now attempting to map the financial infrastructure surrounding sanctioned actors, leading to more widespread enforcement. FinCEN’s latest alert is intended to assist FI’s in identifying suspicious activity associated with the network and other similar foreign sanctions evasion exploits, with the role banks serve as watchdogs remaining of the utmost importance in the fight against sanctions evasion and illicit finance.
Citations
1. Fabrichnaya E, Bryanski G. Russia’s A7 payment platform denies links to Iran after US sanctions. Reuters. Published October 2, 2026.
2. U.S. Department of the Treasury. Operation Economic Outcast Takes Unprecedented Action Against Sanctions Evasion Network Used by Iran. October 1, 2026.
