What happened

The US Treasury's Office of Foreign Assets Control sanctioned Xinbi Guarantee, a Chinese-language marketplace that connects scam center operators in Southeast Asia with merchants selling financial services, technology and other supplies. The UK had already sanctioned the platform in March, and Washington has now followed.

Treasury estimated that the marketplace has processed more than $24 billion in digital and fiat currency since it launched in 2022. Treasury Secretary Scott Bessent said scam centers in the region "steal billions of dollars from American victims each year" and described the designations as part of an effort to dismantle the networks behind the fraud.

OFAC also designated two companies it says support Xinbi's core operations: Singapore-based SafeW Technology, which provides an end-to-end encrypted messaging app, and Cambodia-based Anwen Technology, which makes the XinbiPay digital wallet. Blockchain analytics firm TRM Labs, which tracks the marketplace, put transaction volume even higher at more than $36 billion and said listings included stolen personal data, fake identity documents and AI deepfake tools. The Secret Service and blockchain intelligence firm Elliptic said they identified and froze $52.8 million in cryptoassets tied to Xinbi. Elliptic said the marketplace now appears to be offline, and Telegram removed its main channels.

Why this is a GRC story

Sanctions exposure is no longer a banking-only problem. Designations like this one create screening obligations for any company that touches crypto payments, wallet infrastructure, messaging platforms or cross-border merchant services. A processor, an exchange or a cloud provider that onboards a linked customer inherits the risk, and the designations of SafeW and Anwen show how far Treasury is willing to reach into the supply chain behind a marketplace.

The human side of the scam economy matters too. TRM notes that these platforms support operations built on trafficked workers, which turns a fraud story into a labour and supply chain story. For compliance teams, that means third party risk reviews should follow the money and the infrastructure, not just the registered corporate name on the application.

There is an AI governance thread as well. Deepfake tools sold on the same platform are the operational layer of identity fraud, so any vendor that signs customers up quickly can end up enabling it without a single person intending to.

What to watch

Watch whether other jurisdictions follow with their own designations and whether individuals behind the platform are named, since coordinated action across the US and UK narrows the field of exchanges and wallet providers still willing to move the funds.

Watch also how the $52.8 million freeze progresses. Enforcement that disrupts a marketplace but returns nothing to the people who lost money does not close the loop.

Attribution: Analysis based on Infosecurity Magazine and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News