👋 Welcome to the September CryptoCubed edition. From unregistered UK P2P trading crackdown to offshore VASPs targeting Indian customers, this month’s crypto news digest is packed with the most interesting developments across Anti-Money Laundering (AML) controls and governance.
Take a look at the latest enforcement cases shaping AML regulations in crypto and what compliance teams should start taking seriously before officers start knocking on their doors.
Ukraine Shuts Down Crypto Scam Network
Ukraine, September 1, 2026 🇺🇦: Ukrainian National Police officially announced the dismantling of a fake crypto investment platform network. According to reports, the network used a crypto drainer, a form of malicious software that plugs in and steals assets from customers’ cryptocurrency wallets.


A crypto drainer can be potent. It uses advanced fake websites to lure users into connecting their wallets, draining funds instantly. Over $1 million was stolen from victims in a month. Ukrainian regulators have identified 62 victims so far, and confirmed over 46 citizens operating in the network.
Wichtigste Erkenntnis zur Einhaltung der Vorschriften:
Crypto scams often rely on highly convincing impersonation. This can make Know Your Customer (KYC) alone insufficient. As such, adopting a multi-layered approach is crucial to preventing fraud and money-laundering risks. This includes transaction screening, Geräteintelligenz, and mobile verification, which use multiple risk signals to flag potentially suspicious destinations.
Für weitere Informationen zu dieser Geschichte klicken Sie hier Hier.
India Blocks 15 Virtual Digital Asset Service Providers (VDASPs)
India, September 9, 2026 🇮🇳: India’s Financial Intelligence Unit (FIU) issued a formal warning to 15 VDASPs after finding out that these firms did not comply with the country’s Prevention of Money Laundering Act, 2002 (PMLA) regulations. These firms include Weex, BloFin, RezorEx, and more.


Notably, most of these companies do not have physical offices in India. Instead, they operate globally, serving customers worldwide, including in India. While the exact violations have not been stated explicitly, this case signals India’s strong stance around businesses operating in the crypto sector.
Wichtigste Erkenntnis zur Einhaltung der Vorschriften:
For global firms, this case highlights growing concern about generic AML/KYC processes. Businesses operating offshore must still map obligations by customer jurisdiction, not office location. Notably, Richtlinienkontrolle und Custom AML Risk Engine solutions let businesses tailor risk factors at a granular level while ensuring compliance in each jurisdiction.
Für weitere Informationen zu dieser Geschichte klicken Sie hier Hier.
Ongoing UK P2P Trading Crackdown
United Kingdom, September 17, 2026 🇬🇧: The Financial Conduct Authority (FCA), together with HM Revenue & Customs (HMRC) and the Metropolitan Police Service, issued formal cease-and-desist orders to three premises suspected of engaging in peer-to-peer (P2P) crypto trading.
Anyone running an unregistered peer-to-peer crypto business should assume we are looking at them.
In the UK, there are no P2P firms that are legally registered. This is because the country deems crypto a high-risk sector, with P2P trading often providing a quick and easy way to move illicit funds.


FCA executive director of enforcement and market oversight Steve Smart notes, “Working with partners, we continue to track and disrupt illegal crypto activity. Anyone running an unregistered peer-to-peer crypto business should assume we are looking at them.”
Wichtigste Erkenntnis zur Einhaltung der Vorschriften:
Unregistered or cash-heavy P2P trading can be especially high-risk as it can conceal who is behind a transaction and the source of funds. For example, countries such as China and Bangladesh impose blanket restrictions on crypto trading. Firms that facilitate crypto trades should register under the appropriate jurisdiction and uphold source-of-funds checks, Customer Due Diligence (CDD), and regulatory reporting.
Für weitere Informationen zu dieser Geschichte klicken Sie hier Hier.
Australia Refuses Renewal for 45 Virtual Asset Service Providers (VASPs)
Australia, September 7, 2026 🇦🇺: The Australian Transaction Reports and Analysis Center (AUSTRAC) recently issued a powerful warning in a media release. In the past year, AUSTRAC has suspended or refused the renewal of 45 remittance and VASP registrations.


In Australia, firms must be registered to operate. According to reports, these 45 firms failed to meet AUSTRAC’s mandates, including inadequate operational capacity to begin or continue trading and the inability to effectively identify and investigate money laundering or terrorism financing risk.
In one case, the cryptocurrency service provider GetCoins had its registration canceled after customers complained to the National Anti-Scam Center (NASC). Investigations found that bad actors were targeting GetCoins to run crypto investment scams.
Wichtigste Erkenntnis zur Einhaltung der Vorschriften:
AUSTRAC’s sweeping action shows that registration is only the first step to implementing AML/CTF controls. It does not automatically translate into defensible, effective systems. In this case, regulators may suspend or cancel a firm’s registration if fraudsters repeatedly exploit it, as this provides reasonable grounds to conclude the firm cannot operate at the required level.
Für weitere Informationen zu dieser Geschichte klicken Sie hier Hier.
Crypto ATM CoinFlip Fined Over $1M for Poor Compliance Controls
United States, September 3, 2026 🇺🇸: The Washington State Department of Financial Institutions (DFI) ordered a $1,029,600 fine against CoinFlip after investigations found significant lapses in the crypto kiosk’s compliance and risk management processes.


This is particularly harmful because 50% of its customer base consists of senior citizens. Notably, the Federal Trade Commission reports that older adults are more likely to suffer losses ranging from tens of thousands of dollars lost to scammers.
According to the DFI’s Statement of Charges, CoinFlip violated multiple AML laws. This includes inadequate due diligence processes, and insufficient transaction monitoring. Additionally, the DFI seeks to revoke CoinFlip’s license, particularly due to the severity of the violations.
Wichtigste Erkenntnis zur Einhaltung der Vorschriften:
Crypto ATMs can be particularly high-risk because they allow anonymous, irreversible, and real-time cash-to-crypto conversions. That is why jurisdictions such as the FCA outright ban them. For crypto firms that provide remote services, basic identity verification may not detect high-risk activity. Instead, implementing strong Erweiterte Due Diligence (EDD) triggers, scam-specific transaction rules, and intervention before suspicious transfers are completed is crucial.
Für weitere Informationen zu dieser Geschichte klicken Sie hier Hier.
Zeit für ein wenig unbeschwerte kreative Kritik?
Sie haben es also bis zum Ende unseres Newsletters geschafft. Es ist Zeit, ein wenig Satire zu genießen, lieber Leser, Sie haben es sich verdient.
🔥DAS CRYPTO-WÜRFEL-GEDICHT: SEPTEMBER🔥
Wallets move fast, but regulators quickly follow,
Weak controls leave compliance processes hollow.
Offshore borders offer little defense,
While customer risk demands more diligence.
From crypto kiosks to P2P, the message is clear,
Monitor the transactions, not just who appears.
Crypto may change how money can flow,
But understanding the risks must grow.
Stay tuned for our October newsletter, and have a great month!





