On 21 July 2026, Malaysian authorities detained a 28-year-old man at Kuala Lumpur International Airport for his alleged involvement in a money laundering network that targeted Singaporean bank accounts.
According to the Singapore Police Force (SPF), MariBank shared crucial information with authorities, which contributed to disrupting the illicit network and making the arrests. This arrest did not happen overnight. Uncover the full details below.
The Backstory of the Notorious Illegal Network
The SPF noted that intelligence sharing from MariBank and the Anti-Scam Center contributed to Operation FRONTIER+ III, a coordinated alliance involving both Singaporean and Malaysian authorities.
With part of this information, the joint alliance was able to expose a Malaysian-based syndicate that supplied mule accounts to funnel illicit flows. In March this year, Malaysian authorities raided the syndicate’s property and seized 83 mobile phones, 45 bank security tokens, and a computer containing operating software used by the syndicate.
The private industry is an important partner in this fight against scams.
The items seized gave an insight into how the syndicate operated. It allowed them to operate multiple bank accounts registered under different identity credentials. MariBank’s role was significant and highlighted the difference between AML alerts and demonstrable financial crime intelligence.
Senior Assistant Commissioner of Police (SAC) Justin Wong said, “The private industry is an important partner in this fight against scams. I commend MariBank for their proactive cooperation with the SPF, which allowed Singapore and Malaysian authorities to dismantle the syndicate.
Correct Identity Doesn’t Mean Legitimate Control
Traditional Know Your Customer (KYC) processes enable businesses to answer one question: “Did we verify the customer details correctly?” Modern financial crime intelligence is where current regulatory authorities want businesses to move to. It answers, “Is the customer the same person controlling the account?”
Verifying whether a customer is who they claim to be may not be enough on its own.
Your KYC infrastructure may seem effective from the outset. It means a customer’s passport is genuine, their facial biometrics match their documents, and they pass sanctions and adverse media screening. However, that same customer can be part of a money laundering network long after.
The Chief Product Officer of ComplyCube mentions, “Verifying whether a customer is who they claim to be may not be enough on its own. Regulated entities require ongoing controls to evidence that a customer is still the rightful controller of an account.”
Fraud Intelligence as the Next Growing AML Requirement
Modern KYC and Anti-Money Laundering (AML) programs have to combine identity verification, ongoing monitoring, and fraud intelligence into a single workflow. The SPF did not disclose what information MariBank shared.
However, the outcome suggests that the bank was able to do more than flag an isolated suspicious account. For AML and KYC teams, the goal should therefore be to move beyond asking whether a single customer or transaction appears suspicious.
What AML and KYC Teams Should Do Next
The MariBank case shows that effective AML is no longer measured by how many alerts or suspicious activity is reported. To strengthen financial crime controls, here are the three key pillars AML and KYC teams should implement next.
1. Introduce Device Intelligence Controls
The case saw the syndicate using different mobile phones and bank security tokens to perform illegal activities. This highlights the need for device intelligence solutions, as customer names and date of birth cannot verify if an account is being used on the same device, IP address, and browser. These device signals can reveal mule-account networks that traditional monitoring may overlook.
2. Map Behavioral KYC Risk Indicators
Identity verification should not stop at onboarding. In reality, a customer’s risk profile can evolve well beyond that stage. As such, compliance teams must map behavioral deviations to a customer’s risk score, with automated enhanced review where required. Some examples of this include exceeding specific transaction values and rapid pass-through transactions.
3. Connect AML, Fraud and Cybersecurity Teams
Customer risks can be fragmented across different functions. For instance, cybersecurity teams identify compromised devices, while fraud teams manage victim handling. This can create data sharing gaps. Compliance teams should instead adopt integrated financial crime solutions, with robust APIs, SDKs, and webhooks to support seamless information sharing and unified case management.

Find out more AML news in ComplyCube’s Trust Edition newsletter. We explore the latest in developments across identity verification and AML globally.



