Skip to main content
Sanctions EvasionInvestigation· 3 min read· in Finance

Kremlin-Backed FinTech A7 Funneled $6.9 Billion Past Sanctions Using SWIFT and Counterfeit Invoices

A Russian state-backed financial network bypassed Western sanctions to move $6.9 billion through the global banking system. The operation relied on forged trade documents and a network of front companies to access the SWIFT messaging network.

By Camille Durand

Sanctions Enforcement Advocates 50%Global Banking Institutions 50%
Sanctions Enforcement Advocates
Argue that the breach demonstrates the need for stricter liability and enhanced due diligence in correspondent banking.
Global Banking Institutions
Emphasize the difficulty of detecting sophisticated, state-sponsored forgery within millions of daily transactions.

Perspectives this story doesn't cover

  • Russian State Financial Authorities
  • Chinese Recipient Banks

Why this matters

The breach exposes a massive vulnerability in the global correspondent banking system, demonstrating that state-backed actors can still access Western financial infrastructure despite comprehensive sanctions. The scale of the evasion raises immediate questions about the efficacy of current anti-money laundering controls at major international banks.

A Kremlin-backed financial network known as A7 successfully moved more than $6.9 billion through the global banking system between late 2024 and August 2025, bypassing Western sanctions designed to isolate the Russian economy. The operation utilized a vast network of front companies and counterfeit trade documents to retain access to the SWIFT messaging system, masking the origin of the funds from international compliance monitors.[1][3]

Founded in late 2024 by sanctioned Moldovan oligarch Ilan Shor and the Russian state-owned Promsvyazbank, A7 was designed specifically as an alternative to Western-dominated payment infrastructure. To execute the transfers, the network established over 100 front companies registered in jurisdictions including the United Arab Emirates, Hong Kong, and Kyrgyzstan.[1][3]

When international banks flagged transactions for routine anti-money laundering checks, A7 employees produced forged invoices and altered customs codes to disguise the purpose of the funds. Staff systematically removed Cyrillic characters from documentation and utilized a library of counterfeit corporate stamps to clear compliance hurdles and present the transfers as legitimate global trade.[2][3]

The A7 network utilized over 100 front companies to route funds through the SWIFT messaging system.

The illicit flows passed through several of the world's largest financial institutions before the scheme was fully uncovered. Accounts linked to A7 at Standard Chartered's Hong Kong branch received $1.1 billion before the bank detected the suspicious activity—specifically noting transactions split into smaller tranches to avoid reporting thresholds—and closed the accounts in February 2025.[1][3]

The illicit flows passed through several of the world's largest financial institutions before the scheme was fully uncovered.

During that same operational window, DBS Bank in Hong Kong processed $273 million, while Citigroup clients received $74 million. First Abu Dhabi Bank held accounts for 17 separate A7-linked entities that collectively processed more than $1.8 billion in outbound payments.[1][3]

Addressing the exposure, First Abu Dhabi Bank stated it does not comment on specific client matters but confirmed that the identified A7-linked accounts have been closed, adding that the institution "applies sanctions frameworks from the US, the UK, the EU, and the UN." The cited financial intelligence reports note that other involved institutions similarly reaffirmed their commitment to anti-money laundering regulations.[1][3]

Counterfeit invoices and altered customs codes were used to bypass routine anti-money laundering checks.

Just over half of the identified financial flows ultimately reached accounts at Chinese banks. A portion of the transferred funds was reportedly used to settle invoices for highly sensitive war-related goods, including military equipment and purchases directed by Russian security services, demonstrating the strategic stakes of the compliance breach.[1][2]

The revelation of the $6.9 billion scheme has prompted renewed scrutiny of correspondent banking networks and the mechanisms that trigger sanctions alerts. While the involved banks maintain that they have since closed the identified accounts, the breach highlights the ongoing challenge of policing state-sponsored financial evasion within the millions of daily SWIFT transactions.[1][3]

Viewpoints in depth

Sanctions Enforcement Advocates

Argue that the breach demonstrates the need for stricter liability and enhanced due diligence in correspondent banking.

Proponents of tighter financial controls point to the A7 network as evidence that current anti-money laundering frameworks are insufficient against state-backed evasion. They argue that global banks rely too heavily on automated screening and superficial document checks, which can be defeated by coordinated forgery. This camp advocates for holding correspondent banks strictly liable for the ultimate origin of funds, pushing institutions to look beyond the immediate sender and verify the underlying trade reality of every major transaction.

Global Banking Institutions

Emphasize the difficulty of detecting sophisticated, state-sponsored forgery within millions of daily transactions.

Financial institutions maintain that they are committed to enforcing international sanctions but face an asymmetric challenge when combating state-level actors. Banks argue that the A7 operation succeeded precisely because it utilized highly sophisticated counterfeit documents and legitimate-appearing front companies that mimic routine corporate trade. From this perspective, the eventual detection and closure of the A7-linked accounts demonstrates that the compliance systems ultimately work, even if they are initially bypassed by coordinated fraud.

Key points

  • A Kremlin-backed network named A7 moved $6.9 billion through global banks between late 2024 and August 2025.
  • The operation used over 100 front companies in jurisdictions like Hong Kong, the UAE, and Kyrgyzstan to access SWIFT.
  • A7 staff evaded compliance checks by producing forged invoices, altering customs codes, and using counterfeit corporate stamps.
  • Standard Chartered, DBS Bank, Citigroup, and First Abu Dhabi Bank processed portions of the illicit funds.
  • Over half of the transferred funds ultimately reached Chinese bank accounts, with some paying for military equipment.

Sources

Source coverage

3 outlets

2 viewpoints surfaced

Sanctions Enforcement Advocates 50%Global Banking Institutions 50%
  1. [1]PYMNTS.comGlobal Banking Institutions

    Russian FinTech Allegedly Laundered $6.9 Billion Via Global Banks

    Read on PYMNTS.com →
  2. [2]ComsureGlobal Banking Institutions

    A7's $6.9bn forgery route into global banks using front companies. Fake invoices.

    Read on Comsure →
  3. [3]Fincrime CentralSanctions Enforcement Advocates

    A7 Allegedly Laundered $6.9 Billion Through Global Banks

    Read on Fincrime Central →

Comments

Stay informed

Every angle. Every day.

Get Finance stories with full source coverage and perspective breakdowns delivered to your inbox.