Glossary for definitions in the Investment and Payment Fraud Industry

A

Account velocity refers to how quickly and how often funds enter and leave a bank account, payment account or wallet within a given period.

Account hopping describes the repeated movement of funds from one account to another, often quickly and with limited apparent economic purpose, in order to avoid detection, delay traceability or bypass account-level controls.

AI-powered voice cloning is the AI-based creation or replication of a person’s voice so that synthetic speech sounds like the targeted individual, including tone, accent, rhythm and vocal characteristics.

AI-enabled recruitment scams are fraudulent schemes in which artificial intelligence is used to impersonate employers, recruiters, or job applicants, create convincing job advertisements and communications, or automate interactions with victims. They may involve fake interviews, deepfake video or audio, fabricated company profiles, and requests for fees, personal data, account access, or money transfers.

AISPS – Account Information Service Providers

AMLA – Authority for Anti-Money Laundering and Countering the Financing of Terrorism
AMLA is the European Union’s central anti-money laundering and counter-terrorist financing authority, established by Regulation (EU) 2024/1620. It is intended to strengthen the EU’s fragmented AML/CFT supervisory system by coordinating national supervisors and Financial Intelligence Units and, for selected high-risk obliged entities, exercising direct supervisory and enforcement powers.

AMLR – Anti-Money Laundering Regulation
The AMLR is Regulation (EU) 2024/1624, the EU’s directly applicable anti-money laundering and counter-terrorist financing rulebook. It harmonises core AML/CFT obligations for obliged entities across the EU, including customer due diligence, beneficial ownership transparency, internal controls and measures to prevent the misuse of the financial system for money laundering or terrorist financing.

Authorised Push Payment fraud occurs when a payer is manipulated into approving a bank transfer that they believe is legitimate, but the payment is actually made to a fraudster, mule account, shell company, fake investment platform, impersonator, or other fraud-controlled recipient. The payment is “authorised” because the victim themselves instructs the bank to make the transfer, but the authorisation is obtained through deception, social engineering, impersonation, false investment promises, romance manipulation, invoice fraud, or other fraudulent conduct. The UK Payment Systems Regulator describes APP scams as cases where someone is tricked into sending money to a fraudster posing as a genuine payee.

B

Behavioural biometrics is the use of behavioural patterns — such as typing rhythm, mouse movement, touchscreen pressure, scrolling behaviour, device handling, navigation habits or transaction behaviour — to help identify a user, detect anomalies or flag possible fraud.

Bust-out fraud refers to a staged fraud model in which a fraudster opens or controls an account, credit line, merchant account, payment account, bank account, card account, or crypto/fintech account and initially behaves like a legitimate customer. The fraudster may make normal transactions, repay balances, process apparently genuine payments, build turnover, improve trust scores, or request higher limits. Once trust, limits, liquidity, or processing capacity have increased, the fraudster “busts out” by maxing out credit, withdrawing funds, processing fraudulent transactions, moving assets, or leaving unpaid obligations behind.

The Federal Reserve describes the pattern in the synthetic-identity context as building creditworthiness over time and then “busting out” by purchasing high-value goods or services on credit before disappearing.

C

CASPs: A Crypto-Asset Service Provider (CASP) is a legal person or undertaking that provides one or more crypto-asset services to clients on a professional basis and is authorised to do so under MiCA.

CMLN- Chinese Money Laundering Networks – CMLNs have become key financial enablers for cartels and other transnational criminal
organizations, providing fast liquidity and near-instant value transfer in exchange for illicit proceeds. They use networks of licit and illicit businesses to launder funds and help these organizations expand their influence inside the United States. (FinCEN, 2025; DOJ, 2024) 

The Consumer Financial Protection Bureau (CFPB) is a U.S. government agency responsible for protecting consumers in financial markets. It implements and enforces federal consumer financial laws and aims to ensure that markets for consumer financial products and services are fair, transparent and competitive. The CFPB supervises certain banks, lenders and large non-bank financial companies, enforces consumer-protection rules, provides consumer education, and accepts complaints from consumers about financial products and services.

Native Cross-chain swap: users can exchange assets across blockchains directly, without wrapped tokens or centralized intermediaries.

Cyber-scam compounds are organised-crime-controlled facilities in which trafficked, coerced, or otherwise controlled workers are used to conduct large-scale online fraud against victims worldwide, usually supported by digital payment channels, crypto infrastructure, corruption, private security, and money-laundering networks

Cyber-enabled fraud: scams are conducted through phones, social media, dating apps, messaging platforms, fake trading platforms, crypto wallets, and payment processors.

A Currency Transaction Report (CTR) is a mandatory anti-money-laundering report filed by a U.S. financial institution with FinCEN when a customer conducts a cash / currency transaction exceeding USD 10,000 in one business day. This includes deposits, withdrawals, exchanges of currency, or other cash payments/transfers, including multiple related cash transactions that aggregate above the threshold.

Important distinction: a CTR is threshold-based, not suspicion-based. A lawful cash deposit over USD 10,000 can still trigger a CTR. Suspicious conduct is usually reported separately through a Suspicious Activity Report (SAR).

D

A DAML (Defense Anti Money Laundering) request is a Suspicious Activity Report submitted to the UK Financial Intelligence Unit, part of the National Crime Agency, by a person or regulated entity seeking a legal defence before carrying out an intended act involving property they suspect may be criminal property.

A DAML refusal means the UKFIU/NCA’s refusal to grant a Defence Against Money Laundering request. It does not prove criminality, but it prevents the reporting entity from safely proceeding with the proposed transaction and creates a temporary intervention window during which law enforcement may investigate, restrain, freeze or recover suspected criminal property.

Decentralised Finance (DeFi) is a blockchain-based financial ecosystem in which users can access services such as trading, lending, borrowing, staking, liquidity provision, asset management, derivatives, synthetic assets, or payment functions through smart contracts and decentralised protocols. In DeFi, transactions are usually executed automatically by code, and users often interact directly with protocols through non-custodial wallets.

Decentralised liquidity protocol: A blockchain-based financial protocol where users supply assets to shared liquidity pools, and other users can trade, borrow, or access those assets automatically through smart contracts. 

A decentralisation threshold is a functional benchmark used to assess whether control over a crypto system is sufficiently distributed across independent actors. It refers to the level of decentralisation at which decision-making power, technical control, governance rights, validator influence, admin-key control, treasury control, front-end control, and economic incentives are no longer concentrated in a way that allows one identifiable actor or coordinated group to dominate the system.

Deepfakes are synthetic or manipulated media created with artificial intelligence to realistically imitate a person’s face, voice, movements or expressions.

Digital identity compliance refers to the policies, processes and controls used by an organisation to verify, manage and monitor a person’s or entity’s digital identity in line with legal, regulatory and risk-management requirements

DLT – Distributed Ledger Technology
Distributed Ledger Technology refers to the technological infrastructure that enables distributed ledgers: records of transactions or ownership that are shared across, and synchronised between, multiple network participants. In EU financial regulation, DLT is relevant for crypto-assets, tokenised financial instruments and market infrastructures that rely on decentralised or shared record-keeping rather than traditional centralised databases.

DPRK-related cyber theft refers to cyber-enabled theft carried out by or on behalf of actors linked to the Democratic People’s Republic of Korea (North Korea). It commonly involves attacks on financial institutions, crypto-asset businesses, wallets, or technology companies to steal funds or virtual assets. The proceeds are typically laundered through complex cross-border transactions and may be used to evade sanctions or finance the DPRK’s weapons programmes.

Dynamic monitoring or risk-based monitoring, where the system adapts to behaviour, patterns, anomaly detection, network links and updated intelligence.

E

EBA –  European Banking Authority

EJCN – European Judicial Cybercrime Network 

F

FCA – Financial Conduct Authority (UK)

FDIC – Federal Deposit Insurance Corporation

FEC duties –  the internal and regulatory duties of a financial institution to prevent, detect and report financial economic crime. These include, in particular, anti‑money‑laundering prevention, counter‑terrorism‑financing prevention, sanctions screening, customer due diligence / KYC, ongoing transaction monitoring, as well as the obligation to escalate and, if necessary, report suspicious or unusual activities to the competent authorities.

The Financial Crimes Enforcement Network (FinCEN) is a bureau of the U.S. Department of the Treasury and acts as the United States’ financial intelligence authority for combating money laundering, terrorist financing, fraud and other financial crimes. FinCEN collects, analyses and disseminates financial intelligence, administers key U.S. anti-money laundering rules, and works with law enforcement, regulators, financial institutions and international partners to detect and prevent illicit finance. FinCEN’s official mission is to safeguard the financial system from illicit activity, counter money laundering and terrorist financing, and promote national security through financial intelligence.

FSRB plenaries are the principal decision-making meetings of FATF-Style Regional Bodies (FSRBs). At these meetings, member jurisdictions discuss regional AML/CFT and proliferation-financing issues, adopt mutual evaluation and follow-up reports, assess countries’ compliance with the FATF Standards, and agree on regional policies and priorities.

FSRBs are autonomous regional organisations that form part of the FATF Global Network and promote the implementation of the FATF Recommendations within their respective regions.

FTD – First Time Deposit equals the Initial Deposit Address in Cryptocurrency confidence scams

G

Gift cards are one of the original fraud payment rails in consumer scams. Their appeal to criminals lies in their simplicity: victims can buy them almost anywhere, transfer value by sending only a code, and usually cannot reverse the loss once the code has been shared. For fraudsters, gift cards offer speed, distance from the regulated banking system, reduced traceability, easy monetisation and limited recovery options for victims. They are therefore not merely a payment method, but a fraud-enabling asset frequently used to move value quickly in social-engineering scams

H

Hawala banking, also known as the hawala system or an informal value transfer system (IVTS), is a trust-based mechanism for transferring money or value between persons in different locations through intermediaries known as hawaladars. A customer gives money to a hawaladar in one country, and a corresponding hawaladar in another country pays the equivalent amount to the intended recipient. The settlement between hawaladars may occur later through cash, trade transactions, offsetting debts, goods, services, or other value-balancing methods. FinCEN describes informal value transfer systems as networks that receive money to make funds or equivalent value payable to a third party in another location, generally outside conventional banking channels.

High-velocity scam refers to a fast-moving fraud operation that relies on rapid victim acquisition, repeated transaction processing, quick movement of funds and frequent infrastructure changes to maximise proceeds before banks, PSPs, platforms, regulators or law enforcement intervene.

Hybrid launderer refers to an individual or network that moves, disguises or legitimises illicit funds by combining conventional financial channels — such as bank accounts, shell companies, cash businesses, money mules or payment institutions — with digital channels such as crypto wallets, exchanges, stablecoins, mixers, bridges, fintech accounts or online payment platforms.

Hybrid payment chains are payment or value-transfer arrangements that combine different forms of value or payment infrastructure within a single transaction chain, particularly fiat currency and virtual assets. A transfer may, for example, begin as a bank payment, be converted into crypto-assets, pass through one or more crypto-asset service providers, and later be converted back into fiat currency.

Such chains can involve banks, payment institutions, crypto-asset service providers, exchanges, wallets, and other intermediaries. They create particular challenges for transaction traceability, allocation of compliance responsibilities, and the consistent transmission of originator and beneficiary information under the Travel Rule.

The term is used by the FATF in connection with complex payment chains under Recommendations 15 and 16.

I

Illegal logging refers to the unlawful harvesting, processing, transport, or sale of timber. It includes logging without permits, extraction from protected areas, exceeding authorised volumes, and concealing or falsifying the origin of timber.

J

K

L

Layering across accounts refers to the movement of funds through several bank accounts, payment accounts, e-money accounts, crypto wallets or exchange accounts in order to distance the funds from their original source and obscure the identity of the ultimate beneficiary or controller

A Legal Entity Identifier (LEI) is a standardized 20-character alphanumeric code used to uniquely identify legally distinct entities in financial markets and regulatory reporting.

M

Micro-splitting of funds is the practice of dividing a larger amount into numerous small-value transactions or transfers. It may be used legitimately, but in a financial-crime context it can serve to avoid reporting or monitoring thresholds, reduce the visibility of transaction patterns, and make the tracing of funds more difficult.

The technique is also referred to as structuring or smurfing, particularly where multiple accounts, wallets, intermediaries, or payment channels are used.

MLAT Request – Mutual Legal Assistance Treaty Request- is a formal request from one country to another for help in a criminal investigation or prosecution.

A money mule is a person or entity whose bank account, payment account, crypto wallet or other financial access point is used to receive and transfer funds for someone else, often as part of fraud, money laundering or sanctions-evasion activity.

MOTO Transaction means a mail-order or telephone-order card transaction in which the customer provides card details through a non-electronic channel and the merchant manually initiates the payment. It is a form of card-not-present transaction and is generally outside standard SCA requirements, making it particularly relevant in fraud-risk, chargeback and payment-monitoring analysis.

MOTO Transaction Permission / MOTO Use Conditions means that a card transaction may be classified as Mail Order / Telephone Order only where the payer provides payment details through a genuinely non-electronic mail or telephone channel. MOTO transactions are generally outside the SCA requirement because they are not electronically initiated by the payer. However, a transaction cannot lawfully or properly be treated as MOTO merely because the merchant manually enters card details. Misclassifying online or electronically initiated payments as MOTO may indicate SCA circumvention and create fraud-monitoring, acquirer-control and compliance issues.

Mule clusters are networks of mule accounts, wallets, companies or individuals that show common control, coordination or repeated use within the same fraud or laundering structure.

Mule layering is the movement of illicit funds through multiple mule accounts, payment accounts, wallets, shell entities or intermediaries to create distance between the original crime proceeds and the final beneficiary.

Muling activity refers to the use of individuals, companies, wallets or accounts to receive, move, withdraw or convert funds on behalf of another party, often to obscure the origin, destination or controller of the funds.

Multi-hop transfers are transactions in which funds or crypto-assets are moved through several intermediary accounts, wallets, service providers, or blockchains before reaching the final recipient.

They may serve legitimate operational purposes, but in a financial-crime context they can be used to obscure the source, ownership, or destination of funds and make transaction tracing more difficult.

N

Nested services refer to arrangements in which a crypto intermediary accesses the infrastructure of another Virtual Asset Service Provider (VASP), such as a regulated crypto exchange, broker, custodian, or fiat on/off-ramp, and then uses that access to serve its own customers. In such arrangements, the regulated platform may see only the intermediary as its direct customer, while the intermediary’s underlying users remain partly or fully hidden.

NCUA National Credit Union Administration

O

OCC – Office of the Controller of Currency (USA)

Offshore Virtual Asset Service Providers (oVASPs) are crypto-asset service providers that conduct business across borders or serve customers in jurisdictions where they have no meaningful physical presence, licence, registration, or effective regulatory supervision.

Open-weight AI models are AI models whose trained parameters, known as weights, are publicly available for download. This allows users to run the model on their own infrastructure and, subject to the applicable licence, modify or fine-tune it for specific purposes.

OSINT (Open-Source Intelligence) refers to the collection, analysis and interpretation of information obtained from publicly available sources for investigative, intelligence, compliance, security, journalistic or research purposes.

An over-the-counter (OTC) broker arranges transactions in financial instruments or crypto-assets directly between buyers and sellers, outside a public exchange or order book. OTC brokers are commonly used for large or customised trades and may negotiate the price, volume, settlement terms, and counterparties privately.

Depending on their activities and jurisdiction, OTC brokers may be subject to licensing, AML/CFT, sanctions-screening, record-keeping, and transaction-monitoring requirements.

P

Payment Fraud refers to any intentional deception, manipulation, or unauthorised act through which a payment transaction is initiated, altered, redirected, or otherwise misused in order to obtain an unlawful financial benefit for the perpetrator or a third party and to cause financial loss to the payer, the payee, or a payment service provider.

The term includes, in particular:

  • unauthorised payment transactions, such as payments made following the theft or misuse of card, account, or authentication data;

  • fraudulently induced authorised payments, where the victim technically authorises the transaction but is induced to do so through false representations, social engineering, impersonation, or other forms of deception;

  • manipulation of the payment process, including the alteration of payment instructions, beneficiary details, or account information;

  • misuse of payment infrastructure, including merchant accounts, payment service providers, money mules, or bank accounts used to receive, transfer, or conceal fraudulently obtained funds.

Payment fraud is therefore broader than the mere unauthorised use of a payment instrument. It also covers transactions that were formally authorised by the payer but where that authorisation was obtained through fraud or deception.

A pig butchering scam is a long-term confidence and investment fraud in which criminals build a fake personal, romantic, or friendly relationship with a victim and then gradually manipulate the victim into transferring money into a fraudulent investment scheme, often involving crypto-assets, fake trading platforms, or fake investment apps. The FBI describes “pig butchering” as a common media term for cryptocurrency investment fraud, while INTERPOL has warned that the term can stigmatise victims and has encouraged more neutral language such as romance baiting or investment scam.

Pishing refers to a scam perpetrated via email.

PISPs – Payment Initiation Service Providers (PISPs)

Permitted Payment Stablecoin Issuers (PPSIs)

Q

Quincecare Duty – The Quincecare Duty was first established in the case of Barclays Bank Plc v Quincecare Ltd [1992] 4 All ER 363. Simply put, it is a duty on a bank to refuse to comply with a payment instruction in circumstances where the bank is on notice that the instruction may be part of a fraud. This duty lasts “unless and until the bank’s inquiries satisfy it that the instruction is validly authorised.

R

FATF Recommendation 15 – New Technologies requires countries and financial institutions to identify, assess, and mitigate money-laundering and terrorist-financing risks arising from new products, business practices, delivery mechanisms, and technologies. It also extends the FATF’s AML/CFT framework to virtual assets and virtual asset service providers (VASPs), which must generally be licensed or registered, supervised, and subject to relevant preventive measures.

Recruited mules are persons whose bank accounts, payment accounts or crypto wallets are used to receive, transfer, withdraw or convert criminal proceeds, often after being recruited through fake job offers, social media, romance scams, “investment” opportunities or promises of easy mone

Regulatory arbitrage refers to the deliberate use of differences between laws, supervisory standards, licensing regimes, or enforcement practices to reduce regulatory obligations, avoid stricter oversight, lower compliance costs, or continue high-risk activity through a more favourable jurisdiction, entity, product structure, or legal classification.

Rotating wallet addresses are frequently changed or newly generated blockchain addresses used to receive, hold, or transfer crypto-assets instead of repeatedly using one fixed address. Address rotation may serve legitimate privacy and security purposes, but it can also make it more difficult to link transactions, identify the parties involved, and trace illicit funds.

RTS – Regulatory Technical Standards  

S

Sand mining is the extraction of sand from rivers, lakes, coastal areas, or land for use primarily in construction and industry. It becomes illegal when carried out without authorisation or in breach of environmental, licensing, tax, or labour rules.

SCA and CSC – Strong Customer Authentication  and Common and Secure Communication 

Scam Compounds – a location where workers, often victims of human trafficking themselves, work in conjunction to defraud victims and launder victim funds.

Smishing scammers make recourse to SMS or instant messages.

Static monitoring is the monitoring of customers, transactions, entities or systems against fixed rules, thresholds, lists or risk indicators, without dynamic adjustment based on behavioural changes, emerging typologies or real-time risk signals.

Strong Customer Authentication (SCA) means a multi-factor authentication process used by payment service providers to verify a payer’s identity through at least two independent elements from the categories of knowledge, possession and inherence. It is designed to reduce unauthorised payments but does not, by itself, exclude fraud, manipulation, social engineering or a PSP’s duty to monitor suspicious transactions.

Suspicious Activity Reports (SARs): are reports submitted by regulated entities, such as banks, payment institutions, crypto-asset service providers or other obliged entities, to the competent Financial Intelligence Unit when they detect facts, patterns or transactions that may indicate money laundering, terrorist financing, fraud or other financial crime.

Synthetic identity fraud refers to the creation and use of a fabricated identity made from a mixture of real, stolen, manipulated, or fictitious personally identifiable information (PII). Instead of simply impersonating one real person, the fraudster constructs a new identity profile — for example by combining a real identification number, stolen data, a fake name, a false address, a manipulated date of birth, or AI-generated documents — and uses it to access financial services, crypto platforms, payment accounts, loans, cards, mule accounts, or online services.

The Federal Reserve defines synthetic identity fraud as using a combination of PII to fabricate a person or entity for dishonest personal or financial gain. FinCEN similarly describes synthetic identity as a combination of real and fake PII used to fabricate a person or entity to pass validation processes

T

THORChain: THORChain is a decentralised liquidity protocol that enables native cross-chain swaps — meaning users can exchange assets across blockchains directly, without wrapped tokens or centralized intermediaries.

TF/PF stands for Terrorist Financing and Proliferation Financing. Terrorist financing refers to the provision or collection of funds for terrorist acts, terrorists, or terrorist organisations. Proliferation financing refers to financial activities that support the development, acquisition, transfer, or use of nuclear, chemical, or biological weapons and their means of delivery.

The original EU Travel Rule under Regulation (EU) 2015/847 applied to transfers of funds, in any currency, carried out at least partly by electronic means through payment service providers. It covered classical payment rails, not only bank wire transfers. Regulation (EU) 2023/1113 extended the same traceability logic to certain crypto-asset transfers involving CASPs. A transfer of funds must be accompanied by information identifying both the payer and the payee: the payer’s name, payment account number and an additional identifier such as address, official document number, customer identification number, or date and place of birth; and the payee’s name and payment account number. Where no payment account is used, a unique transaction identifier must accompany the transfer instead.

A Total Value Locked (TVL) threshold is the minimum amount of crypto-assets deposited, staked, pooled, locked, or otherwise committed in a DeFi protocol or smart contract that triggers a specific risk, compliance, governance, or regulatory response. TVL is commonly used as a proxy for the economic size and systemic relevance of a protocol. Once a protocol exceeds a defined TVL threshold, it may be considered more relevant for financial-crime monitoring, consumer-risk assessment, market-abuse analysis, cybersecurity review, or supervisory scrutiny.

Trade-based transaction laundering refers to the use of trade, e-commerce, merchant accounts, payment processing, invoices, goods, services, or commercial transactions to disguise the true origin, nature, beneficiary, or purpose of payments. It may involve making illicit or high-risk transactions appear as legitimate commercial sales, routing payments through approved merchants, misdescribing goods or services, or using invoices and settlement flows to move value while hiding the real underlying business

Trump’s January 31, 2025 Executive Order 14192: requires that for every new rule an agency proposes that imposes costs “greater than zero”, it must eliminate ten existing rules, and offset any new incremental costs by eliminating costs associated with those ten rules.

U

V

A Virtual Asset Service Provider (VASP) is an entity that, as a business, provides services involving virtual assets for or on behalf of clients. This includes exchanging virtual assets for fiat currency, exchanging one virtual asset for another, transferring virtual assets, safeguarding or administering virtual assets or instruments that enable control over them, or providing financial services related to the issuance or sale of a virtual asset. VASPs are relevant AML/CFT gatekeepers because they can enable access to, movement of, and conversion from virtual assets into the traditional financial system. Under FATF standards, VASPs should be licensed or registered, supervised, and subject to preventive measures such as customer due diligence, record-keeping, suspicious transaction reporting and Travel Rule obligations

Virtual IBAN –  means a payment account identifier in IBAN format that is functionally linked to a separate underlying master payment account, but does not itself constitute an independent payment account. It serves primarily as a routing and allocation reference for incoming payments and enables the identification of a designated end user, sub-account, client, or transaction purpose within the framework of the master account.

Vishing takes place on a telephone call. 

W

Wrapped Tokens are tokenised representations of existing crypto-assets that allow an asset from one blockchain or token standard to be used in another blockchain ecosystem. They are typically intended to be backed 1:1 by the underlying asset, but introduce additional custody, bridge, smart-contract and redemption risks.

X

Z

ZKP – Zero-Knowledge Proof
A zero-knowledge proof is a cryptographic method that allows one party to prove to another party that a statement is true without revealing the underlying information that makes the statement true. In financial and crypto-related contexts, ZKPs can be used to verify data, identities, balances or transactions while preserving confidentiality.