/ KYB Watch
AML & Financial Crime

Xinbi shows how criminal networks migrate across platforms and payment rails

The Xinbi case shows how illicit networks can migrate across marketplaces, apps and payment rails after regulatory intervention.

U.S. Department of the Treasury / OFAC
September 9, 2026
Multiple regions
Analysis by Detelio
Geometric editorial illustration of interconnected service nodes rerouting around a disrupted central network hub.

What happened

On 9 September, the U.S. Treasury’s Office of Foreign Assets Control designated Xinbi Guarantee as a significant transnational criminal organisation, while the Department of Justice’s Scam Center Strike Force seized infrastructure and digital-asset wallets associated with the marketplace.

Treasury describes Xinbi as a Chinese-language illicit marketplace connecting scam-centre operators and other criminal syndicates with merchants providing financial services, technology and other support. The platform also provided escrow services to scam operators, money-laundering networks and cybercrime syndicates. Since its inception around 2022, Treasury says Xinbi’s marketplace processed the equivalent of more than $24 billion in digital assets and fiat currency, primarily facilitating transactions in Southeast Asia.

The case is particularly notable for what happened after earlier regulatory intervention. Treasury says that after FinCEN identified Huione Pay as a financial institution of primary money-laundering concern, cybercriminals attempted to preserve their operations by moving activity to Xinbi, which offered substantially similar services to an overlapping customer base.

Treasury also designated two technology companies supporting Xinbi. As law-enforcement scrutiny increased, Xinbi began migrating its merchant and money-laundering networks to the encrypted SafeW application, developed by Singapore-based SafeW Technology. At roughly the same time, Xinbi launched XinbiPay, also known as NewPay, a cryptocurrency payment and digital-wallet application developed by Cambodia-based Anwen Technology.

In the coordinated enforcement action, DOJ says it seized two cryptocurrency wallets used by Xinbi to collect payments for vendors and sought restraint of 47 additional wallets associated with money laundering on the network. More than $52 million in cryptocurrency was restrained from Xinbi and its vendor network.

The Treasury action and DOJ seizure action show a criminal-service ecosystem moving across marketplaces, applications and payment infrastructure rather than depending on a single entity or channel.

Why it matters for KYB teams

The KYB lesson is not simply that Xinbi and its supporting companies now require sanctions screening. The more important operational issue is risk migration: when one provider becomes unusable after regulatory action, the same customers, merchants and facilitators can reappear through another marketplace, application or payment rail.

A workflow that treats each legal entity or platform as an isolated record can miss that continuity. Effective KYB monitoring should preserve relationships between businesses, service providers, counterparties and other relevant identifiers so that newly identified risk can trigger a wider portfolio review rather than only an alert on the named entity.

The designation of Anwen Technology and SafeW Technology also illustrates why business-model context matters. Treasury says these companies provided applications that supported Xinbi’s operations. A company does not need to be the marketplace moving illicit funds directly to become material to the network around it. KYB teams therefore need to understand what a business provides, who relies on it and whether changes in its counterparties or operating model alter the relationship’s risk.

This strengthens the case for continuous monitoring that can re-evaluate an existing relationship when new entities, counterparties or risk signals become connected to it. Where a connection triggers escalation, the evidence and reasoning behind the resulting decision should remain reconstructable through a connected audit trail.

This is an operational interpretation of the case, not an indication that every technology provider or payment application connected to a high-risk sector should automatically be treated as suspicious.

What teams should review

  • Can a newly sanctioned or high-risk entity trigger a portfolio-wide search for connected customers, counterparties and service providers?
  • Are relationships between legal entities, platforms, applications and relevant counterparties retained in a form reviewers can query later?
  • Can monitoring identify when activity migrates from a previously restricted provider to a successor platform offering similar services?
  • Does the risk assessment capture what a technology or payment provider actually enables, rather than relying only on its registered business category?
  • Can changes in counterparties, payment rails or operating model trigger re-risking even when the customer’s legal identity has not changed?
  • When network risk causes escalation, are the source evidence, reviewer rationale and final disposition preserved together?
U.S. Department of the Treasury / OFAC
Government
September 9, 2026
Read the official update
Paper airplane icon representing sending an invitation or dispatching a report.

Get new updates occasionally

Important KYB, AML, ownership, monitoring, and enforcement developments

Thanks, you’re subscribed.
Something went wrong. Please try again.
Heading
This is some text inside of a div block.
Request a demo