Leak reveals $2T of possibly corrupt US financial activity
theguardian.com
theguardian.com
https://news.ycombinator.com/item?id=24535241 (535 points/220 comments)
https://news.ycombinator.com/item?id=24535903 (131 points/16 comments)
https://news.ycombinator.com/item?id=24539132 (110 points/26 comments)
https://news.ycombinator.com/item?id=24536630 (83 points)
> “The Financial Crimes Enforcement Network is aware that various media outlets intend to publish a series of articles based on unlawfully disclosed suspicious activity reports (SARs), as well as other sensitive government documents, from several years ago,” it stated.
> “As FinCEN has stated previously, the unauthorised disclosure of SARs is a crime that can impact the national security of the United States, compromise law enforcement investigations, and threaten the safety and security of the institutions and individuals who file such reports
Government response: Punish the leakers
Collateral Damage, Snowden panama papers...
Imagine if they spend 10% of resources that they spent going after leakers punishing real perpetrators.
You’re asking for something to be proved - or supporting evidence that requires a whole dissertation - because your exposure is starting from a position that is fundamentally wrong.
“Suspicious” is a misnomer referring to an automatic reporting threshold, that in fewer additional circumstances allows for discretion in filing. The end.
I’m baffled how asking for data is revealing my position?
I had the hope that your position is well founded and it would be easy to point to actual data.
I hardly believe that the compliance laws are not accompanied by studies that collect the data that i asked for. So it should be out there.
Good luck.
It's certainly conventional wisdom in financial circles that a SAR is worth about as much as a user report on a Reddit comment.
If they are, they probably don't want the perpetrators to know how much information they have.
If so, their cases may have just been blown apart by these leaks, and the perpetrators are even less likely to get persecuted.
Didn't we have many financial crime leaks this past decade with essentially no repercussions?
>Twenty-three countries have already recovered at least US$1.2 billion in taxes, heads of government implicated in corruption or tax avoidance have resigned or faced prosecution and there have been investigations in at least 82 countries. Mossack Fonseca, the law firm at the centre of the story, has shut down and the Panama Papers have prompted high-level political debates and expedited policy reforms around the world
https://www.transparency.org/en/news/three-years-after-the-p...
So it seems what I said is still correct... almost no repercussions for white collar crime across the globe. I'd bet it still occurs rampantly.
What happened?
Some people had to pay fines. The company paid a small fine with no charges filed. Leaker went to prison.
The system is completely corrupt.
Edit: you don’t publish your company’s proprietary source code and then expect you just walk away right? You’d be sued into oblivion. It’s important that people abide by their agreements. Whistleblower statutes exist to ensure protection when fraud, abuse, or other illegal activity occurs. I’m not clear if this actually meets that standard.
For what it’s worth, the problem is that most folks don’t know what SARs are, when they’re filed, etc. This is basically the equivalent of leaking a bunch of private banking records that banks have to provide to the government, not “leaking hidden crimes that nobody stopped”
It’s financial crimes. If someone leaked investigational records of say, the FBI, while they are investigating an extortion ring, that could seriously compromise any prosecution.
Seems reasonable to me to punish someone leaking information that was meant to be private.
I recently read "Treasure Islands: Tax Havens and the Men who stole the world" and can't recommend it highly enough. It shows that tax fraud and offshore banking is despite propaganda that "it's dead" very much alive and the US is a central player now. Hollywood still uses Switzerland and the Cayman's but a lot more convenient are setups involving Nevada, New Mexico, etc.
Offshore banking is a key component in maintaining control when an empire retreats/collapses. The French installed puppets in Gabon who let them launder their money until today in a similar fashion that the City of London and the more reckless jurisdictions (BVI) allowed the Brits to keep their loot which they stole in the past 200 years.
we had a chance to burn all this to the ground during the financial crisis but Occupy Wallstreet was just a "leaflet campaign" without teeth. You don't fight a real enemy that subverts the rules of democracy with democratic tools.
https://en.wikipedia.org/wiki/Treasure_Islands:_Tax_Havens_a...
https://www.theguardian.com/world/2019/nov/14/the-great-amer...
I think you meant to write something like:
You don't fight a real enemy that subverts the rules of democracy with subverted democratic tools.
One of the main reasons FinCEN requires strict confidentiality on SARs is to not tip off the account owners that they're being watched/investigated.
Investigators will often monitor the accounts to gather enough evidence to prosecute them or to gain intel into broader criminal networks. Regulators also rightfully don't want money launderers to know the playbook and tactics they use to track down these networks.
The secrecy also protects bank employees. If you're a compliance department worker that's reporting on potential criminal activities of terrorists or a criminal network to the authorities, and you think there's a risk you'll be outed, you might be less willing to submit the SAR.
No. It will generate a CTR. It may generate a SAR.
Not a bank employee leaking the data.
Why would they leak it? Cause they know the system is fubar.
The simple question to ask is how many people are needed to monitor the system.
Now you have one clown after another saying the banks file zillions of reports every day.
Thats not the issue. Someone has to monitor all that.
And when that someone realizes they arent making a dent, given the volumes, they get sick of the pointlessness and leak the DB.
This is going to keep happening. Swiss leaks, Panama papers, libor etc etc
We have learnt how to scale things up over the last 20 year exponentially.
But oversight can't scale exponentially.
It's unsustainable and pressure will build to ridiculous levels on regulators and law enforcement.
National security...
Seems China practiced this excuse so well that US decides to copy that...
https://www.occ.treas.gov/topics/supervision-and-examination...
Keep records of cash purchases of negotiable instruments, File reports of cash transactions exceeding $10,000 (daily aggregate amount), and Report suspicious activity that might signal criminal activity (e.g., money laundering, tax evasion)
If you do more than $10,000 in cash business/transactions, the bank will (must) file a report -- if you're deposit $8000 one day and $4000 the next day, the bank might be forced to consider it a single transaction for $12,000 -- and file a SAR.
There's fantastic reasons to keep this confidential -- Given that requirements to file are so broad, almost all of these are going to be normal business activity.
Transactions over $10k aren't automatically a SAR.
https://en.wikipedia.org/wiki/Currency_transaction_report
> CTRs since 1996 include an optional checkbox at the top if the bank employee believes the transaction to be suspicious or fraudulent, commonly called a SAR, or Suspicious Activity Referral.
* Depositing $9,999 cash (yeah, still gonna report that)
* Depositing random X,000 cash increments across multiple transactions (yeah, still going to report that)
* Making cash deposits across multiple locations in the same day/week (as if the computer didn’t alert us to multiple cash deposits)
* make sure the deposits are under $9000, but also not some amount that's "suspicious" like $8,999
* make sure the deposits happen on a regular interval
* make sure the deposits are at the same branch
I also suspect banks don't share information to generate SAR (eg. a deposit of $15,000 at one bank would generate a SAR, but a deposit of $7,500 at two banks on the same day won't generate a SAR), so if you need to deposit more cash then all you need to do is open more accounts at more banks.
$10k is just the automatic threshold for a CTR. A $1 transaction could cause a SAR to be filed, if there was a reason for the bank to be suspicious of it.
In a lot of countries if you establish a small company and open a bank account for it they will just do the bare minimum, after all if you got a tax number and just got a new company registered you already jumped through a few background check hoops.
Of course they will still run your name through their whatever systems. And eventually if your business starts transacting it'll be constantly looked at by the automated systems.
As long as you don't do anything suspicious, no one will care.
Basically if you behave like all the small shops that have to deposit cash, no one will look twice.
Also, cash is not interesting, the problem is when you start to wire money (or get transfers) to/from places that small kitchens usually don't. And that's when risk and compliance departments might notice the activity.
No, the bank doesn't ask for receipts or stake out businesses.
If that business has a transaction profile that's out of line with the 'similar business' model, they potentially get flagged.
Side note: I see this kind of response a lot on HN. Whenever a precisely-defined law or regulation comes up, there will be the inevitable tricksy engineers pointing out a bug in the program. Except they haven't read the whole program, but only a couple of stanzas. And it's not actually a program. It's not being interpreted by a computer, but by people. At a certain point, rules-laywering will get the actual lawyers to tell you to get out of here with that.
Repeating something I've written here before: Your adversaries are people, not bash scripts.
Nothing? Nowhere near the thresholds.
Untraceable entries/exits: cash, money orders, cashier checks, wire transfers, etc.
"Deposit $9,999 to fool the IRS" is up there with "Consult with top divorce lawyers to keep them from representing you spouse" in the Hall of Bad Legal Advice.
I think it's important to get the right mindset on what these are before we cry foul.
All banks will report 'large' transactions to their country's Financial Intelligence bureau. In the US, that's FINCEN. In Canada, that's FINTRAC, where I interned way back in 2006. Here, that means for all transactions over $10,000 CAD (or if the sum of transactions from an account within 24 hours exceeds $10,000), a report is filed, and FINTRAC keeps the report for 5 years while they look for signs of money laundering or terrorist financing. They data mine this to find patterns that indicate criminal activity. In 2006, while I was an intern, the Montreal mafia was brought down this way.
Suspicious Activity Reports, SARs are just what they sound like- the banker says 'something smells funny about this'. They want to let someone know about it. For example, let's say there's a particular person who moves $9,999 every day from his account to another one. That's under the $10,000 reporting limit but the bank can say "That's a bit weird, let's report it with an SAR". They can provide more details of why they're concerned.
The banks aren't the police. They don't know a crime has taken place. That person moving $9,999 every day could be doing something not criminal at all. And it's not the banks place to stop them- because that is just ripe for abuse. "Hey, I think all people of <race> are suspicious, so anytime they move $1000 or more, I file an SAR and close their accounts". Or "Hey, that guy is part of <political organization which I don't agree with>, so I flag all his transactions with SARs".
In this case, there are SARs leaked related to some large transactions involving suspicious circumstances. That doesn't mean there's a crime! But it does mean that someone raised an eyebrow and flagged something so that it could be followed up on by the right government authorities.
It's up to the US FINCEN to decide if a crime took place and to handle it accordingly. You decide if you trust them or not, but that is their role in this.
(Do I think Paul Manafort is innocent? That is a whole different question.)
If money enters or leaves a bank account in a quantity greater than $10k within 24 hours, a report is filed with every detail they know about you and about the transactions.
This has been law for more than 20 years. And it's made money laundering really, really hard.
CTRs (https://en.wikipedia.org/wiki/Currency_transaction_report) are not SARs.
You can have a large transaction that isn't deemed suspicious by your bank. You can have a tiny transaction that is deemed suspicious by your bank, too. CTR = "big transaction". SAR = "suspicious transaction". Often related; not identical.
If you ever move $10,000 into our out of your bank account, a report is filed with your country's FinInt agency. Every time. It has whatever ID numbers you gave when you opened the bank account, everything else they know about you, and where the money moved from and to.
In Canada (and maybe the US as well?), this also includes large cash transactions with currency converters, casinos, and jewelry stores- because people kept finding new tricks for moving around money.
Edit: And this is why leaking these things is super serious! There's a lot of personal information in them!
> It's up to the US FINCEN to decide if a crime took place and to handle it accordingly. You decide if you trust them or not, but that is their role in this.
Who watches the watchmen?
The US Attorney, who'd receive the information and decide whether or not to prosecute, and the juries/courts involved in that prosecution. Plus, the typical regulatory loop of Congress, courts, etc. involved in the all of the Department of the Treasury's doings.
First these are 2000 SARs over a period of 8 years, so if SARs get filled very often (I have no idea if they do), then this would be a very select few of them. Maybe someone already did a selection based on the specific activity?!
Second this is $2 Tn in 2000 transactions I leave it as an excersise to calculate how much on average that is, but you can be assured this is not some random person buying. I would wager that most nation states very rarely move that amount of money around.
My gut says these leaked reports will have a greater negative impact on current corruption investigations than any positive impact from public consumption.
Does that sum it up pretty well? You seem to have a pretty vested interest in this being ignored if judged by the volume of similar comments you've left in this thread.
A suspicious activity report is not about a crime, it isn't about anything being suspected of a crime or even actually suspicious.
SARs are an ill thought compliance nuance created by Congress 50 years ago with a ridiculous name.
The headline even has a vested interested in covering its own ass with the wording "possibly corrupt" because their own legal department was like "really?" and the editor in chief was like "but think of the clicks!"
TFA literally makes no accusations, it is simply stating the facts. Manafort was convicted of money laundering and fraud, and the fact that many of these reports were filed on him makes it seem like the system is working as intended. Similarly, Mogilevich is wanted by the FBI. Maybe that should mean there's a reason for banks to stop doing business with him?
No one here is arguing that banks should be required to stop doing business with anyone who triggers one of these reports. The point is that based on retrospect, they haven't been doing a good job of operating on the information they have, so maybe it's time to actually give such a law teeth.
2000+ reports from between 1999 to 2017 amounting to a total of $2tn. Of those reports they only name-check Manafort, a Russian oligarch, and HSBC. How many people are feeling outrage because of the perceived connection between the current administration and corruption when these reports also cover years from the previous 3 administrations? How many characters connected to powerful Democrats could be found among these 2000 reports?
What if someone at the IRS leaked their flagged accounts as "possible tax fraud" or if Google leaked suspicious traffic logs as "possible cyber terrorism"? How much information could the general public be expected to glean about actual bad actors based on similar reporting? How many people here actually understand what an SAR contains and why it is created? Can anyone cite me what % of SARs turn out to be indicators of actual crimes?
I don't doubt that many of the people in these reports are guilty of crimes, but corruption investigations also take a long time and the more recent reports may very well be relevant to ongoing investigations and having them made public could spook suspects before authorities have gathered enough evidence to bring a charge.
That is all, carry on.
So this isn't new "they're not taking this seriously" allegations; it's a methods leak. As a aggressively-pro-transparency advocate, this seems like... a reasonable thing to keep secret, no?
Am I missing something? JP Morgan did the right thing; HSBC was _already known_ to be failing to stop fraudulent transfers; and there's no allegations of impropriety on the part of the government.
Seriously: what's the motivation behind the leak?
To let criminals know which banks they can trust?
Have never been able to determine if what someone told me is true... that publicly traded companies are exempt from many of these regulations.
Imagine going to your bank and trying to withdraw $3000 or $5000 in cash, and them asking you to fill out a CTR out of an abundance of caution (like the fact that you’ve never made a cash withdrawal of that size before).
Don’t feel like filling out extra forms to get access to your own money? In a hurry and don’t have time? Decline the CTR and say you’ll deal with it another time?
It’s now a criminal offense for the bank to not file a SAR based on your refusal to complete the requested CTR.
Quoted from above page on SAR reports:
Under the Bank Secrecy Act (BSA), financial institutions are required to assist U.S. government agencies in detecting and preventing money laundering, such as:
-Keep records of cash purchases of negotiable instruments,
-File reports of cash transactions exceeding $10,000 (daily aggregate amount), and
-Report suspicious activity that might signal criminal activity (e.g., money laundering, tax evasion).
This feels broken. Was this intended to prevent competitors from falsely filing SARs against each other to freeze their business? What are the penalties for abusing this system?
It sounds like banks file SARs about their own clients. I'm guessing they don't have to cease doing business with the client because that would create an incentive not to file SARs.
"Hey, this persons makes mostly foreign transactions with vague companies" is a SAR. That's not a crime, and it may not be criminal behavior - it's just an indicator that someone should look closer.
Can you imagine if your bank closed your account and refused to do business with you, without any kind of trial or notification, just because you did something that triggered a fraud measure?
Or to put this another way, how many times have you had to call your credit card provider because they stopped a transaction just because it was suspicious, even when it wasn't?
Ugh. I'd pay more for a credit card which didn't block my own transactions. Using a US credit card abroad can be seriously frustrating.
The only thing worse than rapidly increasing airfares on small airlines with websites which barely work is when your credit card refuses to complete the transaction, requiring multiple international phone calls to resolve.
But if they’re leaked - that means reputational damage risk is higher so you’ll get less reports from banks and likely make it a lot harder to see patterns of illegal behavior. That’s why this agreement is in place.
Cash heavy businesses could easily hit this level, as well as large transactions that are perfectly legal, so you wouldn't want to stop doing business with a customer, just because they deposited a large amount of cash.
[1] https://www.occ.treas.gov/topics/supervision-and-examination...
The immense pressure of money laundering comes with a lot of consequences to the cost of transactions, the utilization of commercial banks as part of monetary policy, etc. This is one of the core reasons why bitcoin exists, to precisely avoid these kind of banking issues.
Moreover its over-sensationalized with the conflation between money and wealth. All the dollars stashed away in a cayman islands account is doing no harm to anyone: its depreciating as it is as a holding. Money has no effect unless its spent. And whatever is spent is just as good as regular consumption. It's not even in the interest of government to get the money back: if a few trillion dollars were suddently released into circulation you would have inflation and would not be able to print money that gov is already spending.
Following the money to fight crime has been a ruse.
With each transfer, my investment company has me fill-out / sign a form declaring Source of Funds.
If the gov’t finds anything suspicious, there’s an airtight paper-trail for all these transactions.
Nothing to see here.
https://finance.yahoo.com/news/pentagon-35-trillion-accounti...
The 2 trillion we are talking about is 'corrupt' financial activity. Money laundering and this sort of thing.
Pentagon financial adjustments are not even close to being related.
Lastly the article you posted says 35 trillion in adjustments, but doesn't say how far back in time they went making adjustments, so that number is meaningless. Whoever this reporter is seems to not be familiar with accounting or finance.