Financial Integrity Monitor

United States — Idaho US-ID

Domains (D1–D6)
6
Sources
10
Role actions
8
Jurisdiction profile
CompliantTier BRisk: IncreasingMixed

Idaho operates under the federal BSA/AML framework (FinCEN, OFAC) with state-level money transmitter licensing administered by the Idaho Department of Finance.

MoreNo Idaho-specific BO registry exists; the state relies on the federal CTA regime, now sharply narrowed. State AML supervisory capacity is modest relative to crypto-enabled fraud exposure.

Key deficiencies
  • No state beneficial-ownership registry; Idaho-formed LLCs/corporations now face no operative BO disclosure obligation at either state or federal level following FinCEN's 2025 CTA domestic rollback
  • Idaho has not joined the multistate AG enforcement wave against crypto-ATM operators (Bitcoin Depot, CoinFlip, Athena Bitcoin) despite documented high-volume local scam-wallet exposure
  • Limited publicly available Idaho-specific AML/CFT enforcement data (state primary sourcing is thin relative to national datasets)
Recent developments (18m)
  • FinCEN interim final rule (March 26, 2025) exempted all domestic reporting companies, including Idaho-formed entities, from Corporate Transparency Act beneficial-ownership reporting
  • FinCEN Notice FIN-2025-NTC1 (August 4, 2025) on convertible virtual currency kiosks, directly applicable to Idaho-licensed money transmitters operating crypto ATMs
  • DOJ/FBI $112 million multi-district pig-butchering cryptocurrency seizure, with seizure warrants authorized by a federal judge in the District of Idaho
  • ICIJ 'Coin Laundry' investigation documented a Boise Police Department detective's identification of a single recurring Bitcoin Depot-linked wallet address used in over 100 Idaho-area scam cases
Weekly brief

Lead signal

Lead Signal

Read full brief

Lead Signal

The first full-cycle financial-integrity baseline for Idaho surfaces two structural findings that outweigh any single enforcement episode: a reopened beneficial-ownership opacity vector affecting every Idaho-formed entity, and a documented crypto-ATM cash-out architecture servicing scam networks that has drawn no state-level enforcement response. Following the March 2025 FinCEN interim final rule, Idaho-formed LLCs and corporations are no longer required to disclose beneficial ownership under the Corporate Transparency Act, and because the Idaho Secretary of State registry does not independently collect beneficial-ownership data, Idaho entities now sit outside beneficial-ownership disclosure at both the state and federal level. This is an architecture-level regression, not an isolated policy choice: the rule remains an interim final rule under a 60-day comment period, and its durability is contingent on unresolved appellate litigation and a promised final rulemaking, a status the original framing of the exemption understated by presenting it as settled policy.

Running in parallel, a Boise Police Department detective identified a single Bitcoin Depot-linked wallet address recurring across more than 100 separate Idaho-area scam investigations, illustrating how a small number of upstream crypto-ATM liquidity providers can service a geographically dispersed low-level fraud economy. Idaho functions simultaneously as a victim-origination point and an investigative venue: a separate 112 million US dollar multi-district pig-butchering seizure required parallel warrants authorized by federal judges in Arizona, California, and Idaho, evidencing commingled laundering flows rather than a discrete local incident.

Other Developments

Sanctions architecture continues to diverge across the Atlantic. The OFAC re-designation of Garantex successor Grinex and the A7A5 ruble-backed token targets a continuing Russian crypto-based cross-border settlement rail used for sanctions evasion; EU and UK regimes track OFAC designations with a lag, creating a temporary compliance window that Idaho-licensed institutions must independently manage through their own sanctions-screening programs. A parallel unilateral pattern appears in counter-narcotics enforcement. OFAC designated Armando de Jesus Ojeda Aviles and associates for converting bulk US cash drug proceeds into cryptocurrency for cross-border transfer to Mexico; no parallel EU or OFSI designation has been identified, illustrating a unilateral OFAC-led approach to cartel-finance sanctions relative to European counter-narcotics sanctions architecture. A third designation connects US domestic fraud losses to an active foreign conflict. OFAC designated the Democratic Karen Benevolent Army, its senior leadership, and affiliated companies for supporting Myanmar-based cyber scam centers targeting Americans, alongside the DOJ, FBI, and Secret Service establishment of a Scam Center Strike Force; again, no parallel EU or UK designation has been identified.

The United States retains a clean standing on the FATF list architecture. As of the 19 June 2026 plenary, the United States is not listed on either the FATF Jurisdictions Under Increased Monitoring list or the Call for Action list, a status Idaho inherits federally, though Idaho-licensed institutions must still apply enhanced due diligence to counterparties in grey-listed jurisdictions; this clean status is scheduled for re-verification at the October 2026 plenary.

Idaho has not joined the multistate enforcement wave against crypto-ATM operators pursued by several peer states. No Idaho Attorney General or Department of Finance enforcement action against Bitcoin Depot, CoinFlip, or Athena Bitcoin has been identified, in contrast to peer states, though this absence may partly reflect sourcing thinness specific to Idaho rather than a confirmed enforcement gap.

A federal rulemaking horizon item will extend obligations to stablecoin issuers. The GENIUS Act permitted payment stablecoin issuer AML/CFT rulemaking, a joint FinCEN and OFAC notice of proposed rulemaking under docket FINCEN-2026-0100, is at the consultation stage and expected within the 2026-to-mid-2027 window; it will directly affect any Idaho-domiciled or Idaho-licensed stablecoin issuer. Separately, FinCEN Notice FIN-2025-NTC1 reaffirms that 31 CFR 1022.320 SAR and CTR obligations apply to convertible-virtual-currency kiosk operators nationwide, including Idaho-licensed operators.

Cross-Monitor Connections

The Democratic Karen Benevolent Army designation links a US domestic fraud-victim channel, including Idaho victims, to an armed ethnic organization operating within the internal conflict in Myanmar, warranting SCEM review of the conflict-finance nexus underlying DKBA scam-center revenue. The same designation, alongside Chinese organized-crime-linked companies supporting the Myanmar scam-center network, is flagged for WDM review of state-capture and quasi-state criminal-network dynamics in the region, assessed at Possible confidence. Separately, the continuing pattern of OFAC-led designations against the Russian Garantex, Grinex, and A7A5 crypto settlement rail, running ahead of EU and UK listings, is a macro-relevant sanctions-architecture divergence signal flagged for GMM tracking of sanctions as a macro variable.

Outlook

The Idaho jurisdiction risk trajectory is assessed as increasing, driven by a combination of crypto-enabled fraud exposure and a reopened beneficial-ownership opacity vector, set against a mixed enforcement-versus-enablement balance overall. The durability of the beneficial-ownership exemption remains genuinely unresolved: it rests on an interim final rule subject to a comment period, pending appellate litigation, and a promised final rulemaking, any of which could restore, narrow, or permanently repeal domestic reporting obligations. On the digital-asset side, the pending GENIUS Act stablecoin rulemaking and the FinCEN kiosk notice point toward tightening federal obligations, but state-level consumer-protection enforcement against crypto-ATM operators has not yet kept pace with documented local exposure, and whether Idaho joins the peer-state enforcement wave is a genuine open question for the next cycle.

weekly_brief_draft · JID US-ID
Domain intelligence (D1–D6)

D1 Sanctions Architecture and Evasion

Sanctions Architecture and Evasion

Continue reading

Three new OFAC designations this cycle bear directly on the sanctions-screening obligations of Idaho-licensed institutions, and each illustrates a variant of the same structural pattern: unilateral United States action running ahead of counterpart European sanctions regimes. The OFAC re-designation of Russian exchange Garantex successor Grinex, together with the A7A5 ruble-backed token, targets a continuing crypto-based cross-border settlement rail engineered to survive prior sanctions action. The EU and UK regimes track OFAC designations with a lag, which creates a temporary compliance window; Idaho-licensed virtual-asset service providers and banks with crypto-asset counterparties must independently manage screening against the newly designated entities rather than relying on parallel EU or UK listings appearing on any predictable timetable.

A second designation targeted a Sinaloa Cartel-run network, led by Armando de Jesus Ojeda Aviles, that converted bulk US cash drug proceeds into cryptocurrency for cross-border transfer to Mexico. No parallel EU or OFSI designation has been identified for this network, a further instance of the unilateral OFAC-led posture that characterizes US cartel-finance sanctions relative to European practice. A third designation, targeting the Democratic Karen Benevolent Army and its senior leadership and affiliated companies for supporting Myanmar-based cyber scam centers targeting Americans, was issued alongside DOJ, FBI, and Secret Service establishment of a new Scam Center Strike Force; here too, no equivalent EU or UK designation has been identified.

For Idaho specifically, none of these three designations name an Idaho-based entity or corridor directly; Idaho exposure is structural rather than incident-specific, running through the federal OFAC and BSA sanctions-screening obligations that all Idaho-licensed institutions inherit regardless of state boundary. Idaho retains a clean FATF standing: the United States is not listed on either the FATF Jurisdictions Under Increased Monitoring list or the Call for Action list as of the 19 June 2026 plenary, a status Idaho inherits federally. Enhanced due diligence remains a live obligation, however, for counterparties of Idaho-licensed institutions located in currently grey-listed jurisdictions, and this clean status is due for re-verification at the October 2026 plenary rather than being a permanent condition.

Read together, the three designations and the clean FATF status describe a jurisdiction where sanctions-architecture risk is imported rather than locally generated: Idaho does not produce sanctions-evasion infrastructure of its own, but its licensed institutions sit downstream of a federal sanctions regime that continues to designate crypto-settlement rails, cartel-finance networks, and conflict-adjacent scam-center enablers faster than counterpart European authorities can mirror. The structurally significant finding is not any one designation but the persistence of the EU-UK lag itself, which creates a recurring compliance-window architecture that Idaho-licensed institutions must manage through independent internal sanctions-list monitoring rather than through reliance on regime convergence.

Two of the three designations carry a dimension beyond ordinary money-laundering enforcement. The DKBA designation satisfies both the sanctions-architecture and conflict-finance filters simultaneously, since the underlying scam-center revenue is understood to finance an armed ethnic organization operating within the internal conflict in Myanmar, and this connection has been separately flagged for cross-monitor review by SCEM, for the conflict-finance context, and by WDM, at Possible confidence, for the state-capture and quasi-state criminal-network dimension given reported Chinese organized-crime company involvement. The Sinaloa Cartel designation likewise sits at the intersection of AML and counter-narcotics-finance objectives rather than as a pure money-laundering matter. Idaho-licensed institutions should read all three designations through this cross-pillar lens rather than treating them as routine AML list updates, since the DKBA and Sinaloa Cartel designations in particular reflect the three-pillar balance principle applied by this monitor, under which CTF and CPF findings are frequently under-weighted relative to AML enforcement volume.

The Russia-related re-designation of Grinex and A7A5 also merits separate note as the most durable of the three signals: it represents at least a second identified iteration of the same underlying settlement-rail architecture following the original Garantex action, illustrating that sanctions-evasion infrastructure is frequently rebuilt rather than eliminated by a single designation, a pattern this monitor has previously documented in other crypto-settlement contexts and one that Idaho-licensed institutions with any Russia-adjacent correspondent exposure should treat as a standing rather than one-time screening requirement.

Outlook

The near-term outlook for the Idaho sanctions-architecture exposure turns on whether EU and UK authorities move to mirror the Grinex, A7A5, Sinaloa Cartel, and DKBA designations, and on what further OFAC action follows against adjacent nodes in the same networks. Absent EU-UK convergence, the compliance-window pattern is likely to recur with each new OFAC action, placing continued weight on independent sanctions-screening capability at Idaho-licensed institutions rather than on any assumption of automatic multilateral alignment. The October 2026 FATF plenary is the next scheduled point at which the clean grey-list standing of the United States will be reassessed.

Cumulative analysis

Sanctions Architecture and Evasion — Cumulative Analysis

This is the first full-cycle sanctions-architecture baseline established for the Idaho (US-ID) jurisdiction profile within the Financial Integrity Monitor. The baseline finds that Idaho sanctions-architecture exposure is structural rather than locally generated: no Idaho-based entity or transit corridor has been identified in any reviewed Russian sanctions-evasion reporting, cartel-finance network, or Myanmar scam-center financing chain. Instead, Idaho-licensed institutions inherit exposure entirely through the federal OFAC and Bank Secrecy Act sanctions-screening framework that applies uniformly across US states.

The baseline cycle documents three concurrent OFAC designation actions: a re-designation of Russian exchange Garantex successor Grinex together with the A7A5 ruble-backed token, targeting a continuing Russian crypto-based cross-border settlement rail; a designation of a Sinaloa Cartel-run crypto money-laundering network converting bulk US cash drug proceeds into cryptocurrency for transfer to Mexico; and a designation of the Democratic Karen Benevolent Army and affiliated companies for supporting Myanmar-based cyber scam centers targeting Americans, issued alongside a new multi-agency Scam Center Strike Force. In each case, no parallel EU or UK designation has yet been identified, establishing a recurring pattern of OFAC-led unilateral action that this baseline treats as the primary structural signal, rather than treating any single designation as a standalone incident. The EU-UK designation lag creates what this monitor characterizes as a temporary compliance window: a period during which Idaho-licensed institutions with crypto-asset or correspondent-banking exposure must rely on independent internal sanctions-screening against the OFAC list rather than assuming multilateral alignment will follow on a predictable schedule.

Against this designation activity, the baseline also establishes the inherited FATF standing of Idaho: the United States is not listed on either FATF list as of the June 2026 plenary, a clean status that nonetheless requires Idaho-licensed institutions to apply enhanced due diligence to counterparties in currently grey-listed jurisdictions, and that is scheduled for re-verification at the October 2026 plenary rather than standing as a permanent condition.

Two of the three designations documented in this baseline carry a dimension beyond ordinary money-laundering enforcement. The DKBA designation satisfies both the sanctions-architecture and conflict-finance filters simultaneously, given the underlying scam-center revenue is understood to finance an armed ethnic organization operating within the internal conflict in Myanmar; this baseline has flagged that connection for SCEM review of the conflict-finance context and for WDM review, at Possible confidence, of the state-capture and quasi-state criminal-network dimension given reported Chinese organized-crime company involvement in the same network. The Sinaloa Cartel designation similarly sits at the intersection of AML and counter-narcotics-finance objectives. This baseline treats both designations as evidence that the three-pillar balance principle, under which CTF and CPF findings are structurally under-weighted relative to AML enforcement volume, is a live concern for the Idaho sanctions-architecture exposure and not merely a theoretical one.

The Grinex and A7A5 re-designation also merits standing note as the most durable signal in this baseline: it represents at least a second identified iteration of the underlying Russian settlement-rail architecture following the original Garantex action, illustrating that sanctions-evasion infrastructure is frequently rebuilt rather than permanently eliminated by a single designation. This baseline treats Russia-adjacent correspondent and crypto-asset screening as a standing requirement for any Idaho-licensed institution with relevant exposure, rather than a response to a single, closed event.

Taken as a whole, this baseline positions the Idaho sanctions-architecture domain as importer rather than generator of risk: every documented designation this cycle targets an entity or network with no Idaho nexus, yet each carries direct screening implications for Idaho-licensed institutions through the uniform federal BSA and OFAC framework. This is consistent with the architecture-over-incident principle applied by this monitor, under which the structural condition, an EU-UK designation lag that Idaho-licensed institutions must independently manage, is the more analytically significant finding than any single designation considered in isolation. Subsequent baselines should track whether this importer-only pattern persists or whether an Idaho-specific transit or facilitation nexus eventually emerges within reviewed reporting.

Outlook

Future cycles should test whether EU and UK authorities move to mirror the designations documented in this baseline, whether the compliance-window pattern recurs with subsequent OFAC actions, and whether the United States retains its clean FATF standing at the October 2026 plenary. Any Idaho-specific transit or facilitation nexus emerging in later reporting would represent a material escalation from the current structural-exposure-only baseline.

domain_sub_briefs · D1 · Cumulative analysis

D2 Beneficial Ownership and Corporate Transparency

Beneficial Ownership and Corporate Transparency

Continue reading

The beneficial-ownership exposure of Idaho itself is the primary subject here, and it has moved in a single direction this cycle: away from disclosure. Idaho maintains no independent state-level beneficial-ownership registry; corporate filings held by the Idaho Secretary of State capture only registered agents and officers, not beneficial owners. Until early 2025 this state-level gap was offset by the federal Corporate Transparency Act beneficial-ownership reporting requirement, which applied to Idaho-formed LLCs and corporations as domestic reporting companies. The March 2025 FinCEN interim final rule eliminated that federal requirement for domestic reporting companies, formally exempting entities previously known as domestic reporting companies, including Idaho-formed entities, from CTA reporting; only foreign-formed entities registering to do business in a US state remain covered. The combined effect is that Idaho-formed entities now face no operative beneficial-ownership disclosure obligation at either level of government, reopening the shell-entity opacity vector the CTA was designed to close nationally.

This is a structural finding, not a single-incident one, and it is corroborated by two independent source categories, a FinCEN primary publication and ICIJ investigative reporting, meeting the High-confidence corroboration standard applied by this monitor for the underlying registry-absence finding. Both corroborating sources sit at tier 1, reinforcing analytical confidence in the registry-absence architecture even as the exemption legal durability remains genuinely open. The rule that removed the federal backstop, however, carries its own caveat: it is an interim final rule, not settled final policy, subject to a 60-day comment period and to ongoing appellate litigation in National Small Business United v. Yellen, either of which could restore, further narrow, or permanently repeal the domestic reporting-company exemption. The original framing of the exemption as settled policy understated this open status, and this brief treats the exemption durability as unresolved rather than fixed.

Globally, the EU AML Package sets the structural direction against which BO-transparency architecture is increasingly measured, even though Idaho and the United States sit entirely outside its supervisory perimeter. The package is properly understood as three distinct instruments rather than a single measure: the AML Regulation (Regulation (EU) 2024/1624, the AMLR), which is directly applicable across EU member states without domestic transposition; the sixth Anti-Money Laundering Directive (6AMLD), which each member state transposes into its own national law; and the AMLA Regulation (Regulation (EU) 2024/1620), which establishes the Anti-Money Laundering Authority and shifts supervision of the highest-risk cross-border obliged entities from purely national authorities toward a hybrid EU-level direct-and-indirect supervisory regime. For Idaho, this architecture has no direct application: Idaho-licensed institutions with EU counterparties may experience indirect compliance friction from AMLR correspondent-banking due-diligence provisions, but no AMLA direct-supervision nexus attaches to Idaho or US entities. The EU package is durable backdrop against which the international transparency-architecture trend can be read, not the operative regime governing the beneficial-ownership exposure of Idaho itself, which is instead defined entirely by the contested domestic-exemption status of the CTA and the absence of a state registry.

This reopened opacity vector reaches a broad customer-typology base: any Idaho-formed LLC or corporation, regardless of the wealth or sophistication of its beneficial owner, now falls outside both the state and federal beneficial-ownership disclosure regime, touching corporate and high-net-worth customer segments alike. Financial institutions maintaining correspondent, custody, or account relationships with Idaho-formed corporate customers can no longer rely on the CTA reporting chain as an independent source of beneficial-ownership verification and must depend entirely on their own customer-due-diligence programs to identify beneficial owners, a burden-shift from public-registry disclosure to private-sector control frameworks that this brief treats as a material control-framework consequence of the federal rule change.

Read against the overall Idaho jurisdiction risk trajectory, assessed as increasing, the beneficial-ownership finding stands as one of two structural drivers, alongside the crypto-ATM exposure documented in the digital-asset domain, that combine with an otherwise mixed enforcement-versus-enablement balance to produce a deteriorating rather than stable overall assessment for Idaho. Neither driver reflects a discrete state policy choice; both instead reflect federal-level developments that Idaho inherits by virtue of its position within the US federal financial-regulatory architecture rather than through any distinguishing state-level action of its own.

Outlook

The determinative question for the Idaho beneficial-ownership posture over the next several cycles is whether National Small Business United v. Yellen resolves in a way that restores, narrows, or forecloses the domestic reporting-company exemption, and whether FinCEN proceeds to a final rule that entrenches or reverses the current interim position. Absent a state-level registry initiative, which no Idaho legislative proposal currently addresses, Idaho-formed entities will remain without any operative beneficial-ownership disclosure obligation for as long as the interim exemption stands, a structural condition this monitor will continue to track independently of the separate, EU-specific AMLA supervisory build-out.

Cumulative analysis

Beneficial Ownership and Corporate Transparency — Cumulative Analysis

This is the first baseline cycle for the beneficial-ownership and corporate-transparency posture of Idaho within the Financial Integrity Monitor, and it establishes a jurisdiction whose exposure runs through federal policy rather than state design. Idaho itself has never operated an independent state-level beneficial-ownership registry; Secretary of State filings capture registered agents and officers only. For the period the Corporate Transparency Act domestic reporting-company requirement was in force, this state-level gap was immaterial, because Idaho-formed LLCs and corporations reported beneficial ownership federally as domestic reporting companies. That backstop was removed by the March 2025 FinCEN interim final rule, which formally exempted domestic reporting companies, including all Idaho-formed entities, from CTA beneficial-ownership reporting, leaving only foreign-formed entities registering to do business in a US state within scope. The baseline therefore documents a jurisdiction that has moved, within roughly one cycle of coverage, from full federal beneficial-ownership disclosure coverage to none, without any change in the registry design of Idaho itself.

The corroboration for the state-level registry-absence finding is strong, drawing on both a FinCEN primary source and independent ICIJ investigative reporting, and the monitor treats it as an architecture-level fact rather than a provisional read. The federal exemption underlying the broader opacity-vector finding is treated with appropriate caution, however: it remains an interim final rule, open to a comment period, and contingent on the unresolved appellate litigation in National Small Business United v. Yellen and on a promised final rulemaking that has not yet issued. This baseline is explicit that any subsequent cycle could see the exemption narrowed, reinstated in modified form, or permanently entrenched, and treats the current opacity condition as provisional rather than settled.

Set against this Idaho-specific trajectory, the baseline also documents the durable global backdrop of the EU AML Package as context, not as governing law for Idaho. That package comprises three distinct instruments: the directly applicable AML Regulation (Regulation (EU) 2024/1624), the sixth AML Directive requiring member-state transposition, and the AMLA Regulation (Regulation (EU) 2024/1620) establishing the Anti-Money Laundering Authority, which is progressively shifting supervision of the highest-risk cross-border obliged entities toward a hybrid EU-level regime. Idaho and the United States sit entirely outside this perimeter; the relevance to Idaho is confined to indirect correspondent-banking due-diligence friction for institutions with EU counterparties, not to any direct supervisory nexus.

This reopened opacity vector reaches a broad customer-typology base within the baseline: any Idaho-formed LLC or corporation, regardless of the wealth or sophistication of its beneficial owner, now falls outside both the state and federal beneficial-ownership disclosure regime, touching corporate and high-net-worth customer segments alike. Financial institutions maintaining correspondent, custody, or account relationships with Idaho-formed corporate customers can no longer rely on the CTA reporting chain as an independent source of beneficial-ownership verification and must depend entirely on their own customer-due-diligence programs, a burden-shift from public-registry disclosure to private-sector control frameworks that this baseline records as a material control-framework consequence of the federal rule change.

Read against the overall Idaho jurisdiction risk trajectory, assessed in this baseline as increasing, the beneficial-ownership finding stands as one of two structural drivers, alongside the crypto-ATM exposure documented in the digital-asset domain, that combine with an otherwise mixed enforcement-versus-enablement balance to produce a deteriorating rather than stable overall assessment for Idaho. Neither driver reflects a discrete state policy choice; both instead reflect federal-level developments that Idaho inherits by virtue of its position within the US federal financial-regulatory architecture rather than through any distinguishing state-level action of its own. This baseline establishes that distinction as a standing analytical frame for future cycles: Idaho-specific developments, whether legislative or enforcement-related, would represent a materially different category of finding from the federally driven conditions documented here.

The state-of-domain read established by this baseline is that the beneficial-ownership transparency posture of Idaho is currently on a deteriorating trajectory driven by a federal decision rather than a local one, with the durability of that deterioration hinging on litigation and rulemaking outcomes external to Idaho itself, and with no Idaho-specific registry initiative on record to offset the federal rollback.

Outlook

Subsequent cycles should track the National Small Business United v. Yellen appellate outcome, any FinCEN final rule on CTA domestic scope, and any Idaho legislative movement toward an independent state-level beneficial-ownership registry, none of which had resolved as of this baseline.

domain_sub_briefs · D2 · Cumulative analysis

D3 Enabler Jurisdictions and Professional Facilitators

Enabler Jurisdictions and Professional Facilitators

Continue reading

The Idaho enabler-jurisdiction signal this cycle is narrow but worth stating plainly: despite a Boise Police Department detective identifying a single recurring Bitcoin Depot-linked wallet address across more than 100 local scam investigations, no Idaho Attorney General or Idaho Department of Finance enforcement action against Bitcoin Depot, CoinFlip, or Athena Bitcoin has been identified, in contrast to the multistate Attorney General enforcement wave pursued by Iowa, Massachusetts, Connecticut, Missouri, Nevada, Maine, and the District of Columbia against crypto-ATM operators. This is presented as a possible enforcement-gap signal rather than a confirmed one. The reviewer challenge attached to this finding cautions explicitly that the absence of identified Idaho enforcement action may partly reflect the thinness of publicly accessible Idaho-specific primary-source enforcement dockets rather than a genuine absence of enforcement activity, and the confidence tier on this finding is set to Possible to reflect that caveat rather than to assert a confirmed capacity or prioritization gap. The absence of Idaho from this wave stands out given the volume of evidence documented in the crypto-ATM scam pipeline, and if confirmed as a genuine non-participation rather than a sourcing artifact, it would constitute an enabler-jurisdiction signal under the enablement-as-signal principle applied by this monitor: the absence of enforcement action in a jurisdiction with documented high-volume exposure is itself analytically significant, independent of any subsequent action.

Outlook

This finding should be treated as a watch item rather than a settled assessment. Confirming or ruling out non-public Idaho enforcement activity against crypto-ATM operators would require direct access to Idaho Department of Finance and Attorney General dockets, which was not available this cycle; the next cycle should specifically seek that access before upgrading this signal beyond Possible confidence.

Cumulative analysis

Enabler Jurisdictions and Professional Facilitators — Cumulative Analysis

This is the first baseline cycle for the enabler-jurisdiction and professional-facilitator profile of Idaho, and the initial signal is narrow and appropriately caveated. The baseline documents a single recurring Bitcoin Depot-linked wallet address identified by a Boise Police Department detective across more than 100 local scam investigations, alongside the absence of any identified Idaho Attorney General or Department of Finance enforcement action against Bitcoin Depot, CoinFlip, or Athena Bitcoin, in contrast to the multistate Attorney General enforcement wave pursued by several peer states against crypto-ATM operators. The monitor treats this as a possible enforcement-gap signal rather than a confirmed one: the reviewer challenge attached to this baseline explicitly cautions that Idaho-specific primary-source sourcing thinness, not a confirmed absence of enforcement, may account for the finding, and the confidence tier is set to Possible accordingly.

Under the enablement-as-signal principle applied by this monitor, the absence of enforcement action in a jurisdiction with documented high-volume scam-wallet exposure is itself analytically significant regardless of cause, and this baseline flags it as a standing watch item rather than closing the question. Subsequent cycles should specifically pursue direct access to Idaho Department of Finance and Attorney General enforcement dockets, which was not available this cycle, in order to distinguish a genuine capacity or prioritization gap from a sourcing artifact.

Outlook

The state-of-domain assessment going forward is watch-and-confirm: this baseline establishes the enforcement-gap hypothesis but does not resolve it, and the priority for the next cycle should be direct docket access rather than continued reliance on secondary reporting.

domain_sub_briefs · D3 · Cumulative analysis

D4 Conflict Finance and Extractive-Industry Integrity

Conflict Finance and Extractive-Industry Integrity

Continue reading

The connection of Idaho to conflict finance this cycle runs through a single sanctions designation rather than a locally originated scheme. The OFAC designation of the Democratic Karen Benevolent Army, its senior leadership, and affiliated companies for supporting Myanmar-based cyber scam centers targeting Americans establishes a traceable channel: the source is US and global scam-victim cash proceeds, including Idaho victims documented elsewhere in this baseline crypto-ATM findings; the channel is crypto-ATM and VASP layering infrastructure; and the deployment is financing of the DKBA, an armed ethnic organization operating within the internal conflict in Myanmar. This is treated as an early, single-designation signal rather than an established durable financing channel, and the F4 conflict-finance trace applied by this monitor structures the analysis of source, channel, and deployment rather than asserting a mature or continuing pipeline. No direct Idaho-based entity or transit corridor has been identified within this channel; the connection of Idaho is limited to its documented status as one of the many US jurisdictions whose scam-victim losses feed the broader proceeds pool that this designation targets. This finding was flagged for SCEM review given its conflict-finance context and for WDM review at Possible confidence given the reported entanglement of Chinese organized-crime-linked companies with the scam-center network, illustrating how a single designation can carry cross-monitor significance beyond its immediate sanctions effect.

Outlook

Whether this designation marks an isolated action or the first documented instance of a recurring US-scam-to-Myanmar-conflict financing channel is the open question for subsequent cycles. The role of Idaho in this picture remains indirect, as one origination point among many US jurisdictions feeding the broader scam-victim proceeds pool rather than a distinct conflict-finance node in its own right; continued monitoring of further OFAC action against Myanmar-based armed-group financing would be the clearest signal of an established pattern.

Cumulative analysis

Conflict Finance and Extractive-Industry Integrity — Cumulative Analysis

This is the first baseline cycle in which the profile of Idaho intersects with conflict-finance analysis, and the connection is narrow, indirect, and appropriately early-stage. The baseline traces a single channel arising from the OFAC designation of the Democratic Karen Benevolent Army and affiliated companies for supporting Myanmar-based cyber scam centers targeting Americans: source funds are US and global scam-victim cash proceeds, including losses documented among Idaho victims elsewhere in this baseline; the channel is crypto-ATM and VASP layering infrastructure of the kind documented in the digital-asset domain; and the deployment is financing of an armed ethnic organization operating within an active internal conflict in Myanmar. No Idaho-based entity or transit corridor has been identified within this channel, and the role of Idaho is limited to its status as one of many US jurisdictions whose scam-victim losses feed the broader proceeds pool. The monitor treats this as an early, single-designation signal, not an established durable financing pipeline, and has flagged it for SCEM review of the conflict-finance context and for WDM review, at Possible confidence, of state-capture and quasi-state criminal-network dynamics given the reported involvement of Chinese organized-crime-linked companies in the same scam-center network.

Outlook

Future cycles should watch for further OFAC or partner-agency action against Myanmar-based armed-group financing to determine whether this designation represents an isolated action or the first documented instance of a recurring channel; absent such follow-on action, this baseline should be read as an early flag rather than a settled conflict-finance finding.

domain_sub_briefs · D4 · Cumulative analysis

D5 Crypto, Digital Assets, and Financial Innovation

Crypto, Digital Assets, and Financial Innovation

Continue reading

The digital-asset integrity exposure of Idaho is concentrated in a single mechanism operating at street level: crypto-ATM kiosks functioning as cash-out points for scam networks. A Boise Police Department detective identified a single Bitcoin Depot-linked wallet address recurring across more than 100 Idaho-area scam investigations, illustrating how scammers instruct victims to withdraw cash and deposit it into kiosks operated by Bitcoin Depot, CoinFlip, and Athena Bitcoin, which convert the cash to bitcoin and forward it near-instantly to attacker-controlled wallets before the funds are layered through peel chains and offshore exchanges. Idaho functions as both a victim-origination point and an investigative venue: a separate 112 million US dollar multi-district pig-butchering seizure, spanning six virtual-currency accounts, required parallel seizure warrants authorized by federal judges in the District of Arizona, the Central District of California, and the District of Idaho, evidencing commingled laundering flows that reach well beyond any single state.

The applicable federal supervisory framework for Idaho-licensed money-services businesses operating these kiosks is FinCEN Notice FIN-2025-NTC1, issued August 2025, which reaffirms that 31 CFR 1022.320 SAR and CTR obligations apply nationwide to convertible-virtual-currency kiosk operators, including those licensed in Idaho. Layered on top of that existing obligation is a forward-looking rulemaking: a joint FinCEN and OFAC notice of proposed rulemaking under docket FINCEN-2026-0100 will impose Bank Secrecy Act obligations and mandatory sanctions-compliance programs on permitted payment stablecoin issuers under the GENIUS Act framework, a rule currently at the consultation stage and expected within the 2026-to-mid-2027 window, which will directly affect any Idaho-domiciled or Idaho-licensed stablecoin issuer that enters the space.

Globally, instruments such as the EU Markets in Crypto-Assets Regulation and FATF virtual-asset standards set the international direction for digital-asset supervision, but neither is the operative framework governing the exposure of Idaho itself; the crypto-integrity posture of Idaho is defined instead by the interaction between kiosk-level BSA obligations already in force and the pending federal stablecoin-issuer rulemaking, both of which sit within the existing US federal supervisory architecture rather than any EU or FATF instrument directly binding Idaho-licensed firms.

The retail, MSB, and VASP-counterparty customer segments identified in this baseline crypto-ATM findings sit squarely within existing 31 CFR 1022.320 reporting coverage, meaning the control gap here is one of enforcement follow-through rather than regulatory design: the obligation is already covered on paper, but the state-level consumer-protection response has not matched the volume of documented kiosk-linked scam activity. This is a materially different gap-type from the beneficial-ownership finding elsewhere in this baseline, where the underlying obligation itself was removed; here, the underlying BSA reporting and monitoring obligation for kiosk operators remains fully in force, and the open question is one of Idaho-specific enforcement capacity or prioritization rather than of any regulatory vacancy.

The pending GENIUS Act rulemaking is best read as closing a different kind of gap: general industry practice for permitted payment stablecoin issuers currently lacks a finalized mandatory sanctions-compliance-program standard, and this rulemaking, once finalized, would establish that standard for the first time. Any Idaho-domiciled or Idaho-licensed entity contemplating entry into the stablecoin-issuance space should treat this NPRM, now at the consultation stage, as a near-certain future compliance requirement rather than a speculative one, given its High confidence rating and direct primary-source basis in a joint FinCEN and OFAC docket.

Outlook

The principal near-term digital-asset risk for Idaho is the continued gap between documented kiosk-level scam exposure and the absence of state-level consumer-protection enforcement matching the multistate Attorney General wave seen in peer states. Finalization of the GENIUS Act PPSI AML/CFT rule would extend mandatory sanctions-compliance-program obligations to any Idaho stablecoin issuer, closing a current gap in industry practice; whether the enforcement posture of Idaho toward kiosk operators shifts before then remains an open question for subsequent cycles.

Cumulative analysis

Crypto, Digital Assets, and Financial Innovation — Cumulative Analysis

This is the first baseline cycle establishing the digital-asset integrity profile of Idaho, and it identifies crypto-ATM kiosks as the principal exposure mechanism for the jurisdiction. The baseline documents a single Bitcoin Depot-linked wallet address recurring across more than 100 Idaho-area scam investigations, evidencing a cash-to-bitcoin laundering pipeline in which victims are instructed to deposit cash into kiosks operated by Bitcoin Depot, CoinFlip, and Athena Bitcoin, with funds converted and forwarded near-instantly to attacker-controlled wallets before layering through peel chains and offshore exchanges. The role of Idaho in this pipeline is dual: it is both a victim-origination point and, via a 112 million US dollar multi-district pig-butchering seizure requiring a parallel Idaho warrant alongside Arizona and California warrants, an investigative venue within a commingled national laundering network.

Idaho-licensed kiosk operators already sit within an existing federal supervisory framework: FinCEN Notice FIN-2025-NTC1 reaffirms that 31 CFR 1022.320 SAR and CTR obligations apply nationwide, including to Idaho-licensed money-services businesses operating kiosks. Layered onto this baseline is a forward-looking development that will extend obligations further: the joint FinCEN and OFAC GENIUS Act PPSI AML/CFT rulemaking, currently at the consultation stage under docket FINCEN-2026-0100, will impose mandatory sanctions-compliance-program obligations on permitted payment stablecoin issuers, directly affecting any Idaho-domiciled or Idaho-licensed stablecoin issuer entering that space in the 2026-to-mid-2027 window.

The baseline is explicit that the crypto-integrity posture of Idaho is governed by this US federal architecture rather than by international instruments such as MiCA or the FATF virtual-asset standards, which remain relevant only as global contextual backdrop rather than as directly binding frameworks for Idaho-licensed firms.

The retail, MSB, and VASP-counterparty customer segments identified within this baseline crypto-ATM findings sit squarely within existing 31 CFR 1022.320 reporting coverage, meaning the control gap this baseline documents is one of enforcement follow-through rather than regulatory design: the underlying obligation is already covered on paper, but the state-level consumer-protection response has not matched the volume of kiosk-linked scam activity. This is a materially different gap-type from the beneficial-ownership finding documented in the D2 domain, where the underlying disclosure obligation itself was removed; here, the underlying BSA reporting and monitoring obligation for kiosk operators remains fully in force, and the open question this baseline identifies is one of Idaho-specific enforcement capacity or prioritization rather than of any regulatory vacancy.

The pending GENIUS Act rulemaking is best read within this baseline as closing a different kind of gap entirely: general industry practice for permitted payment stablecoin issuers currently lacks a finalized mandatory sanctions-compliance-program standard, and this rulemaking, once finalized, would establish that standard for the first time. Any Idaho-domiciled or Idaho-licensed entity contemplating entry into stablecoin issuance should treat this NPRM, currently at the consultation stage with a High confidence rating and a direct primary-source basis in a joint FinCEN and OFAC docket, as a near-certain future compliance requirement rather than a speculative one.

The overall state-of-domain read of this baseline is that the digital-asset integrity exposure of Idaho is high-volume but reactive rather than proactive at the state level: existing federal kiosk obligations and the coming stablecoin-specific rulemaking address the regulatory-design side of the picture, while the documented gap between scam-wallet volume and state enforcement activity remains the open operational question for subsequent cycles to track.

Outlook

Subsequent cycles should track finalization of the GENIUS Act PPSI AML/CFT rule, any Idaho Attorney General or Department of Finance enforcement action against kiosk operators, and any further multi-district seizure activity connecting Idaho to national laundering networks, as the key indicators of whether the deteriorating trajectory assessment in this baseline continues, stabilizes, or reverses.

domain_sub_briefs · D5 · Cumulative analysis

D6 Compliance Technology and Active Defence

Compliance Technology and Active Defence

Continue reading

No independent compliance-technology or active-defence development, such as a RegTech deployment, AI-driven transaction-monitoring initiative, or perpetual-KYC program, was identified for Idaho this cycle. The only proximate signal is a cross-reference to the crypto, digital-assets domain: FinCEN Notice FIN-2025-NTC1 reminds money-services businesses, including Idaho-licensed crypto-ATM kiosk operators, of ongoing SAR and CTR vigilance obligations under 31 CFR 1022.320, which is consistent with the broader sector-wide shift from reactive to forward-looking, proactive compliance posture, though the notice itself is fundamentally a virtual-currency-kiosk supervisory development rather than a standalone compliance-technology deployment. The pending GENIUS Act stablecoin AML/CFT rulemaking similarly mandates formal sanctions-compliance programs for permitted payment stablecoin issuers, a governance-obligation development consistent with the proactive-compliance paradigm generally, but again not itself a technology or supervisory-guidance signal specific to this domain. The absence of a domain-specific development this cycle should not be read as an absence of underlying pressure: the same crypto-ATM and beneficial-ownership findings that drive the D5 and D2 assessments in this baseline create an implicit case for exactly the kind of automated screening and transaction-monitoring capability this domain tracks, even though no such capability has yet been documented for an Idaho-licensed institution specifically.

Outlook

This domain remains on watch status for Idaho pending an independent compliance-technology or active-defence development. Subsequent cycles should specifically look for adoption by any Idaho-licensed institution of automated sanctions-screening tools, transaction-monitoring upgrades, or perpetual-KYC programs responsive to the crypto-ATM and beneficial-ownership findings documented elsewhere in this baseline, as the clearest indicator that this domain would move from watch to active status. Given the volume of crypto-ATM scam activity already documented in this baseline, a compliance-technology response, whether vendor-driven or supervisory, would be a reasonably expected next development to track.

Cumulative analysis

Compliance Technology and Active Defence — Cumulative Analysis

This is the first baseline cycle for the compliance-technology and active-defence domain of Idaho, and it establishes a watch-status jurisdiction rather than an active one: no independent RegTech, AI-driven monitoring, or perpetual-KYC development specific to an Idaho-licensed institution was identified. The only proximate signal available this cycle is a cross-domain reference to FinCEN Notice FIN-2025-NTC1, which reminds money-services businesses, including Idaho-licensed crypto-ATM kiosk operators, of ongoing SAR and CTR vigilance obligations under 31 CFR 1022.320, consistent with a broader sector-wide shift toward proactive compliance posture but not itself a standalone compliance-technology deployment. The pending GENIUS Act stablecoin AML/CFT rulemaking carries a similar governance-obligation character without constituting a technology-specific signal.

The baseline notes that the absence of a domain-specific finding sits in tension with the volume of crypto-ATM scam activity and beneficial-ownership opacity documented elsewhere in this same baseline, both of which would reasonably be expected to generate compliance-technology responses, whether vendor-driven monitoring tools or supervisory guidance specifically addressing automated screening capability, over subsequent cycles.

Outlook

Future cycles should specifically track whether any Idaho-licensed institution adopts automated sanctions-screening, transaction-monitoring, or perpetual-KYC capability responsive to the exposures documented in the D2 and D5 domains of this baseline, as the indicator that would move this domain from watch to active status.

domain_sub_briefs · D6 · Cumulative analysis
Regulatory horizon
No dated horizon items this cycle. 3 items tracked without a confirmed date.
3 pending date · baseline financial-integrity-2026-07-05
Role action cards
MLROHigh

Idaho beneficial-ownership disclosure is now absent at both state and federal level, while three new OFAC designations and a FinCEN kiosk notice reaffirmation expand sanctions and SAR and CTR screening obligations for Idaho-licensed institutions this cycle.

The CTA domestic reporting-company exemption removes the federal beneficial-ownership disclosure backstop for Idaho-formed entities, shifting beneficial-owner identification onto internal CDD programs. Concurrently, new OFAC designations against Russian crypto-settlement rails, a Sinaloa Cartel network, and Myanmar scam-center enablers, together with FinCEN reaffirmation of kiosk-operator SAR and CTR obligations, expand the population of entities and activity requiring sanctions screening and suspicious-activity assessment.

8 evidence refs
ComplianceHigh

A federal beneficial-ownership reporting exemption and a pending GENIUS Act stablecoin rulemaking together reshape the Idaho control-framework landscape this cycle.

The removal of CTA reporting for domestic entities creates a documented control gap requiring reliance on internal customer-due-diligence programs rather than public-registry verification. The pending GENIUS Act PPSI AML/CFT rulemaking and the reaffirmed kiosk-operator SAR and CTR obligations signal where policy adequacy will next be tested, while possible Idaho non-participation in multistate crypto-ATM enforcement is flagged as an unresolved gap-assessment question.

7 evidence refs
LegalHigh

The CTA domestic beneficial-ownership exemption remains legally unsettled, and new OFAC designations create sanctions-nexus exposure without corroborated Idaho enforcement action against crypto-ATM operators.

The exemption rests on an interim final rule subject to a comment period and to pending appellate litigation in National Small Business United v. Yellen, leaving its durability genuinely open. Three new OFAC designations create potential sanctions-nexus and client-instruction risk for counterparties, while the absence of confirmed Idaho enforcement action against crypto-ATM operators and the multi-district seizure network both bear on enforcement-trajectory assessment.

8 evidence refs
BoardHigh

Idaho jurisdiction risk is assessed as increasing this cycle, driven by a reopened beneficial-ownership opacity vector and expanding sanctions and crypto-related exposure.

The combination of the CTA domestic exemption, continuing OFAC designations against Russian, cartel, and Myanmar-linked networks, and documented but unaddressed crypto-ATM scam exposure together drive a deteriorating overall jurisdiction risk trajectory against a mixed enforcement-versus-enablement balance, a material strategic-level signal for governance attention.

7 evidence refs
CTOHigh

A recurring crypto-ATM wallet address, a multi-district pig-butchering seizure, and a pending GENIUS Act stablecoin rulemaking define the Idaho digital-asset architecture risk this cycle.

A single Bitcoin Depot-linked wallet address recurring across more than 100 scam investigations illustrates a concentrated technical evasion vector at the kiosk layer, while the pending GENIUS Act PPSI AML/CFT rulemaking will impose new sanctions-compliance-program architecture requirements on stablecoin issuers, a forward platform and data-governance implication for any Idaho-domiciled entity entering that space.

5 evidence refs
RiskHigh

Idaho crypto-enabled fraud exposure and a reopened beneficial-ownership opacity vector combine with continuing sanctions-designation activity to raise overall jurisdiction risk exposure concentration this cycle.

The crypto-ATM cash-out pipeline, the multi-district seizure, and three new OFAC designations together represent an emerging concentration of exposure in the digital-asset and sanctions typologies, while possible non-participation in multistate crypto-ATM enforcement is flagged as an escalation signal warranting cross-monitor and cross-cycle tracking.

7 evidence refs
OperationsHigh

New OFAC designations and the reaffirmed kiosk-operator SAR and CTR obligations expand transaction-monitoring and screening-list update requirements this cycle.

Three new OFAC designations expand the sanctions-list population requiring screening, the FinCEN kiosk notice reaffirms existing SAR and CTR reporting workflow obligations for kiosk operators, the clean FATF standing of the United States is unchanged pending the October 2026 plenary, and the pending GENIUS Act rulemaking signals a future workflow change for stablecoin-related operations.

7 evidence refs
AuditHigh

The CTA beneficial-ownership exemption and possible Idaho enforcement gap against crypto-ATM operators both surface documentation and control-testing scope questions this cycle.

The removal of CTA reporting for domestic entities and the absence of an independent Idaho beneficial-ownership registry together create an audit-trail gap in beneficial-ownership verification evidence, while possible non-participation in multistate crypto-ATM enforcement, flagged at Possible confidence due to sourcing thinness, raises a documented-evidence question for control-testing scope regarding Idaho enforcement activity.

4 evidence refs
Decision lens
MLRO

Idaho beneficial-ownership disclosure is now absent at both state and federal level, while three new OFAC designations and a FinCEN kiosk notice reaffirmation expand sanctions and SAR and CTR screening obligations for Idaho-licensed institutions this cycle.

Compliance

A federal beneficial-ownership reporting exemption and a pending GENIUS Act stablecoin rulemaking together reshape the Idaho control-framework landscape this cycle.

Legal

The CTA domestic beneficial-ownership exemption remains legally unsettled, and new OFAC designations create sanctions-nexus exposure without corroborated Idaho enforcement action against crypto-ATM operators.

Board

Idaho jurisdiction risk is assessed as increasing this cycle, driven by a reopened beneficial-ownership opacity vector and expanding sanctions and crypto-related exposure.

CTO

A recurring crypto-ATM wallet address, a multi-district pig-butchering seizure, and a pending GENIUS Act stablecoin rulemaking define the Idaho digital-asset architecture risk this cycle.

Risk

Idaho crypto-enabled fraud exposure and a reopened beneficial-ownership opacity vector combine with continuing sanctions-designation activity to raise overall jurisdiction risk exposure concentration this cycle.

Operations

New OFAC designations and the reaffirmed kiosk-operator SAR and CTR obligations expand transaction-monitoring and screening-list update requirements this cycle.

Audit

The CTA beneficial-ownership exemption and possible Idaho enforcement gap against crypto-ATM operators both surface documentation and control-testing scope questions this cycle.

Shared evidence: 12 refs
Typology observations
Exposure: {'total_matched_typologies': 0, 'by_typology': {}, 'top_indicators': [], 'exposure_note': None}
Scenario sketches

Illustrative AMLA Direct-Supervision Transition Scenario

As an illustrative orientation only, consider how the shift from purely national AML supervision toward AMLA direct and indirect supervision of cross-border obliged entities, operating alongside the directly applicable AMLR and the per-state transposition of the sixth AML Directive, could reshape the supervisory and evasion landscape over coming cycles. In this illustrative sketch, a cross-border payment group currently supervised only by fragmented national authorities across several member states could, once designated for direct AMLA supervision, face a single consolidated supervisory relationship in place of multiple parallel national relationships, potentially closing arbitrage gaps that previously allowed evasion actors to select the most permissive national supervisor within the group structure. This is architecture-over-incident framing describing a possible structural mechanism, not an observed development or a prediction of how any specific entity will be treated.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Illustrative Crypto-ATM to Stablecoin Layering Scenario

As an illustrative orientation only, consider how a scam-cash-out network currently reliant on crypto-ATM kiosks for cash-to-bitcoin conversion could, once a permitted payment stablecoin issuer AML/CFT and sanctions-compliance standard is finalized, attempt to shift a portion of layering activity toward stablecoin rails perceived as offering faster settlement, in order to test whether the new compliance-program requirement closes the same conversion-and-forwarding pattern currently observed at the kiosk layer. This sketch illustrates a possible adaptation pathway for illicit finance infrastructure in response to a tightening regulatory perimeter, not an observed migration or a prediction that any specific issuer, kiosk operator, or network will pursue this path.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Russian Sanctions-Evasion ArchitecturestableIncremental Russia list maintenance (GL13R amendment, SDN delistings) alongside a material Houthi/Iran-channel tranche this cycle.
T2 · EU AML Package / AMLAescalating10 July 2026 deadline live for AMLD6 BO-register Articles 11-13/15 and AMLA Level 2/3 technical standards; Italy's Decree 210/2025 shows a member-state transposition delta.
T3 · FATF Grey ListescalatingJune 2026 Plenary added Bosnia and Herzegovina and Iraq, removed Algeria and Namibia (22 jurisdictions remain); presidency transitioned to the UK's Giles Thomson with fraud/scam-compound risk named as the incoming priority.
T4 · Beneficial-Ownership Register Statusdeteriorating (US) / improving (EEA)US domestic CTA exemption persists with a GAO-flagged visibility gap; EU AMLD6 register provisions and Italy's access-rule tightening move the opposite direction.
T5 · Crypto & Digital-Asset IntegrityescalatingMiCA transitional-period expiry (1 Jul 2026, ~17% authorized) plus FinCEN's Huione-successor 311 proposal continue the crypto-laundering enforcement track.
T6 · Sanctions Regime DivergencestableFATF's June 2026 update to Recommendation 6 embeds UNSCR 2664/2761 humanitarian exemptions, a convergence signal, while US/EU/UK autonomous Russia-designation drift continues via routine OFAC maintenance.
Registers

Enforcement actions

  • Federal seizure of approximately $112 million across six virtual currency accounts linked to pig-butchering and other crypto investment scams, with seizure warrants authorized in three federal districts including the District of Idaho, reflecting Idaho-origin victim funds within the commingled laundering network. 18 Sep 2025
  • FinCEN issued Notice FIN-2025-NTC1 urging increased vigilance around CVC kiosks used for scam payments and other illicit activity, reminding MSBs (including Idaho-registered money transmitters operating crypto ATMs) of SAR/CTR obligations under 31 CFR 1022.320. 4 Aug 2025
  • FinCEN issued an interim final rule removing the requirement for US companies and US persons to report beneficial ownership information under the Corporate Transparency Act, narrowing the reporting-company definition to foreign entities only. 26 Mar 2025

Sanctions changes

  • OFAC designated a Sinaloa Cartel-run money-laundering network (Armando de Jesus Ojeda Aviles and associates) that converts bulk US cash drug proceeds into cryptocurrency for cross-border transfer to Mexico, relevant to US financial institutions (including Idaho-licensed MSBs) screening for cartel-linked crypto flows. 20 May 2026
  • OFAC designated the Democratic Karen Benevolent Army (DKBA), a Burma-based armed group, along with senior leaders and Chinese organized-crime-linked companies for supporting cyber scam centers that target Americans, alongside DOJ/FBI/Secret Service establishment of a Scam Center Strike Force. 12 Nov 2025
  • OFAC re-designated Russian exchange Garantex and sanctioned its successor Grinex along with affiliates tied to the ruble-backed token A7A5, targeting a crypto-based Russian cross-border settlement rail used for sanctions evasion, relevant to Idaho-licensed VASPs' sanctions-screening obligations. 14 Aug 2025

Regulatory horizon (register)

  • GENIUS Act PPSI AML/CFT and sanctions-compliance final rule
  • FATF October 2026 Plenary and virtual-asset/hawala reports
  • CTA domestic BOI litigation appellate resolution

Active schemes

  • [HIGH] Crypto-ATM cash-to-bitcoin scam laundering pipeline
  • [HIGH] Multi-district pig-butchering crypto seizure network
  • Domestic shell-entity BO disclosure gap post-CTA rollback
Sources
  1. Idaho Department of Finance
  2. FinCEN / US Department of the Treasury
  3. FinCEN / US Department of the Treasury
  4. International Consortium of Investigative Journalists (ICIJ)
  5. TRM Labs
  6. Financial Action Task Force (FATF)
  7. Chainalysis
  8. Office of Foreign Assets Control (OFAC), US Department of the Treasury
  9. HM Treasury (United Kingdom)
  10. Chainalysis
Coverage gaps
While Iowa, Massachusetts, Connecticut, Missouri, Nevada, Ma…
While Iowa, Massachusetts, Connecticut, Missouri, Nevada, Maine, and the District of Columbia have sued, fined, or opened investigations into crypto-ATM operators (Bitcoin Depot, CoinFlip, Athena Bitcoin) for facilitating scam transactions, no equivalent Idaho Attorney General or Department of Finance enforcement action was identified despite Boise Police documentation of a single recurring scam-linked wallet address across more than 100 local cases.
FinCEN's March 2025 rule change exempts all domestic reporti…
FinCEN's March 2025 rule change exempts all domestic reporting companies, including Idaho LLCs and corporations, from beneficial-ownership disclosure; the Idaho Secretary of State's corporate registry independently collects no beneficial-ownership data, leaving Idaho-formed entities without any operative BO transparency mechanism at state or federal level.
Publicly available primary-source data specific to Idaho AML…
Publicly available primary-source data specific to Idaho AML/CFT enforcement (Idaho Department of Finance consent orders, Idaho Attorney General press releases) within the 18-month baseline window is sparse; most Idaho-specific findings in this baseline are derived from secondary investigative journalism (ICIJ, TRM Labs) rather than Idaho state primary filings.

Evidence

Confidence-tiered claims

No structured claims published for this jurisdiction yet.