How SWIFT's Bank-Level Sanctions Checks Became a Vulnerability for $6.9 Billion in Russian Payments
SWIFT delivers messages, not money. Banks enforce sanctions. When one bank turned a blind eye to forged documents, billions moved.

SWIFT, the Society for Worldwide Interbank Financial Telecommunication, does not know or care who is sending money. The network simply routes payment messages between its 11,000 member institutions in secure, standardized form. It connects the instructions from one bank to another. It does not verify transaction parties, check sanctions lists or enforce compliance rules.
This design—elegant for moving money globally, dangerous when sanctions are in place—allowed a Kremlin-linked fintech called A7 to move more than $6.9 billion through major international banks despite Western restrictions on Russian finance. A7 relied on forged documents and shell companies to move the money through the international banking system.
SWIFT handles messages, not money or compliance
When a bank in Hong Kong wants to send funds to a bank in Dubai, it does not use SWIFT to move the money itself. Instead, SWIFT carries the message describing what payment the sending bank wants to make. The actual transfer happens through separate correspondent banking relationships and settlement systems. SWIFT's role is purely informational.
This separation means SWIFT cannot inherently police who sends payments or who receives them. The network does not hold accounts, does not settle transactions and does not see the real-world identities behind the bank codes. Responsibility for checking whether a transaction violates sanctions laws rests entirely with the financial institutions handling the money—the banks themselves and their national and international regulators, not SWIFT.
SWIFT can be compelled to enforce sanctions at the extreme end. When the European Union imposed severe financial restrictions on Iran in 2012, regulators prohibited SWIFT from serving certain Iranian banks, and SWIFT disconnected them. But this applies only to the banks themselves, not to the billions of transactions passing through the network each day.
Banks bear sole responsibility for verifying transaction parties
Each bank that touches a transaction—the originating bank, the correspondent banks, the receiving bank—must independently check the parties involved against sanctions watchlists maintained by national and international authorities. This happens in seconds as the transaction flows through SWIFT. If a bank's screening systems flag a match, the bank must freeze the transaction and report it.
The system assumes that this distributed responsibility works because multiple banks will scrutinize the same payment at different points. If one bank misses a sanctions violation, others downstream should catch it. The model works when banks take compliance seriously. It breaks when a single bank in the chain does not.
Compliance systems cross-reference transaction data—names, addresses, company registration numbers, account details—against watchlists. But they can only screen what they see. If the names, companies and documents presented to a bank are fabricated, the screening catches nothing.
A7 exploited the compliance gap with industrial-scale forgery
A7, established in late 2024 by Moldovan oligarch Ilan Shor with backing from Promsvyazbank, a Russian state-owned bank, built an operation that appeared to work within the legitimate banking system. The network created approximately 200 shell companies across the United Arab Emirates, Hong Kong, Kyrgyzstan and Indonesia. These front entities opened bank accounts and began moving money.
To disguise what the payments were actually for, A7 produced counterfeit invoices and corporate documents at scale. When goods subject to U.S. or EU sanctions—military equipment, components for restricted technologies, goods for Russian security services—formed the actual basis of a transaction, A7 staff replaced product descriptions and customs codes with alternatives that would not trigger compliance alerts. Night-vision scopes became "toughened glass" in forged paperwork — and, when that description drew a compliance query, staff briefly considered relabeling the same shipment as footwear before deciding to keep the cover story consistent. The substitution was precise enough to avoid immediately raising suspicions.
The front companies deposited cash at banks connected to the SWIFT network. That cash could then be used to settle legitimate-looking invoices for goods supposedly being imported from abroad. To the compliance systems at Standard Chartered in Hong Kong, DBS in Hong Kong, Citigroup and JPMorgan Chase, the transactions appeared routine: a company placing an order, money moving for payment, nothing obviously illicit. The forged documents passed the first layer of screening because the compliance system only checks the names and account details on the transaction, not the authenticity of the underlying commercial documents.
“SWIFT's role is purely informational—responsibility for checking whether a transaction violates sanctions laws rests with the financial institutions handling the money and their regulators, not with SWIFT.”
How a single bank became the bottleneck for $6.9 billion
Standard Chartered's Hong Kong operation received $1.1 billion from A7-linked entities between late 2024 and August 2025. DBS in Hong Kong processed $273 million. Other major banks, including Deutsche Bank, processed smaller volumes. All of them saw transactions that their compliance systems did not flag as violations because the transactions were disguised through forged documents and shell companies.
The scheme unraveled not through the banking system's internal controls but through investigative reporting. The Financial Times, examining leaked internal files from A7's operations, traced the flow of money, identified the front companies, and reconstructed the forgery operation. Standard Chartered raised alarms over suspicious payment patterns tied to the scheme in February 2025, closing the linked accounts shortly afterward. In May 2025, the United Kingdom placed A7 under sanctions.
What remained unclear was how much each bank knew, when it knew it, and whether the compliance failures reflected genuine mistakes or willful blindness. Standard Chartered, Citigroup, JPMorgan and Deutsche Bank declined to provide detailed explanations, citing their commitment to anti-money laundering controls. The scheme succeeded because each bank in the chain saw only its own slice of the transaction, and the forged documents made that slice look legitimate.
The design flaw SWIFT cannot fix alone
SWIFT has developed transaction screening tools that banks can use to flag potential sanctions violations before sending a message. But these tools are optional, and they screen only against the data provided in the SWIFT message itself. They cannot verify whether the invoices attached to a transaction are real or forged. They cannot know whether the company name on the payment is a front or a legitimate business. They rely on banks to do that.
Tightening compliance at SWIFT itself would not prevent schemes like A7's. The only remedies are stronger scrutiny by banks of the documents behind transactions, more aggressive use of compliance tools, and willingness to reject transactions that look legitimate on the surface but feel wrong upon deeper examination. These require resources, training and institutional commitment that vary widely across the global banking system. Until they do, SWIFT's design—perfectly efficient for moving messages—will remain a vulnerability for money that should never move at all.



