Skip to content

A7 allegedly moved $6.9bn through global banks, FT says

A leaked-record investigation alleges A7-linked entities moved over $6.9bn through global banks using shell companies and forged invoices. No public source reviewed shows a named bank knowingly handled illicit payments.

By

Published
A wooden shipping crate stacked with panes of glass, with a row of dark boxy devices visible underneath where one pane has slipped aside.

What the investigation alleges

A Financial Times investigation published on 21 September 2026, based on hundreds of thousands of files reportedly taken from A7's internal systems, alleges that more than $6.9bn passed through international banks using front companies and forged trade documents. A7 Limited Liability Company is a Russian financial-technology firm that the UK designated on 20 May 2025 under the Russia (Sanctions) (EU Exit) Regulations 2019. The NCA separately describes A7 as backed by Promsvyazbank, a Russian bank already under UK sanctions, and VEB.RF, a Russian state-owned development corporation.

The $6.9bn figure is an investigative estimate drawn from leaked records. It has not been audited, and no regulator or court has adopted it as a finding. It principally covers activity from late 2024 to August 2025, according to the reporting. The UK's National Crime Agency (NCA) published its own Flash Alert on A7 in August 2026, describing a similar mechanism — shell companies, false invoices, correspondent banking and Swift-connected institutions — but explicitly says this has not been evaluated to the same standard as a formal Red or Amber Alert and should not be read as a definitive finding that all the described activity was illicit.

This matters for the UK because the alleged method does not rely on any bank knowingly banking a sanctioned entity. It relies on payment messages and supporting paperwork that, on their face, describe an unconnected transaction. That is precisely the gap UK sanctions and anti-money laundering controls are supposed to close, and the Financial Conduct Authority (FCA) has recently found weaknesses in how consistently firms do so.

How the payment route allegedly worked

According to the NCA, A7 used promissory notes, known as veksel, to record obligations inside Russia, while a separate overseas shell company completed what looked like an unconnected bank payment, supported by false documentation. The NCA says A7 built non-Russian pools of liquidity and linked payments to shell companies or sub-agents, so that the bank at the end of the chain saw only the shell company's name and stated business, not any connection to Russia or to a sanctioned bank.

The FT-derived reporting says the network used at least 100 shell companies to make payments, with references to at least another 100 entities in the leaked documents. Reported geographical counts include at least 61 companies in the United Arab Emirates, 87 in Hong Kong, 16 in Kyrgyzstan and 14 in Indonesia. These categories may overlap, so they should not be added into a single total.

The NCA separately estimates that around $8bn flowed through the Trading Company of the Republic of Kyrgyzstan by April 2025, an entity it says was liquidated in February 2026. Other reporting puts the same entity's contribution to the investigated dataset at closer to $2.4bn. The packet does not explain the gap, and it may reflect different transaction populations or measurement periods rather than a genuine conflict.

The forgery operation

The NCA says A7 manufactured websites and email addresses, and used virtual private networks so that personnel appeared to be operating from the jurisdictions where its shell companies were registered. It also says invoices were altered to misdescribe the goods involved. The FT-derived reporting gives one specific example: an alleged $510,000 payment for 500 night-vision devices, documented in the supporting paperwork as a purchase of glass. Some payments in the leaked records reportedly related to military equipment or procurement for Russian security agencies, an allegation the NCA supports in general terms by noting that A7's clients include participants in Russia's military-industrial complex, and that proliferation financing may be involved. None of this is a court or regulatory finding; it is what the leaked material and the NCA's typology describe.

Standard Chartered and the other named banks

The reporting names several banks whose accounts reportedly handled funds linked to A7 — receiving inbound payments in most cases, and in First Abu Dhabi Bank's case also making outbound payments from A7-linked accounts. Holding an account that received or sent such a payment is not the same as a bank knowingly dealing with A7, and the packet is explicit that no public source establishes that any of these banks knew the payments were connected to A7 or breached sanctions.

InstitutionLocationReported amountPeriod
Standard CharteredHong Kong$1.1bn receivedLate 2024 to August 2025
First Abu Dhabi BankUAEOver $1.8bn in outbound payments from 17 linked entities (about $1.3bn external, roughly $500m between shell companies)Investigated period to August 2025
DBSHong Kong$273m receivedInvestigated period to August 2025
CitigroupClients, jurisdiction unspecified$74m receivedInvestigated period to August 2025
Deutsche BankEuropeAbout $18m receivedInvestigated period to August 2025

Public reporting says the named banks pointed to their anti-money laundering compliance commitments, and that First Abu Dhabi Bank said it had closed identified A7-linked accounts. It is not established which Standard Chartered legal entity held the Hong Kong accounts, whether Standard Chartered acted as a beneficiary bank, a correspondent bank, or both, or what information appeared in the payment messages it processed. The FCA has not publicly said whether it is examining Standard Chartered or any other named institution in connection with this reporting.

What Swift can and cannot control

Swift is a financial-messaging network, not a payment processor or regulator. Swift states directly that it does not monitor or control every message its users send and does not determine whether an individual transaction is legitimate. Responsibility for screening a payment against sanctions lists and assessing its legitimacy sits with the banks handling it, and with the relevant authorities.

That distinction matters here. The NCA's account describes A7 gaining access to the international payment system indirectly, through third-country institutions and shell-company accounts, rather than through any sanctioned Russian bank regaining direct Swift access. A message carried over Swift can look entirely ordinary if the sender's name, the goods description and the stated business all appear unconnected to Russia, sanctioned entities, or restricted goods.

The UK sanctions timeline

  • Promsvyazbank: already under UK sanctions before A7's activity began.
  • A7 Limited Liability Company: designated by the UK on 20 May 2025 under the Russia (Sanctions) (EU Exit) Regulations 2019, listed as UK Sanctions List reference RUS2718.
  • The FT's investigated payment period: reportedly late 2024 to August 2025, meaning some of the flows under scrutiny may predate A7's own UK designation.
  • Further UK designations: a Sanctions Notice dated 16 June 2026 added further A7-associated entities, including A71 and A7-Agent, recording their stated links to A7 and Promsvyazbank.

Whether transactions before 20 May 2025 could still have breached UK sanctions depends on facts not available publicly, including any ownership or control link to Promsvyazbank, which was already designated, and the location, currency and parties to each payment.

Implications for UK sanctions and AML controls

The FCA has said, in general terms unconnected to any single case, that ordinary anti-money laundering checks do not by themselves amount to sanctions-list screening, and that UK financial sanctions carry no minimum transaction threshold — a single payment of any size can trigger a breach. In findings published on 28 May 2026, drawn from work with more than 150 FCA-supervised firms since February 2022, the regulator said the most common causes of suspected sanctions breaches were deficiencies in screening and alert management: incomplete data coverage, weak screening of ownership and control, delayed sanctions-list updates and poorly calibrated matching. The FCA's own testing found that exact-name alerts correctly identified the sanctioned party 90% of the time, against 75% for variant names — a gap that matters when a network is built specifically to avoid an exact name match.

The FCA expects firms to look beyond a clean list check: to corroborate trade documentation against public information where risk warrants it, and to compare a customer's actual activity against its stated business model. Under regulation 34 of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, financial and credit institutions that enter correspondent relationships with third-country institutions must apply enhanced due diligence, including understanding the respondent's business and assessing its own controls.

The NCA's alert lists indicators relevant to this pattern: recently created companies conducting large transactions, invoices inconsistent with a supplier's stated business, transfers between obscure companies in unrelated industries, opaque ownership, limited online presence and anomalous VPN use. It stresses that no single red flag proves A7 involvement — a point that cuts both ways for firms trying to calibrate alerts without generating unmanageable false positives.

What remains unproven

The packet underlying this reporting leaves several central questions open. The leaked dataset itself was not publicly available for independent verification of the $6.9bn total or the bank-by-bank subtotals. It is not established whether any bank identified concerns, filed a suspicious activity report, or escalated and rejected payments — this is confidential information not in the public sources reviewed. No enforcement notice, court judgment or regulatory finding establishes that Standard Chartered, Citigroup, Deutsche Bank, DBS or First Abu Dhabi Bank knowingly handled illicit A7 payments. The identities of the at least three UK-registered entities the FT reporting says were involved have not been established from the sources reviewed, though the NCA separately confirms that the UK's Office of Financial Sanctions Implementation (OFSI) identified suspected A7 transactions involving UK-incorporated beneficiaries and banks in several intermediary jurisdictions.

Readers should treat the $6.9bn figure, the named-bank amounts and the specific examples as reported allegations from an investigation based on leaked material, corroborated in general method by an independent NCA alert, rather than as established facts about any individual bank's conduct.

What to watch next

The NCA Flash Alert is published in full on the National Crime Agency's website and sets out the red flags firms are expected to weigh. The FCA's May 2026 findings on sanctions systems and controls set out the specific screening and due-diligence gaps regulators are focused on. Beyond that, the questions that would resolve most of the uncertainty here — bank-level disclosures, any OFSI or FCA action, and identification of the UK-registered entities named in the leaked files — have not yet been answered publicly.

Sources

  1. Kremlin-backed forgery scheme moved $6.9bn through global banks (opens in a new tab)

    Financial Times · · Accessed

  2. A7 Sanctions Evasion Mechanism (opens in a new tab)

    National Crime Agency and National Economic Crime Centre · · Accessed

  3. List of Russia sanctions targets, 20 May 2025 (opens in a new tab)

    Foreign, Commonwealth & Development Office · · Accessed

  4. Sanctions systems and controls in our firms: our findings (opens in a new tab)

    Financial Conduct Authority · · Accessed

  5. Financial sanctions (opens in a new tab)

    Financial Conduct Authority · · Accessed

  6. Swift and sanctions (opens in a new tab)

    Swift · Accessed

  7. Sanctions Notice, Russia: 16 June 2026 (opens in a new tab)

    UK Government · · Accessed

All Fraud & Security coverage