ASIC Sentences Former Finance Director Over Crypto Scam Proceeds: What Accounting Firms and CFOs Must Act On Now
On 22 July 2026, the Australian Securities and Investments Commission announced that Brendan Gunn, a former finance director, had been sentenced in the NSW Local Court for dealing with more than AU$180,000 that there was reasonable cause to suspect were proceeds of crime. The funds were connected to an offshore cryptocurrency investment scam that targeted Australian retail investors. For accounting firms, auditors, and CFOs with any exposure to digital asset businesses or clients that receive crypto-related deposits, this case contains compliance lessons that cannot be ignored.
Background: The Mormarkets Case
From December 2018, Gunn served as a director of Mormarkets Pty Ltd, a company trading under the name Coinshype. Mormarkets accepted deposits from Australians for cryptocurrency and other purported investments. Between January 2019 and May 2020, the company opened 22 separate bank accounts across six financial institutions.
The Warning Signs That Were Ignored
On multiple occasions, banks notified Gunn directly that they had received complaints alleging that funds credited to Mormarkets accounts were linked to fraud or other suspicious activity. Despite those warnings, Gunn continued to deal with the funds. When two of the Mormarkets bank accounts were eventually closed, he received two bank cheques totalling AU$181,000 that included investor deposits. He then forwarded those cheques to an associate. In January 2026, Gunn pleaded guilty to dealing with money that was reasonably suspected of being proceeds of crime.
The Sentence
The NSW Local Court sentenced Gunn to 12 months' imprisonment, with immediate release conditional on entering a recognizance of AU$3,000 requiring good behaviour for 12 months. That 12-month term was the maximum available in a summary prosecution for this class of offence. The matter was prosecuted by the Commonwealth Director of Public Prosecutions following a referral from ASIC.
Why the "Reasonable Suspicion" Standard Matters for Firms
The offence Gunn pleaded guilty to does not require proof that the funds were definitively proceeds of crime. The legal bar is lower: it requires only that a reasonable person in his position would have suspected the criminal origin of the money. This distinction is critical for anyone working in or alongside digital asset businesses.
Constructive Knowledge and Director Liability
Gunn was not a passive bystander. He received formal notifications from multiple banks, over an extended period, that customer complaints had been raised about funds flowing through Mormarkets accounts. ASIC Chair Sarah Court stated that he "ignored several clear warnings" and that by continuing to deal with those funds, he helped suspected international scammers move money taken from Australians. The regulatory view is that those warnings constituted constructive notice, and the failure to act on them was itself the offence.
For directors and senior officers of any entity that touches crypto-related cash flows, this creates a clear obligation: receiving a complaint or bank notification about suspicious activity is not a bureaucratic inconvenience. It is a legal trigger that demands a documented response. Firms using crypto accounting software or digital asset accounting software to track client flows need to ensure that compliance alerts generated by those systems feed directly into a triage and escalation process, not just a transaction log.
The Multi-Bank Account Pattern as a Red Flag
Twenty-two bank accounts across six institutions, opened in a 16-month window for a single operating entity, is a textbook structuring indicator. Australia's Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act) requires reporting entities to monitor for and report suspicious matters. But the Mormarkets pattern should also be recognised at the client onboarding and ongoing monitoring stage by any accounting firm or auditor engaged by a crypto-adjacent business. A client operating dozens of accounts across multiple institutions, receiving retail crypto deposits, and experiencing a pattern of fraud complaints is a client that warrants enhanced due diligence and, in some circumstances, a suspicious matter report.
ASIC's Broader Enforcement Context
This conviction does not sit in isolation. ASIC has built a multi-layered scam disruption programme that spans enforcement referrals, civil actions, and a website takedown capability that has removed more than 25,000 investment scam and phishing websites since its 2023 launch. That programme explicitly covers fake cryptocurrency investment platforms.
Scale of the Problem in Australia
ScamWatch and ReportCyber data for the first quarter of 2026 recorded a combined 60,657 scam reports with reported losses of AU$248.3 million. That figure covers a single quarter. Cryptocurrency investment scams account for a material share of that total, and cross-border structures, where Australian retail victims transfer funds to offshore entities through domestic intermediaries like Mormarkets, remain the dominant vehicle.
ASIC coordinates its scam response with the National Anti-Scam Centre and law enforcement agencies. The Gunn prosecution followed an ASIC investigation and a referral to the CDPP, a pathway that signals ASIC's willingness to use criminal referral mechanisms, not just civil penalty proceedings, when the facts support it. Accounting firms and CFOs should treat this as evidence that ASIC's enforcement appetite in this space has expanded, not contracted. Refer also to ASIC's earlier action against NAB's WealthHub for reporting failures for a parallel example of the regulator holding institutions to account for control weaknesses.
The International Dimension
ASIC describes the underlying scam as an international cryptocurrency scam that targeted Australians. This cross-border element is increasingly common. Offshore operators establish the fraudulent investment proposition, domestic intermediaries handle the cash collection and movement, and Australian retail victims bear the loss. The Gunn case illustrates that ASIC is focused on the domestic layer of that chain, even where the ultimate beneficiaries are offshore and may remain out of reach. For compliance professionals, this means that acting as a payment intermediary or account holder for a cross-border crypto operation without rigorous due diligence creates genuine criminal exposure, regardless of where the alleged fraud originates.
The global enforcement trajectory reinforces this. The FATF's 7th targeted update on crypto highlighted the enforcement gap as the central challenge for regulators, and Australia's actions in this space are consistent with the FATF's expectation that member jurisdictions pursue both primary offenders and those who facilitate illicit flows.
Accounting and AML Implications for Firms
There are several practical areas where this case should prompt a review.
Client Onboarding and Ongoing Monitoring
Any firm that provides bookkeeping, accounting, or audit services to a crypto deposit-taking or crypto investment business in Australia needs to confirm that its client acceptance procedures include a review of banking arrangements. A client operating a large number of accounts relative to its size, or across an unusual number of institutions, warrants explanation. If those accounts are also the subject of bank-initiated fraud complaints, the firm has an obligation to assess whether continued engagement is appropriate and whether a suspicious matter report is required under the AML/CTF Act.
Transaction Monitoring and Documentation
Crypto bookkeeping software and digital asset accounting software can surface anomalies in cash flow patterns, including unusual volumes relative to a client's stated business purpose or rapid cycling of funds across accounts. The Mormarkets pattern, repeated deposits followed by consolidation and onward transfer via bank cheques, is the kind of pattern that well-configured transaction monitoring should flag. However, technology only creates the alert. The firm's documented response to that alert is what determines whether the firm has met its legal obligations. That documentation needs to exist, be time-stamped, and be retained.
Director and Officer Exposure
The Gunn case is a reminder that exposure to proceeds-of-crime liability is not limited to the primary scam operators. A director who receives warnings and continues to deal with the funds faces the same criminal offence, regardless of whether they designed the scam. For CFOs and finance directors of any crypto-adjacent business, this creates a personal obligation to act on compliance alerts promptly and to ensure that decisions about continuing to deal with flagged funds are documented and, where appropriate, escalated to the board or external counsel.
Audit Considerations
Auditors working on engagements that involve crypto deposit-taking entities should consider whether the client's banking arrangements, complaint history, and account opening patterns are consistent with a legitimate business. Where a client has received bank notifications about suspected fraudulent activity and cannot demonstrate a documented response, auditors need to assess whether that constitutes a reportable matter under their professional obligations and whether it affects the risk assessment for the engagement as a whole.
What Firms Should Do Now
Three immediate steps are worth prioritising. First, review client portfolios for any crypto-adjacent businesses that receive retail deposits and assess whether their banking arrangements and complaint histories have been adequately documented. Second, confirm that your firm's AML programme includes a clear escalation path for bank notifications and fraud complaints received by clients. Third, ensure that any crypto accounting software or digital asset accounting software in use is configured to flag account proliferation and rapid fund cycling as transaction monitoring triggers, and that the process for handling those flags includes documented human review.
ASIC's scam disruption programme is active and expanding. The Gunn conviction demonstrates that the regulator will pursue criminal referrals against facilitators, not just primary operators, and that the reasonable suspicion standard gives it a relatively accessible legal threshold to work with. Firms that have not reviewed their exposure in this area since the AML/CTF legislative updates should treat this case as a prompt to do so.
Source: ASIC Media Release 26-167MR
FAQ
Gunn pleaded guilty to dealing with money where there was reasonable cause to suspect it was proceeds of crime. The AU$181,000 involved was connected to an offshore cryptocurrency investment scam targeting Australian retail investors.
The offence does not require proof that funds were definitively criminal in origin. It applies where a reasonable person in the same position would have suspected a criminal link. For accounting firms, this means that receiving a bank notification or client complaint about suspected fraud creates a legal trigger to investigate, document a response, and consider whether a suspicious matter report is required.
Yes. The Gunn case confirms that a director who receives warnings about suspected fraudulent activity and continues to deal with those funds can face the same criminal offence as a primary offender. Personal liability is not limited to those who designed the scheme.
Under Australia's AML/CTF Act, reporting entities must conduct customer due diligence, monitor transactions for suspicious activity, and lodge suspicious matter reports where appropriate. Accounting firms that are not themselves reporting entities still have professional obligations to assess client risk and, in some circumstances, to cease engagement if a client's activities present unacceptable AML exposure.
ASIC operates a service that removes investment scam websites and advertisements, including fake cryptocurrency investment platforms. Since its 2023 launch, more than 25,000 such sites have been taken down. The Gunn prosecution represents the enforcement arm of the same programme: where takedowns address the online presence of scams, criminal referrals target the human facilitators who enable money movement.
