Russia FSB Arrests 20-Plus in Unlicensed Crypto Exchange Sweep at Moscow City
Russia's Federal Security Service (FSB) has detained more than 20 people in Moscow City, the capital's high-rise business district, accusing them of running unregistered cryptocurrency exchange offices that allegedly funnelled money stolen from Russian citizens to Ukraine. The action is one of the most publicly visible domestic crypto enforcement moves Moscow has announced in recent months, and it carries direct implications for any accounting firm or CFO whose clients hold counterparty exposure to Russian-linked crypto venues or payment channels.
What the FSB Said Happened
According to the FSB's public statement, the arrested individuals operated physical crypto exchange offices that were not registered with Russian financial regulators. The agency claims the wider scheme relied on call centers based in Ukraine that contacted Russian residents remotely, including pensioners, and kept them on the phone while guiding them step by step through purchasing cryptocurrency at these offices and then transferring the acquired assets to accounts the suspects controlled.
Key operational details the FSB disclosed
The FSB said it also acted alongside Russia's Interior Ministry to shut down nine channels that had been used to move funds abroad via cryptocurrency. Separately, the agency stated that the exchange offices recruited young people from Russian regions who were seeking income but lacked formal financial literacy, suggesting a deliberate targeting of individuals with limited regulatory awareness as frontline operators.
What the FSB did not disclose
The statement left out several details that would ordinarily be central to any credible enforcement disclosure. The FSB did not name the exchange offices or venues involved, did not identify the specific cryptocurrencies used, and did not provide a figure for the total sums allegedly stolen from victims. It also released no documentary evidence to substantiate its claim that the scheme was coordinated from Ukrainian call centers. That absence of verifiable detail is itself a compliance consideration: firms cannot screen against unnamed counterparties.
The Regulatory and Legal Context in Russia
Russia has been tightening its domestic crypto framework over the past year. Operating a cryptocurrency exchange without registration or a licence from the relevant Russian financial authority is a violation of domestic law, and regulators have signalled that unregistered exchange offices are a primary enforcement target. The FSB framing this sweep as part of efforts to crack down on entities allegedly funding Ukraine's war effort adds a national-security dimension that goes beyond routine financial-crime enforcement, and that framing matters for firms assessing reputational and sanctions risk.
How this fits the broader sanctions picture
Western regulators have been moving in parallel. The EU's 21st Russia sanctions package explicitly targeted crypto platforms, introducing new designation powers and naming specific venues. Firms that have already reviewed their exposure in response to those measures should now layer in the risk that domestic Russian enforcement may surface additional unlicensed operators who have been processing cross-border crypto flows. Our earlier coverage of the EU 21st Russia sanctions package targeting crypto platforms sets out the designation framework in detail and is a useful reference point for firms mapping their counterparty lists.
AML and Licensing Implications for Accounting Firms
For accounting firms advising clients with any Russian crypto exposure, this enforcement action raises three immediate questions that should be worked through systematically.
Counterparty identification and transaction tracing
The FSB's refusal to name the exchanges involved creates a genuine due-diligence gap. Firms cannot add unnamed entities to a sanctions or watchlist screening process. What they can do is review whether any client transactions have been routed through physical exchange offices in Russia, particularly in Moscow City, and assess whether those venues held valid registrations at the time of the transaction. Digital asset accounting software that captures on-chain transaction metadata and exchange identifiers is essential here: manual ledger entries that record only the fiat settlement amount will not provide enough information for a meaningful AML review.
Suspicious activity reporting thresholds
In jurisdictions where your firm has SAR or STR obligations, a transaction routed through an unregistered Russian exchange office, even if the underlying client was not aware of its unlicensed status, may cross the threshold for a report. The key test in most frameworks is whether the firm knew or had reasonable grounds to suspect that funds were connected to criminal activity. The FSB's public allegation that these offices were used to receive stolen funds is now a matter of public record, which means firms can no longer claim lack of awareness as a complete defence if similar routing appears in a client's transaction history.
Engagement letters and client risk ratings
Any client whose crypto activity touches Russian OTC desks, physical exchange offices, or P2P brokers operating in Russia should be reviewed against enhanced due diligence criteria. This is not a new obligation, but the FSB action provides a concrete, documented trigger for upgrading risk ratings where they have not already been elevated. Compliance teams should document the date of this public enforcement action and the steps taken in response, because that paper trail becomes evidence of a functioning compliance framework if a regulator ever asks.
Implications for CFOs with Russian Crypto Exposure
CFOs at firms or treasury operations that hold crypto assets, or that have accepted crypto payments from Russian counterparties, face a narrower but equally pressing set of questions.
Counterparty due diligence on exchange venues
If your treasury has used a Russian exchange venue to convert, hold, or transfer crypto, the first step is confirming that venue holds valid registration under Russian law and does not appear on any sanctions list. The FSB action demonstrates that unlicensed venues can operate at scale in prominent commercial locations, meaning that a high-profile address is not, by itself, evidence of regulatory compliance. Any digital asset accounting software or crypto bookkeeping software used to record treasury transactions should tag exchange counterparties with their licensing status so that a compliance review can be run quickly if a venue is later named in an enforcement action.
Financial statement disclosure considerations
Where a CFO has identified a transaction that may have passed through an unlicensed exchange, the question of whether a contingent liability or disclosure note is required depends on the jurisdiction and the applicable accounting standard. Under IFRS, where a material uncertainty exists about the recoverability of an asset or the potential for regulatory action, disclosure in the notes to the financial statements is generally required. CFOs should loop in their external auditors promptly rather than waiting for a formal regulatory inquiry.
Sanctions screening and OFAC/OFSI exposure
Even if your firm is not subject to Russian domestic law, transactions that passed through exchange offices later found to have been involved in moving funds for sanctioned purposes can create secondary sanctions exposure. The precedent set by enforcement actions such as the OFAC designations of Hamas crypto facilitators and TRON addresses shows that US authorities are willing to designate both the operators and the infrastructure used. CFOs should not assume that geographic distance from Russia provides insulation.
What Firms Should Do Now
Given the information gaps in the FSB's disclosure, the practical response is procedural rather than reactive. Firms and their clients cannot screen against unnamed counterparties, but they can strengthen the processes that would surface a problem if more names are released.
Immediate steps
First, pull a transaction review for any client or treasury account with Russian-linked crypto activity in the relevant period and flag transactions routed through physical exchange offices. Second, confirm exchange licensing status for every Russian venue in your counterparty records using publicly available Russian central bank and financial regulator data. Third, document the review in writing, including the date, the trigger (this FSB enforcement action), the scope, and the outcome. Fourth, escalate to your MLRO or compliance officer any transaction where the venue's licensing status cannot be confirmed.
Robust crypto bookkeeping software and digital asset accounting software that maintains a full audit trail of exchange counterparty identifiers, transaction timestamps, and on-chain references is not a luxury in this environment. It is the foundation that makes a compliance review possible within hours rather than weeks.
Frequently Asked Questions
Does this FSB action create any direct legal exposure for Western accounting firms?
Not directly, since Western firms are not subject to Russian domestic criminal law. The risk is indirect: if a client's transaction history includes flows through venues later found to be involved in money laundering or to be connected to sanctioned persons, the firm may face obligations under its own jurisdiction's AML framework, including SAR filing and enhanced due diligence requirements.
How can a firm screen against counterparties the FSB has not named?
It cannot screen against unnamed entities in the traditional sense. The practical response is to review whether any client transactions used physical exchange offices in Russia, verify licensing status through the Russian regulator's public register, and flag unverifiable venues for enhanced scrutiny. If more names are released by Russian authorities, those should be run against existing transaction records immediately.
Does a transaction through an unlicensed exchange automatically trigger a SAR obligation?
Not automatically in most jurisdictions. The trigger is reasonable suspicion of a connection to criminal property or money laundering. The FSB's public allegation that these offices received stolen funds is now a matter of public record, so firms should assess whether that allegation, combined with specific transaction facts, crosses the reasonable suspicion threshold under their applicable legislation. Legal advice specific to the jurisdiction is warranted where the position is unclear.
What accounting standard governs disclosure where a CFO suspects a transaction passed through an unlicensed venue?
Under IFRS (IAS 37 and IFRS 7), where a material uncertainty exists, disclosure in the notes is generally required even if no formal regulatory claim has been made. Under US GAAP, ASC 450 on contingencies applies a similar principle. The specific disclosure depends on materiality and the likelihood of a financial outflow. Auditors should be consulted promptly.
Is Russian crypto activity automatically high-risk for AML purposes after this action?
Russian-linked crypto activity has been elevated-risk under most Western AML frameworks for some time, given existing sanctions regimes and FATF guidance. This FSB action reinforces that position but does not, by itself, change the legal classification. Firms should ensure their risk ratings already reflect the elevated risk profile of Russian crypto counterparties and review whether any ratings need updating in light of this development.
Source: CoinDesk Policy
