decrypted · 5 september 2026 · vulnerabilities and patching · uk policy and law · ai and llm security

The scam-compound deal that targets prosecutors, not payment rails

On Thursday the US Attorney for the District of Columbia, the UK's National Crime Agency and the Crown Prosecution Service for England and Wales signed a memorandum to run parallel investigations into the organised crime networks behind Southeast Asian scam compounds. It reads like a policing story, and mostly it is. But the reason it belongs here is what it says about the rails those scams run on: the same crypto exchanges, payment apps and messaging platforms that UK banks and fintechs build their own products on top of every day.

What the memorandum does

US Attorney Jeanine Ferris Pirro, NCA Director General Graeme Biggar and Crown Prosecutor Stephen Parkinson agreed to run joint investigations, share intelligence on the syndicates behind the compounds, and decide jointly which country prosecutes which case. The compounds themselves sit in Myanmar, Cambodia and Laos, staffed largely by trafficking victims and run by Chinese-linked organised crime with the cooperation of local officials, conducting romance and investment fraud at industrial scale. The two countries have already gone after one operator: Prince Group and its chief executive Chen Zhi, a case in which US authorities seized roughly $15 billion in bitcoin. A joint disruption operation involving law enforcement and private industry partners is planned for London in early October.

The design gap this doesn't fix

A memorandum coordinates prosecutors. It does not touch the reason the money keeps moving: victims are recruited through social platforms and dating apps, then walked through crypto on-ramps and payment rails that were built to move money quickly, with identity and source-of-funds checks treated as a compliance step to satisfy a regulator rather than a control built into the transaction path itself. That is the Secure by Design lesson for the UK firms that sit on these rails, not just the compounds that abuse them: friction on a large, first-time payment to a new beneficiary, or a newly onboarded exchange account moving straight to withdrawal, is not an inconvenience to be minimised. It is the control. Bolting verification on after the transfer clears, in the form of a suspicious activity report filed once the money is gone, is not the same thing as designing the system so the money is harder to move in the first place.

For UK banks, crypto platforms and the ad networks that carry the recruitment traffic, the practical take is to treat behavioural friction, cooling-off periods on new payees, and advertiser verification for financial promotions as core product decisions rather than afterthoughts layered on for the regulator. The compounds are someone else's jurisdiction. The rails are not.

Also this week

Chrome's sixth zero-day of the year. Google shipped Chrome 152.0.7977.82/.83 on 4 September, fixing twelve flaws including CVE-2026-85046, a type confusion bug in the V8 engine that Google says is already being exploited through malicious web pages. It is the sixth actively exploited Chrome zero-day patched this year. Chrome updates itself, but only on restart, so the practical advice for any UK organisation is to actually close the browser rather than leave the same tabs open for a week.

AI plumbing is now a live target. CISA's 2 September batch of known exploited vulnerabilities included CVE-2026-59822, an authentication flaw in BerriAI's LiteLLM gateway that lets an attacker mint a valid session using an arbitrary bearer token. Reporting says it is being chained with a second flaw to deploy cryptocurrency miners and harvest API keys and model-provider credentials. LiteLLM and similar tools are the plumbing a growing number of UK firms have wired into internal systems this year to connect chatbots to real data, usually with far less scrutiny than they would give a database.

The cloud basics still aren't done. A fresh look at Intruder's Cloud Security Index, covering misconfiguration data from 3,000 organisations to July 2026 and revisited this week by the Cloud Security Alliance, found weak identity controls and missing logging on 80 to 98 percent of accounts regardless of provider. AWS had the highest rate of exposed services at 76 percent against Google Cloud's 8 percent, but the number that matters for a UK board is the 80 to 98: whichever hyperscaler you have chosen, the basics of who can do what, and whether anyone would notice, are still mostly unmanaged.

Sources

If any of this touches your own systems or supply chain, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.