HOW USEFUL WAS THIS POST? RATE, LEAVE A COMMENT REQUESTING CHANGES, AND WE’LL AMEND ACCORDINGLY.
OFAC sanctions Xinbi, Meta faces claims over unauthorized biometric data use, and the FATF sheds light on ML and TF red flags in the gambling sector. This edition of Risk Wrap highlights six developments shaping compliance, governance, and insurance exposure across high-risk industries.
$52 Million in Crypto Restrained as OFAC Sanctions Xinbi
The US Treasury’s Office of Foreign Assets Control has sanctioned Xinbi Guarantee, a Chinese-language illicit marketplace that authorities say has processed more than $24 billion in digital assets and fiat currency to date.
OFAC designated 52 cryptocurrency addresses linked to Xinbi that had received more than $8.4 billion in stablecoins, while the Justice Department’s Scam Center Strike Force seized $12 million in crypto. In total, $52 million in crypto was restrained.
North Korea-linked actors have moved tens of millions of dollars through Xinbi’s network, including $1.5 billion from the Bybit breach and $235 million from the WazirX theft.
Vendors referred to as “Black U” launderers take the stolen funds and replace them with stablecoins from other illicit streams, as shown below. Mixing the funds together like this reduces traceability and provides North Korea-linked actors with assets they can convert to fiat.
Implications for brokers and their clients:
- Consider D&O cover that reflects the growing management exposure created by rapidly changing sanctions and other regulatory designations.
- Consider digital asset crime insurance to cover losses arising from the theft, fraud, or misappropriation of digital assets, including exposures involving hot and cold wallet custody.
- Consider specialized digital asset insurance that accounts for the sector’s varied exposures, including fraud, custody risks, smart contract failure, protocol vulnerabilities, and regulatory risks.
Source: Chainalysis (September 9, 2026). OFAC and DOJ Strike Xinbi, a Multibillion-Dollar Marketplace for Cybercriminals.
Emerging insurance industries mentioned: Digital Asset and Web3 Insurance.
Lines of business mentioned: Directors and Officers Liability Insurance, Digital Asset Crime Insurance.
Meta Lawsuit Puts AI Wearables’ Biometric Risks Under Scrutiny
Meta’s smart glasses are at the center of a proposed class action lawsuit brought by parents and their children in California and Illinois. The lawsuit concerns the NameTag feature, which was reportedly designed to enable facial recognition through the glasses.
The plaintiffs allege that Meta used photographs from Facebook and Instagram to develop NameTag and train AI models including Emu and Muse Image, without getting permission to use the biometric information contained in those images. The lawsuit claims this violated privacy laws in both states.
NameTag hasn’t been released, but an analysis found that the proposed system could convert faces captured by the glasses into biometric signatures and compare them against “faceprints” stored on the user’s phone. The suit also refers to a Meta-owned patent for facial matching.
Meta disputed the allegations, stating that it’s not developing a universal database of faces and that no decision has been made about releasing NameTag.
Implications for brokers and their clients:
- Companies developing AI-enabled wearables may consider tech E&O insurance to cover exposures arising from the design and operation of systems that process biometric information.
- Firms collecting or processing biometric data should assess whether their cyber liability coverage addresses the potentially significant privacy liabilities associated with the unauthorized collection, use, or disclosure of that information.
- Consider D&O insurance to protect executives from exposures related to the development and deployment of AI features that process biometric data.
Source: PYMNTS (September 14, 2026). Meta Faces Lawsuit Over Smart Glasses Facial Recognition.
Lines of business mentioned: Tech E&O Insurance, Cyber Liability Insurance, Directors and Officers Liability Insurance.
New FATF Report Details ML Red Flags in Gambling Sector
The Financial Action Task Force has published a new report detailing risk indicators of potential money laundering, terrorist financing, and proliferation financing in the gaming and gambling sector. The risks are based on an industry consultation and questionnaire responses across 80 jurisdictions. The FATF recommends licensing and registration requirements be strengthened to prevent criminal activity.
Some of the risks identified are:
- IP and device anomalies: The IP address doesn’t match the customer’s stated location, several accounts are accessed from the same IP address or device, or the IP address repeatedly changes location between logins.
- Shared customer infrastructure: Multiple accounts use the same physical address, contact details, bank account, or payment method.
- Unusual withdrawal patterns: Funds are withdrawn to an account different from the original funding source, or deposits are followed by withdrawals with little or no gambling activity in between.
- Dormant balances: Customers leave unusually large sums in their accounts for extended periods without meaningful gambling activity.
- Coordinated gambling: Customers repeatedly play together in patterns where one consistently wins and another loses, or appear to bet on opposing outcomes of the same event.
- Unusual funding networks: A customer funds an account through numerous international bank accounts, or multiple customers use the same bank account or payment method to fund or withdraw from their accounts.
- Threshold avoidance: A customer repeatedly collects winnings just below a customer identification threshold or structures deposits into amounts that fall below reporting thresholds.
Implications for brokers and their clients:
- Review existing policies for coverage relating to regulatory action, investigations, and associated legal or defense costs.
- Consider specialized gambling insurance designed around the regulatory, operational and other exposures of gambling operations.
- Consider business interruption cover in case of losses arising from temporary suspension of operations due to regulatory investigations or enforcement.
Source: FATF (September 9, 2026). FATF warns of emerging risks in gaming and gambling and publishes new risk indicators.
Emerging insurance industries mentioned: Gambling Insurance.
Lines of business mentioned: Business Interruption Insurance.
EU Crypto Wallet Providers Face New Cyber Reporting Rules
New reporting obligations under the EU’s Cyber Resilience Act (CRA) came into effect on September 11. The CRA is not crypto-specific legislation, but it covers hardware and software products with digital elements that are made commercially available in the EU. This brings products like hardware wallets and wallet applications within its potential scope.
Where a manufacturer becomes aware that attackers are actively exploiting a vulnerability, it must report the issue to the relevant national Computer Security Incident Response Team and the EU Agency for Cybersecurity through a designated reporting platform.
An initial warning is due within 24 hours, which must also detail which member states the product is available in. Within 72 hours, a more detailed notification is required, which explains the nature of the vulnerability and exploit, as well as any corrective or mitigating measures taken and the measures that users can take.
A final report must be submitted within 14 days of a mitigation measure becoming available, which must describe the severity and impact of the vulnerability. If information on the attackers is known, that must also be included, along with further details on corrective measures. Non-compliance may lead to substantial fines.
Implications for brokers and their clients:
- Review whether existing cyber liability policies cover the specific risks faced by crypto firms, including vulnerabilities affecting wallet software and hardware, and associated security incidents and regulatory response costs.
- Consider directors and officers insurance to cover executives in case of non-compliance.
- Consider specialized crypto asset insurance that covers the sector’s key exposures across jurisdictions.
Source: CryptoTicker (September 13, 2026). Reporting Duty for Wallet Makers: What Has Applied Since September 11, 2026.
Emerging insurance industries mentioned: Digital Asset and Web3 Insurance.
Lines of business mentioned: Cyber Liability Insurance, Directors and Officers Liability Insurance.
US Weighs New Duty of Care Rules for AI Developers
US Senate negotiators are considering legislation that would establish a new ‘duty of care’ for AI developers, requiring companies to design certain AI products with the aim of preventing catastrophic risks.
The proposal could also give the government authority to prevent the release of AI models considered unsafe. Examples given by a Senate aide include the possibility that they could be used to design nuclear or bioweapons. Companies would have the option to challenge decisions in court.
The discussion around this prospective legislation follows concerns about AI agents going rogue and hacking external systems.
Implications for brokers and their clients:
- Consider specialized AI coverage from providers with expertise in the regulatory requirements governing AI across jurisdictions. This can help address exposures created by evolving duties of care and differing approaches to AI oversight.
- Review professional liability coverage for claims arising from errors, omissions, or failures in the development and deployment of AI systems, particularly where new safety obligations increase expectations around risk assessment and safeguards.
- Review directors and officers insurance in light of emerging AI governance requirements.
Source: Reuters (September 11, 2026). US Senate negotiators consider requiring AI firms to mitigate known major risks.
Emerging insurance industries mentioned: Artificial Intelligence Insurance.
Lines of business mentioned: , Errors and Omissions Insurance.
Revolut Data Exposed Through “Sophisticated Impersonation Scam”
Revolut has disclosed that an unauthorized party obtained sensitive customer information by submitting bogus data requests from an email address associated with a genuine government domain. The incident has been described as a “sophisticated external impersonation scam”.
The information potentially disclosed includes customers’ names, dates of birth, contact details, and copies of passports and driving licenses. Verification selfies, account statements, IBANs, withdrawal records and transaction histories, including Bitcoin transactions, may also have been accessed.
Revolut said the incident affected a limited number of customers and that it has contacted those individuals. The company said its systems and customer funds were not compromised.
Implications for brokers and their clients:
- Investigate specialized fintech insurance designed around the combined financial and technological exposures of the sector.
- Review cyber insurance policies to ensure they address social engineering attacks that result in the disclosure of sensitive customer information, including investigation, notification, and regulatory response costs.
- Assess whether crime policies provide adequate protection against losses caused by fraudulent transactions, impersonation, and other deceptive schemes.
Source: THE BLOCK (September 12, 2026). Revolut says customer KYC, Bitcoin transaction data exposed after fake request from gov’t domain.
Emerging insurance industries mentioned: Fintech Insurance.
Lines of business mentioned: Cyber Liability Insurance, Crime Insurance.