Skip to main content
WebID
WebID
All contributions
AMLR

The Laundromat – August Edition 2026

Recent Fraud Cases Underscore Need for EU-wide AML Harmonization

Author
Authored byWebID Team
Published on08/24/2026

Welcome to the August issue of The Laundromat newsletter, in which we take a look at recent cases of financial fraud and money laundering and their implications in practice.

Here’s what you’ll find in this issue:

  • Why recent cases once again confirm the need for EU-wide harmonization of regulatory requirements
  • The role that pluralistic identification ecosystems play in this context
  • How these can be seamlessly integrated into EU-AMLR-compliant Know Your Customer (KYC) and Know Your Business (KYB) architectures

Caritas Luxembourg Involved in Fraud and Money Laundering Scandal: Over 61 Million Euros in Losses

In connection with the embezzlement of approximately 61.2 million euros in the spring of 2024 at the Catholic aid organization Caritas Luxembourg, a suspected key figure in the money laundering network was arrested in Rome in early June this year.

According to investigators, nearly the entire annual budget of Caritas Luxembourg was embezzled through approximately 8,200 fraudulent wire transfers. The perpetrators allegedly used a so-called “CEO fraud” scheme, in which employees were tricked into authorizing payments through social engineering. The alleged key figure is accused of establishing shell companies in several EU countries, opening bank accounts in Italy, Austria, Sweden, Portugal, and other countries, and creating forged documents to conceal the origin of the funds. She is also alleged to have coordinated the money laundering on behalf of one of the main organizers.

This money-laundering scandal has far-reaching consequences, as outlined on the Comsure Compliance Limited website:

Caritas Luxembourg was forced to suspend numerous aid projects and undergo a comprehensive reorganization. As early as 2025 (even before the alleged money laundering coordinator was arrested) the Luxembourg state-owned bank Spuerkeess was fined nearly 5 million euros for serious deficiencies in its anti-money laundering measures.

The case led to increased regulatory scrutiny and stricter requirements for banks and other financial service providers, particularly regarding transaction monitoring, customer due diligence, and the monitoring of cross-border payment flows. It also highlights structural gaps that will be addressed by the EU AML package, which becomes mandatory on July 10, 2027:

  • Approvals without reliably verified identities
  • Shell companies without robust UBO verification
  • Account openings in multiple countries, each of which appears plausible when considered in isolation.

Achieving Fraud Resilience Across the EU

Regulated companies can improve their fraud resilience by managing onboarding and reevaluation processes through a pluralistic identification ecosystem that complies with the requirements of the EU AML package. This is the only way to prevent individual procedures from becoming a single point of failure. NFC, eID, and wallet-based verification, as well as alternative, eIDAS 2.0-certified identification methods, render fake identities useless; sophisticated KYB procedures trace ownership chains back to the natural person; and strong authentication eliminates the vulnerability to (CEO) fraud.

Cyberattack on Liechtenstein's Registry of Beneficial Owners

On the night of July 30, 2026, hackers gained access to Liechtenstein’s registry of beneficial owners. On August 3, 2026, the government reported that copies of data on approximately 31,000 legal entities, including their underlying beneficial owners, had been compromised. With a population of about 41,000, this is a scale that extends far beyond Principality. The Liechtenstein Bankers Association emphasizes, however, that no banks and no bank customer data were affected.

Various sources, including heise online, reported on this cyberattack on the Liechtenstein registry.

What is noteworthy is not so much the attack itself as its target: a key tool for preventing money laundering was compromised, since such registries naturally centralize the very information attackers seek – namely, names, chains of ownership, and economic attribution. However, this centralization can also be interpreted as a potential structural vulnerability.

Focus Shifting for Obligated Entities: From Security of the Registry to Security of their Own System Architecture

The EU-AMLR views registry queries as a supplementary, but not sufficient, source for determining the UBO; independent, risk-based verification remains mandatory. Risks to confidentiality, integrity, and availability therefore converge from three directions toward the same consequence: The chain of ownership and the persons acting on behalf of the entity must be verified through KYB procedures, including document review and unambiguous identification of individuals. Those who verify the persons acting on behalf of the entity (after receiving the complete KYB file from a primary source) through a seamlessly integrated eIDAS 2.0-compliant identification process can significantly reduce the risk of fraud.

Further Reading

Designing an Efficient Know Your Business Process

Considering the EU AML Regulation, companies in regulated industries should document their Know Your Business processes in a more data-driven, auditable, and verifiable manner. They are supported in this effort by automated procedures that generate complete KYB files for their business customers in a cost- and resource-efficient manner. You can read here how this can be achieved, for example, via CorporateID from WebID.

Automate KYB Easily

27 National Wallets, One Integration: EUDI Wallet Connector

With the mandatory acceptance of the EUDI Wallet, obligated companies face a key question: How does integration into the identification ecosystem work, not only in theory, but also across national borders? WebID’s EUDI Wallet Connector has already been verified against six national test environments. In practice, this means less fragmentation in the identification pathways, with a single integration for all European markets instead of isolated solutions for each country.

All Details Here

Your Roadmap to AMLR Readiness

Discover how modern KYC and KYB solutions can help your organization prepare for the EU-AMLR and build a future proof compliance framework.

EU-AMLR Compliant Identity Verification