I spend my days inside fraud networks most Americans never see â dark web forums, Telegram channels and marketplaces where stolen identities are bought and sold like commodities. I study them because understanding how these systems work is the only way to stay ahead of them.
What Im seeing right now should concern every American.
Iran, North Korea, Russia and are not just conducting cyberattacks against the United States. They are running coordinated financial fraud operations inside our system â deliberately, systematically and in ways our defenses were never designed to detect.
This isnt ordinary . Its statecraft.
While policymakers rightly focus on to power grids and water systems, a quieter operation is already underway, and this is one that reaches directly into the U.S. financial system using the same tools as everyday fraudsters.
Iran has spent decades building what amounts to a parallel financial network that is designed to function when access to the formal system is restricted.
It relies on front companies registered across multiple jurisdictions, nominee directors who exist only on paper and bank accounts opened with stolen or . Each new round of sanctions forces adaptation and, each time, the system evolves. We see new shell companies appear and new identities being deployed. Funds are routed through intermediaries that cannot see who is actually behind the transactions.
For example, on June 6, 2025, the Office of Foreign Asset Control (OFAC) sanctioned over 40 individuals and entities linked to the three Zarringhalam brothers â Mansour, Nasser, and Fazlolah –brothers for laundering billions through Irans “shadow banking” network. This network uses exchange houses and front companies in the UAE and Hong Kong to evade sanctions and move funds from oil and petrochemical sales.
The operation enables payments to flow through international banks in multiple currencies on behalf of sanctioned Iranian entities, including -linked groups. Proceeds help finance Irans nuclear and missile programs as well as support terrorist proxies.
North Koreas approach is even more direct.
The regime has U.S. companies using fabricated identities. These are not low-level scams. The identities are constructed from stolen personal information, purchased documents, and in some cases fully synthetic profiles built to pass employment verification.
Those workers draw legitimate salaries, which flow into accounts that feed into laundering pipelines. The of transactions designed to look like ordinary retail banking activity, until its origin is effectively invisible.
Russia plays a different role: supplier.
Infostealer malware operations harvest numbers, dates of birth and account credentials from millions of Americans. That data feeds dark web markets where identity components are packaged and sold to criminals and foreign state actors alike.
China, by contrast, plays a long game. In 2015, Chinese state actors breached the Office of Personnel Management, exposing sensitive data on 21.5 million people. That was one of the most impactful intelligence windfalls of recent times and it created a durable identity dataset that has been detailed enough to build, verify and sustain false identities at scale.
That data didnt disappear after the breach. It has circulated for years in underground markets, where it can be combined with other stolen information to construct identities that pass financial and employment checks.
In other words, China didnt just steal data. It helped seed the very id
