A wire transfer originates at a bank in the , routes through a correspondent bank in Europe and lands at an American financial institution as what appears to be a routine commercial payment. The compliance team at the receiving bank sees a company with clean corporate filings, a beneficial owner whose documents check out, and a payment from a jurisdiction that carries no sanctions risk. Nothing triggers a flag. On the other end of that transaction is the Iranian government, and the identity documents underpinning the shell company that sent it were assembled from stolen Social Security numbers purchased on a dark web market six weeks earlier.
I spend my days inside the fraud networks that make operations like this possible, monitoring dark web markets, Telegram channels, document forgery platforms and the facilitator networks that handle logistics on the ground. Iran, North Korea, Russia, and China are all running operations working to overcome the defenses of American institutions right now. The machinery they rely on is more visible than most people assume, if you know where to look.
Every one of these operations starts in the same place: underground markets selling stolen identity components. Social Security numbers, dates of birth, address histories, account credentials, all harvested from data breaches, packaged, and priced by freshness and geographic origin. Russia supplies more of this raw material than any other country, through infostealer malware that captures everything typed or stored on a victims computer and quietly sends it to collection servers for sorting and resale.
One of the marketplaces I monitor, a Telegram channel called “Karma Fullz,” is run by Russian-speaking actors and sells the identities of former legal immigrants to the , bundled with associated bank accounts and established credit histories. Buyers use them to incorporate shell businesses and defraud financial institutions and government programs.
Another market I tracked, “South Park BA Logs,” sells compromised U.S. bank account credentials bundled with session cookies, browser fingerprints and linked email access. Between March 2023 and January 2026, in a paper I recently published, I identified 1,210 listings on that single channel, representing an estimated $152 million in accessible financial exposure.
Chinas contribution to this supply came in a single, devastating operation. In 2015, Chinese state hackers breached the Office of Personnel Management and walked out with 21.5 million federal employee records: security clearance files, psychological evaluations, financial histories, foreign contacts. An identity built from OPM material can do more than open a bank account. It can clear a background check, survive a hiring process at a sensitive institution, and accumulate access quietly for years. That data is still circulating more than a decade later.
This is the foundation that everything else rests on. What each government builds on top of it varies, but the raw material is shared.
The wire transfer I opened with illustrates a vulnerability that runs through the entire correspondent banking system. Each institution in a multi-bank chain sees only its own segment of the transaction, and Iran has engineered a architecture around that structural blind spot.
The front companies populating these chains carry nominee directors on their corporate filings and beneficial owners whose identities were fabricated from the same . Every time a new sanctions designation lands, the structure reconstitutes: different shell companies, different names, different routing that pushes the Iranian connection one layer further from view.
The same technique defeats screening. The Committee on Foreign Investment in the United St