The U.S. Treasury’s Office of Foreign Assets Control sanctioned Xinbi Guarantee, a Chinese-language online marketplace, on September 9, along with two entities that supply it with digital currency and financial services. The Justice Department’s Scam Center Strike Force simultaneously seized infrastructure and digital asset wallets tied to the platform. Treasury says Xinbi Guarantee has processed more than $24 billion in digital assets and fiat currency since roughly 2022, operating as an escrow and payments layer that connects scam center operators in Southeast Asia with the merchants who supply them technology, money laundering services and other criminal infrastructure.
“Scam centers in Southeast Asia steal billions of dollars from American victims each year,” said Secretary of the Treasury Scott Bessent. “The Trump Administration is united in its efforts to dismantle these overseas criminal enterprises, and Treasury will continue using its tools to disrupt the networks behind this egregious fraud and protect Americans.”
Why it matters to security teams specifically: Treasury’s own release states Xinbi’s platform has reportedly been used by North Korean hackers as well as by entities already designated under the Prince Group transnational criminal organization sanctions. That puts Xinbi in the same category of shared criminal infrastructure this publication covered today in Proofpoint’s report on the BlueMoon exploit kit, a single piece of infrastructure or tooling that quietly supports many otherwise unrelated threat actors. The original insight is that disrupting the marketplace, rather than any single scam operator, is now the explicit strategy, following the same approach Treasury and the UK’s Foreign, Commonwealth and Development Office have already taken against the related Prince Group and Huione Group networks. Security and compliance teams that have any exposure to sanctioned wallets or laundering-adjacent crypto infrastructure should treat today’s designations as a prompt to re-screen counterparties, not just a law enforcement headline.
Source: U.S. Department of the Treasury. See also our coverage of a separate Chinese hacking-tools vendor seizure and this week’s joint advisory on Chinese AI model theft.