惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
爱范儿
爱范儿
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园_首页
博客园 - 叶小钗
酷 壳 – CoolShell
酷 壳 – CoolShell
Apple Machine Learning Research
Apple Machine Learning Research
云风的 BLOG
云风的 BLOG
量子位
博客园 - 三生石上(FineUI控件)
Stack Overflow Blog
Stack Overflow Blog
小众软件
小众软件
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
V2EX
人人都是产品经理
人人都是产品经理
V
Visual Studio Blog
Jina AI
Jina AI
L
LangChain Blog
M
MIT News - Artificial intelligence
MongoDB | Blog
MongoDB | Blog
Last Week in AI
Last Week in AI
Martin Fowler
Martin Fowler
WordPress大学
WordPress大学

Security

Scope Systems confirms cyber incident, says no data loss occurred Instructure breach: ShinyHunters says ‘matter has been resolved’ Rapid7 launches Cyber GRC program to connect compliance with live risk data Australian federal budget 2026: The industry perspective Op-Ed: Microsoft May Patch Tuesday reveals 137 vulnerabilities Federal Budget 2026: The state of cyber security spending for the coming year OpenAI offers EU early access to its cyber security model Exclusive: Aussie firm Earth Systems listed by INC Ransom hacking group Op-Ed: Why Middle East tensions demand immediate action on OT security Aussie schools breach: Instructure boss “reaches agreement” with ShinyHunters to not release data Institute of Public Accountants members hit by data breach Union demands answers on Qantas AI plans 1 in 3 small businesses don't think they're a cyber target, new research finds Exclusive: Aussie toy distributor listed by M3rx ransomware Exclusive: Australian Computer Society investigating possible breach after ShinyHunters hack claims The industry speaks – part 2: World Password Day 2026 Aussie schools breach: The Instructure hack “transcends an isolated IT incident” Exclusive: Aussie car part importer Strategic Imports allegedly breached by threat actors New South Wales, other states, investigating Instructure/Canvas data breach Australian Cyber Security Centre warns of ClickFix campaign leveraging Australian infrastructure Queensland Department of Education confirms students & staff impacted by ShinyHunters data breach ACMA takes action against SpinTel & Yomojo over mobile number fraud violations The Industry Speaks, Part 1: World Password Day 2026 Qualys and Converge tie cyber insurance pricing to real-time security posture Fakeout: Iranian APT caught hiding behind Chaos ransomware activity Exclusive: Australian energy management firm allegedly breached by SafePay Real estate giant Cushman & Wakefield confirms cyber incident, Qilin and ShinyHunters claim attack CrowdStrike expands Project QuiltWorks as more partners join AI security coalition Hacked: ALS discloses cyber incident, unauthorised access to IT systems Microsoft the main target of AI phishing attacks, report uncovers
Op-Ed: The transaction was legitimate; the crime was hidd...
Keith Bulfin · 2026-06-03 · via Security

One of the biggest misconceptions in financial crime is the belief that sophisticated criminal activity is hidden because transactions themselves appear suspicious.

In reality, the opposite is often true.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

The most sophisticated criminal systems frequently operate through transactions that appear entirely legitimate. A payment is made; an invoice is issued; funds move through recognised financial institutions; goods are shipped; customs documentation is completed; containers arrive at their destination.

Every individual component may appear legitimate when viewed in isolation. The problem is that organised crime does not operate in isolation.

It operates as a system. This is where what I describe as the “Operational Interpretation Gap” begins to emerge.

Across the world, financial institutions invest billions of dollars into:

• transaction monitoring
• AML systems
• AI-driven detection
• sanctions screening
• compliance programs
• governance frameworks.

Yet global illicit financial flows continue to exceed US$4.5 trillion annually. Why?

Because institutions often analyse transactions individually, while criminal organisations operate behaviourally across multiple jurisdictions simultaneously.

A payment may be sent to a company in Europe for goods that appear legitimate. A shipment may move through several countries. Funds may pass through multiple financial centres. Ownership structures may span several jurisdictions.

No single transaction triggers concern.

No individual participant sees the complete picture.

The criminal activity is not hidden inside one transaction. The criminal activity is hidden within the architecture connecting all of them – this distinction is critically important.

Compliance systems are generally designed to identify anomalies, and operational intelligence seeks to understand intent.

Compliance asks: “Does this transaction trigger a rule?”

Operational intelligence asks: “What larger system is this transaction part of?”

That question is becoming increasingly important as organised crime groups continue evolving into highly sophisticated multinational enterprises.

Many now employ:

• cyber specialists
• financial professionals
• logistics experts
• technology teams
• recruiters
• facilitators operating across multiple countries.

They understand jurisdictions. They understand regulatory differences. They understand how institutions share information. Most importantly, they understand that modern systems often analyse activity in fragments.

Their advantage comes from understanding the whole picture.

The future challenge for financial institutions, cyber professionals, regulators, intelligence agencies, and governance leaders is not simply collecting more data. It is in developing the capability to interpret behavioural systems operating behind that data.

Because ultimately, the transaction itself is rarely the story. The behavioural architecture behind the transaction is the story.

And until institutions become better at understanding that architecture, organised criminal systems will continue adapting faster than the systems designed to stop them.


Keith Bulfin is the founder of the Applied Financial Intelligence Programme and author of the bestselling book “Undercover”. His background includes work across global financial intelligence, organised crime investigations, illicit finance systems, and operational intelligence environments involving international agencies and investigations.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.