惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
爱范儿
爱范儿
GbyAI
GbyAI
博客园 - 叶小钗
Last Week in AI
Last Week in AI
Jina AI
Jina AI
Microsoft Security Blog
Microsoft Security Blog
云风的 BLOG
云风的 BLOG
C
Check Point Blog
H
Help Net Security
P
Proofpoint News Feed
酷 壳 – CoolShell
酷 壳 – CoolShell
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
大猫的无限游戏
大猫的无限游戏
H
Hackread – Cybersecurity News, Data Breaches, AI and More
B
Blog RSS Feed
Y
Y Combinator Blog
U
Unit 42
T
Tailwind CSS Blog
MyScale Blog
MyScale Blog
N
Netflix TechBlog - Medium
S
SegmentFault 最新的问题
J
Java Code Geeks
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知

Security

Scope Systems confirms cyber incident, says no data loss occurred Instructure breach: ShinyHunters says ‘matter has been resolved’ Rapid7 launches Cyber GRC program to connect compliance with live risk data Australian federal budget 2026: The industry perspective Op-Ed: Microsoft May Patch Tuesday reveals 137 vulnerabilities Federal Budget 2026: The state of cyber security spending for the coming year OpenAI offers EU early access to its cyber security model Exclusive: Aussie firm Earth Systems listed by INC Ransom hacking group Op-Ed: Why Middle East tensions demand immediate action on OT security Aussie schools breach: Instructure boss “reaches agreement” with ShinyHunters to not release data Institute of Public Accountants members hit by data breach Union demands answers on Qantas AI plans 1 in 3 small businesses don't think they're a cyber target, new research finds Exclusive: Aussie toy distributor listed by M3rx ransomware Exclusive: Australian Computer Society investigating possible breach after ShinyHunters hack claims The industry speaks – part 2: World Password Day 2026 Aussie schools breach: The Instructure hack “transcends an isolated IT incident” Exclusive: Aussie car part importer Strategic Imports allegedly breached by threat actors New South Wales, other states, investigating Instructure/Canvas data breach Australian Cyber Security Centre warns of ClickFix campaign leveraging Australian infrastructure Queensland Department of Education confirms students & staff impacted by ShinyHunters data breach ACMA takes action against SpinTel & Yomojo over mobile number fraud violations The Industry Speaks, Part 1: World Password Day 2026 Qualys and Converge tie cyber insurance pricing to real-time security posture Fakeout: Iranian APT caught hiding behind Chaos ransomware activity Exclusive: Australian energy management firm allegedly breached by SafePay Real estate giant Cushman & Wakefield confirms cyber incident, Qilin and ShinyHunters claim attack CrowdStrike expands Project QuiltWorks as more partners join AI security coalition Hacked: ALS discloses cyber incident, unauthorised access to IT systems Microsoft the main target of AI phishing attacks, report uncovers
Op-Ed: The transaction was legitimate; the crime was hidd...
Keith Bulfin · 2026-06-03 · via Security

One of the biggest misconceptions in financial crime is the belief that sophisticated criminal activity is hidden because transactions themselves appear suspicious.

In reality, the opposite is often true.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

The most sophisticated criminal systems frequently operate through transactions that appear entirely legitimate. A payment is made; an invoice is issued; funds move through recognised financial institutions; goods are shipped; customs documentation is completed; containers arrive at their destination.

Every individual component may appear legitimate when viewed in isolation. The problem is that organised crime does not operate in isolation.

It operates as a system. This is where what I describe as the “Operational Interpretation Gap” begins to emerge.

Across the world, financial institutions invest billions of dollars into:

• transaction monitoring
• AML systems
• AI-driven detection
• sanctions screening
• compliance programs
• governance frameworks.

Yet global illicit financial flows continue to exceed US$4.5 trillion annually. Why?

Because institutions often analyse transactions individually, while criminal organisations operate behaviourally across multiple jurisdictions simultaneously.

A payment may be sent to a company in Europe for goods that appear legitimate. A shipment may move through several countries. Funds may pass through multiple financial centres. Ownership structures may span several jurisdictions.

No single transaction triggers concern.

No individual participant sees the complete picture.

The criminal activity is not hidden inside one transaction. The criminal activity is hidden within the architecture connecting all of them – this distinction is critically important.

Compliance systems are generally designed to identify anomalies, and operational intelligence seeks to understand intent.

Compliance asks: “Does this transaction trigger a rule?”

Operational intelligence asks: “What larger system is this transaction part of?”

That question is becoming increasingly important as organised crime groups continue evolving into highly sophisticated multinational enterprises.

Many now employ:

• cyber specialists
• financial professionals
• logistics experts
• technology teams
• recruiters
• facilitators operating across multiple countries.

They understand jurisdictions. They understand regulatory differences. They understand how institutions share information. Most importantly, they understand that modern systems often analyse activity in fragments.

Their advantage comes from understanding the whole picture.

The future challenge for financial institutions, cyber professionals, regulators, intelligence agencies, and governance leaders is not simply collecting more data. It is in developing the capability to interpret behavioural systems operating behind that data.

Because ultimately, the transaction itself is rarely the story. The behavioural architecture behind the transaction is the story.

And until institutions become better at understanding that architecture, organised criminal systems will continue adapting faster than the systems designed to stop them.


Keith Bulfin is the founder of the Applied Financial Intelligence Programme and author of the bestselling book “Undercover”. His background includes work across global financial intelligence, organised crime investigations, illicit finance systems, and operational intelligence environments involving international agencies and investigations.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.