Digital Money Laundering: How Fintech, Crypto, and Cloud Services Changed Financial Crime

Money laundering

Remember when laundering money meant a guy in a Members Only jacket walking into a casino with a duffel bag, and walking out with “winnings”? Adorable. Quaint. Practically artisanal. These days the duffel bag is a wallet address, the casino is a decentralized exchange, and the guy in the jacket has been replaced by a script that can spin up forty shell accounts before your coffee finishes brewing. Ocean’s Eleven took a heist crew and months of planning to move money. Modern digital money laundering operations do it with an API key and a lunch break. (And maybe a Members Only jacket.)

We’ve written before about how fintech has scrambled the traditional three-stage laundering model of placement, layering, and integration. Crypto lets financial criminals skip placement almost entirely, since the money is already digital and already a little bit anonymous when it shows up. But the part that should really get MSPs’ attention isn’t the crime itself. It’s what’s underneath it: Cloud compute, hosting, domains, and the identity tools that let a fintech app go from idea to “accepting payments” in a weekend. That’s your stack. That’s the stuff you sell, secure, and support.

The numbers stopped being a rounding error

According to Chainalysis’s 2026 Crypto Crime Report, illicit cryptocurrency addresses pulled in a record haul in 2025, and the firm is calling it a conservative floor. Crypto-native laundering specifically has grown roughly eightfold since 2020, and a large chunk of that growth is now attributed to what analysts call Chinese-language money laundering networks, which operate less like a rogue trader and more like a full-service agency. Think of it as laundering-as-a-service, complete with account managers and, presumably, a Slack channel. These groups use Telegram marketplaces, money mules, and OTC brokers to move funds at industrial scale, and none of that infrastructure appears out of thin air. It runs on servers somebody rents, domains somebody registers, and onboarding flows somebody built to be frictionless, because friction was the enemy right up until it became the point.

Breaking Bad had a car wash. Fintech has a landing page

Walter White needed a car wash to make his money look clean. Today’s operators need something much less conspicuous: a fintech front end, a payment API, and enough automated onboarding that nobody has to actually look a human in the eye. That’s the uncomfortable part of this story for anyone in managed services. When regulators go looking for how a shell company spun up a working payment app in a weekend, or how a network of mule accounts got onboarded in minutes, the trail increasingly runs through the providers who never touched a single transaction: the MSP who set up the infrastructure, the reseller who provisioned the instance, the platform that let “instant onboarding” mean “unverified onboarding”.

The FCA’s £28.9 million fine against Starling Bank is the case everyone in fintech compliance now quotes, and for good reason. It wasn’t about a bank helping criminals on purpose. It was about controls that couldn’t keep pace with growth. Swap “bank” for “MSP-managed fintech client” and the lesson lands just as hard on this side of the industry.

Why MSPs are suddenly part of the plot, not just the crew

MSPs love to think of themselves as the neutral IT crew: keep the lights on, patch the servers, answer the crack-of-dawn call—but regulators are no longer interested in that distinction. If your client is a payments startup, a challenger bank, or a crypto-adjacent app, the speed and automation you’re proud of delivering is exactly the feature criminals are exploiting. Fast provisioning, minimal-friction onboarding, and “we don’t ask too many questions” client relationships were selling points a few years ago. Now they’re liability exposure with a compliance officer’s phone number attached.

This isn’t a call for every MSP to become an amateur anti-money laundering analyst. It’s a nudge to treat client due diligence, abuse monitoring, and know-your-customer checks as part of the actual service, not a box ticked once during onboarding and never opened again; similar to how our ransomware crisis management guidance for MSPs argues you need an incident response plan before the incident, not during it. The MSPs who get ahead of this will be the ones who can answer a regulator’s questions about a client’s onboarding flow without having to call the client first to find out what it even does.

The takeaway, minus the Ocean’s Eleven soundtrack

Nobody’s suggesting your average MSP is secretly running a laundering ring out of a spare rack in Secaucus, New Jersey. However, the ecosystem around fintech, crypto, and digital banking has gotten fast, automated, and cross-border in ways that outpace the old three-stage model regulators built their playbook around. Infrastructure providers who assumed they were just “the pipes” are finding out that pipes get inspected too. Better to put the verification and monitoring in place now than to explain to a regulator later why your client’s onboarding flow was quicker than a Vegas valet.

Oh, and here’s the Ocean’s Eleven soundtrack anyway, because it’s really good…

Eugenio Cirmi Avatar

This might also interest you