In June 2025, US regulators took an unprecedented step, flagging three well-established Mexican financial institutions as money laundering risks, exposing their alleged ties to cartels already designated as foreign terrorist organizations. Within months, all three had collapsed.
Listen to this article
Key insights:
- Having the law is not the same as having results — Many experts have stated that Mexico has a solid legal foundation for the prevention of money laundering, but the operational effectiveness is where the gap and its obstacles show up.
- A legal origin does not guarantee a legal destination — The transactions could look, individually, like ordinary business operations. The risk was not in where the money came from, but in where it was going and who actually controlled it.
- The amount is not the decisive indicator, signal synchronization is — Detecting risk does not depend on setting higher or lower thresholds, but on connecting patterns that look harmless in isolation.
On June 25, 2025, the U.S. Treasury Department's Financial Crimes Enforcement Network (FinCEN) publicly identified three Mexican financial institutions — CIBanco, Intercam Banco, and Vector Casa de Bolsa — as institutions of "primary money laundering concern," under the newly enacted FEND Off Fentanyl Act, an American law created to prevent money laundering in order to address the illicit funding behind the fentanyl crisis.
According to the designation, CIBanco and Intercam had allegedly provided financial services to three of the eight Mexican criminal organizations later designated as Foreign Terrorist Organizations (FTOs), facilitating payments for fentanyl precursor chemicals sourced from China. Vector, for its part, was accused of enabling the laundering of more than $2 million dollars in proceeds for two FTOs, in addition to facilitating payments linked to the same chemical procurement.
The consequences were not long in coming. After several extensions, the sanctions took effect on October 20, 2025. US banks were barred from processing transfers involving the three Mexican entities. Mexico's National Banking and Securities Commission (CNBV) took over management of the three banks, revoked CIBanco's license and began its liquidation. Meanwhile, Intercam and Vector were left severely weakened after both sold most of their operations to other financial firms.
Without compare, it was one of the most significant red alerts the Mexican financial system has faced in recent years.
One uncomfortable detail is worth dwelling on, however. It was not a Mexican authority that first detected the pattern and acted — it was the U.S. Treasury. And that is precisely the point at which this case stops being just another financial headline and becomes a concrete lesson about the role that financial institutions all over the world actually play in preventing money laundering and detecting terrorism financing.
Making “a rule on paper” actually work
Before discussing what failed, it is worth giving credit to what does exist. Mexico has a solid legal foundation for preventing money laundering and terrorist financing, specifically, the Federal Law for the Prevention and Identification of Operations with Resources of Illicit Origin (LFPIORPI) for vulnerable activities, and a specific regime for financial institutions under the Credit Institutions Law, the Securities Market Law, and the provisions of the CNBV. Both frameworks require that financial institutions identify their customers, know beneficial owners, monitor transactions, and report any unusual activity to the Mexican Financial Intelligence Unit (UIF).
Without compare, it was one of the most significant red alerts the Mexican financial system has faced in recent years.
The CIBanco-Intercam-Vector case does not, then, reveal a legal vacuum. Instead, it reveals something more specific and harder to solve: The gap between having the rule on paper and making it operate with real effectiveness.
A financial institution can comply formally — with its manuals, its policies, and its monthly reports — and still sustain, for years, relationships with actors the government already flagged as threats. That is exactly the blind spot this preventive regime is meant to close.
Learning from the mistakes of others
Viewing this case through the lens of the obligations the law imposes on financial institutions makes it possible to see clearly which concrete actions actually separate paper compliance from real compliance. Indeed, risk management professionals and compliance experts within Mexican financial institutions would do well to follow these steps:
- Identify the true beneficial owner of an account, not just the apparent client — The preventive regime does not require knowing only who signs a contract or opens an account, but who actually controls the funds moving through it. In transactions that are linked to the purchase of chemical precursors, for example, the relevant question was not simply "Who is the company paying?" but "Who is behind that company, and what relationship does that entity have with organizations already identified as high-risk?"
- Monitor behavioral patterns, not just dollar amounts — A $2 million dollar transfer may look, in isolation, like just another commercial operation. However, effective monitoring does not stop at the threshold that triggers an automatic report; rather, it observes whether the operation repeats, whether it coincides with other accounts, whether it relates to actors or routes already flagged, and whether its frequency or destination deviates from the client's declared profile.
The Financial Action Task Force (FATF) — a branch that operates inside the Organisation for Economic Co-operation and Development (OECD) to create the global standards to combat money laundering, terrorism financing, and other illicit financing — itself has repeatedly noted that the decisive indicator is almost never the amount of the transaction, but the synchronization of signals that, seen individually, appear harmless.
- Generate reports with intelligence value, not just paperwork — A notice that merely describes a relevant transaction, without context or analysis, is of little use to the UIF. The preventive regime works better when the reporting institution contributes information that helps reconstruct a relationship, such as identifying and listing counterparties, routes, beneficiaries, and coincidences with other accounts or devices.
- Sustain a compliance culture from senior leadership down — None of the above works, however, if the commitment to prevention stays confined to the institution’s compliance department and fails to permeate its commercial decisions. When a business relationship proves profitable, the temptation to look the other way is precisely the risk that Mexico’s preventive regime is designed to neutralize.
The lesson the case leaves behind
The most revealing thing about this episode may not be those three financial institutions operated for a time with ties to criminal economies — that, unfortunately, is nothing new. What is revealing is that the alert came from outside the country, and that it took a foreign law, the United States’ FEND Off Fentanyl Act, to trigger a response that Mexico's own system should have discovered first.
That is the core of the problem that has been repeatedly pointed out: The issue is not the absence of rules, but the absence of an architecture that connects financial intelligence with foreign trade, intelligence agencies, and international cooperation before a threat materializes. An isolated rule acknowledges an obligation; yet, an integrated legal architecture disrupts the operation.
In 2026, the UIF and the CNBV formalized a new coordination scheme to improve information sharing and joint analysis of suspicious transactions, largely in response to what had occurred. While that is definitely a step in the right direction, it also confirms that the correction came after the scandal, not before it.
The advantage of a prevention system never lies in detecting the last transfer once the damage is already done. It lies in recognizing early signals, connecting fragments of information that appear harmless in isolation, and acting before an institution — through action or omission — ends up becoming part of the threat it was supposed to prevent.

