Article digitalization: The digital laundering playbook: what Belgium's 2025 AML report reveals about the future of financial crime
The CFI's 2025 annual report does not mince words. The digitalisation of the financial sector has brought undeniable benefits for consumers and businesses. It has also handed criminal organisations a significantly more powerful set of tools.
The picture that emerges from the CFI's analysis is not one of technology displacing traditional laundering methods. It is one of integration: digital speed and reach layered onto proven techniques, making the resulting constructions faster to execute and considerably harder to unravel.
The infrastructure has shifted, and criminals moved first
The past decade has fundamentally transformed the Belgian financial ecosystem. Instant payments, open banking, e-money institutions, crypto-asset service providers, decentralised finance platforms: each of these innovations has expanded access, reduced friction, and created genuine value for consumers and businesses.
It has also expanded the attack surface for financial crime.
The CFI documents a consistent pattern in 2025: criminal networks exploit the speed of account opening at online payment institutions, the velocity of cross-border transactions, and the ease of converting between fiat money and virtual assets. Where a cash-intensive operation once required physical infrastructure and trusted couriers, a payment institution account opened online in minutes now provides the same functionality, with global reach and near-instant settlement.
Crypto: not anonymous, but deliberately obscured
Crypto-asset related dossiers represent a growing proportion of the CFI's workload, and the 2025 report provides a detailed picture of how virtual assets are being misused.
The techniques are layered. Offshore crypto exchanges operating outside regulated jurisdictions pool client assets in shared wallets, making it impossible to trace individual fund origins from public blockchain analysis alone. Crypto mixers deliberately blend funds from multiple users, severing the on-chain link between sender and recipient. Decentralised Finance platforms, governed by smart contracts rather than regulated entities, enable trading, lending, and derivatives without any central compliance function.
Beyond these structural tools, the CFI documents the use of DeFi platforms for NFT auctions and leveraged positions by Belgian nationals, sometimes generating taxable income that goes undeclared, resulting in referrals to prosecutors for serious tax fraud.
One case stands out for its sophistication: a Belgian individual generated tokens, listed them on a decentralised exchange, artificially inflated their price by purchasing them through a separate wallet, then disabled trading and absconded with investor funds. The victims were left holding worthless tokens. The entire scheme ran on infrastructure that, by design, has no compliance layer.
The CFI is equally clear on the limitations of these techniques as a guarantee of impunity. In multiple dossiers, Belgian individuals were identified by tracing funds through mixers, exchanges, and DeFi platforms. Technology creates complexity. It does not create invisibility.
AI, deepfakes, and the industrialisation of fraud
The CFI's 2025 report explicitly flags the use of artificial intelligence in investment fraud. Deepfakes of well-known public figures are deployed to lure victims to fraudulent investment platforms. AI tools are used to identify and target potential victims at scale. Phishing kits, ready-to-deploy software packages for executing phishing attacks, are available online, removing the technical barrier to entry for fraud entirely.
This has a direct implication for financial institutions: the fraud that generates the proceeds being laundered is itself becoming more scalable, more convincing, and more widely accessible. The volume of fraud-related suspicious transaction reports is not a temporary spike. It reflects a structural shift in the economics of financial crime.
Payment institutions: the new front line
The sheer volume of payment institution data in the CFI's 2025 report, nearly 52,000 reports from this sector alone, reflects both the growth of the sector and its elevated exposure to financial crime risk.
The CFI is careful to contextualise this: more than 90% of these reports are externalised to other EU FIUs under cross-border reporting procedures, as they relate to clients in other member states served from Belgium under the European passport. But the underlying dynamic is significant. Payment institutions, by design, offer fast onboarding, low friction, and broad geographic reach. These are features, but they are also vulnerabilities.
The combination of virtual IBANs, instant cross-border transfers, and easy integration with crypto platforms creates an infrastructure that criminal networks are actively exploiting. The CFI documents funds being routed from fraud victims through foreign payment institutions, across to crypto platforms, and into offshore exchanges, a chain that becomes progressively harder to follow at each step.
Underground banking goes digital
Traditional hawala, trust-based value transfer between brokers without funds physically moving, has not disappeared. It has evolved. The CFI documents the emergence of digital hawala structures, where mobile transfer capabilities are layered onto classical broker networks, increasing scale, speed, and geographic reach while preserving the core feature that makes IVTS attractive to criminals: the absence of a traceable financial record.
In one category of dossiers, Belgian-resident individuals with accounts at multiple banks showed patterns entirely inconsistent with any declared professional activity, funded by transfers, debited to foreign accounts, punctuated by cash deposits, and subsequently linked to active hawala networks through intelligence service information.
The counter-strategy: data-driven by design
The CFI draws an important parallel. The same combination of old and new techniques that characterises criminal behaviour in 2025 is also the blueprint for the counter-strategy. Data-driven detection models, pattern recognition across large transaction volumes, and intelligence sharing between FIUs are the tools that allow financial intelligence to keep pace with the threat.
For financial institutions, this has practical implications. Rule-based monitoring systems designed for a slower, less connected financial ecosystem are increasingly insufficient against adversaries who operate across multiple platforms, jurisdictions, and asset classes simultaneously. The investment case for more sophisticated detection infrastructure, and for the human expertise to interpret its outputs, has never been stronger.
What this means for your institution
The CFI's 2025 report makes clear that digitalisation is not a future risk to be monitored. It is a present reality to be managed. The institutions best positioned to respond are those that have already moved beyond compliance as a documentation exercise and toward compliance as a genuine risk intelligence function.