Treasury's September 9 action against Xinbi Guarantee names a marketplace, a messaging app, and a wallet app in the same designation. Here is why that matters for a compliance program built around name screening, and four steps to take before an examiner asks.
OFAC designated Xinbi Guarantee as a transnational criminal organization under Executive Order 13581. It also designated two companies that built Xinbi's tools: SafeW Technology in Singapore, which makes the encrypted messaging app Xinbi moved its buyers and sellers onto around June 2025, and Anwen Technology in Cambodia, which built the XinbiPay wallet. According to Treasury, Xinbi has handled the equivalent of more than $24 billion in digital assets and cash since it started around 2022. It provided escrow and coordination services to scam center operators, money laundering networks, and entities already on the SDN list, including parts of the Prince Group. The Justice Department's Scam Center Strike Force seized Xinbi's infrastructure and wallets the same day. Treasury also says that after FinCEN cut off Huione in October 2025, Huione's customers simply moved to Xinbi and kept doing the same business.
Why the Pattern Matters More Than the Name
For a chief compliance officer at a US bank, payments company, or exchange, the important fact is the pattern, not the name. Huione was shut out in October 2025. The business moved to Xinbi. When Xinbi drew attention, it moved its coordination to SafeW and its payments to its own wallet. Each move put the activity one step further from anything a name-matching screen would catch, while the people and the money stayed mostly the same. OFAC's answer was to sanction the tools. In effect, the regulator has told you where it expects your screening to reach: past the named entity, into the apps and payment rails that carry the activity.
The Legal Obligations Are Familiar and Strict
The obligations that follow are familiar and strict. Any property of the designated parties in US hands must be blocked and reported. The 50 percent rule extends that to any company they majority-own, whether or not it is on a list. Civil penalties apply even when the violation was unintentional, and foreign parties face exposure for causing a US institution to violate. That language is aimed at exactly the institution whose screening looked clean on paper while its customers were still receiving funds that passed through a XinbiPay wallet.
The practical question is whether your program can see a counterparty as a connected set of accounts, apps, and wallets rather than as a name to match. That takes entity resolution across onboarding records, transaction data, and blockchain analytics, and it takes a data layer current enough to reflect a designation made this morning. Institutions running sanctions and AML analytics on a governed platform such as Cloudera, with lineage back to the source of each match, are positioned to answer an examiner's question about when they knew and what they did. Institutions still reconciling list updates against static customer files will answer it after the fact.
Four Steps to Take This Month
Confirm today's designations, including SafeW Technology and Anwen Technology, are live in every screening feed you rely on, not just the primary list vendor, and assign an owner to the lag between OFAC publication and your screen.
Run a lookback for exposure to XinbiPay and NewPay wallet addresses and to SafeW-linked merchant activity using whatever blockchain analytics coverage you have. If you have none, that gap is itself a finding.
Apply the 50 percent rule proactively. Ask your entity resolution team to identify affiliates of the three designated companies before OFAC lists them.
Document all of it. The examiner's question after an action like this is when you knew and what you did, and the institutions that answer it well are the ones whose data lineage already holds the answer.
This is the fourth action against this network in eleven months, and Treasury has said it plans to keep going after illicit marketplaces.
