Targeting Russia's Financial Sector and War Machine
The EU has passed its 21st Russia sanctions package; what's in it?
The EU this week, after much haggling and debating, passed its 21st Russia sanctions package. To be sure, there were concessions made, particularly to Greece, which demanded that its shipping sector be protected from financial loss, and also to France, Poland, Germany, Portugal, and Italy who demanded protections for tourism and fish.
However, despite being watered down, this sanctions package has some significant designations targeting Russia’s war machine and the financial sector that supports it. The results of these sanctions should put compliance teams on their toes.
The bloc imposed asset freezes and a prohibition on making funds available to 94 banks and major financial institutions and extended the transaction ban to 33 additional Russian credit and financial institutions.
Sergey (alternately Sergei or Sergej) Belov, Deputy Governor of the Central Bank of Russia, was sanctioned for overseeing field institutions near frontline areas and facilitating forced ruble conversion in occupied territories. This designation indicates that the EU is now applying sanctions deep into the Russian central bank’s operational structure, rather than just sanctioning commercial banks.
The scope of these sanctions has been expanded to non-Russian banks. The package introduces a transaction ban against a Kyrgyz bank connected to Russia’s SWIFT alternative SPFS and several others for facilitating sanctions evasion. Firms, financial institutions and banks, should not assume that just because a counterparty is “not Russian,” it’s safe.
On that note, jurisdictions that were widely known to be sanctions-evasion hotspots have been specifically named in this EU sanctions package, including Georgia, Panama, the UAE, the Marshall Islands, Kyrgyzstan, and Belarus that host sanctioned crypto platforms to help Russia evade sanctions.
Separately, China (including Hong Kong), India, Kazakhstan, Kyrgyzstan, Türkiye, and the UAE have been flagged by our allies as sources of entities that help Moscow circumvent trade restrictions on dual-use goods.
Watching the future unfold

Many in my field are cautious of the crypto sector, and some outright oppose any transactions with digital assets.
I understand the skeptics, and I recognize the risks. However, the future is here, and I don’t see any way to avoid it. So the best advice I can give is to minimize the risks. But that’s not easy to do.
The EU has now implemented a standing mechanism for future crypto jurisdiction bans. This is not just a political statement. The new package creates a framework to threaten transaction bans against crypto-asset providers and platforms in specified third countries that help Russia evade sanctions; as I mentioned, the bloc specifically flags Georgia, Panama, and others for hosting sanctioned crypto platforms. But now, a mechanism exists and can be activated without a full new legislative package.
That means that a jurisdiction can go from "not listed" to "banned" without legislative haggling, so those transacting in risky jurisdictions must look at the future and what it can bring.
The A7 designations
The EU originally sanctioned the Russian payment firm A7 LLC on July 15, 2025. The new package adds new designations related to the cross-border A7 network, including its new links to Africa.
The UK designated A7 in May, targeting infrastructure used to transfer funds, procure goods, and support Russia's war machine. At the time, the UK designations included:
EXMO Exchange Limited
Rapira Group LLC
Aifory LLC
Bitpapa IC FZC LLC
Open Joint Stock Company “Eurasian Savings Bank”
Huobi Global S.A.
Igor Gorin
Irina Akopyan
Sergey Mendeleev
Liran Cohen
Mendeleev and BitPapa are already sanctioned by OFAC.
Sergey (alternate spellings: Sergej, Sergei, Serge, etc.) Mendeleev (alternate spellings: Mendeleyev, Mendeleiev, etc.) cofounded sanctioned crypto exchange Garantex, according to OFAC, and was designated in August 2025.
BitPapa operates a peer-to-peer virtual currency exchange and offers services to Russian nationals, as well as US-designated Russian entities Hydra Market and Garantex. It was designated pursuant to EO14024 for operating in Russia’s financial services sector.
The EU’s new designations include:
Leonid Shumakov, Mikhail (alternate spellings: Mihail, Michail, Mikhael, etc.) Dorofeev (alternate spellings: Dorofeyev, Dorofeiev, Dorofejev, etc.), A7 Agent Limited Liability Company, Limited Liability Company A71, and others. Needless to say, any entity containing the term “A7,” especially if it operates in one of the risky jurisdictions I mentioned, or in Russia itself, should be examined closely.
In addition, you absolutely want to check out the Annex and ensure you’re not transacting with the following entities after August 13,2026.
Crypto Daily is a marvelous resource for understanding risky entities and developments in the crypto sector, so you may want to bookmark their site. According to their latest take on the EU sanctions targeting Russia-linked crypto, you absolutely want to ensure you’re prepared for the EU’s August 13 deadline. They’ve even provided a useful checklist:
Freeze onboarding and cut API keys for the listed services before the entry dates. Log the change and notify impacted users.
Push an emergency update to your sanctions screening layer so both the brand and corporate names trigger blocks.
Map dependencies. Look through wallet providers, liquidity aggregators, PSPs, and OTC partners to identify second-order exposure.
Re-paper contracts. Add a sanctions representation and a right to terminate on designation to vendor and liquidity agreements.
Train customer support. Provide a public statement and a playbook for handling withdrawals that would route to a prohibited venue.
Engage your bank early. Explain your cutover plan so fiat rails are not flagged or de-risked while you comply.
To add a more general strategy, when I received my certification in virtual asset service provider (VASP) risk, I created a checklist that firms, banks, and financial institutions can use to inform their risk appetite when dealing with VASPs.
Check VASP location: is the location in a high risk jurisdiction either for sanctions, embargo, or money laundering?
Check VASP anctions status: On SDN list? On OFSI or EU blocked list? has it changed its name recently as a sanctions evasion technique?
Check the ownership/control structure of the VASP: are any sanctioned entities involved in the company directly or indirectly?
Check KYC controls: What kind of KYC controls are in place at the exchange? If there’s little to no KYC for small amounts, structuring could become easier.
Check the customer identification program (CIP): What kind of documentation does the VASP require for identity verification?
Check the VASP’s KYC history: How have KYC and CDD processes evolved over time?
Check for high-risk transactions: What are they? What percentage of transactions are high-risk? What kind of cryptocurrencies does it transact in?
Check adverse media: Is the VASP involved in any risky activity or legal proceedings that’s been reported in the media?
Leadership: Are the VASP’s leaders real people? Do they have a robust online presence that’s linked to the VASP? Are they considered PEPs?
Check privacy/anonymity policies: What level of privacy/anonymity does the VASP offer its customers? Privacy coins? Direct/indirect onramps and offramps?
Check banking connections: What financial institutions and banks are transacting or have accounts for the VASP? Transactions with major banks could indicate the VASP is likely safe, or it could indicate that illicit actors are using the bank’s size to hide their activity.
Check the transactions: What kind of sources is the VASP receiving crypto from and where is it sending crypto? Are there any criminally linked transactions? Any company can miss a suspicious transaction here and there, but if massive transfers aren’t flagged and the VASP is regularly moving large amounts of money, that’s a red flag.
Check regulatory compliance: If transactions involve criminal activity such as ransomware or dark web activity, have SARs been filed with FinCEN? How many SARs have been submitted?
Examine the VASP’s compliance team: How big is the team? What are the team’s qualifications?
I’m not saying this is the be-all and end-all strategy, but it can help.
What about MOEX?

OK, last thing, and I’ll stop geeking out. There’s a lot in this new sanctions package, and I’m trying to only focus on the important points.
The EU’s 21st package designates PJSC Moscow Exchange MICEX-RTS (MOEX). This is hardly a symbolic gesture against a national stock exchange. The bloc has identified MOEX as the central platform for domestic financing and trading in Russia, including investment into Russian military corporations and government bonds issued by the Finance Ministry.
Two MOEX subsidiaries—the National Settlement Depository (NSD) and the National Clearing Centre (NCC)—are identified as systemically important financial market infrastructure institutions under the Central Bank of Russia’s own designation, with the NSD noted as already separately listed by the EU.
A firm screening for “Moscow Exchange” may not be enough, because exposure could exist through NSD-related custody or settlement chains, or through NCC-cleared transactions, and the subsidiaries may or may not show up under the parent company’s name in a standard screen.
As I’ve mentioned before, simple list screening is no longer sufficient. Enhanced due diligence must exceed research into the designated entity itself and include its operationally critical subsidiaries, which may include shadow SDNs (entities sanctioned by operation of law, but which may not explicitly appear on the sanctions list). Firms with any historical or residual exposure to Russian securities or custody arrangements touching NSD or NCC should treat the MOEX designation as a trigger to repeat look-back screening specifically at the subsidiary level, not just the parent entity name.
Final Notes
Yeah, I know this is long, but as someone who is steeped in this stuff, I’d call this useful.
You may have noticed that I provided name variations above. Names transliterated from Cyrillic (and other alphabets as well) can be written in numerous ways, and illicit actors can use name variations as strategies to evade detection.
For example: Stanislav Alekseyevich POZDNYAKOV, the former President of the Olympic Committee of the Russian Federation (2018-2024); member of the Board of Russian Central Sports Club of the Army (CSKA); and a Lieutenant Colonel in the Russian armed forces was designated by the EU this week.
Cyrillic spelling: Станислав Алексеевич ПОЗДНЯКОВ
Latin name variations: Stanislav Alexeyevich (Alekseievich, Alexeievich, Aleksejevich, Alexejevich) Pozdniakov (Pozdnjakov, Pozdnyakov).
Hint: simple list screening is not enough. Engage with a linguistic experts to supplement your automated tools.
Hint: also look for similar last names of possible family members and reports about close associates. OSINT research can help a lot here, and I would encourage you to use your tools.







