FATF Terrorist Financing on Social Media: What AML Teams Should Check
On 26 June 2026 the Financial Action Task Force published a report on terrorist financing through social media, instant messaging applications and streaming platforms, and it lands with an uncomfortable number attached. Fewer than 30% of jurisdictions contributing to the FATF report said that this risk was covered in their national risk assessments. That national-level gap is relevant to firms, but the report does not quantify how many obliged entities have incorporated the risk into transaction-monitoring rules or suspicious-transaction-report processes.
The report itself is a typologies and trends paper. It describes how these platforms, which the FATF groups under the label SMSPs, are being abused to raise and move terrorist funds, and it recommends how countries and the private sector should respond. It adds no new line to any return and creates no new reporting obligation, and its practical value for AML teams sits in that description. It is a fresh, structured list of behaviours to look for, and a prompt to check whether your monitoring, your indicators and your risk assessment have kept pace with where the money actually flows.
This is a global standard-setter speaking to a global problem, so the framing below stays at the FATF Standards level and uses the EU implementation only as a worked example. The instruments and control expectations differ by jurisdiction, and the relevance and prevalence of individual typologies also vary according to the local threat, products, customers and channels.
Related reading: FATF report on public-private partnerships for illicit finance
What the FATF said about terrorist financing on social media
The publication is titled Detecting and disrupting terrorist financing activity through social media, instant messaging applications and streaming platforms. It builds on the FATF’s Comprehensive Update on Terrorist Financing Risks from 8 July 2025, which found that 69% of jurisdictions assessed by the FATF and its Global Network had major or structural deficiencies in investigating, prosecuting and convicting terrorist financing. The 2026 report narrows that broad warning to one part of the problem: the platforms where a growing share of fundraising, coordination and value transfer now happens.
The FATF is direct about the reason these platforms matter. Over the past decade they have moved from communication tools into integrated systems that carry payments, virtual assets, creator monetisation and cross-border financial services inside the same interface a user opens to send a message or watch a stream. The report says the FATF worked with major technology companies and specialised think tanks to map the vulnerabilities, and that further analysis, including detailed case studies, sits on the FATF’s secure platform for public authorities only. Private-sector teams work from the public typologies, so those typologies carry more weight than usual.
One line in the report needs careful reading before anyone builds a control around it. As SMSPs integrate or enable access to financial services, certain activities conducted through or facilitated by them may fall within the scope of sectors already regulated under the FATF Standards. SMSPs are not an obliged-entity category merely because they are social media, messaging or streaming platforms. However, the FATF says an SMSP may itself fall within the definition of a financial institution or virtual asset service provider where it directly offers, controls or materially influences the custody, transfer, exchange or facilitation of funds or virtual assets. Where it provides only an interface for a regulated third party, the primary obligations may attach to that third party, subject to national law and the SMSP’s degree of control, influence or benefit.
The dates worth writing on the wall
This is a non-binding FATF methods-and-trends publication and carries no filing date to diarise. The dates that matter are the applicability points of the frameworks that turn these typologies into live obligations for regulated firms, plus the two FATF publications that frame the risk.
- 8 July 2025: FATF Comprehensive Update on Terrorist Financing Risks, the parent report.
- 26 June 2026: FATF report on terrorist financing through social media, instant messaging applications and streaming platforms.
- 30 December 2024: the EU Transfer of Funds Regulation, Regulation (EU) 2023/1113, became applicable, extending the travel rule to crypto-asset transfers.
- 10 July 2027: Regulation (EU) 2024/1624 generally applies and lists crowdfunding service providers and crowdfunding intermediaries as obliged entities. MiCA crypto-asset service providers were already brought into the EU obliged-entity perimeter by amendments to Directive (EU) 2015/849 made by Regulation (EU) 2023/1113, applicable from 30 December 2024.
The typologies the report puts on the table
The report names a cluster of methods, and each one maps to something a monitoring team can actually look for. Read them as behaviours to detect.
Propaganda and open fundraising remain, but the report moves past them to the mechanics that generate and move value. Fraudulent humanitarian and charitable crowdfunding campaigns raise money under a legitimate-looking cause. Creator-economy features such as live-streaming and tipping let supporters send small, frequent payments that read as fan support. Virtual asset fundraising uses rotating wallets and QR codes so that no single address stays visible long enough to screen cleanly. Coded language and ephemeral content, meaning posts and messages that disappear, are used to arrange payments while defeating after-the-fact review. Commercial entities are placed in the chain to give the flow a business rationale and obscure its purpose.
Around those methods the report lists the enabling technologies: AI-driven content, encrypted communications, decentralised finance, virtual assets and embedded payment tools. None of these is inherently suspicious, and that is the trap. Each is a mass-market consumer feature. The signal is never the tool on its own; it is the tool combined with a fundraising narrative, a mismatched beneficiary and a payment pattern that does not fit the stated purpose.
Why the platform being unregulated is the wrong place to stop
The most common misread of a report like this is defensive: the platform is not an obliged entity, so the risk sits with someone else. The FATF closes that door. Its key measures include clarifying regulatory scope because the applicable obligations depend on the financial functions performed by the SMSP or third-party provider and on the relevant national framework.
SMSP-linked fundraising may reach banks, payment or e-money providers and virtual asset service providers, but the FATF report also identifies cash collection, prepaid cards, mobile money, vouchers and informal transfer systems. Whether an entity is obliged depends on the functions it performs and the applicable national framework. Recommendation 15 requires countries to regulate virtual asset service providers for AML/CFT purposes. In the EU, Regulation (EU) 2023/1113 amended Directive (EU) 2015/849 so that MiCA crypto-asset service providers became obliged entities from 30 December 2024; Regulation (EU) 2024/1624 continues that treatment from 10 July 2027.
This is where the EU example is useful. The EU Anti-Money Laundering Regulation explicitly extends the obliged-entity list to crowdfunding service providers and crypto-asset service providers, alongside the traditional financial sector. A firm that dismissed crowdfunding-linked flows as out of scope under the old regime should re-check that assumption against the instrument that applies from 10 July 2027.
What to add to transaction monitoring and indicators
Building targeted indicators is one of the report’s explicit recommendations, and it is the measure most directly in a monitoring team’s hands. The typologies translate into detection logic that most legacy rule sets do not carry.
The FATF does not prescribe firm-level scenarios or thresholds. As a risk-based implementation exercise, firms may test whether their controls can identify patterns consistent with the report’s typologies, such as unexplained clusters of micro-donations, campaign or social-handle references, rapid conversion of collected virtual assets, or charity-related payments where the beneficiary does not match the stated organisation. For rotating-address fundraising, the relevant signal is successive recipient or QR-linked addresses associated with the same campaign or customer where wallet-clustering or case intelligence supports the link; many first-seen sender addresses alone do not establish that typology.
None of these is a standalone red flag, and a team that alerts on every micro-donation will drown. The report’s own framing helps here: it stresses linking financial intelligence with digital intelligence. A single small transfer means little. The same transfer, tied to a handle that also appears in adverse media, a wallet flagged by a chain-analytics provider and a beneficiary whose stated purpose does not fit, is a case. Weight the indicators; do not fire on each one alone.
Writing the STR when the trail runs through a platform
Reporting a suspicious transaction to the financial intelligence unit is a core FATF Standard, set out in Recommendation 20, and it is the point where the digital-intelligence message either lands or gets lost. When the suspicion originates on a platform, the transaction record on its own is thin. A EUR 40 inbound transfer tells the FIU almost nothing. The context is where the intelligence value sits.
As a practitioner recommendation rather than a FATF filing instruction, firms should follow the applicable FIU’s schema and guidance and include relevant digital identifiers where permitted and useful, such as a social handle, campaign name or URL, wallet address, QR-linked destination and event timing. The FATF report calls for linking financial and digital intelligence, but it does not prescribe STR fields or narrative content.
Two cautions on scope. Retention and disclosure of underlying digital material, such as a URL or handle, are governed by the applicable record-keeping, data-protection, legal-process, confidentiality and tipping-off rules. Firms should follow the relevant jurisdiction’s law and FIU instructions. The reporting duty is governed by the applicable national regime and may cover attempted transactions as well as completed transactions. The FATF Interpretive Note to Recommendation 20 states that all suspicious transactions, including attempted transactions, should be reported regardless of amount. The report does not create a general duty for a financial institution to monitor a platform it does not operate. For the operational mechanics of filing, our note on AML reporting in Luxembourg walks through the goAML route that many EU financial intelligence units use.
Crowdfunding, charities and the non-profit risk balance
Fraudulent humanitarian and charitable crowdfunding is one of the report’s headline typologies, and it drags in a sector the FATF treats with deliberate care. The FATF Standard on non-profit organisations, Recommendation 8, was revised in 2023 to require focused, proportionate and risk-based measures aimed only at the non-profits actually at risk of terrorist financing abuse. The revision exists because blanket suspicion of the whole sector caused real harm to legitimate charities.
The practical instruction for an AML team is to hold two ideas at once. A campaign that impersonates a humanitarian cause to raise terrorist funds is a genuine and named risk. Recommendation 8 requires countries to identify the FATF-defined non-profit organisations at risk and apply focused, proportionate measures without disrupting legitimate non-profit activity, given that registration is not a proxy for low risk and the scope of Recommendation 8 covers the FATF-defined NPO subset rather than all crowdfunding activity. The signal is the mismatch: a cause with no registered organisation behind it, a beneficiary account that does not match the named charity, a collection that appears only on ephemeral posts, or funds that route straight to conversion rather than to programme delivery. De-risking an entire category of customer to avoid the work is the failure mode supervisors have started to push back on, a theme the CSSF set out in its guidance on de-risking and money-laundering risk management.
Virtual assets, rotating wallets and the travel rule
Virtual asset fundraising through rotating wallets and QR codes is the typology that most directly tests existing controls, because it is engineered to beat static screening. A campaign that publishes a fresh receiving address for each appeal, or generates addresses on demand behind a QR code, denies a screening engine the stable identifier it was built to match.
The FATF Standards apply relevant AML/CFT measures to virtual asset service providers through Recommendation 15 and the virtual-asset transfer requirements incorporated through Recommendation 16. FATF revised Recommendation 16 at its June 2025 Plenary, but states that the revised changes are to come into effect by the end of 2030. The travel rule requires the originator and beneficiary information to travel with a transfer, which is what gives investigators something to follow when the on-chain address is disposable. In the EU, the Recommendation 16 travel-rule framework is implemented through the Transfer of Funds Regulation, Regulation (EU) 2023/1113, applicable since 30 December 2024, which extends originator and beneficiary data requirements to crypto-asset transfers. For a VASP, the control response to rotating wallets runs through complete travel-rule data, counterparty-VASP diligence and behavioural monitoring across the whole customer relationship, all of which reach further than screening a single disposable address. The FATF’s targeted update on VASP standards implementation tracks how far member jurisdictions have actually built this.
Public-private partnerships: the report’s real ask
Strip the report to its recommendations and the centre of gravity is cooperation. The key measures lead with strengthening structured dialogue between public authorities and the private sector, enabling effective information sharing and deepening public-private partnerships, and they run through enhancing inter-agency coordination and linking financial intelligence with digital intelligence. FATF President Elisa de Anda Madrazo framed it plainly, saying that no single jurisdiction or authority can address the threat alone and welcoming the engagement so far with technology and social media companies.
For a financial institution, the operational reading is about being ready to use the channels that already exist. Where a jurisdiction runs a public-private partnership for financial intelligence, the platform typologies are precisely the kind of pattern those forums are designed to surface, because the digital context that a firm cannot see may be exactly what a tech company or an FIU can. The constraint is legal, not technical: what can be shared, with whom and under what gateway is set by national law and the confidentiality rules around the STR process. Appetite does not change the gateway. The report asks for more and better sharing; the discipline is to do it within the gateways your jurisdiction actually provides.
Frequently Asked Questions
Does the FATF report create a new reporting obligation for my firm?
No. It is a typologies and trends report. It introduces no new return, template or filing deadline. Its effect on obliged entities is indirect: firms should assess whether the typologies are relevant to their products and customers and, where appropriate, reflect them in risk assessments, controls and reporting practices under applicable national law. The FATF publication itself does not create a supervisory deadline or a new firm-level requirement.
Are social media and messaging platforms now obliged entities under the FATF Standards?
Not as a class. The report draws a clear line on scope: specific activities conducted through or facilitated by SMSPs may fall within sectors already regulated under the FATF Standards, such as virtual asset service providers and payment institutions. The platforms themselves carry no direct AML/CFT obligation as a class; the regulated endpoint carries the obligation.
What is the single most useful change to make in transaction monitoring?
Add indicators that combine a payment pattern with digital context, since neither element carries the signal alone. A cluster of small inbound transfers or first-seen virtual asset addresses, tied to a fundraising narrative, a social handle or a QR-linked address and a beneficiary whose profile does not fit, is far more informative than any of those elements on its own. The report’s emphasis on linking financial and digital intelligence is the design principle.
How should the suspicious-transaction report be written differently?
Follow the applicable FIU’s filing schema and guidance. Where permitted and relevant, include digital identifiers such as handles, campaign names or URLs, wallet addresses, QR-linked destinations and event timing in the designated fields or narrative. The FATF report supports linking financial and digital intelligence but does not prescribe the content of an STR narrative.
Does this mean we should treat charities and crowdfunding as high risk?
No blanket classification is supported. Recommendation 8 requires countries to identify the FATF-defined non-profit organisations at risk and apply focused, proportionate measures without disrupting legitimate non-profit activity; it does not make registration conclusive and does not govern every crowdfunding campaign. Firms should assess charity and crowdfunding activity under their own risk-based obligations and applicable national guidance, including mismatches between the stated cause, beneficiary and use of funds.
We are a crypto-asset service provider. What does the report change for us?
The rotating-wallet and QR-code typology is aimed squarely at your controls. Address screening alone will not catch a campaign that issues a fresh address per appeal. The FATF Standards already reach the activity through Recommendation 15 and the Recommendation 16 travel rule, so the response is complete travel-rule data, counterparty-VASP diligence and monitoring across the whole customer relationship instead of a single address. In the EU, Regulation (EU) 2023/1113 has required specified originator and beneficiary information and related missing-information controls for covered crypto-asset transfers since 30 December 2024. Broader customer due diligence, ongoing monitoring and correspondent-relationship duties arise from the AML framework and applicable national law.
How does this connect to the EU AML reform?
The EU perimeter change is split across instruments. Regulation (EU) 2023/1113 applied from 30 December 2024, extended transfer-information requirements to crypto-asset transfers and amended Directive (EU) 2015/849 to bring MiCA crypto-asset service providers into the obliged-entity perimeter. Regulation (EU) 2024/1624 generally applies from 10 July 2027 and includes crowdfunding service providers and crowdfunding intermediaries. Neither instrument prescribes the report’s specific SMSP monitoring scenarios; firms must map relevant typologies into risk-based controls under the applicable AML/CFT framework.
Related Articles
- FATF report on public-private partnerships for illicit finance: how information sharing between financial institutions, law enforcement and other private entities is expected to work.
- FATF’s seventh targeted update on VASP standards implementation: where member jurisdictions stand on Recommendations 15 and 16 for cross-border compliance.
- FATF travel-rule consultation on Recommendation 16: the payment-transparency changes shaping originator and beneficiary data rules.
- FATF’s 2026-28 fraud-focused presidency roadmap: what firms should prepare for in fraud-related AML controls and risk assessments.
- FATF on stablecoins and unhosted wallets: the AML/CFT questions around wallet-based value transfer.
- AML reporting in Luxembourg: the goAML suspicious-transaction reporting route used across many EU financial intelligence units.
Key Takeaways
- The FATF’s 26 June 2026 report on terrorist financing through social media, messaging and streaming platforms creates no new reporting obligation. Its value is a fresh, structured set of typologies and indicators for risk assessments and monitoring.
- Fewer than 30% of jurisdictions contributing to the FATF report covered this risk in their national risk assessments. The report does not quantify the prevalence of firm-level control gaps or state when supervisors will test them.
- SMSPs are not an obliged-entity category merely because they are platforms, but an SMSP or associated provider may itself fall within the FATF definition of a financial institution or virtual asset service provider depending on the financial functions it performs. Obligations attach under the applicable functional and national-law perimeter, not automatically to every downstream endpoint.
- Named typologies include fraudulent charitable crowdfunding, creator-economy tipping, virtual asset fundraising via rotating wallets and QR codes, and coded or ephemeral content used to arrange payments.
- Build indicators that combine a payment pattern with digital context; single micro-transactions are noise until they are linked to a handle, a campaign, a flagged wallet and a mismatched beneficiary.
- Include digital identifiers in STR narratives where the FIU’s schema and applicable law permit: handles, campaign URLs, wallet addresses and event timing carry intelligence value, subject to tipping-off and confidentiality rules.
- Keep the charity response proportionate. FATF Recommendation 8 targets the non-profits actually at risk and warns against blanket de-risking of the sector.
- For virtual assets, complete travel-rule data under Recommendations 15 and 16, and counterparty-VASP diligence, answer rotating wallets better than address screening alone.
Sources and References
- FATF, FATF highlights the latest risks of terrorist financing through social media, instant messaging applications and streaming platforms (26 June 2026), and the accompanying report Detecting and disrupting terrorist financing activity through social media, instant messaging applications and streaming platforms.
- FATF, Comprehensive Update on Terrorist Financing Risks (8 July 2025).
- FATF, The FATF Recommendations (as amended), including Recommendation 1 (risk-based approach), Recommendation 8 (non-profit organisations), Recommendation 15 (virtual assets and VASPs), Recommendation 16 (wire transfers, the travel rule) and Recommendation 20 (reporting of suspicious transactions).
- FATF, Protecting non-profit organisations from terrorist financing abuse through risk-based implementation of revised Recommendation 8.
- FATF, Update to Recommendation 16 on payment transparency (June 2025).
- Regulation (EU) 2024/1624 (Anti-Money Laundering Regulation) on the prevention of the use of the financial system for money laundering or terrorist financing, applicable from 10 July 2027: EUR-Lex.
- Directive (EU) 2024/1640 (AMLD6) on the mechanisms to prevent the use of the financial system for money laundering or terrorist financing: EUR-Lex.
- Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets and amending Directive (EU) 2015/849 (Transfer of Funds Regulation), applicable from 30 December 2024: EUR-Lex.
Turning the FATF’s platform typologies into your next risk review
At firm level, a reasonable response is to assess whether the report’s typologies are relevant to the institution’s products, customers and transaction channels, and to update risk assessments, controls or reporting practices where required by the applicable framework. The report’s formal recommendations are principally addressed to jurisdictions and competent authorities. The starting move is small and specific: take the typologies list, check it against your current scenarios, and mark the ones you cannot currently detect. That mapping is the gap the FATF has flagged at a global level, made concrete for one firm. Close it before a supervisor asks to see the working.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
