A sanctioned entity that transacts under its own name gets caught by basic screening. The name is on a list, the screening engine flags it, the transaction stops. This happens thousands of times a day, and it is not where the problem lives.
The problem lives one step away. A sanctioned party that wants to move money or goods does not need to beat the screening engine. It needs to make sure its name never reaches it. Every evasion typology is a method of severing the documentary link between the designated party and the money or goods. Corporate layering severs the ownership link. Trade obfuscation severs the destination link. Maritime tactics sever the cargo link. Crypto severs the flow link.
The mechanics of that severing are ordinary. An entity is formed in a jurisdiction that asks few questions. A nominee takes a directorship. A document gets a different end user. A transponder goes dark. A wallet appears that has no history. None of these steps is exotic, and none of them is visible from a sanctions list.
That is why screening a name against a list is necessary but not sufficient. The evasion happens in the gap between the listed name and the transaction you actually see. A compliance program that only screens what is in front of it is always one typology behind.
The four typologies below are the most common ways that gap gets built. They read as four separate problems. Operationally they are one problem.
The sections that follow take each typology in turn, then close with what they share:
- Corporate layering: shell companies, front companies, and nominees
- Trade obfuscation: transshipment, misdescription, and dual-use goods
- Maritime evasion: the shadow fleet
- Crypto evasion: mixers, bridges, and cross-chain swaps
- The common thread: severing the link
- How Sanction Scanner helps
Corporate layering: shell companies, front companies, and nominees
Sanctioned actors rarely hold anything in their own names. They use chains of shell companies, front companies, nominee directors, and trade intermediaries to put layers between themselves and the asset. Each layer adds a registry entry, a jurisdiction, and a name that is not on any sanctions list.
These do different jobs. A shell company has no real operations: it exists to hold, to receive, and to sign. A front company has operations, sometimes real ones, and exists to look like a normal trading counterparty while acting for the sanctioned party behind it. A nominee is a natural person whose name stands in for someone else's, as shareholder or director. Most real structures use all three at once: A front company trades, a chain of shells holds, and a nominee signs.
The 50% rule is the main countermeasure, and the evasion response to it is instructive. OFAC blocks entities that are owned 50% or more by an SDN-listed person, with ownership counted in the aggregate and through intermediate layers. Evaders fragment ownership below the threshold: a 49% stake here, a 24% stake there, spread across entities that each stay under the line. An unlisted natural-person nominee holding the rest removes the problem entirely. The nominee's name is not on the list, and the listed person's name never appears on paper at all.
Detection has to follow the same logic in reverse.
- Map the ownership structure to the natural person, not to the first layer of entities. The question at every level is the same: Who is this entity working for.
- Watch for co-location red flags: entities sharing an address, an agent, a formation date, or a corporate services provider with listed parties. Proximity in the filings is proximity in the structure.
- Interrogate nominees. An unlisted nominee with no genuine business role is a name doing a job, and the job is concealment. Ask what the person does, where they are, and how they came to hold the shares.
Trade intermediaries round out the toolkit. They receive payments, hold goods, and issue invoices that sever the link between the sanctioned party and the final counterparty. Screening the intermediary is easy. Screening through it is the actual job.
The tell is almost always in the pattern, not in any single document. A single holding company is normal. A holding company that shares a registered agent with a sanctioned entity, was formed the same week as two similar companies, and lists a nominee director who appears in five unrelated filings is not normal. The pattern is the signal, and ownership mapping is what makes the pattern visible.
One more pressure point works against the evader: The structure has to stay usable. The front company must trade, the shells must sign, the nominee must renew filings. Each of those actions leaves a trace, and the traces point inward. A compliance team that keeps asking eventually reaches a person who has no good answer.
Trade obfuscation: transshipment, misdescription, and dual-use goods
When goods cannot cross a border in their own name, they change their story. Trade obfuscation routes goods and payments through third countries to mask the final destination. The hubs that keep recurring in enforcement and open-source analysis: Hong Kong, Switzerland, Malaysia, Oman, and Central Asia. The pattern in each is the same: A shipment arrives from a sanctioned supplier, gets re-invoiced by a local intermediary, and departs for its real destination with a clean paper trail.
The techniques are paperwork first and logistics second. Falsified end-user certificates and commodity documents describe a civilian buyer in a friendly jurisdiction. HS code misclassification relabels a restricted component as an unrestricted one: A pump becomes a general machine part, a navigation part becomes consumer electronics. Dual-use goods get described as their civilian versions. The cargo itself is the same. The documents are the disguise.
The financial side runs in parallel. Payments route through the same intermediary chain, and the invoices are written to match the falsified documents. A trade finance bank sees a complete, consistent file that happens to be false, which is why the checks below treat consistency as a minimum rather than an assurance.
The hard part is that the honest version of this trade exists. Dual-use goods are genuinely sold to civilian buyers, and transshipment hubs are genuinely convenient. Evasion hides inside legitimate trade, so detection works on anomalies rather than on suspicion: A shipment that matches its documents, its port pairs, and its end user is fine, and one that does not is not.
Detection works on documents and on data.
- Verify end users. Ask who will actually receive and use the goods, then check that the answer holds up against the intermediary's history and the destination's realities.
- Run supply chain due diligence on the intermediaries, not just the counterparty. The intermediary in a transshipment hub is where the evasion happens. A newly formed trading company with no history that suddenly exports sophisticated goods is a classic setup.
- Read bills of lading for inconsistencies: ports, dates, weights, and descriptions that do not line up. A bill of lading records physical events, and physical events leave traces that falsified documents rarely get right.
- Watch for trade-data anomalies. The clearest is goods appearing in a sanctioned jurisdiction after a suspicious transshipment. Mirror statistics, comparing what one country reports exporting against what the other reports importing, surface the same thing at aggregate scale.
US enforcement has spelled this out directly. The Tri-Seal Compliance Note issued by BIS, DOJ, and OFAC in March 2023 warns that third-country intermediaries are a primary channel for Russia-related evasion, and it puts the burden on exporters, freight forwarders, and banks to look past the paperwork. The pattern it describes is simple: Goods leave a friendly country, stop somewhere convenient, and arrive where they were never supposed to go. The paper trail describes a different trip.
One organizational note: Trade documentation often sits with a different team than sanctions screening. The evaders know this. The gap between the sanctions team and the trade team is part of the evasion surface.
Maritime evasion: The shadow fleet
Maritime sanctions evasion is trade obfuscation with an engine room. The tools are specific to ships: Automatic Identification System (AIS) manipulation, ship-to-ship transfers, flag-hopping, and opaque vessel ownership. They move Russian, Iranian, North Korean, and Venezuelan oil, and they move it through a shadow fleet of aging tankers whose owners are deliberately hard to establish. Estimates of the fleet's size run from several hundred to well over a thousand vessels, and the number keeps growing as the trades it serves keep growing.
AIS manipulation is the first trick. AIS broadcasts a vessel's position, and evaders disable or spoof the transponder. A tanker that goes dark for three days in the Gulf of Oman and reappears lighter by a few hundred thousand barrels has made its cargo change hands invisibly. Spoofing is the riskier variant: The vessel broadcasts another ship's identity, so the record shows a different ship in a different place.
Ship-to-ship transfers are how the cargo changes identity. The oil leaves a sanctioned seller's vessel and enters a clean one, sometimes in a busy anchorage, sometimes at sea. From that moment the cargo's documentation starts over with a new ship and a new origin story. The transfer is legal in ordinary trade, which is exactly what makes it useful as evasion.
Flag-hopping is the same trick with paperwork. A vessel re-registers from one flag to another, often to a registry with weak oversight, and picks up a new name in the process. The hull, the crew, and the cargo are the same. The identity is new. A ship that has carried several names and several flags in a few years is not well traveled. It is being managed.
Regulators treat this as deception, not sophistication. The Price Cap Coalition advisory for the maritime oil industry, updated in October 2024, catalogs the practices explicitly: manipulated AIS, transfers in high-risk areas, falsified documentation, and layered ownership, with instructions for insurers, port authorities, and flag registries on what to do when they see them. OFAC's maritime guidance goes back further, to the May 2020 advisory that first told the industry to treat vessel identity as a sanctions question.
Detection follows the parts that cannot be renamed.
- Screen by International Maritime Organization (IMO) ship identification number not by name. The IMO number stays with the hull through renames and re-flagging.
- Monitor AIS gaps and spoofing. A gap is not necessarily a violation, but a gap combined with a transfer is a pattern.
- Flag frequent re-flagging as a signal by itself, and ask what the vessel's history says about its operator.
- Screen the associated parties: the registered owner, the beneficial owner, the manager, and the charterer. Opaque ownership is the whole point of the shadow fleet, so the screening has to reach past the registration.
The choke points for the shadow fleet are commercial: insurance, classification, port access, and dollar clearing. Evasion survives by finding providers that do not look. Providers that look find the fleet quickly, and the ones that do not become part of the story when enforcement comes.

Crypto evasion: Mixers, bridges, and cross-chain swaps
Crypto is the newest typology and the fastest growing one. Wallets are generated instantly and cost nothing. Funds move across chains through bridges, get obfuscated through mixers and privacy protocols, and reappear in a wallet that has no history and no owner on file. What used to take a dozen shell companies now takes an afternoon.
The tools deserve quick definitions. A mixer pools deposits from many users and returns funds minus a fee, which breaks the link between the sender and the eventual recipient. A bridge moves assets from one blockchain to another, and tracing tools handle some chains better than others. A cross-chain swap does the same without a centralized bridge, exchanging one chain's asset for another's through liquidity pools. Privacy protocols then remove the address history that analytics would otherwise reconstruct. Used in sequence, they convert a traceable payment into a wallet with no past.
The numbers put this beyond anecdote. Chainalysis's 2026 Crypto Crime Report found that sanctioned entities received at least $104 billion in cryptocurrency in 2025, up 694% year over year. Illicit addresses overall received at least $154 billion, up 162%. The growth is state driven. Russia, Iran, and North Korea all use crypto at scale now, each with its own tradecraft: Russian legislation passed in 2024 turned into on-chain settlement in 2025, including a ruble-linked stablecoin that processed more than $93 billion in less than a year; IRGC-linked addresses accounted for over half of all value received by Iranian entities in late 2025, moving more than $3 billion; and North Korean actors stole more than $2 billion in crypto in 2025 alone.
The enforcement response has been direct. OFAC designated the Blender.io mixer in May 2022 and Tornado Cash in August 2022. Tornado Cash was later delisted, in March 2025, after a court ruled that its autonomous smart contracts could not be treated as property subject to sanctions, which leaves the legal debate about privacy tools open even as designations keep coming. On the basic question OFAC has been consistent from the start: IEEPA prohibitions apply to virtual assets identically to fiat currency. A sanctioned address is a sanctioned party, in a wallet or in a bank account.
Detection is analytics work with four moving parts.
- Run blockchain analytics on inflows and outflows, not just the counterparty wallet. The exposure often sits one hop away.
- Screen wallets against OFAC-designated addresses, and against addresses attributed to designated actors. OFAC has designated hundreds of addresses, and the lists grow with each enforcement package.
- Monitor indirect exposure. A wallet one or two hops from a sanctioned address is the crypto version of a co-located shell company.
- Flag mixer and bridge behavior. Funds that enter a mixer or cross a chain and re-emerge immediately are asking to be explained, and the explanation usually comes later or not at all.
Crypto also adds a new failure mode for traditional programs: A bank can screen every counterparty perfectly and still hold exposure through an exchange, a payment processor, or a stablecoin issuer that did not. Indirect exposure is not a crypto curiosity. It is now a standard item in sanctions risk assessment.
The typology is new. The underlying move, hiding the flow, is as old as the others.
The common thread: Severing the link
Every typology in this article does the same thing: It creates distance between the sanctioned party and the visible transaction. Corporate layering hides ownership. Trade obfuscation hides destination. Maritime tactics hide cargo origin. Crypto hides the flow.
The distance is the product. A compliance program screens what it can see, so evaders invest in what they can hide. This is also why the typologies compound in practice: Oil bought with crypto, carried by a shadow tanker, and sold through a shell trader is one transaction using three typologies at once. A program that covers two of the three still misses the deal.
That is why effective sanctions compliance is not a single name check. It is a layered program:
- Entity screening plus Ultimate Beneficial Owner (UBO) mapping to reach the natural person.
- Adverse media to surface the networks behind the entities.
- Vessel and IMO screening for the cargo side.
- Transaction and behavioral monitoring for the patterns.
- Ongoing re-screening, because designations and structures change.
The layers also need owners. Sanctions teams own the screening, but trade documentation belongs to trade compliance, vessel checks to shipping and logistics, and wallet exposure to whoever runs payments. The evaders' advantage is that most institutions keep these functions in separate silos. Closing that gap is as much an organizational job as a software one.
|
Typology |
How it severs the link |
Detection method |
Screening layer |
|
Corporate layering |
Ownership fragmented below 50%, nominees hold the rest |
Ownership mapping, co-location red flags, nominee interrogation |
Entity screening, UBO mapping |
|
Trade obfuscation |
Goods rerouted and documents rewritten |
End-use verification, document checks, trade-data anomalies |
Trade and document screening |
|
Maritime evasion |
Vessels renamed, repositioned, and re-flagged |
IMO screening, AIS gap monitoring, ownership checks |
Vessel and IMO screening |
|
Crypto evasion |
Funds mixed, bridged, and re-walleted |
Blockchain analytics, indirect exposure, mixer and bridge flags |
Wallet and transaction monitoring |
How Sanction Scanner helps
Sanction Scanner's layered screening is built for exactly these gaps. Entity and UBO screening follows the ownership chain instead of stopping at the front company, which matters most where ownership has been fragmented below the 50% line or handed to a nominee. Adverse media screening surfaces the networks and intermediaries that keep appearing around evaders: the trading company with no history, the provider that shows up next to designated entities in three unrelated filings, the vessel operator that renames its ships every other year.
The same lists do more work than a name check when they are pointed at the right objects. Sanctions list screening covers the designated vessels that OFAC lists by IMO number, the designated wallet addresses that show up in crypto enforcement actions, and the entities behind them, not just the front names. That is the practical version of screening the distance instead of the name.
The layers connect in one system. A KYB check that maps an ownership chain feeds the same case file as a sanctions match or an adverse media hit, so an analyst can see that the shell company flagged in screening is the same party that appeared in a vessel's ownership structure two months earlier. Case management keeps that trail intact, and it is the part an examiner or auditor will ask for first: who you screened, what you found, and why you proceeded or stopped.
Ongoing monitoring closes the loop. Designations change, structures change, and a clean counterparty can become a problem overnight: a new SDN designation next month, a new owner on a re-registered vessel, an address that is now one hop from a sanctioned wallet. Re-screening picks that up without waiting for the next onboarding. See the AML sanctions screening, sanctions list screening and monitoring, adverse media screening, and KYB capabilities for the mechanics.
The typologies above will keep evolving, because the incentive behind them does not. The programs that stay effective are the ones that screen the distance, not just the name.
Sources
[1] Financial Crimes Enforcement Network, and Office of Foreign Assets Control. Note: The 50 Percent Rule guidance is OFAC's. OFAC FAQ 401: Revised Guidance on Entities Owned by Blocked Persons. 2025.
[2] Bureau of Industry and Security, Department of Justice, and Office of Foreign Assets Control. Tri-Seal Compliance Note: Cracking Down on Third-Party Intermediaries Used to Evade Russia-Related Sanctions and Export Controls. 2023.
[3] Price Cap Coalition (G7, EU, Australia, New Zealand). Updated Price Cap Coalition Advisory for the Maritime Oil Industry and Related Sectors. 2024.
[4] Chainalysis. The 2026 Crypto Crime Report. 2026.
[5] Office of Foreign Assets Control, U.S. Department of the Treasury. Treasury Sanctions Tornado Cash and Delisting Notice. 2025.
FAQ's Blog Post
Transshipment routes goods through a third country to disguise the real destination. A shipment leaves a friendly country, stops somewhere convenient like Hong Kong or Central Asia, gets re-invoiced by a local intermediary, and departs for a sanctioned destination with a clean paper trail. The intermediary is where the evasion actually happens.
Dual-use goods have both civilian and military or restricted applications, and evasion works by describing the restricted item as its civilian version. A navigation component becomes consumer electronics on the paperwork while the cargo stays the same. The honest trade genuinely exists, so detection depends on anomalies, not suspicion.
Ship-to-ship transfers move oil from a sanctioned seller's vessel to a clean one, sometimes at anchorage, sometimes at sea. From that moment the cargo's documentation restarts with a new ship and origin story. The transfer is legal in ordinary trade, which is exactly what makes it useful for laundering sanctioned cargo.
Tornado Cash is no longer sanctioned. OFAC designated it in August 2022, but delisted it in March 2025 after a court held that its immutable smart contracts could not be treated as property under IEEPA. OFAC's position that sanctioned wallet addresses remain off-limits, in crypto or fiat, has not changed.
Sanctioned entities use crypto by generating fresh wallets and moving funds through mixers, bridges, and cross-chain swaps that break the link between sender and recipient. Chainalysis found sanctioned entities received at least $104 billion in crypto in 2025, up 694%, making evasion the largest single driver of illicit on-chain volume.
AIS manipulation is the disabling or spoofing of a vessel's Automatic Identification System transponder to hide its movements. A tanker that goes dark for days and reappears lighter has transferred cargo invisibly. Spoofing goes further, broadcasting another ship's identity so the record shows a different vessel in a different place.
Vessels should be screened by IMO number because the name and flag can change but the IMO number cannot. The International Maritime Organization number stays with the hull through renames and re-flagging, so it is the one identifier a shadow-fleet operator cannot swap out to defeat name-based screening.
Shadow fleet refers to aging tankers, estimated from several hundred to well over a thousand vessels, that move sanctioned Russian, Iranian, North Korean, and Venezuelan oil while hiding their ownership and cargo origin. They rely on AIS manipulation, ship-to-ship transfers, and flag-hopping, which is why regulators treat these practices as deliberate evasion.
Sanctioned parties get around the 50% rule by fragmenting ownership below the threshold. Instead of one blocked person holding a majority, the stake is split, a 49% share here, a 24% there, with an unlisted nominee holding the rest. No single entity crosses the line, and the listed name never appears on paper.
Shell companies and front companies both hide a sanctioned party, but they work differently. A shell company has no real operations and exists only to hold, receive, and sign. A front company has genuine operations and trades normally while acting for the sanctioned party behind it. Most real structures use both, plus a nominee.