Home / Companies / Didit / Blog / Post Details
Content Deep Dive

The UK's first A7 alert describes a network built to pass identity checks

Blog post from Didit

Aggregate trend data notice

Excluded from normalized aggregate trends after staff review: 3056 posts were attributed to March 2026; 671 shared March 14, 2026. The preceding six-month median was 13.5 posts.

Review evidence: 3,056 posts in March 2026; 671 shared March 14, 2026; preceding six-month median 13.5. Reviewed August 9, 2026.

This company's pages remain public, but its content is excluded from normalized aggregate trends. Unfiltered raw trends and advanced filtering are available to Accelerate and Lead accounts.

Post Details
Company
Date Published
Author
Didit
Word Count
3,018
Company Posts That Month
12
Language
English
Hacker News Points
-
Post removed?
No
Summary

The UK National Crime Agency’s Flash Alert 0808-NECC, issued on 31 August 2026 with the National Economic Crime Centre, OFSI and other partners, describes A7 as a Russian-backed cross-border settlement network allegedly designed to help sanctioned clients move value through foreign shell companies, local bank accounts, promissory notes and layered correspondent-banking arrangements that obscure Russian origins. Established in 2024 and backed by Promsvyazbank and VEB.RF, A7 claims to have settled more than USD 86 billion in its first year, though the NCA notes this is the network’s own unverified figure. The alert says A7 creates or controls overseas “sub-agents,” including by furnishing websites, corporate email addresses and VPN access intended to make staff and companies appear locally based, while transactions may be supported by false invoices and routed through intermediary jurisdictions. It identifies seven indicators, including unusual transaction volumes or invoices, limited ownership information, high-risk jurisdictions, thin or generic online presences, and VPN activity inconsistent with a customer’s profile, emphasizing that four indicators focus on customer identity and onboarding data rather than payments. The NCA cautions that a Flash Alert is intelligence about a potential typology rather than proof of illicit conduct or a sanctions list, so firms should assess all circumstances, submit suspicious activity reports where appropriate, and report confirmed sanctions breaches or frozen assets to OFSI.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.