Transaction laundering occurs when a merchant uses a payment account approved by its bank or payment provider to accept card payments on behalf of another business the provider is unaware of. The hidden business, often one that is illegal or deals in prohibited goods, uses the legitimate merchant's details to get paid. It is also known as factoring or merchant laundering.
On paper, the approved merchant looks harmless: it has passed onboarding, it has a functional website, and its transactions seem normal. In fact, sales from an undisclosed store go through the same account, so the money that reaches the criminals looks like ordinary e-commerce income.
Transaction laundering vs. money laundering
Transaction laundering is a type of money laundering, but the emphasis is different. In traditional money laundering, dirty money is passed through the financial system to conceal where it came from. In transaction laundering, it is the sale itself that is hidden. The criminal is not only cleaning the proceeds; they are using someone else's merchant account to accept payments they would never be approved for on their own. That makes it a problem for payment compliance and merchant risk teams as much as for AML teams.
How does transaction laundering work?
A typical scheme follows a few steps:
- The front merchant is put in place. A criminal opens a merchant account with a website that looks legitimate, a range of products and a business profile.
- The hidden store takes orders. A second website, often selling drugs, counterfeit goods, unlicensed gambling or other prohibited products, accepts orders from customers.
- Payments are routed through the front. The hidden store sends its card payments through the front merchant's account, so the payment provider only sees the approved business.
- The acquirer pays out. The acquiring bank or payment provider handles the transactions and pays the front merchant as it normally would.
- The money moves on. The funds are passed to the criminal and now look like ordinary sales income.
Customers often have no idea they are part of it. Their card statement shows the front merchant's name, not the store they actually bought from.
A simple example
Picture a merchant that applies to an acquirer as an online shop selling phone accessories. The website is neat, the prices are reasonable and the owners clear screening. A few weeks after onboarding, transaction volume triples, the average ticket rises from around 20 dollars to more than 150, and a growing number of cards come from countries the store doesn't ship to. Behind the scenes, an unlicensed online pharmacy is running its checkout through the accessories store. Cardholders see the accessories brand on their statements, some of them don't recognize it, and chargebacks start to climb. Each of these signals is minor on its own, but together they point to transaction laundering.
Why transaction laundering is hard to spot
Each piece of the scheme looks legitimate on its own. The front merchant has a real legal entity, a working website and owners who pass screening. Payments come from genuine cardholders using real cards, so fraud rules built to catch stolen cards rarely fire. The hidden store often keeps volumes modest at first and grows slowly, and it may spread activity across several front merchants to stay under thresholds. By the time chargebacks or complaints make the problem obvious, the money has usually moved on. That is why detection depends on comparing what a merchant says it does with what its payments actually show.
Why transaction laundering matters
With the growth of e-commerce, marketplaces and payment facilitators, it has become easier to set up merchant accounts and harder to tell who is actually responsible for each transaction. That poses a risk for everyone involved in the payment process.
For acquirers, payment service providers and payment facilitators, handling transactions for a merchant whose identity is hidden can violate AML requirements and card network rules. Card networks run merchant compliance programs and can fine the acquirer when prohibited transactions are detected, and supervisors expect companies to know who their merchants are and what they sell. On top of the fines, the harm to reputation and banking relationships can be severe.
Who is most exposed?
Acquiring banks have the greatest exposure, since they hold the relationship with the card networks. Payment service providers, payment facilitators and marketplaces come next, as they take on large numbers of small merchants, often quickly and with limited documentation. Risk rises again in categories criminals tend to prefer, such as digital goods, subscriptions, nutraceuticals and online services, because the products are hard to verify from the outside.
Red flags to watch for
Transaction laundering is built to look normal, so detection depends on noticing when the numbers and the business don't match. Common warning signs include:
- A sales volume that does not match the website's traffic, product range or prices.
- A merchant category code that does not match the goods actually being sold.
- Unusual jumps in volume, ticket size or cross-border cards soon after onboarding.
- High chargeback or refund rates, or complaints from cardholders who don't recognize the merchant name. These often overlap with fraud signals.
- Sites that have little or copied content, lack a working checkout, or link to other stores.
- Owners, addresses or contact details shared with other merchants, especially ones that were terminated before.
How to detect transaction laundering
Detection works best when several methods are combined:
- Website and content checks. Crawl the merchant's listed websites regularly and compare products, prices and payment pages with what was approved. Also look for links, scripts or redirects that lead to other stores.
- Test purchases. When the risk justifies it, a controlled purchase shows exactly which descriptor and merchant account the payment goes through.
- Transaction analytics. Compare real activity with the expected profile: volume, ticket size, refund and chargeback rates, card origin and time-of-day patterns.
- Network analysis. Connect merchants that share owners, bank accounts, IP addresses, devices or contact details, so a terminated merchant cannot simply reappear under a new name.
- Continuous risk review. Feed the results of these checks back into the merchant's risk rating, so monitoring tightens as the signals accumulate.
What action should payment companies take?
No single control stops transaction laundering, but a layered approach makes it much harder to hide:
- Verify merchants properly at onboarding. Check the legal entity, its ultimate beneficial owners and its business model, and screen owners and directors against sanctions lists, PEP data and adverse media.
- Check the merchant's online presence. Compare the website, products and prices with what the merchant stated, and keep doing it after onboarding, since websites change.
- Keep a continuous watch over transactions. Use transaction monitoring to detect patterns that don't fit the merchant's profile, such as volume, ticket size, geography and time of day, then act on alerts promptly.
- Reassess risk over time. A merchant's risk rating should change when its behavior changes, not just at the annual review.
- Raise the issue and report it. If a merchant seems to be processing transactions on someone else's behalf, your AML compliance officer should take action on the account and file a suspicious activity report where necessary.
Technology matters a great deal here. On an AI-native compliance platform, automated screening and monitoring can review volumes no team could handle by hand and flag the merchants whose activity doesn't add up, so analysts can focus on the real cases.