Skip to main content
OFAC's Ecuador Sanctions Expose a Screening GapSanctions Lists & Screening
5 min readFor AML Compliance Officers

OFAC's Ecuador Sanctions Expose a Screening Gap

The Challenge

A network of fishing companies and construction-material suppliers in Manta, Ecuador, moved thousands of kilograms of cocaine monthly while appearing legitimate. These businesses provided fuel, food, medical support, and logistical assistance to cocaine-laden vessels heading north through the Eastern Pacific toward Mexico.

In June 2026, OFAC sanctioned 15 individuals and entities, plus 10 vessels tied to this network. These businesses were linked to Los Choneros, Los Lobos, and Mexican cartels, including the Sinaloa Cartel and CJNG. By the time OFAC acted, Operation Pacific Viper had already seized over 225,000 pounds of cocaine in the Eastern Pacific.

The technical problem for compliance teams: your name screening system probably wouldn't have caught these entities before designation. They looked like fishing companies, had legitimate customers, filed paperwork, and the people controlling them weren't always listed as direct owners.

Screening Limitations

Financial institutions face two main challenges when screening for sanctions risk in cases like this.

First, most screening workflows check customer names against the SDN List and other watchlists at onboarding and periodically thereafter. This works when the sanctioned party is your direct customer. It doesn't work when your customer is owned by a sanctioned individual through a holding structure or when your customer does business with a sanctioned entity you've never heard of.

Second, OFAC's 50 Percent Rule requires blocking entities owned 50% or more by designated persons. However, many core banking systems and payment platforms don't automatically include beneficial ownership data in the screening process. You're expected to know who owns your customer and block transactions involving entities controlled by sanctioned parties. But the data infrastructure to do that at scale often doesn't exist.

Add sector-specific risk into the mix. Maritime and trade finance are vulnerable to exploitation due to cross-border movement of goods, complex documentation, and multiple intermediaries. A fishing vessel can operate in international waters. A construction-material supplier can ship cement to a port. The red flags aren't in the business type; they're in the ownership, transaction patterns, and network of relationships around the entity.

OFAC's Approach

OFAC didn't just sanction the individuals running the cocaine operation. It sanctioned the companies they controlled, the vessels those companies operated, and the infrastructure supporting the trafficking network.

This is network-level enforcement. OFAC identified fishing businesses and construction firms allegedly owned or controlled by designated individuals, then blocked those entities under the 50 Percent Rule. It designated vessels by name and IMO number. It made clear that logistical support (fuel, food, medical assistance) counts as material support to a sanctioned activity.

The action was coordinated with U.S. law enforcement and military agencies and built on Operation Pacific Viper, which the Coast Guard launched in August 2025. Treasury framed the sanctions as part of a broader effort targeting cocaine flows through the Eastern Pacific.

For compliance teams, the lesson isn't just that OFAC will designate front companies. It's that OFAC expects you to identify those front companies before they show up on the SDN List.

Results and Implications

The immediate result: any U.S. financial institution holding accounts or processing payments for the sanctioned entities must block those transactions. Any institution with correspondent relationships touching Ecuadorian maritime or construction sectors now has heightened exposure.

The broader result: this case shows that name-based screening alone won't catch sanctions risk in time. You need beneficial ownership visibility. You need to screen related entities, not just direct customers. And you need sector-specific risk assessments that account for how criminal networks exploit legitimate industries.

OFAC's designation packages often include ownership details, vessel identifiers, and business relationships. Those details are there because OFAC expects you to use them. If you're only screening the company name your customer gave you at onboarding, you're missing half the picture.

What Compliance Teams Should Do Differently

Start with beneficial ownership. If your customer due diligence process doesn't capture beneficial owners at onboarding, you can't screen them. If you capture them but don't run them through sanctions lists, you're not complying with the 50 Percent Rule. And if you only check beneficial ownership once at onboarding, you won't catch changes in control that create new sanctions exposure.

Next, build sector-specific risk indicators into your monitoring. For maritime customers, track vessel ownership, flag registries, and port activity. For trade finance, understand the counterparties in the transaction, not just your direct customer. For construction and commodity suppliers, ask why a small business in a high-risk area is moving large volumes of goods to or from ports associated with trafficking routes.

You also need relationship screening. If your customer does business with a sanctioned entity, it's a risk indicator you should investigate. Some platforms can map commercial relationships and flag connections to sanctioned parties. If yours can't, you're relying on manual reviews that won't scale.

Finally, don't treat sanctions screening as a point-in-time check. OFAC adds designations constantly. Your customer might be clean today and sanctioned tomorrow. Ongoing due diligence means rescreening your customer base against updated lists and reassessing risk when circumstances change (new ownership, new business lines, new geographies).

Takeaways for Your Team

This case shows what happens when criminal networks use legitimate businesses as fronts. Your screening controls need to see through that.

Beneficial ownership isn't optional. You must identify who controls your customer, and you must screen those individuals and entities against sanctions lists. The 50 Percent Rule makes this a legal requirement.

Sector matters. Maritime, trade finance, construction, and commodities are vulnerable to exploitation. If you serve customers in these sectors, your enhanced due diligence should include ownership verification, transaction pattern analysis, and relationship mapping.

Network-level risk is real. OFAC doesn't just sanction individuals anymore. It sanctions the companies they own, the vessels they operate, and the infrastructure they use. Your screening process needs to account for that.

If you're waiting for a name to appear on the SDN List before you investigate, you're already behind. The point of sanctions compliance isn't just to block designated persons. It's to prevent your institution from becoming a conduit for illicit finance.

You Might Also Like