A US federal court case wrapping up this year has laid bare one of the more elaborate identity-theft and money-laundering operations ever documented in open court — and it touches Vietnam, crypto and a major international media organisation.

Between June and July 2026, the US District Court for the Southern District of New York processed guilty pleas from Weidong "Bill" Guan, former CFO of The Epoch Times, and Le Van Hung, a Vietnam-linked individual. Guan pleaded guilty on 9 July to conspiracy to conduct financial transactions involving criminally derived property; Hung pleaded guilty in late June to conspiracy to commit identity theft. Sentencing for Hung has been scheduled, while Guan's is expected in December 2026. The charges carry maximum sentences of up to 10 years, plus possible asset forfeiture and restitution.

According to the US Department of Justice, the scheme moved roughly $67 million between 2019 and May 2024 and worked in three stages. First, stolen personal identity information (PII) was bought in bulk via the dark web and other illegal channels. Then that data was used to open fraudulent accounts: proceeds from online scams and unemployment-benefit fraud were loaded onto prepaid debit cards and converted into cryptocurrency to disguise their origin. Finally, tens of millions of dollars ended up in accounts tied to The Epoch Times and organisations in Deerpark, north of New York State — including the Dragon Springs complex — often labelled as "donations".

The revenue numbers raised eyebrows too. Internal accounts showed annual revenue jumping about 410% in 2020, from roughly $15 million to $62 million, while tax records cited by The New York Times and others put the figure at $71 million, rising to about $121 million the following year — a surge that coincides with the period prosecutors say the illicit funds were flowing in.

None of this is about the organisation's beliefs or editorial content; the court case concerns financial conduct. But it is a genuinely useful cautionary tale for anyone who travels, books online or uses public Wi-Fi. Your identity data is a commodity: scraped from breaches, sold in bulk, then cycled through fake accounts, prepaid cards and crypto within days. A single leaked passport scan or card number can feed operations at this scale.

Practical takeaways for travellers: use a credit card rather than a debit card for bookings so fraudulent charges are easier to reverse; enable transaction alerts on every account; be wary of unsolicited refund or unemployment-benefit links, a favourite vector in schemes like this one; and consider freezing your credit if your data has appeared in a breach. If you have travelled through a company that later suffered a data breach, treat any unexpected "refund" message as a scam until proven otherwise.

Sentencing is still pending, so the full picture may yet grow — but the court filings themselves are public and verifiable, making this one of the clearest windows yet into how transnational cyber-fraud money actually moves.

Story reported by Vietnam Insider.