Cartel Terrorism Designations Are Quietly Rewriting Corporate Risk in Latin America

A significant shift in U.S. enforcement policy is underway, and most companies operating in Mexico, Brazil, and elsewhere in Latin America have not yet fully absorbed what it means for them. Over the past year and a half, the government has moved major cartels and organized criminal networks onto the same legal footing as international terrorist organizations. That reclassification is not a symbolic gesture. It opens an entirely new statutory pathway for corporate liability, one that does not require a company to know it was dealing with a cartel at all.
From Sanctions Issue to White-Collar Enforcement Priority
For years, cartel-related risk sat primarily inside the sanctions compliance function. Screen the counterparty against the OFAC list, avoid the obviously designated entities, and move on. That framing is now outdated. Executive Order 14157 directs the government to treat cartels and related criminal organizations as national security threats and authorizes their designation as Foreign Terrorist Organizations. Once a cartel carries that designation, a separate and much broader body of law comes into play: the material support statutes under the Anti-Terrorism Act.
Material support liability was built for a different era, aimed at people and entities knowingly funding or equipping terrorist networks. But the statute does not require that kind of knowing intent to create exposure. It reaches money, goods, services, and transportation provided to a designated organization, and it can attach even when the company providing that support had no idea a cartel was anywhere near the transaction. That is the core problem for corporate compliance teams: an ordinary commercial relationship, a customs broker, a freight forwarder, a logistics partner, a bank correspondent, can become a material support problem the moment any part of the value chain touches a designated organization, regardless of whether anyone in the company knew it.

Compounding this, U.S. jurisdiction over these matters is not limited to companies with an obvious American footprint. A dollar-denominated wire transfer, an email that happens to route through a U.S. server, or a single meeting held on U.S. soil can be enough to establish the jurisdictional hook prosecutors need. For any multinational moving goods or payments through Mexico, Brazil, or other high-risk jurisdictions, that is a strikingly low bar.
The Numbers Behind the Shift
The enforcement statistics since January 2025 tell their own story. More than 50 criminal cases for material support to Foreign Terrorist Organizations. Over 250 individual charges tied to cartel activity. More than 350 individuals and entities from Latin America added to the Treasury Department’s Specially Designated Nationals and Blocked Persons List. This is not an isolated policy announcement sitting on a shelf. It is an active, coordinated enforcement program, with the Justice Department, the Financial Crimes Enforcement Network, and the Office of Foreign Assets Control all moving in the same direction, and all increasingly focused not just on traffickers themselves but on the financial institutions, logistics providers, and other commercial actors that keep money and goods moving around them.
The Scoular Case Shows How This Plays Out in Practice
The Scoular Company’s recent Foreign Corrupt Practices Act resolution is the clearest illustration yet of how quickly an ordinary compliance failure can pick up a cartel dimension. Scoular, a Nebraska-based agricultural company, entered a three-year deferred prosecution agreement after authorizing customs brokers to bribe Mexican officials so that grain shipments could cross the border despite failed inspections. On its own, that is a straightforward FCPA case: a company paying to smooth over a regulatory problem.
What elevated the case was the government’s finding that a portion of the bribe payments ultimately flowed to individuals connected to a Mexican cartel. Scoular did not know about that connection. It did not matter. The penalty reflected the cartel nexus regardless. An FCPA problem became a cartel problem, and the company’s lack of knowledge about where the money ultimately went did not insulate it from that additional layer of risk. This is likely to become a recurring pattern: enforcement actions that begin as conventional bribery, sanctions, or fraud matters, and are then treated more severely once investigators trace the downstream flow of funds to a designated organization.
Brazil Adds a Second Front
The risk is not confined to Mexico. Brazil’s Operacao Carbono Oculto, launched in August 2025, became one of the largest organized-crime investigations in that country’s history, targeting the Primeiro Comando da Capital, a Sao Paulo-based criminal organization, and exposing a level of penetration into Brazil’s formal economy that appears to have surprised even experienced investigators. When the United States designated both the PCC and the Rio de Janeiro-linked Comando Vermelho as Foreign Terrorist Organizations in May 2026, it dramatically widened the exposure for multinational companies operating in Brazil. The conduct that can trigger liability under these statutes is defined broadly enough that, for virtually any multinational with Brazilian operations, this is no longer a theoretical risk category. It is a live one.

Certain sectors deserve particular attention here. Online betting and gaming platforms, in particular, combine several features that make them attractive vehicles for infiltration: explosive growth, extremely high transaction volumes, cross-border payment flows that are often already dollar-denominated, layered and sometimes opaque ownership structures, and regulatory frameworks that have not yet caught up to the pace of the industry’s expansion. Any company operating in or adjacent to that space in Latin America should treat cartel-related infiltration as a standing risk category, not a remote possibility.
What This Means for Compliance Programs
The practical implication of all this is that sanctions screening alone is no longer an adequate response to cartel risk. A counterparty can pass every standard OFAC screen and still expose a company to material support liability if money or services move, even indirectly, toward a designated organization. Compliance functions built around siloed sanctions, anti-money laundering, and anti-corruption teams are increasingly poorly matched to a risk that cuts across all three disciplines simultaneously. Effective risk identification now requires those functions to share data and analysis routinely, not just refer matters to one another after a problem has already surfaced.
Companies operating in Mexico, Brazil, and other high-risk jurisdictions should revisit existing risk assessments with this new designation landscape specifically in mind, rather than assuming that a general anti-corruption or sanctions risk assessment already captures it. That means mapping actual counterparties, supply chain nodes, and payment flows against the geographies and sectors where designated organizations are known to operate, and asking pointed questions about who is actually representing the company on the ground in those markets. It also means building periodic look-back reviews into the compliance calendar, since new designations can retroactively implicate transactions and relationships that looked clean at the time they occurred. Finally, companies should think now, before a crisis hits, about how employees facing extortion demands or coercion from criminal organizations can escalate that information quickly and safely, separate from ordinary compliance reporting channels.
The Bottom Line
Terrorism designations for cartels were framed publicly as a national security and law enforcement tool aimed at criminal organizations themselves. In practice, they have created a new and fast-moving corporate liability channel that does not depend on a company’s knowledge or intent. The Scoular case shows how an existing compliance failure can be amplified once a cartel connection is traced. The Brazilian designations show how quickly that exposure can expand into new geographies and sectors. Companies with meaningful operations in these markets should treat this as an active, not hypothetical, compliance priority, and should be building the cross-functional visibility now that would let them demonstrate, if ever asked, that they had real systems in place to identify these risks before they materialized.











