Resources · Glossary · Long-form

What is SFMA? A category that did not have a name.

SFMA — Systemic Financial Manipulation & Attack — is the Silbad-coined name for a class of coordinated financial activity that targets the stability, liquidity or market functioning of a country, a financial institution or a major company. This page is the canonical definition, the boundaries of the category, and an honest account of why the term exists.

Definition

The canonical Silbad definition.

Quoted exactly as it appears in Silbad's internal messaging framework — the same wording that appears, where appropriate, in our contractual and pilot documentation.

Systemic Financial Manipulation & Attack (SFMA) — a set of financial activities, detectable from transactional and market patterns, aimed at manipulating or destabilising the stability, liquidity or market functioning of a country, financial institution or company.

Detectable from transactional and market patterns. The category is bounded to what is visible in financial data. Off-market coercion, regulatory abuse and political pressure are real phenomena, but they are not SFMA — SFMA is the part of the picture that financial systems themselves can see.
Manipulating or destabilising. The intent layer of the definition. Not every anomaly is manipulation; not every manipulation is destabilising. SFMA covers the union of the two: activity intended to alter or disrupt market function.
Country, institution, or company. The target layer. National financial systems, individual banks or insurance undertakings, and large publicly-quoted companies are all in scope. SFMA is not exclusively a "sovereign-level" concept — it is sovereign-level first because that is where the consequences are largest, but the institution-level cases are no less real.
What SFMA is not

The categories around it.

SFMA sits between several established disciplines and overlaps with all of them. It is not a replacement for any of them — and being precise about that boundary is part of what makes the category useful.

Not fraud

Fraud has a victim — a person, an account, an institution from whom value is taken. SFMA can have a victim too, but its target is the market itself, the institution as a system, or the macroeconomic surface a country sits on. The damage is measured in stability and confidence, not in stolen balances.

Not AML

AML follows the proceeds of past predicate crime through the financial system. It is retrospective by construction — the crime happened, the money is moving, the AML programme tries to interdict it. SFMA is forward-looking: it watches for coordinated activity that is preparing or executing a market-level effect, not laundering its proceeds.

Not market abuse (MAR)

Market-abuse regimes — MAR-style insider-dealing and instrument-level manipulation rules — are about specific instruments and specific counterparties. SFMA is broader and systemic: coordinated activity across instruments, venues, currencies and actors, intended to move a market or a national balance sheet rather than to harvest mispricing on a single instrument.

Not market manipulation in the narrow sense

Pump-and-dump, spoofing, layering and similar are tactical patterns; they can serve SFMA, but a single instance of any of them is not SFMA. SFMA requires the coordination, the systemic target, and the intent to disrupt stability or function — not just a price move.

Not classic sanctions evasion

Sanctions evasion seeks to move value past a regulatory wall. It overlaps with SFMA when the evasion is itself part of a destabilisation effort, but the two are not equivalent. Most sanctions-evasion screening fits inside AML / sanctions disciplines, not inside SFMA.

Not surveillance

SFMA detection works on the transactional and market patterns that regulated financial institutions already collect under their existing mandates. It does not extend the data the institution holds, and it does not import data from outside the regulated frame. It is a different reading of existing data — not a new data acquisition.

Why it matters

The consequences are paid by people who never entered the trade.

When SFMA succeeds, the costs land on populations who never participated in the financial event at all — and who therefore also have no obvious recourse.

Currency and credit

A coordinated attack on a national currency or on credit conditions inside a banking system shows up at the supermarket — through the cost of imports, through mortgage rates, through whether banks lend to small businesses next quarter. The pricing happens in trading rooms; the bill arrives elsewhere.

Stability of the financial system

A financial-stability event — a sudden liquidity squeeze, a cascading counterparty failure, a confidence collapse — is the macroeconomic side of SFMA. Once it starts, it rarely stays inside the institution it began at; contagion is part of the design.

Public finances

Sovereign-debt manipulation, coordinated short-selling against state-linked banks, or attacks on a country's reserves all translate into public-finance losses. The losses are absorbed through tax, through cuts to public services, or through monetary tightening — not through the original counterparties.

Systemic confidence

The deepest consequence is in confidence — in the institution, the market, the regulator, the currency, the system itself. Confidence is slow to rebuild and easy to lose. SFMA succeeds, in many of its forms, simply by making confidence harder to sustain.

Detection challenges

Why traditional tools were not built for this.

Each financial-defence discipline that SFMA borders was built for a different problem. Each is good at its own problem and structurally weak at SFMA's.

01

Cross-actor by nature, not single-counterparty

AML and fraud systems are built around a single regulated institution's view of its own customers and transactions. SFMA signals are diffuse across multiple institutions, instruments and venues. No one institution sees the whole pattern; the pattern only exists when those views are correlated.

02

Patterns hide in normal ranges

Each individual transaction inside an SFMA pattern is typically inside the normal distribution. The thing that is anomalous is the coordination — many actors moving in the same direction at the same time. Per-event scoring will rarely flag any of them.

03

Preparation is invisible to event-based systems

The most useful early signal — the preparatory phase of an attack — is by definition not yet the attack. Event-based detection misses preparation because nothing has happened in the strict event sense; the signal is in the shape of the activity, not in any single event being abnormal.

04

Geopolitical sensitivity

SFMA findings touch geopolitics, attribution, and sometimes the integrity of named state actors. Tools that confidently "name the attacker" or attribute findings to specific governments are a liability — both because they overstate what financial data can prove, and because they put the using institution in the wrong public position.

05

Statutory and procedural maturity

AML, fraud, market abuse and DORA all have decades of statutes, supervisory expectations and case law behind them. SFMA does not yet have a comparable scaffolding. Defending against it therefore requires both the technical tooling and an explicit position on what the institution will and will not do with what it sees.

06

Organisational ambiguity

In most jurisdictions, no single body has SFMA as an explicit mandate. Pieces of the picture sit with the central bank's financial-stability function, the financial supervisor, the treasury, sometimes a national security service. The detection problem is therefore also a coordination problem.

A category we coined

Why this term exists.

The phenomenon is not new. The term is. The reason is practical, not proprietary.

What we do claim

  • That the activity SFMA describes is real, increasingly observable in the data, and increasingly relevant to public-sector institutions.
  • That naming the category — distinct from AML, fraud and market abuse — makes it possible to talk about it operationally, build dedicated tools for it (Marengo), and write it into engagement scopes.
  • That the canonical definition above is the one we use internally, the one we contract under, and the one we think — to our knowledge — is not currently served by a dedicated commercial platform on the market.

What we do not claim

  • That we invented the underlying phenomenon. Coordinated attacks on financial systems pre-date the company by a long way; we have only framed them.
  • That the term will, or should, become regulatory taxonomy. SFMA is a working term; if it gains adoption, it will be on its merits.
  • That every coordinated financial event is SFMA. The category is bounded by intent (manipulation or destabilisation) and target (system-level), and most coordinated activity falls outside it.
How Silbad addresses SFMA

The product is called Marengo.

Marengo is Silbad's real-time, advisory-grade defence platform against SFMA. It is offered exclusively to public-sector and EU institutional users — central banks, treasury and finance ministries' economic-security functions, and EU-level supervisors such as the ECB SSM, ESRB and EBA — on a pilot-led, ethically reviewed basis. Marengo recognises both the manipulation event and the preparatory activity that precedes it; the operational interpretation and any public communication remain, by design, with the institution.

Open the Marengo product page →