The payment pattern now drawing attention in Europe is not defined by one company or one rail. It begins when a gambling operator reaches customers in a market where it may not be authorised, continues through a cashier that accepts deposits, and relies on payment accounts or wallets that can obscure which brand, entity and jurisdiction generated the money.
Fortris is not named in the European cases. Yet the pattern looks familiar because Fortris markets the infrastructure needed to manage it in crypto: an embeddable cashier, incoming customer payments, player and affiliate payouts, wallets dedicated to brands or regions, real-time settlement and transaction-level compliance tools.
That resemblance demands a controls test. Payments Watch Source has previously reported a source accusation that Fortris processes payment flows for offshore betting companies serving U.S. customers outside licensed state markets. The accusation is not a regulatory or judicial finding. But it puts Fortris’s implementation of merchant identification, jurisdiction controls and ongoing monitoring squarely within the payment pattern regulators and licensed-industry groups are targeting.
Start with the underlying operator, not the account name
Investigate Europe reported that leaked records appeared to show payment firms moving money between companies associated with blacklisted casino websites and entities connected to Soft2bet or its partners. It said two Cypriot companies, Tranello and Tilaros, used My EU Pay accounts to send €543 million between 2020 and 2024 to other accounts linked to Soft2bet or partners. The report said account-opening documents described Tranello as belonging to the Soft2bet group and identified deposits from casino brands that had been blacklisted by European authorities.
Soft2bet denied wrongdoing and said the investigation misinterpreted its business and corporate structure. Investigate Europe said it had no evidence that the payment firms knew their products had been used in relation to blacklisted websites. Those qualifications matter. So does the control lesson: knowing the account holder is not necessarily the same as knowing every gambling brand, domain and market behind its receipts.
Fortris promotes dedicated wallets for each “sub-brand, region or game title.” That feature creates an obvious compliance question. Does the platform merely let the customer name a wallet, or does Fortris verify the legal entity, websites, licenses and permitted territories associated with each label? A regional wallet is useful evidence only if the region in the system matches the location of the players funding it.
Follow the deposit through the cashier
EGBA’s July complaint against Walletto focuses on the transaction at the consumer edge. The association said test deposits on websites and apps it considered illegal produced evidence suggesting that Walletto’s services were used. EGBA asked the Bank of Lithuania to act and called for closer coordination among financial regulators, gambling regulators, payment service providers, acquirers and card schemes.
The complaint has not been adjudicated. EGBA represents licensed gambling operators and has a commercial as well as consumer-protection interest in cutting off unlicensed competitors. Even so, its test-transaction method identifies the control point that matters: the payment journey a real user encounters, not only the merchant description supplied at onboarding.
Fortris Cashier can be embedded and branded, while customers may connect their own cashier through the Fortris API. Fortris also says crypto deposits can land directly in enterprise wallets. This architecture can give a provider transaction data at the point where the customer funds a gaming account. It can also split responsibility among Fortris, the operator’s front end, outside wallet or conversion partners and any provider handling identity or location checks.
The decisive questions are practical. What merchant and domain identifiers accompany the deposit? Is the player’s location available to Fortris or kept solely by the operator? Does the API reject deposits when location or license data is absent? Can one approved cashier credential be reused across undeclared brands? Does the platform detect deposits from markets outside the customer’s approved profile?
Map payouts as carefully as deposits
Illegal-gambling enforcement often focuses on money entering a casino, but the operating model also depends on withdrawals and affiliate payments. Fortris advertises payouts to players, affiliates and suppliers, including bulk approvals and scheduled execution. Investigate Europe’s reporting describes onward transfers among payment accounts and entities connected to the wider Soft2bet-related network.
The two structures are not evidence of a connection. They do reveal the same monitoring problem. A provider must understand whether an outgoing transfer is a customer withdrawal, marketing payment, inter-company settlement or movement to another payment provider. Bulk capability increases efficiency, but it can also move large numbers of transactions before a weak review process catches the underlying merchant risk.
Fortris says it provides audit trails, approvals and live transaction histories. Those controls answer who approved a payout. They do not by themselves answer whether the operator was entitled to earn and distribute the underlying gambling revenue. The latter requires license data, brand attribution, customer geography and escalation rules linked to external warnings and blacklists.
Irreversibility raises the pre-transaction standard
Fortris markets “no risk of chargebacks” to gaming companies. That is a merchant benefit, not a consumer safeguard. In card payments, chargebacks are imperfect and can be abused, but they provide a route to challenge some transactions. A crypto payment settled directly into an enterprise wallet can be difficult to reverse once approved.
The absence of chargebacks therefore shifts more responsibility to controls before settlement. Screening a blockchain address for sanctions or known illicit exposure is not enough. A clean wallet can still be used by a gambling operator serving customers where it lacks permission. Know-your-transaction tools must be joined to know-your-merchant and know-your-market controls.
Fortris says its compliance product includes KYT and AML detection, pre-transaction Travel Rule support through integrations, metadata and real-time visibility. Those are relevant tools. The allegation against Fortris tests whether they are configured to detect unauthorised gambling activity rather than only conventional financial-crime indicators.
The pattern regulators should test at Fortris
A serious examination of Fortris would not begin by assuming the source accusation is true. It would select alleged gaming flows and reconstruct them. Regulators or auditors would identify the contracting Fortris customer, beneficial owners, declared brands and domains, gaming licenses, approved markets, wallets, cashier credentials, fiat-conversion partners and payout counterparties. They would then compare that approved profile with actual deposits and withdrawals.
That reconstruction should test five breakpoints:
- Merchant attribution: whether every consumer-facing casino brand maps to the legal entity Fortris approved.
- Jurisdiction: whether player location and license coverage are checked at transaction time, not inferred from a wallet label.
- Credential reuse: whether APIs, cashier configurations or wallets appear across undeclared domains.
- Flow consistency: whether transaction volume, counterparties and payout behaviour match the stated business model.
- Escalation: whether blacklists, complaints or partner alerts trigger suspension and documented review.
None of the reviewed sources says European regulators are performing those tests at Fortris. Nor do the Soft2bet-related reporting and Walletto complaint connect their named companies to Fortris. The point is that the pattern gives authorities and payment partners a concrete test plan for a platform that openly offers the relevant functions and faces a separate allegation about offshore betting flows.
Features are not controls until they stop something
Payments companies routinely describe segregation, approvals, monitoring and auditability as evidence of control. The European cases show why that description is incomplete. An account can be regulated, a transaction can be logged and a payout can be duly approved while the underlying gambling activity remains unauthorised in the customer’s market.
Fortris should be able to show where its system prevents that outcome. If brand wallets improve attribution, the company should disclose how undeclared brands are detected. If the cashier supports compliance, it should explain which jurisdiction and operator-license checks are mandatory. If KYT identifies risk, it should state how merchant legality changes the decision.
The payment pattern under scrutiny is familiar at Fortris because the company has productised its main control points. That is not proof of wrongdoing. It is a reason to demand evidence that the controls do more than make complex gaming payment flows faster, cheaper and easier to audit after the money has moved.