Insights / Blog / Insights
Insights

FinCEN's $12.7B Scam Finding: What BSP Banks Must Do

FinCEN traced $12.7B in scam proceeds through money mules and stablecoins. What BSP-regulated institutions should watch for in transaction data.

FinCEN's $12.7B Scam Finding: What BSP Banks Must Do

FinCEN's analysis identifies $12.7 billion in suspicious activity tied to Southeast Asian scam compounds, drawn from 33,904 reports filed by roughly 1,300 U.S. institutions. It does not name the Philippines. But the money-mule and stablecoin-conversion pattern it describes is a regional typology, and BSP-regulated institutions sit inside that region's payment rails.

That distinction matters more than the headline figure. A compliance program that reads this as “a U.S. problem in Cambodia” misses where the exposure actually sits.

What did FinCEN actually find?

On 3 September 2026, FinCEN published an alert and financial trend analysis on digital-asset investment scams, built from 33,904 Bank Secrecy Act reports filed between September 2023 and December 2025 by approximately 1,300 institutions. Total suspicious activity identified: $12.7 billion. Banks filed the larger share, $6.4 billion, against $5.5 billion from crypto-focused money services businesses.

The compounds themselves are concentrated in Cambodia, Laos, and Myanmar, and rely on human trafficking and fraudulent job recruitment to staff them. FinCEN's own language is careful not to localize the problem: the alert states the scam-compound model “is spreading well beyond Southeast Asia.” Victims were reported in all fifty U.S. states.

Filer split
Banks filed more of the $12.7B than crypto firms did
Suspicious activity FinCEN linked to Southeast Asian scam-compound proceeds, by filer type
FyscalTech
Banks
50% of total
$6.4B
Crypto MSBs (exchanges, etc.)
43% of total
$5.5B
Total identified
$12.7B

Source: FinCEN, FIN-2026-Alert005 and accompanying analysis, 3 September 2026. Based on 33,904 BSA reports filed September 2023–December 2025 by approximately 1,300 institutions.

How do the proceeds actually move?

FinCEN's analysis describes the laundering mechanism directly. Professional money launderers, in FinCEN's words, “integrate scam proceeds into the formal financial system through networks of money mules and through stablecoin transfers to digital asset exchanges outside of the United States.” Scammers used 22 different digital assets along the way. Nearly all of it converged on one, USDT, once a scam concluded. Collection addresses were often reused across several victims at once, which points to a repeatable pattern, not a series of one-off incidents.

Two components carry the exposure for any institution outside the compound's host country: the mule network, and the point where crypto value crosses back into fiat rails.

Why does a Southeast Asian scam compound become a Philippine bank's problem?

Because a compound has to move money through institutions it doesn't control before stolen funds become usable. Mule accounts are typically opened close to the compound's regional footprint, not inside it, usually through the same onboarding process any legitimate customer goes through, which is exactly why customer due diligence doesn't end at account opening. FinCEN did not name the Philippines in this analysis, and this piece does not claim it did. What FinCEN described is a regional typology: people recruited or coerced into moving funds through personal or small-business accounts, converting to and from stablecoins, and routing through offshore exchanges. None of that requires the account holder to be anywhere near Cambodia, Laos, or Myanmar.

BSP-supervised institutions are already treating this as a live, measured problem, independent of the FinCEN release. Under the Anti-Financial Account Scamming Act (Republic Act 12010), BSP General Counsel Roberto L. Figueroa told a Senate Committee on Finance hearing on 17 August 2026 that the Philippine National Police's Anti-Cybercrime Group recorded 527 AFASA-related cases in 2025, with 447 resolved. Online scam incidents declined in the first half of 2026. That data predates this FinCEN release and doesn't reference it. It points to the same underlying typology anyway: scam proceeds moving through mule-held accounts inside the regulated financial system.

What does the typology look like inside your own transaction data?

Not as a single large transfer. The pattern FinCEN describes, and the one AFASA's monitoring requirements are built to catch, shows up as many smaller inbound transfers converging on an account from unrelated sources, followed by rapid outbound movement, often to a wallet or exchange instead of another bank account. A single-transaction rule won't catch this. Each individual transfer is unremarkable on its own. Only the aggregate pattern, several counterparties in, one or two counterparties out, inside a tight window, looks like money muling instead of ordinary account activity.

That is an aggregation problem, not a threshold problem. Institutions that run detection at the level of individual transactions, instead of across a customer's transaction history over a defined window, will see the same account clear each transfer one at a time. The pattern behind those transfers goes unnoticed, which is the same reason a static, point-in-time risk view misses an account whose behavior shifts well after onboarding.

What does AFASA require, and what does it not cover?

AFASA requires BSP-supervised institutions handling complex electronic services above a ₱75 million monthly transaction threshold to run automated, real-time fraud management systems, covering transaction velocity checks, geolocation monitoring, blacklist screening, and behavioral anomaly detection. It also mandates multi-factor authentication, a 24-hour transaction pause after key account changes, and the authority to hold disputed funds for up to thirty days while a claim is verified across institutions. Compliant institutions gain a liability shield; institutions that cannot show adequate controls face restitution obligations to account holders regardless of whether a conviction follows.

AFASA is built around fraud committed against a customer, account takeover, phishing, social engineering, not around a customer's own account being used, knowingly or under coercion, to move someone else's proceeds. The two obligations overlap in practice, since both require aggregation-aware, behavior-based monitoring, but a fraud management system tuned only to protect account holders from being scammed will not necessarily flag that same account being used as a conduit once it has been recruited as a mule.

What should a transaction monitoring program specifically catch?

The gap above makes the case for building detection around aggregated behavior, not individual transaction thresholds. A monitoring rule can be built around a variable: the count or sum of inbound transfers from distinct counterparties over a rolling window, checked against a similarly windowed outbound concentration. That catches the fan-in, fan-out signature directly, instead of waiting for a single transfer to cross a fixed amount.

“

FyscalTech's Transaction Monitoring module lets a compliance team build that kind of variable directly, sum, count, or average of any transaction attribute over any time window they define, without an engineering ticket, and test it against historical data before it goes live.

Fyscal ARCX, Transaction Monitoring

Where does this map in your AML program?

This is a Transaction Monitoring problem first: cross-account, cross-window aggregation is the control that catches a mule pattern individual-transaction rules miss. It's a Regulatory Reporting problem second, since a confirmed mule pattern is exactly the kind of suspicion that triggers an STR under AMLC's GoTRACS framework, filed the next working day from the point suspicion is established. Both sit inside the same broader financial crime program, alongside the payment fraud controls AFASA already mandates. This isn't a case for new policy on its own. AFASA's monitoring mandate already covers the technical requirement. The gap is in what the monitoring is tuned to look for, and it sits alongside the broader shift in what BSP-supervised fintechs are expected to demonstrate since the FATF grey-list exit: not just a policy on paper, but detection that produces results.

Aggregation catches what single transfers hide
See how Fyscal ARCX builds fan-in, fan-out variables without an engineering ticket
Book a demo

Frequently asked questions

No. FinCEN's analysis names Cambodia, Laos, and Myanmar as the compounds' locations and states the model is spreading beyond Southeast Asia, without naming the Philippines specifically. The connection to BSP-regulated institutions is this piece's own analysis of the typology FinCEN described, money mules and stablecoin conversion, set alongside the Philippines' own, separately reported AFASA enforcement data.
$12.7 billion in suspicious financial activity tied to Southeast Asian scam compounds, drawn from 33,904 Bank Secrecy Act reports filed by about 1,300 institutions between September 2023 and December 2025. Banks filed $6.4 billion of that total; crypto-focused money services businesses filed $5.5 billion.
Someone who moves funds through their own personal or small-business account on behalf of a criminal network, often after being recruited through a fake job offer or coerced once involved. Scam-compound operators depend on mule networks to move stolen funds into the formal financial system before converting them to stablecoins.
Real-time fraud management systems with velocity checks, geolocation monitoring, and behavioral anomaly detection for institutions above a ₱75 million monthly transaction threshold, plus multi-factor authentication, a 24-hour hold after key account changes, and authority to hold disputed funds for up to 30 days. Institutions that meet these requirements gain a liability shield; those that don't face restitution obligations.
Not fully. AFASA is built primarily around protecting an account holder from fraud committed against them, the payment fraud scenario the law names directly. A mule account is different: it's the customer's own account being used to move someone else's proceeds, which needs monitoring tuned to aggregated inbound and outbound patterns, not only to fraud committed against the account holder.
Because each individual transfer in a mule pattern is typically small and unremarkable on its own. The signal sits in the aggregate: multiple inbound transfers from unrelated counterparties converging on one account, followed by rapid outbound concentration. That only becomes visible when monitoring evaluates a transaction history over a time window, instead of one transaction at a time.
Stay in the loop

Insights on modern finance, monthly.

No noise — just the engineering and strategy behind banking that scales.

Keep reading

Related articles