FinCEN's analysis identifies $12.7 billion in suspicious activity tied to Southeast Asian scam compounds, drawn from 33,904 reports filed by roughly 1,300 U.S. institutions. It does not name the Philippines. But the money-mule and stablecoin-conversion pattern it describes is a regional typology, and BSP-regulated institutions sit inside that region's payment rails.
That distinction matters more than the headline figure. A compliance program that reads this as “a U.S. problem in Cambodia” misses where the exposure actually sits.
What did FinCEN actually find?
On 3 September 2026, FinCEN published an alert and financial trend analysis on digital-asset investment scams, built from 33,904 Bank Secrecy Act reports filed between September 2023 and December 2025 by approximately 1,300 institutions. Total suspicious activity identified: $12.7 billion. Banks filed the larger share, $6.4 billion, against $5.5 billion from crypto-focused money services businesses.
The compounds themselves are concentrated in Cambodia, Laos, and Myanmar, and rely on human trafficking and fraudulent job recruitment to staff them. FinCEN's own language is careful not to localize the problem: the alert states the scam-compound model “is spreading well beyond Southeast Asia.” Victims were reported in all fifty U.S. states.
Source: FinCEN, FIN-2026-Alert005 and accompanying analysis, 3 September 2026. Based on 33,904 BSA reports filed September 2023–December 2025 by approximately 1,300 institutions.
How do the proceeds actually move?
FinCEN's analysis describes the laundering mechanism directly. Professional money launderers, in FinCEN's words, “integrate scam proceeds into the formal financial system through networks of money mules and through stablecoin transfers to digital asset exchanges outside of the United States.” Scammers used 22 different digital assets along the way. Nearly all of it converged on one, USDT, once a scam concluded. Collection addresses were often reused across several victims at once, which points to a repeatable pattern, not a series of one-off incidents.
Two components carry the exposure for any institution outside the compound's host country: the mule network, and the point where crypto value crosses back into fiat rails.
Why does a Southeast Asian scam compound become a Philippine bank's problem?
Because a compound has to move money through institutions it doesn't control before stolen funds become usable. Mule accounts are typically opened close to the compound's regional footprint, not inside it, usually through the same onboarding process any legitimate customer goes through, which is exactly why customer due diligence doesn't end at account opening. FinCEN did not name the Philippines in this analysis, and this piece does not claim it did. What FinCEN described is a regional typology: people recruited or coerced into moving funds through personal or small-business accounts, converting to and from stablecoins, and routing through offshore exchanges. None of that requires the account holder to be anywhere near Cambodia, Laos, or Myanmar.
BSP-supervised institutions are already treating this as a live, measured problem, independent of the FinCEN release. Under the Anti-Financial Account Scamming Act (Republic Act 12010), BSP General Counsel Roberto L. Figueroa told a Senate Committee on Finance hearing on 17 August 2026 that the Philippine National Police's Anti-Cybercrime Group recorded 527 AFASA-related cases in 2025, with 447 resolved. Online scam incidents declined in the first half of 2026. That data predates this FinCEN release and doesn't reference it. It points to the same underlying typology anyway: scam proceeds moving through mule-held accounts inside the regulated financial system.
What does the typology look like inside your own transaction data?
Not as a single large transfer. The pattern FinCEN describes, and the one AFASA's monitoring requirements are built to catch, shows up as many smaller inbound transfers converging on an account from unrelated sources, followed by rapid outbound movement, often to a wallet or exchange instead of another bank account. A single-transaction rule won't catch this. Each individual transfer is unremarkable on its own. Only the aggregate pattern, several counterparties in, one or two counterparties out, inside a tight window, looks like money muling instead of ordinary account activity.
That is an aggregation problem, not a threshold problem. Institutions that run detection at the level of individual transactions, instead of across a customer's transaction history over a defined window, will see the same account clear each transfer one at a time. The pattern behind those transfers goes unnoticed, which is the same reason a static, point-in-time risk view misses an account whose behavior shifts well after onboarding.
What does AFASA require, and what does it not cover?
AFASA requires BSP-supervised institutions handling complex electronic services above a ₱75 million monthly transaction threshold to run automated, real-time fraud management systems, covering transaction velocity checks, geolocation monitoring, blacklist screening, and behavioral anomaly detection. It also mandates multi-factor authentication, a 24-hour transaction pause after key account changes, and the authority to hold disputed funds for up to thirty days while a claim is verified across institutions. Compliant institutions gain a liability shield; institutions that cannot show adequate controls face restitution obligations to account holders regardless of whether a conviction follows.
AFASA is built around fraud committed against a customer, account takeover, phishing, social engineering, not around a customer's own account being used, knowingly or under coercion, to move someone else's proceeds. The two obligations overlap in practice, since both require aggregation-aware, behavior-based monitoring, but a fraud management system tuned only to protect account holders from being scammed will not necessarily flag that same account being used as a conduit once it has been recruited as a mule.
What should a transaction monitoring program specifically catch?
The gap above makes the case for building detection around aggregated behavior, not individual transaction thresholds. A monitoring rule can be built around a variable: the count or sum of inbound transfers from distinct counterparties over a rolling window, checked against a similarly windowed outbound concentration. That catches the fan-in, fan-out signature directly, instead of waiting for a single transfer to cross a fixed amount.
FyscalTech's Transaction Monitoring module lets a compliance team build that kind of variable directly, sum, count, or average of any transaction attribute over any time window they define, without an engineering ticket, and test it against historical data before it goes live.
Where does this map in your AML program?
This is a Transaction Monitoring problem first: cross-account, cross-window aggregation is the control that catches a mule pattern individual-transaction rules miss. It's a Regulatory Reporting problem second, since a confirmed mule pattern is exactly the kind of suspicion that triggers an STR under AMLC's GoTRACS framework, filed the next working day from the point suspicion is established. Both sit inside the same broader financial crime program, alongside the payment fraud controls AFASA already mandates. This isn't a case for new policy on its own. AFASA's monitoring mandate already covers the technical requirement. The gap is in what the monitoring is tuned to look for, and it sits alongside the broader shift in what BSP-supervised fintechs are expected to demonstrate since the FATF grey-list exit: not just a policy on paper, but detection that produces results.

