Skip to content

From the FinCrime Agent course

Want to do this for a living?

This is the kind of story financial-crime professionals act on every day. Learn the craft in Marco’s AML & Financial Crime course.

AML & Financial Crime course →
Back to Issue №15

FinCEN links nearly $13bn to pig butchering scam centers in Asia

A new FinCEN alert ties $12.7bn in Bank Secrecy Act filings to overseas romance and investment scams routed through stablecoins.

Act now Fraud Crypto Transaction Monitoring Global

What happened

The US Financial Crimes Enforcement Network (FinCEN) said on September 3, 2026, that it has identified approximately $12.7 billion in financial activity connected to suspected digital asset investment scams. FinCEN’s figure comes from an analysis of 33,904 Bank Secrecy Act (BSA) reports filed between September 8, 2023 and December 31, 2025, published alongside Alert FIN-2026-Alert005 and an accompanying financial trend analysis.

FinCEN describes the scams as “pig butchering,” romance baiting, or cryptocurrency confidence schemes. According to the alert, victims were targeted across all 50 US states and several US territories. FinCEN attributes the operations to transnational criminal organizations based in Southeast Asia running what it calls overseas scam centers.

The alert lays out the method: illicit actors adopt assumed identities to pose as romantic partners, new friends, or business contacts, then direct victims to fake websites and mobile applications built to imitate legitimate investment platforms. FinCEN states that scam operators employ professional money launderers who set up shell companies, recruit money mules, and move victim funds through stablecoin exchanges based outside the United States.

FinCEN is urging financial institutions to report suspicious activity tied to these patterns and to use voluntary information sharing under Section 314(b) of the USA PATRIOT Act. It directs fraud victims to the FBI’s Internet Crime Complaint Center (IC3) or the US Secret Service.

Why it matters

The scale FinCEN is reporting, spanning roughly 28 months of BSA filings, suggests this fraud typology has moved well past isolated incidents and into a volume problem that transaction-monitoring teams are likely already seeing without labeling it correctly. Because the alert describes a layered structure (shell companies, money mules, then offshore stablecoin exchanges) a single control checking any one layer in isolation is unlikely to catch the full pattern.

The reliance on stablecoin exchanges located outside the United States is worth flagging as a structural choice, not an incidental detail. It places a jurisdictional and access gap between the victim’s US-based funds and the point where they exit the traceable banking system, which is consistent with why FinCEN is pushing 314(b) information sharing rather than relying on any single institution’s data alone.

It is also notable that FinCEN frames this as an alert rather than a one-off case reference, meaning the agency expects the pattern to continue and wants institutions actively watching for it, not just recording it after the fact.

Practitioner angle

Financial institutions should treat this alert as a trigger to revisit typology coverage for romance and investment scam patterns, specifically:

  • Review transaction-monitoring rules for customer transfers to virtual asset service providers, with particular attention to accounts that received funds shortly after being opened or that show a sudden shift from low activity to large outbound crypto-linked transfers.
  • Check whether shell company detection logic and beneficial ownership review procedures flag newly formed entities receiving inbound wires from multiple unrelated individual customers, a pattern consistent with money mule layering described in the alert.
  • Confirm SAR narrative templates and staff guidance reference “pig butchering,” romance baiting, and cryptocurrency confidence scheme terminology so filings are searchable and comparable against FinCEN’s own analysis.
  • Assess whether the institution currently participates in Section 314(b) information sharing and, if not, evaluate onboarding given FinCEN’s explicit call for it in this alert.
  • Make sure frontline and fraud teams know to direct victims to IC3 or the US Secret Service rather than only closing accounts.

The single most important action: pull the institution’s own SAR filings from the alert’s covered period and check how many map to this typology, since FinCEN’s 33,904 filing count implies most institutions have already seen fragments of this pattern without connecting them.

Share:

Want to do this for a living?

Turn this weekly intelligence into a career. Marco’s AML & Financial Crime course takes you from curious to hireable.

AML & Financial Crime course →