Fresh Filipino Living

PH economy could lose PHP 603B annually as digital fraud threat grows

Whitepaper urges stronger, layered defenses as mule accounts, deepfakes, and digital scams expand across the financial system

The Philippine economy could be exposed to approximately PHP 603 billion in annual losses from digital fraud as illicit mule account networks continue to facilitate the movement of stolen funds, according to a joint whitepaper from IDfy Philippines and CIBI Information, Inc.

The report, “Mule Hunting: Are We Chasing Ghosts?,” examined transaction data from the Bangko Sentral ng Pilipinas (BSP), which recorded PHP 24.74 trillion in combined transaction flows through PESONet and InstaPay in 2025.

Of this amount, the whitepaper estimates that PHP 1.088 trillion in transactions was vulnerable to digital fraud. Around 55.4% of these transactions were directly associated with authorized push payment (APP) scams and account takeovers (ATO), both of which rely on mule accounts to move stolen money.

The growing exposure comes amid the Philippines’ rapid transition toward digital payments. The country reached 52.8% digitalization of retail payments in 2023, surpassing its target of 50% three years ahead of schedule.

But while digital adoption has accelerated, the report said transnational criminal networks have also found opportunities to exploit the expanding digital financial ecosystem.

Official reporting remains a significant challenge. Cybercrime reports account for less than 2%, even as Cybercrime Investigation and Coordinating Center (CICC) data shows that 34% of Filipinos have suffered financial scam losses.

Many victims do not formally report incidents because individual losses can be relatively small and the legal process can be complex. As a result, mule accounts can remain operational and appear legitimate for months.

The whitepaper estimates that 60% to 70% of mule accounts involve voluntary participants. This is linked to a growing “mule-for-hire” market, where verified bank and e-wallet accounts are reportedly purchased in bulk for PHP 500 to PHP 5,000, according to NBI data.

The remaining 30% to 40% are believed to be coerced into participating through schemes including romance-investment fraud and fake remote employment offers.

Meanwhile, regulatory requirements are placing greater pressure on financial institutions. Under the Anti-Financial Account Scamming Act (AFASA) and BSP Circular 1213, responsibility for fraud losses is fundamentally shifting from consumers toward financial institutions.

Institutions that fail to implement real-time fraud management systems face full, unlimited reimbursement liability for customer losses.

BSP Circular 1213 also restricts the use of SMS and Email OTPs to initial account setups and prohibits their use for high-risk activities, including fund transfers, payee additions, and credential changes.

The report recommends a layered approach that combines server-side biometrics, cryptographic device binding, and real-time AI behavioral risk scoring to strengthen digital identity and transaction security.

“Clinging to interceptable OTPs is no longer just legacy technology; under AFASA, it is a direct financial liability for institutions,” said Raghuraman Chandrashekhar, Country Head of IDfy Philippines. “No single institution can close this gap alone. What works is layering device intelligence, real-time AI transaction monitoring, and biometric verification into a unified defense stack.”

The report further calls for Fraud Intelligence Data Sharing (FIDS), AI-powered transaction monitoring, and server-side facial authentication to work together rather than operate as isolated security measures.

The whitepaper argues that these technologies, supported by the AFASA regulatory framework, can create an end-to-end defense mechanism designed to make it more difficult for mule networks to operate across the financial system.

For the full version of the report, visit idfy.ph/mule-hunting-whitepaper-landing.