Insider Spotlight
A mule account network is a coordinated system of bank or financial accounts used by cybercriminals to receive, split and rapidly move illegally obtained money across multiple institutions. By layering funds through numerous accounts, these networks make stolen money increasingly difficult for financial institutions and authorities to trace.
A total of P24.74 trillion flowed through PESONet and InstaPay in 2025, with about P1.088 trillion in transactions identified as being at risk of digital fraud. Authorized push payment scams and account takeovers requiring mule accounts to move stolen funds accounted for 55.4 percent of the amount at risk.
Hyper accelerated digital adoption
Rapid digital payment adoption has expanded the potential attack surface for fraud networks. Digital payments accounted for 52.8 percent of Philippine retail payments in 2023, exceeding the government's 50-percent digitization target three years early.
Official cybercrime reporting remains below 2 percent even as data indicates 34 percent of Filipinos suffered financial scam losses. An estimated 60 percent to 70 percent of mule accounts involve voluntary participation, with verified bank and e-wallet accounts bought for P500 to P5,000.
The regulatory shift
The Anti-Financial Account Scamming Act (AFASA) and BSP Circular No. 1213 are increasing pressure on financial institutions, including potential reimbursement liability when required real-time fraud management systems are not deployed.
The circular also restricts SMS and email one-time passwords to initial account setup rather than high-risk transactions such as fund transfers, payee additions and credential changes.
Financial liability
"Clinging to interceptable OTPs is no longer just legacy technology; under AFASA, it is a direct financial liability for institutions," IDfy Philippines country head Raghuraman Chandrashekhar said in a press statement.
"No single institution can close this gap alone. What works is layering device intelligence, real-time AI transaction monitoring, and biometric verification into a unified defense stack," Chandrashekhar said.
Integrated defense
A more integrated defense would combine server-side biometrics, cryptographic device binding, AI-driven behavioral risk scoring and Fraud Intelligence Data Sharing rather than relying on isolated safeguards. —Vanessa Hidalgo | Ed: Corrie S. Narisma