Feature Compliance Strategy
FinCEN's Scam Center Alert: What BSA Officers Need to Do with FIN-2026-Alert005
FinCEN's September 3, 2026 alert identified nearly $13 billion in suspected illicit activity tied to overseas scam centers running pig butchering, romance baiting, and cryptocurrency confidence schemes. Here's what the red flags are, who needs to file SARs, and how to update your transaction monitoring program.
Table of Contents
TL;DR
- FinCEN’s September 3, 2026 alert (FIN-2026-Alert005) identified nearly $13 billion in suspected illicit activity tied to overseas scam centers running pig butchering, romance baiting, and cryptocurrency fraud targeting US consumers.
- The alert analyzed 33,904 BSA reports from 2023–2025 and covers every US state.
- Key red flags: “no KYC” crypto exchanges, stablecoin flows to flagged addresses, recovery services, government impersonation, and unusual investment platforms introduced via social media or dating apps.
- Action items: Update SAR narrative templates to include “FIN-2026-Alert005,” brief frontline staff, and review transaction monitoring typologies. Inaction after a FinCEN alert is an examination finding.
On September 3, 2026, FinCEN issued FIN-2026-Alert005, its most comprehensive warning yet on overseas scam centers. The numbers are stark: 33,904 BSA reports analyzed, nearly $13 billion in suspected illicit activity identified, and victims in every US state.
If you’re a BSA officer and this is the first you’re hearing about it, you have a gap. FinCEN alerts don’t create new legal obligations — but they do establish that your institution was on notice. Failing to update your program after an alert is the kind of thing that gets cited in examination findings.
Here’s what the alert covers, what it asks you to do, and how to translate it into concrete updates to your SAR program and transaction monitoring typologies.
What Scam Centers Are — and Why They’re a BSA Problem
The term “scam center” refers to criminal operations — concentrated in Southeast Asia, particularly Myanmar, Cambodia, Laos, and the Philippines — that combine two elements: trafficked labor and industrialized fraud. Workers, often recruited through false job advertisements and held against their will, are forced to run online fraud schemes targeting victims in the United States, Europe, and elsewhere.
FinCEN’s alert focuses on four primary scheme types:
Pig butchering (investment fraud). A fraudster builds a relationship with a victim — often through dating apps, social media, or chance contact — and gradually introduces a cryptocurrency investment opportunity. The platform appears legitimate and shows paper profits. Victims invest increasing amounts. When they try to withdraw, they’re told to pay fees or taxes. The platform disappears. The name comes from the Chinese idiom for fattening a pig before slaughter.
Romance baiting. Similar to pig butchering in its relationship-building phase, but the financial extraction may come through direct requests for money, gift cards, or wire transfers rather than a structured investment platform.
Cryptocurrency confidence schemes. Fraudsters pose as cryptocurrency experts, exchange representatives, or recovery services. Victims are persuaded to move funds to wallets or platforms controlled by the scam center. Recovery service fraud — targeting victims of prior crypto losses with promises to retrieve funds — is explicitly called out in the alert.
Government impersonation and commodity payment schemes. Fraudsters impersonate IRS agents, Social Security Administration officials, law enforcement, or utilities. Victims are told they face arrest, account seizure, or utility shutoff unless they pay immediately via cryptocurrency, wire, gift cards, or precious metals. The precious metals angle — where victims purchase gold or silver and hand it to an “agent” — has surged in elder fraud.
All four scheme types funnel money through the US financial system. That’s why this is a BSA problem, not just a consumer protection one. Banks process the wires. MSBs process the crypto and gift card payments. Credit unions see the account activity. Every link in the chain has a reporting obligation.
The Scale: What 33,904 Filings Tell Us
FinCEN’s analytical base for this alert — 33,904 BSA reports filed between September 2023 and December 2025 — is significantly larger than the data underlying the 2023 alert. The agency analyzed SARs, CTRs, and international fund transfer reports to map the flow of funds, identify common platforms and addresses, and isolate the behavioral patterns that distinguish scam center activity from ordinary investment losses.
The nearly $13 billion figure in suspected illicit activity represents the aggregate of reported transactions that matched scam center patterns — not confirmed losses, but flagged flows that BSA filers considered suspicious enough to report. Given known underreporting in fraud (many victims are embarrassed, confused, or unaware their funds have been stolen), the actual figure is likely higher.
Geographic reach across every US state means no institution can treat this as a regional or demographic outlier. Victims skew older — elder fraud is a documented component — but the investment fraud typologies target younger demographics who are active on dating apps and social media.
The Red Flags FinCEN Identified
The alert enumerates specific red flags that BSA compliance programs should incorporate into their monitoring typologies. Organized by channel:
Cryptocurrency and Virtual Asset Red Flags
- Customer moves funds to unhosted wallets or exchanges that don’t require identity verification (“no KYC” platforms)
- Customer transfers funds to blockchain addresses previously associated with fraud or included on OFAC or law enforcement lists
- Unusual stablecoin flows — particularly USDT or USDC — to offshore wallets or exchanges with minimal regulatory oversight
- Customer mentions a cryptocurrency platform or investment opportunity introduced through a romantic or social media contact
- Customer sends funds to a “recovery service” claiming to retrieve previously lost cryptocurrency, but the service cannot provide documentation, licensing, or verifiable contact information
- Multiple customers sending funds to the same blockchain address or exchange account
Wire and ACH Red Flags
- Customer initiates wires to overseas accounts in amounts inconsistent with stated employment or account history
- Wire destination country is Southeast Asian (Myanmar, Cambodia, Laos, Philippines) with no established business relationship
- Customer expresses urgency, mentions pressure from an online contact, or becomes distressed when staff ask about the recipient
- Customer requests wire reversal shortly after a transfer and appears confused about where the funds went
Cash, Gift Card, and Commodity Red Flags
- Customer purchases gift cards — particularly Google Play, iTunes, or Amazon — in large amounts or multiple transactions
- Customer purchases precious metals for cash delivery to an unknown third party or “agent”
- Elderly customer appears accompanied by a stranger who directs the transaction
- Customer mentions owing a debt to the IRS, Social Security Administration, or law enforcement that must be paid immediately in gift cards, crypto, or cash
Account Behavior Red Flags
- Account shows sudden inflows followed by immediate transfer out — a pattern inconsistent with the customer’s profile
- Customer opens new account and immediately receives wire from an overseas sender, followed by outbound transfers
- Account activity inconsistent with stated income, particularly for retirees or fixed-income customers who begin moving significant funds
What the Alert Asks You to Do
FinCEN’s ask is specific:
File SARs using the alert keyword. When filing a SAR on activity connected to scam center operations, include “FIN-2026-Alert005” in the SAR narrative. FinCEN uses these keywords to aggregate filings and identify patterns — the keyword is how your filing contributes to the broader law enforcement picture.
Apply enhanced due diligence to flagged activity. For customers whose transactions trigger scam center red flags, conduct additional customer outreach before processing — particularly for elderly or first-time international wire senders. The alert notes that some victims are unaware their funds are being stolen.
Review transaction monitoring typologies. Your AML system’s existing rules may not be calibrated to catch stablecoin flows to no-KYC exchanges or gift card purchases that pattern-match to elder fraud. FIN-2026-Alert005 is a basis to request a rule review from your compliance vendor or internal analytics team.
Coordinate with law enforcement where appropriate. For active schemes — particularly where a customer is about to send additional funds — BSA regulations permit proactive coordination with law enforcement without triggering tipping-off concerns.
The Examination Exposure
Here’s the compliance calculus that matters: FinCEN issues alerts as public notice. Once an alert is issued, your institution is on record as having been informed. An examiner reviewing your BSA program after September 3, 2026 can ask: “What did you do in response to FIN-2026-Alert005?”
The answer your program needs to be able to give:
- We received and reviewed the alert
- We updated our SAR narrative templates to include the alert keyword
- We reviewed and updated transaction monitoring rules to incorporate the red flags
- We briefed frontline staff on the customer-facing warning signs
- We identified any existing cases that may qualify for retroactive SAR amendments
The Issues Management Tracker is the right tool for managing this response — log the alert as an open issue, document each remediation step with completion dates and responsible owners, and close it out when your program review is complete. That log is your examination-ready evidence that you acted on notice.
An institution that received the alert, did nothing, and then got cited in the next examination cycle for inadequate scam center monitoring has the worst possible outcome: a known typology, a documented alert, and a paper trail showing inaction.
Updating Your Program: The Practical Checklist
SAR narrative template. Add “FIN-2026-Alert005” as a required keyword in your template for cryptocurrency fraud, investment fraud, elder fraud, and romance scam typologies. Brief your SAR writing team on where and how to include it.
Transaction monitoring rules. Work with your monitoring system’s configuration team to review rules for:
- Large or unusual stablecoin transactions
- Rapid outbound wire following unusual inflows
- Gift card purchases above defined thresholds
- Multiple customers using the same destination address or account
Blockchain address screening. If your institution handles cryptocurrency — directly or through correspondent relationships — add scam center-associated blockchain addresses to your screening lists. FinCEN’s alert references coordination with the FBI and Secret Service; those agencies maintain and share flagged address lists through law enforcement channels.
Frontline staff briefing. Branch staff, customer service representatives, and relationship managers are the first line of detection for elder fraud and urgency-driven payment schemes. Brief them on the customer-facing warning signs: a caller who says they owe money to the government, a customer buying gift cards in unusual amounts, an elderly customer who seems coached or accompanied by an unfamiliar person.
Prior SAR review. Check whether any existing SARs filed since September 2023 match scam center typologies but didn’t include the 2023 or 2026 alert keywords. Consider whether amendments are warranted to improve FinCEN’s aggregate picture.
The Broader Context: This Is a Three-Year Pattern
FinCEN’s 2023 pig butchering alert established the baseline reporting expectations, and the DOJ’s scam center strike force shows the criminal enforcement picture running alongside FinCEN’s BSA framework. FIN-2026-Alert005 isn’t a new obligation — it’s a reminder that the obligation exists, backed by three additional years of data showing the scheme has not slowed down.
The $13 billion figure in the 2026 alert reflects a fraud typology that has scaled. Southeast Asian scam centers have industrialized. The labor trafficking infrastructure is documented. The cryptocurrency rails are established. The schemes are reaching every demographic in every state.
Your BSA program’s job is to make the US financial system less hospitable to these flows. That means filing the SARs, updating the monitoring rules, and briefing the staff. Not because FinCEN told you to — because that’s what the program is for.
Sources:
- FinCEN Alert FIN-2026-Alert005: Schemes Conducted by Overseas Scam Centers — FinCEN
- FinCEN Alert FIN-2023-Alert005: Pig Butchering Schemes (September 2023) — FinCEN
- FBI IC3 2025 Internet Crime Report — FBI
- FinCEN Issues Alert on Scam Center Financial Activity — ABA Banking Journal
- FinCEN Alert Warns of Overseas Scam Centers — Ballard Spahr
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is FinCEN FIN-2026-Alert005?
Who needs to file SARs in response to this alert?
What are the main red flags FinCEN identified in this alert?
How does this alert differ from FinCEN's 2023 pig butchering alert?
What should our SAR narrative say when filing under this alert?
Do we need to update our transaction monitoring rules after this alert?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Compliance Strategy
DORA Is in Active Enforcement and 44% of Financial Institutions Still Have Gaps. Here's What Supervisors Are Finding — and What Your Program Needs to Fix Before They Get to You.
The Digital Operational Resilience Act entered active enforcement in January 2026. Fourteen months in, supervisory reviews are surfacing the same structural gaps at institution after institution: incomplete Registers of Information, empty exit strategy fields, and concentration risk documentation that looks complete but doesn't hold up. Here's what EU-exposed fintechs need to fix before the first wave of formal enforcement actions land in H2 2026.
Sep 9, 2026
Compliance Strategy
H.R. 10184 Would Cut the Maximum CFPB Penalty to $50,120 Per Day and Move Supervision to $30 Billion. What the CFPB Reform Act Means for Your Compliance Program.
The Consumer Financial Protection Accountability and Reform Act of 2026, introduced August 31, proposes to raise the CFPB supervision threshold to $30B, slash maximum daily penalties, narrow the UDAAP 'abusive' standard, and subject the bureau to congressional appropriations. Here's what it means for your compliance program — and what to watch regardless of whether it passes.
Sep 5, 2026
Compliance Strategy
FinCEN Just Permanently Ended BOI Reporting for US Companies. Here's What Your Compliance Program Needs to Update Before Q4.
FinCEN's August 14, 2026 final rule permanently exempts all domestic US entities from Corporate Transparency Act beneficial ownership reporting. Here's what compliance programs need to change — and what the exemption doesn't touch.
Sep 2, 2026