> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023
- URL: https://f4n6.co.uk/security-feed/treasury-urges-banks-to-file-cyber-scam-reports-noting-nearly-13-billion-in-losses-since-2023/
- Published: 2026-09-11T21:10:03.000Z
- Updated: 2026-09-11T21:10:03.000Z
- Author: Jeff Davies
- Tags: #security-feed

## 1\. Executive summary

FinCEN has issued an alert to the U.S. financial industry alongside a study of more than 33,000 cyber fraud incident reports filed between September 2023 and December 2025, urging banks to improve detection and reporting of scams run by transnational criminal organisations operating from overseas scam centres. The study, based on filings from roughly 1,300 financial institutions, attributes approximately $12.7 billion in losses to cryptocurrency investment scams ("pig butchering"-type schemes) affecting victims across all 50 U.S. states and territories. Scam activity is expanding beyond established centres in Myanmar, Cambodia and Laos, with FinCEN receiving nearly 11% more reports each month compared to the prior month. For EMEA financial services clients, the operational takeaway is not a vulnerability to patch but a fraud-detection and reporting gap: the scam lifecycle is only partially visible to any single institution, and the report documents concrete transactional behaviours — retirement-fund liquidations, loan applications tied to crypto purchases, wires to digital-asset institutions — that should drive enhanced monitoring rules. No CVEs, exploited products, or named malware are involved in this item.

## 2\. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. This is a U.S. Treasury/FinCEN alert and fraud-trend study; it creates no new reporting obligation for EMEA entities under the referenced DORA or NIS2 provisions, and the trigger facts (fraud typologies, victim behaviour) do not map to a distinctive obligation under the articles in scope. Clients with U.S. operations should note the alert may engage FinCEN's own reporting expectations, but that is outside the regulatory reference for this advisory.

## 3\. Technical analysis & attack chain

This is a strategic/trend item, not a technical intrusion; there is no CVE, exploit, or malware payload to analyse. The following describes how the fraud worked, per the FinCEN study as reported by The Record.

### How the scheme operated

1. **Approach and grooming.** Scammers contacted victims via social media, adopting personas ranging from romantic partner to trusted financial adviser. Victims were coached over time into "investing" in apparently fictitious digital-asset-related companies.
2. **Fund mobilisation.** Victims moved money through both traditional rails and cryptocurrency. Banks reported detecting schemes at two points: when a victim sent funds to a financial institution in the digital-asset sector to purchase digital assets, or when a customer sent a wire transfer to a scam-affiliated beneficiary, frequently referencing digital asset investments.
3. **Victim-side financing behaviour.** A significant number of victims liquidated investment accounts, submitted loan and second-mortgage applications, took out personal loans, and opened lines of credit on their homes to fund transfers. One documented case: an older adult transferred nearly $640,000 from her retirement fund to a suspected scammer after meeting an individual over social media who instructed her to invest in a fictitious digital-asset company. Another victim withdrew almost $150,000 from a retirement account, took a personal loan and home equity lines of credit, and was denied personal loans twice before succeeding.
4. **Cash-out via stablecoin.** Most filings reported use of Ethereum, Tether (USDT), and USD Coin (USDC), with at least 18 other coins appearing. FinCEN noted scammers almost always exchanged stolen funds for USDT — the stablecoin is the dominant cash-out vehicle.
5. **Secondary victimisation.** Most victims only realised they were being scammed when asked to pay a fee to recover their money. Investigators documented several cases where scammers posed as an "asset recovery service" to steal from victims a second time.
6. **Laundering infrastructure.** Days after the report's release, the U.S. government took action against Xinbi Guarantee, described as a key Telegram-based illicit marketplace that helped scammers launder billions.

**Scale and trend data:** \~$12.7 billion stolen in crypto investment scams; \~$5.5 billion in suspected scam activity identified by cryptocurrency firms; \~$6.4 billion in potential fraud reported by traditional banks. Reports came from \~1,300 financial institutions. Adults over 60 accounted for about 25% of reports — not overrepresented — indicating similar victimisation rates across age demographics. Report volume grew nearly 11% month-over-month. The schemes are expanding beyond centres in Myanmar, Cambodia and Laos.

**Confidence caveat:** All figures and case details above are single-sourced, resting on The Record's reporting of the FinCEN study. The article text is truncated mid-quote (Ari Redbord, global he…), so any additional findings or commentary from the full report are not reflected here. Attribution to "transnational criminal organisations" is generic and unconfirmed at actor level; no specific named group with a verifiable profile is identified in the available material.

## 4\. Mitigation & containment

There is no technical containment for this item. Actions are process and monitoring controls for fraud, payments, and financial-crime teams:

### P1 — within 24h

- Brief fraud/AML and customer-facing teams on the two detection points banks found most productive: (a) customer funds sent to digital-asset-sector institutions for crypto purchase, and (b) wire transfers to beneficiaries referencing digital asset investments. Review whether current transaction-monitoring scenarios flag these patterns.
- Flag the "asset recovery service" secondary-scam pattern to customer-facing staff: victims who report a prior scam loss are targets for a second fraud attempt, and requests to pay a "recovery fee" are themselves an indicator.

### P2 — within 72h

- Review monitoring rules for the victim-side financing behaviours documented in the report: retirement-fund liquidations followed by crypto purchases, loan or second-mortgage applications where stated purpose involves digital-asset investment, and repeated personal-loan applications by customers with no prior borrowing need. These are pre-transaction intervention opportunities.
- Assess coverage of stablecoin cash-out flows: given that scammers almost always exchange funds for USDT, on-chain monitoring or third-party blockchain-analytics coverage for USDT transfer patterns to scam-affiliated addresses is the highest-value detection investment.

### P3 — within 7 days

- Review callback and out-of-band verification procedures for large transfers to digital-asset institutions, particularly where the customer's stated purpose references an investment opportunity introduced via social media contact.
- For institutions with U.S. operations, review the FinCEN alert and assess whether current suspicious-activity reporting captures the scam lifecycle phases visible to you; the report notes institutions typically see only one phase, so filing quality directly affects law-enforcement visibility.
- Consider retrospective review of the last 12 months of wires and crypto on-ramp transfers against the patterns above to quantify exposure.

## 5\. Indicators of compromise

No indicators of compromise available in the source material.

### Behavioural indicators

| Behaviour                                                                                                                                   | Where to observe                                 | Confidence                                            |
| ------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------ | ----------------------------------------------------- |
| Customer sends funds to a digital-asset-sector financial institution to purchase digital assets, in a pattern consistent with scam coaching | Transaction monitoring, payments                 | High — per FinCEN study as reported                   |
| Wire transfer to scam-affiliated beneficiary referencing digital asset investments                                                          | Wire processing, transaction monitoring          | High — per FinCEN study as reported                   |
| Retirement-fund liquidation followed by crypto purchase or transfer to suspected scammer                                                    | Pension/custody records correlated with payments | High — documented case (\~$640,000)                   |
| Loan, second-mortgage, or home-equity credit applications where funds are destined for digital-asset investment                             | Loan origination, credit applications            | High — documented case (\~$150,000 plus credit lines) |
| Victim asked to pay a fee to recover prior losses; contact from an "asset recovery service"                                                 | Customer complaints, fraud case records          | Medium — several cases cited                          |
| Stolen funds exchanged for USDT (Tether)                                                                                                    | Blockchain analytics, crypto exchange partners   | High — FinCEN finding                                 |
| Investment opportunity introduced by a social-media contact (romantic partner or financial adviser persona)                                 | Customer interactions, fraud interviews          | High — per report                                     |

## 6\. Detection

Insufficient indicators to author detection rules. The source material describes fraud typologies and transactional behaviours but contains no file artefacts, command-line indicators, network signatures, or other technical observables suitable for YARA or Sigma rules. The behavioural indicators in §5 should be implemented as transaction-monitoring scenarios rather than security detection rules.

## 7\. Sources

- The Record, "Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023," https://therecord.media/treasury-urges-banks-report-cyber-scams, 2026-09-10

## 8\. Adverse Trace position

This is a strategic fraud-trend item, not a technical vulnerability, and we assess it as operationally significant for fraud and financial-crime functions rather than security operations. The $12.7 billion loss figure and the near-11% month-over-month growth in reports indicate an industrialised, expanding scam economy with stablecoin cash-out at its core, and the victim-side financing behaviours (retirement liquidations, credit-line draws to fund crypto transfers) represent the most actionable early-intervention points for EMEA banks — the same typologies transfer directly to European retail customer bases even though the study covers U.S. victims. All quantitative claims are single-sourced from The Record's reporting of the FinCEN study; we will obtain and review the underlying FinCEN alert and full report, monitor for corroboration of the Xinbi Guarantee action and any follow-on enforcement, and update clients if the full report contains typology detail or indicators beyond what this coverage provides.

---

[Read the original source →](https://therecord.media/treasury-urges-banks-report-cyber-scams?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*