Money Mules in the Philippines: The Hidden AML Layer Behind Online Scams
Online scams do not stop when a victim sends money. That is where the next layer begins.
Behind phishing pages, romance scams, fake investment platforms, illegal gambling schemes, and social engineering attacks is a financial movement system built to receive, split, move, and cash out stolen funds. In the Philippines, this layer is increasingly visible through one simple but dangerous role: the money mule.
​
Money mules are individuals who allow their bank accounts, ATM cards, online banking profiles, or e-wallets to be used by criminal networks. Some know exactly what they are doing. Others are recruited through fake jobs, easy money offers, or social media promises. Either way, these accounts become disposable infrastructure for cybercrime.
​
In March 2026, the Philippine National Police Anti-Cybercrime Group reported that it arrested 67 individuals in 60 operations from January to February 2026 for alleged violations of the Anti-Financial Account Scamming Act, also known as AFASA. The operations targeted individuals accused of being involved in the sale or misuse of financial accounts used in scam and cybercrime activity. For defenders, this matters because money mule activity sits at the intersection of fraud, cybercrime, and anti-money laundering. It is not just a banking issue. It is part of the operational backbone that allows online scams to scale.
​
​​
Why Money Mules Matter
Most public scam awareness focuses on the front end: the phishing link, the fake romance profile, the investment pitch, or the impersonation message. Those are important, but they are only one part of the chain.
The financial layer is what turns deception into profit. A victim sends money. The money lands in a mule account.
The mule transfers it, withdraws it, or sends it to another account.
The funds may move through additional bank accounts, e-wallets, crypto services, gambling platforms, or cash-out points. By the time investigators trace the first transaction, the money may already be several layers away.
This is why mule accounts are so valuable to scam networks. They create distance between the victim and the organizer. They make attribution harder. They give criminals a way to rotate financial infrastructure quickly, especially when accounts get frozen or flagged.
In plain terms: money mules are the cash-out layer of the scam economy.
​
​
The Philippines Context
The Philippines is a major digital finance environment. E-wallets, online banking, mobile payments, and social media commerce are deeply embedded in daily life. That makes financial access faster and more convenient, but it also creates more opportunities for abuse. Scammers do not always need sophisticated malware or advanced hacking tools. Sometimes they only need access to real accounts controlled by real people. That is what makes mule recruitment dangerous. Criminal groups can use economic pressure, fake job ads, social media messages, or “easy income” offers to convince people to open accounts, hand over ATM cards, share online banking credentials, or receive and forward funds.
To the mule, it may look like a side hustle.
To the scam network, it is laundering infrastructure.
​
​
AFASA and the Shift Toward Account Abuse Enforcement
The Philippines’ Anti-Financial Account Scamming Act, officially Republic Act No. 12010, was signed into law in July 2024. The law defines and penalizes financial account scamming and specifically includes money muling activities as a prohibited act.
This is important because it directly targets the misuse of financial accounts, not only the scam message or fraud operator.
The law recognizes that bank accounts, e-wallets, and financial credentials can be weaponized as part of scam operations.
The Bangko Sentral ng Pilipinas’ AFASA materials describe the law as a response to digital fraud that is fast, pervasive, sophisticated, and enabled by anonymity. That framing is useful for defenders. It shows that the problem is not limited to individual fraud cases. It is a systemic abuse of digital finance infrastructure.
​
How the Mule Layer Usually Works
A typical money mule flow may look like this:
-
A scammer contacts a victim through phishing, romance fraud, fake investment offers, illegal gambling, or impersonation.
-
The victim is convinced to send money.
-
The receiving account belongs to a mule, not the main operator.
-
The mule quickly transfers or withdraws the funds.
-
The money is split across more accounts or converted into other channels.
-
The original scammer becomes harder to identify.
The key point is speed. Mule networks rely on fast movement. The longer money stays in one account, the higher the chance a bank, e-wallet provider, victim, or investigator can interrupt the flow.
What Defenders Should Watch For
Banks, fintechs, cybercrime investigators, and fraud teams should treat mule activity as behavioral infrastructure. The account may look normal at first, but the pattern often reveals the risk.
Useful warning signs include:
-
New accounts receiving sudden third-party deposits.
-
Multiple small inbound transfers followed by rapid outbound movement.
-
Accounts that receive money from unrelated individuals.
-
Fast withdrawals after victim deposits.
-
Shared devices, IP addresses, or login behavior across multiple accounts.
-
Customers who cannot explain the source or purpose of funds.
-
Account holders who surrender ATM cards, SIM cards, credentials, or e-wallet access.
-
Social media posts offering money in exchange for “renting” or “borrowing” accounts.
-
Repeated links between accounts and known scam reports.
For public awareness, the message should be direct: do not lend, sell, rent, or open financial accounts for someone else. Even if the person claims it is for payroll, online work, crypto trading, gambling, or business transactions, the account holder may become part of a criminal investigation.
Why This Is Underreported
Philippine scam coverage often focuses on large scam compounds, POGO-linked activity, trafficking, or high-profile cybercrime arrests. Those stories matter. But the mule layer is quieter and more distributed.
It is harder to visualize than a raid.
It is less dramatic than a scam compound.
It often involves ordinary people, small accounts, and fragmented transactions.
But without mule accounts, many scam operations become harder to monetize.
That is why this deserves more attention. The mule layer is where cybercrime meets the financial system. It is also where prevention, detection, and public education can have real impact.
PhishSauce Assessment
PhishSauce assesses with moderate confidence that money mule activity will remain a key enabler of Philippine and Southeast Asian scam operations in 2026. The combination of digital wallet adoption, online banking access, social media recruitment, economic pressure, and cross-border scam activity makes account abuse a persistent AML and cybercrime challenge.
Current reporting confirms Philippine enforcement activity against suspected mule accounts and scammers under AFASA. However, open-source reporting does not yet clearly identify whether these arrests are connected to one organized network, multiple unrelated groups, or broader regional scam infrastructure.
Intelligence Gaps
Several questions remain open:
-
Were the arrested individuals connected to one network or multiple smaller mule rings?
-
Which scam types generated the funds moved through these accounts?
-
Did any accounts connect to crypto exchanges, online gambling platforms, or overseas entities?
-
How were the mules recruited?
-
Were the accounts newly opened, purchased, rented, or compromised?
-
How many victims were linked to the identified mule accounts?
-
Are mule recruiters operating mainly through social media, messaging apps, job scams, or personal networks?
These gaps matter because they help defenders move from reactive fraud investigation to proactive detection.
​
​​
Final Takeaway
Money mules are not a side issue in scam investigations. They are part of the financial infrastructure that allows scams to work.
For the Philippines, AFASA gives law enforcement and regulators a clearer path to target financial account abuse. But public awareness is still critical. People need to understand that lending an account, selling an ATM card, or allowing someone else to use an e-wallet is not harmless.
It may be the missing link that helps a scam network steal, move, and hide victim funds.
For defenders tracking cybercrime in Southeast Asia, the mule layer deserves more attention. It is quiet, distributed, and often overlooked. But it is one of the most important parts of the scam economy.
​​
​
References:
Note: Much of the analysis presented here was gathered by our analysts and is drawn from open-source reporting, Philippine legal materials, and regulatory guidance on financial account scamming and money mule activity.
Here’s some supporting resources:
Philippine News Agency — PNP busts 67 money mules, scammers in first 2 months of 2026.
Republic Act No. 12010 — Anti-Financial Account Scamming Act.
Bangko Sentral ng Pilipinas — AFASA Booklet with Implementing Rules and Regulations.
​
​
​​
​