The Philippine economy could be losing around PHP 603 billion annually, equivalent to nearly 3% of national GDP, to illicit mule account networks without stronger identity and fraud safeguards, according to a joint whitepaper by IDfy Philippines and CIBI Information, Inc.
Titled Mule Hunting: Are We Chasing Ghosts?, the report analyzed transaction data from the Bangko Sentral ng Pilipinas (BSP), which recorded PHP 24.74 trillion in combined PESONet and InstaPay transaction flows in 2025. Of this, approximately PHP 1.088 trillion was considered at risk of digital fraud, with 55.4% linked directly to authorized push payment (APP) scams and account takeovers (ATO)—fraud schemes that rely on mule accounts to move stolen funds.
Digital Growth Creates New Fraud Risks
The report points to the Philippines’ rapid digital payment adoption as a key factor. The country reached 52.8% digital retail payments in 2023, surpassing its target of 50% three years ahead of schedule. However, the accelerated shift has also created opportunities for transnational fraud networks.
Despite the scale of the problem, official cybercrime reporting remains below 2%. CICC data cited in the report indicates that 34% of Filipinos have experienced financial scam losses, but many victims do not formally report incidents because of relatively small transaction amounts and the complexity of pursuing complaints.
The whitepaper estimates that 60% to 70% of mule accounts involve voluntary participants, fueled by a “mule-for-hire” market in which verified bank and e-wallet accounts can reportedly be acquired for PHP 500 to PHP 5,000. The remaining 30% to 40% are believed to involve coercion through schemes such as romance-investment fraud and fake remote job offers.
Stronger Authentication Becomes Critical
Regulatory requirements are also raising the stakes for financial institutions. Under the Anti-Financial Account Scamming Act (AFASA) and BSP Circular 1213, financial institutions face greater responsibility for fraud losses, while SMS and email OTPs are restricted to initial account setup and cannot be used for high-risk actions such as fund transfers, adding payees, or changing credentials.
The report recommends a layered approach combining server-side biometrics, cryptographic device binding, real-time AI behavioral risk scoring, Fraud Intelligence Data Sharing (FIDS), and AI-powered transaction monitoring.
“Clinging to interceptable OTPs is no longer just legacy technology; under AFASA, it is a direct financial liability for institutions,” said Raghuraman Chandrashekhar, Country Head of IDfy Philippines. “What works is layering device intelligence, real-time AI transaction monitoring, and biometric verification into a unified defense stack.”
The whitepaper argues that collaboration among financial institutions and the adoption of interconnected fraud defenses will be essential to addressing increasingly sophisticated mule networks.