Mule Accounts Threaten to Drain 3% of PH’s Entire GDP
Nearly 3% of the Philippine economy could vanish into a web of fake bank accounts. A new joint whitepaper warns the country risks losing roughly PHP 603 billion a year to illicit mule account networks.
The study, from IDfy Philippines and CIBI Information, Inc., says the losses will keep mounting without stronger identity safeguards in place.
The report, titled “Mule Hunting: Are We Chasing Ghosts?,” analyzed transaction data from the Bangko Sentral ng Pilipinas. It found that PESONet and InstaPay carried a combined PHP 24.74 trillion in transaction flows in 2025.

Of that total, about PHP 1.088 trillion in transactions was flagged as at risk of digital fraud. The whitepaper noted that 55.4% of that risk stems directly from authorized push payment scams and account takeovers that rely on mule accounts to move stolen cash.
How the Philippines’ Digital Payment Boom Fueled Mule Account Fraud
The vulnerability traces back to how fast the Philippines went digital. The country blew past its target to digitize 50% of retail payments three years ahead of schedule, hitting 52.8% in 2023.
That rapid shift, however, opened a gap that transnational syndicates have been quick to exploit. Weak identity checks made it easier for fraud networks to slip mule accounts into the formal banking system.
The scale of the problem is likely underreported. Official cybercrime reporting remains under 2%, even though Cybercrime Investigation and Coordinating Center data shows 34% of Filipinos have suffered financial scam losses.
Most victims never file formal complaints because of small transaction values and legal complexity. That gap lets weaponized mule accounts stay active and appear clean for months at a time.
The whitepaper estimates 60% to 70% of mule accounts involve voluntary participation. National Bureau of Investigation data points to a “mule-for-hire” market where verified accounts are bulk-purchased for PHP 500 to PHP 5,000.
The remaining 30% to 40% of mule accounts are coerced through sophisticated schemes. These include romance-investment fraud and fake remote job scams targeting vulnerable Filipinos.
New AFASA Law Shifts Fraud Liability Onto Philippine Banks
Regulatory pressure is mounting fast. The Anti-Financial Account Scamming Act and BSP Circular 1213 shift liability for fraud losses away from consumers and onto financial institutions.
Under the new rules, institutions that fail to deploy real-time fraud management systems face full, unlimited reimbursement liability for customer losses. The circular also restricts SMS and email one-time passwords to initial account setups.
That means banks can no longer rely on OTPs for high-risk actions like fund transfers, payee additions, and credential changes. Regulators are urging stronger alternatives instead.
Institutions are being pushed toward server-side biometrics, cryptographic device binding, and real-time AI behavioral risk scoring. Together, those tools are meant to replace easily intercepted OTP codes.
“Clinging to interceptable OTPs is no longer just legacy technology; under AFASA, it is a direct financial liability for institutions,” said Raghuraman Chandrashekhar, country head of IDfy Philippines. “No single institution can close this gap alone.”
Chandrashekhar added that the fix lies in combining multiple layers of defense at once. “What works is layering device intelligence, real-time AI transaction monitoring, and biometric verification into a unified defense stack,” he said.
Industry experts stressed that no single safeguard will be enough on its own. Systems like Fraud Intelligence Data Sharing, AI-driven transaction monitoring, and server-side facial authentication need to work in unison.
Under the AFASA framework, those tools are meant to bind together into one defense mechanism. The goal is an end-to-end system that mule networks cannot easily bypass.