AML, FinCEN & Banking Access: A De-Risking Event, Not an Enforcement Event

FinCENs latest digital-asset scam alert signals a sharper focus on identifying illicit networks without imposing new rules or targeting the broader crypto industry. For financial institutions and digital-asset companies, the development reinforces the importance of risk-based AML controls that protect banking access while isolating genuine criminal activity.


On September 3, 2026, the Financial Crimes Enforcement Network (“FinCEN”) published Alert FIN-2026-Alert005, addressing money laundering activity associated with overseas digital-asset investment scam centers.

According to FinCEN, these centers are industrial-scale operations run by transnational criminal organizations, predominantly based in Southeast Asia. Their methods may include:

  • Creating fabricated online identities and cultivating relationships with potential victims;

  • Directing victims to fraudulent investment websites or applications that display fictitious gains;

  • Persuading victims to transfer additional funds, frequently through digital assets;

  • Using money mules, shell companies and professional laundering networks to move or conceal proceeds; and

  • Procuring phishing tools, account-creation services and laundering infrastructure through online “guarantee marketplaces.”

The alert asks financial institutions to monitor for activity involving scam operators, money mules, shell companies, guarantee marketplaces and professional money laundering networks. It also encourages eligible financial institutions to share information voluntarily under Section 314(b) of the USA PATRIOT Act and instructs institutions filing related Suspicious Activity Reports (“SARs”) to include the key term FIN-2026-SCAMCENTERS.

The scale is significant. FinCEN cites FBI Internet Crime Complaint Center data showing reported losses suffered by U.S. victims rising from approximately $907 million in 2021 to $7.2 billion in 2025. FinCEN separately reported identifying nearly $13 billion in transactions potentially connected to digital-asset scams operated by overseas scam centers.

What the Alert Does—and Does Not Do

The legal distinction matters.

FIN-2026-Alert005 is not a regulation. It does not amend the Bank Secrecy Act (“BSA”), create a new category of regulated entity, expand the statutory definition of a money services business or establish a new reporting deadline. It also does not announce penalties against a particular financial institution or digital-asset company.

Instead, the alert provides financial institutions with typologies, behavioral indicators and filing instructions intended to improve the identification and reporting of suspicious activity. FinCEN describes alerts and advisories as tools that institutions may use to enhance their anti-money laundering (“AML”) monitoring systems and produce more useful SAR reporting.

The practical expectation is not that an institution treat every transaction involving digital assets, Southeast Asia or an online investment platform as suspicious. Red flags are contextual indicators, not automatic proof of criminal conduct. A determination should be based on the facts surrounding the customer, transaction pattern, counterparties, source and destination of funds, and the institution’s broader understanding of the activity.

Why Section 314(b) Matters

FinCEN’s emphasis on Section 314(b) is particularly important because scam-center networks commonly distribute activity across multiple institutions, accounts, platforms and jurisdictions.

Section 314(b) permits eligible and properly registered financial institutions to share information with one another under a statutory safe harbor when the information may relate to money laundering, terrorist financing or specified unlawful activity—including fraud.

That information sharing can help institutions:

  • Identify accounts connected to the same criminal network;

  • Detect previously unknown counterparties or related transactions;

  • Understand activity that may appear legitimate when viewed through only one institution;

  • Coordinate more complete SAR filings; and

  • Make better-informed decisions about opening, maintaining, restricting or closing an account.

The safe harbor is subject to important conditions. Participating institutions must verify the other party’s Section 314(b) status, protect the security and confidentiality of shared information, and use that information only for authorized purposes. Section 314(b) also does not eliminate applicable SAR-confidentiality restrictions.

The Banking-Access Implication

The broader significance of the alert is its support for targeted risk management.

Banks and other financial institutions may reasonably respond by strengthening due diligence and transaction monitoring for customers exposed to the identified typologies. That could include closer review of rapid fund movements, newly created counterparties, unusual account access patterns, connections to high-risk jurisdictions, transfers involving suspected money-mule activity, or transactions with no clear economic purpose.

But the alert does not support treating all digital-asset businesses as presenting the same risk. A compliant U.S. digital-asset company with transparent ownership, documented sources of funds, appropriate customer controls and a functioning AML program is not equivalent to an opaque offshore investment platform, an unregistered intermediary or an entity associated with scam-center infrastructure.

That distinction is central to responsible banking access. Effective AML supervision should encourage institutions to identify, assess and manage specific risks—not avoid entire lawful industries merely because some participants may be exposed to financial crime.

In that sense, this is a de-risking event in the operational sense: FinCEN is giving institutions more information with which to reduce exposure to identifiable criminal networks. It should not be interpreted as a directive to engage in indiscriminate account closures or industry-wide debanking.

What Digital-Asset Companies Should Do Now

Digital-asset exchanges, custodians, payment companies, stablecoin businesses and other platforms should consider whether the alert’s typologies are adequately reflected in their existing compliance frameworks.

Practical next steps may include:

  1. Review the alert against existing controls. Determine whether transaction-monitoring rules and investigative procedures account for the identified scam-center behaviors.

  2. Update internal red-flag guidance. Compliance personnel should understand how fabricated investment platforms, money-mule networks, shell companies and guarantee marketplaces may interact.

  3. Evaluate geographic and counterparty exposure. Firms should assess whether their products or payment flows provide exposure to the jurisdictions, platforms or transactional patterns discussed by FinCEN.

  4. Review SAR procedures. Where the relevant facts support a filing, institutions should follow FinCEN’s instructions concerning the FIN-2026-SCAMCENTERS key term.

  5. Consider Section 314(b) participation. Eligible institutions should assess whether voluntary information sharing would improve their ability to identify related accounts or activity.

  6. Prepare for banking-partner questions. Digital-asset companies should be ready to explain their customer-identification processes, transaction-monitoring systems, geographic restrictions, escalation procedures and response to the new alert.

  7. Document risk-based decisions. Institutions should preserve the reasoning supporting enhanced monitoring, account restrictions or other measures rather than relying on generalized assumptions about digital assets.

The Bottom Line

FIN-2026-Alert005 reflects the government’s growing focus on the infrastructure surrounding digital-asset fraud: not only the individuals who solicit victims, but also the shell companies, money mules, online marketplaces and professional laundering networks that make large-scale scams possible.

The alert is consequential, but its consequence is operational rather than punitive. It gives financial institutions more detailed intelligence, encourages lawful information sharing and creates a consistent SAR identifier for related activity. It does not announce a new legal prohibition or justify the wholesale exclusion of legitimate digital-asset businesses from banking services.

For digital-asset companies, the message is straightforward: strong, demonstrable AML controls are increasingly tied not only to regulatory compliance, but also to sustainable banking access. Companies that can show how they identify and manage the specific risks described by FinCEN will be better positioned to distinguish themselves from the illicit networks the alert is designed to disrupt.

Learn more

This blog post is for informational purposes only and is not legal advice. Please consult with a Launch Legal attorney regarding your specific situation.