FinCEN’s Scam-Center Alert: The Compliance Shockwave Legitimate Crypto Businesses Should Expect

FinCENs new scam-center alert is set to reshape how banks, payment processors, and other financial institutions monitor digital-asset activity. As compliance systems adjust to the new typologies, legitimate on-chain businesses should prepare for increased scrutiny, information requests, and false positives.

FinCEN’s latest scam-center alert is not an enforcement action, but it may be the week’s most consequential operational development for banks, payment processors, money services businesses, and the digital-asset companies that rely on them.

On September 3, 2026, the Financial Crimes Enforcement Network (“FinCEN”) issued Alert FIN-2026-Alert005, directing financial institutions to identify and report suspicious activity associated with digital-asset investment scams operated by overseas scam centers.

The alert focuses on the operators themselves and the broader infrastructure supporting their activities, including money mules, shell companies, professional money-laundering networks, and online “guarantee marketplaces.” FinCEN also instructed institutions filing related Suspicious Activity Reports (“SARs”) to use the key term FIN-2026-SCAMCENTERS.

The immediate target is criminal activity. The near-term effects, however, will likely extend well beyond criminal actors.

The Data Will Drive the Operational Response

FinCEN released the alert alongside a Financial Trend Analysis examining Bank Secrecy Act (“BSA”) reporting from September 8, 2023, through December 31, 2025.

During that period, FinCEN identified:

  • 33,904 BSA reports involving suspected digital-asset investment scam activity;

  • approximately $12.7 billion in reported financial activity;

  • victims across all 50 states and several U.S. territories; and

  • 96% of the reports coming from money services businesses—predominantly those related to digital assets—and depository institutions.

FinCEN also found that the monthly volume of reports increased by an average of 10.9%, while the reported dollar value increased by an average of 18% month over month during the review period.

FinCEN cautioned that increased use of the reporting key term established by its prior alert may partly explain the growth in reported activity. The figures therefore do not necessarily establish that the underlying rate of scams increased at the same pace.

Those qualifications matter, but they are unlikely to soften the operational response. Compliance teams will see a large nationwide dataset, detailed typologies, and a dedicated SAR key term. Banks, exchanges, payment processors, and other financial intermediaries are therefore likely to recalibrate their transaction-monitoring rules, customer-risk models, escalation procedures, and investigative playbooks around the conduct identified in the alert.

What FinCEN Wants Institutions to Detect

The alert describes industrial-scale scam operations, often associated with transnational criminal organizations based in Southeast Asia. These operations use fabricated identities, social-engineering tactics, fraudulent investment websites and applications, and promises of outsized returns to persuade victims to transfer money or digital assets.

FinCEN asks institutions to monitor activity connected to several layers of the scam ecosystem, including:

  • scam-center operators and their financial facilitators;

  • victims directed to purchase digital assets through reputable exchanges and transfer them to unattributed, scammer-controlled addresses;

  • money mules and shell companies used to receive or move proceeds;

  • rapid movement of funds through multiple accounts, institutions, or wallet addresses;

  • professional money-laundering networks; and

  • “guarantee marketplaces” that may provide marketing, communications, escrow, and payment infrastructure for gray-market or illicit services.

The alert’s focus is therefore not limited to accounts that are obviously fraudulent. It reaches transaction patterns, counterparties, onboarding behavior, payment flows, digital-asset addresses, and networks that may appear legitimate when viewed individually.

Legitimate On-Chain Businesses Sit Inside the False-Positive Expansion

For lawful digital-asset companies, the principal near-term risk is not that the alert changes the legal status of their business models. It is that financial institutions may broaden their controls faster than they refine them.

Transaction-monitoring systems are designed to identify anomalies and combinations of risk indicators—not to deliver final legal conclusions. When institutions incorporate FinCEN’s new scam-center typologies, lawful activity may be swept into the same review queues.

Cross-border payments, high-velocity transactions, newly created wallets, transfers to unattributed addresses, interactions with centralized exchanges, layered wallet movements, and exposure to higher-risk jurisdictions can all arise during legitimate operations.

For digital-asset businesses, that may result in:

  • increased requests for information from banking and payment partners;

  • delayed transactions or enhanced manual review;

  • tighter onboarding and periodic-review requirements;

  • account restrictions or exits based on institutional risk appetite rather than proven misconduct; and

  • greater scrutiny of customers, counterparties, beneficial owners, wallet addresses, and sources of funds.

This is the familiar de-risking problem in a new operational form. An alert aimed at serious criminal conduct can cause regulated intermediaries to cast a wider net, particularly during the initial implementation period.

For crypto businesses, the quality and accessibility of their compliance documentation may determine whether an unusual transaction is quickly understood or treated as an unacceptable risk.

What Digital-Asset Companies Should Do Now

Legitimate businesses should not wait for a banking or payment partner to raise questions. This is the time to pressure-test whether their compliance programs can explain their activities using the language and risk indicators financial institutions are likely to adopt.

Companies should consider the following steps:

1. Map Exposure to the New Typologies

Identify products, customer segments, jurisdictions, transaction paths, wallet activity, and counterparties that may overlap with the alert’s indicators—even where the underlying activity is lawful.

2. Review Transaction-Monitoring Scenarios

Determine whether existing controls can identify scam-related patterns without relying on overly broad proxies that generate unmanageable false positives.

3. Strengthen Source-of-Funds and Counterparty Documentation

Maintain clear records demonstrating the commercial purpose, ownership, source of funds, and anticipated flow of higher-risk transactions.

4. Prepare for Partner Diligence

Update compliance summaries, flow-of-funds diagrams, licensing analyses, AML policies, escalation procedures, and explanations of wallet-screening practices so they can be provided promptly when questions arise.

5. Test Incident-Response Procedures

Establish who will respond to account freezes, information requests, fraud complaints, law-enforcement outreach, and suspected exposure to scam-linked wallet addresses.

6. Reassess Vendor and Banking Dependencies

Understand which service providers may change their risk thresholds and determine where a restriction involving a single account or provider could disrupt customer access or core operations.

The Bottom Line

FIN-2026-Alert005 does not impose a new rule on every digital-asset company, and the presence of a red flag does not, by itself, establish illicit activity.

The alert does, however, give financial institutions a detailed framework for identifying, escalating, and reporting suspected scam-center activity. The accompanying analysis identifying approximately $12.7 billion in suspected activity creates a strong incentive for institutions to act quickly.

The practical consequence will likely be an expansion of monitoring and diligence across the financial system. Legitimate on-chain businesses should expect more questions, increased scrutiny, and potentially more false positives.

The best defense is not simply to insist that the business is lawful. Companies should maintain a compliance record that enables banks, payment processors, and other partners to distinguish their lawful activities from the scam typologies FinCEN has now placed at the center of its reporting priorities.

Learn more

This blog post is for informational purposes only and is not legal advice. Please consult with a Launch Legal attorney regarding your specific situation.