Moves include setting up layered defenses against deepfakes and mule account networks.
In a whitepaper released by IDfy Philippines and CIBI Information, Inc. entitled Mule Hunting: Are We Chasing Ghosts? — which analyzed transaction data from the Bangko Sentral ng Pilipinas (BSP) — it was able to find several cracks in the system.
In 2025, PHP24.74 trillion of combined transaction flows through PESONet and InstaPay platforms.
Although, about PHP 1.088 trillion in transactions was at risk of digital fraud, as 55.4% were directly dependent on authorized push payment (APP) scams and account takeovers (ATO) that require mule accounts to exfiltrate stolen cash.
Thus, without stronger identity safeguards, tne Philippine economy might possibly lose approximately PHP603 billion annually, or nearly 3% of national Gross Domestic Product (GDP), to illicit mule account networks.
This vulnerability, the paper suggested, stems from hyper-accelerated digital adoption Tha created a gap that transnational syndicates actively exploit.
The Philippines surpassed its target to digitize 52.8% of retail payments in 2023.
However, despite the scale of the shadow economy, official cybercrime reporting remains low at under 2%, in spite of the Cybercrime Investigation and Coordinating Center (CICC) data noting that 34% of Filipinos suffered financial scam losses.
It was found that victims rarely file formal complaints due to small transaction values and legal complexity—allowing weaponised mule accounts to remain active and clean for months.
The whitepaper also estimated that 60% to 70% of mule accounts involve voluntary participation, driven by a rampant “mule-for-hire” market where verified bank and e-wallet accounts are bulk-purchased for PHP 500 to PHP 5,000, according to National Bureau of Investigation.
The remaining 30% to 40%, meanwhile, are coerced through sophisticated schemes like romance-investment frauds and fake remote job scams.
Regulatory pressure is rapidly escalating under the Anti-Financial Account Scamming Act (AFASA) and BSP Circular 1213, which fundamentally shift liability for fraud losses from consumers to financial institutions.
Those who fail to deploy real-time fraud management systems face full, unlimited reimbursement liability for customer losses.
Crucially, the circular also restricts SMS and Email OTPs to initial account setups, prohibiting their use for high-risk actions such as fund transfers, payee additions, and credential changes.
To secure the digital grid, institutions are urged to adopt multi-layered, resilient authentication that requires server-side biometrics, cryptographic device binding, and real-time AI behavioral risk scoring.
In a statement, Raghuraman Chandrashekhar, Country Head of IDfy Philippines, stressed, “Clinging to interceptable OTPs is no longer just legacy technology; under AFASA, it is a direct financial liability for institutions.”
“No single institution can close this gap alone. What works is layering device intelligence, real-time AI transaction monitoring, and biometric verification into a unified defense stack,” he added.
Industry experts also emphasized that closing the gap requires a multi-layered architecture rather than isolated safeguards.
Collaborative systems like Fraud Intelligence Data Sharing (FIDS), AI-driven transaction monitoring, and server-side facial authentication must be operated in unison, with the AFASA regulatory framework also binding them into an end-to-end defense mechanism that mule networks cannot bypass.
