Inside the Treasury’s Latest Scam Alert, and Why It Applies Past Banking

Key takeaways
- FinCEN warned banks and crypto firms about relationship-based investment scams and reported that from September 2023 to December 2025, $12.7 billion left victims’ accounts; banks flagged $6.4 billion, crypto firms flagged $5.5 billion, and FinCEN’s monthly report volume rose about 11% month over month.
- The scam pattern relies on long-built fake personas, often posing as romantic partners or financial advisers for weeks or months before pitching investments; about a quarter of victims are over 60, and some cases only came to light when victims were asked to pay a so-called recovery fee.
- CSIS researcher Julia Dickson said generative AI and large language models help scammers craft authentic messages that build trust faster; CSIS also found nearly three-quarters of Americans have experienced an online scam, with $16.6 billion in U.S. losses in 2024 alone.
- Although FinCEN’s alert focuses on consumer investment fraud rather than corporate wire fraud, the article says the transferable risk is the technique: AI-assisted, trust-building messages that can also power business email compromise against finance teams.
- Treasury paired its reporting push with sanctions on Xinbi Guarantee, a Telegram-based marketplace accused of laundering an estimated $36 billion, while CSIS recommended a single centralized scam-reporting repository instead of splitting reports across agencies like the FBI, FTC, and Social Security Administration.
- The article recommends combining AI-first detection with verification habits: use AI-driven email security to spot language-model-generated messages, make it easy for employees to report suspicious requests across email, SMS, phone, and video, and require controls like callbacks to known directory numbers and dual authorization for high-value transfers.
What Washington Is Watching
FinCEN, the Treasury Department’s financial crimes unit, issued an alert this month urging banks and cryptocurrency firms to sharpen how they detect and report a specific pattern. Scam networks operating out of organized centers overseas are patiently building relationships with victims before steering them into fraudulent investment platforms.
The numbers behind that alert deserve a closer look. Between September 2023 and December 2025, $12.7 billion moved out of victims’ accounts into cryptocurrency investment scams. Traditional banks flagged $6.4 billion of it. Cryptocurrency firms flagged the other $5.5 billion. FinCEN’s monthly report volume has climbed roughly 11 percent month over month.
Gene Lange, a Treasury Department official, described the pattern this way: “The transnational criminal organizations behind these scams exploit both emerging technologies and human vulnerabilities, resulting in devastating financial losses for innocent American victims.”
That sentence names the two ingredients any social engineering operation needs. A capable tool and a believable story. Technology changed how far each dollar of criminal effort now goes.
The Persona Behind the Scam
These operations run on manufactured relationships. A scammer poses as a romantic partner or a financial adviser and spends weeks or months earning a target’s confidence before ever mentioning an investment. About a quarter of victims are adults over 60. Many cases only surfaced when the victim was asked to pay a “recovery fee,” a sign the relationship itself was the product.
Researchers at the Center for Strategic and International Studies have tracked how these operations professionalize. Julia Dickson, a research associate in CSIS’s International Security Program, points to the specific role generative AI now plays. Large language models “help scammers craft authentic messages to gain victims' trust and persuade them to invest faster.”
A persona built to win a retirement investor’s trust over months and a message built to win a controller’s trust in thirty seconds rely on the same ingredient. A believable voice on the other end. Neither depends on the target being careless.
Where the Techniques Overlap With Corporate Fraud
The FinCEN alert is about consumer-directed investment fraud, not corporate wire fraud, and the two are often run by different actors with different targets. Worth being precise about that distinction rather than blurring it for effect.
What transfers between the two is the technique, not necessarily the infrastructure. The FinCEN alert notes at least 18 different cryptocurrencies now moving through these networks, one sign of how much this criminal ecosystem has professionalized and diversified. Dickson’s broader research at CSIS puts the consumer side in context: “Nearly three-quarters of Americans have experienced an online scam,” with $16.6 billion in U.S. losses in 2024 alone.
A criminal ecosystem operating at that scale, using generative AI to write persuasive, trust-building messages, is the same toolset available to whoever runs a business email compromise campaign against a corporate finance team. The actors may differ. The technique, an AI-assisted message designed to earn trust before making a financial request, isn’t limited to one category of victim, which is how it reaches a company too.
What’s Working: Faster Reporting, Better Visibility
Treasury’s ask of banks is straightforward: report more, report faster, and report consistently. That request arrives alongside a concrete enforcement action: sanctions against Xinbi Guarantee, a Telegram-based marketplace that let scam networks launder their proceeds, an estimated $36 billion worth. Together, the reporting push and the sanctions turn a diffuse global problem into something specific enough to act on.
CSIS has made a version of this same recommendation to Congress: establish “a single, centralized repository where victims can report scams” instead of splitting reports across the FBI, FTC, and Social Security Administration. The logic holds at any scale. A single flagged incident tells you little on its own. A connected pattern of flagged incidents tells you where to focus.
Pairing AI-First Detection With Better Habits
This is the part worth building deliberately rather than hoping it happens on its own. Readiness comes from two things working together: detection built specifically for AI-generated threats, and habits that hold up when a message gets through anyway.
- Start with detection. AI-driven email security analyzes incoming messages for the patterns a language model leaves behind, catching a message crafted to sound like your own controller before it ever reaches an inbox. A rules-based spam filter built for a different decade was never designed to see that kind of message. Voice calls and video conferences call for a different layer, which is where the habits below still matter.
- Give employees a fast, low-friction way to flag a suspicious request, whether it arrives by email, text, phone call, or video. The goal matches what FinCEN is chasing at the national level: more reports, sooner, from the people closest to the activity.
- Connect those reports to what detection is already catching. One report is a data point. A dozen reports sharing the same pattern, matched against what an AI system flagged the week before, is a campaign, and a campaign is far easier to stop once it is visible.
- Put verification steps in place that do not depend on how long a relationship has existed or how familiar a voice sounds. A callback to a phone number pulled from an existing directory, not the number provided in the message, is a small step with a large effect. Dual authorization on any high-value transfer removes the single point of failure a well-crafted message is trying to create.
- Detection catches more of these attempts before a person ever has to make a judgment call. Habits catch what detection has not learned to see yet. Neither piece does the job alone.
Adaptive Security builds both halves. Our email security analyzes incoming messages in real time to flag AI-generated threats before they reach an inbox, and our simulations and training cover voice, video, SMS, and email so finance and security teams build the habits to catch what detection alone cannot.
Washington’s response to this scam wave is a genuinely encouraging sign. Better visibility, faster reporting, and coordinated enforcement are exactly what closes the gap between a criminal network and the people it targets. Companies pairing strong detection with strong habits internally are applying a model that is already showing results, not inventing an unproven one.
Curious what this kind of detection and reporting loop could look like at your organization? We're glad to walk you through it.