MANILA, Philippines — The Philippine economy risks losing roughly PHP 603 billion annually, or nearly 3% of national Gross Domestic Product (GDP), to illicit mule account networks without stronger identity safeguards, according to a joint whitepaper released by IDfy Philippines and CIBI Information, Inc.
The report, “Mule Hunting: Are We Chasing Ghosts?,” analyzed transaction data from the Bangko Sentral ng Pilipinas (BSP), which saw PHP 24.74 trillion in combined transaction flows through PESONet and InstaPay in 2025. The report noted that about PHP 1.088 trillion in transactions was at risk of digital fraud, with 55.4% directly dependent on authorized push payment (APP) scams and account takeovers (ATO) that require mule accounts to exfiltrate stolen cash.
The vulnerability stems from hyper-accelerated digital adoption. The Philippines surpassed its target to digitize 50% of retail payments three years early, reaching 52.8% in 2023. However, this rapid growth created a gap that transnational syndicates actively exploit.
Despite the scale of the shadow economy, official cybercrime reporting remains low at under 2%. While Cybercrime Investigation and Coordinating Center (CICC) data indicates 34% of Filipinos suffered financial scam losses, victims rarely file formal complaints due to small transaction values and legal complexity. This allows weaponised mule accounts to remain active and clean for months.
The whitepaper estimates that 60% to 70% of mule accounts involve voluntary participation, driven by a rampant “mule-for-hire” market where verified bank and e-wallet accounts are bulk-purchased for PHP 500 to PHP 5,000, according to NBI data. The remaining 30% to 40% are coerced through sophisticated schemes like romance-investment frauds and fake remote job scams.
Regulatory pressure is rapidly escalating under the Anti-Financial Account Scamming Act (AFASA) and BSP Circular 1213, which fundamentally shift liability for fraud losses from consumers to financial institutions. Institutions that fail to deploy real-time fraud management systems face full, unlimited reimbursement liability for customer losses.
Crucially, the circular restricts SMS and Email OTPs to initial account setups, prohibiting their use for high-risk actions such as fund transfers, payee additions, and credential changes. To secure the digital grid, institutions are urged to adopt multi-layered, resilient authentication that requires server-side biometrics, cryptographic device binding, and real-time AI behavioral risk scoring.
“Clinging to interceptable OTPs is no longer just legacy technology; under AFASA, it is a direct financial liability for institutions,” said Raghuraman Chandrashekhar, Country Head of IDfy Philippines. “No single institution can close this gap alone. What works is layering device intelligence, real-time AI transaction monitoring, and biometric verification into a unified defense stack.”
Industry experts emphasized that closing the gap requires a multi-layered architecture rather than isolated safeguards. Collaborative systems like Fraud Intelligence Data Sharing (FIDS), AI-driven transaction monitoring, and server-side facial authentication must operate in unison, with the AFASA regulatory framework binding them into an end-to-end defense mechanism that mule networks cannot bypass.