Pig Butchering Scam Detection: What Banks Can Actually See

How banks detect pig butchering scams: FinCEN red flags, the trial-transaction signal, receiving-side mule controls, and why 78% of victims defend the payment.
Alexandre Berkovic

TL;DR: Pig butchering scam detection is difficult because the victim authorizes every payment, which makes the transaction look legitimate on every dimension a fraud model measures. The FBI's Internet Crime Complaint Center recorded $7.228 billion in cryptocurrency investment fraud losses across 61,559 complaints in 2025, the single largest source of financial loss to Americans. The controls that work are not payment blocks — they are early-sequence detection on the victim side and account-lifecycle detection on the receiving side.

What the Bank Actually Sees

Timeline of a pig butchering scam from contact and grooming through trial transfer, escalation, fees and silence, divided by where bank visibility begins
The first three phases of a pig butchering scam happen off the bank's rails; the trial transfer is the earliest signal an institution can actually see.

Pig butchering is a long-form investment scam in which the perpetrator builds a relationship with the victim over weeks or months, directs them to a fabricated trading platform, and extracts escalating payments until the victim has nothing left. The name comes from the practice of "fattening" the victim with fake portfolio gains before the slaughter.

The structural problem for a financial institution is that the first three phases of the scam happen entirely off its rails. Contact arrives through a text message, a dating app, or a professional networking site. Grooming happens on an encrypted messaging platform. The pitch happens on a website the bank has never seen. By the time any money moves, the customer has already been convinced.

The first bank-visible signal is usually a trial transaction: a handful of small transfers to a virtual asset service provider, sized to test that the rails work. FinCEN's alert on the typology, issued in September 2023, names this pattern explicitly — a customer with a short history of small-value electronic transfers to a VASP who abruptly stops and begins sending multiple high-value wires to holding companies, limited liability corporations, and individuals with no prior transaction history. That trial transaction is the earliest reliable signal available, and it is small by design.

What follows is escalation. Funding sources become extreme in ways that are visible inside the institution but usually sit in different systems: certificates of deposit broken before maturity, retirement account drawdowns, home equity lines of credit, second mortgages. Then the withdrawal attempt fails, "taxes" and "fees" are demanded, and the customer wires again under time pressure. Then communication stops, and a recovery scam begins.

The Number That Breaks the Intervention Playbook

The FBI's Operation Level Up notifies pig butchering victims identified through investigative work. In 2025, of the 3,780 victims it contacted, 78 percent did not know they were being scammed. The operation estimates it saved $225.8 million that year and has prevented more than $500 million in losses since launching in January 2024.

That 78 percent figure is the most important detection statistic in this typology, and it is not a modeling statistic. It means that at the moment of the transaction, roughly four out of five customers will actively defend the payment. The standard fraud control — call the customer and ask whether they are sure — fails on the majority of attempts. Worse, FinCEN lists customer distress and anxiety about accessing funds as a red flag, which means the intervention itself often produces a customer motivated to defeat it.

Victims who are blocked do not stop. They go into a branch, split the transaction, or move to another institution entirely. A block at one bank is not a prevented loss. It is a routed loss, and the receiving institution sees a new customer with no history to compare against.

Red Flags Worth Building Detection Around

FinCEN's alert groups its indicators into behavioral, financial, and technical categories. The financial indicators are the ones most institutions already have the data for:

The behavioral indicators are higher signal and harder to capture. A customer mentioning an investment opportunity described by a new contact who reached out unsolicited. A customer saying they were told to convert cash at a virtual currency kiosk. A customer who appears distressed about meeting a deadline set by someone else. These live in call recordings, branch notes, and wire memo lines, not in structured transaction fields.

The cash-out channel deserves separate attention. FinCEN's August 2025 notice on virtual currency kiosks reported that the FBI received more than 10,956 complaints involving kiosks in 2024, with roughly $246.7 million in losses — a 99 percent increase in complaint volume over 2023. More than two of every three dollars lost through kiosks was lost by an older adult, which connects this typology directly to elder financial exploitation detection.

The Receiving Side Is Where the Leverage Is

Victim funds do not go to the scammer. They go to a rented U.S. bank account, typically belonging to a recently incorporated shell entity, and from there into stablecoin and out of the country. ProPublica's 2025 investigation traced a New Jersey victim's $716,000 across accounts tied to purported businesses in Boston, New York, California, and Hong Kong, most incorporated by Chinese nationals sometimes days before the accounts began accepting large sums. One reported case listed a one-bedroom Los Angeles apartment as headquarters for a dozen businesses formed by different individuals.

The receiving-side signals are structural rather than behavioral, which makes them substantially easier to operationalize:

This is a data problem rather than a customer-conversation problem, and the account holder has no emotional investment in defending it. Most published guidance concentrates on the victim side. The receiving side is less discussed and arguably higher yield. It also overlaps directly with mule account detection, which means institutions building one capability are usually building both.

Why Transaction Monitoring Misses It

There is no unauthorized-access event, no stolen credential, no anomalous device on the originating side, and no chargeback. Every control tuned to detect account takeover is blind by construction.

Thresholds compound the problem. The highest-value early signal is the trial transaction, which is small enough to sit under most rule thresholds. By the time a rule fires on dollar amount or velocity, the customer is already sending liquidated retirement funds.

The detection signals also live in systems that do not talk to each other. Catching this typology early requires joining digital banking session telemetry, branch interaction notes, wire narrative fields, lending origination, deposit product events, retirement distributions, card activity at kiosk operators, and blockchain attribution on the beneficiary side. In most institutions those sit across the fraud team, the AML team, retail operations, and lending — which is the practical case for fraud and AML convergence rather than an argument about tooling.

And no single institution sees the whole flow. The originating bank sees an outbound wire to a plausible-looking LLC. The receiving bank sees an inbound wire to a customer of record. Section 314(b) exists to close that gap, and FinCEN's alert reminds institutions of the safe harbor, but participation remains thin.

Enforcement Has Not Reduced Volume

In October 2025, FinCEN issued a final rule severing Huione Group from the U.S. financial system under Section 311, describing it as a critical node for laundering virtual currency investment scam proceeds from Southeast Asia. The same month, the Department of Justice indicted the chairman of Cambodia's Prince Group and filed a civil forfeiture action against approximately 127,271 Bitcoin — the largest forfeiture action in the department's history.

Volume still rose. UNODC's 2026 assessment estimates combined annual scam losses across East Asia, Southeast Asia, Australia, and New Zealand at between $88.3 billion and $114.1 billion for 2025 alone, with individuals from at least 80 countries identified inside scam compounds. The assessment is that enforcement has displaced rather than dismantled these operations. Static blocklists and country-risk tables decay in months, and successor entities appear within quarters.

Where the False Positive Risk Sits

FinCEN states plainly that no single red flag is determinative. Buying cryptocurrency for the first time is not suspicious. Breaking a CD is not suspicious. Taking a HELOC is not suspicious. The signal exists only in the conjunction and the sequencing, and any program that treats these indicators as standalone triggers will generate a queue nobody can work.

The cost of over-blocking is real. Retail crypto adoption is mainstream, and aggressively blocking first-time VASP transfers de-banks legitimate customers and generates complaints from exactly the people most convinced you are wrong. Age-gating does not solve it either — IC3 data show losses rising across every age group, and the largest individual losses cluster among financially sophisticated professionals with liquid assets.

Where Sphinx Fits

Sphinx's compliance agents work inside the systems institutions already run, which matters for this typology specifically because the detection signal is scattered across them. An agent can assemble the full picture behind an alert — the CD breakage, the lending event, the session telemetry, the wire narrative, the beneficiary entity's formation date — and produce a case file with the reasoning documented rather than just the conclusion, through the Interpretable Agentic Framework.

What that does not do is have the conversation. The 78 percent figure is a human problem, and the intervention still requires a trained person with evidence in hand. What agents change is how much of that evidence is already assembled when the call happens, and how many receiving-side accounts get reviewed at all.

Frequently Asked Questions

What SAR key term does FinCEN require for pig butchering?

FinCEN asks institutions to include the key term "FIN-2023-PIGBUTCHERING" in SAR field 2 and in the narrative, and to select "Fraud-Other" under field 34(z) with the description "Pig Butchering." FinCEN also requests technical cyber indicators — chat logs, scammer phone numbers and usernames, wallet addresses, transaction hashes, and the deposit site domain or IP — in the structured cyber event fields or as an attachment.

Is pig butchering a fraud problem or an AML problem?

Both, and treating it as one or the other is why most institutions detect it late. The outbound victim payment is a fraud event. The inbound mule account, the shell entity, and the stablecoin conversion are AML events. FATF's February 2026 report found that 156 jurisdictions, or 90 percent of those it has assessed, now identify fraud as a major money laundering risk.

Why do victims keep sending money after the bank warns them?

Because most of them do not believe they are victims. The FBI's Operation Level Up found that 78 percent of the victims it notified in 2025 were unaware they were being scammed. Victims who are blocked frequently route around the block — going in-branch, splitting the payment, or opening an account at a second institution where there is no transaction history to compare against.

What is the single strongest transactional red flag?

A transfer annotated as covering "taxes," "fees," or "penalties" required to release funds from an investment platform. Legitimate exchanges do not collect withdrawal taxes, so the precision of this signal is unusually high. The limitation is timing — it appears in the final phase of the scam, after most of the loss has already occurred.

Does blocking the payment actually prevent the loss?

Not reliably at a single institution. Blocked victims commonly move the payment to another bank, and the second institution has no prior activity baseline for comparison. This is the operational argument for information sharing under Section 314(b) and for building receiving-side controls, where the institution has more leverage and a customer with no motivation to argue.

Get Your Free AI Compliance Handbook

What compliance leaders need to know about AI-driven fraud, autonomous laundering, and how your team can
fight back.
Submit
Thank you! Your submission has been received!
Something went wrong while submitting the form. Please try again.