Scams are a network problem - Fighting Fraud at the AFI Global Policy Forum

By Dr Amanah Ramadiah, Director Asia Pacific


I have just come back from Port Moresby. This was my third time in the city, having visited twice before through our work with the Bank of Papua New Guinea on suptech for its Payment Oversight, Compliance and Monitoring Office (see here).


Last week I was there to join central bankers from around the world at the Alliance for Financial Inclusion (AFI) Global Policy Forum, and I spent much of the week meeting colleagues from across AFI's member countries. I was also grateful for the opportunity to speak on two panels on fraud and scams: one on protecting consumers, alongside central bankers from Armenia, Namibia, El Salvador, and the Philippines, and one on data sharing between institutions, with colleagues from the central banks of Sri Lanka and Zimbabwe and from The Asia Foundation.

Why we can't leave consumers to fight scams alone

My point across both sessions was that no single institution, and no single fix, stops scams on its own. Getting ahead of them takes collaboration on several fronts at once: education, coordination between institutions, sensible policy, and the right technology. Rely on any one of those fronts alone, and the defence will not hold.


Public health is a useful comparison here. We teach people to wash their hands, and it helps, but we never expected hygiene on its own to stop an epidemic. We also built the quieter machinery around it: ways to spot an outbreak early, trace it, and contain it before it spreads. With scams, I think we have leaned heavily on the hand-washing, and we are only now starting to build the machinery.

Education matters, but it can't carry the weight

None of this is meant to diminish financial education. The people who do it well are up against a great deal, and good awareness raises the floor. But scams tend not to succeed because someone didn't know better. They succeed in a moment of fear, or hope, or simple hurry, and that moment is exactly what they are built to exploit. That is why the victims are so often not who we picture. Careful, well-informed people are caught all the time, because knowledge is a thin defence against being rushed by someone who does this for a living.


The scams growing fastest make the point. They are the ones where the customer is persuaded to send the money themselves. Most of the controls we have built assume the customer never meant to pay, and in these cases they did. A warning leaflet rarely survives contact with a convincing voice and a ticking clock.

We are facing a network, and fighting it in silos

The other difficulty is that the people running these scams have become far more organised, working across borders and increasingly using artificial intelligence (AI) to clone a voice or tailor a lie at scale. Even the mules who move the money are often coerced or deceived themselves, so a heavy-handed response can end up catching the wrong people.


What we are up against behaves like a network, and most of us, my own industry very much included, are still set up to fight it one institution at a time. Any single bank only ever sees its own corner, and the money does not stay in one corner for long.

Where losses have come down

What has struck me, looking at the places where losses have fallen, is that the fall rarely comes down to a better campaign. It tends to come from institutions choosing to act together.


Malaysia's banks can now trace stolen money across the system in around 30 minutes, work that used to take days, and that is where the gains have shown up. Singapore recorded its first fall in scam losses in 2025, to S$913 million from S$1.1 billion the year before, with cases down 24.8%, and the Singapore Police Force was careful to credit a combination of enforcement, pressure on the platforms, and education together, rather than any single measure. Indonesia shows the same point from the harder side: when a scam is reported hours later rather than minutes later, the money has usually gone, so the system itself has to be quick.


In public-health terms, this is tracing and containment. See the scam early, follow the money across institutions, and stop it before it scatters.

Time is not on our side

As more countries switch on instant payments, stolen funds can be gone in seconds, and no awareness campaign works on that timescale. We have tended, collectively, to build the rails first and think about the criminals afterwards, so the defences usually arrive as a retrofit, which is harder and more costly than building them in. The countries putting their systems in place now have a real head start, if they design those systems with protection built in from the beginning.


This is also why a national anti-scam utility, the shared infrastructure that lets banks, payment providers, regulators, and police detect, trace, and freeze scam payments as one system, is not one tool but several, working together across the moment money moves. Before a payment settles, real-time scoring and graph analytics can flag a suspicious transaction, and even interdict it, before the money leaves. That is the detection side. Once the payment has settled, tracing follows the funds as they hop across banks and rails so they can be frozen and returned, and the mule accounts behind them identified. That is the recovery side. Around those two sit the pieces that let them work at national scale: shared case management, so investigators across institutions work from the same view; a secure exchange for passing fraud intelligence, account data, and device data between banks and with supervisors; and lighter modules such as Confirmation of Payee and complaints handling. All of it rests on a common data layer, which is what lets these parts talk to each other rather than becoming yet another set of silos.


None of it has to follow a single template. The design can be shaped around a country's own payment systems, and run as a centralised, distributed, or hybrid network, whichever suits.


The encouraging part is that we are not starting from theory. A few countries have now built the shared version, and it is reasonably clear what it takes: the legal basis to share data, freeze funds, and return money to victims; a trusted operator, and enough of the banks and payment providers willing to join; funding that lasts beyond the first grant; and, on the technology side, a common data layer, a secure real-time exchange that protects people's privacy, and a design that keeps each country's data under its own control. Colleagues at FNA and I tried to set this out in a paper, A Blueprint for Building National Anti-Scam Utilities, so that others do not have to begin from a blank page.


Education still matters, and we should keep at it. But it asks too much to expect any of us to be the last line of defence on the day a scam finally lands. The coordination, the policy, and the shared infrastructure behind the scenes are what should carry that weight, and building them is a shared job, not the consumer's alone.


My expectation is that within a few years the question for most central banks will no longer be whether to build a national anti-fraud network.

Common questions

What is the difference between fraud and a scam?

In fraud, the payment is unauthorised: someone gets hold of a customer's card or credentials and moves money without their knowledge. In a scam, the customer is deceived into authorising the payment themselves. Most bank controls were built for the first case, which is why scams slip through so easily. We set out why the two need different defences in Fraud vs scams: the architectural shift required to protect real-time payments.

What is a national anti-scam utility?

It is shared infrastructure that lets banks, payment providers, regulators, and law enforcement detect, trace, and freeze scam payments as one system rather than institution by institution. It typically combines real-time detection before a payment settles with tracing and recovery after it does, backed by shared case management and a secure exchange for fraud intelligence. Our national anti-scam utilities page explains how the pieces fit together, and the National Anti-Scam Utility Resource Library collects the underlying research.

How does a fraud portal trace stolen money across banks?

Once a victim reports a scam, the portal follows the funds as they move from the receiving account through mule accounts and across payment rails, using graph analytics to map the network rather than a single transfer. Investigators at every bank in the chain work from the same view, so a trace that used to take days of phone calls and emails can be completed in minutes and the funds frozen before they are withdrawn. See FNA Fraud Portals for how this works in practice.

Which countries have already built one?

Malaysia is the most developed example. PayNet's National Fraud Portal, built with FNA, connects the country's banks so stolen funds can be traced across the system in around 30 minutes. The portal won at the 2025 Tackling Economic Crime Awards, and the Money Trails work behind it was recognised by Central Banking in 2025. Singapore and several other markets are running shared models of their own.

Does a country need new laws before it can build one?

Usually some change is needed. The three legal questions that come up most often are whether banks can share customer and account data with each other for fraud purposes, whether funds can be frozen on suspicion before a court order, and how recovered money is returned to victims. The Blueprint for Building National Anti-Scam Utilities covers the legal basis alongside the operating model, funding, and technology.

Related reading

  • Fraud portals — how financial authorities build shared, national fraud-fighting capability

  • FNA papers — our research on financial networks, payment systems, and systemic risk

  • Insights — more from the FNA team

Next
Next

What the Silk Road teaches us about trust in agentic payments