FinCEN’s Rapid Response Program Interdicts More Than $1.8 Billion in Cyber-Fraud Proceeds

FinCEN’s Rapid Response Program has helped stop more than $1.8 billion in cyber-enabled fraud proceeds from being transferred beyond recovery.
Since the program began in 2015, more than $1 billion has been recovered on behalf of 5,790 U.S. victims. The cases have involved beneficiary accounts and financial institutions across 96 foreign jurisdictions.
The figures demonstrate an important feature of modern fraud prevention: detecting a suspicious payment is not always enough. Once money has been transferred abroad, the ability to recover it depends heavily on how quickly the victim, financial institution, law enforcement agency and foreign authorities can act.
For banks and payment institutions, fraud reporting is therefore not only a retrospective compliance function. In time-sensitive cases, it can become part of the asset recovery process.
How the Rapid Response Program Works
The Rapid Response Program, or RRP, connects three groups:
- FinCEN, acting as the U.S. financial intelligence unit;
- U.S. law enforcement agencies; and
- Foreign financial intelligence units and competent authorities.
The process usually begins when a victim or the victim’s financial institution reports the fraud to law enforcement. This may involve a complaint to the FBI’s Internet Crime Complaint Center or contact with a U.S. Secret Service field office.
Law enforcement reviews the complaint and, where the funds have been transferred to a foreign beneficiary account, refers the case to FinCEN.
FinCEN can then rapidly share relevant financial intelligence with its counterpart financial intelligence unit in the receiving jurisdiction. The foreign authority may use its own legal powers to contact financial institutions, trace the transfer, place funds on hold or support their return.
The process can be summarised as follows:
- The victim discovers the fraudulent transfer;
- The victim immediately informs its financial institution and law enforcement;
- Law enforcement confirms the transaction details and refers the case to FinCEN;
- FinCEN contacts the relevant foreign financial intelligence unit;
- Foreign authorities attempt to locate and stop the funds; and
- The participating authorities coordinate possible recovery and repatriation.
FinCEN does not receive complaints directly from victims. The program is activated through law-enforcement referral.
Interdicted Does Not Always Mean Recovered
FinCEN reports two different figures for the program:
- More than $1.8 billion interdicted; and
- More than $1 billion recovered.
The distinction is important.
“Interdicted” generally means that authorities successfully located and stopped, froze or otherwise prevented the suspected fraud proceeds from moving further.
“Recovered” refers to funds that were ultimately returned or made available for return to victims.
A successful freeze does not automatically result in immediate repayment. Recovery may still depend on:
- The law of the receiving jurisdiction;
- Evidence establishing that the transfer was fraudulent;
- Competing claims over the account;
- Court or administrative procedures;
- Cooperation from the receiving financial institution; and
- The stage at which the funds were located.
The gap between the two figures illustrates why asset recovery is both a financial and legal process.
Business Email Compromise Remains the Largest Category
Business email compromise, commonly known as BEC, accounted for approximately $425.2 million of the funds interdicted through the program.
BEC schemes typically involve criminals compromising or impersonating a business email account and sending fraudulent payment instructions.
Common examples include:
- A supplier’s invoice being replaced with false bank details;
- An employee receiving an apparent instruction from a senior executive;
- A property purchaser being sent fraudulent settlement instructions;
- A company being told that a vendor has changed its bank account; and
- An employee’s email account being used to redirect a genuine payment.
BEC can be particularly damaging because the payment is often properly authorised from the bank’s perspective. The customer may use their usual device, pass authentication checks and approve the transfer themselves.
The fraud lies in the payment instruction, not necessarily in the mechanics of the transaction.
This means that conventional account-takeover controls may not detect the risk. Effective prevention may also require:
- Confirmation of changed beneficiary details;
- Additional checks for unusually large first-time payments;
- Warnings when customers amend payment instructions;
- Behavioural analysis;
- Verification through a previously established communication channel; and
- Rapid escalation when a customer reports suspected impersonation.
Investment Fraud Can Produce Repeated Transfers
The program has also interdicted approximately $49.8 million connected with investment fraud.
Investment scams often develop over a longer period than BEC. Victims may be persuaded to make several payments after being shown false investment returns or fabricated account balances.
The scheme may involve:
- Fake online investment platforms;
- Cryptocurrency investment offers;
- Social media advertisements;
- Impersonation of legitimate financial professionals;
- Relationship-based or “pig-butchering” scams;
- Requests for additional tax or withdrawal fees; and
- Transfers to multiple overseas accounts or wallets.
The first payment may be relatively small. Larger transfers follow after the victim believes the investment is profitable.
For financial institutions, the pattern may be more important than any individual transaction. Relevant indicators can include:
- A customer with no previous investment activity making repeated international transfers;
- Payments to newly established beneficiaries;
- Transfers to personal accounts described as investment payments;
- Customers liquidating savings or borrowing to fund further payments;
- Sudden interest in virtual assets following online contact;
- Payments to several unrelated recipients associated with the same platform; and
- A customer continuing to transfer funds after receiving fraud warnings.
Intervention may require more than displaying a standard scam notice. Where indicators are strong, the institution may need to speak directly with the customer and understand the claimed investment.
Phone Scams Create Urgency and Fear
FinCEN reported approximately $54.5 million interdicted in connection with phone scams.
These schemes frequently rely on urgency, fear or the apparent authority of the caller.
Criminals may impersonate:
- Government officials;
- Police or tax authorities;
- Bank fraud departments;
- Technology support providers;
- Utility companies;
- Courts or immigration agencies; or
- Family members claiming to face an emergency.
The victim may be instructed to move funds to a supposedly “safe” account, purchase virtual assets, send an international transfer or provide remote access to their device.
The transaction may appear voluntary, but the customer is acting under deception or coercion.
Financial institutions should therefore treat certain behavioural indicators seriously, including customers who:
- Appear unusually distressed or secretive;
- Say they have been told not to discuss the payment;
- Describe transferring funds to protect them from fraud;
- Receive instructions while speaking to someone on the phone;
- Suddenly send savings to an unfamiliar individual;
- Attempt to override repeated warnings; or
- Make payments inconsistent with their normal activity.
Frontline staff can play an important role because the customer’s behaviour may provide information that transaction data alone cannot reveal.
Why Reporting Speed Matters
Cyber-fraud proceeds can move through several accounts shortly after the initial payment.
A receiving account may transfer the money to:
- Another domestic bank;
- An overseas account;
- A money mule network;
- A payment platform;
- A virtual asset exchange; or
- Multiple beneficiaries in smaller amounts.
Each additional transfer reduces the likelihood that the full amount will remain available for recovery.
A delay of several days may allow the proceeds to be withdrawn, converted or transferred through jurisdictions where recovery becomes more difficult.
FinCEN’s fact sheet therefore states clearly that time is of the essence.
Victims should contact their financial institution immediately. Financial institutions should not wait for the completion of an internal fraud investigation before taking reasonable recovery steps.
Where appropriate, the institution may need to:
- Contact the receiving institution;
- Attempt a payment recall;
- Preserve transaction and communication records;
- Escalate the case internally;
- Notify law enforcement;
- Provide complete beneficiary and routing information; and
- Consider relevant suspicious activity reporting obligations.
A suspicious activity report remains important, but filing a SAR alone may not activate the Rapid Response Program or stop an outgoing transfer in time.
The Quality of the Initial Report Also Matters
Speed is essential, but an incomplete report can delay the response.
Financial institutions should be prepared to provide accurate information such as:
- The date and time of the transfer;
- The amount and currency;
- The originating account;
- The beneficiary name and account number;
- The receiving bank;
- Intermediary or correspondent institutions;
- Transaction references;
- SWIFT or payment messages;
- The reason the payment is believed to be fraudulent;
- Related communications or invoices; and
- Details of any subsequent attempted transfers.
Where virtual assets are involved, useful information may include:
- Wallet addresses;
- Transaction hashes;
- The relevant blockchain;
- The exchange or hosted wallet provider;
- The time of the transfer; and
- Available customer or counterparty information.
Standardised internal procedures can reduce the time needed to collect this information after a fraud report is received.
Financial Institutions Should Connect Fraud Response and AML
The RRP also highlights the operational relationship between fraud controls and AML.
The sending institution may see a victim making an induced payment. The receiving institution may see a money mule account receiving and rapidly dispersing funds.
The same transaction can therefore generate different risks at each institution:
- Customer protection risk for the sending institution;
- Money laundering risk for the receiving institution;
- Asset recovery considerations for both;
- Suspicious activity reporting obligations; and
- Possible information-sharing needs.
Fraud and AML teams should be able to share relevant information quickly.
A fraud report should be capable of triggering:
- Review of the beneficiary and connected accounts;
- Reassessment of customer risk;
- Examination of earlier incoming payments;
- Identification of related victims;
- Transaction restrictions where legally permitted; and
- Consideration of a SAR.
Similarly, an AML investigation into a suspected mule account may identify victims whose financial institutions need to be contacted urgently.
What Financial Institutions Should Review
The results of the Rapid Response Program suggest several practical questions for financial institutions:
- Can customers report a fraudulent transfer at any time?
- Are urgent international fraud cases escalated immediately?
- Do staff know when and how to contact law enforcement?
- Can complete payment information be retrieved quickly?
- Are recall requests initiated without unnecessary delay?
- Do fraud and AML teams share information on beneficiary accounts?
- Can the institution identify other customers who paid the same recipient?
- Are suspected mule accounts reviewed across the full relationship?
- Are SARs filed accurately without delaying urgent recovery action?
- Are major fraud incidents used to improve monitoring and customer warnings?
The effectiveness of a fraud response process should be measured not only by whether a case is eventually investigated, but also by how quickly the institution acts while the funds remain recoverable.
The Compliance Takeaway
FinCEN’s Rapid Response Program demonstrates that international cooperation can recover substantial cyber-fraud proceeds, but only when the relevant institutions act quickly.
BEC, investment fraud and phone scams use different forms of deception. Their financial outcome is often similar: an apparently authorised payment is sent to an account controlled by criminals and rapidly transferred across borders.
The opportunity to intervene may be brief.
Financial institutions therefore need processes that connect customer reporting, fraud investigation, AML review, law-enforcement referral and international asset recovery.
In cyber-enabled fraud cases, reporting speed is not merely an administrative performance measure.
It can determine whether the money is stopped, recovered or lost.
Main Sources
FinCEN — FinCEN’s Rapid Response Program Interdicts Nearly $2 Billion on Behalf of U.S. Cyber-Enabled Fraud Victims
FinCEN — Rapid Response Program Fact Sheet
https://www.fincen.gov/system/files/2026-04/RRPFactSheet.pdf



