ADVERTISEMENT
Fraud, Scams & Cybercrime
02:53 AM 27th July 2026 GMT+00:00
Indonesian Banks Warn Mule Accounts Are Bypassing Scam Controls
Analysis by Bradley Maclean
ADVERTISEMENT
Roundtable participants said onboarding checks verify customer identity but not intent, allowing mule networks to flourish and drain funds before freezes take effect.
Indonesian bank compliance heads say their onboarding controls verify who a customer is, but not what an account will ultimately be used for – and that this limitation allows mule accounts to bypass checks, lie dormant for months and activate only once funds are already moving.
At a closed-door roundtable in Jakarta, bank executives said the binding constraint was no longer detection technology but the speed of coordinated response, the legal basis for information sharing, and how quickly victims report losses.
“Everything is right during the onboarding,” one compliance head said, describing accounts that pass digital checks, sit dormant for two or three months and activate in the fourth or fifth month. “That’s the time when it hits our alert in the system.” By then, participants said, much of the money has already gone.
The roundtable discussion was convened on 30 June by Regulation Asia in partnership with SymphonyAI, bringing together financial crime heads from several large retail banks and the Global Anti-Scam Alliance (GASA).
Participants discussed the Indonesia Anti-Scam Centre (IASC), which has since its launch in 2024 received more than 608,000 reports as of June 2026 and frozen about IDR 674 billion (USD 37 million). Of this, close to IDR 200 billion (USD 11 million) has been returned to victims.
Reported losses stood at IDR 9.1 trillion (USD 506 million) for 2025, the Financial Services Authority (OJK) announced in January.
Speed and scale
Brian Hanley, APAC director of GASA, said Indonesia was among the highest-volume scam markets globally, citing research showing 66% of Indonesian adults encountered a scam in 2025. Under-reporting makes precise totals difficult, he said, though some estimates place scam proceeds at 1% to 2% of global GDP.
Investment and job scams are expanding fastest, he said, while generative AI has lowered barriers to impersonation and manipulation. Roughly three-quarters of people believe they can identify a scam, Hanley noted, yet a similar proportion struggle to detect deepfakes. “In scams, speed kills,” he said. “The scammers are counting on you to act fast.”
Participants at the roundtable said that the speed advantage has become structural. Indonesia’s BI-FAST transfers and QRIS merchant payments settle within seconds, while freeze coordination and investigations take hours or days. “Fifty percent or more of the funds are already gone by the time we freeze the account,” one participant said.
Victim reporting delays compound the gap. OJK has said victims in some markets report losses within about 10 minutes, while average reporting times in Indonesia have been significantly longer – by which point funds may have cascaded across multiple accounts.
Identity verified but not intent
The participants described a mule recruitment model in which intermediaries collect identity cards in rural areas, assist residents in opening accounts digitally, and later transfer control to syndicates. In some cases, mobile numbers and SIM cards are also handed over, granting access to one-time passwords.
A key issue highlighted was that electronic KYC checks verify identity credentials but do not assess behavioural intent. “E-KYC is really on identity verification,” said Jordan Hoo, an AML consultant at SymphonyAI. “But do we have the layer of intent verification? Why did you open that account?”
Banks said networks often target individuals with no prior banking history and therefore no behavioural baseline in internal systems. As a result, misuse is typically identified only once high-velocity transactions begin.
Several participants said detection models at Indonesian banks remain largely transaction-triggered and reactive, reflecting an infrastructure built for monitoring flows rather than anticipating network recruitment.
Managing alerts vs disrupting networks
Asked how effectiveness should be measured, Hanley said some jurisdictions were shifting from reporting volumes toward outcome indicators such as disruption of entire mule networks, asset recovery rates and repeat victimisation.
The participants acknowledged that most current metrics remain activity-based – focused on alerts cleared, reports filed and accounts closed – rather than structural ecosystem disruption.
Several said governance frameworks were designed for a “batch-era” banking system, while criminal networks now operate at real-time velocity across banks, telecoms providers and digital platforms.
Funds outrun the freeze
Coordination of account freezing in Indonesia is routed through the IASC, which banks join voluntarily. Participants described the speed mismatch between instant settlement and slower investigative processes as the defining constraint.
The freeze mechanism also creates operational strain. Because fraud definitions applied at the reporting stage are broad, commercial disputes are sometimes filed as fraud claims, requiring banks to freeze accounts with limited ability to verify allegations and generating customer complaints that are difficult to resolve.
The participants suggested that the core challenge lies less in detection rules than in having coordination architecture that operates at the speed of instant settlement.
Friction, competition, and inclusion
Hanley said the UK, Singapore and Australia were among the few jurisdictions to record sustained reductions in scam losses – after they introduced payment frictions alongside shared-responsibility frameworks that allocate liability across banks, telecoms operators and platforms.
“Maybe speed is the problem,” he said, explaining the unintended consequences of instant payments. “Maybe banks shouldn’t be racing to keep up. Maybe we should be focusing more on protecting our customers.”
The participants from Indonesian banks did not advocate for slowing down payments, but described selective friction already in place. They said fraud teams at several banks operate around the clock, calling customers to verify transactions before release when risk scenarios are triggered.
One participant said their institution had accepted some reduction in customer experience – including blocking transactions pending verification – at ongoing resourcing cost. Others noted that false positives limit scalability, particularly where alerts are processed sequentially or if higher-risk cases are not prioritised first. Competitive pressure from e-wallet providers and fintech firms also makes slowing down payments difficult, several participants argued.
Yet, inserting friction into payments intersects with Indonesia’s financial inclusion agenda. Some participants noted that a portion of the population remains outside formal banking channels by choice rather than means, preferring cash or cryptocurrency to avoid visibility. Additional barriers risk pushing activity into channels banks cannot monitor.
Fraud and AML alignment
Contrary to perceptions of fragmentation, the participants said fraud and AML functions are increasingly aligned operationally, even though the units are structurally separate.
Fraud monitoring typically operates in real time and escalates cases to AML teams where suspicion persists. Several banks said post-pandemic growth in scams and high-profile cyber incidents had forced closer coordination between the units.
SymphonyAI’s Hoo advocated a transition to an “AI-First Investigation Model”, which uses autonomous agents to fuse fragmented data into a single, dynamic evidence board and consolidates alerts into a single enterprise case management system.
This model “completely eliminates legacy handoff delays and ensures unbroken investigative continuity,” he added.
AI ambition constrained by data
A discussion on the use of AI by Indonesian banks revealed significant data challenges. Participants cited incomplete customer records, inconsistent identity fields across systems, outdated documentation, and limited historical behavioural baselines as constraints on model effectiveness.
One participant questioned how AI tools could be built on “dirty data”. In response, Hoo noted that data lineage work, governance frameworks and synthetic data could partially address these issues, but emphasised that explainability, audit logs and human review are needed as well to ensure outputs remain defensible under supervisory scrutiny.
The roundtable participants broadly agreed that AI may accelerate case handling and alert triage, but cannot compensate for structural gaps in identity verification, KYC or cross-institution coordination.
Sharing without structure
The participants said Indonesia’s personal data protection law has made institutions cautious about sharing customer information, and that no formal mechanism exists for systematic bank-to-bank intelligence exchange. Some information is shared informally when cases overlap, they said, but broader exchange lacks a clear legal basis.
Hanley described fragmentation as a key weakness, noting that effective disruption requires coordinated information flow across banks, telecoms operators and digital platforms.
He pointed to the Global Signal Exchange, launched in January 2025, which he said holds more than 1.4 billion scam-related signals – including URLs, phone numbers and account identifiers – with roughly one million exchanged daily.
In Indonesia, he noted that only a subset of banks actively participates in coordinated freeze and signal-sharing processes, leaving significant parts of the ecosystem outside structured collaboration.
What participants would change
Asked to identify a reform that would materially reduce scam losses, participants most frequently cited public education, particularly outside major cities.
Several also called for enforceable consequences for selling or renting bank accounts, arguing that prevention at the mule recruitment stage would be more effective than faster downstream detection.
Other proposals included stronger law enforcement coordination and clearer allocation of authority between Bank Indonesia, OJK and the Financial Transaction Reports and Analysis Centre (PPATK).
In addition, the participants called for tighter governance of cryptocurrency accounts that can be used to launder proceeds, a national digital identity that can link to a single phone number, broader financial literacy initiatives, and a shift toward behavioural monitoring rather than purely transaction-based detection.
Upstream vulnerability
OJK is developing a National Fraud Portal within the IASC to accelerate report collection, information exchange, and tracing of suspected fraudulent transactions. Officials have acknowledged that the speed of account blocking largely determines whether funds can be preserved.
Participants said, however, that the system’s vulnerability sits upstream of the freeze. Instant settlement rails, digital onboarding at scale, and fragmented coordination have altered the tempo of financial crime faster than institutional response models have adapted.
As one attendee summarised: “We are very good at managing alerts. But dismantling networks is something else.”
--
This article was produced by Regulation Asia in collaboration with SymphonyAI, which provides AI-native financial crime compliance and risk management solutions for financial institutions.
Read SymphonyAI's leader’s guide and learn how to transform financial crime compliance from reactive operations into an always-on, intelligence-led advantage.
Related stories
JOIN OUR NEWSLETTER
An exclusive weekly selection of top stories from the Regulation Asia editorial team.






