HomeIntelligenceBrief
BREACH BRIEF 🟠 High ThreatIntel

Treasury Urges Banks to Report Cyber Scams as Losses Near $13 Billion

FinCEN’s latest study of 33,000 fraud reports reveals roughly $13 B stolen via crypto and wire‑transfer scams. The surge underscores the need for continuous monitoring, documented awareness training, and a repeatable reporting workflow to meet regulator expectations.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 therecord.media
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
therecord.media

Treasury Urges Banks to Report Cyber Scams as Losses Near $13 Billion

What Happened — FinCEN released an alert and a study of 33,000 cyber‑fraud incident reports filed between Sept 2023 and Dec 2025. The analysis shows ≈ $12.7 B stolen from Americans in cryptocurrency‑investment scams and ≈ $6.4 B lost through traditional bank‑wire fraud, with reporting institutions increasing submissions by ~11 % month‑over‑month.

Why It Matters for Trust & Control Assurance

  • Continuous transaction monitoring and automated anomaly detection are core controls that can surface the early stages of “pig‑butchering” and wire‑transfer scams, providing the evidence needed for audit‑ready reporting.
  • Documented security‑awareness training and phishing‑simulation programs give institutions defensible proof that human‑risk controls are in place, a key requirement for many governance frameworks (e.g., NIST CSF 2.0 Detect).
  • A formal, repeatable reporting workflow satisfies regulator‑driven evidence‑collection expectations and reduces the gap between detection and FinCEN notification.

Who Is Affected – Banks, credit unions, crypto‑exchange platforms, fintech firms, and other financial‑services providers that process wire transfers or digital‑asset transactions.

Recommended Actions

  1. Map your transaction‑monitoring and suspicious‑activity‑reporting (SAR) processes to the NIST CSF Detect function and capture evidence in a centralized Trust Center.
  2. Deploy or refresh security‑awareness training focused on social‑engineering and crypto‑investment scams; track completion and test results as audit artifacts.
  3. Formalize a reporting playbook that logs detection timestamps, investigative steps, and FinCEN filing details for each incident.

Technical Notes – Scammers employ social‑engineering personas (romantic partners, “financial advisers”) to coax victims into wire transfers or crypto purchases. No software vulnerability is cited; the attack vector is primarily phishing/social engineering. Source: https://therecord.media/treasury-urges-banks-report-cyber-scams

📰 Original Source
https://therecord.media/treasury-urges-banks-report-cyber-scams

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →