CiberLATAMbywhalemate

U.S. Treasury urges more cyberfraud reports

The U.S. Treasury asked banks and fintechs to step up cyberfraud reporting, citing losses of nearly $13 billion since 2023.

Whalemate Labs · AI-assisted researchPublished:4 min read

The U.S. Treasury Department urged banks, credit unions, crypto exchanges, fintechs, and other financial providers to strengthen how they identify and report cyberfraud schemes. The push centers on suspicious activity reports, or SARs, tied to scam centers abroad, amid losses estimated at nearly $13 billion since 2023, according to a summary of official statements.

The U.S. Treasury Department has asked banks, credit unions, crypto asset exchanges, fintechs, and other financial service providers to strengthen the identification and reporting of cyberfraud schemes. The directive focuses on suspicious activity reports, or SARs, for operations linked to scam centers overseas, and draws on estimates that put losses at nearly $13 billion since 2023.

What did the Treasury ask financial institutions to do?

The Treasury urged institutions to use suspicious activity reports more diligently to detect and document cyberfraud, especially when there are links to scam centers outside the United States. According to coverage by The Record and a summary from Verisq, the guidance applies to banks, credit unions, crypto asset exchanges, fintechs, and other financial providers.

Coverage from NatLawReview added that FinCEN wants all available technical cyber indicators included in SARs. These include chats, phone numbers, social media usernames, email addresses, digital asset types, blockchain addresses, transaction hashes, app names, and URLs. It also said that institutions filing SARs tied to scam centers should include the identifier FIN-2026-SCAMCENTERS in the note field and narrative, and choose Fraud, Other with the description Scam Centers.

What scale of losses did the U.S. government cite?

Specialized coverage cited in the material points to nearly $13 billion in losses since 2023 linked to these schemes, although that figure is presented as an aggregated estimate in news reports and risk intelligence analysis, not as a standalone number from a single official statement.

The Record, in a summary of Treasury statements, and Verisq.ai both referred to that figure. In Verisq’s case, the amount appears as part of a risk intelligence reading of the call to increase cyberfraud reporting.

What other regulatory signals is Washington sending to banks and fintechs?

The Treasury warning comes alongside other supervisory moves in the U.S. financial system. The Federal Reserve, the FDIC, and the OCC issued a joint statement to clarify their risk-based supervisory approach to certain services provided by core providers to community banks, with attention to cyber risks and operational resilience tied to essential outsourced services.

At the same time, federal regulators, the Federal Reserve, the FDIC, the OCC, and the NCUA, proposed updated third-party risk management guidance for banks and credit unions. The goal is to tighten oversight of technology and information security vendors that directly affect the financial sector’s cybersecurity controls.

The OCC and the FDIC also adopted a final rule on Aug. 27, 2026, that codifies the definition of unsafe or unsound practice under Section 8 of the Federal Deposit Insurance Act and revises the framework for MRAs and other supervisory communications. Reuters said the measure is meant to guide supervision and enforcement around material financial risks, and that MRAs will normally require a reasonable expectation of material harm or a banking or bank-related legal violation.

What does this mean for banks using AI and model-based systems?

The interagency model risk management guidance was rewritten in April 2026 to narrow the definition of model to complex quantitative methods, leaving generative and agentic AI outside its formal scope, according to specialized analyses cited in the material. For models that do fall under the guidance, inventory, independent validation, and performance monitoring requirements remain in place.

The same set of analyses argues that advanced AI governance now sits within broader risk and control frameworks, separate from that specific guidance. In practice, that pushes institutions to handle generative and agentic AI under compliance schemes that differ from those applied to traditional models.

What other security practices are regulators reinforcing?

The technical notes gathered in the material show that the FFIEC continues to use its handbooks and shared examination standards to assess information security practices, including secure destruction of customer data during disposal processes. They also note that the interagency guidance on authentication and access considers single-factor, single-layer controls inadequate for high-risk activities and points institutions toward layered controls and multifactor authentication.

In BSA and AML, a sector analysis published in 2026 reported 42 enforcement actions in 2024, up from 29 in 2023, with more penalties against institutions with less than $1 billion in assets. That review cites cases involving gaps in suspicious activity monitoring, customer due diligence, governance, staffing, independent testing, and training, including OCC orders against TD Bank, Summit National Bank, and Community Federal Savings Bank.

What is on the radar for post-quantum cryptography?

The post-quantum cryptography debate is already on the U.S. banking agenda, with transition timelines that, according to analyses cited in the material, combine planning between 2025 and 2027, risk assessments through 2029, and full execution by 2034. Another analysis adds that NIST expects to retire quantum-vulnerable algorithms after 2030 and discontinue most of the rest by 2035.

Those same texts say financial institutions should move ahead with cryptographic inventories and cryptographic agility. As a point of comparison, Moneycontrol reported that India’s RBI is already pushing banks and fintechs to begin quantum-proofing their systems, a signal the material links to Latin American subsidiaries operating under multinational cyber resilience standards.

Sources

View all