fraud high risk

Romance Scam: How It Works, Red Flags, and How to Detect It

Published: Last updated: Also known as: pig butchering Industries: banking,fintech,crypto

Romance scam (also called pig butchering) is a high-risk fraud typology in which organized criminals build fake romantic or social relationships online to gain a victim's trust, then manipulate them into transferring funds, typically to cryptocurrency wallets or overseas accounts. It's among the fastest-growing fraud categories by total financial loss globally.

What is Romance Scam?

Romance scam, also known as pig butchering from the Mandarin criminal slang "sha zhu pan," is a fraud typology in which organized criminal networks build fake emotional relationships with victims online, then manipulate them into transferring money to fraudulent investment platforms or overseas accounts. It falls into the fraud category of financial crime, though the downstream money movement typically involves money mule networks and multi-hop layering structures.

An offender creates a convincing online profile, often using stolen photos of real people presented as military personnel, offshore engineers, or medical professionals. Contact happens through dating apps, social media, or misdirected text messages. The grooming period runs from weeks to months. Once trust is established, money requests begin: a medical emergency, a business deal requiring a bridge loan, legal fees to release frozen assets. Each request is framed as temporary and urgent.

The pig butchering variant works differently. The scammer introduces a fraudulent crypto trading platform, shows the victim fabricated portfolio gains, and encourages escalating deposits. There's no direct request for emergency funds. The victim believes they're making money. When they try to withdraw, the platform demands additional "tax" payments before releasing funds, then disappears entirely.

The Investment Scam overlap is important to understand. Pig butchering is technically an investment fraud embedded within a romance scam structure, and the proceeds follow identical laundering paths: victim funds convert to cryptocurrency, move through multiple exchange accounts, and land at addresses linked to organized crime networks operating from Southeast Asia.

The scale is significant. The FBI's Internet Crime Complaint Center received 19,021 romance scam complaints in 2023, with reported losses of $652.5 million, per its 2023 Annual Report. Investment fraud overall, much of it pig butchering, accounted for a further $4.57 billion that year. The real figures are higher. The Global Anti-Scam Organization estimates fewer than 5% of victims report, because shame and disbelief prevent disclosure. The UK's National Fraud Intelligence Bureau recorded parallel trends, with authorized push payment fraud linked to romance scams rising year-on-year.

Victims aren't exclusively elderly or unsophisticated. IC3 data consistently show the highest-loss demographic is 30 to 49. Pig butchering operations specifically target high-income professionals: investors, engineers, and executives hold larger accounts and respond to investment framing.

The criminal operations behind these schemes are large-scale enterprises. Interpol and Europol investigations have confirmed that many call centers operate in Myanmar, Cambodia, and Laos, inside special economic zones with limited law enforcement access. Workers are frequently trafficking victims themselves, recruited under false job offers and held against their will. A victim sending $50,000 abroad isn't sending money to an opportunistic fraudster; they're funding a criminal enterprise with human trafficking at its core.

The financial institution is often the only viable intervention point. By the time a victim reports to law enforcement, funds have already moved through multiple wallets and accounts across several jurisdictions. A customer sending $50,000 in wire transfers to five different accounts over 30 days, with escalating amounts and new beneficiaries, should trigger a transaction monitoring alert, and recognizing that pattern early is the difference between stopping a loss and filing a SAR after the fact. Romance scam victims rarely self-report to their bank; they see the bank as an obstacle to helping the person they love.


How does Romance Scam work?

The pattern follows five consistent phases.

Phase 1: Contact. The criminal initiates contact through dating apps, social media, LinkedIn, or a "wrong number" text message. The profile uses stolen or AI-generated photographs and a fabricated identity, typically posing as a successful professional living abroad. Singapore, Hong Kong, and major U.S. cities are the most common cover identities used in Southeast Asia-run operations.

Phase 2: Trust-building. Over days to weeks, the criminal invests in daily conversation, emotional support, and manufactured intimacy. There's no financial ask during this phase. The goal is to migrate the victim off the original platform to WhatsApp or Telegram, where the app's fraud reporting tools don't reach.

Phase 3: The lure. The criminal mentions a high-yield investment opportunity, framed as a family trading secret or insider access to a crypto platform. That platform is controlled by the criminal network. Early "investments" generate visible profits on a fake dashboard, and the victim is encouraged to withdraw a small amount to build confidence.

Phase 4: The slaughter. Persuaded by apparent returns, the victim invests larger sums. They may liquidate savings, take personal loans, or borrow from family. When they try to withdraw, the platform demands "fees," "taxes," or "insurance deposits." These are additional theft. No withdrawal ever happens.

Phase 5: Money movement. Victim funds move rapidly through crypto wallets, often via chain hopping and cryptocurrency mixer laundering, before being converted to fiat in jurisdictions with limited asset tracing capability. The full cycle from victim transfer to clean cash can take under 48 hours.

Illustrative scenario: A retail bank customer aged 42, with a monthly transaction average of $800, begins purchasing cryptocurrency through a linked account. Over six weeks, purchases escalate: $2,000, then $5,000, then $8,000, then $15,000. The customer contacts the fraud team twice to dispute holds, stating the transfers are personal investment decisions. A compliance analyst reviewing the case notes no prior crypto activity, a single new payee at an overseas exchange, and two overridden fraud alerts. The bank files a SAR and contacts the customer directly. By then, $31,000 has left the account.


How is Romance Scam used in practice?

From a compliance operations standpoint, romance scam generates two distinct case types: victim protection and money mule detection.

Victim cases arrive through transaction monitoring alerts, contact center notes, and referrals from the fraud team. The behavioral signature is a customer whose outbound transfer pattern changes sharply: higher amounts, new beneficiaries, faster frequency, often accompanied by cash withdrawals or cryptocurrency purchases. When analysts investigate, they find no legitimate business relationship between the customer and the beneficiaries.

Intervention requires care. Victims are emotionally invested. A flat "this is a scam" call often backfires, especially with pig butchering targets who've watched their portfolio "grow" for months. Institutions that reduce losses have trained staff to use motivational interviewing, acknowledging the relationship while presenting specific factual inconsistencies: the beneficiary's IP resolves to Cambodia, the trading platform was registered eleven days ago, the withdrawal request triggered an unsolicited tax demand.

On the mule side, incoming fund reviews are the entry point. Accounts receiving multiple small transfers from unrelated third parties, then forwarding the net balance onward, match classic Money Mule Account behavior. Some of those mules are romance scam victims themselves, forwarding funds because the scammer told them to "help move money" for the relationship.

A Suspicious Activity Report (SAR) is required when the bank has reason to suspect a transaction involves proceeds of criminal activity. For romance scam, that bar is usually cleared by the combination of victim statement, anomalous transfer pattern, and beneficiary account behavior. The SAR narrative should document the victim interaction, the stated relationship, and the specific transactions in chronological order. Sparse narratives that omit the victim's explanation create problems during regulatory examinations.


Red flags and indicators

We've found that no single indicator is conclusive. Detection requires looking at multiple signal types simultaneously.

Transaction-level signals

  • Large outbound wire transfers or crypto purchases from accounts with no prior cross-border transfer history
  • Transfer amounts escalating over 2-8 weeks, each one larger than the last
  • Multiple payment methods funding the same crypto exchange within a short window
  • Funds withdrawn from savings or retirement accounts to support outbound transfers

Account-level signals

  • Previously dormant account suddenly initiating high-value outbound transfers
  • Customer overrides fraud alerts and contacts service teams to explain why the transfer is legitimate
  • No prior crypto history, but two or more exchange accounts opened within a few weeks
  • All new outbound activity concentrating on a single recently added beneficiary

Network-level signals

  • Beneficiary wallets or accounts linked to known romance scam mule infrastructure
  • Multiple unrelated customers sending funds to the same wallet address or account
  • Receiving accounts that empty and forward funds within hours, consistent with layering
  • Beneficiary entity recently incorporated with no visible commercial activity in a high-risk jurisdiction

Behavioral signals

  • Customer becomes distressed or evasive when asked about transfer purpose
  • Customer mentions an online contact they have never met who introduced an investment opportunity
  • Customer service transcripts include phrases: "trading platform," "my friend abroad," "guaranteed returns"
  • Repeated attempts to complete a blocked transfer across multiple service channels

Notable real-world cases

FinCEN Alert FIN-2023-Alert005 (2023). The Financial Crimes Enforcement Network issued a specific alert on pig butchering schemes in September 2023, citing FBI IC3 data showing more than $3.3 billion in victim losses in 2022. The alert lists specific red flags and requires financial institutions to file SARs using the keyword "FIN-2023-Alert005" to enable law enforcement aggregation across institutions. FinCEN Alert, September 2023.

DOJ Operation Level Up (2024). The U.S. Department of Justice and Homeland Security Investigations disrupted multiple pig butchering networks and recovered approximately $6 million in victim funds through civil asset forfeiture of seized cryptocurrency wallets. The operation confirmed that criminal call centers in Southeast Asia run these schemes industrially, often staffed by trafficked workers. DOJ press release, 2024.

Europol and Interpol Operation HAECHI-IV (2023). A 34-country operation resulted in 3,500 arrests and the freezing of $82.1 million linked to online fraud, with pig butchering among the primary typologies identified. The operation confirmed that romance scam proceeds move through decentralized finance laundering structures specifically to frustrate cross-border tracing. Europol press release, November 2023.

FBI IC3 2023 Internet Crime Report. The FBI's annual report recorded $652 million in romance scam losses for 2023, with the 30-49 age cohort reporting the highest aggregate losses. The report specifically notes that victims are frequently not identified until after multiple transfers have already cleared. FBI IC3 Annual Report 2023.


How to detect Romance Scam

Detection requires combining transaction monitoring with behavioral and network signals. Victims authorize their transfers willingly, so rules designed to catch unauthorized transactions won't fire here.

Rule-based detection covers the baseline. Threshold alerts should trigger for large outbound wires or crypto purchases from accounts with no prior cross-border transfer history. Velocity checks should flag amounts escalating in a staircase pattern over 30-60 days. A separate rule should alert when multiple customers route funds to the same beneficiary account or wallet address.

Behavioral analytics adds the account-level view. Peer-group comparison models score customers whose transfer behavior deviates sharply from their cohort. A customer with an established domestic spend pattern who suddenly initiates five-figure international wires is a clear anomaly, even if no individual transaction crosses a reporting threshold. Friction-point scoring (how many times a customer bypassed a fraud warning) adds a behavioral risk dimension that doesn't depend on transaction size alone.

Network graph analysis is the most powerful tool for identifying organized criminal infrastructure. When two or more victims route funds to the same wallet or account, the convergence appears in a network graph before any individual transaction triggers a rule. Beneficiary nodes linked to known mule infrastructure escalate automatically. This approach moves investigators from single-victim cases to disrupting the network operating behind dozens of victims simultaneously.

Customer contact monitoring adds a non-transactional layer. Text analytics on service call transcripts, chat logs, and secure messages can surface romance scam keywords before the next transfer clears.

This pattern overlaps substantially with authorized push payment fraud detection. Institutions building APP detection programs should include pig butchering variants explicitly in their scenario library, as the behavioral signals are near-identical.


Which regulations cover Romance Scam

Under FATF Recommendation 16, financial institutions must verify the stated purpose of international wire transfers, and transfers to overseas accounts linked to romance scams trigger that obligation directly. FATF Recommendation 20 covers the duty to report suspicious transactions without delay. FATF's wider work on virtual assets and fraud-to-laundering pathways addresses the typology specifically, and the reason is speed: a victim wire transfer can convert to cryptocurrency and disperse across multiple wallets within hours of leaving the victim's account.

In the United States, romance scam proceeds trigger Bank Secrecy Act reporting obligations under 31 U.S.C. § 5318(g). FinCEN Advisory FIN-2019-A006, issued September 2019, first identified romance scams as a primary source of money mule activity and directed institutions to file SARs using the "Confidence/Romance Fraud" characterization field. FinCEN Alert FIN-2023-Alert005, issued September 2023, updated that guidance for the pig butchering variant and set a designated keyword for law enforcement aggregation. Filing timelines follow the standard BSA rule: within 30 days of detecting suspicious activity, or 60 days if no suspect is identified.

This isn't a theoretical compliance risk. FinCEN has cited inadequate SAR programs in recent consent orders against mid-sized banks, and OCC and FinCEN examiners have cited institutions for gaps in romance scam typology coverage during AML model validations, specifically where monitoring rules fail to catch a customer sending progressively escalating transfers to new international beneficiaries.

The EU's Sixth Anti-Money Laundering Directive (AMLD6) requires transaction monitoring covering fraud-linked money laundering, and romance scam proceeds qualify as predicate offense proceeds under its expanded list. The 2024 EU AML Package introduces a single EU AML supervisory authority with direct oversight powers, increasing enforcement exposure for institutions with detection gaps.

In the UK, the Proceeds of Crime Act 2002 (POCA 2002) creates an obligation to file SARs with the National Crime Agency when there is knowledge or suspicion of money laundering. Romance scam proceeds laundered through smurfing and structuring patterns fall squarely within scope. The Payment Systems Regulator's mandatory Authorized Push Payment Fraud (APP Fraud) reimbursement rules, effective October 2024, changed the financial equation: sending banks must now reimburse victims up to £85,000 for Faster Payments transactions, with limited exceptions for gross negligence. That liability exposure has driven measurable investment in real-time intervention tooling across UK retail banks.

Reported losses give a sense of the exposure being regulated. The UK Finance 2023 Annual Fraud Report documented £92.7 million in romance fraud losses, with authorized push payments the dominant transfer mechanism, and the FTC reported $1.3 billion in US romance scam losses for 2022, paid by bank transfer or cryptocurrency in the majority of cases.


Common challenges and how to address them

Three operational challenges define romance scam response at most institutions.

First, victim resistance. A customer who's spent six months building an emotional bond with a scammer won't accept a single phone call telling them to stop. Banks relying on one outbound warning call find the customer often dismisses it and switches to a different bank to continue sending funds. The better approach is a two-call model: the first call asks open questions about the relationship and the transfer purpose without making accusations. The second, if transfers continue, presents specific documented facts with written follow-up confirmation. Some institutions also send physical letters citing FTC guidance and asking for written acknowledgment.

Second, detection lag. Transaction monitoring rules built on velocity thresholds and round-number patterns catch some cases. Pig butchering victims, though, often send funds slowly and in irregular amounts. Behavioral Analytics that track peer group deviations, such as a 62-year-old retail customer with no prior international wire history suddenly sending transfers to Hong Kong-registered entities, outperform threshold rules. Institutions that reduced romance scam losses by 40-60% did so by adding peer comparison models alongside their existing rules.

Third, the unwitting mule problem. A romance scam victim who's also forwarding funds for the scammer is simultaneously a victim and a participant in the laundering chain. Enhanced due diligence reviews are appropriate for accounts showing this pattern. The compliance team must document its assessment of the customer's intent, because examiners will ask. The working assumption in most cases is unwitting participation, but the SAR still gets filed.

Documentation discipline matters throughout. Every victim call, every refusal to stop transfers, and every SAR decision should be timestamped and stored in the case management system. Inconsistent documentation is one of the most common examination findings in romance scam cases.


Related terms and concepts

Romance scam connects to several financial crime typologies that compliance teams need to understand together.

The pig butchering variant blurs the line between romance scam and investment fraud. Both the relationship and the fake trading platform are constructed by the same criminal network, usually operating from organized compounds across Southeast Asia. The FBI issued a public service announcement in June 2022 specifically linking pig butchering to these operations, noting that many workers in the compounds are themselves trafficking victims forced to run the scams.

Deepfake Fraud is an accelerating risk within romance scam. Criminals are now using AI-generated video to maintain the illusion of a real relationship, countering the victim's instinct to verify via video call. The Global Anti-Scam Alliance's 2023 State of Scams Report documented growing victim reports of fraudsters using video chat, with increasing indications of real-time or pre-recorded synthetic video.

Mule Network activity is consistently downstream of romance scam. Proceeds don't move from victim to criminal in a single hop. They pass through layers of recruited and coerced mules, each forwarding the net balance onward, before reaching the criminal network. Network analysis of beneficiary accounts frequently shows that a single romance scam campaign feeds five to fifteen mule accounts operating in parallel during the same period.

From a classification standpoint, romance scam is a predicate offense under most AML frameworks. The fraud proceeds are subject to money laundering prohibitions from the moment they're transferred, not just when they reach the criminal's final account. This distinction matters for SAR narrative construction and for coordination with law enforcement, because it determines which statutes apply to every node in the money flow, including the unwitting mules.


How FluxForce detects Romance Scam

FluxForce's Aiden Flux monitors transaction velocity, escalation patterns, and peer-group anomalies in real time. Accounts where outbound crypto or wire activity deviates from a customer's established behavior are flagged for review. Nova Sentinel runs network graph analysis to identify when multiple accounts route funds to the same beneficiary infrastructure. This surfaces the organized criminal network operating behind individual victim cases.

Both agents share risk signals with human review queues, including customer service transcript flags and fraud-alert override counts. Automated SAR drafting reduces analyst time from hours to minutes. Book a demo to see how FluxForce handles romance scam detection across banking, fintech, and crypto environments.

How FluxForce detects romance scam

FluxForce AI agents monitor romance scam-related patterns in real time, surface red-flag activity for analyst review, and produce evidence-backed decisions with full audit trails.

← Back to Typologies