How Is Money Muling Prosecuted Under AFASA?
Introduction
Company bank accounts and e-wallets may be used to receive, transfer, or withdraw proceeds from online fraud. When a corporation or its officers knowingly allow an account to serve as a conduit for illicit digital funds, the conduct may expose both the individuals involved and the entity’s responsible personnel to criminal, administrative, and regulatory consequences.
The principal statute is the Anti-Financial Account Scamming Act (AFASA), or R.A. No. 12010. It addresses financial cybercrime, protects financial consumers, and authorizes government action against social engineering schemes, money muling, and related misuse of financial accounts. The Supreme Court has recognized that AFASA operates together with the Cybercrime Prevention Act, the Bank Secrecy Law, and the Data Privacy Act in investigations involving cybercrime.
What Is Money Muling?
Money muling generally involves receiving, keeping, transferring, withdrawing, or otherwise moving money obtained through fraud or another unlawful activity, usually in exchange for a fee or other benefit. A person may act as a money mule even if the person did not personally commit the original phishing, impersonation, hacking, or social engineering offense.
In a corporate setting, the account may belong to a corporation rather than an individual. The relevant questions include who controlled the account, who authorized the transactions, whether the company received a benefit, and whether the officers or employees knew—or deliberately ignored facts indicating—that the funds were illicit.
AFASA also criminalizes social engineering schemes. These include obtaining sensitive identifying information through deception or fraud to gain unauthorized access to a financial account, including falsely representing oneself as an institution or using electronic communication for that purpose. Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., G.R. No. 273720, 2025.
What Conduct May Create Criminal Exposure?
Corporate account use may become prosecutable when the evidence shows that the account was intentionally or knowingly used to receive or move proceeds of a financial scam. Relevant conduct may include the following:
- opening or maintaining an account for the principal purpose of receiving fraudulent proceeds;
- allowing unknown persons to control corporate online banking credentials, cards, or authentication devices;
- receiving funds inconsistent with the corporation’s business and immediately transferring or withdrawing them;
- splitting or layering transactions to conceal the source or destination of the funds; and
- retaining a commission or other benefit for permitting the account to be used.
Suspicious conduct alone does not automatically establish criminal liability. Prosecutors must still connect the accused person to the account, the transactions, and the required mental element of the offense charged. Evidence of knowledge, participation, authorization, concealment, or deliberate disregard of obvious warning signs is particularly important.
How Does AFASA Apply to Corporate Bank Accounts?
A corporation may be used as a vehicle for money muling, but criminal responsibility ordinarily depends on the acts and participation of identifiable natural persons, such as directors, officers, authorized signatories, employees, agents, or beneficial owners. The corporation’s separate juridical personality does not shield individuals who use it to commit a crime.
Corporate liability may also arise where the governing law expressly attaches consequences to the juridical entity or where the corporation’s officers or personnel acted within the scope of their authority and used the entity to facilitate the prohibited transaction. The specific liability depends on the statutory language, the corporation’s participation, and the evidence establishing authorization or benefit.
Accordingly, a company is not automatically criminally liable merely because its account received fraudulent funds. Investigators should determine whether the company was an innocent recipient, an unwitting victim, a negligent account holder, or an intentional conduit.
What Evidence Is Relevant?
Prosecutors and investigators will typically examine the complete transaction and control history of the account. The following evidence may be material:
- account-opening records, beneficial ownership information, and corporate registration documents;
- specimen signatures, board resolutions, authorization documents, and online-banking access logs;
- transaction records, beneficiary details, device identifiers, IP addresses, and authentication records;
- communications among officers, employees, customers, recruiters, and alleged scam victims; and
- invoices, contracts, payroll records, accounting entries, and explanations for the receipt or transfer of funds.
A company’s ordinary business records may become significant when the transactions are inconsistent with the corporation’s stated operations. Examples include substantial transfers involving individuals with no apparent commercial relationship, immediate withdrawals after deposits, multiple unrelated remittances, or transactions unsupported by invoices or delivery records.
Can Authorities Obtain Bank Information?
AFASA gives the Bangko Sentral ng Pilipinas authority to investigate financial accounts and share relevant information with law-enforcement and other competent authorities, subject to the statute’s limitations. Section 13 of AFASA also authorizes the BSP or its authorized officers to apply for cybercrime warrants and related orders under the Cybercrime Prevention Act.
The Supreme Court has held that the Cybercrime Prevention Act did not repeal the Bank Secrecy Law. However, a bank acting as a service provider may disclose basic subscriber information—such as the identity and contact details of an account holder—when authorized by a valid court-issued warrant to disclose computer data. Financial details remain protected unless a lawful exception applies. Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., G.R. No. 273720, 2025.
AFASA further provides that the prohibitions against inquiry into or disclosure of deposits do not apply to financial accounts under BSP investigation within the scope recognized by the statute. The investigating authority must nevertheless observe the applicable warrant, procedural, and statutory safeguards.
How Are Corporate Accounts Investigated?
An investigation may begin with a complaint from a victim, a bank’s fraud report, a suspicious transaction report, a referral from law enforcement, or information developed through cybercrime monitoring. The account may then be examined in relation to the alleged scam, the movement of funds, and the persons who controlled the account.
The BSP may seek assistance from the National Bureau of Investigation and the Philippine National Police in investigating AFASA violations and enforcing cybercrime warrants. The BSP’s authority is without prejudice to the existing powers of the NBI and PNP cybercrime units.
Where an investigation seeks a court order concerning computer data or account information, the application should identify the alleged offense, the accounts or data involved, and the facts supporting the requested disclosure. A generalized suspicion that a company account was used in a scam may be insufficient without a factual link to the specific transactions and persons involved.
How Does AFASA Relate to the Anti-Money Laundering Act?
Conduct connected with financial scams may also have consequences under the Anti-Money Laundering Act, or R.A. No. 9160, as amended. The Anti-Money Laundering Council may investigate covered transactions, receive suspicious transaction reports, and pursue the remedies authorized by the AMLA when the funds are proceeds of an unlawful activity.
The remedies of bank inquiry and asset freezing under the AMLA are extraordinary. The AMLC bears the burden of establishing probable cause that the accounts are related to predicate crimes. Republic of the Philippines v. Ongpin, et al., G.R. No. 207078, 2022.
Earlier jurisprudence also emphasized that a bank inquiry order under the AMLA could not be issued ex parte under the law then considered by the Court; notice and an opportunity to be heard were required. The exception to bank secrecy was strictly construed. Republic of the Philippines v. Eugenio, Jr., et al., G.R. No. 174629, 2008.
Because AFASA now contains specific provisions concerning financial-account investigations and cybercrime warrants, counsel should distinguish the statutory basis of the requested order and determine which procedural safeguards apply to the particular investigation.
What Are the Possible Consequences?
AFASA provides criminal penalties for prohibited conduct, including money muling and social engineering schemes. The penalty may depend on the specific offense, the manner in which it was committed, the value or extent of the fraud, and any circumstance that increases the classification of the offense.
The search materials available for this article do not contain the complete penalty provisions of R.A. No. 12010. The exact period of imprisonment, fine, and classification of the offense should therefore be confirmed from the current text of AFASA before a charging recommendation or public legal advice is issued. It would be unsafe to state a specific prison term without the applicable statutory subsection.
Separate consequences may include freezing or holding disputed funds, closure or restriction of accounts, regulatory sanctions, forfeiture proceedings, liability under the Cybercrime Prevention Act, and prosecution under the AMLA or other applicable laws. A person who knowingly deals with illicit funds may face more than one charge arising from the same transaction, subject to constitutional and procedural limitations.
When May Corporate Officers Be Held Responsible?
Corporate officers may be exposed when they personally participated in the transactions, authorized the use of the account, supplied access credentials, received proceeds, concealed the source of funds, or knowingly failed to stop an established scheme despite having control and responsibility over the account.
Titles alone do not establish criminal liability. A president, treasurer, director, or compliance officer is not automatically liable for every transaction of the company. The prosecution must establish the officer’s participation and the mental state required by the offense.
Nevertheless, an officer may not rely solely on the corporation’s separate personality when the evidence shows that the corporation was used as an instrument for fraud. Courts may examine the actual control of the account, the flow of funds, and the relationship between the corporation and the individuals who benefited from the transactions.
Typical Corporate Scenarios
Unwitting recipient. A legitimate company receives a mistaken or fraudulent transfer, promptly reports it, preserves the funds, and cooperates with the bank and investigators. These facts may support the company’s position that it was a victim rather than a money mule.
Paid account conduit. An officer permits third parties to use the company’s account in exchange for a fee, despite knowing that the transactions have no legitimate business purpose. This presents substantial exposure for money muling and related offenses.
Compromised account. Criminals obtain the company’s credentials through phishing and transfer funds without authorization. The company’s prompt containment, reporting, and preservation of evidence may be important in distinguishing unauthorized use from intentional participation.
Deliberate corporate concealment. The company creates false invoices, records sham services, or transfers funds among related accounts to disguise the proceeds. Such conduct may support charges beyond the initial receipt of the funds.
Recommended Compliance Measures
Companies that maintain bank or payment accounts should adopt controls proportionate to the risk of digital fraud. At a minimum, the company should:
- limit online-banking access to authorized personnel and use multi-factor authentication;
- segregate payment preparation, approval, and release functions;
- require written support for unusual receipts, transfers, and withdrawals;
- review beneficial owners, counterparties, and third-party payment instructions;
- preserve transaction records, access logs, emails, and internal approvals; and
- report suspected unauthorized or fraudulent transactions immediately to the bank and appropriate authorities.
Companies should also maintain a written incident-response procedure. It should identify the personnel authorized to contact the bank, suspend access, preserve electronic evidence, notify affected persons, and coordinate with counsel.
What Should a Company Do After Discovering Suspicious Funds?
The company should avoid withdrawing, transferring, returning, or otherwise disposing of suspicious funds without first coordinating with the bank and counsel. A private return to an unknown sender may complicate tracing and may create the appearance of concealment or further movement of illicit proceeds.
The company should preserve the original records, avoid altering accounting entries, document the discovery, identify all persons with account access, and secure relevant devices. It should also determine whether a suspicious transaction report, cybercrime complaint, or other regulatory disclosure is required.
Management should not coach employees or delete messages connected with the transactions. A transparent internal investigation, supported by preserved records and clear reporting lines, is generally more defensible than informal attempts to resolve the matter privately.
Conclusion
AFASA places money muling and digital financial-account abuse within a more direct enforcement regime. The use of a corporate account does not prevent prosecution when the evidence shows that officers, employees, agents, or other responsible persons knowingly allowed the account to receive or move illicit digital funds.
At the same time, receipt of suspicious funds does not by itself prove criminal liability. The decisive issues are account control, participation, knowledge, authorization, benefit, and the company’s response after discovering the suspicious activity. Companies should implement strong access controls, investigate unusual transactions promptly, preserve evidence, and obtain legal advice before moving or returning disputed funds.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

