From Luxury Apartments to Money Trails: AML Lessons from the Forest City Scam Bust
The raids took place in luxury apartments and bungalows.
But the real financial crime risk begins far beyond the premises.
Malaysian police recently dismantled two online scam syndicates operating from Forest City, Johor, arresting 335 suspects in an operation involving 27 residential apartment units and five bungalows. Reports said the syndicates were linked to fake cryptocurrency investment offers, love scams, investment fraud and bogus law-firm impersonation schemes targeting victims abroad.
At first glance, this may look like another call-centre scam bust. But for banks, e-wallets, payment firms, remittance providers and compliance teams, the bigger question is what happened after the victims were deceived. Multi-scam operations do not stop at fake profiles, scripts or online messages. They need accounts, wallets, payment routes, mule networks and cross-border channels to collect, move and layer proceeds.
That is where the AML risk begins.

What Happened in Forest City?
According to reports, Johor police busted two online scam syndicates operating call centres in Forest City in Iskandar Puteri. The arrests followed an integrated operation carried out on July 15, 2026 across 32 premises, including 27 apartment units and five bungalows used as operational centres.
The suspects were aged between 20 and 58. Malay Mail reported that the 335 people arrested included 309 Chinese nationals, 19 Indonesian nationals, four Myanmar nationals and three locals. Police also seized 313 computers, 1,557 mobile phones, 17 laptops, 10 modems, a Mazda CX-8 SUV and other equipment estimated to be worth RM1 million.
The Star reported that the scam centres occupied 32 premises and had allegedly generated millions in scam money from victims abroad. Police said the suspects used platforms such as Telegram, WhatsApp and TikTok to target victims, while the scams involved love scams, currency scams, cryptocurrency fraud and impersonation of law firms.
In one operation, a syndicate had allegedly taken over almost five floors of luxury apartments across more than two dozen units. In another, raids on several bungalows led to the arrest of Chinese nationals believed to have targeted victims in China, Japan, Europe and the United States. Each house was reportedly assigned victims from a specific country, with most scams involving investments, cryptocurrency and law-firm impersonation.
Separately, 159 Chinese nationals were charged in Johor Bahru over an alleged criminal conspiracy involving attempts to defraud victims through a non-existent cryptocurrency investment scheme. The alleged offences took place at Jalan Forest City 16, Gelang Patah, Tanjung Kupang, Iskandar Puteri, on July 15.
For financial institutions, the scale and structure of the operation matter. This was not a single scam narrative run by a few individuals. It was a multi-scam infrastructure using different scripts, different victim markets and different digital channels.
Why This Matters for Malaysian Financial Institutions
Malaysia’s financial institutions operate in a region where payments, remittances, e-wallets, digital onboarding and cross-border transfers are increasingly connected. That connectivity benefits customers, but it also gives organised scam networks more ways to collect and move illicit proceeds quickly.
The Forest City case highlights a difficult challenge. Different scam narratives can feed into the same financial crime infrastructure. A love scam, a fake crypto investment scheme, a bogus law-firm claim and recruitment-agent impersonation may look different at the victim-contact stage. But once money starts moving, the typologies can converge through mule accounts, wallets, payment intermediaries, remittance routes, crypto on-ramps and layered transfers.
For banks and payment firms, the question is not only whether a customer authorised a transfer. It is whether the beneficiary account, source of funds, transaction velocity, device links, counterparties and onward movement indicate that scam proceeds are being collected or laundered.
A customer may believe they are sending money for an investment, legal fee, emergency request or relationship-related payment. The financial institution may see an authorised transaction. But the receiving account may be part of a wider collection network linked to multiple victims and multiple scam scripts.
That is why scam-centre cases are also AML cases. The deception may happen on social media or messaging platforms, but the proceeds often pass through regulated financial channels.
How Multi-Scam Centres Create AML Risk
Multi-scam centres are dangerous because they are operationally flexible. The same infrastructure can support romance fraud, fake investment offers, crypto scams, impersonation scams and recovery-fraud narratives. The scripts may change, but the financial objective remains the same: persuade victims to transfer money and then move the proceeds before detection or recovery action begins.
The Forest City case shows several features that matter from an AML perspective. Police found large numbers of phones, computers and communication devices, while reports described the use of Telegram, WhatsApp and TikTok to lure victims. The operation also involved country-specific targeting, with some premises allegedly assigned to victims from specific jurisdictions.
This structure can create multiple financial crime risks. Victim payments may be split across receiving accounts to avoid concentration. Mule accounts may be opened or rented to receive funds. Crypto investment narratives may move funds into digital asset channels. Bogus law-firm impersonation may create a credible explanation for urgent payments. Recruitment-agent impersonation may produce salary, placement-fee or work-permit-related payment narratives that appear legitimate on the surface.
For financial institutions, the challenge is that each payment may carry a different stated purpose. One may look like an investment. Another may look like a legal fee. Another may look like personal support. But if the same beneficiaries, devices, addresses, introducers, accounts or onward transfer routes appear across multiple cases, the institution may be looking at a common scam collection network.
The Money Mule, Crypto and Cross-Border Flow Risk
The public reports do not provide a full picture of how victim funds moved after the Forest City scams. That detail is important to state clearly. However, the reported use of love scams, fake cryptocurrency investments, investment fraud and law-firm impersonation points to several plausible financial crime pathways that compliance teams should watch for.
In love-scam cases, victims may be persuaded to send money to accounts controlled by mules or intermediaries. In fake investment and crypto schemes, funds may be collected through bank transfers, wallet top-ups, payment accounts or crypto-related channels. In bogus law-firm impersonation scams, victims may be pressured to pay legal, recovery, verification or settlement fees to accounts that appear professional but are controlled by the fraud network.
Once funds are received, they may be moved quickly to other accounts, withdrawn, split into smaller transfers, converted into crypto, routed through remittance providers or transferred across borders. The objective is to create distance between the victim payment and the person controlling the proceeds.
This is where money mule detection becomes critical. A mule account may not advertise itself as high risk during onboarding. It may be newly opened, previously dormant or controlled by someone with a plausible profile. The risk often appears only after the account begins receiving funds from unrelated victims and sending them onward rapidly.
Cross-border scams add another layer of complexity. Victims, operators, digital platforms, payment accounts and ultimate beneficiaries may sit across different countries. A single institution may see only one part of the chain, which makes network-level detection and intelligence-led monitoring essential.
Red Flags Banks, Wallets and Payment Firms Should Monitor
Forest City-style multi-scam operations can generate warning signs across onboarding, transaction monitoring, customer behaviour, beneficiary patterns and investigations.
Key red flags may include:
- Multiple inbound transfers from unrelated individuals into the same account, wallet or beneficiary profile
- Newly opened or previously dormant accounts receiving sudden third-party credits
- Payment references linked to investments, crypto, legal fees, recovery services, recruitment, emergency help or relationship-related support
- Rapid onward movement of funds shortly after receipt, including splitting across multiple accounts
- Accounts receiving funds from customers across different jurisdictions without a clear business rationale
- Beneficiaries linked to repeated complaints, fraud recalls, suspicious transaction reports or scam intelligence
- Multiple accounts connected by the same phone number, device, IP address, address, introducer or common beneficiary
- Transfers into crypto-related platforms, remittance channels or offshore accounts soon after victim payments
- Customers receiving funds inconsistent with their occupation, income, stated business activity or expected account behaviour
- Repeated use of similar narratives across victims, such as guaranteed investment returns, urgent legal payments or recovery assistance
Individually, these signals may not prove wrongdoing. Together, they may indicate that an account or wallet is being used as part of a scam collection and laundering network.
The strongest signal is rarely one transaction. It is the pattern across senders, beneficiaries, devices, counterparties, timing and onward movement.
Why Traditional Monitoring May Miss the Risk
Traditional monitoring may struggle with multi-scam operations because the transactions can appear ordinary when viewed in isolation. A customer may authorise a payment. A beneficiary may receive funds below a reporting threshold. A transaction may be described as an investment, legal fee, personal support or recruitment-related payment.
Rules-based systems may also miss the connection between different scam narratives. A romance scam payment, a crypto investment transfer and a law-firm impersonation payment may be categorised differently. But if the receiving accounts, devices, addresses or onward routes overlap, they may belong to the same underlying network.
The risk becomes clearer when institutions connect multiple signals. These include customer behaviour change, beneficiary inflow patterns, new-account activity, shared identifiers, suspicious counterparties, rapid layering, cross-border routes, prior complaints and links to known scam typologies.
For example, one payment to a new beneficiary may not look suspicious. But if that beneficiary receives funds from multiple unrelated customers, quickly transfers money onward, shares identifiers with other flagged accounts and has links to crypto-related outflows, the risk profile changes significantly.
This is why scam and AML detection needs to move beyond isolated alerts. It needs to understand behaviour, relationships and networks.

Why Fraud and AML Teams Need a Shared View
Multi-scam centres sit at the intersection of fraud, AML, customer protection, cyber-enabled crime and cross-border financial intelligence.
The fraud team may see customer complaints, scam reports or unusual payment behaviour. The AML team may see mule-like inflows, rapid onward movement or suspicious layering. The onboarding team may see weak profiles, shared devices or unusual account-opening patterns. The investigations team may detect links across phone numbers, addresses, counterparties, devices, IPs or beneficiaries.
If these signals remain in separate systems, the institution may only see fragments of the risk. A payment may look authorised. A beneficiary may look normal. A crypto-related transfer may look like customer-directed activity. But when the signals are connected, the same activity may point to a broader scam proceeds network.
A shared view helps teams understand both sides of the case: the victim who was deceived and the account that may be receiving or moving the proceeds. This is especially important when one scam centre runs multiple narratives, because the laundering pattern may be more consistent than the scam script.
For financial institutions, the key question should not only be whether a customer approved a payment. It should also be whether the beneficiary behaviour, transaction pattern and network links suggest that the account is part of an organised fraud infrastructure.
What This Means for Compliance Teams
For compliance teams in Malaysia, the Forest City case reinforces three practical priorities.
First, institutions need stronger beneficiary and mule-account monitoring. Scam prevention cannot focus only on the sender. Receiving accounts that collect funds from multiple unrelated individuals, show sudden activity, or move money onward quickly should be reviewed as potential scam collection accounts.
Second, institutions need to connect scam typologies across channels. Love scams, fake crypto investments, bogus law-firm impersonation and recruitment-related scams may appear different at the point of victim contact, but their money movement can share common accounts, devices, counterparties and routes.
Third, institutions need network-level investigation. Shared identifiers such as phone numbers, devices, IPs, addresses, common beneficiaries, introducers, account controllers and onward transfer paths can help reveal organised networks that are not visible through single transaction alerts.
This is especially important in cross-border scam cases where victims, suspects, platforms, mule accounts and financial flows may span multiple jurisdictions. The earlier institutions can identify repeated patterns, the faster they can disrupt collection accounts and reduce downstream laundering risk.
How Tookitaki Helps Financial Institutions Detect These Patterns
Tookitaki helps financial institutions move beyond isolated alerts to a more connected view of scam, mule and AML risk.
FinCense brings together customer risk, transaction monitoring, fraud signals, screening, alert management and case investigation to help compliance teams identify suspicious patterns across accounts, beneficiaries, counterparties and networks.
In multi-scam cases like Forest City, the risk may appear through a combination of signals: repeated victim-to-beneficiary transfers, rapid onward movement, newly active mule accounts, shared devices, common beneficiaries, crypto-related outflows, cross-border payments, inconsistent customer profiles, adverse intelligence and links to known scam typologies.
FinCense helps institutions connect these signals, prioritise higher-risk alerts and give investigators a clearer view of the network behind the activity. Through the AFC Ecosystem, Tookitaki also helps institutions stay closer to emerging typologies involving scam proceeds, mule accounts, authorised push payment fraud, crypto-investment scams, romance scams, impersonation fraud, cross-border layering and digital deception.
The goal is not to create more alerts. It is to detect the right patterns earlier, identify connected accounts and support faster investigation outcomes.
The Bigger Lesson: Scam Scripts Change, Money Trails Repeat
The Forest City case shows how organised scam networks can run multiple deception models from the same operational base. One victim may be targeted through romance fraud. Another may be drawn into a fake crypto investment. Another may be pressured by a bogus law-firm claim. The stories differ, but the financial crime objective is the same: collect the funds and move them quickly.
For banks, e-wallets, payment firms and remittance providers, this is the key lesson. Scam typologies should not be viewed only by their front-end narrative. They should also be analysed by their back-end money movement.
The scam may begin on Telegram, WhatsApp or TikTok. It may be run from luxury apartments or bungalows. It may target victims across multiple countries. But once the funds move, the AML risk becomes visible in accounts, wallets, beneficiaries, counterparties and transaction patterns.
Compliance teams do not need to know every scam script to detect the risk.
They need to recognise the money trail.
Experience the most intelligent AML and fraud prevention platform
Experience the most intelligent AML and fraud prevention platform
Experience the most intelligent AML and fraud prevention platform
Top AML Scenarios in ASEAN

The Role of AML Software in Compliance

The Role of AML Software in Compliance





