Behind the Love Scam: How a Kedah Call Centre Exposed Cross-Border Money Mule Risks
The scam began with fake identities and emotional manipulation.
But for financial institutions, the bigger risk begins when victim funds enter the financial system and move through accounts, wallets, payment channels or mule networks.
Kedah police recently busted an online love-scam syndicate operating from a shop lot in Kristal Light Industrial Park, Alor Setar. According to reports, seven foreign nationals were arrested during a raid on July 20, with police seizing phones, laptops and other equipment believed to have been used in the operation.
The syndicate allegedly targeted victims in Japan using fake identities created on apps such as Line and Langmate. Police said information from seized computers showed that 19 Japanese nationals had fallen prey so far, while investigations are ongoing to determine the actual number of victims and identify the upper-level network.
At first glance, this may look like a romance scam case. But for banks, e-wallets, payment firms, remittance providers and compliance teams, the key question is not only how victims were deceived. It is how the proceeds were collected, moved and potentially laundered after the deception worked.
That is where the AML risk begins.

What Happened in the Kedah Love Scam Case?
According to The Star, Kedah police raided the suspected call centre at 1.40pm on July 20 after intelligence indicated that the premises were being used for scam operations. The male suspects, aged between 21 and 30, were believed to have identified potential victims before passing their details to another group.
Police said the suspects had allegedly been recruited through overseas job offers advertised on Douyin and were placed at the premises with monthly salaries ranging from RM2,000 to RM3,000. The syndicate is believed to have started operating in mid-June and used digital platforms to create fake identities and deceive victims.
Police also seized 58 items, including 34 mobile phones, six laptops, one monitor, one CPU, one router and a modem, with the items estimated at RM50,000. The suspects were remanded to assist investigations under the Penal Code and Immigration Act, while police also identified a Malaysian building owner linked to the syndicate who remained at large at the time of reporting.
This matters because the case shows how organised scam operations can be run like small digital workforces. Devices, scripts, fake profiles, victim lists and cross-border coordination can all sit behind what appears to the victim as a personal online relationship.
For financial institutions, the scam communication is only one part of the risk. The financial trail that follows is where fraud exposure becomes an AML concern.
Why This Matters for Malaysian Financial Institutions
Malaysia’s financial sector sits within a fast-moving regional payments environment. Banks, e-wallets, remittance providers and payment firms process domestic and cross-border flows every day. That speed and connectivity are valuable for customers, but they can also be exploited by scam networks that need to collect and move proceeds quickly.
Love scams are especially difficult because victims often authorise the payments themselves. The transfer may be framed as financial help, travel support, emergency assistance, investment participation, medical expenses or a business opportunity. From the payment system’s perspective, the transaction may look like a voluntary transfer. From the victim’s perspective, it may feel like helping someone they trust.
This creates a detection challenge. A single payment may not look unusual. But repeated victim-authorised payments into the same beneficiary account, followed by rapid onward movement, may reveal a scam collection pattern.
Malaysia’s AML/CFT framework requires reporting institutions to manage financial crime risk using a risk-based approach. Bank Negara Malaysia’s AML/CFT/CPF and TFS policy document for DNFBPs and non-bank financial institutions also reinforces the need for reporting institutions to manage ML, TF and PF risks through a risk-based approach.
For financial institutions, this means romance scam monitoring cannot stop at customer authentication or payment approval. Institutions need to understand whether the beneficiary account, transaction pattern, customer behaviour and wider network indicate that scam proceeds may be entering or moving through the financial system.
The Money Trail Behind Love Scams
A love scam depends on trust at the front end and speed at the back end. The victim is first groomed through emotional manipulation, fake identity building and repeated communication. Once trust is established, the scammer introduces a reason for payment.
The stated reason may vary. It could be an emergency, a travel issue, a business need, a customs fee, a medical bill, an investment opportunity or a request for temporary financial support. The victim may make multiple payments over time because the relationship feels personal and the explanations appear urgent or believable.
Once the money is transferred, the scam becomes a financial crime risk. Funds may land in mule accounts, payment accounts, bank accounts or wallets controlled by the scam network. From there, proceeds may be split, transferred onward, withdrawn, converted into other assets or moved across borders.
In a case like the Kedah call-centre bust, the article does not provide the full payment pathway. However, the presence of a structured operation, multiple devices, identified victims and an upper-level network under investigation points to the wider risk that such scams often require organised collection and movement of proceeds.
For compliance teams, the important point is that the emotional deception may happen outside the bank, but the financial trail often passes through regulated channels.

The Mule Account and Cross-Border Risk
Love scams typically need accounts that can receive victim funds. These may include mule accounts, rented accounts, compromised accounts, accounts opened using false information or accounts controlled by intermediaries. In cross-border cases, funds may also move through remittance channels, wallets, foreign accounts or layered transfers designed to create distance from the original victim payment.
The mule account may not belong to the scam organiser. It may be controlled by someone recruited to receive funds, someone who sold or rented account access, or someone who does not fully understand the role they are playing. But once scam proceeds enter that account, it becomes part of the laundering chain.
This is why beneficiary-level and network-level monitoring matter. An account receiving funds from one victim may not immediately appear suspicious. But if the same account receives multiple payments from unrelated senders, shows sudden activity after dormancy, transfers funds onward quickly or connects to other flagged beneficiaries, the risk profile changes.
Cross-border love scams add another layer of complexity. Victims, scammers, mule accounts, devices, platforms and organisers may sit in different jurisdictions. This makes it harder for any one institution to see the full picture unless it can connect signals across customer behaviour, account activity, counterparties and investigation outcomes.
Red Flags Banks, E-Wallets and Payment Firms Should Monitor
Love scam proceeds can generate warning signs across customer behaviour, account activity, beneficiary patterns and fund movement.
Key red flags may include:
- Multiple inbound transfers from unrelated individuals into the same account, wallet or beneficiary profile
- Transfers with references linked to personal help, emergency support, travel, medical bills, gifts, investments or relationship-related explanations
- Sudden increase in incoming credits into a previously dormant or low-activity account
- Rapid onward transfers, withdrawals or fund splitting shortly after receipt
- Accounts receiving funds from customers across different locations without a clear business or personal rationale
- Beneficiary accounts linked to multiple scam complaints, disputed payments or suspicious transaction reports
- Newly opened accounts receiving frequent third-party credits soon after onboarding
- Multiple accounts connected by the same phone number, device, address, IP, introducer or common beneficiary
- Incoming funds followed by transfers to overseas accounts, remittance channels, crypto platforms or high-risk counterparties
- Customers unable to explain the source, purpose or relationship behind repeated incoming payments
Individually, some of these signals may not prove wrongdoing. Together, they may reveal an account being used to collect, layer or move scam proceeds.
The strongest signal is rarely one transaction. It is the pattern across senders, beneficiaries, timing, devices, counterparties and onward movement.
Why Traditional Monitoring May Miss the Risk
Traditional monitoring may struggle with love scams because many payments are authorised by the victim. The customer may pass authentication checks, confirm the transfer and provide a plausible reason for sending the money.
Rules-based systems may also miss the risk if they focus mainly on transaction amount, simple thresholds or known blacklisted accounts. Romance scam payments may begin with smaller amounts, increase gradually or be spread across multiple transfers. The receiving account may not have a long suspicious history, especially if it is newly opened or newly repurposed for scam collection.
The real risk becomes clearer when institutions connect several signals together. These include the victim’s behavioural change, the beneficiary’s inflow pattern, the speed of onward movement, shared identifiers across accounts, links to other suspicious beneficiaries and any complaint history connected to the same account.
For example, one customer sending money to a new beneficiary may not trigger an alert. But several unrelated customers sending funds to the same beneficiary, followed by rapid onward transfers to another account, may indicate a scam collection node.
This is why love scam detection requires behavioural, beneficiary and network-level monitoring. The fraud may be personalised, but the laundering pattern is often repeatable.
Why Fraud and AML Teams Need a Shared View
Love scams sit at the intersection of fraud, AML, customer protection and financial crime investigation.
The fraud team may see customer complaints, unusual payment behaviour or victim reports. The AML team may see suspicious inflows, mule-like account activity or rapid layering. The onboarding team may see weak customer profiles or account-opening anomalies. The investigations team may see links across devices, phone numbers, addresses, counterparties or accounts.
If these signals remain in separate systems, the institution may only see fragments of the risk. A payment may look authorised. A beneficiary may look normal. An account may appear low risk. But when the signals are connected, the same activity may point to scam proceeds moving through a mule network.
A shared view helps teams understand both sides of the case: the victim who was deceived and the account that may be receiving or moving the proceeds. This is important because romance scams are not only customer harm events. Once funds move through the financial system, they can become AML events requiring investigation, escalation and reporting.
For financial institutions, the question should not only be whether the customer approved the payment. It should also be whether the beneficiary behaviour, transaction pattern and network links indicate that the account is part of a scam operation.
What This Means for Compliance Teams
For compliance teams in Malaysia, the Kedah case reinforces three practical priorities.
First, institutions need stronger beneficiary monitoring. Scam detection should not focus only on the sender. Receiving accounts that collect funds from multiple unrelated individuals, move money quickly or connect to suspicious counterparties should be reviewed as potential scam collection accounts.
Second, institutions need to monitor customer behaviour changes. A customer who suddenly begins sending repeated payments to a new beneficiary, especially with emotional or urgent explanations, may require intervention, friction or enhanced review.
Third, institutions need network-level investigation. Shared devices, phone numbers, addresses, IPs, beneficiaries, mule accounts and transfer paths can help reveal organised scam networks that are not visible through isolated transaction alerts.
This is especially important in cross-border scam cases where victims, suspects, platforms and financial flows may span multiple jurisdictions. The earlier institutions can identify repeated patterns, the faster they can help disrupt collection accounts and reduce downstream laundering risk.
How Tookitaki Helps Financial Institutions Detect These Patterns
Tookitaki helps financial institutions move beyond isolated alerts to a more connected view of scam, mule and AML risk.
FinCense brings together customer risk, transaction monitoring, fraud signals, screening, alert management and case investigation to help compliance teams identify suspicious patterns across accounts, beneficiaries, counterparties and networks.
In love scam and mule-account cases, the risk may appear through a combination of signals. These can include unusual payment behaviour, repeated transfers to new beneficiaries, multiple inbound payments from unrelated victims, rapid onward movement, shared identifiers, common devices, linked accounts, cross-border movement and adverse intelligence connected to known scam patterns.
FinCense helps institutions connect these signals, prioritise higher-risk alerts and give investigators a clearer view of the network behind the activity. Through the AFC Ecosystem, Tookitaki also helps institutions stay closer to emerging typologies involving scam proceeds, mule accounts, authorised push payment fraud, romance scams, cross-border layering and digital deception.
The goal is not to create more alerts. It is to detect the right patterns earlier, identify connected accounts and support faster investigation outcomes.
The Bigger Lesson: The Scam Starts with Trust, but the AML Risk Starts with Movement
The Kedah love scam case shows how organised scam operations can target victims across borders using fake identities, digital platforms and call-centre-style coordination. The emotional deception happens outside the financial institution, but the proceeds often depend on financial channels to be collected, moved and layered.
For banks, e-wallets, payment firms and remittance providers, the key lesson is clear. Romance scams should not be viewed only as customer fraud. They should also be treated as potential AML risk when accounts, wallets or payment channels are used to receive and move criminal proceeds.
The victim may see a relationship.
The scammer may see a target.
But compliance teams need to see the money trail.
Experience the most intelligent AML and fraud prevention platform
Experience the most intelligent AML and fraud prevention platform
Experience the most intelligent AML and fraud prevention platform
Top AML Scenarios in ASEAN

The Role of AML Software in Compliance

The Role of AML Software in Compliance





