
The Headline Number
The US Treasury’s financial intelligence arm just put a striking figure on the table: nearly $2 billion in stolen funds intercepted before criminals could walk away with it. Andrea Gacki, director of the Financial Crimes Enforcement Network (FinCEN), told a House Financial Services subcommittee that the agency’s Rapid Response Program (RRP) has facilitated the interdiction of close to $2 billion in stolen proceeds tied to cyber-enabled fraud, benefiting more than 5,700 American individuals and businesses since the program began in 2015.
That’s not a one-time seizure — it’s a running total from a program purpose-built to chase money across borders before it disappears for good.
What Exactly Is the Rapid Response Program?
Cyber fraud victims often assume that once money is wired out, it’s gone. The RRP exists specifically to challenge that assumption. It’s a coordination mechanism that connects FinCEN, US law enforcement agencies, and financial intelligence units in foreign countries, with one goal: freeze fraudulently obtained funds before they get laundered through the international banking system and become unrecoverable.
Here’s how the process generally works:
- A victim of cyber-enabled fraud — or their bank — reports the incident to law enforcement, typically through the FBI’s Internet Crime Complaint Center (IC3) or the US Secret Service.
- If the stolen funds have already moved overseas, FinCEN uses the RRP to rapidly share financial intelligence with its counterpart agency in the destination country.
- That foreign financial intelligence unit is encouraged to use its own legal authority to freeze or hold the funds before they’re withdrawn or moved further downstream.
- If successful, the money can eventually be repatriated to the victim.
Speed is the entire point. Fraud proceeds typically move through multiple accounts and jurisdictions within hours, so a program that can act fast — rather than through a slow, traditional mutual legal assistance process — has a real shot at recovery.
According to FinCEN, the RRP has now been used to respond to cyber threats across more than 96 foreign jurisdictions, addressing a range of schemes including business email compromise and other fraud typologies.
Fraud Is the Biggest Driver of Illicit Money in the US
Perhaps the most notable line from Gacki’s testimony wasn’t the $2 billion figure — it was her broader assessment that fraud remains one of the largest sources of illicit proceeds in the United States. FinCEN has flagged recurring patterns in schemes targeting government benefit programs, healthcare systems, and other public assistance channels, alongside the more commonly discussed categories like romance scams, business email compromise, and investment fraud.
This tracks with a trend FinCEN has highlighted before: cyber-enabled fraud has increased every year since at least 2013, and today spans an unusually wide range of tactics — elder financial exploitation, digital-asset investment scams (commonly called “pig butchering” scams), account takeover attacks, and increasingly, AI-enabled fraud that makes scam communications more convincing than ever.
The Huione Group: A Case Study in Why This Matters
Gacki’s testimony also pointed to a major enforcement action that illustrates why intercepting money matters so much: FinCEN’s move to sever the Cambodia-based Huione Group from the US financial system. FinCEN has described Huione as responsible for laundering at least $4 billion in illicit proceeds — a scale that shows individual fraud cases, however devastating for each victim, are often feeding into much larger, organized laundering infrastructure.
Huione has previously been identified by FinCEN as a key node for laundering money tied to cyber heists linked to North Korea, as well as proceeds from Southeast Asia-based organized crime networks running large-scale digital-asset scams. In other words: the same money trail that starts with an individual American losing money to a scam email or a fake investment app often ends up flowing into networks with far bigger geopolitical and criminal implications.
A New Tool: FinCEN’s Whistleblower Program
Alongside the interdiction numbers, Gacki flagged another development — FinCEN is working to make its whistleblower program fully operational. Treasury Secretary Scott Bessent announced a dedicated website in February to accept confidential tips, and a proposed rule issued in April laid out procedures, eligibility standards, and confidentiality protections for whistleblower awards. Gacki said FinCEN is now actively triaging incoming tips, with award payments expected to begin once the final rule is in place.
This matters because fraud networks — especially the more sophisticated, cross-border ones — often rely on insiders: people running shell accounts, mules moving money, or employees at complicit financial institutions. A functioning whistleblower incentive program gives FinCEN a new channel to identify these networks before losses scale up.
Why This Story Matters Beyond US Borders
While the RRP is a US government program built to help US-based victims, the story has relevance well beyond America’s borders for a few reasons:
- Fraud infrastructure is global by design. Scammers routing money through Southeast Asian laundering networks, or exploiting weak points in one country’s banking oversight, means every country’s financial system is a potential link in someone else’s fraud chain. The same playbook — romance scams, fake investment platforms, fake courier/customs charges — shows up in India, the UK, the US, and elsewhere with only minor local variations.
- Cross-border cooperation is the only real defense. The RRP’s success depends entirely on foreign financial intelligence units being willing and legally able to act quickly. That kind of cooperation is becoming a template other countries are likely to study or replicate as fraud losses mount globally.
- It’s a reminder that recovery, not just prevention, matters. Much of the public conversation around cyber fraud focuses on prevention — awareness campaigns, spotting red flags, not sharing OTPs. The RRP represents the other half of the equation: what happens after someone has already been scammed. For victims, knowing that agencies are actively trying to claw back stolen funds — and have recovered nearly $2 billion doing so — is meaningfully different from being told the money is simply gone.
The Takeaway
FinCEN’s disclosure to lawmakers is, in part, a case for its own funding and authority — but the underlying numbers are hard to dismiss. Nearly $2 billion recovered for more than 5,700 victims, a major laundering hub cut off from the US financial system, and a whistleblower program coming online all point to a shift in how financial crime enforcement treats cyber fraud: not as scattered individual crimes, but as an interconnected global laundering problem that requires equally interconnected, fast-moving responses.
For everyday consumers, the practical lesson is straightforward: if you’re defrauded, speed matters as much on the reporting side as it does on the scamming side. The sooner a fraud is reported — through IC3, your bank’s fraud department, or local cybercrime authorities — the better the odds that programs like the RRP can intervene before the money disappears into the next jurisdiction.