Fraud as asymmetric warfare: what the Strait of Hormuz teaches us about digital crime

By Rafael Costa Abreu, director, fraud and identity, LexisNexis Risk Solutions [ Join Cybersecurity Insiders ]
25

During my training in the Army, much of what we studied was based on a classic concept: symmetric warfare. Two armies, relatively equivalent structures, well-defined lines, clear battlefields. There was order, predictability and, above all, a logic of direct confrontation. 

More recently, this paradigm has shifted towards what we know as asymmetric warfare. The adversary stopped being an equivalent force and became diffuse, decentralized and highly adaptable. Instead of direct confrontation, it exploits vulnerabilities, avoids points of strength and operates where the system is most fragile.

Few examples illustrate this better than the Strait of Hormuz crisis. Responsible for a significant portion of global oil supply flow, the strait is one of the most strategic points on the planet. Its vulnerability lies not only in its importance but also in its geography and in the type of threat it faces. Small vessels, drones, mines and indirect actions have the potential to generate disproportionate impacts across the global economy.

The strategic lesson of the Strait of Hormuz is not about force, but about leverage. Indirect actions that exploit chokepoints, dependencies and uncertainty can trigger consequences far beyond the scale of the initial act. Disruption does not require confrontation, only an understanding of where the system is most exposed. That logic increasingly applies not just to global trade routes, but to digital ecosystems too.

This example extends beyond geopolitics. It shows how modern systems are rarely disrupted head-on, but rather through pressure applied at their most sensitive points. As power, trade and coordination migrate into interconnected digital networks, the same dynamics of chokepoints and leverage emerge in less visible forms. Financial systems are one of the clearest expressions of this shift.

Fraud: from event to system

The current fraud landscape is no longer episodic – today it operates at scale. According to data from the Federal Trade Commission, Americans reported a record $16 billion in fraud losses in 2025, the highest ever recorded and up 25% compared to 2024. Imposter scams alone accounted for more than $3.5 billion of losses.

One of the main catalysts for this growth is the highly structured nature of organized crime. Money mule networks facilitate billions of dollars in fraudulent transfers each year in the United States. They play an essential role in the digital financial crime infrastructure, obfuscating the origin of fraudulent funds and allow criminal groups to ultimately profit from their actions. Without mules, the economic model of organized fraud breaks down.  

The emergence of “Mule 2.0” networks

Modern fraud operates as a network. After the initial scam, often rooted in social engineering, funds enter a primary account and are rapidly dispersed. Amounts are split into dozens of transfers, distributed across multiple institutions and then converted into cryptocurrency, withdrawn or sent abroad. This entire process can occur in less than three minutes.

Speed, fragmentation and interoperability create an environment in which:

• Tracking is complex

• Human response is slow

• Money disappears before detection

It is estimated that up to 72% of fraud now involves mule accounts, compared with about 34% just a few years ago. This is no longer opportunistic fraud. It is criminal infrastructure. This dynamic intensifies further in an increasingly interconnected economy. Instant payments, crypto assets, decentralized finance and global digital platforms deliver unprecedented efficiency, but also expand the attack surface.

The United States is a global leader in real-time payments. Zelle, one of the largest American payments networks moved more than $1.2 trillion in 2025. This marked the platform’s second consecutive trillion-dollar year and represented 20% year-over-year growth in total payment volume. However, the U.S. is far from alone. Brazil (Pix), India (UPI), Singapore (PayNow) and the United Kingdom (Faster Payments) follow the same direction: speed, interoperability and scale. 

The challenge is universal. The faster the system, the narrower the defense window, a reality that favors the asymmetric attacker.

Industry’s response must be to think and act as a network.

When facing a networked adversary, the response cannot be linear. Adaptive structures cannot be countered with isolated controls. As in asymmetric warfare, defense must evolve into a systemic approach:

• Shared intelligence to understand behavior and anticipate moves

• Layered defenses across the entire journey

• Coordination across institutions, functions and markets

• Decision speed that matches the tempo of the attack

U.S. regulators already acknowledge this shift. The Federal Reserve has said FedNow could monitor for unusual concentrations of inbound and outbound activity that signal mule networks and reject payments showing abnormal frequency or cumulative value. Congressional scrutiny of Zelle fraud, meanwhile, has pushed banks toward consortium data-sharing arrangements that use privacy-preserving machine learning to flag mule accounts across institutions within milliseconds. Together with FinCEN’s own enforcement priorities for 2026, these initiatives move precisely in this direction: transforming the financial system into a mechanism of collective intelligence. 

The new battlefield

If the Strait of Hormuz teaches us anything, it is that control of critical points, whether physical or digital, determines the stability of entire systems. In the digital world, these points include:

• onboarding

• authentication

• payments

• account recovery

The Strait of Hormuz also offers a second lesson. Strategic defense is not only about protecting critical infrastructure. It is also about denying adversaries access to the infrastructure they depend on. In global shipping, disrupting the channels that enable hostile actors to operate can reduce risk across the entire system. The same principle applies to fraud. If mule networks are the essential infrastructure that allows criminal organizations to move, obscure and monetize illicit funds, then identifying and disrupting those networks must become a central objective of fraud prevention. Combined with greater industry coordination and shared intelligence, a more systematic effort to detect and dismantle mule activity can help weaken the economic foundations of organized fraud itself. In asymmetric conflicts, success often comes not from confronting every attack, but from targeting the infrastructure that makes those attacks possible.

 

Join our LinkedIn group Information Security Community!

No posts to display