Money mule detection is the practice of identifying bank accounts used to receive and pass on the proceeds of fraud for someone else. It’s hard because a mule account rarely looks abnormal to the institution holding it. Money arrives, money leaves, and the customer is a real person with real documents.

That gap matters more each year. UK payment fraud losses hit £1.28 billion in 2025, up 4%, across a record 4.06 million cases, UK Finance reported in its Annual Fraud Report 2026. Authorised push payment losses rose 19% to £576.4 million. Every one of those payments landed in an account somewhere, and the accounts receiving them are the part of the chain the industry understands least.

What is a money mule in banking? 

A money mule in banking is a customer whose account is used to receive stolen funds and move them on, usually within minutes, either knowingly or without understanding what they’re doing. The account is genuine and so is the identity behind it. Only the purpose of the money passing through the account is criminal.

The recruitment picture isn’t the one most fraud teams design for. Home Office research published on 16 July 2026, Lived experiences of money muling, found that 80% of reported muling activities happened at the request of someone the account holder knew: friends in 51% of cases, family in 15%, romantic partners in 14%. Just over half of respondents had either never heard the term “money muling” or had heard it without knowing what it meant. Around 36% of activities were one-offs.

The base sizes are small and the percentages count activities rather than individuals, so read them as direction rather than precision.

That profile defeats a lot of conventional controls. Someone who moves money once, for a friend, out of an account they opened legitimately years ago, won’t trip a rule built for a professional launderer. 

Filings are rising sharply. Cifas members recorded more than 13,000 money mule cases in the first half of 2026, up 69% year on year and now 30% of all misuse-of-facility filings, according to the Fraudscape 2026 six-month update. Under-30s accounted for 57% of them. One caveat belongs with that number: Cifas only introduced a dedicated money mule filing category in 2025, so part of the rise reflects members adopting the new code.

Why can’t one bank detect a mule account?

Because the evidence is distributed. Each institution in the chain sees a fragment that is unremarkable on its own, and the fragment that would make it alarming sits with somebody else.

Candice Pressinger, director of customer data security at Elavon Europe, told Fintechly how a single mule payment looks to each party in turn.

“The bank sees that the customer received the money. It’s nothing unusual. The merchant sees a legitimate transaction, nothing unusual. Telecoms provider sees the customer’s recent change to device and SIM numbers. That’s potentially unusual. Another bank sees the money immediately move through three additional accounts and that’s potentially unusual. Individually, none of these signals proves any kind of criminal activity but collectively they would suggest a money mule network.”

– Candice Pressinger, director of customer data security, Elavon Europe

 

Who is looking What they see How it reads in isolation
Receiving bank An inbound credit to an existing customer Normal
Merchant or acquirer A completed, authorised transaction Normal
Telecoms provider A recent SIM swap and new device Mildly odd
Downstream banks Funds split across three accounts in minutes Mildly odd
All four combined Recruitment, takeover, receipt and dispersal A mule network

 

Pressinger made the same point about the account itself. 

“A mule account rarely identifies itself as a mule account. Viewed in isolation it often looks like a legitimate customer. The risk emerges when you can connect behaviour, relationships and money flows across the wider network.”

“Most organisations aren’t unwilling to share intelligence,” she said. “They just need confidence they’re doing it safely, legally and in a way that’s genuinely useful.” Her diagnosis is tempo: “fraud moves faster than information. By the time one organisation spots a pattern, it often hasn’t reached the next organisation quickly enough to stop the next victim.”

How to identify money mule account behaviour inside your own book 

Distribution is the hard constraint, but it isn’t an excuse for weak in-house controls, and the FCA has been specific about what firms miss. Its review of firms’ use of the National Fraud Database and money mule account detection tools, published on 23 January 2025, listed the indicators used by firms that detected mules well:

  • Unexpected or unexplained deposits into the account
  • Rapid dispersal of funds through networks of accounts, often within minutes of receipt
  • Movement of funds to international jurisdictions
  • Rapid withdrawal of funds from ATMs
  • Large deposits shortly after account opening that exceed the customer’s stated income
  • Activity inconsistent with the stated purpose of the account

 

The recurring structural failure is directional. In an earlier multi-firm review, the regulator found that “some firms focus on outbound transaction monitoring and do not have adequate inbound transaction monitoring systems or controls”. Fraud teams are built to stop money leaving, and a mule account is defined by money arriving.

The FCA also traced a mundane root cause: many firms never captured expected annual income or business turnover at onboarding, which leaves downstream monitoring with no baseline to measure a suspicious credit against.

Does the law allow fraud data sharing between banks?

Yes, and it has since 15 January 2024. Sections 188 and 189 of the Economic Crime and Corporate Transparency Act 2023 mean a disclosure between businesses in the regulated sector, made because of economic crime concerns, doesn’t breach an obligation of confidence or create civil liability to the customer concerned. 

Section 188 covers direct sharing between two regulated firms, on either a request from the receiving firm or a warning from a firm that has decided to exit or restrict a customer. Section 189 covers sharing routed through an intermediary, and applies to a narrower set of firms including banks, e-money institutions, payment institutions and cryptoasset businesses. Both carve out data protection law, which still applies in full, and Home Office guidance confirms the measures are domestic only.

The infrastructure exists too. More than 320 payment service providers now offer Confirmation of Payee, covering over 99% of providers that initiate Faster Payments transactions, with more than two million checks a day, the Payment Systems Regulator reported in July 2026. 

What is the best money mule fraud detection software? 

There’s no neutral ranking to give. The more useful question is what a tool has to do, and the FCA’s findings make a serviceable specification. 

Firms in its review used a commercial mule account detection tool that traces the proceeds of fraud across the Faster Payments System, issuing alerts about suspected mules and mapping how funds moved. The regulator found the tool worked, and that firms undermined it: most investigated first-generation alerts thoroughly and under-responded to later generations, and some set internal thresholds, such as minimum transaction values, that filtered out genuine mule activity.

So the buying criteria that matter are unglamorous:

 

  • Inbound as well as outbound monitoring, since the mule signal is a credit
  • Network or link analysis that follows funds across institutions, not just across your own accounts
  • Real-time screening against shared databases, not a check performed once at onboarding
  • Explainability, because the FCA criticised firms that relied on machine learning without understanding how it reached a decision, a caveat that applies to any machine-learning control in the fraud stack
  • Alert handling that survives past the first hop, which is a process question more than a product one

 

The category also publishes remarkably little about itself. The best-known UK example of cross-institution tracing, the Mule Insights Tactical Solution built by Mastercard’s Vocalink and launched with Pay.UK in December 2018, still leads its product page with a December 2018 pilot statistic. No adoption count, recovery figure or independent evaluation has been published in the years since. That silence isn’t proof the system failed. It does mean buyers are being asked to assess a category on a pilot result from December 2018.

Most detected mules are never reported to anyone 

FCA data shows 25 firms offboarded 194,084 money mules between January 2022 and September 2023, and reported just 37% of them to the National Fraud Database. One firm reported 6%. Some reported more than 66%. 

Roughly two in three detected mules were shown the door and never flagged to the industry, which means the detection worked and the account holder was free to open an account elsewhere against a clean record. 

The timing problem runs alongside it. Only one firm in the review ran real-time checks against the database after onboarding. Most therefore failed to notice new fraud markers filed by other firms, in one case for more than two years. Nearly a third of the cases the FCA examined where a firm chose not to file actually met the database’s standard of proof, and firms often recorded no rationale for the decision.

That is what separates mule detection from most fraud problems. A firm can buy better analytics and still contribute nothing to the industry’s picture, because the failure sits after the alert: in whether the finding is filed, how quickly, and whether anyone else is screening in real time. Pressinger frames it as a supply problem in the wrong place. “We’re not suffering from an intelligence shortage,” she said. “We’re suffering from an intelligence-sharing problem.”

It also explains why the liability debate and the detection debate keep talking past each other. APP reimbursement is working while the fraud starts beyond its reach, and tech platforms face growing pressure as losses climb. Both of those are arguments about who pays. Mule detection is the argument about who can see, and paying for a loss you couldn’t have spotted does nothing to make the next one visible.

FAQs

What is a money mule in banking? An account holder who receives the proceeds of fraud and passes them on for someone else. The account and identity are usually genuine, which is why the activity is hard to separate from ordinary customer behaviour. 

How to identify money mule account activity early? Watch inbound credits rather than outbound payments: unexplained deposits, funds dispersed within minutes, large credits soon after account opening that exceed stated income, and rapid ATM withdrawal. Firms that catch mules monitor money coming in.

What is the best money mule fraud detection software? No neutral ranking exists. Judge tools on inbound monitoring, cross-institution link analysis, real-time screening against shared fraud databases, and whether the vendor can explain a decision to your regulator.

Is fraud data sharing between banks legal in the UK? Yes. Sections 188 and 189 of the Economic Crime and Corporate Transparency Act 2023, in force since 15 January 2024, remove breach-of-confidence and civil liability for disclosures between regulated firms made over economic crime concerns. Data protection law still applies.

Why do mule accounts reopen after being closed? Because closure and reporting are separate acts. FCA data shows only 37% of offboarded mules were reported to the National Fraud Database, so the next firm has nothing to screen against. 

Next read 

On what happens when fraud controls are tuned too tightly and genuine customers get caught: when World Cup fraud looks like a good customer.