Mule Account Detection 2026: How AI Finds What Monitoring Misses

Money mule cases in the UK rose 69% in the first half of 2026. Cifas recorded over 13,000 filings to the National Fraud Database in that period alone with mule-related cases now accounting for 30% of all misuse of facility filings, up from 15% a year earlier. Mule accounts are not a fraud adjacency. They are the financial infrastructure through which every major fraud typology APP scams, synthetic identity bust-outs, account takeover converts stolen funds into usable proceeds. Detecting them is not a compliance obligation in isolation. Under the PSR’s APP fraud reimbursement scheme, it is a direct balance sheet control.
WHAT A MULE ACCOUNT DOES IN THE FRAUD LIFECYCLE
A money mule account receives the proceeds of fraud from a victim’s account and rapidly redistributes those funds through cash withdrawal, crypto conversion, or onward transfer through further mule accounts to create distance between the crime and the money.
UK Finance data confirms that over 70% of APP fraud proceeds pass through mule accounts within 24 hours of the initial transfer. Detection after that point is a recovery exercise. Detection before or at the point of receipt is the only control that interrupts the laundering chain.
What the FCA Found When It Reviewed Mule Account Controls
The FCA’s multi-firm review of payment account providers’ systems and controls against money mule activity published by the FCA and updated December 2025 is the most detailed regulatory assessment of mule detection practice available. Its findings are a direct benchmark against which institutions should assess their own controls.
The FCA found that most firms focus on outbound transaction monitoring and do not have adequate inbound transaction monitoring systems. This is the single most consequential gap identified in the review: a mule account receives funds before it redistributes them, and without inbound monitoring, the receipt of fraudulent funds goes undetected until money has already moved. By that point, the reimbursement liability under the PSR scheme has already been created.
At onboarding, the FCA identified that some firms conduct relatively few checks and rely on subsequent behavioural monitoring to identify mule characteristics. The review flagged specific control gaps: multiple customers onboarding from the same device or address without further investigation, virtual address usage not reviewed, and card activation not verified. Each of these is a known mule typology indicator that rule-based onboarding checks routinely miss.
THE REPORTING GAP THE FCA IDENTIFIED
The FCA found that of 194,084 money mules offboarded by 25 firms between January 2022 and September 2023, only 37% were reported to the National Fraud Database. Mule accounts that are offboarded but not reported allow the same individuals to open accounts elsewhere and continue operating as mules. The detection gap does not end at offboarding it extends to the speed and completeness of reporting that allows the network to be disrupted across the industry.
What AI Detection Identifies That Rule-Based Systems Miss
Rule-based mule detection looks for individual account characteristics: unusually high inbound transfers, rapid redistribution, dormant accounts suddenly receiving large sums. These signals exist but sophisticated mule networks are explicitly engineered to stay below the thresholds that trigger them. A mule herder controlling 50 accounts will calibrate each account’s transaction behaviour to individually appear unremarkable, while collectively moving significant volumes of fraudulent funds.
Consider a representative scenario: Twenty accounts are opened across a three-month period, each from a different individual, each passing onboarding checks. Each account receives three or four transfers a week, all below £1,000. Each redistributes funds within 48 hours via a different outbound channel. No individual account crosses a rule threshold. But all 20 share two device fingerprints, cluster around four address variations, and route funds to the same three downstream accounts. AI graph-based detection sees the network. Rules see 20 unremarkable accounts.
The FCA review of firms’ use of mule detection tools confirms that machine learning models combined with device profiling, geolocation, and behavioural biometrics significantly outperform static rules in identifying mule network patterns. The FCA explicitly identifies inbound transaction monitoring and network-level analysis as the capabilities firms that struggle most with mule detection are lacking. The gap is not in the sophistication of individual account checks. It is in the inability to see connections across accounts.
The Governance Implication: Mule Detection Is Now a Financial Control
The PSR’s APP fraud reimbursement scheme changed the financial consequence of a mule account operating undetected within an institution’s portfolio. Before October 2024, a receiving PSP had no mandatory reimbursement obligation. From October 2024, every APP fraud that routes through a mule account at the receiving institution creates a 50% reimbursement liability up to £42,500 per claim.
This transforms mule account detection from a financial crime compliance activity into a balance sheet risk control. The longer a mule account operates undetected, the more reimbursement claims accumulate against it. Institutions with weak inbound monitoring and limited network-level detection are not simply failing a regulatory expectation. They are accumulating a compounding financial liability with every payment cycle.
THREE DETECTION LAYERS THE FCA EXPECTS
- Onboarding: device profiling, geolocation, behavioural biometrics, shared address and device analysis, virtual address investigation.
- Inbound transaction monitoring: rapid fund receipt followed by redistribution, dormant accounts activating, high-velocity low-value inbound patterns.
- Network-level analysis: connections across accounts through shared devices, addresses, beneficiaries, and timing the layer rules cannot see and AI is built to find.
Conclusion
Money mule detection has never been more urgent or more consequential. With mule cases rising 69% in H1 2026 and the FCA having already published a detailed assessment of where institutional controls are failing, the detection gap is not a matter of speculation. It is documented, measurable, and now financially priced into every institution’s balance sheet through the PSR’s mandatory reimbursement scheme.
The core problem the FCA identified is architectural, not operational. Institutions that monitor outbound transactions without equivalent inbound controls will always detect mule activity too late. Those that evaluate accounts in isolation will always miss the network structures that mule herders deliberately engineer to stay below individual rule thresholds. And those that offboard mule accounts without reporting them to the National Fraud Database will keep the same individuals cycling through the industry.
AI-driven graph analysis, inbound monitoring, and behavioural profiling at onboarding are not advanced capabilities. In 2026, with 69% case volume growth and mandatory reimbursement liability, they are the baseline. Institutions that have not yet built these three detection layers are not behind the curve. They are accumulating a liability that compounds with every payment cycle they remain exposed.