Money mule activity is a system priority within the UK’s response to economic crime. The Government’s Fraud Strategy 2026–2029 also recognises the role mule networks play in facilitating fraud and financial crime, reinforcing the need for firms to identify and disrupt the movement of criminal funds through the financial system.
Against this backdrop, the FCA has published new findings on money mule activity, providing further insight into who firms are identifying as suspected mules, how criminal funds move through the financial system and, importantly, how those funds are ultimately cashed out.
FCA-regulated firms reported closing 238,396 suspected money mule accounts in 2025, compared with 184,935 in 2023, and more than 650,000 across the three-year period reviewed.
However, the findings raise a broader question: are firms’ controls keeping pace with the way mule activity is changing?
The FCA’s findings point to five key takeaways for firms:
the profile of suspected money mules is broadening, including across older age groups and established accounts;
cash-out activity is concentrated in the early stages of the mule chain, particularly around the second account;
card payments are playing a significant role in cash-out activity;
repeat use of accounts points to wider mule networks rather than isolated cases; and
information sharing remains a key part of identifying and disrupting those networks.
The profile of a money mule may be changing
Younger customers continue to represent a significant proportion of suspected money mule activity. Customers aged 18–39 accounted for 71.9% of suspected mules offboarded in 2025, with those aged 26–39 representing the largest group. The increase among older customers is also notable: offboarding among customers aged 40–49 rose by 44.7% between 2024 and 2025, and by 79.8% compared with 2023.
The FCA does not explain what is driving this increase, and firms should be careful not to draw conclusions from age alone. There are, however, several factors worth considering. Recent Home Office research found that 51% of people who had engaged in money muling reported severe financial stress, 47% job instability and 41% loss of employment within the previous five years. The sample was small and does not explain the increase among 40–49 year olds specifically, but it reinforces the importance of considering financial vulnerability and changing customer circumstances when assessing mule risk.
Criminal recruitment methods have also evolved. Mule activity can be disguised as legitimate employment or as a favour for someone the customer knows. Previous Cifas analysis has suggested that criminals may also target older customers because larger transactions can appear less unusual against their expected financial profile.
The same applies to account tenure. At retail banks and building societies, 45.4% of accounts closed for suspected mule activity had been open for more than two years. The FCA rightly cautions that this does not tell us when the mule activity began. Nevertheless, firms cannot assume an established account presents lower mule risk simply because it has previously behaved legitimately.
Customer demographics and tenure should inform customer risk assessments, rather than define them. The findings also strengthen the case for focused ongoing monitoring that can identify meaningful changes in customer behaviour over time. A long-standing account receiving unexpected third-party credits, changing its transaction velocity, or suddenly dispersing funds in ways inconsistent with its previous activity may warrant additional scrutiny, regardless of the customer's age or account tenure.
Understanding how the money leaves the mule network
One of the most useful aspects of the FCA's review is its analysis of what happens after fraud proceeds enter the mule network. Working with 22 regulated firms, the FCA traced the highest-value payments across 140 fraud cases. Although some funds travelled through longer chains, cash-out activity was concentrated between the second and fifth mule accounts, with the greatest concentration at the second account.
Fraud controls tend to focus heavily on the first receiving account, and there is a structural reason for that. Under the mandatory APP reimbursement regime introduced in October 2024, the cost of reimbursing victims for in-scope payments is split equally between the sending PSP and the receiving PSP that received the victim’s payment. Firms further along the mule chain carry no equivalent reimbursement liability for the onward transmission of those funds. However, the onward movement of fraud proceeds may still form part of the layering of criminal property, creating a clear financial crime risk regardless of where reimbursement liability sits.
Firms therefore need to understand not only whether their customers are receiving suspected fraud proceeds, but also where they sit in the movement of criminal funds and how their exposure may differ by firm type. Retail banks saw the highest transaction volumes, while non-retail firms saw lower volumes but higher-value transactions, pointing to different risk concentrations and cash-out behaviours across the sector. Controls should therefore be calibrated to the firm’s specific exposure, including through appropriate customer and transaction segmentation, scenario design, thresholds and monitoring logic that reflect the volume, value, velocity and cash-out methods most relevant to its business model.
Card payments present a different detection challenge
The FCA found that card payments were the most common method of cashing out fraud proceeds, including through multiple lower-value transactions and higher-value payments to local businesses and retailers.
At first glance, that may appear less significant than transfers to overseas accounts, cash withdrawals or cryptoassets. In practice, though, it creates a different detection challenge. Many mule detection scenarios are designed around the rapid movement of money: funds enter an account and are quickly transferred elsewhere. Card spending disrupts that pattern, dispersing criminal funds through activity that resembles ordinary consumer spending.
The FCA findings do not establish what sits behind those card payments or how the value is ultimately realised. What it does show is that card spending can provide a route for dispersing and monetising fraud proceeds through transactions that may appear entirely consistent with normal consumer behaviour. Importantly, the FCA does not suggest that the merchants themselves are complicit.
The 2025 National Risk Assessment notes that criminal proceeds are often used to buy high-value goods and lifestyle assets. The FCA’s findings suggest that proceeds may also be dispersed through smaller, more routine-looking purchases, making the activity harder to distinguish from legitimate consumer behaviour. This raises an important question for firms: do mule detection strategies identify how criminal funds are spent, as well as how they are transferred? Card activity, the types of merchants where spend is taking place, changes in spending behaviour and transaction velocity all need to form part of that picture.
Repeat use points to a network problem
The FCA also identified accounts that had been used multiple times for mule activity, including across different fraud types. Where the same accounts, beneficiaries, devices, contact details or payment destinations reappear across investigations, firms may be looking at components of a wider criminal network rather than isolated cases of customer misuse. Closing an account removes one point in that network; firms should also look across cases to identify recurring accounts, beneficiaries, devices or payment patterns that may point to a wider issue on their platform.
Information sharing needs to become operational
Information sharing is one of the most important themes running through the FCA's findings. Only 15.3% of customers offboarded for suspected mule activity in 2025 were filed to the Cifas National Fraud Database. While changes to Cifas categories and filing criteria limit direct year-on-year comparison, the figures suggest there remains significant scope to increase intelligence shared through the NFD.
The FCA encourages firms to consider the voluntary information-sharing provisions introduced by the Economic Crime and Corporate Transparency Act 2023 (ECCTA).
As a reminder: ECCTA information sharing
Sections 188 and 189 of ECCTA protect firms from breach of confidence and civil liability claims when they share information to prevent, detect or investigate economic crime, provided the relevant statutory conditions are met.
Section 188 supports direct information sharing between AML-regulated firms, including where a firm has decided to exit, restrict or refuse a customer because of economic crime concerns, or where another firm makes a relevant information request.
Section 189 supports indirect sharing through a third-party intermediary for specified firms, including banks, EMIs, PIs and cryptoasset firms, where the relevant conditions are met.
For example, if Firm A closes an account after identifying fraud proceeds that were transferred on to Firm B, section 188 can provide a basis for Firm A to warn Firm B, provided the relevant conditions are met.
The provisions apply only to sharing within the UK. They do not override UK GDPR or change existing SAR and tipping-off obligations, so firms still need appropriate governance around what is shared, why and how it is handled. Uptake also remains limited: in its March 2026 call for evidence, the Home Office acknowledged that direct sharing is only gradually increasing and indirect sharing remains low.
Five areas firms should consider now
The FCA asks firms to consider its findings against their own business models, customer bases and exposure to mule risk. Translating that into practice, these are five areas we think firms should prioritise:
Understand your position in the mule journey
Firms should use their own data to understand whether they typically see the initial receipt of victim funds, onward movement through intermediary mule accounts or eventual cash-out. Controls should reflect that exposure and the specific risks associated with their business model, rather than relying solely on industry-wide typologies.
Review whether mule detection captures cash-out behaviour
Pass-through rules remain important, but monitoring should also capture changes in card spending, merchant activity, crypto transactions, international payments and other methods through which criminal proceeds may be dispersed or monetised.
Reassess assumptions around the 'typical' mule
Firms should test whether their models and rules remain effective across different age groups and account tenures, with greater emphasis on unexpected changes in customer behaviour than on static indicators.
Turn individual mule cases into network intelligence
A mule investigation should not end when an account is closed. Linked accounts, beneficiaries, devices, contact details and payment destinations should inform wider monitoring, and cases should be filed to the National Fraud Database where the criteria is met.
Make information sharing part of the operating model
Firms should have clear triggers for sharing under sections 188 and 189, defined ownership, and practical processes for both sharing information and acting on information received from other firms.
Moving beyond the first mule account
The FCA’s findings build on what firms already know about money mule risk, while giving a clearer picture of how that risk is evolving. Mule activity can no longer be reduced to a young customer receiving money into a newly opened account and immediately transferring it elsewhere.
For firms, this means moving from detecting individual mule accounts towards understanding mule networks and the movement of criminal funds. That requires controls which can identify behavioural change, follow the money beyond the initial payment, connect intelligence across customers and accounts, and share relevant information quickly enough for another firm to act on it.
The FCA’s findings reinforce the direction of the UK’s wider response to money mule activity: firms need to look beyond individual accounts and make better use of the intelligence generated through their investigations. Stronger detection remains essential, but identifying wider networks and sharing relevant information across the financial system will be critical to disrupting the infrastructure that allows fraud proceeds to move and be cashed out.

