
FCA money mules review: closing accounts is not enough
TLT picks out the key points you shouldn't miss...
What's this about?
The FCA's latest review of money mule activity sends a clear message to regulated firms: identifying and closing suspected mule accounts remains important, but it is not enough on its own. Criminal groups continue to move fraud proceeds through chains of accounts before cashing out, meaning firms must focus not only on detecting mule accounts, but on disrupting the wider networks behind them.
Our Financial Services Regulatory Partner, Ben Cooper says...
"The FCA's review shows that offboarding suspected mules is necessary, but not sufficient. Firms need to identify and disrupt criminal activity earlier, make better use of intelligence-sharing and understand how funds move through the wider payment ecosystem. Those that view this as a narrow compliance exercise risk both regulatory scrutiny and continued financial crime exposure."
The points not to miss...
Reported offboarding of suspected mule accounts increased to 238,396 in 2025. Whilst that reflects increased detection activity, the FCA's findings indicate that criminal networks continue to operate at scale, often using accounts repeatedly and across multiple fraud typologies.
Rising offboarding volumes should not be mistaken for success. The review suggests criminal groups are adapting rather than retreating, reinforcing the need for firms to focus on prevention and network disruption as well as account closures.
Fraud proceeds were typically cashed out between the second and fifth mule account in the payment chain, with the highest concentration occurring at the second account.
As funds move through multiple accounts they become harder to identify, trace and recover. Firms should therefore focus on detecting suspicious activity as early as possible, particularly at the start of the payment chain where intervention is most effective
The FCA found that card payments are commonly used to monetise fraud proceeds, often through multiple low-value purchases or higher-value spending with merchants and retailers.
Because these transactions can closely resemble legitimate consumer activity, firms should ensure their monitoring frameworks are capable of identifying suspicious spending behaviours rather than relying solely on traditional red flags.
The review highlights opportunities for firms to share more intelligence relating to suspected mule activity, including through the voluntary information-sharing provisions introduced by the Economic Crime and Corporate Transparency Act 2023 ("ECCTA"). The FCA's findings suggest that information-sharing remains an underutilised tool in the fight against fraud and money laundering.
Timely information-sharing can help firms identify linked accounts, recurring laundering methodologies and common cash-out routes before funds disappear from the financial system. It can also improve firms' understanding of wider criminal networks, enabling earlier intervention and more effective disruption of fraudulent activity.
Firms should consider whether their governance, legal and compliance frameworks enable them to make effective use of these powers. The publication of UK Finance's guidance on information-sharing under ECCTA has provided firms with practical examples of how these provisions can be used in practice whilst managing legal, regulatory and data protection considerations. Firms that have not yet assessed how they might operationalise these powers may wish to do so.
The FCA identified recurring overseas destinations for mule-related funds, including jurisdictions in South Asia, West Africa and the Middle East. Whilst crypto-related cash-outs were lower in volume, they tended to be higher in value.
Firms with cross-border payment activity or crypto-related exposure should ensure that these risks are appropriately reflected within their financial crime risk assessments, controls and monitoring frameworks.
Customers aged 26 to 39 continued to account for the largest proportion of offboarded mule accounts. However, the fastest growth was seen in the 40 to 49 age group.
The findings suggest firms should regularly reassess customer risk models and avoid assuming that mule activity is predominantly associated with younger customers. Risk indicators should evolve alongside criminal behaviour.
The review found increasing levels of suspected mule activity involving business accounts, charities, non-profits and other legal entities.
Although overall volumes remain relatively low, the trend suggests firms should review whether onboarding, monitoring and enhanced due diligence controls adequately capture risks associated with non-personal customers, particularly SMEs and third-sector organisations.
Whilst firms submitted more than 113,000 National Fraud Database filings over the review period, the proportion of offboarded customers reported to the database decreased during the most recent year.
The FCA's observations suggest firms should review their internal governance, evidential thresholds and processes relating to Cifas reporting to ensure that the National Fraud Database is being used effectively as part of a broader anti-fraud strategy.
The review found that different types of firms experience different patterns of mule activity. Retail banks generally see higher transaction volumes, while other firms often encounter fewer but higher-value transactions.
A one-size-fits-all approach is unlikely to be sufficient. Firms should ensure that monitoring, governance and investigative controls are calibrated to their own risk profile and customer base.
The FCA has indicated that it will continue working with the National Economic Crime Centre and will use supervisory activity to assess how firms are responding to evolving mule risks.
Firms should treat the review as an opportunity to assess the effectiveness of their current framework rather than waiting for direct regulatory engagement.
What firms should do now
In light of the FCA's findings, firms should consider whether:
- transaction monitoring controls can identify suspicious activity before funds move through multiple mule accounts;
- monitoring frameworks adequately capture mule-related card payment behaviours;
- customer risk models reflect changing demographic trends;
- National Fraud Database and Cifas reporting processes are operating effectively;
- ECCTA information-sharing powers are being used where appropriate and the firm has a clear framework for sharing and receiving intelligence; and
- governance and oversight arrangements provide sufficient visibility of emerging mule typologies and cash-out methods.
Our view
The review reinforces a broader regulatory trend. The FCA increasingly expects firms not only to identify financial crime risks, but to demonstrate that their controls are effective, proportionate and capable of adapting to evolving criminal methodologies.
For many firms, the most significant message is not the volume of mule accounts being identified, but the continued emphasis on intelligence-sharing, network disruption and proactive risk management. Firms that use this review as an opportunity to test and strengthen their anti-mule framework are likely to be better placed when supervisory scrutiny follows. As industry guidance and market practice around ECCTA information-sharing continue to mature, firms have an increasing opportunity to identify linked criminal activity beyond their own customer base and take a more proactive role in disrupting financial crime.
At a glance...
This publication is intended for general guidance and represents our understanding of the relevant law and practice as at September 2026. For more information see our terms & conditions.
Get in touch
Related services
Get in touch
Insights & events

FCA AML supervision reform: what law firms, accountants and TCSPs need to do now

FCA money mules review: closing accounts is not enough

FCA Pure Protection Market Study: what firms need to know

FCA Pure Protection Market Study: Fair value findings - what firms need to do

FCA reviews payments firms' support for vulnerable consumers under Consumer Duty

FCA regulation is not a major barrier to SME finance – but challenges remain

AML reform is accelerating: what firms should take from the UK’s 2026–2029 strategy

Tightening the net: rising evasion risks and escalating penalties

The Failure to Prevent Fraud offence – one year on

Open finance meets mortgages: the FCA sets out its vision – but the hard work starts now

Frontier AI and cyber resilience: what financial services firms need to know now

Consumer Credit Act 1974 (CCA) reform: summer recap

FOS confirms major overhaul of the complaints process – what firms need to know

FCA puts asset managers on notice: financial crime controls falling short

Tipping off under POCA: the first Court of Appeal authority arrives

FCA raises the bar on Consumer Duty outcomes monitoring: what your firm needs to do now




%20790px%20X%20451px%2072ppi.jpg)
%20%C3%94%C3%87%C3%B4%20790px%20X%20451px%2072ppi21.jpg)
%20%C3%94%C3%87%C3%B4%20790px%20X%20451px%2072ppi.jpg)
%20%C3%94%C3%87%C3%B4%20790px%20X%20451px%2072ppi.jpg)


%20%C3%94%C3%87%C3%B4%20790px%20X%20451px%2072ppi2.jpg)


%20%E2%80%93%20790px%20X%20451px%2072ppi%20LONDON9.jpg)

