The Mule Chain Playbook: What the FCA’s Money Mule Review Tells Every Payments Firm

September 29, 2026 By FinCheck

Every fraud has a second act. The scam, the phishing text, the fake investment platform: these get the headlines. But the money has to go somewhere, and that “somewhere” is almost always an ordinary account opened by an ordinary-looking customer. On 23 September 2026 the UK Financial Conduct Authority published a multi-firm review of money mules that puts hard numbers on that second act, and the message for banks, e-money institutions, payment firms and money transmitters on both sides of the Atlantic is uncomfortable.

What the FCA found

The review surveyed 35 regulated firms and drew on a public/private cell of 22 firms that analysed 140 cases across seven fraud types. Firms closed 238,396 suspected mule accounts in 2025, up from 184,935 in 2023, and roughly 656,600 customers were offboarded across the three years. Nearly half of the accounts (47.1%) were closed within their first year of life.

The finding that matters most operationally is about structure, not volume. Criminals moved fraudulent funds through multiple accounts, usually cashing out between the second and fifth account, with the heaviest concentration at the second. The FCA also concluded that the evidence points to established criminal infrastructure rather than isolated or opportunistic misuse, with the same accounts reused across multiple fraud types.

The profile is changing, and so is the rail

The stereotype of the student mule is out of date. The 26–39 age group is the largest, and the 40–49 group is growing fastest. E-money institutions saw a 164.6% increase in offboarding between 2024 and 2025, and 74.1% of their mule accounts were closed within six months, against 56.9% for payment institutions. Cash-out routes were equally telling: card payments for low-value items, international transfers to South Asia, West Africa and the Middle East, and cryptocurrency at lower volume but higher individual values, which the FCA read as deliberate laundering.

Put simply, mule networks follow the path of least friction. As banks tighten onboarding, activity migrates to faster, lighter-touch rails: e-wallets, prepaid, instant payments, remittance and crypto on-ramps. That is precisely where many FinCheck clients operate.

Why this matters beyond the UK

The FCA’s review is UK regulation, but the typology is global. US money services businesses, payment facilitators and sponsor-bank FinTechs see the same layered chains, and FinCEN’s recent work on scam centers, health care fraud and human smuggling all describe the same pattern: proceeds fragment across many accounts within hours. Examiners in every jurisdiction are converging on one question: can you see the chain, or only the account?

There is also a shared-liability point. The FCA explicitly expects firms to use the information-sharing provisions of the UK’s Economic Crime and Corporate Transparency Act 2023. In the US, Section 314(b) offers a comparable safe harbour that too many non-bank institutions leave unused.

Where programs typically fall short

Across the programs we review, the same gaps recur. Monitoring is built around single-account thresholds instead of network behaviour, so the second-account “pass-through” pattern of rapid in, rapid out with a near-zero retained balance goes unnoticed. Onboarding controls verify identity at day one but do not re-test it when device, login or payee behaviour changes. Offboarding is treated as an endpoint rather than as intelligence: the closed account’s counterparties, devices and funding sources are rarely fed back into rules. And suspicious activity reporting often describes the mule account without describing the network around it.

FinCheck’s perspective & way forward

Mule risk is a design problem, not a headcount problem, and it can be addressed in a defined sequence.

  • Map the chain, not the account. Add network and velocity typologies to monitoring: fan-in from unrelated senders, rapid onward payments, shared devices or addresses, and dormant-then-active profiles.
  • Focus on the first 90 days. With nearly half of mule accounts closed in year one, enhanced early-life monitoring gives the best return on analyst time.
  • Close the loop. Feed every offboarding into rule tuning, watchlists and information-sharing, and use 314(b) or its local equivalent deliberately.
  • Document a risk-based rationale. Regulators do not expect zero mules; they expect proportionate controls, evidence of testing and a credible governance trail. An independent review of scenarios and thresholds is the cleanest way to produce it.
  • Extend to your vendors. If a third-party platform runs your onboarding or monitoring, your mule controls are only as strong as its configuration and your oversight of it.

Closing thought

Mule accounts are not a side issue in fraud; they are the laundering infrastructure of fraud. Firms that can see and disrupt the second account will stop the money, help victims and protect their own licences.

FinCheck LLC provides AML program design, independent AML audits, transaction monitoring tuning, sanctions and KYC advisory, and fractional CCO services for MSBs, payment firms, FinTechs, crypto businesses and gaming operators. If you would like a practical review of your mule-detection controls, message us here on LinkedIn to arrange a conversation.