1 min read
The different roles of money mules in fraud operations
Money mule activity is often treated as a single category of risk. An account is flagged as a mule, controls are applied, and the case moves forward....
11 min read
Acoru : Jun 4, 2026, 12:29:12 PM
The UK's authorised push payment (APP) reimbursement requirement took effect on October 7th, 2024, and there is now enough data to move past the early headlines. When we first looked at this scheme, the initial numbers looked encouraging: high reimbursement rates, faster claim resolution, closer coordination between sending and receiving banks. The picture is more complete now, and for fraud operations teams, the more useful questions sit underneath the headline reimbursement rate. What does the policy reveal about incentives, detection maturity, counterparty accountability, and the structural weaknesses that APP fraud continues to exploit?
The reimbursement regime is more than a consumer protection policy. It is a stress test of a bank's fraud architecture, and increasingly, of every jurisdiction now deciding whether to follow the UK's lead.
The UK's reimbursement regime reshaped the economics of APP fraud. By splitting liability between sending and receiving firms, the framework created financial accountability on both sides of a payment for the first time.
Sending institutions now have to invest more heavily in detecting manipulation and emerging victimisation. Receiving institutions can no longer treat inbound monitoring as secondary. Mule account detection now directly affects their loss exposure. Under a shared-liability model, weaknesses in counterparty monitoring translate into shared cost, which is pushing fraud teams toward ecosystem thinking rather than perimeter thinking.
That shift matters because APP fraud depends on infrastructure, particularly the intermediary mule accounts that receive, layer, and disperse funds. The incentive now runs in the right direction: strengthen inbound surveillance, accelerate interbank information sharing, and tighten onboarding scrutiny where mule activity tends to concentrate.
The more interesting shift, though, is how fraud adapts to the edges of the rules. The reimbursement regime applies to specific payment types, mainly domestic Faster Payments and CHAPS transfers within the UK. It does not cover most cryptocurrency transactions, cross-border transfers, or a range of alternative payment platforms. Fraud networks are adapting to that boundary. Funds increasingly route through hybrid structures: a domestic transfer followed by rapid crypto conversion, cross-border layering, or a move to a fintech platform sitting outside the scheme's scope. Regulation can reduce loss within its perimeter while pushing fraud displacement beyond it.
There is also a quieter, behavioural effect inside institutions. With reimbursement largely mandatory and the negligence exemption used sparingly, post-loss debate has become less commercially useful, and the economics now favour prevention over adjudication. Fraud teams are under pressure to reduce exposure upstream: identifying risky counterparties, catching aggregation patterns early, and spotting trajectory signals before a transaction is initiated, rather than reacting once the payment has already gone.
In the 15 months to the end of 2025, payment firms reimbursed 89% of claimed and in-scope APP fraud losses, worth £243 million, up from a 65% voluntary reimbursement rate before the scheme began. Response times have improved too: in the PSR's one-year review, 84% of claims were resolved within five days and 97% within 35 days.
Look one quarter closer and the trend is less clean. In Q4 2025, the reimbursement rate dipped to 85%, even as the amount reimbursed rose 15% quarter on quarter to £70.2 million. Reimbursement rates move with claim mix, not just with how well firms are performing, which is part of why regulators are cautious about treating the headline percentage as a scorecard.
An independent review by Frontier Economics, published by the PSR on 1 July 2026, found the policy delivered a net benefit in its first year: APP fraud losses sent over Faster Payments fell by around 21% following implementation, a reduction estimated at roughly £73 million. That is the strongest evidence yet that shared liability changes behaviour, not just claims processing.
Set against UK Finance's Annual Fraud Report 2026, the picture gets more complicated. Across all APP fraud, not just the subset in scope for the PSR's reimbursement requirement, losses rose 19% in 2025 to £576.4 million across 248,070 cases, and banks reimbursed £354.3 million, 61% of that broader total. The two data sets are not contradictory:
Investment fraud drove much of the increase, up 40% to £221.5 million, the single largest category of loss. Two-thirds of APP fraud still starts on an online platform, and 17% starts on a telecoms channel; banks remain downstream of where the deception begins.
Enforcement has teeth, too. In February 2026, the PSR fined Bank of Ireland UK for missing its implementation deadline for Confirmation of Payee, the account-name-check mechanism the regulator treats as a baseline control against APP fraud. And trust data from the PSR's one-year review shows why prevention still outperforms reimbursement as a strategy: half of victims who were reimbursed say their trust in their bank increased, against roughly one in three among victims who were not.
Put together: reimbursement is working as a safety net. It is not reducing the number of people who get scammed, and it was never built to.
The current rules apply to authorised transfers between UK bank accounts over Faster Payments and CHAPS. That scope is deliberate, but it creates a clear boundary. Cryptocurrency wallets, certain cross-border transfers, and a range of alternative payment platforms sit outside the protective layer entirely.
As liability tightens within reimbursable flows, fraud networks have a rational incentive to move monetisation toward channels with weaker recall mechanisms or no regulatory coverage. A domestic push payment followed by rapid crypto conversion, or an immediate onward transfer to an overseas account, can move funds beyond the scheme's reach before a claim is even filed.
There is a legal boundary too. In Santander UK plc v CCP Graduate School Ltd, a business that had been deceived into authorising payments of more than £415,000 into a fraudster-controlled Santander account argued that Santander, as the receiving bank, owed it a duty to try to retrieve the funds once notified. In March 2025, the High Court struck the claim out, holding that a receiving bank owes no free-standing duty to a third-party victim it has no contractual relationship with, simply because the fraudster happened to bank there. The court was clear that a receiving bank's primary obligation runs to its own customer's instructions, not to a stranger's losses.
Outside the formal reimbursement framework that covers consumers, microenterprises, and charities, most business victims have limited legal recourse against institutions that unknowingly facilitate the monetisation stage of a scam. For fraud teams, that reinforces the same conclusion: the protection sits in catching the pattern early, not in relying on redress after the fact.
Fraud and compliance leaders tracking this scheme now have a second variable to watch: who regulates it. On 21 April 2026, HM Treasury confirmed it will abolish the Payment Systems Regulator and fold its functions into the Financial Conduct Authority. The Financial Services and Markets Bill 2026 had its first reading in the House of Lords on 19 May 2026, and the two regulators have already moved to shared leadership ahead of the formal transfer.
The PSR keeps its statutory powers and continues to operate, including its APP fraud remit, until the transfer completes, so nothing changes for institutions in the near term. What is worth watching is where the independent review of the reimbursement requirement lands. Legal commentary suggests receiving-PSP standards are likely to be the next area the regulator consults on, based on what the first year of data has shown about where liability concentrates.
That is the exact question our continuous account classification is built to answer: not just whether a receiving account looks suspicious after the fact, but how its risk classification evolved in the run-up to the payment.
For international banking groups and US institutions watching the UK's experience, it is worth being precise about where the rest of the world actually stands. One note on naming, because it trips up a lot of coverage: the UK's regulator is the Payment Systems Regulator, also abbreviated PSR. The EU's new Payment Services Regulation is unrelated legislation that happens to share the same acronym. We have spelled out which is which below.
|
Region |
Mechanism |
Status in 2026 |
|---|---|---|
|
UK |
Mandatory reimbursement requirement under PS23/4, consolidated in PS25/5. 50/50 sending/receiving split, £85,000 cap |
Live since 7 October 2024. Oversight moving from the Payment Systems Regulator to the FCA |
|
EU |
PSD3 and the new EU Payment Services Regulation, requiring explainable, auditable fraud controls and expanded PSP liability |
Text approved by Parliament's ECON committee in May 2026, heading toward formal adoption and Official Journal publication. Full application not expected before 2027 to 2028 |
|
US |
No federal reimbursement mandate. Regulation E covers unauthorised transactions, not scams the customer was deceived into authorising |
The CFPB dropped its Zelle enforcement case in March 2025. New York's separate suit against Zelle operator Early Warning Services survived a motion to dismiss in July 2026 and is proceeding toward trial. Nacha's 2026 credit-push fraud monitoring rules, phased in across March and June 2026, add detection obligations across the ACH network without a reimbursement requirement attached |
The direction of travel is consistent even where the mechanism differs. The UK legislated a liability split. The EU is close behind with an explainability and auditability standard. The US, absent federal action, is getting there through litigation and through NACHA's ACH-specific rules rather than a single statute.
For US financial institutions watching the UK experience, the lesson is less about copying the reimbursement mechanism and more about what happens if an institution waits for regulation to force detection maturity rather than building it ahead of the mandate. New York's case argues Early Warning Services could have deployed stronger identity verification and anti-fraud controls before losses reached the scale prosecutors allege. That is close to the same conversation UK banks were having in 2023, before PS23/4 made prevention mandatory.
APP fraud runs through a predictable lifecycle, but a bank only ever sees part of it. The deception begins out of view, and stays invisible until the victim moves money. From that point there are two chances to intervene, and they fall to two different banks: the sending bank as the payment leaves, and the receiving bank as it arrives. If neither acts in time, the funds are split across layered accounts and moved on, often within minutes and well before the victim realises, leaving little that can be practically recovered.

Where banks act today
The problem is that the two points where banks typically act are already the closing stages. By then the victim has been manipulated and the receiving account is already in place. The better moments come earlier: while a customer's behaviour is drifting under a scammer's influence, and while the receiving infrastructure is being set up and tested. Neither is fully outside a bank's view. Behavioural signals sit in the run-up to the payment, and mule accounts leave detectable traces as they are opened and tested. Acting in that preparation window is the difference between preventing a loss and processing a claim.

Where banks could act earlier
For a closer look at what those early signals actually look like inside a bank's existing systems, see our guide to payment fraud red flags and three best practices for detecting APP fraud in banking.
Loss exposure now sits on both sides of the payment flow, which means a fraud posture has to extend to the accounts receiving funds as much as the accounts sending them. Monitoring outbound behaviour alone will not protect an institution. What is needed is continuous visibility into counterparty risk, inbound aggregation patterns, and emerging mule activity, not just at the moment of payment but across the weeks that precede it.
Coordination with other institutions goes beyond a compliance exercise; it becomes part of the core control environment. If APP fraud operates across the ecosystem, detection strategy has to do the same. We go deeper on why shared intelligence changes detection outcomes in why collaboration is key in fraud detection, and on how account-level context strengthens existing controls in strengthening transaction monitoring with continuous account intelligence.
Most scams are set in motion long before the money moves, so the strongest signals show up in how a customer behaves in the run-up to a payment, not in the payment itself.
The reimbursement model makes post-loss processing less commercially defensible than pre-loss interruption.
On the receiving side, the task is to recognise an account being used to collect and move stolen funds, and to act before the balance is dispersed beyond recovery.
Reducing reimbursement exposure increasingly depends on how quickly an institution identifies and disables receiving infrastructure. We cover the different ways mule accounts get used, from unwitting to complicit, in the different roles of money mules in fraud operations, and the specific indicators to watch for in money mule red flags and how to detect mule accounts.
Once funds convert to crypto or cross a border, recovery becomes far harder, so the window that matters is the domestic leg: the moment before money leaves reimbursable rails.
As liability tightens within Faster Payments, fraud pressure is likely to keep shifting toward less protected channels.
Two years of data make one thing clear: the UK's reimbursement regime improves outcomes for victims. It accelerates claim handling. It strengthens interbank communication, and the independent evidence now shows it is genuinely reducing losses within its perimeter.
What it has not done, and was never designed to do, is remove the underlying conditions that let APP fraud thrive. Real-time payments, external social engineering channels, and monetisation infrastructure built around mule networks and rapid dispersal are all still there.
INTERPOL's 2026 Global Financial Fraud Threat Assessment estimates $442 billion in financial fraud losses worldwide in 2025 and finds that AI-enhanced fraud is now roughly 4.5 times more profitable than traditional methods, with agentic AI systems able to plan and run entire fraud campaigns with minimal human input. The infrastructure side of the problem is scaling faster than any single reimbursement scheme can absorb.
Banks typically encounter these scams at the monetisation stage, which means the decisive leverage points sit well before a customer calls to complain or a claim gets filed. Reducing exposure calls for continuous visibility into the accounts that receive funds, the networks they connect to, and the behavioural signals that indicate emerging victimisation before a high-value transfer is initiated. Fraud teams need to evaluate every event across every channel, not in isolation, but in the context of the accounts involved, both first-party and counterparty.
This is where our Continuous Account Intelligence Platform aligns with the direction regulation is already pushing the market toward. By ingesting data from across an institution, orchestrating signals across every channel, and continuously classifying accounts as potential victims, mules, or laundering nodes, we help fraud teams surface pre-fraud signals before the dots connect elsewhere. Instead of reacting once a claim is raised, they gain the ability to identify risky trajectories and monetisation clusters early, before a transaction is initiated, not after.
Reimbursement schemes absorb losses after fraud succeeds. Account-level intelligence reduces the probability that those losses happen in the first place.
Authorised push payment (APP) fraud reimbursement is a regulatory requirement, mandatory in the UK since October 2024, that obliges payment firms to refund customers who were deceived into authorising a payment to a scammer. It differs from unauthorised fraud protection because the customer, not a criminal, initiated the transaction, just under manipulation.
Up to £85,000 per claim for in-scope Faster Payments and CHAPS transfers, under the PSR's policy statement PS23/4, consolidated in PS25/5. Firms can apply an optional excess of up to £100, except for vulnerable customers, and must resolve most claims within five business days, or 35 if more information is needed.
The cost is split 50/50 between the sending payment service provider and the receiving payment service provider. This is the mechanism that turned receiving-side mule account detection from a secondary concern into a direct driver of loss exposure.
Partially, and the two most recent UK data sets show why the answer is nuanced. The PSR's independent review found Faster Payments APP losses fell around 21% after the requirement took effect, evidence that shared liability changes bank behaviour. At the same time, UK Finance's Annual Fraud Report 2026 recorded a 19% rise in total APP fraud losses across the wider market in 2025. Reimbursement is compressing losses within its own scope while total fraud, driven largely by investment scams and AI-enabled social engineering, continues to grow around it.
Not yet, in most markets. The EU's PSD3 and its new Payment Services Regulation introduce explainable, auditable fraud controls but are not expected to fully apply until 2027 to 2028. The US has no federal reimbursement mandate; Regulation E does not cover authorised scam payments, and liability questions there are currently being tested through state litigation, including New York's ongoing case against Zelle's operator, rather than through federal rulemaking.
Nothing changes immediately. The Payment Systems Regulator keeps its statutory powers, including its APP fraud remit, until the transfer to the FCA is complete. HM Treasury has said it intends to preserve the substance of the PSR's objectives, but institutions should expect the FCA to take over supervision, including any follow-up consultation on receiving-PSP standards that comes out of the independent review.
By shifting detection earlier, into the weeks before a payment is made rather than the hours after a claim is filed. That means continuously classifying both first-party and counterparty accounts, tracking behavioural drift and mule-account setup as they happen, and connecting signals across channels instead of scoring transactions or sessions in isolation. This is the approach behind our Continuous Account Intelligence Platform.
1 min read
Money mule activity is often treated as a single category of risk. An account is flagged as a mule, controls are applied, and the case moves forward....
1 min read
Authorized push payment (APP) fraud is a type of scam in which criminals manipulate victims over days or even weeks before convincing them to...
1 min read
Instant payment platforms like Pix in Brazil and CoDi in Mexico have transformed how money moves. What once took days now happens instantly. For...