UK firms offboarded 238,396 suspected money mules in 2025, but the share filed to the National Fraud Database fell to 15.3%. What compliance teams must do.
Table of contents
UK firms offboarded 238,396 suspected money mules in 2025, yet filed only 15.3% of them to the National Fraud Database. Detection of money mule accounts improved while the shared signal weakened. The FCA review of 23 September 2026 sets supervisory expectations, not new rules.
- Reported offboarding rose 28.9% across three years to 238,396, but growth has stalled: the 2024 to 2025 rise was just 2.2%.
- The share of offboarded customers filed to the National Fraud Database fell from 17.4% in 2024 to 15.3% in 2025.
- Payment and e-money institutions filed just 320 cases, a 1.2% filing rate against the 15.3% sector average.
- Criminals usually cashed out between the second and fifth account, with the heaviest concentration at the second.
- The sharing gateway has been open since January 2024, and since February 2026 the lawful basis question has eased too.
What did the FCA actually find?
Firms offboarded 238,396 suspected money mules in 2025, up 28.9% on 2023, but filed only 15.3% of them to the National Fraud Database. The FCA drew the figures from a survey of 35 firms plus a public and private sector cell of 22 regulated firms that traced 140 cases across 7 fraud types.
Steve Smart, the FCA's executive director of enforcement and market oversight, said in the FCA's press release that "banks, law enforcement, technology companies and consumers all have a role to play".
Across the three years firms offboarded 656,600 customers. The FCA is careful to note that rising closures may reflect customer growth and better detection rather than a higher proportion of mules. It also says offboarding slowed in the final year, a qualifier the headline numbers hide. For scale, the National Crime Agency estimates more than £100bn is laundered through the UK or UK corporate structures each year.
| Measure | 2023 | 2024 | 2025 |
|---|---|---|---|
| Suspected mules offboarded | 184,935 | 233,269 | 238,396 |
| Change on prior year | not applicable | up 26.1% | up 2.2% |
| Share filed to the NFD | 19.7% | 17.4% | 15.3% |
Change on prior year is calculated from the FCA figures.
The profile is also shifting. Offboarding among customers aged 40 to 49 rose 79.8% against 2023, the sharpest increase of any age group, while under-16 offboarding fell 23.4%, though still 13.5% above 2023 levels. Under-16s are the only age band the FCA reports shrinking, and under-18s together were just 3.7% of 2025 offboarding, so controls tuned to minors chase a small slice. The bulk sits higher: 18 to 25 year olds were 32.8% of the 2025 age return, and our Cifas coverage puts 57% of mule cases under 30.
Why does the reporting rate matter more than the closures?
Closing an account protects one firm. Filing the case to a shared database protects the next one. A control that stops at one firm's perimeter solves very little. In 2025 those two things moved in opposite directions: firms shut more money mule accounts than in any year the FCA surveyed and passed on proportionally fewer of them.
That divergence is the substance of the review. Retail banks and building societies submitted 23,397 filings in 2025, 64.1% of the total. Challenger banks submitted 12,785. Payment institutions filed 215 and e-money institutions 105, against none reported in 2023. Applying the published shares for retail and challenger banks, with payment and e-money institutions as the residual, to the 238,396 total shows where the sector rate comes from.
| Firm type | Share of 2025 offboarding | 2025 NFD filings | Implied filing rate |
|---|---|---|---|
| Retail banks and building societies | 56.1% | 23,397 | 17.5% |
| Challenger banks | 33.0% | 12,785 | 16.3% |
| Payment and e-money institutions | 10.9% | 320 | 1.2% |
| All surveyed firms | 100% | 36,502 | 15.3% |
Zyphe calculation from FCA published figures; the sector row reconciles to the FCA's own 15.3%. The FCA reports segment shares on slightly different bases, so read the segment rows as close approximations rather than exact rates. The outlier is payment and e-money institutions, at 1.2% even as e-money offboarding rose 164.6% year on year.
One qualifier deserves emphasis. The FCA states plainly that the threshold for filing to the National Fraud Database differs from the threshold for closing an account, and that it does not expect the two numbers to match. Cifas members must have reasonable grounds to believe fraud or financial crime has been committed or attempted, supported by clear evidence. A firm may close money mule accounts on suspicion that falls short of that evidential bar. So the gap is not, by itself, evidence of under-reporting.
The direction is the concern rather than the level. Cifas introduced a dedicated money muling category in January 2025, replacing the broader misuse of facility classification. A purpose-built category with revised criteria should make correct filing easier, not harder. The rate fell anyway. The 2026 picture may already differ: our coverage of the Cifas first-half 2026 data reports muling cases up 69% to more than 13,000, so the decline the FCA measured in 2025 may be reversing as the new category beds in.
What does this change for your obligations?
Nothing in this publication changes the law. A multi-firm review is a supervisory document: the FCA says firms "should" review their controls and strengthen them where necessary. Treat it as the standard against which your next supervisory conversation will be measured, not as a new rule with a commencement date.
On customer due diligence and ongoing monitoring, the FCA found 114,984 money mule accounts closed within the first year of opening in 2025, 47.1% of the account tenure total and including 55,353 inside three months. E-money institutions closed 74.1% of their money mule accounts within six months and payment institutions 56.9%, so for those firms the control that matters runs in the first weeks. For retail banks the opposite holds: 45.4% of their closures were accounts open more than two years, so there the burden falls on ongoing monitoring.
On suspicious activity reporting, nothing here displaces the obligation to report under the Proceeds of Crime Act 2002. A suspicious activity report to the UK Financial Intelligence Unit and a Cifas filing serve different purposes and neither substitutes for the other.
On information sharing, the FCA points firms to the voluntary provisions in the Economic Crime and Corporate Transparency Act 2023, the same Act behind Companies House identity verification. The legal position is better than many teams assume. Section 188, covering direct disclosure between firms, and section 189, covering indirect disclosure through an intermediary, both came into force on 15 January 2024. Both disapply obligations of confidence and civil liability for qualifying disclosures. Section 189 is narrower: it reaches deposit-taking bodies, electronic money institutions, payment institutions, cryptoasset exchange providers and custodian wallet providers. It also reaches audit, insolvency, accountancy, tax and legal firms with UK revenue above £36 million, described in the statute since April 2026 as bands B to D.
There is a practical point the review does not spell out. Home Office guidance, updated on 3 October 2025, says that for indirect sharing firms should rely only on the warning condition, not the request condition, so a firm may upload a customer to an intermediary database only where it has decided to take safeguarding action. Safeguarding action means terminating, refusing or restricting a customer because of economic crime concerns. An offboarding for suspected muling is exactly that, so the trigger is already met every time a firm closes one of these accounts.
The limit is data protection, and that limit moved this year. Section 188 expressly preserves the data protection legislation. But since 5 February 2026, section 70 of the Data (Use and Access) Act 2025 has inserted Article 6(1)(ea) into the UK GDPR and made processing necessary for "detecting, investigating or preventing crime" a recognised legitimate interest at Annex 1 paragraph 5, which removes the balancing test. What survives is Article 10: mule intelligence is criminal offence data. A Data Protection Act 2018 Schedule 1 condition is still required. The usual one here is paragraph 14, covering disclosure by a member of an anti-fraud organisation such as Cifas, and on 5 February 2026 it was widened to cover processing in preparation for that disclosure. That, rather than confidentiality or lawful basis, is now the binding constraint.
What is still uncertain?
Five things the review does not settle: when muling actually started on a closed account, how much of the filing drop is reclassification, what the growing unknown-gender bucket hides, what wider monitoring costs a small payment institution, and what the FCA does about a firm whose filing rate keeps falling.
The tenure data does not say when muling started. The FCA states this openly: the figures show how old the closed accounts were, not when the suspected activity occurred. The published data cannot distinguish a mule from day one from an account recruited last year.
The demographic series carries real measurement noise. The proportion of records where gender was unknown, not collected or withheld rose from 24.1% in 2024 to 30.1% in 2025, which the FCA says limits the conclusions available.
The 2025 filing numbers are not cleanly comparable with earlier years, because the Cifas category changed in January 2025. The FCA flags this, and it cuts both ways: the falling rate could partly reflect reclassification rather than behaviour, though it was already falling before the change, from 19.7% in 2023 to 17.4% in 2024.
The cost question is unaddressed. The review tells firms to look beyond the initial receiving account to linked accounts, payment characteristics and broader transaction context. For a small payment institution that is a material engineering programme, and the review offers no proportionality guidance beyond saying controls should match the risks a firm faces.
Finally, enforcement posture is unclear. The FCA says it will work with the National Economic Crime Centre to issue an alert and will keep monitoring firms through supervisory work. It does not say what follows for a firm whose filing rate keeps falling, which leaves a supervisory conversation as the only stated consequence.
Why is this an identity problem rather than a fraud problem?
Money mule accounts are hard to stop because the identity is usually real. A recruited mule presents a genuine document, passes a liveness check and clears onboarding cleanly, because nothing about the person is forged. Document-centric verification is the wrong instrument: there is no forgery to find.
What separates a mule from an ordinary customer is history held somewhere else. Cash out concentrates between the second and fifth account in a chain, with the heaviest concentration at the second, which means the decisive moment is usually the next firm's onboarding or early monitoring decision. That firm can only act on a signal the previous firm passed on.
The legal obstacles have mostly gone. What remains is moving a minimal, lawful signal about money mule accounts between firms without building another database of personal data to defend. That is a real incentive problem, sharpened by the identity vendor breaches of the last year.
How should compliance teams respond?
Start with the number your supervisor will ask for: your own filing rate against the 15.3% sector figure. The rest follows from where the review found the gaps, in early-life monitoring, in section 189 scope, and in whether closure records survive as usable intelligence.
If your rate is falling, establish whether that is threshold discipline or friction. Move detection earlier: if roughly half of money mule accounts are closed inside their first year, perpetual KYC and early-life monitoring matter more than periodic review. Check scope carefully, since the section 189 list is narrower than the general regulated sector. Then make closure records linkable to later attempts, the way mature transaction monitoring programmes retain and reuse case outcomes.
Zyphe approaches this from the identity side. Reusable, privacy-preserving verification lets a network share the fact that an identity carries risk without moving the underlying personal data between firms. If you are rebuilding mule controls around shared signal rather than document checks, book a demo or read how our AML software and KYC software handle cross-firm risk signals.
The bottom line
The uncomfortable finding in this review is not that firms are missing mules. They are closing more accounts each year, and the operational picture the cell produced is far better than the sector had before. The problem is that the intelligence is not travelling. A closure protects one balance sheet; a filing protects the network, and the network is where mule chains operate. The legal excuses for not sharing have been falling away since January 2024, and another went in February 2026. What is left is an operational choice, and until it changes firms will keep independently rediscovering the same money mule accounts while criminals cash out two hops downstream of wherever the last firm looked.
Cited sources
- FCA, Money mules: mule activity and cashing out findings, 23 September 2026
- FCA press release, Firms crack down on money mules but need to do more
- Economic Crime and Corporate Transparency Act 2023, section 188
- Economic Crime and Corporate Transparency Act 2023, section 189
- Data (Use and Access) Act 2025, section 70 and Schedule 4
- Home Office, Guidance on the information sharing measures in ECCTA 2023
- Data Protection Act 2018, Schedule 1 paragraph 14
- Finance Act 2022, section 55 (UK revenue bands)
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.