CasePilot

Authorised push payment fraud: victim or mule?

When fraudulent funds land in an account, the person who holds that account might be a criminal, a recruited helper, or someone being controlled by another person. The data narrows it, but never all the way. This note sets out what I actually look at, in what order, and how to keep the decision humane when the evidence is thin.

The same alert, three different people

A payment arrives. Within the hour, it leaves. The sending bank raises a fraud claim two days later and the receiving account is now sitting on your desk with a name against it and very little else.

In the teams I have run, this is the alert that separates the analysts who are learning from the ones who have learned. The junior instinct is to decide immediately: mule, close it, file. The instinct after a few years is the opposite — to keep the account open indefinitely because you cannot prove anything. Both are failures of nerve dressed up as judgement.

The account holder receiving fraudulent funds is one of at least four people. They may have sold or rented their account details for a fee. They may have been recruited through a job advert and believe they are processing payments for a legitimate employer. They may be under the control of a partner, a family member, a trafficker or a debt collector, and have no meaningful choice at all. Or they may themselves have been defrauded — persuaded to receive money and move it on as part of a romance or investment approach, in which case they are the second victim in the chain, not a participant in it.

Your job is not to establish which of these is true beyond doubt. Your job is to describe the account behaviour accurately, decide what protective action the evidence supports, and preserve the distinction between what you observed and what you inferred. An alert is arithmetic. It is not an accusation, and the file you write should read that way.

What the data actually distinguishes

There are five signals I weigh, and they are not equal.

Account age and prior activity

An account opened eleven weeks ago that has done almost nothing until a five-figure credit arrives is a different object from a twelve-year-old current account with a salary, a mortgage direct debit and a school-fees standing order. Not because longevity is innocence — I have seen long-held accounts sold outright when someone's circumstances collapsed — but because a genuine victim of an authorised push payment scam usually has a life visible in the statement. Recruitment-based mule accounts often do not, or the life visible in them stops abruptly.

The pattern I find most telling is not newness but discontinuity: an account that behaved one way for three years and then, from a specific week onwards, behaves entirely differently. That week is your anchor. Something changed then, and the change is what you are investigating.

The speed of the outbound leg

This is the strongest single signal in my experience. Money that arrives and leaves within minutes, to accounts the customer has never paid before, in amounts that closely track the inbound credits, is not being used. It is being moved. A victim who has been persuaded to send money onward will usually leave a human fingerprint on the timing — a delay while they read a message, a partial payment, a round number that does not match what came in, a small amount left behind.

Layering behaviour is tidier than human behaviour. When the outbound total is ninety-something per cent of the inbound total and the residue looks like a commission, that arithmetic tells you something the customer's explanation will have to account for.

The shape of the inbound sources

One large credit from one sender is consistent with a great many innocent stories. Nine credits from nine unrelated individuals across four days, none of whom the customer can plausibly know, is a collection function. The spread of sources matters more than the total. And where the amounts sit just under a reporting or review level that applies in your jurisdiction, look at the sequencing rather than the individual figures — the same reasoning I set out in the note on what structuring looks like on a statement applies to inbound flows as much as to cash deposits.

Device, channel and access

If your firm holds device and session data, use it. Access from a device or IP range shared with other flagged accounts is close to determinative of a coordinated network. Access that suddenly moves to a new device the week the behaviour changed points towards either an account takeover or a handover of credentials. That distinction matters enormously for how you treat the customer.

What the customer says

The conversation is evidence, and it is evidence you can influence badly if you handle it poorly. More on that below.

Case note

A composite from several reviews. A personal current account, opened in 2016, ordinary use throughout: salary of about £1,850 monthly, rent, a gym membership, occasional overdraft. From 4 September the salary credits stopped. Nothing else changed until 22 October, when the account received eleven credits from nine different individuals over a nine-day window, totalling £48,600, the largest being £9,200 and the smallest £740.

Ninety-one per cent left within an average of thirty-eight minutes, split across three new payees, two of which were also under review at other firms. About £4,300 remained and was withdrawn in cash across six ATM visits. On the surface, a textbook collection-and-forward pattern, and the first analyst recommended closure and exit.

The interview changed the shape of it. The customer, a woman in her early thirties, had lost her job on 1 September. Her account access showed a new device from 19 October. She could name the three payees but not explain them, gave the same rehearsed sentence three times, and asked twice whether the call was being recorded and whether anyone else would be told. We kept the account restricted rather than closed, submitted a report to the national FIU describing both the transaction pattern and the indicators of possible coercion, and routed her to the firm's vulnerable customer team. Six weeks later she disclosed a controlling relationship. Had we exited her at the first review, she would have lost banking access at the moment she most needed it, and we would have learned nothing about the two payees.

The conversation, and how not to ruin it

An outbound call to someone whose account is receiving fraudulent funds is a delicate thing. If they are a knowing participant, you have just told a network that you are looking. If they are coerced, you may have created a risk to them at home. If they are a victim, you are about to deliver bad news badly.

I train analysts to ask open questions about the relationship and the purpose, and never to lead. "Tell me about the payments you received from these senders" is useful. "Did someone ask you to move this money for them?" invites a yes or a no that tells you nothing. Listen for the texture of the answer, not its content: rehearsal, hesitation at specific points, a script that arrives too fast, or an answer that is entirely fluent until you ask about the onward payee.

Note what you hear verbatim where you can. When the file eventually becomes a suspicious activity report, quoted speech carries far more weight with a financial intelligence unit than your characterisation of it. The worked example of a SAR narrative shows how that quoting works in practice. In the UK, reports go to the National Crime Agency; other jurisdictions route them elsewhere and on different timetables, so check your own reporting framework rather than assuming the one you trained under.

Coercion, vulnerability and the limits of a transaction record

Coerced account use does not look different from willing account use in the payment data. That is the uncomfortable truth of this work. The distinguishing signals sit almost entirely in the human layer: recent bereavement or job loss, a new person with access to the device, reluctance to speak freely, a request to call back later, evidence of an age or capacity difference between the account holder and whoever seems to be directing the flow.

Students, recent arrivals to a country, people in serious debt and people leaving care are recruited disproportionately. That is a well-documented typology rather than a reason for suspicion in itself — FATF material on laundering networks describes the recruitment layer at length, and the point of knowing it is to prompt a better question, never to substitute for one. A demographic is not a risk indicator. Behaviour is.

Where the picture is ambiguous, the answer is usually restriction plus escalation rather than exit. Freeze the outbound leg, protect the funds still present, refer to whoever in your firm handles vulnerability, and let the intelligence function do its work.

Getting it wrong, in both directions

Close the account of a genuine victim and you have compounded a fraud with an institutional harm. Unbanking someone is not a neutral act; it affects their wages, their tenancy, their benefits and their ability to be a customer anywhere else, because the exit itself becomes a marker other firms may see. The FCA has taken increasing interest in whether firms in its perimeter can evidence the reasoning behind account closures, and "the model flagged it" is not reasoning.

Leave a functioning mule account open and you have supplied a laundering channel with a legitimate front. The funds that pass through it in the following months belong to people who have not yet been defrauded.

The way out of that bind is not to make better guesses. It is to make the decision proportionate to the evidence, to write down the evidence you had and the inference you drew as two separate things, and to build in a review date. Restriction with a thirty-day reassessment is a real answer. So is exit, when the file supports it. What is not an answer is a closure recommendation whose entire basis is a fast outbound payment, which is the most common weak file I see when I review a fraud desk's output. If you are still building the habits, the alert triage checklist covers the sequencing that keeps these reviews from collapsing into instinct.

What a good file looks like

Short version: it separates observation from interpretation, it states what was not established, and it names the action taken with a date attached.

Observed behaviour — dates, amounts, counterparties, timings, device changes, stated verbatim and without adjective.

The customer's account of it, quoted where possible, with a note on how and when contact was made and whether anything about the circumstances of the call was unusual.

What remains unknown, which is the section most analysts skip and the one a reviewer reading your file eighteen months later will value most, because it tells them whether your conclusion was cautious or confident.

The decision, the reasoning and the review date.

I have never met an experienced investigator who is comfortable with this alert type. That discomfort is appropriate. You are making a decision about somebody's access to the financial system on the basis of about forty data points and one telephone call, and the honest position is that you will sometimes be wrong. What you can control is whether your file makes it possible for the next person to see how you got there.

Bottom line: The transaction data tells you what moved and how fast; only the conversation and the context tell you whether the person holding the account had any choice about it, so do not let the arithmetic finish the sentence for you.

Practise the work, not the theory

CasePilot puts you in the analyst's seat with a morning queue of alerts and authored case files — the same decisions this note describes, with a disposition to defend at the end of each one.

Open CasePilot

Or work cases offline — iOS and Android, free.