Introduction

UPI, mobile banking, digital wallets and prepaid payment instruments have made moving money faster and easier than ever. Unfortunately, the same infrastructure that makes a legitimate payment instant also lets a fraudster move stolen funds through several accounts before anyone notices.

A mule account is a bank account used to receive, hold or pass on the proceeds of fraud or other illegal activity. Sometimes the holder knows exactly what they’re doing, having been recruited for the purpose. Just as often, the account belongs to someone with no idea they’re being used, having been talked into it through a fake job offer, a commission scheme, or the promise of a loan.

The Supreme Court has been grappling with this in In Re: Victims of Digital Arrest Related to Forged Documents, Suo Motu Writ Petition (Criminal) No. 3 of 2025, order dated 4 August 2026, Supreme Court of India. On 4 August 2026, a Bench of Chief Justice Surya Kant, Justice Joymalya Bagchi and Justice V. Mohana directed the RBI to adopt and circulate a Standard Operating Procedure (“SOP”) for mule accounts and cyber-fraud-linked accounts within four weeks, with a copy going to the Registrars General of every High Court.

States, Union Territories and law-enforcement agencies were also told to get existing grievance-redressal and money-restoration mechanisms actually working, and to make sure people know they exist. For fintech, this matters: the same speed and interoperability that make digital payments attractive also make fraud harder to catch and more urgent to stop.

Mule Accounts and Digital Payments

Think of a mule account as a relay point between the victim and whoever ultimately benefits from the fraud. In phishing, impersonation, investment scams and digital-arrest schemes alike, money typically passes through several accounts before withdrawal, and each hop adds distance between the victim and the trail investigators are following.

That’s precisely what makes mule accounts effective: real-time payments, remote onboarding, multiple payment identifiers, and interoperable banking and payment platforms. Even a genuine account can start looking suspicious if its behaviour changes sharply, say, several unrelated credits followed by quick outward transfers. That alone doesn’t prove the holder knew about the fraud, but it explains why monitoring must be paired with a fair review and grievance process.

Under the RBI’s existing KYC framework, regulated entities must already carry out customer due diligence, watch transactions, and act when an account looks connected to mule activity, including reporting suspicious transactions to the Financial Intelligence Unit–India where required.

Supreme Court Proceedings and the RBI SOP

The August 2026 order builds on the Court’s earlier engagement with the RBI’s approach to cyber-enabled fraud. In its order dated 9 February 2026, the Court recorded information that banks were using AI/ML tools for fraud-risk management and that approximately 26 of 53 banks had reportedly adopted MuleHunter AI. The Court was also informed that the RBI and I4C were working towards sharing suspect-registry data. The Court was also apprised of the RBI’s framework, including a draft SOP, concerning temporary debit holds on accounts linked to mule activity and cyber-enabled financial fraud. The significant development in August is that the Court has now directed the RBI to formally adopt and circulate the relevant SOP within four weeks, after refining it in light of the Court’s directions. Separately, in May 2026, I4C and the Reserve Bank Innovation Hub (RBIH) entered into an MoU to facilitate the sharing of mule-account intelligence and suspect identifiers from the I4C Suspect Registry, strengthening AI-based fraud-detection systems such as MuleHunter AI.

Since the final SOP isn’t out yet, its likely contents shouldn’t be treated as settled law. What obligations end up applying to any entity will depend on the final text, its regulatory status, and how it interacts with the rest of the framework.

Temporary Debit Holds and FinTech Implications

A temporary debit hold would generally be intended to restrict withdrawals or transfers involving identified funds while a transaction is examined. This would be different from freezing an entire account and restricting access to money unconnected with the suspected fraud. The SOP will need to spell out when a hold can be imposed, whether it applies to a specific amount or the whole account, who can impose or review it, its duration, how customers are informed and can complain, and how undisputed funds get released. It would be jumping the gun to say the Court has mandated narrow, amount-specific holds in every case; it has directed the RBI to build a standardised procedure, and its exact shape remains to be seen.

For banks and fintech players, a few implications stand out:

  • Continuous transaction monitoring flagging unusual volumes, unrelated credits, fast outward transfers, or links to already-flagged accounts.
  • Tighter KYC and due diligence, especially for remote onboarding. Fintechs working alongside banks would do well to nail down, in writing, who’s responsible for what.
  • AI-assisted detection spotting shared devices, common beneficiaries and suspicious networks, backed by human review and safeguards against false positives.
  • Better inter-institutional coordination: since fraud rarely stays within one bank, a standardised framework should help banks, payment intermediaries, the RBI, I4C and investigators actually talk to each other.
  • Banks will likely feel the SOP’s weight first, but payment aggregators, PPI issuers and other regulated players may be pulled in too, depending on the final scope.
  • Restoration and Customer Protection: Catching and restricting suspicious accounts is only half the job; the other half is stopping money from disappearing further.
AMLEGALS Remarks

Taken together, these directions are a meaningful step forward in how India responds to cyber-enabled financial fraud. Done well, the RBI’s SOP could finally bring some consistency to how mule accounts are identified and handled, how temporary debit holds work, and how recovered money finds its way back to victims.

For fintech businesses, the message is fairly clear: transaction monitoring, KYC, AI-assisted fraud detection and coordination with other institutions all need to get sharper. None of this, though, should come at the cost of ordinary customers caught in restrictions that drag on longer than they should.

In the end, how well this framework works will come down to whether it’s quick, proportionate, transparent and open to review, protecting the integrity of India’s digital payments infrastructure without losing sight of the people who use it every day.

For any queries or feedback, feel free to connect with Hiteashi.desai@amlegals.com or Khilansha.mukhija@amlegals.com

Leave a Reply

Your email address will not be published. Required fields are marked *

 

Disclaimer & Confirmation

As per the rules of the Bar Council of India, law firms are not permitted to solicit work and advertise. By clicking on the “I AGREE” button below, user acknowledges the following:

    • there has been no advertisements, personal communication, solicitation, invitation or inducement of any sort whatsoever from us or any of our members to solicit any work through this website;
    • user wishes to gain more information about AMLEGALS and its attorneys for his/her own information and use;
  • the information about us is provided to the user on his/her specific request and any information obtained or materials downloaded from this website is completely at their own volition and any transmission, receipt or use of this site does not create any lawyer-client relationship; and that
  • We are not responsible for any reliance that a user places on such information and shall not be liable for any loss or damage caused due to any inaccuracy in or exclusion of any information, or its interpretation thereof.

However, the user is advised to confirm the veracity of the same from independent and expert sources.