KYCKART
KYCKART Guide · August 2026Guide

Mule Accounts in 2026: Inside I4C’s AI-Powered Detection Push

In 2026, I4C signed an AI-training MOU with RBIH and the Supreme Court ordered RBI to issue a mule-account debit-hold SOP. Here’s what changed.

calendar_monthAugust 2026
schedule13 min read
library_books12 Cited Sources
personBhanujeet Choudhary, Head of Compliance

In 2026, India’s mule-account fight added two new pieces on top of the detection tools already in place. In May, the Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs, signed a Memorandum of Understanding with the Reserve Bank Innovation Hub (RBIH) to feed data from I4C’s Suspect Registry directly into RBIH’s AI/ML fraud-detection models. In August, the Supreme Court ordered RBI to issue a Standard Operating Procedure, within four weeks, telling banks exactly what to do when they find an account linked to mule activity.

For what a mule account is, how the four common typologies work, and the six-signal framework banks use to catch them, see KYCKART’s explainer on mule-account fraud detection. This piece covers only what changed in 2026: a new AI-training partnership, updated national scale figures, two enforcement operations, and the regulatory development most likely to reshape what banks are actually required to do next.

01

2026 at a Glance

DateDevelopment
6 March 2026RBI opens public consultation on a revised customer-liability and compensation framework for unauthorised digital transactions
May 2026I4C signs MOU with RBIH to feed Suspect Registry data into AI fraud-detection models, including MuleHunter.AI
Month to 6 July 2026Gujarat Police's Operation Mule Hunt 2.0 concludes, unwinding a mule-account network tied to ₹802 crore in reported fraud
14 July 2026A Siddharthnagar (UP) student's six bank accounts, linked to 17 cyber-fraud complaints, are reported as an individual-recruitment case
26-28 July 2026BioCatch's “Digital Banking Fraud Trends in India 2026” report documents a Southeast Asia-to-India shift in mule-account infrastructure
4 August 2026 (per most outlets)Supreme Court orders RBI to issue a bank debit-hold SOP within four weeks
12 August 2026A Lok Sabha reply confirms Suspect Registry figures through 30 June 2026: 32.08 lakh mule accounts flagged, ₹25,698 crore in transactions declined
02

The I4C-RBIH MOU: What It Actually Changes

The MOU, signed in May 2026 by Smt Roopa M (Inspector General, Admin, I4C) and Shri Sahil Kinni (CEO, RBIH), with RBI Deputy Governor Shri Rohit Jain and senior MHA officials present, is an intelligence-sharing and analytical-support arrangement rather than a new detection system. Under its terms, I4C will share mule-account-related intelligence and suspect identifiers from its Suspect Registry with RBIH, and RBIH will use that data to train and improve its AI/ML fraud-risk models, including MuleHunter.AI, so those models can identify suspicious banking activity and hidden mule-account networks faster. Union Home Minister Amit Shah described the collaboration as designed to “swiftly detect and cull hidden mule accounts by feeding the data from the I4C’s Suspect Registry to the AI-driven fraud detection system.”

None of the coverage of the MOU itself names a specific rupee or account-count figure as the agreement’s own achievement. Some numbers that circulate in the same news cycle, ₹9,518 crore and 27.37 lakh flagged accounts, are sometimes read as something the MOU has already prevented. They aren’t: those are the I4C Suspect Registry’s own cumulative totals as of 31 January 2026, reported in a Lok Sabha written reply from the Ministry of Home Affairs, whose responding minister is not named in public coverage of that reply, months before the MOU was signed, not a MOU-specific result.

03

The Scale, Updated

The Suspect Registry’s most recent public figures come from a Lok Sabha reply given by Union Minister of State for Home Bandi Sanjay Kumar on 12 August 2026, covering activity through 30 June 2026. As of that date, the Registry had received suspect-identifier data on 30.48 lakh individuals from banks and had shared 32.08 lakh Layer-1 mule accounts with participating entities, helping decline transactions worth ₹25,698 crore. The same reply reported that the government had blocked 3,718 fraudulent mobile apps (including fraudulent loan apps), blocked 15.75 lakh SIM cards and 5.77 lakh IMEIs, and that the Citizen Financial Cyber Fraud Reporting and Management System had processed 32.80 lakh complaints and saved more than ₹11,158 crore. A Money Restoration Module and a Grievance Redressal Module became operational in April 2026.

As of 30 June 2026, India’s Suspect Registry had shared 32.08 lakh mule accounts with banks and other participating entities, helping decline ₹25,698 crore in transactions.

BioCatch’s “Digital Banking Fraud Trends in India 2026” report, covered in Indian media in late July 2026, found that fraudsters are increasingly routing stolen funds through India-based mule accounts instead of accounts based overseas. The report attributes this to enforcement crackdowns led by the United Nations Office on Drugs and Crime against scam centres in Myanmar, Cambodia, and Laos, which displaced rather than dismantled those networks and pushed them toward more distributed infrastructure built on domestic Indian cash-out systems, SIM cards, and payment networks. BioCatch describes this as “mule-as-a-service” infrastructure that consolidates stolen funds, converts them to cryptocurrency, and routes them to wallets associated with scam centres.

The same report’s India-specific session data adds texture to that shift: attempted fraud sessions fell 12% while the value of attempted fraudulent payments rose 35%; text-message-based scams surged 146%; mobile-banking fraud sessions rose 67% (iOS up 86%, Android up 35%) while web-based fraud sessions fell 10%; average fraud-call duration fell 31%; and the median fraudulent transfer value rose 1.7 times per session.

04

2026 Enforcement in Action

Gujarat Police’s Cyber Centre of Excellence (CID Crime) closed out “Operation Mule Hunt 2.0” in early July 2026 having arrested 55 people over the preceding month, a statewide initiative aimed at the financial infrastructure behind cybercrime rather than individual fraudsters alone. The arrested individuals’ bank accounts were linked to 1,117 cybercrime complaints registered nationwide, involving an estimated ₹802 crore in fraud, spanning 22 states and Union Territories, with Maharashtra recording the highest number of linked complaints (56), followed by Karnataka (28) and Gujarat (23).

One case from that operation shows how concentrated the damage from a small number of accounts can be. Police allege that Vishal Sureshbhai Dodiya, an Ahmedabad resident, registered a bogus firm named “Chamunda Communication” and opened three bank accounts in its name; those three accounts alone were linked to more than 253 cybercrime cases nationally, involving an estimated ₹161 crore in fraudulent transactions. Three other individuals were arrested in the same operation: Mohammad Khaliq Ghulam Husain of Surat, accused of operating accounts that received stolen funds from a bank-hacking case; Shoaib Gulabnabi Rana, also of Surat, accused of facilitating transfers of the illegally accessed funds; and Afzal Pir Mohammad Mansuri of Ahmedabad, accused of managing mule accounts and withdrawal operations, whose accounts police say were linked to 60 accounts across 132 complaints. A related case in the same operation, the hacking of Bhavnagar District Cooperative Bank, involved ₹7.34 crore siphoned off.

A separate, smaller case published in July 2026 illustrates the same problem at individual scale. In Siddharthnagar district, Uttar Pradesh, police arrested a 20-year-old undergraduate, Nasim Ahmad, after six bank accounts opened in his name across Union Bank, an Urban Cooperative Bank, Punjab National Bank, Axis Bank, State Bank of India, and India Post Payments Bank were found linked to 17 cyber-fraud complaints across multiple states, with a cumulative reported fraud value of ₹22.55 crore across all connected complaints (police clarified that only about ₹14 lakh was directly traced as having passed through Ahmad’s own accounts). Investigators said Ahmad allegedly first received money through online gaming platforms before routing it onward. Cybercrime expert Prof. Triveni Singh, quoted in the coverage, warned that sharing banking credentials in exchange for money “can itself attract criminal liability regardless of whether the account holder personally profited.”

05

The Regulatory Turning Point: The Supreme Court's SOP Order

On 4 August 2026, as reported by most outlets covering the order, a Supreme Court bench led by Chief Justice of India Surya Kant, with Justices Joymalya Bagchi and V. Mohana, acting in a suo motu proceeding (Suo Motu Writ Petition (Criminal) No. 3 of 2025, originally triggered by a senior-citizen couple’s complaint about a “digital arrest” scam), directed RBI to formally adopt and circulate, within four weeks, an SOP prescribing what banks must do to place temporary debit holds on amounts or accounts linked to mule activity and cyber-enabled fraud, with copies furnished to the Registrar General of every High Court.

The same order directed several other steps: states, Union Territories, and law-enforcement agencies must operationalise existing cyber-fraud grievance-redressal and Money Restoration Module mechanisms and raise public awareness of them; State Cyber Crime Coordination Centres must adopt the “e-Zero FIR” mechanism with I4C within the same four-week window; an Inter-Departmental Committee will examine a shared-liability and victim-compensation framework; and courts are to expedite account-freezing matters arising from cyber-fraud cases. The Court noted that “digital arrest” complaints on the National Cybercrime Reporting Portal fell from 1,23,672 in 2024 to 58,249 in 2025 and further to 16,377 through 30 June 2026, and recorded that the grievance-redressal mechanism already covers 1,23,590 branches of 69 banks, while the Money Restoration Mechanism Portal has 57 participating banks across every state and Union Territory. The matter returns for a further hearing on 16 September 2026.

The SOP itself had not been published as of this piece’s most recent research (30 August 2026), so what it will actually require is still open. One analysis of the order, by the law firm AMLEGALS, suggests the eventual SOP will likely need to define the scope of a “temporary debit hold” (a specific amount within an account versus the whole account), may extend obligations beyond banks to payment aggregators and prepaid-instrument issuers, and is likely to formalise expectations already informally in place: continuous transaction monitoring, enhanced KYC and due diligence for remote onboarding, AI-assisted detection paired with human review, and cross-institutional coordination through a standardised framework. That is one firm’s forward-looking read of a document that doesn’t exist yet, not confirmed SOP content.

This order addresses the freeze-authority gap: banks’ inability to freeze suspect accounts without court or law-enforcement authorisation. RBI’s four-week deadline from the widely reported 4 August 2026 order date puts the SOP due on or around 1 September 2026.

Also in motion: RBI’s liability overhaul and MuleHunter.AI’s growing footprint

On 6 March 2026, RBI issued for public consultation a draft “Review of Framework of Limiting Customer Liability in Digital/Unauthorised Electronic Banking Transactions,”expanding the scope of its existing 2017 liability instructions to more categories of fraudulent electronic transactions, aiming to reduce complaint-processing time, and introducing, for the first time, a compensation mechanism for small-value fraudulent transactions: 85% of the loss amount or ₹25,000, whichever is lower, as a once-in-a-lifetime benefit per customer. The revised instructions are set to take effect from 1 January 2027.

The same RBI communication reiterated that MuleHunter.AI, the RBIH-developed detection tool, was live in 26 banks as of that announcement and being scaled further, up from the 23-bank figure reported in a December 2025 RTI response, and that RBI has advised banks to deploy real-time transaction-monitoring software and use AI/ML and network analytics against suspicious transaction patterns.

Read together, the 2026 developments above point to a shift in what’s still open versus what’s now underway. Detection capacity kept expanding on multiple fronts this year: MuleHunter.AI’s bank footprint grew from 23 to 26, the I4C-RBIH MOU adds a formal channel for training those models on fresher Suspect Registry data, and the Registry itself scaled from 27.37 lakh to 32.08 lakh flagged mule accounts between January and June. What it took a court order to move was the process question the sibling piece to this one had already flagged as unresolved: what a bank is actually authorised to do the moment its own systems, or a shared registry, tell it an account looks like a mule account. The Supreme Court’s SOP order is the first dated 2026 instruction aimed squarely at that gap.

The practical implication for a compliance or fraud team is that the SOP due around 1 September 2026, once published, is worth reading closely rather than treating as a formality, since AMLEGALS’s analysis cited above suggests it may extend beyond banks to payment aggregators and prepaid-instrument issuers, and may formalise expectations, such as pairing AI-assisted detection with human review, that many institutions already operate informally. Separately, the BioCatch finding that mule infrastructure is shifting toward domestic Indian cash-out systems suggests the accounts an institution’s own monitoring needs to catch are increasingly opened inside India rather than routed abroad, which is also the population the I4C-RBIH data-sharing arrangement is now built to help models learn from. And the Gujarat operation’s Chamunda Communication case, three accounts absorbing 253 cybercrime complaints, is a reminder that the account-opening stage still carries weight even as freeze-and-hold procedures get formalised after the fact; a faster SOP for what happens once a mule account is found doesn’t reduce the value of catching it before it opens.

verified

How KYCKART Helps

KYCKART’s fraud intelligence platform catches the same account-opening-stage signals this piece describes, before a mule account is ever used to move stolen funds.

Frequently Asked Questions

person

Bhanujeet Choudhary

Head of Compliance, KYCKART

Published August 30, 2026

Disclaimer: This piece summarises public regulatory, judicial, and news reporting on 2026 mule-account developments in India for informational purposes. The Supreme Court-ordered SOP referenced above had not been published as of this piece’s most recent research (30 August 2026); the law firm analysis of its likely scope is commentary on an unpublished document, not confirmed SOP content. This is not legal or compliance advice; institutions should confirm current regulatory requirements directly with RBI and other applicable regulators.

KYCKART Intelligence

Catch Mule Accounts Before They Open, Not Just After

KYCKART’s fraud intelligence platform screens for mule-account signals at onboarding, so your team isn’t waiting on a court-ordered SOP to know what to do next.

Explore Fraud Intelligencearrow_forward