KYCKART
KYCKART Fraud Intelligence · September 2026RBI & Digital Public Infrastructure

MuleHunter, DPIP, and IDPIC: India’s New Public Fraud-Intelligence Infrastructure

MuleHunter.AI, DPIP, and IDPIC form RBI’s new shared fraud-intelligence infrastructure. What each does, adoption across 31 banks, and what it means for BFSI compliance.

calendar_monthSeptember 21, 2026
schedule7 min read
library_books11 Cited Sources
personBhanujeet Choudhary, Head of Compliance
MuleHunter, DPIP, and IDPIC Explainer

The Reserve Bank of India (RBI), the Reserve Bank Innovation Hub (RBIH), and major commercial banks have stood up three linked layers of shared fraud-intelligence infrastructure: MuleHunter.AI, the Digital Payments Intelligence Platform (DPIP), and the Indian Digital Payment Intelligence Corporation (IDPIC). MuleHunter.AI provides artificial intelligence scoring to detect mule accounts at the account and institution level, DPIP delivers real-time, cross-bank fraud signaling before transactions clear, and IDPIC operates as a permanent Section 8 public utility to govern and run this network nationally. Together, these systems transition fraud intelligence in India from isolated institutional silos into national Digital Public Infrastructure.

For compliance officers, risk leaders, and digital product managers across Indian banking and fintech, this rollout fundamentally changes the operating environment. Understanding how each component functions, where they intersect, and what responsibilities remain with individual institutions is now essential.

01

The Structural Defect of Siloed Bank Defenses

Why isolated fraud registries and rule-based AML engines failed to stop mule networks.

Money mule accounts serve as the primary transmission mechanism for cyber financial fraud in India, allowing criminal networks to receive, layer, and siphon illicit funds from digital payment scams. Historically, banking fraud defenses operated in complete isolation. An account or individual flagged for suspicious behavior at one bank could open accounts or move money across peer institutions without triggering alerts, because fraud intelligence remained trapped inside separate corporate walls.

Compounding this isolation, traditional rule-based transaction monitoring systems produce false-positive rates of up to 40%. High false-positive volumes create severe alert fatigue for compliance teams and bury genuine fraud signals under routine operational noise.

Speed further tilted the field in favor of fraud syndicates. Operational enforcement records reveal that mule accounts in digital scams frequently remain active for only 1 to 2 days before abandonment or closure. Because post-incident police reporting and inter-bank freezing mechanisms operate on a lag, funds are routinely laundered and withdrawn before a reactive freeze order reaches the destination bank. Closing this window required moving from isolated, post-transaction reporting to proactive, shared intelligence across the entire financial system.

“Mule accounts in digital fraud schemes frequently exhibit an active window of only 1 to 2 days before closure, making post-incident freezing insufficient on its own.”
02

MuleHunter.AI: Account-Level Machine Learning Detection

19 behavioral patterns, 95% accuracy, and the Ministry of Home Affairs mandate.

To address the limitations of static rules, the Reserve Bank Innovation Hub developed MuleHunter.AI in-house, unveiling the platform in December 2024. MuleHunter.AI operates as an artificial intelligence and machine learning scoring engine that evaluates bank account data to identify mule activity.

Unlike traditional AML rules that look at isolated thresholds, MuleHunter.AI analyzes transaction and account behavior across 19 distinct behavioral patterns. These patterns evaluate complex signals including rapid velocity spikes, sudden transitions from prolonged dormancy to high-value throughput, and immediate pass-through transfers where funds exit within minutes of arrival.

Across its deployed banking footprint, MuleHunter.AI detects approximately 20,000 mule accounts per month. The platform was initially tested in a pilot deployment with two large public sector lenders. Among them, Canara Bank reported achieving a 95% detection accuracy rate when identifying mule accounts through the platform.

Adoption Trajectory and the MHA Mandate

The expansion of MuleHunter.AI has progressed through several documented phases:

Adoption is shifting into a mandatory operational requirement. The Ministry of Home Affairs directed all financial institutions in India to integrate with MuleHunter by December 2026. To further sharpen the tool’s machine learning models, the Indian Cyber Crime Coordination Centre (I4C) signed an MOU with RBIH in May 2026 to feed suspect identifiers from the national Suspect Registry directly into RBIH detection algorithms. Read our companion analysis on I4C’s AI-powered mule detection push.

03

DPIP: The Real-Time Network Intelligence Layer

Pre-transaction querying across UPI, IMPS, cards, and digital wallets.

While MuleHunter.AI scores accounts within an institution, the Digital Payments Intelligence Platform (DPIP) addresses cross-institutional payment flows in real time.

In June 2024, the Reserve Bank of India announced the proposal to establish DPIP within its Statement on Developmental and Regulatory Policies. To design the operational architecture and governance model, the RBI constituted a committee chaired by Shri A.P. Hota, former MD and CEO of NPCI.

DPIP is engineered to provide real-time, cross-institution risk signals across digital payment rails, including UPI, IMPS, card networks, and prepaid digital wallets. Prototyped and built by the RBIH, DPIP was tested in a pilot deployment with seven banks.

The architectural shift in DPIP is its timing. DPIP enables issuing and acquiring institutions to query a shared, network-wide risk score prior to transaction authorization. If a beneficiary account or device identifier exhibits high-velocity fraud signals across three different banks within the same hour, DPIP alerts the initiating bank before funds leave the remitter’s account.

04

IDPIC: Governing Shared Infrastructure as a Public Utility

Section 8 not-for-profit company promoted by SBI and Bank of Baroda.

A shared intelligence network connecting competing commercial banks requires a neutral, trusted institutional home. To fulfill this function, the Indian Digital Payment Intelligence Corporation (IDPIC) was incorporated on October 16, 2025.

IDPIC was established as a Section 8 not-for-profit company under the Companies Act, 2013, with its registered headquarters in Mumbai. The company was promoted by a consortium of major Indian financial institutions led by State Bank of India (SBI) and Bank of Baroda (BoB), under the direct guidance and sponsorship of the RBI.

IDPIC acts as the permanent operational entity for DPIP. Its institutional mandate covers three primary areas:

1. Operating Platform Infrastructure

Transitioning DPIP from an RBIH technical prototype into an operational national utility.

2. Ecosystem Onboarding

Managing participant integration across public sector banks, private lenders, small finance banks, regional rural banks, and payment aggregators.

3. Privacy and Data Governance

Employing tokenization and cryptographic hashing of identifiers, ensuring member institutions query fraud registries and share risk scores without exposing customer personal identifiable information (PII).

Through IDPIC, India is institutionalizing beneficiary risk scoring as standard Digital Public Infrastructure, mirroring the foundational utility model previously established for identity (Aadhaar) and payments (UPI).

05

Comparing MuleHunter.AI, DPIP, and IDPIC

Side-by-side architecture, originating bodies, intervention points, and data scopes.

The three initiatives operate as complementary layers of a single public fraud-defense ecosystem:

AttributeMuleHunter.AIDPIPIDPIC
Primary NatureMachine learning detection softwareTechnical intelligence sharing networkOperational Section 8 company
Originating EntityReserve Bank Innovation Hub (RBIH)Conceived by RBI; prototyped by RBIHPromoted by bank consortium (SBI, BoB) under RBI
Key FunctionScores accounts on 19 mule behavioral patternsTransmits real-time risk scores across payment railsGoverns platform operations and participant access
Intervention PointAccount level and ongoing batch monitoringPre-transaction and real-time payment authorizationInstitutional governance and policy enforcement
Adoption Status29–31 banks deployed; flags ~20,000 accounts/moPiloted with 7 banksIncorporated Oct 2025; operational utility rollout
Data ScopeInternal bank transactions & account parametersCross-bank payment velocity & entity risk signalsHashed & tokenized privacy-preserving data registry
06

What This Means for Regulated Entities: Analysis and Industry Take

Institutional liability, zero-day onboarding defenses, and complementary internal analytics.

The establishment of MuleHunter.AI, DPIP, and IDPIC marks a decisive inflection point for Indian BFSI risk architecture. Shared fraud intelligence is rapidly transitioning from a proprietary advantage into basic table stakes. When every bank queries the same beneficiary risk signals through IDPIC, institutions cannot differentiate themselves merely by subscribing to the utility.

Read together, these three initiatives reveal three critical operational realities for compliance and fraud teams:

1. Public utilities do not displace institutional liability

The presence of a national scoring utility does not absolve a bank or NBFC of statutory compliance. Regulated entities retain strict legal liability under the Prevention of Money Laundering Act (PMLA) 2002 and the RBI Master Direction on KYC. If a mule account is onboarded through compromised due diligence, the institution remains accountable to regulatory inspection.

2. Shared utilities catch known velocity, not zero-day onboarding fraud

DPIP and IDPIC excel at detecting cross-institutional velocity, known compromised device fingerprints, and inter-bank layering patterns. However, they rely on transaction activity to generate risk scores. They do not prevent zero-day synthetic identity creation, document forgery, or deepfake impersonation at the point of customer onboarding.

3. Complementary internal intelligence remains essential

To maximize the value of public infrastructure, institutions must strengthen internal analytical capabilities: device telemetry, behavioral biometrics, and entity-resolution intelligence to block fraud before an account enters the payment stream.

Frequently Asked Questions

person

Bhanujeet Choudhary

Head of Compliance, KYCKART

Published September 21, 2026

Disclaimer: This article is for informational purposes only and does not constitute legal, financial, or regulatory compliance advice. Financial institutions should refer to primary RBI circulars and legal counsel for operational compliance.

Next Steps for BFSI

Fortify Your Front-Door Onboarding & Mule Detection

Equip your compliance and risk teams with real-time synthetic identity detection, biometric liveness validation, and device fingerprinting to prevent mule accounts before they transact.

Explore Fraud Intelligencearrow_forward