MuleHunter, DPIP, and IDPIC: India’s New Public Fraud-Intelligence Infrastructure
MuleHunter.AI, DPIP, and IDPIC form RBI’s new shared fraud-intelligence infrastructure. What each does, adoption across 31 banks, and what it means for BFSI compliance.

The Reserve Bank of India (RBI), the Reserve Bank Innovation Hub (RBIH), and major commercial banks have stood up three linked layers of shared fraud-intelligence infrastructure: MuleHunter.AI, the Digital Payments Intelligence Platform (DPIP), and the Indian Digital Payment Intelligence Corporation (IDPIC). MuleHunter.AI provides artificial intelligence scoring to detect mule accounts at the account and institution level, DPIP delivers real-time, cross-bank fraud signaling before transactions clear, and IDPIC operates as a permanent Section 8 public utility to govern and run this network nationally. Together, these systems transition fraud intelligence in India from isolated institutional silos into national Digital Public Infrastructure.
For compliance officers, risk leaders, and digital product managers across Indian banking and fintech, this rollout fundamentally changes the operating environment. Understanding how each component functions, where they intersect, and what responsibilities remain with individual institutions is now essential.
The Structural Defect of Siloed Bank Defenses
Why isolated fraud registries and rule-based AML engines failed to stop mule networks.
Money mule accounts serve as the primary transmission mechanism for cyber financial fraud in India, allowing criminal networks to receive, layer, and siphon illicit funds from digital payment scams. Historically, banking fraud defenses operated in complete isolation. An account or individual flagged for suspicious behavior at one bank could open accounts or move money across peer institutions without triggering alerts, because fraud intelligence remained trapped inside separate corporate walls.
Compounding this isolation, traditional rule-based transaction monitoring systems produce false-positive rates of up to 40%. High false-positive volumes create severe alert fatigue for compliance teams and bury genuine fraud signals under routine operational noise.
Speed further tilted the field in favor of fraud syndicates. Operational enforcement records reveal that mule accounts in digital scams frequently remain active for only 1 to 2 days before abandonment or closure. Because post-incident police reporting and inter-bank freezing mechanisms operate on a lag, funds are routinely laundered and withdrawn before a reactive freeze order reaches the destination bank. Closing this window required moving from isolated, post-transaction reporting to proactive, shared intelligence across the entire financial system.
“Mule accounts in digital fraud schemes frequently exhibit an active window of only 1 to 2 days before closure, making post-incident freezing insufficient on its own.”
MuleHunter.AI: Account-Level Machine Learning Detection
19 behavioral patterns, 95% accuracy, and the Ministry of Home Affairs mandate.
To address the limitations of static rules, the Reserve Bank Innovation Hub developed MuleHunter.AI in-house, unveiling the platform in December 2024. MuleHunter.AI operates as an artificial intelligence and machine learning scoring engine that evaluates bank account data to identify mule activity.
Unlike traditional AML rules that look at isolated thresholds, MuleHunter.AI analyzes transaction and account behavior across 19 distinct behavioral patterns. These patterns evaluate complex signals including rapid velocity spikes, sudden transitions from prolonged dormancy to high-value throughput, and immediate pass-through transfers where funds exit within minutes of arrival.
Across its deployed banking footprint, MuleHunter.AI detects approximately 20,000 mule accounts per month. The platform was initially tested in a pilot deployment with two large public sector lenders. Among them, Canara Bank reported achieving a 95% detection accuracy rate when identifying mule accounts through the platform.
Adoption Trajectory and the MHA Mandate
The expansion of MuleHunter.AI has progressed through several documented phases:
- Late 2025: Nearly 20 commercial banks onboarded during early scaling.
- December 2025: An RTI disclosure published by MediaNama confirmed deployment across 23 banks.
- March 2026: Official RBI communications confirmed the tool was active across 26 banks.
- August–September 2026: Deployment reached 29 to 31 commercial banks, with an additional 15 banks scheduled to onboard by October 2026.
Adoption is shifting into a mandatory operational requirement. The Ministry of Home Affairs directed all financial institutions in India to integrate with MuleHunter by December 2026. To further sharpen the tool’s machine learning models, the Indian Cyber Crime Coordination Centre (I4C) signed an MOU with RBIH in May 2026 to feed suspect identifiers from the national Suspect Registry directly into RBIH detection algorithms. Read our companion analysis on I4C’s AI-powered mule detection push.
DPIP: The Real-Time Network Intelligence Layer
Pre-transaction querying across UPI, IMPS, cards, and digital wallets.
While MuleHunter.AI scores accounts within an institution, the Digital Payments Intelligence Platform (DPIP) addresses cross-institutional payment flows in real time.
In June 2024, the Reserve Bank of India announced the proposal to establish DPIP within its Statement on Developmental and Regulatory Policies. To design the operational architecture and governance model, the RBI constituted a committee chaired by Shri A.P. Hota, former MD and CEO of NPCI.
DPIP is engineered to provide real-time, cross-institution risk signals across digital payment rails, including UPI, IMPS, card networks, and prepaid digital wallets. Prototyped and built by the RBIH, DPIP was tested in a pilot deployment with seven banks.
The architectural shift in DPIP is its timing. DPIP enables issuing and acquiring institutions to query a shared, network-wide risk score prior to transaction authorization. If a beneficiary account or device identifier exhibits high-velocity fraud signals across three different banks within the same hour, DPIP alerts the initiating bank before funds leave the remitter’s account.
IDPIC: Governing Shared Infrastructure as a Public Utility
Section 8 not-for-profit company promoted by SBI and Bank of Baroda.
A shared intelligence network connecting competing commercial banks requires a neutral, trusted institutional home. To fulfill this function, the Indian Digital Payment Intelligence Corporation (IDPIC) was incorporated on October 16, 2025.
IDPIC was established as a Section 8 not-for-profit company under the Companies Act, 2013, with its registered headquarters in Mumbai. The company was promoted by a consortium of major Indian financial institutions led by State Bank of India (SBI) and Bank of Baroda (BoB), under the direct guidance and sponsorship of the RBI.
IDPIC acts as the permanent operational entity for DPIP. Its institutional mandate covers three primary areas:
1. Operating Platform Infrastructure
Transitioning DPIP from an RBIH technical prototype into an operational national utility.
2. Ecosystem Onboarding
Managing participant integration across public sector banks, private lenders, small finance banks, regional rural banks, and payment aggregators.
3. Privacy and Data Governance
Employing tokenization and cryptographic hashing of identifiers, ensuring member institutions query fraud registries and share risk scores without exposing customer personal identifiable information (PII).
Through IDPIC, India is institutionalizing beneficiary risk scoring as standard Digital Public Infrastructure, mirroring the foundational utility model previously established for identity (Aadhaar) and payments (UPI).
Comparing MuleHunter.AI, DPIP, and IDPIC
Side-by-side architecture, originating bodies, intervention points, and data scopes.
The three initiatives operate as complementary layers of a single public fraud-defense ecosystem:
| Attribute | MuleHunter.AI | DPIP | IDPIC |
|---|---|---|---|
| Primary Nature | Machine learning detection software | Technical intelligence sharing network | Operational Section 8 company |
| Originating Entity | Reserve Bank Innovation Hub (RBIH) | Conceived by RBI; prototyped by RBIH | Promoted by bank consortium (SBI, BoB) under RBI |
| Key Function | Scores accounts on 19 mule behavioral patterns | Transmits real-time risk scores across payment rails | Governs platform operations and participant access |
| Intervention Point | Account level and ongoing batch monitoring | Pre-transaction and real-time payment authorization | Institutional governance and policy enforcement |
| Adoption Status | 29–31 banks deployed; flags ~20,000 accounts/mo | Piloted with 7 banks | Incorporated Oct 2025; operational utility rollout |
| Data Scope | Internal bank transactions & account parameters | Cross-bank payment velocity & entity risk signals | Hashed & tokenized privacy-preserving data registry |
What This Means for Regulated Entities: Analysis and Industry Take
Institutional liability, zero-day onboarding defenses, and complementary internal analytics.
The establishment of MuleHunter.AI, DPIP, and IDPIC marks a decisive inflection point for Indian BFSI risk architecture. Shared fraud intelligence is rapidly transitioning from a proprietary advantage into basic table stakes. When every bank queries the same beneficiary risk signals through IDPIC, institutions cannot differentiate themselves merely by subscribing to the utility.
Read together, these three initiatives reveal three critical operational realities for compliance and fraud teams:
1. Public utilities do not displace institutional liability
The presence of a national scoring utility does not absolve a bank or NBFC of statutory compliance. Regulated entities retain strict legal liability under the Prevention of Money Laundering Act (PMLA) 2002 and the RBI Master Direction on KYC. If a mule account is onboarded through compromised due diligence, the institution remains accountable to regulatory inspection.
2. Shared utilities catch known velocity, not zero-day onboarding fraud
DPIP and IDPIC excel at detecting cross-institutional velocity, known compromised device fingerprints, and inter-bank layering patterns. However, they rely on transaction activity to generate risk scores. They do not prevent zero-day synthetic identity creation, document forgery, or deepfake impersonation at the point of customer onboarding.
3. Complementary internal intelligence remains essential
To maximize the value of public infrastructure, institutions must strengthen internal analytical capabilities: device telemetry, behavioral biometrics, and entity-resolution intelligence to block fraud before an account enters the payment stream.
Frequently Asked Questions
Bhanujeet Choudhary
Head of Compliance, KYCKART
Published September 21, 2026
Disclaimer: This article is for informational purposes only and does not constitute legal, financial, or regulatory compliance advice. Financial institutions should refer to primary RBI circulars and legal counsel for operational compliance.
Next Steps for BFSI
Fortify Your Front-Door Onboarding & Mule Detection
Equip your compliance and risk teams with real-time synthetic identity detection, biometric liveness validation, and device fingerprinting to prevent mule accounts before they transact.
Explore Fraud Intelligencearrow_forward