Cyber-Enabled Fraud Is Now a Core AML Risk: What FATF’s 2026 Paper Means for Financial Institutions

Cyber-enabled fraud is no longer only a consumer protection problem, a cybersecurity issue or a payment fraud concern. It has become a core money laundering risk.
In its 2026 paper on cyber-enabled fraud, the Financial Action Task Force, or FATF, found that 156 jurisdictions—approximately 90% of those assessed—had explicitly identified fraud as a major money laundering risk.
This finding has important implications for financial institutions.
Fraud should not be viewed only as the moment when a victim loses money. It is also a predicate offence that generates criminal proceeds. Those proceeds must then be received, transferred, concealed, converted or integrated into the financial system.
For banks, payment institutions, fintech companies and virtual asset service providers, the distinction between fraud prevention and anti-money laundering is therefore becoming increasingly difficult to maintain.
The key question is no longer whether fraud and money laundering are connected. They clearly are.
The more important question is:
Should fraud monitoring and AML transaction monitoring continue to operate as separate control functions?
Fraud and Money Laundering Are Part of the Same Transaction Chain
Traditional financial crime controls often treat fraud and money laundering as two separate stages.
Fraud teams focus on preventing the initial loss. They may investigate unusual logins, account takeovers, unauthorised card payments, social engineering or transfers initiated under deception.
AML teams focus on what happens to the criminal proceeds after the fraud has occurred. They monitor suspicious transactions, investigate unusual customer activity, identify hidden relationships and submit suspicious transaction reports.
Cyber-enabled fraud increasingly collapses this distinction.
In many modern fraud schemes, the money laundering infrastructure is established before the fraud takes place. Criminal networks prepare receiving accounts, money mule networks, payment channels, shell companies and virtual asset wallets in advance.
Once the victim transfers the money, the laundering process begins almost immediately.
A payment may be:
- Received into a money mule account;
- Divided among several accounts;
- Transferred to another financial institution;
- Converted into virtual assets;
- Sent across borders;
- Withdrawn in cash; or
- Layered through companies and payment platforms.
From a financial institution’s perspective, the same transaction chain may simultaneously involve:
- A fraud victim making a payment;
- A money mule receiving criminal proceeds;
- A compromised account being misused;
- An organised laundering network;
- A cross-border transfer of illicit funds; and
- A time-sensitive opportunity to freeze or recover assets.
When fraud and AML functions operate separately, each team may see only one part of the activity.
The fraud team may focus on whether the payment was authorised or induced by deception. The AML team may focus on whether the receiving account displays suspicious behaviour.
Neither team may immediately see the complete network.
Money Mules Have Become Essential Financial Crime Infrastructure
Money mule accounts are central to cyber-enabled fraud.
These accounts allow criminals to receive, move and disguise fraud proceeds without using accounts directly connected to the main organisers of the scheme.
Some money mules knowingly participate in criminal activity. They may open or provide bank accounts in exchange for payment.
Others are recruited through:
- Fake employment offers;
- Online investment schemes;
- Romance scams;
- Social media advertisements;
- Requests to receive money on behalf of another person;
- Opportunities to earn commissions by transferring funds; or
- Fraudulent business arrangements.
Some account holders may initially believe they are performing legitimate work. Others may continue transferring funds even after signs of criminal activity become apparent.
This creates a difficult classification problem for financial institutions.
A customer may be:
- A genuine fraud victim;
- An unwitting money mule;
- A negligent facilitator;
- A nominee acting for another person;
- The holder of a compromised account; or
- An intentional participant in organised crime.
The role of the customer may also change over time.
An individual may initially be deceived into receiving funds but later become aware of the nature of the activity. A customer may also be both a victim and a facilitator within the same scheme.
This is why money mule risk cannot always be assessed by looking at one transaction in isolation.
Financial institutions need to examine the wider pattern of behaviour.
Relevant indicators may include:
- Multiple incoming payments from unrelated individuals;
- Incoming funds followed by immediate onward transfers;
- Accounts that repeatedly return to a near-zero balance;
- Funds divided among several newly added beneficiaries;
- Transaction activity inconsistent with the customer’s profile;
- Newly opened accounts receiving unexpectedly large payments;
- Multiple accounts sharing devices, contact details or addresses;
- Transfers involving high-risk payment platforms;
- Rapid movement between fiat currency and virtual assets; and
- Similar transaction patterns across apparently unrelated customers.
These are both fraud indicators and money laundering indicators.
Where an account receives fraud proceeds and rapidly moves them through the financial system, the distinction between fraud detection and AML monitoring becomes largely operational rather than substantive.
The Speed of Payments Has Become an AML Vulnerability
Digital payments have made financial services faster, cheaper and more convenient.
The same infrastructure also allows criminals to move fraud proceeds before victims, financial institutions or law enforcement agencies can respond.
Instant payment systems can transfer funds within seconds. Mobile banking allows transactions to be initiated from almost anywhere. Fintech platforms can move money across multiple payment channels. Virtual assets may allow funds to be transferred across borders without relying on traditional correspondent banking relationships.
A fraud victim may realise what has happened only after the funds have already passed through several accounts.
This creates a fundamental imbalance:
Criminals can move money in real time, while investigations and recovery processes often operate much more slowly.
Traditional AML transaction monitoring frequently relies on post-transaction detection.
An alert may be generated after the transaction has been completed. It may then enter a review queue, be assigned to an investigator and pass through several levels of escalation.
This model remains useful for identifying complex or long-term money laundering activity. However, it may be insufficient for cyber-enabled fraud, where criminal proceeds can leave the institution or jurisdiction within minutes.
For this reason, financial institutions increasingly need controls that operate before, during and immediately after the payment.
These may include:
- Real-time payment risk scoring;
- Behavioural monitoring;
- Confirmation or warning mechanisms for high-risk transfers;
- Temporary payment delays where legally permitted;
- Rapid escalation procedures;
- Immediate communication with receiving institutions;
- Faster account restriction processes; and
- Structured asset tracing and recovery procedures.
An alert may be technically accurate but operationally ineffective if it is reviewed too late.
In cyber-enabled fraud, detection speed can be as important as detection accuracy.
Cross-Border Transfers Make the Risk More Difficult to Detect
Cyber-enabled fraud is inherently international.
The victim, money mule, scam operator, payment intermediary, shell company and virtual asset service provider may all be located in different jurisdictions.
A scam may be organised in one country, target victims in another, receive funds through accounts in several financial centres and ultimately convert the proceeds into virtual assets through a platform located elsewhere.
This creates major visibility problems.
One financial institution may see a victim making a payment.
A second institution may see an account receiving funds from multiple unrelated individuals.
A third institution may see the funds being consolidated.
A virtual asset service provider may see the proceeds converted and transferred to an external wallet.
Each institution sees only a fragment of the activity.
Without information sharing, no single institution may have enough evidence to identify the complete scheme.
Cyber-enabled fraud therefore demonstrates the importance of:
- Public-private information sharing;
- Information sharing between financial institutions;
- Cooperation between banks, payment institutions and virtual asset service providers;
- Faster communication between fraud and AML teams;
- Cross-border cooperation between law enforcement agencies;
- Shared fraud typologies and risk indicators; and
- National anti-scam or anti-fraud coordination mechanisms.
Information sharing should not be limited to periodic industry reports or general typology updates.
Its greatest value may come from enabling action while the funds are still traceable and recoverable.
Machine Learning Can Improve Anomaly Detection
The scale of digital transactions makes purely manual monitoring impossible.
Financial institutions are increasingly using machine learning and advanced analytics to identify fraud and money laundering patterns that may not be captured by traditional rules.
Rule-based monitoring might identify a transaction exceeding a specific value or a transfer involving a high-risk jurisdiction.
Machine learning can potentially identify combinations of weaker signals.
For example, an individual transaction may not appear highly suspicious. Risk may only become apparent when several factors are considered together:
- The account was recently opened;
- The customer has changed devices;
- Several unrelated parties have sent funds to the account;
- Incoming funds are immediately transferred onward;
- New beneficiaries have recently been added;
- Transaction activity occurs at unusual times;
- Funds are divided into smaller amounts; and
- Payments involve several jurisdictions or platforms.
Machine learning may also help financial institutions identify groups of connected accounts rather than reviewing each customer separately.
Network analysis can reveal common devices, addresses, telephone numbers, beneficiaries, counterparties or transaction patterns.
This is especially relevant for money mule networks, where individual accounts may appear relatively low-risk when viewed separately.
However, machine learning is not a substitute for good control design.
Financial institutions still need to understand:
- What risks the model is designed to detect;
- Whether the available data is complete and reliable;
- How the model distinguishes victims from perpetrators;
- How alerts are prioritised;
- How investigators interpret the model’s output;
- Whether decisions can be explained to regulators;
- How model performance is tested;
- Whether false positives are properly managed; and
- How the model is updated as criminal techniques evolve.
A sophisticated model operating on incomplete or fragmented data may still fail to detect important relationships.
The value of machine learning depends not only on the technology itself, but also on data quality, governance, investigation processes and human judgement.
Should Fraud Monitoring and AML Transaction Monitoring Be Integrated?
FATF does not require every financial institution to combine its fraud and AML teams into a single department.
It also does not prescribe one specific technology platform or organisational structure.
However, the risks described in the paper make a heavily siloed approach increasingly difficult to defend.
Where fraud proceeds are moved immediately, money mule accounts are reused across multiple schemes and transactions pass rapidly through several payment channels, the separation between fraud data and AML data may become a major control weakness.
Integration does not necessarily mean merging every team.
A more practical objective is to create a connected financial crime operating model.
Under such a model, information and risk signals can move between fraud, AML, cybersecurity, sanctions and payment operations without unnecessary delay.
A Shared View of the Customer
Fraud and AML investigators should be able to access relevant customer, account, device, beneficiary and transaction information.
Risk should be assessed at the customer relationship and network level, rather than only at the level of an individual alert.
Cross-Triggering Between Monitoring Systems
A fraud alert should be capable of triggering an AML review where an account may be receiving or transferring criminal proceeds.
An AML investigation should also be capable of triggering fraud prevention action where customers or counterparties may be at immediate risk.
Coordinated Case Management
Where fraud and AML alerts involve the same customer, account or transaction chain, institutions should avoid conducting two disconnected investigations.
Relevant evidence, decisions and investigation outcomes should be accessible to both functions.
Common Typologies and Risk Indicators
Fraud, AML, cybersecurity and sanctions teams may observe different parts of the same criminal network.
Combining those observations can produce stronger risk indicators than maintaining separate typology libraries.
Aligned Escalation Procedures
Financial institutions need clear processes for deciding when to:
- Block a payment;
- Delay a transaction;
- Contact the customer;
- Restrict an account;
- Investigate connected parties;
- Contact another financial institution;
- Attempt asset recovery; or
- Submit a suspicious transaction report.
Fraud prevention, customer protection, AML reporting and asset recovery may involve different legal thresholds.
However, the operational response should be coordinated.
The objective is not to create organisational uniformity. It is to prevent information barriers from helping criminals move funds through the institution.
Integration Must Be Implemented Carefully
Integrating fraud and AML controls also creates risks that need to be managed.
A customer who receives suspicious funds should not automatically be treated as an intentional money launderer.
Cyber-enabled fraud creates complex relationships between victims, facilitators and perpetrators.
A customer may have been manipulated into transferring money. An account may have been compromised. An individual may have been recruited without understanding the criminal purpose.
Institutions therefore need proportionate investigation processes.
Automatically closing accounts or restricting services solely because a customer has interacted with suspected fraud proceeds may create unfair outcomes.
It may also discourage genuine victims from reporting scams.
Data governance is another important consideration.
Greater integration may involve wider use of:
- Device information;
- Behavioural data;
- Payment histories;
- Customer communications;
- External intelligence;
- Shared databases; and
- Network analysis.
Access to this information must remain consistent with privacy, banking secrecy and data protection requirements.
Machine learning models must also be supervised carefully.
Poorly governed models may produce excessive false positives, replicate historical biases or become less effective as fraud methods evolve.
The purpose of integration should be to improve the quality and speed of decisions—not simply to centralise a larger number of alerts.
What Financial Institutions Should Review
FATF’s paper should encourage financial institutions to assess whether their controls reflect the way modern fraud proceeds actually move.
A useful starting point is to map the full lifecycle of a cyber-enabled fraud event:
- The victim is contacted or manipulated;
- A payment is initiated;
- Funds are received into a mule or controlled account;
- The proceeds are divided or transferred;
- Funds move through additional institutions or platforms;
- The proceeds cross borders;
- Funds are converted, withdrawn or integrated; and
- The institution attempts investigation, reporting and recovery.
Institutions can then identify where systems, teams and responsibilities are disconnected.
Important questions include:
- Can the AML function access relevant fraud alerts and investigation outcomes?
- Can fraud teams identify accounts already linked to AML concerns?
- Are money mule risks considered during customer onboarding?
- Are mule account indicators included in transaction monitoring?
- Can related accounts, devices and beneficiaries be analysed as a network?
- How quickly can a high-risk payment be reviewed?
- Can the institution delay or suspend suspicious transactions where legally permitted?
- Are virtual asset transactions included in the financial crime risk assessment?
- Can investigators see activity across different payment channels?
- Can the institution contact a receiving financial institution quickly?
- Are machine learning models properly governed and tested?
- Does management receive an integrated view of fraud, AML and asset recovery outcomes?
The effectiveness of integration should be judged by operational outcomes.
These outcomes may include:
- Faster detection of mule accounts;
- Reduced movement of fraud proceeds;
- Higher asset recovery rates;
- Better identification of connected accounts;
- More useful suspicious transaction reports;
- Fewer duplicated investigations; and
- More accurate identification of victims and perpetrators.
The Broader Message From FATF
The most important message in FATF’s 2026 paper is not simply that cyber-enabled fraud is increasing.
It is that fraud has become deeply embedded in the wider illicit finance ecosystem.
Fraud proceeds are transferred through money mule networks. They are moved through instant payment systems, fintech platforms and bank accounts. They may be converted into virtual assets or sent across borders before recovery action can begin.
The underlying operations may involve shell companies, professional money launderers and transnational organised crime groups.
Financial institutions that view fraud only as a payment loss risk may fail to identify the laundering network behind the transaction.
Institutions that view AML primarily as a post-transaction reporting obligation may identify criminal proceeds only after the opportunity to stop or recover them has passed.
The direction of travel is increasingly clear.
Fraud prevention, AML transaction monitoring, payment controls, intelligence sharing and asset recovery should operate as connected parts of the same financial crime framework.
Cyber-enabled fraud is no longer adjacent to AML.
It is now one of AML’s core risks.
Main Source
FATF — Cyber-Enabled Fraud: Digitalisation and Money Laundering, Terrorist Financing and Proliferation Financing Risks



