Supreme Court Directs RBI to Standardise Mule Account Response Amid Rising Cyber Fraud

India has built one of the world’s most advanced digital payment ecosystems in less than a decade. Unified Payments Interface (UPI) now processes over 20 billion transactions every month, making India the global leader in real-time retail payments. The speed, scale and accessibility of digital payments have transformed financial inclusion, commerce and customer experience, establishing the country’s Digital Public Infrastructure (DPI) as a global benchmark.

However, every technological leap creates a corresponding governance challenge. The same infrastructure that enables money to move between accounts in seconds has also compressed the time available to detect, intercept and recover fraudulent transactions. Organised cybercriminals are increasingly exploiting the velocity of instant payments, using networks of mule accounts, layered fund transfers and digital identities to dissipate stolen money long before victims, banks or law enforcement agencies can respond.

It is against this backdrop that the Supreme Court’s recent directions assume considerable significance. While responding to a series of petitions concerning cyber-enabled financial frauds and digital arrest scams, the Court directed the Reserve Bank of India (RBI) to prepare and circulate a Standard Operating Procedure (SOP) within four weeks for handling bank accounts linked to cyber frauds, including mule accounts. Simultaneously, it instructed states, Union Territories and law enforcement agencies to accelerate the operationalisation of grievance redressal and money restoration mechanisms, establish State Cyber Crime Coordination Centres, adopt the e-Zero FIR framework and strengthen public awareness campaigns.

Viewed together, these directions represent more than judicial oversight of cybercrime. They acknowledge a structural reality: India’s payment ecosystem has become real-time, and its governance architecture must evolve at the same pace.

A Digital Economy Facing an Increasingly Sophisticated Threat Landscape

India’s digital payments ecosystem has expanded at an unprecedented pace. According to the RBI’s Annual Report, digital payments have recorded sustained double-digit growth, while UPI has become the preferred payment rail for individuals, businesses and government services alike. This rapid adoption has delivered significant economic benefits but has also expanded the attack surface available to organised fraud networks.

The Ministry of Home Affairs’ Indian Cyber Crime Coordination Centre (I4C) has repeatedly identified financial fraud as one of the fastest-growing categories of cybercrime. Investment scams, impersonation frauds, phishing attacks, fake trading platforms and the rapidly proliferating “digital arrest” scams increasingly rely on complex transaction chains designed to frustrate investigations and delay fund recovery.

Government data also indicates that complaints registered through the National Cyber Crime Reporting Portal (NCRP) and the 1930 Cyber Helpline continue to rise as digital transactions become more pervasive. In many instances, stolen funds are dispersed across multiple accounts within minutes, often moving through several banks before being withdrawn or redirected to other jurisdictions. The challenge is no longer confined to preventing unauthorised transactions; it has become one of disrupting organised financial crime ecosystems operating at machine speed.

Why the Supreme Court’s Directions Matter

The Supreme Court’s intervention is notable because it shifts the conversation beyond individual fraud cases to the broader architecture of cyber fraud governance. Rather than focusing exclusively on investigation or prosecution, the Court has emphasised institutional coordination, operational consistency and faster victim restitution.

The direction requiring the RBI to develop a standardised SOP for mule accounts is particularly significant. While banks already maintain internal fraud management frameworks, customer due diligence processes and suspicious transaction monitoring systems, operational responses often differ across institutions. A common framework has the potential to bring greater consistency in identifying suspicious accounts, coordinating inter-bank communication, preserving evidence, freezing fraudulent transactions and supporting law enforcement investigations.

The Court has also directed all states and Union Territories to operationalise the Grievance Redressal Module and Money Restoration Module developed under the Ministry of Home Affairs’ Standard Operating Procedure for the National Cyber Crime Reporting Portal. Equally important are the directions to establish State Cyber Crime Coordination Centres, expand the adoption of the e-Zero FIR mechanism and expedite matters relating to freezing bank accounts linked to cyber-enabled financial frauds.

Collectively, these measures recognise that successful fraud response depends as much on governance, coordination and speed as it does on investigative capability.

India’s Cyber Fraud Response Is Becoming More Integrated

India’s institutional response to cyber-enabled financial crime has evolved significantly over the past few years. The establishment of the Indian Cyber Crime Coordination Centre (I4C), expansion of the National Cyber Crime Reporting Portal, launch of the nationwide 1930 helpline and development of grievance and money restoration modules have gradually shifted the response from a complaint-driven model towards coordinated intervention.

The RBI has simultaneously strengthened regulatory expectations around fraud risk management, cybersecurity, customer due diligence and technology resilience. Banks have invested heavily in behavioural analytics, artificial intelligence, transaction monitoring systems and real-time fraud detection capabilities. Increasing emphasis is also being placed on information sharing between financial institutions and law enforcement agencies to reduce response times during active fraud incidents.

One notable initiative has been the collaboration between the RBI Innovation Hub (RBIH) and I4C to develop MuleHunter.ai, an artificial intelligence-based solution designed to identify networks of suspected mule accounts by analysing transaction behaviour across multiple banking relationships. Unlike conventional rule-based monitoring, network analytics enables investigators to detect interconnected account ecosystems rather than isolated suspicious transactions, reflecting the growing role of AI in combating financial crime.

These developments suggest that India’s cyber fraud response is gradually transitioning from reactive investigation towards predictive detection and coordinated intervention.

Learning from Global Financial Centres

India is not alone in confronting the challenges posed by real-time payments. Financial regulators across the world are reassessing governance frameworks as payment systems become faster and fraud networks increasingly transnational.

Singapore has introduced the Collaborative Sharing of Money Laundering and Terrorism Financing Information and Cases (COSMIC), enabling participating financial institutions to securely exchange information on suspicious customers and potentially illicit transactions. The initiative reflects a growing recognition that combating organised financial crime requires controlled intelligence sharing rather than isolated institutional responses.

The United Kingdom has pursued a complementary approach. The introduction of Confirmation of Payee enables customers to verify whether the recipient’s account name matches the intended beneficiary before authorising a payment, reducing certain categories of authorised push payment fraud. The UK has also strengthened reimbursement obligations for victims of eligible payment scams, increasing accountability across the payment ecosystem.

Similarly, Australia’s Scam Safe Accord brings together banks, telecommunications providers and digital platforms to strengthen fraud prevention through coordinated intelligence sharing, customer awareness and technology-led interventions. Across the European Union, instant payment regulations are increasingly accompanied by enhanced fraud verification requirements and stronger customer protection measures.

While these approaches differ in design, they share a common principle: fraud prevention is no longer viewed solely as the responsibility of individual banks. It is increasingly treated as a collaborative ecosystem involving regulators, financial institutions, technology providers, telecom operators and law enforcement agencies.

From Faster Payments to Faster Governance

The Supreme Court’s directions also highlight an important shift in regulatory thinking. The emphasis is no longer limited to preventing fraud; it extends to improving the speed of grievance resolution, fund restoration, institutional coordination and public awareness. This reflects an understanding that customer confidence in digital payments depends not only on preventing fraud but also on ensuring that recovery mechanisms function efficiently when incidents occur.

The Court has further asked the Inter-Departmental Committee to examine a shared liability and victim compensation framework, alongside measures to strengthen awareness regarding digital arrest scams and other cyber-enabled financial frauds. Although still under examination, the proposal mirrors international discussions on balancing consumer protection with institutional accountability in increasingly digital financial ecosystems.

As payment infrastructures become more interconnected across jurisdictions, cybercrime networks are also becoming more organised, leveraging automation, synthetic identities, social engineering and cross-border fund movement to exploit gaps between institutions. This makes operational coordination as important as technological capability.

A Defining Moment for India’s Financial Crime Governance

India’s digital payments success story has demonstrated how public digital infrastructure can transform financial inclusion and economic activity at unprecedented scale. Preserving trust in that ecosystem now requires governance frameworks capable of matching its speed and complexity.

The RBI’s forthcoming SOP on mule accounts is therefore significant not merely because it addresses one category of financial crime, but because it has the potential to establish greater operational consistency across banks, strengthen coordination between regulators and law enforcement agencies, and reinforce existing mechanisms for grievance redressal and fund restoration.

The challenge facing financial systems worldwide is no longer simply enabling instant payments, it is ensuring that fraud detection, institutional coordination and regulatory responses operate with equal velocity. India’s recent judicial and regulatory developments indicate that the country’s approach to cyber-enabled financial crime is entering a more integrated phase, where technology, governance and inter-agency collaboration are increasingly viewed as complementary pillars of financial resilience.

As digital payments continue to expand, the effectiveness of this evolving framework will play an important role in shaping confidence in India’s financial system. The next chapter of India’s digital payments journey may therefore be defined not only by how quickly money moves, but also by how effectively institutions work together to protect it.

Top