Money muling and tech-enabled fraud: the UIF’s 2026 red flags for Italian EMIs
On 8 June 2026 Italy’s FIU told every obliged entity, in effect, that the line between online fraud and money laundering has all but disappeared — and that their transaction monitoring has to catch both at once. The UIF communication on scams, technology-facilitated fraud, money muling and other cyber-offences is not a new law; it is an updated map of red flags, built from the financial analysis of tens of thousands of suspicious-transaction reports. For an Italian EMI, payment institution or bank, it is the current working definition of what a fraud-and-muling case looks like on-screen. This piece sets out what the communication says, the indicators it lists, the three new reporting codes it introduces, and how to wire it into a live monitoring programme.
1. What the 8 June 2026 communication is
The communication (“Operatività connessa con truffe, frodi agevolate dalla tecnologia, money muling e altri reati informatici”) is a UIF guidance document addressed to obliged entities (soggetti obbligati) under Legislative Decree 231/2007 — the Italian AML decree. It updates and, in part, replaces earlier UIF material: the 2010 behaviour scheme on computer fraud and the anomaly indicators issued by the UIF Provvedimento of 12 May 2023. It does not create a fresh legal obligation; the duty to report remains Article 35 of Legislative Decree 231/2007 (file a suspicious-transaction report — SOS — whenever there is knowledge, suspicion or reasonable grounds to suspect laundering or terrorist financing). What the communication does is tell analysts what “suspicion” tends to look like in a digital-fraud case, and how to describe it so the report is useful.
2. Why the UIF issued it — the numbers
The trigger is volume. Between 2021 and 2025 the UIF linked more than 80,000 suspicious-transaction reports to fraud schemes, and the annual count rose from just over 9,000 in 2021 to more than 30,000 in 2025 — with 2026 already trending higher. The communication situates this against international data: the Financial Action Task Force published a dedicated Cyber-Enabled Fraud paper in February 2026, global losses were estimated at over USD 400 billion in 2025, and in Italy alone the postal-and-cyber police recorded volumes above EUR 269 million that year. The point for a compliance officer is that fraud proceeds are now a mainstream laundering typology, not an edge case — and instant payments, virtual IBANs and crypto-assets are the rails that move them.
3. Technology-facilitated fraud — the typologies and indicators
The communication first catalogues the predicate frauds it sees feeding the laundering flow: phishing (credential theft), job scams (fake job offers with an up-front payment), impersonation scams, business e-mail compromise (BEC), romance scams, purchase and rental scams, fake-charity scams and investment scams (often in crypto-assets, offered by unauthorised parties). It then lists the anomalies an intermediary can actually observe:
- Subjective red flags — refusal or reluctance to give ordinary information, inconsistent or untrue data, illogical behaviour, prior mentions in SOS or in judicial-authority requests.
- Device and connection anomalies — VPNs, proxies or anonymisers inconsistent with the customer profile; device emulation or virtualisation; frequent changes to the device fingerprint (operating system, browser, resolution, language, hardware); the same IP shared by multiple unrelated accounts; access from geographically distant locations incompatible with the customer’s residence.
- Transaction anomalies — a mismatch between the beneficiary name given by the sender and the actual account holder (especially where the payment is executed anyway); rejected, reversed, disowned or recalled operations; repeated unjustified transfers soon after account opening; activity concentrated at weekends or holidays; funds moved on the same or next day to other accounts, crypto or cash at ATMs (including crypto-ATMs).
These map directly onto data an EMI already holds — the KYC file, the device/session telemetry and the payment record — so the communication is really asking firms to fuse anti-fraud signals with the AML case rather than run them in separate silos.
4. Money muling — the mule-account red flags
Money muling is the transit layer: individuals who, knowingly or not, lend their accounts, cards or wallets to move illicit proceeds. The communication lists characteristic markers — recently opened accounts, cards or wallets; holders whose profile suggests inexperience or vulnerability (young people, the unemployed, pensioners); contact data (e-mail addresses) shared across several unrelated holders, or changed without justification after opening; geolocation anomalies on digital access; fast in-and-out flows, often fractioned, low-value, cross-border, with unrelated counterparties; generic payment references inconsistent with any real economic activity; recall requests that are hard to satisfy; and an account holder who becomes unreachable or uncooperative.
5. Cybercrime as a predicate
The third strand covers laundering connected to cyber-offences proper — intrusion, compromise or digital manipulation to steal information, credentials or crypto keys, or to seize control of systems and accounts. The communication names examples: Advanced Persistent Threats (APT), malware, ransomware, man-in-the-middle attacks and Distributed Denial of Service (DDoS). Publicly available news of a hostile cyber-attack on a counterparty is itself flagged as a relevant input to the suspicion assessment, particularly for unauthorised system-access cases. This is distinct from the fraud strand: the laundering here follows an offence against systems and data, not a deception of a victim.
6. The three new SOS phenomenon codes
Operationally, the most concrete change is in how reports are classified. The communication introduces three new phenomenon codes that obliged entities select when filing, and retires an old one.
| Code | Use it for |
|---|---|
| I01 — Scams and tech-facilitated fraud | Suspected fraudulent conduct and the related laundering. |
| I04 — Money muling | Suspected recruitment of people (aware or not) to move illicitly obtained funds — used alone or alongside I01. |
| I05 — Cybercrime | Suspected computer offences outside I01, marked by abuse or alteration of systems and sophisticated compromise techniques for economic gain. |
| I02 — Computer fraud (retired) | No longer available; the 2010 computer-fraud behaviour scheme ceases to apply from publication. |
Firms should update their SOS-filing templates and staff guidance so that analysts pick I01, I04 and/or I05 — more than one may apply to the same case — and never reach for the discontinued I02.
7. How the rules play out — three worked examples
Scenario A — a mule ring behind an investment scam.
- Facts: Six accounts opened within two weeks at an Italian EMI, held by unemployed customers in their early twenties, three sharing the same recovery e-mail domain. Each receives instant credits of EUR 900–1,500 from unrelated senders, then forwards the funds cross-border within hours; references read “consulting”.
- Rule: The muling markers in §2.2 (recent opening, vulnerable profile, shared contact data, fast fractioned cross-border flow, generic causals) combine; separately, the upstream senders fit an unauthorised-investment-scam pattern (§2.1).
- Action: File one SOS coding I04 (money muling) and, given the scam origin, also I01; describe the ring as a network, not six isolated accounts, and file before executing the next outbound leg where possible.
- Outcome: The report supports rapid tracing and possible asset recovery abroad; the shared telemetry lets the UIF connect the six accounts.
Scenario B — a beneficiary-name mismatch on an instant credit.
- Facts: A payment arrives naming “Maria B.” as beneficiary, but the receiving account is held by an unrelated company; the customer accesses the service via a VPN from a country inconsistent with its registered seat, and the device fingerprint changed twice in a week.
- Rule: The name/holder mismatch executed anyway, plus the connection and device anomalies in §2.1, are cumulative red flags — and the verification-of-payee check under the Instant Payments Regulation would already have surfaced the mismatch.
- Action: Escalate, document the holistic assessment, and file an SOS coded I01; retain the IP, VPN, fingerprint and geolocation data as structured detail in the report.
- Outcome: The technical elements let the UIF and investigators reconstruct a wider network rather than treating one payment in isolation.
Scenario C — laundering after a ransomware payout.
- Facts: A corporate customer suddenly liquidates positions and sends funds to a newly onboarded counterparty using a self-hosted wallet; open-source news reports a ransomware incident at the customer that week.
- Rule: This is a cyber-offence predicate under §2.3, not a victim-deception fraud; the self-hosted-wallet and anonymisation angle raises the tracing difficulty the communication warns about.
- Action: File an SOS coded I05 (cybercrime), incorporating the publicly available attack information and the wallet/crypto trail.
- Outcome: Correct coding routes the case to the right UIF analysis stream and flags the crypto-tracing challenge early.
8. Filing well — quality and timing
The communication closes on report quality, echoing the UIF’s SOS instructions of 18 December 2025. It asks firms to avoid reporting on autopilot: no generic, standardised SOS text copied across filings, no purely defensive reports, and a description calibrated to the concrete facts. Timing is critical — report as early as possible, ideally before the operation is executed, so intervention can protect victims and preserve funds, and complete the “execution status” field correctly. Include the technical elements (IP, VPN, fingerprint, device, geolocation) as structured data, and where an activity touches more than one obliged entity, share information within the bounds of Article 39 of Legislative Decree 231/2007. Finally, use the UIF’s return flow (flusso di ritorno) to tune future reporting.
9. FAQ
Is the 8 June 2026 communication binding law?
No. It is UIF guidance for obliged entities under Legislative Decree 231/2007. The reporting obligation itself sits in Article 35 of that decree; the communication updates the anomaly indicators and behaviour schemes that support the suspicion assessment. It is expressly exemplary and non-exhaustive.
What happened to the old I02 “computer fraud” code?
It is retired. From publication of the communication the I02 code is no longer available and the 2010 computer-fraud behaviour scheme no longer applies. Cases now map to the new codes I01 (scams/tech-fraud), I04 (money muling) and I05 (cybercrime), one or more of which may apply.
Does a customer emptying their account mean I should file a muling SOS?
Not on its own. The UIF states that zeroing a balance is not per se a sign of money muling; it must be assessed together with the other markers — recent opening, vulnerable holder profile, shared contact data, fast fractioned cross-border flows, generic references and an uncooperative holder.
Why does the communication stress IP, device and geolocation data?
Because digital fraud and muling leave technical traces. Shared IPs across unrelated accounts, distant or incompatible geolocation, VPN/anonymiser use and changing device fingerprints are among the strongest signals, and — within privacy limits — capturing them as structured data in the SOS lets the UIF reconstruct networks.
How does a virtual IBAN feature in these schemes?
A virtual IBAN redirects payments to an account identified by a different (master) IBAN — defined in Article 2(1)(26) of Regulation (EU) 2024/1624. The communication flags v-IBANs, especially those issued cross-border to payment service providers in less-cooperative jurisdictions, as a tracing obstacle; Banca d’Italia and the UIF published dedicated v-IBAN AML guidance on 12 December 2024.
10. What to do, today
- Update SOS templates and analyst guidance to the new codes I01, I04 and I05, and remove I02 from the pick-list.
- Fuse anti-fraud and AML signals — feed device, IP, fingerprint and geolocation telemetry into the AML case, not just the fraud queue.
- Re-tune monitoring for the mule pattern: recent openings by vulnerable profiles, shared contact data, fast fractioned cross-border flows — while remembering that balance-zeroing alone is not enough.
- Set the process to report before execution where possible, and drop boilerplate SOS narratives in favour of case-specific descriptions with structured technical data.
- Map the v-IBAN and self-hosted-wallet tracing gaps into your risk assessment, and use Article 39 sharing where a case spans several intermediaries.
Related: UIF anomaly indicators & red-flag schemes · Filing a SOS via Infostat-UIF · Mule-account reporting in Spain · Sanctions & screening in instant payments


