On July 17, 2026, Bank Al-Maghrib (BAM) and Morocco’s Financial Intelligence Unit, the Autorité Nationale du Renseignement Financier (ANRF), gathered banking and compliance officials in Rabat for a national workshop on financial fraud. The result is a Bank Al-Maghrib phishing crackdown that goes well beyond a public-awareness campaign: it includes a new guidance document targeting mule bank accounts and concrete instructions for banks to roll out mandatory multi-factor authentication (MFA), trusted-device recognition, and stronger mobile app security.

For Moroccan businesses, this matters immediately. If your company banks in Morocco, the way you log in and approve transactions is about to change, understanding why can help you avoid becoming an unwitting victim, or worse, a suspect.

Bank Al-Maghrib phishing

What the Bank Al-Maghrib Phishing Crackdown Actually Changes

Bank Al-Maghrib Phishing Crackdown started on a workshop by ANRF President Jawhar Nfissi and BAM’s Director of Banking Supervision, Nabil Badr, alongside a comparative session from Diogo Lencastre of Banco de Portugal — a signal that Morocco is positioning digital fraud as an international supervisory priority, not a purely local problem.

BAM’s response centers on two separate guidance documents that are worth keeping apart:

1. A Second Guidance Document, One Year Later

In July 2024, BAM issued its first phishing best-practices guide for credit institutions, focused on how banks should detect and communicate about phishing attempts targeting their customers. The July 2026 announcement is a second, distinct document — this one specifically about “comptes rebonds,” or mule bank accounts, covering how banks should identify, detect, and handle them.

2. New Technical Requirements for Banks

According to Nabil Badr, fraudsters increasingly succeed not by breaching bank systems directly, but by using social engineering to trick individual users — fake banking SMS messages, malicious links shared on social media, and impersonation of financial institutions. BAM’s response is a set of concrete security requirements for banks’ digital and mobile channels:

  • Mandatory multi-factor authentication (MFA) for both account access and transaction validation — meaning a password alone will no longer be enough to log in or move money.
  • Trusted-device recognition — banking apps will learn which phones and computers a customer normally uses, and treat logins from an unrecognized device as higher risk, typically triggering extra verification.
  • Stronger mobile banking app security, hardening the apps themselves against tampering and interception.

Why the Bank Al-Maghrib Phishing Crackdown Matters for Moroccan Businesses

This is a regulatory signal with real operational consequences, not just an awareness push. Two things follow directly from it.

First, the login and approval experience on business banking portals and apps is set to change as banks implement MFA and trusted-device checks.

Second, and less obvious: any business that regularly sends or receives transfers through Moroccan bank accounts should understand what a “compte rebond” is, because the new detection guidance means banks are actively watching for the patterns mule accounts create.

Who Is Affected

  • Banks and financial institutions, who must implement the new MFA and device-recognition requirements.
  • SMEs and enterprises with Moroccan business bank accounts, whose banking login and transaction-approval workflows will change.
  • E-commerce businesses and any company that regularly sends or receives payments, whose transaction patterns may draw closer bank review.
  • Compliance and AML teams, as Morocco prepares for its periodic evaluation by MENAFATF (the Middle East and North Africa Financial Action Task Force, known locally as GAFIMOAN).
  • Individual banking customers, who are the direct target of the phishing and impersonation campaigns this initiative addresses.

What Are “Comptes Rebonds” (Mule Bank Accounts)?

A “compte rebond,” or mule account, is a bank account used as an intermediary stop for stolen or fraudulently obtained funds. Instead of moving money directly from a victim’s account to their own, a fraudster routes it through one or more mule accounts first.

This step exists for one reason: to break the trail between the victim and the fraudster, making the stolen money harder to trace and recover.

Diagram of the Bank Al-Maghrib phishing fraud chain from phishing message to mule account laundering

How Phishing Campaigns Feed Mule Accounts

The connection between phishing and mule accounts is the whole fraud chain. Fraudsters send a fake banking SMS, email, or social media message impersonating a bank, urging the target to “verify” their account or “confirm” a transaction on a lookalike login page. Once credentials are captured, the funds are moved out.

This is precisely why BAM is treating both ends of the chain together: MFA and trusted-device recognition make it harder for stolen credentials alone to unlock an account, while the mule-account guidance makes it harder for stolen funds to disappear cleanly once they leave it.

Why Now?

This announcement doesn’t stand alone. It builds on the National Committee against Financial Fraud, created in February 2025 and coordinated by ANRF, which brings together the institutions responsible for detecting and disrupting fraud networks. It also comes as Morocco prepares for its periodic evaluation by MENAFATF/GAFIMOAN, the regional body that assesses countries’ anti-money-laundering and counter-terrorist-financing frameworks.

What Moroccan Businesses Should Do Now

To help Bank Al-Maghrib phishing crackdown, You don’t need to wait for your bank to finish rolling out its new controls to reduce your own exposure. Practical steps to take today:

  • Enable MFA everywhere your bank offers it.
  • Verify unexpected bank communications independently.
  • Train staff who handle payments.
  • Never share OTPs (one-time passwords) or verification codes.
  • Review your device list (in banking apps that support trusted-device recognition).
Infographic of security tips for Moroccan businesses following the Bank Al-Maghrib phishing crackdown

Recommendations

Beyond individual vigilance, businesses that process significant payment volume through Moroccan banks should treat this as a prompt to review their own fraud-prevention posture: confirm which staff have banking access and why, document your process for verifying payment changes from suppliers or partners, and make sure your incident-response plan covers what to do if a business account is ever flagged or frozen.

The direction from BAM and ANRF is clear: phishing defense and financial-fraud detection are converging into one coordinated framework. Businesses that get ahead of it — strong authentication, trained staff, and a habit of verifying before trusting — will be far better positioned than those waiting for their bank to make the change for them.


Follow Secureweb