Money Moves in Seconds. Europe’s Evidence Requests Move in Months — If They Are Sent at All

Report on Directive 2019/1153

Money Moves in Seconds. Europe’s Fraud Framework Is Too Slow to Obtain Financial Evidence — And Too Weak on What Must Follow

The EU is improving bank-account discovery, fraud monitoring and information sharing. Three EFRI case files show the two gaps that remain: authorities still lack a sufficiently fast and direct route to obtain cross-border financial evidence, and the framework does not sufficiently determine what action must follow once the information is available.

On 29 July 2026, the European Commission published its report on Directive (EU) 2019/1153 — 726 days after the reporting deadline set by Article 21(1) of the Directive (EU) 2019/1153, the Union’s principal framework for giving law-enforcement authorities access to financial information (Report on the implementation of Directive (EU) 2019/1153, COM(2026) 408 final, adopted 29 July 2026; circulated by the Council as ST 12326/26 on 26 August 2026)

Its findings are precise. In Articles 7 to 10 of the Directive there are no time limits to ensure that Financial Intelligence Units and competent authorities exchange financial information or analyses swiftly across borders. Europol-related requests show the effect: “more than 160 requests over the years 2023/2024 and a response rate of 75%”, with “an average of a 50-days response delay”.

The deeper divide is legal. FIU information may be restricted to intelligence use and therefore unavailable in court; several law-enforcement agencies called “the limitation for using the information only for intelligence purposes” a “relevant hindrance”. Where direct request powers are confined to domestic proceedings, evidence in another Member State requires a European Investigation Order — and “the EIO can take up to 30 days to be recognised, while criminals move money across borders in the matter of minutes if not seconds“, the recognition period set by Article 12(3) of Directive 2014/41/EU. And recognition is not the end of the statutory timetable. Article 12(4) generally allows a further 90 days for the investigative measure to be carried out after the recognition or execution decision. The formal architecture itself is therefore measured in weeks and months.”

More than two thirds of law enforcement authorities consulted called for having the possibility of directly exchanging information with obliged entities”, chiefly because of speed. The Commission nonetheless found “it is too soon to conclude on the need and proportionality of extending the definition of financial information“.

At the same time, the EU is rolling out a substantial new architecture: interconnected bank-account registers, a common format for transaction records, the Anti-Money Laundering Regulation (AMLR), the new AML authority AMLA, and a Payment Services Regulation (PSR) that will impose much stronger fraud-monitoring and provider-to-provider information-sharing duties. These measures are routinely presented as part of Europe’s answer to online fraud.

They are useful reforms. But they do not close two structural gaps that repeatedly defeat cross-border fraud investigations. First, authorities still lack a sufficiently fast and direct route to the financial institution holding the evidence in another Member State. Second, once relevant information is available, the legal and institutional framework does not sufficiently determine who must act, by when, and with what consequence.

EFRI’s case files illustrate both problems. In three investigations spanning almost a decade, the decisive failure occurred at different points after the relevant information either existed or could legally have been obtained: a formal cross-border request took 228 days; known judicial requests were not issued until the victim escalated the case; and a multi-bank risk picture did not result in consistent action across the remaining payment rails.

The common defect was therefore not simply lack of information. Europe still lacks both a fast financial-evidence route and an enforceable chain for turning information into action.

Four different tasks are being treated as one

Policy discussions often treat financial-information access as a single technical problem. Operationally it is at least four separate tasks: finding the account; understanding the transaction network; preserving or freezing data and funds; and producing records in a form that can be used in criminal proceedings. A reform can materially improve one of those tasks while leaving the others almost untouched.

Directive (EU) 2024/1654 is a good example. It will allow designated authorities to search interconnected national bank-account registers across borders and requires transaction records to be supplied in a common structured format. That is a real improvement in account discovery and data processing. But an account register is not a substitute for the account statement, KYC file, beneficial-ownership documentation or transaction evidence held by the institution. The new structured format standardises what arrives after a lawful production obligation has been triggered; it does not itself create that production obligation across borders.

The Commission’s July 2026 report acknowledges the remaining procedural barrier directly: where national powers to obtain information from obliged entities are tied to criminal proceedings, cross-border access still requires an EIO. The Commission was specifically asked by practitioners to create faster direct exchange with obliged entities, but concluded that it was still too early to decide whether the definition of financial information should be extended.

That distinction becomes even clearer when the financial framework is compared with the EU’s new e-Evidence Regulation. Since 18 August 2026, a judicial authority in one Member State can send a European Production Order directly to an in-scope digital service provider in another Member State. The provider must normally respond within ten days and within eight hours in an emergency. Financial services are outside that regime. Europe has therefore demonstrated that it can create a direct, deadline-driven cross-border production mechanism. It has not created an equivalent mechanism for bank and payment-account evidence.

For online fraud, this is not a marginal procedural problem. A mechanism measured in weeks or months is structurally mismatched to a payment chain that can cross several institutions and jurisdictions within minutes.

Three case files, 2017 to 2026: what changed on paper, and what did not

The three files that follow were selected because EFRI holds them in full and because they bracket the period the Commission’s report covers: a European Investigation Order issued in December 2017, a supervisory record from 2017 and 2018, and a prosecution file that ran from January to July 2026. Three files are not a statistical basis, and they differ in jurisdiction, offence and scale. What they permit is narrower and harder to obtain: a reconstruction, document by document, of how long each step actually took and which step was never taken at all — precisely the information that, on the Commission’s own account, is nowhere systematically recorded.

2017 Payvision: one second to pay, ten months to document.

In German proceedings concerning card payments connected with the Option888 scheme, the Munich public prosecutor issued a European Investigation Order to the Netherlands dated 14 December 2017, under file 313 Js 216815/17, seeking information and transaction records from Payvision – the Dutch licensed PSP that processed the card payments for the fraud scheme (Option888). 

The Dutch translation of the EIO was completed on 12 January 2018. The next day shown in the file is 20 June 2018 — 159 days later — when the Amsterdam public prosecutor issued a formal demand to Payvision. Payvision received it by email on 21 June, obtained a four-week extension until 19 July, and responded on 17 July 2018; the Dutch return letter carried the same date. The response was stamped as received in Munich on 30 July 2018: 228 days from the German EIO. 

Where the intervening 160 days were lost, the records reviewed by EFRI do not show — not when the Dutch authority received or recognised the EIO, not which office held it, not why the request reached the institution only in June. Nor does the file contain any indication that the completeness or accuracy of what Payvision supplied was afterwards examined by either authority. That is the accountability gap: the instrument existed and eventually produced a response, but neither the victim nor an external reviewer can reconstruct where the decisive delay occurred, or in which jurisdiction — and no one verified what finally arrived. And as by then the prosecutor in charge had changed in Munich, the answer from Payvision got lost in the files piling up in Munich/Saarbrücken.

Authorising the underlying card payment, between the issuing bank and Payvision, took about a second. Establishing who had acquired that payment took roughly three months of enquiries with the issuing bank; the European Investigation Order that followed took a further 228 days. Some ten months, in total, to document a transaction that had executed in one. The payment rail is instantaneous and automated; the information rail that follows the same payment is manual, sequential and measured in months.

The lesson from Payvision is therefore not merely that an EIO should be administered more efficiently. A system in which financial evidence can spend months moving between public authorities is structurally mismatched to online fraud. For defined categories of financial evidence and subject to judicial safeguards, Europe should consider a direct cross-border production order addressed to the obliged entity itself, with preservation measured in hours and production measured in days. 

Eight years separate that file from the next; in between, Directive (EU) 2019/1153 was transposed in Germany, Article 6a was inserted into it and AMLA was established. What the next file shows is not an instrument used too slowly, but an instrument that — on the available record — was never used at all.

2026 Mainz: five accounts, two enquiries, and a complaint before the requests went out

The second file concerns a 2025 online-investment fraud in which a German victim transferred €163,103 in ten payments to five accounts in Italy, Greece, the Netherlands and Malta. EFRI previously reported on the FINOM/Triventa account and its wider transaction pattern. On 15 January 2026, the Mainz public prosecutor directed the police to identify the account holders. A police record dated 21 January shows the practical consequences of the cross-border structure.

Where the money went, and who was asked about it
# Jurisdiction Receiving institution Amount Approached by the police? What the file records
1 Italy Poste Italiane S.p.A. €43,000 No — the institution was not written to, because it was known from other proceedings that such enquiries are referred to the Italian judiciary No information obtained; a judicial request for mutual legal assistance marked as required
2 Greece Eurobank S.A. €5,000 Yes, 21 January 2026 Replied 4 February 2026, declining disclosure on an informal police request; the account holder would be identified only upon a judicial request for mutual legal assistance, which the report marks as required
3 Italy Banca di Credito Cooperativo di Roma €17,003 * Not separately — recorded as already approached in another strand of the file Account holder identified: an individual resident in Rome
4 Netherlands Finom Payments B.V. €54,000 Yes, 21 January 2026 Replied 3 February 2026 with account information and supporting records; no judicial request marked as required; the records show the funds forwarded, together with other fraudulently obtained money, to a Danish account of Triventa Ltd
5 Malta OpenPayd Financial Services Malta Ltd €44,100 No — the institution was not written to, because it was known from other proceedings that such enquiries are referred to the Maltese judiciary No information obtained; a judicial request for mutual legal assistance marked as required
Total €163,103 Two of five institutions approached A judicial request marked as required for three of the five accounts

Source: police record of the Kriminalinspektion Mainz 1 of 21 January 2026, drawn up pursuant to the direction of the Mainz public prosecutor of 15 January 2026, file 3500 UJs 902/26. Account numbers and the names of account holders and officers have been omitted.
* Figure to be confirmed against the bank records.

In this investigative strand, direct enquiries were sent to two of the five institutions. One further account holder had already been identified elsewhere in the file. For two institutions, no direct enquiry was made because investigators expected that such requests would be referred to the national judiciary. Eurobank in Greece was contacted and replied that it would identify the account holder only on the basis of a judicial request. FINOM in the Netherlands, by contrast, answered the direct police request within thirteen days and supplied account information and supporting records.

That answer materially changed the picture. The €54,000 payment was part of a six-week account that had received 67 credits totalling €314,183.31, predominantly from private remitters in Germany, Austria and Switzerland. €313,725 — 99.85% of the inflow — was passed onward to Banking Circle accounts. One answered enquiry therefore transformed what looked like an individual €54,000 transfer into evidence of a collection account serving dozens of remitters.

Yet on 11 March 2026 the prosecution discontinued the case, reasoning in substance that the traces led abroad, that mutual legal assistance would be required and that further measures would be disproportionate or unlikely to succeed. The case was reopened after a complaint, but a police report of 1 June recorded that no concrete investigative instructions had been issued. The discontinuation was maintained the next day.

The judicial requests that the January police record had already identified as necessary were ultimately sent only after a supervisory complaint to the Generalstaatsanwaltschaft Koblenz in July 2026. By then, the victim had himself obtained additional account information through data-access requests and confirmations from foreign institutions that they would cooperate with competent judicial authorities.

This is a different failure from Payvision. The legal instrument did not run slowly; on the available record, it did not run at all until the victim forced the issue. The case also shows why the claim that more bank-to-bank data sharing will solve the investigative problem is incomplete. The information may exist and an institution may be willing to provide it, yet the case still fails if the competent authority does not activate the procedural channel required to obtain it. 

Where a legally available cross-border investigative measure has been identified but is not used, that decision should require a documented and reviewable justification.

B2G: the network was visible — but action remained fragmented

The B2G file presents the opposite configuration. Here, the problem was not lack of information. Banks, BaFin, the Bundesbank, the FIU and prosecutors accumulated substantial information across multiple institutions during 2017 and 2018. For more information about the criminal case refer to  BaFin knew: But Victims’ Money Continued to Flow for Months.

Kölner Bank filed a suspicious transaction report in August 2017 and terminated its relationship. Deutsche Bank, UniCredit and Südwestbank also filed reports. Following a criminal search, BaFin sent information requests in November 2017 to Sparkasse Koblenz and another B2G bank. In December the Bundesbank, in coordination with BaFin, requested statements from seven institutions. Its January 2018 analysis documented private retail deposits from multiple countries, repeated “Investment” and “Private Investment” references and large onward transfers. BaFin’s internal material recorded at least €2.7 million of inflows by early January 2018.

By January 2018, therefore, the problem was no longer account discovery. A cross-institution picture existed: multiple banks, retail deposits from several countries, recurring investment references, rapid onward transfers and recurring foreign beneficiaries.

The FIU transmitted an operative analysis to the Cologne prosecutor on 5 February 2018 and recommended criminal proceedings. The prosecutor opened file 115 Js 75/18 on 16 February. By the end of February, several banks had closed or frozen B2G relationships. BaFin also issued a disposition ban in relation to the Südwestbank account after that bank had already blocked it.

Sparkasse Koblenz remained the only B2G banking relationship documented in the reviewed file. It had answered BaFin’s November 2017 information request within two days. Its first documented suspicious transaction report in the material reviewed by EFRI is dated 12 June 2018. The Cologne prosecutor seized the remaining balance in July. The Cologne judgment later quantified 153 outward transfers totalling €13,801,292.45 through the relationship up to 4 June 2018. In its later reporting Sparkasse Koblenz reported about complaints and about several law enforcement requests for information starting in March 2018.  

The significance of the two-day response to BaFin is therefore not that the information system worked. It shows that information could be produced quickly once requested. The unresolved question is why an increasingly detailed cross-bank risk picture did not produce comparably consistent intervention across the relationships carrying the same network.

B2G therefore does not support the proposition that authorities simply lacked access to bank information. It supports a harder proposition: even when a multi-bank picture exists, the allocation of responsibility for turning that picture into coordinated intervention can remain fragmented. Information moved. Consequences did not necessarily move with it, resulting in avoidable material harm to consumers.

The B2G file thus exposes the second structural gap. The problem is not only horizontal information sharing. It is also responsibility: who must act on the combined picture, who must identify the next still-open payment rail, who must escalate the case, and within what time?

Three files, two structural gaps

The three cases show different failure modes, but they fall into two broader defects.

Payvision — access and transmission failure: the legal instrument was used, but the cross-border process took 228 days.

Mainz — activation failure: the necessary judicial route was identified, but not initiated until repeated victim escalation.

B2G — coordination and action failure: a broad multi-bank picture existed, but information did not translate into consistent intervention across the payment network.

The first problem is getting the information quickly enough. The second is ensuring that information triggers action. Europe needs to solve both.

Would Europe’s New Financial-Information Framework Have Changed These Three Cases?

Under Article 83a of the current PSR compromise text, payment service providers would be required to participate in fraud-information-sharing arrangements where objectively justified reasons exist to suspect fraudulent behaviour. The information that may be exchanged is tied to the fraud-prevention purposes of Article 83 and to specified categories of transaction, account, payer and payee data.

That may help prevent the next payment. It does not give a German prosecutor a direct right to compel a Dutch, Greek, Maltese or Italian financial institution to produce the full evidentiary record of an account. It does not replace a timely and fully answered EIO, create a Union-wide criminal-case identifier or impose a deadline for the full path from complaint to production, freezing and return.

The AMLR will be broader in one respect. Article 69 strengthens FIU access to obliged entities and requires responses to FIU requests within five working days, with shorter deadlines — including less than 24 hours — in justified urgent cases. Article 75 permits information-sharing partnerships in which obliged entities can exchange customer, beneficial-ownership, transaction and risk information. Competent authorities may participate.

Those are meaningful improvements. But Article 75 itself preserves the applicable national criminal-procedure rules and, where required, judicial authorisation. Information-sharing partnerships can therefore improve intelligence. They do not create a substitute cross-border criminal-evidence code, and they do not establish a direct judicial financial production order comparable to the e-Evidence mechanism.

The relevant question is therefore narrower: would the current EU reform package have prevented the decisive failure documented in any of these three files?

CaseDocumented failureWould PSR/AMLR fix it?
Payvision228 days from EIO to receipt; long unexplained inter-authority intervalNo. PSR Art. 83a concerns PSP fraud-information sharing; AMLR Art. 69 creates deadlines for responses to an FIU, not for the prosecutor–EIO–executing-authority chain.
MainzInvestigators knew judicial requests were required but they were not sent until victim escalationNo. More accessible information does not create an obligation on a prosecutor to initiate the necessary cross-border measure.
B2GExtensive multi-bank information existed, but action across the payment rails remained fragmentedOnly partially. PSR/AMLR may improve detection and the network picture. They do not themselves ensure that a network-level warning produces coordinated restraint, investigation or evidence production.

This is not an argument that the reforms are ineffective. They may materially improve fraud detection, account discovery, transaction monitoring and preventive intervention. The distinction is different: the reforms improve important inputs into the system, but they do not create either a sufficiently direct cross-border financial-evidence route or an enforceable end-to-end obligation governing what must happen after relevant information exists.

More information is not the same as faster evidence. Faster evidence is not the same as freezing. And none of the three necessarily produces coordinated enforcement.

What a reform designed for online-fraud investigations would have to add

A. Fix access to financial evidence

  1. A direct, judicially controlled cross-border production route for specified financial evidence in serious cross-border fraud cases. The e-Evidence model shows that the Union can combine direct service, fixed deadlines and fundamental-rights safeguards. A financial-evidence mechanism would need comparable rules for transaction records, KYC and beneficial-ownership material.

  2. Emergency preservation measured in hours. Emergency preservation measured in hours. Authorities need an immediate mechanism to preserve relevant account and transaction data while the production process continues. Where the legal threshold for provisional asset restraint is met, a parallel mechanism must allow funds to be secured before they are transferred onward.

  3. End-to-end traceability and binding deadlines. A request should carry a common identifier from issue to receipt, recognition, assignment, execution and return. The Payvision file should not contain a 159-day period that cannot be reconstructed from the record.

B. Fix what happens once the information exists

  1. Network-based escalation rather than one-victim proportionality. A complaint involving one €5,000 or €54,000 payment may be one edge of a collection network. Repeated payment recalls, multiple unrelated private remitters, rapid pass-through activity, common beneficiaries or multiple complaints concerning the same receiving account should trigger network-level assessment.

  2. Reviewable reasons when cross-border tracing is declined. Where investigators identify a legally available cross-border measure but decide not to use it on grounds of proportionality, expected delay or anticipated futility, that decision should be documented in a structured and reviewable form. The existence of a foreign financial trail should not itself count as a reason against investigation.

  3. Accountability for what happens after information is shared. The B2G file shows that information sharing is not an outcome. Supervisors, FIUs, banks and prosecutors need defined escalation responsibilities, auditable decisions and outcome metrics: time to next-node identification, time to preservation, amount frozen and amount ultimately returned to victims.

Our Assessment

The EU should stop treating the quantity of information exchanged as a proxy for the effectiveness of the system. A bank-account register is useful. A standardised transaction record is useful. A fraud-information-sharing platform is useful. An FIU response deadline is useful. But none of these measures, by itself, answers the two questions that matter after a fraud payment has left the victim’s account:

How can the competent authority obtain the next financial node directly and in time?

And once the information is available, who must act on it, by when, and what happens if nobody does?

Payvision, Mainz and B2G show three versions of those two structural defects. In Payvision, the mechanism moved too slowly. In Mainz, the known measure was not activated until the case was escalated. In B2G, information was assembled without producing consistent action across the payment network.

The current reforms may improve all three environments. They do not, by themselves, cure either structural problem.

Europe currently lacks both ends of an effective online-fraud response: a sufficiently fast and direct way to obtain cross-border financial evidence, and an enforceable chain that determines what must happen once that evidence exists.

More information sharing is welcome. But it cannot compensate for a system in which obtaining the evidence can take months and responsibility for acting on that evidence can remain diffuse, uncoordinated or insufficiently reviewable.Money moves in seconds. The legal architecture for following it must be designed around that fact. For victims, the difference is not merely procedural. It can determine whether the money remains recoverable at all.

More about this topic.