What Is a Mule Account and How Do You Catch the Fraudsters Behind It?
A mule account passes KYC, transacts normally, then funnels stolen money at speed. This guide explains what mule accounts are, the four types your detection model must cover, and the signal categories that catch them after onboarding.
A mule account is a bank or payment account used to receive, transfer, and layer proceeds of fraud or money laundering on behalf of criminals. The account holder may be a willing participant, a coerced individual, or a victim whose credentials were stolen. In every case the account functions as a conduit, moving illicit funds through the financial system to obscure their criminal origin.
Detecting mule accounts after onboarding, not just at it, is what separates institutions that contain losses from those that absorb them. This guide covers the four account types your detection model must handle, the scale of the problem in India, and the six signal categories that modern detection systems evaluate.
What Makes a Mule Account Different
What Is a Mule Account?
A bank or payment account that receives, layers, and transfers proceeds of fraud or money laundering on behalf of criminals. It passes KYC at onboarding. It may transact normally for a period. Then it moves stolen money at speed, often dispersing funds across 30–50 additional accounts simultaneously before the original fraud is reported.
Mule accounts don’t show up as NPAs. They pass KYC. The Reserve Bank of India describes them as accounts “used by criminals to launder illicit funds, often set up by unsuspecting individuals lured by promises of easy money or coerced into participation.”[12]
The standard KYC question is this person who they say they are? — it does not catch a mule account if the identity is genuine and the account holder is complicit or coerced. The detection problem is behavioural and transactional, not just documentary. That reframe matters for compliance teams designing controls.
“The risk is no longer the borrower who defaults. It is the account that looks clean while funnelling fraud at scale.”
Four Mule Account Types Your Detection Model Must Cover
Fraud intelligence frameworks recognise four categories, each requiring a different detection approach.[11]
Witting Mules
Individuals who knowingly allow their accounts to be used for illegal transfers in exchange for payment. In India, recruitment often happens through direct outreach on WhatsApp, Telegram, and Instagram, offering quick income in exchange for letting business payments pass through a personal account.
Unwitting Mules
Individuals deceived into participation. Common lures include fake job posts advertising money transfer agent roles, and fraudulent customer-support calls where credentials are extracted under the pretext of fixing or upgrading an account.
Synthetic Identity Accounts
Accounts opened under fabricated or stolen Aadhaar and PAN documents. Aadhaar-based eKYC enables near-instant account creation — fraudsters exploit that speed to onboard before transaction monitoring establishes a baseline.
Compromised Legitimate Accounts
Genuine accounts whose credentials were stolen after onboarding. The account was clean at the point of onboarding; a remote operator took control afterward, leaving no signal at the KYC stage.
Key Takeaway
All four types share one characteristic: they pass the onboarding gate. The detection challenge is entirely post-activation. For more on what KYC verification methods can and cannot confirm at the point of onboarding, see What Is Video KYC (V-CIP) and How Does It Differ from e-KYC?
The Industrial Scale of the Problem in India
In 2024, India recorded 22.68 lakh cybercrime complaints — a 42.08% jump from 2023 — with total financial losses of ₹22,845.73 crore. Online financial frauds made up 67.8% of all cybercrime complaints.[3] In March 2026 alone, 5,24,121 mule instances were flagged in digital payments, with payments banks accounting for 41% of all suspicious Virtual Payment Address activity.[2]
26.48L
Layer-1 mule accounts shared with banks by I4C
As of December 2025
₹9,055Cr
Fraudulent transactions prevented by I4C Suspect Registry
Declined by participating banks
4,000+
Mule accounts identified daily through ongoing monitoring
I4C continuous surveillance
₹34,855Cr
Cybercrime proceeds under ED/PMLA investigation
₹12,229 Cr provisionally attached
The geography of mule recruitment has shifted. Organised networks in Rajasthan’s Bharatpur district, Jharkhand’s Jamtara, and Haryana’s Nuh now function as mule account supply chains, not cottage operations.
What the Enforcement Cases Reveal
Three recent operations illustrate where existing controls break down.
Operation Chakra-V (CBI, 2025)[6]
Found that more than 700 bank branches had opened approximately 8.5 lakh mule accounts, either without proper KYC norms or without adequate initial risk assessment. Nine arrested including middlemen, agents, account holders, and bank correspondents. CBI collaborated with the FBI, NCA (UK), and Japan’s Police Agency on cross-border elements.
J&K Operation Sindoor[4]
Uncovered 7,200 mule accounts over one year. Most were controlled remotely from abroad and remained active for only 1–2 days before closure: a deliberate strategy exploiting the lag between monitoring alerts and freeze orders.
ED Case, July 2026[7]
Traced ₹303.24 crore laundered through 216 mule accounts. Banking credentials were shared over Telegram; overseas handlers remotely authenticated transactions; funds converted on crypto exchanges and moved through a UAE-based fintech platform.
The pattern across all three cases: the weakest link is not identity verification at onboarding. It is the gap between onboarding and the first suspicious transaction, and the further gap between detection and freeze authority.
How Detection Actually Works: Six Signal Categories
Modern mule account detection evaluates signals across six categories. No single category is sufficient on its own.
Device Intelligence[10]
200+ device attributes that persist across browser clears and SIM swaps identify shared fraud infrastructure. Multiple account openings from the same device, or post-activation sessions arriving from a device different from the one used at onboarding, flag for review.
Behavioural Biometrics[9]
Typing rhythm, navigation patterns, and session behaviour reveal whether the person operating an account is the same person who onboarded. 48% of mule accounts display behavioural inconsistencies within 72 hours of activation despite clean KYC (per secondary analysis of AuthBridge behavioural biometrics research citing BioCatch 2023; readers should consult the primary source for full methodology). Banks that deployed behavioural biometrics saw a 35–48% reduction in mule account-related fraud attempts (based on secondary analysis of Deloitte India’s 2023 report; readers should consult the primary source for full methodology).
Transaction Monitoring and Velocity Analysis[11]
UPI red flags include: sudden transaction spikes from previously dormant accounts; large credits immediately followed by full withdrawals; round-number transactions with no apparent purpose; profile-transaction mismatches; multiple new beneficiaries added in rapid succession; shared device fingerprints across multiple accounts.
Graph Intelligence[15]
Maps nodes (accounts, devices, addresses, beneficiaries) and edges (shared attributes, fund flows, corporate ties) to surface mule rings that row-by-row transaction monitoring misses. An account receiving funds from multiple unrelated sources and rapidly dispersing to others is a graph-level signal, not a single-account signal.
Identity Verification: Digital Footprint and Synthetic Identity Signals[10]
Beyond Aadhaar/PAN document checks: phone reputation, email age, and cross-referencing submitted information against digital footprint signals. Synthetic identity accounts typically show thin or inconsistent digital histories outside the submitted documents.
Real-Time Risk Scoring[15]
Continuous evaluation across all signal categories, triggering immediate action when thresholds are crossed rather than waiting for batch processing cycles.
Why Rule-Based Systems Alone Don’t Work
Static rule-based AML systems produce up to 40% false positive rates in transaction monitoring (based on secondary analysis of EY-FICCI’s 2023 report; readers should consult the primary source for full methodology).[11] Rule-based systems producing 40% false positives overwhelm compliance teams and bury genuine mule signals under alert noise.
Three regulatory infrastructure layers address this at a national level:
MuleHunter.AI[1]
Developed by the Reserve Bank Innovation Hub (RBIH), announced December 2024, deployed across 23 banks as of December 2025. Uses machine learning to analyse transaction and account data, detecting approximately 20,000 mule accounts per month. The Ministry of Home Affairs has directed all financial institutions to integrate with the platform by December 2026.
Digital Payments Intelligence Platform (DPIP)[15]
Launched by RBI in partnership with NPCI, connecting banks, fintechs, payment service providers, and regulators to share verified fraud signals in real time, coordinating response within minutes rather than days.
Fraud Risk Indicator (FRI)[8]
Launched by the Department of Telecommunications in May 2025, classifying mobile numbers as Medium, High, or Very High risk. Within four months it prevented over 4.8 million fraudulent transactions and saved users ₹140 crore, sharing risk intelligence with 650+ banks and financial institutions. RBI mandated adoption across all scheduled and cooperative banks in June 2025.
The Regulatory Framework
Under PMLA 2002 as currently written, banks do not have the authority to freeze or block customer accounts without authorisation from a court or law enforcement agency.[4] This timing gap is exactly what criminals exploit: funds move out before the freeze order arrives. The Indian Banks’ Association has proposed granting banks authority to place temporary holds on suspected mule accounts. As of mid-2025, that change had not been legislated.
What PMLA does mandate is clear: Regulated Entities (banks, NBFCs, fintechs, VDA providers) must implement KYC, Customer Due Diligence, and ongoing transaction monitoring, and file Suspicious Transaction Reports to FIU-IND within 7 working days of forming suspicion. Tipping off the customer is strictly prohibited.
In July 2024, RBI Governor Shaktikanta Das explicitly directed banks to step up mule account monitoring and intensify customer awareness initiatives.[12] The RBI Master Direction on KYC (updated through 2024) requires continuous transaction monitoring using technology, periodic risk assessments, and Enhanced Due Diligence for high-risk accounts.
Where the Regulatory Obligations Currently Stand
- •Post-onboarding behavioural monitoring is a regulatory expectation under the RBI Master Direction on KYC, not just a detection best practice.
- •The Ministry of Home Affairs has directed all financial institutions to integrate with MuleHunter.AI by December 2026.
- •PMLA STR obligations to FIU-IND: within 7 working days of forming suspicion. Tipping off the customer is prohibited.
- •The IBA-proposed freeze authority amendment has not passed. The timing gap between detection and enforcement remains a real operational constraint.
How KYCKART Helps
KYCKART’s platform combines KYC identity data and fraud intelligence signals in one system for banks, NBFCs, insurers, and fintechs. Joining the identity anchor from onboarding with post-activation behavioural, transactional, and network signals is the same architectural logic behind MuleHunter.AI’s cross-institutional data pooling and the I4C Suspect Registry’s shared identifier blacklisting. For the specific detection capabilities relevant to your institution’s risk profile, speak with our team.
Frequently Asked Questions
Bhanujeet Choudhary
Head of Compliance, KYCKART · July 25, 2026
KYCKART Intelligence
Close the Gap Between Detection and Action
Mule accounts pass KYC. Stopping them requires joining identity data with post-onboarding behavioural and network signals in one system. See how KYCKART’s unified platform addresses this for Indian BFSI institutions.
Speak with Our Teamarrow_forward