A global report finds cyber fraudsters are increasingly using India-based mule accounts, especially in smaller cities, to launder stolen money as overseas scam hubs face crackdowns.

As Overseas Scam Hubs Fall, India’s Own Bank Accounts Become the New Getaway Car

The420 Web Correspondent
5 Min Read

For years, money stolen from Indian cyber-fraud victims tended to disappear across the border, routed through accounts in Southeast Asia before vanishing into crypto wallets. That pattern is now reversing. A new global report finds that international fraud networks are increasingly parking stolen funds in bank accounts opened right here in India, often in the country’s smaller towns and cities rather than its financial capitals.

The shift, detailed in BioCatch’s 2026 Digital Banking Fraud Trends in India report, is being read by officials as a direct consequence of the coordinated international crackdowns on scam compounds in Myanmar, Cambodia and Laos over the past two years. As those overseas hubs have come under sustained pressure, criminal networks appear to be rebuilding their cash-out infrastructure closer to the victims themselves.

An Organised Business, Not Isolated Misuse

What distinguishes this wave from older, opportunistic account misuse is scale and structure. The report describes networks running thousands of accounts in coordination, with stolen funds typically landing in a mule account before being dispersed across several others within minutes, a layering process built specifically to outrun manual investigation.

Union Home Minister Amit Shah underscored the scale of the challenge at a recent event, describing mule accounts as one of the biggest obstacles to curbing cybercrime in India. According to a Lok Sabha reply from the Ministry of Home Affairs, the Indian Cyber Crime Coordination Centre’s Suspect Registry had identified and shared details of 27.37 lakh Layer-1 mule accounts with banks and other participating entities as of January 31, helping prevent transactions worth more than ₹9,518 crore, a figure that illustrates both the size of the problem and the scale of the response already underway.

The Small-City Recruitment Pipeline

The report’s most striking finding may be geographic. Rather than concentrating in metros with dense financial infrastructure, mule account recruitment is increasingly reaching into Tier-2 and Tier-3 towns, where financial awareness tends to be lower and the promise of easy income through a “part-time job” or “work-from-home opportunity” carries more pull. Fraudsters offer commissions in exchange for access to bank accounts, debit cards or mobile numbers, sometimes without the account holder ever realising their credentials are being used by an international syndicate, and sometimes with full knowledge in exchange for a cut.

Either way, account holders face real legal exposure. Investigators say those who knowingly rent out their accounts can be booked alongside the syndicates that use them, while even unwitting participants often find their accounts frozen and their own finances entangled in a criminal investigation they never intended to join.

Detection Is Racing to Catch Up

The report’s core recommendation is that transaction monitoring alone can no longer keep pace with how fast layered fraud moves. It calls for deeper real-time information-sharing between banks, fintech companies, telecom providers and law enforcement, arguing that mule activity needs to be flagged much earlier in an account’s lifecycle rather than only after suspicious transactions have already occurred.

Some of that infrastructure is already being built. The RBI’s MuleHunter.AI system, a machine-learning tool designed to detect anomalous account behaviour, is now operational across 26 banks and expanding, while a separate fraud-detection analysis found over 5.24 lakh suspected mule accounts and digital identities flagged in a single month earlier this year, with payments banks accounting for a disproportionate share due to faster, lighter-touch onboarding processes.

Prof. Triveni Singh, the cybercrime expert and former IPS officer, said mule accounts have become the backbone of nearly every major cyber fraud operating in India today, and that anyone who lends their bank account, ATM card, cheque book or internet banking access to another person risks becoming an unwitting participant in a serious criminal network. He called for stronger KYC compliance at account opening, continuous behavioural monitoring thereafter, and sustained public awareness, particularly in the smaller towns now being targeted, stressing that no commission or promised income is worth the criminal liability that can follow.

Stay Connected