An analysis of video-KYC data from across North India has flagged ten districts as higher-risk zones for mule account activity linked to cyber fraud and illicit fund routing, with eight of the vulnerable areas located in Uttar Pradesh. The study, conducted by fraud prevention company IDfy, evaluated digital onboarding records across approximately 130 districts between April 2025 and June 2026 to detect abnormal verification signals. While financial institutions have increasingly relied on remote identity checks for customer acquisition, the study indicates that syndicates routinely attempt to exploit onboarding channels to create dummy accounts, which are subsequently deployed to obscure the money trail of stolen funds.
Eight Districts in Uttar Pradesh Show Elevated Rejection Levels
The findings indicate that several northern districts require heightened scrutiny during the account creation process, led by Lakhimpur Kheri, which recorded the highest video-KYC rejection rate at 14.03 per cent. Bareilly followed closely with a rejection rate of 13.37 per cent, while Varanasi stood at 12.32 per cent, Saharanpur at 10.32 per cent, and Muzaffarnagar at 9.77 per cent. Beyond these five areas, other flagged locations included Panipat in Haryana at 9.52 per cent, Firozabad in Uttar Pradesh at 8.81 per cent, Jodhpur in Rajasthan at 7.61 per cent, Lucknow at 6 per cent, and Ghaziabad at 5.91 per cent.
Company analysts emphasized that these rejection figures do not mean every resident or account holder in the listed districts is engaged in illicit operations. Instead, the metrics represent warning signals captured during identity screenings, where onboarding calls were blocked because of suspected impersonation, document tampering, third-party prompting, or irregular applicant behavior. Consequently, the affected locations should be considered emerging risk clusters rather than areas where widespread criminal activity is conclusively proven. Mule accounts serve as transactional conduits in cybercrime networks, often established when individuals are lured by commissions to hand over control of banking credentials, enabling fraudsters to disperse illicit balances across multiple layers.
Fraud Patterns Shift Rapidly Across Neighboring Regions
The data shows that risk spikes within specific administrative boundaries tend to be short-lived, with criminal operations moving rapidly to circumvent local detection. Across the 15-month study, around 81 per cent of district-level risk surges persisted for merely one month, while only 6.5 per cent remained elevated for three months or longer. Furthermore, once an area witnessed a decline in risk indicators, the next cluster emerged within the same state in 39 per cent of instances, traveling an average geographic distance of roughly 190 km.
This mobility suggests that commercial banks cannot rely solely on historical hotbeds to defend their systems. A drop in suspicious verifications in one town often signifies geographic migration rather than the total suppression of a syndicate, requiring lenders to monitor onboarding traffic in neighboring districts simultaneously. Additionally, the analysis established that retired hotspots can reactivate after dormancy. IDfy noted that its quarterly forecasts identified around 16 district clusters during financial year 2026, with 85 to 90 per cent later corroborated by law enforcement actions or public disclosures, occasionally anticipating official notices from the Indian Cyber Crime Coordination Centre.
Early Onboarding Metrics Provide Advanced Warning System
To separate incidental anomalies from coordinated abuse, the evaluation employed a three-tier model requiring minimum sample sizes, baseline fraud volumes, and Z-score rankings, where a district had to record at least 30 rejected sessions in a single month to qualify. The findings illustrate how early customer onboarding data could act as an operational early-warning layer alongside government and police efforts, though researchers stressed that automated verification flags cannot substitute for statutory investigations. Concurrently, the patterns underline the importance of public vigilance against sharing passwords, one-time passwords, or account access for promised commissions.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics