Cyber fraud proceeds are increasingly being routed through multiple bank accounts before reaching the actual operators, creating a major challenge for investigating agencies. Fraudsters use mule accounts to transfer money received from victims through different accounts, making it difficult to trace the original source and identify the ultimate beneficiaries. In several cases, money originating from a single fraudulent transaction can pass through dozens, hundreds or even thousands of accounts before being moved to another financial channel. Banks and law-enforcement agencies are now increasingly using artificial intelligence, data analytics and risk-based monitoring to identify suspicious accounts and disrupt these networks.
What Is A Mule Account
A mule account is a bank account held in the name of an individual or entity but used by another person to receive or transfer illegally obtained funds. In some cases, account holders may not know how their accounts are being used. In others, people allegedly provide their accounts to criminals in exchange for money or commissions.
Fraud Proceeds Routed Through Multiple Accounts
Cybercrime investigations have shown that fraud proceeds are often moved rapidly between different bank accounts instead of being kept in a single account. The objective is to break the direct financial trail and make it harder for investigators to identify the actual beneficiaries.
Money transferred by a victim may first reach a mule account before being moved to other accounts. It can then be withdrawn in cash or transferred through other banking and financial channels. Investigators have to reconstruct each transaction to establish the complete money trail.
People from financially vulnerable sections are also allegedly recruited into such networks. Intermediaries may offer them commissions or quick payments for allowing their accounts to be used. In some cases, cheque books, debit cards, SIM cards and banking credentials are also handed over to other people.
Mule Account Found in ₹20.30 Crore Digital Arrest Fraud
A case investigated in Mumbai South involved an 86-year-old woman who was allegedly cheated of ₹20.30 crore in a digital arrest scam. During the investigation, a Bengaluru-based man was arrested after his company’s bank account was allegedly used to transfer ₹5 crore of the fraud proceeds.
According to the investigation, around ₹2.5 crore reached his account. He allegedly retained ₹5 lakh and transferred the remaining amount to his handler. The investigation resulted in the arrest of 13 accused persons and the filing of charge sheets against them.
The case highlights how a business or company bank account can also allegedly be used to move cyber fraud proceeds. Investigators have to determine the account holder’s role, level of knowledge and links with the wider financial network.
Gaming Website Used to Lure Man, ₹5 Crore Reached Account
In another case in Uttarakhand, a young man was allegedly lured with the promise of earning money through a gaming website. He was reportedly told that he would receive a share of the earnings after opening a bank account. The account was subsequently used to receive around ₹5 crore linked to cyber fraud.
The bank blocked the account after receiving a complaint, following which the young man approached the police. Such cases create a challenge for investigators in determining whether an account holder was knowingly involved in the fraud network or was himself being used as a conduit.
Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions
PAN Cards and Government Schemes Used to Collect Identity Details
Investigators have also identified cases in which bank accounts were allegedly opened using people’s identities without their knowledge. In rural areas, Aadhaar details and biometric information were reportedly collected under the pretext of government schemes, subsidies and surveys and allegedly used to open bank accounts.
In a case reported from Madhubani in Bihar, mule accounts were allegedly opened under the pretext of helping people obtain PAN cards. The accused reportedly used their own mobile numbers during the KYC process and later obtained ATM cards linked to the accounts. The accounts were allegedly used to receive cyber fraud proceeds.
₹40 Lakh Jewellery Purchase Exposes Another Money Trail
In another case, two men purchased jewellery worth around ₹40 lakh from a jeweller. They paid ₹2 lakh in cash and promised to transfer the remaining ₹38 lakh through RTGS. The money reached the jeweller’s account and the bank confirmed the transaction, following which the jewellery was handed over.
Police later informed the jeweller that the money credited to his account was linked to cyber fraud and the account had been frozen. Such cases show how criminals can allegedly use apparently legitimate business transactions to move fraudulent funds, sometimes without the immediate knowledge of the recipient.
AI Tools Being Used to Identify Suspicious Accounts
Technology is playing an increasingly important role in the fight against mule accounts. The Department of Telecommunications has introduced the Financial Fraud Risk Indicator, or FRI, which assesses the risk associated with mobile numbers reported in connection with financial fraud. Numbers can be classified as medium, high or very high risk. The information can be shared with banks, payment platforms and financial institutions to generate alerts when flagged numbers are used for financial transactions.
The RBI Innovation Hub has developed MuleHunter, an AI-based tool designed to identify suspicious accounts. It can analyse banking data for patterns such as sudden increases in transaction volumes, repeated transfers to multiple accounts, unusual activity in previously inactive accounts and suspicious login locations or IP addresses.
Renowned cybercrime expert and former IPS officer Prof. Triveni Singh said mule accounts have become a critical link in the financial network of cybercrime. He said identifying such accounts requires more than examining large-value transactions and should include analysis of changes in normal account behaviour, transaction velocity, networks of senders and recipients, and related digital activity. According to him, stronger real-time information sharing between banks and law-enforcement agencies can significantly improve the ability to stop fraudulent funds at an early stage.
KYC Gaps Also Under Scrutiny
With large numbers of mule accounts being detected, investigating agencies are examining weaknesses in account-opening and KYC procedures. If a large number of suspicious accounts are linked to a particular bank branch or intermediary, investigators may also examine whether prescribed verification procedures were properly followed.
Strict KYC, face-to-face verification and video KYC can help reduce the risk of fraudulent accounts being opened. Customers are also being advised to regularly monitor their bank accounts and immediately report unexplained transactions to their banks and the authorities.
People have been cautioned against sharing Aadhaar and biometric information, cheque books, ATM or debit cards, SIM cards and banking credentials with unknown individuals. Suspicious cybercrime activity can be reported through the 1930 cybercrime helpline or the National Cyber Crime Reporting Portal.
The rapid movement of cyber fraud proceeds through multiple mule accounts has made financial investigations increasingly complex. Stronger KYC, AI-based monitoring, financial intelligence and faster coordination between banks and law-enforcement agencies are emerging as key tools to disrupt the financial networks that allow cybercriminals to move and conceal illicit funds.