Executive Overview
Mule accounts are the connective tissue of digital fraud: almost every typology covered elsewhere in this series — UPI social engineering, fake lending apps, merchant collusion — ultimately depends on a mule layer to move and cash out proceeds. This report examines that layer directly, as an ecosystem with its own structure, rather than as an afterthought to each originating scam.
The scale now visible through national coordination infrastructure makes this treatment necessary rather than optional. I4C's Suspect Registry had received more than 23 lakh suspect identifiers and shared more than 27 lakh Layer-1 mule accounts with participating entities by January 2026, with declined-transaction value of ₹9,518.91 crore reported against this data. That is not a cottage industry — it is infrastructure at national scale.
What Is Changing in Mule-Account Behaviour
Mule recruitment and use have professionalised. Rather than a single account holder knowingly or unknowingly lending access, fraud operations increasingly run tiered structures with distinct roles: recruiters sourcing accounts through job and investment scam fronts, herders managing batches of accounts, and aggregators handling final cash-out. Account provenance has also diversified — genuine but coerced or paid account holders, rented accounts, and accounts opened outright on synthetic or stolen identities now coexist within the same laundering chain.
Layer-1 vs Downstream Mule Accounts
I4C's own data-sharing model draws a useful working distinction. Layer-1 mule accounts are the first point of contact for defrauded funds — the account a victim's payment lands in directly. Downstream accounts receive funds passed on from Layer-1 (and subsequent layers), typically in smaller, faster hops designed to break the audit trail before final aggregation and cash-out. Layer-1 accounts are, in practice, the highest-value interdiction point: catching a Layer-1 account before funds move on prevents the entire downstream chain from ever activating.
Rapid Fund Movement
The defining behavioural signature of a mule account is speed: funds that arrive and leave within minutes or hours, far faster than genuine transaction patterns for the account's stated purpose. This is a deliberate design choice by fraud operators, who need to move value through the chain before any single institution's manual review can intervene — which is precisely why real-time, rather than batch, detection is required to act on it.
Account Velocity and Dormancy Patterns
Two velocity patterns recur across confirmed mule cases: a sudden, sharp increase in transaction frequency and value on an account with a previously low or unremarkable activity history, and the reactivation of a long-dormant account immediately followed by high-volume movement. Both patterns are individually simple to define as rules — the harder part operationally is tuning thresholds so they catch mule activity without generating unmanageable false-positive volume against genuine account behaviour changes (a new job, a large legitimate purchase).
Common Device, Mobile and Beneficiary Relationships
Individual mule accounts rarely operate in true isolation. The same device, the same mobile handset or SIM, or the same beneficiary account frequently recurs across multiple mule accounts that otherwise appear to belong to unrelated customers. This shared infrastructure is often the single fastest way to expose a ring, because it does not depend on spotting any one transaction as suspicious — it depends on noticing that several "different" customers are, functionally, the same operation.
Multiple Accounts Controlled Through Common Infrastructure
Beyond shared devices and beneficiaries, mature mule operations show common infrastructure at a deeper level — shared IP ranges or geolocation patterns, common onboarding channels or agent codes, and repeated use of the same identity-fragment sources (a breached data set, a compromised e-KYC vendor) across accounts opened weeks or months apart. Identifying this requires entity resolution — the ability to recognise that data points scattered across separate account records describe the same underlying operation.
Merchant and Mule-Account Connections
Mule networks and merchant fraud increasingly intersect. A merchant account — genuine, compromised, or set up purely as a shell — can function as a cash-out point for mule-layered funds, disguising the final withdrawal as an ordinary sale. Institutions that treat merchant risk and mule-account risk as separate monitoring programmes are structurally likely to miss this connection; it only becomes visible when the two data sets are analysed together.
Network-Based Detection
Rule-based, single-account monitoring is necessary but insufficient here by design: no single-account rule can express "this account shares a device with four other accounts that also show rapid pass-through behaviour." Graph and network analytics — modelling accounts, devices, beneficiaries and IPs as connected entities rather than independent records — are the appropriate detection layer for mule activity specifically, complementing rather than replacing transaction-level rules.
How Banks Can Identify the Network Before Losses Escalate
- Prioritise Layer-1 mule detection: interdicting the first-receiving account prevents the entire downstream chain from activating.
- Treat dormant-account reactivation as an elevated-priority signal, not a routine event.
- Invest in entity resolution and graph analytics capable of linking accounts by shared device, IP, or beneficiary — not just shared identity fields.
- Participate actively in national data-sharing infrastructure (I4C's Suspect Registry and Layer-1 mule-account feeds) rather than relying solely on internally observed patterns.
- Correlate mule-account signals with merchant monitoring, since cash-out increasingly routes through merchant rails.
The single most important shift this report argues for is moving from transaction risk to entity and network risk. A transaction-risk model asks whether this payment looks suspicious. An entity and network risk model asks whether this account, this device, or this beneficiary is part of a pattern — and that second question is where mule networks are actually caught, before losses escalate rather than after.
Sources & References
- Ministry of Home Affairs — I4C Suspect Registry & Financial Fraud Risk Indicator data (Lok Sabha Q. No. 5124, 24.03.2026)
- Ministry of Home Affairs — Press Releases (I4C–RBIH MoU, May 2026)
- Ministry of Home Affairs — Indian Cybercrime Coordination Centre (I4C) Scheme
- Reserve Bank of India — Regulatory Guidance & Statistics
External links open in a new tab. Referenced for authoritative context; BANKiQ is not affiliated with the linked bodies.