Resources / Fraud Intelligence Reports / Mule Network Intelligence Report
Thematic Report
From Individual Fraud Accounts to Fraud Ecosystems

Mule Network Intelligence Report

Every major fraud typology in this series depends on a downstream layer of mule accounts. This report treats that layer as the subject, not the footnote — moving the unit of analysis from the transaction to the entity and the network around it.

Published Sep 2026 BANKiQ Fraud Intelligence Unit

Executive Overview

Mule accounts are the connective tissue of digital fraud: almost every typology covered elsewhere in this series — UPI social engineering, fake lending apps, merchant collusion — ultimately depends on a mule layer to move and cash out proceeds. This report examines that layer directly, as an ecosystem with its own structure, rather than as an afterthought to each originating scam.

The scale now visible through national coordination infrastructure makes this treatment necessary rather than optional. I4C's Suspect Registry had received more than 23 lakh suspect identifiers and shared more than 27 lakh Layer-1 mule accounts with participating entities by January 2026, with declined-transaction value of ₹9,518.91 crore reported against this data. That is not a cottage industry — it is infrastructure at national scale.

What Is Changing in Mule-Account Behaviour

Mule recruitment and use have professionalised. Rather than a single account holder knowingly or unknowingly lending access, fraud operations increasingly run tiered structures with distinct roles: recruiters sourcing accounts through job and investment scam fronts, herders managing batches of accounts, and aggregators handling final cash-out. Account provenance has also diversified — genuine but coerced or paid account holders, rented accounts, and accounts opened outright on synthetic or stolen identities now coexist within the same laundering chain.

Layer-1 vs Downstream Mule Accounts

I4C's own data-sharing model draws a useful working distinction. Layer-1 mule accounts are the first point of contact for defrauded funds — the account a victim's payment lands in directly. Downstream accounts receive funds passed on from Layer-1 (and subsequent layers), typically in smaller, faster hops designed to break the audit trail before final aggregation and cash-out. Layer-1 accounts are, in practice, the highest-value interdiction point: catching a Layer-1 account before funds move on prevents the entire downstream chain from ever activating.

Rapid Fund Movement

The defining behavioural signature of a mule account is speed: funds that arrive and leave within minutes or hours, far faster than genuine transaction patterns for the account's stated purpose. This is a deliberate design choice by fraud operators, who need to move value through the chain before any single institution's manual review can intervene — which is precisely why real-time, rather than batch, detection is required to act on it.

Account Velocity and Dormancy Patterns

Two velocity patterns recur across confirmed mule cases: a sudden, sharp increase in transaction frequency and value on an account with a previously low or unremarkable activity history, and the reactivation of a long-dormant account immediately followed by high-volume movement. Both patterns are individually simple to define as rules — the harder part operationally is tuning thresholds so they catch mule activity without generating unmanageable false-positive volume against genuine account behaviour changes (a new job, a large legitimate purchase).

Common Device, Mobile and Beneficiary Relationships

Individual mule accounts rarely operate in true isolation. The same device, the same mobile handset or SIM, or the same beneficiary account frequently recurs across multiple mule accounts that otherwise appear to belong to unrelated customers. This shared infrastructure is often the single fastest way to expose a ring, because it does not depend on spotting any one transaction as suspicious — it depends on noticing that several "different" customers are, functionally, the same operation.

Multiple Accounts Controlled Through Common Infrastructure

Beyond shared devices and beneficiaries, mature mule operations show common infrastructure at a deeper level — shared IP ranges or geolocation patterns, common onboarding channels or agent codes, and repeated use of the same identity-fragment sources (a breached data set, a compromised e-KYC vendor) across accounts opened weeks or months apart. Identifying this requires entity resolution — the ability to recognise that data points scattered across separate account records describe the same underlying operation.

Merchant and Mule-Account Connections

Mule networks and merchant fraud increasingly intersect. A merchant account — genuine, compromised, or set up purely as a shell — can function as a cash-out point for mule-layered funds, disguising the final withdrawal as an ordinary sale. Institutions that treat merchant risk and mule-account risk as separate monitoring programmes are structurally likely to miss this connection; it only becomes visible when the two data sets are analysed together.

Network-Based Detection

Rule-based, single-account monitoring is necessary but insufficient here by design: no single-account rule can express "this account shares a device with four other accounts that also show rapid pass-through behaviour." Graph and network analytics — modelling accounts, devices, beneficiaries and IPs as connected entities rather than independent records — are the appropriate detection layer for mule activity specifically, complementing rather than replacing transaction-level rules.

How Banks Can Identify the Network Before Losses Escalate

  1. Prioritise Layer-1 mule detection: interdicting the first-receiving account prevents the entire downstream chain from activating.
  2. Treat dormant-account reactivation as an elevated-priority signal, not a routine event.
  3. Invest in entity resolution and graph analytics capable of linking accounts by shared device, IP, or beneficiary — not just shared identity fields.
  4. Participate actively in national data-sharing infrastructure (I4C's Suspect Registry and Layer-1 mule-account feeds) rather than relying solely on internally observed patterns.
  5. Correlate mule-account signals with merchant monitoring, since cash-out increasingly routes through merchant rails.
BANKiQ Perspective

The single most important shift this report argues for is moving from transaction risk to entity and network risk. A transaction-risk model asks whether this payment looks suspicious. An entity and network risk model asks whether this account, this device, or this beneficiary is part of a pattern — and that second question is where mule networks are actually caught, before losses escalate rather than after.

Sources & References

SHARE

Looking for something specific?

Talk to our team directly, or request a demo to see the platform behind the resources.