Mule bank accounts have emerged as a key conduit for cybercriminals to receive, layer and move money obtained through online fraud, prompting banks, law-enforcement agencies and regulators to strengthen mechanisms to identify and block such accounts.
A mule account is a bank account belonging to an individual or entity but used by another person to receive or transfer illegally obtained funds. Such accounts may be opened in the names of unsuspecting individuals or deliberately provided by account holders to criminals in exchange for money.
Cybercrime investigations have shown that fraudulent funds are often moved through multiple layers of mule accounts, making it difficult for agencies to trace the actual perpetrators. In some cases, dozens or even thousands of accounts may be used to circulate the money before it is withdrawn or moved through other channels.
People from financially vulnerable sections, including workers in industrial areas, are sometimes targeted by intermediaries who offer them money or commissions for allowing their accounts to be used. Investigators have also found instances where individuals hand over their cheque books, debit cards, SIM cards and other banking credentials to others.
Authorities have warned that allowing an account to be used for illegal transactions can have serious legal consequences, even when the account holder claims ignorance of the nature of the transactions.
A case investigated in Mumbai South involved an 86-year-old woman who was allegedly defrauded of ₹20.30 crore in a digital arrest case. During the investigation, cyber police arrested a Bengaluru-based man whose company’s account was allegedly used to transfer ₹5 crore of the fraud proceeds. Around ₹2.5 crore was credited to his account, of which he reportedly retained ₹5 lakh and transferred the remaining amount to his handler. The investigation resulted in the arrest of 13 accused persons and the filing of charge sheets against them.
In Uttarakhand, investigators uncovered another case in which fraudsters befriended a young man and lured him with the promise of earning money through a gaming website. He was persuaded to open a bank account on the assurance that he would receive a share of the earnings. The account was subsequently used to receive money linked to cyber fraud, with the amount reaching ₹5 crore. The bank blocked the account after a complaint was received through the cybercrime portal, following which the young man approached the police.
Investigators have also reported cases where bank accounts were opened without the knowledge of the individuals whose identities were used. Fraudsters have allegedly used the pretext of government schemes, subsidies and surveys to collect Aadhaar details and biometric information from people in rural areas and subsequently open accounts.
A case reported from Madhubani in Bihar involved mule accounts allegedly opened under the guise of helping people obtain PAN cards. The accused reportedly used their own mobile numbers during the KYC process and subsequently obtained ATM cards linked to the accounts, which were used to receive proceeds of cyber fraud.
Fraudulent funds are frequently transferred through multiple accounts in rapid succession. Money deposited by a victim into an account provided by a fraudster may move through several layers before reaching a central account. Investigators must trace this money trail and freeze the accounts before the funds are withdrawn or transferred further.
The programme also highlighted a case in which two men purchased jewellery worth ₹40 lakh from a jeweller after paying ₹2 lakh in cash and promising to transfer the remaining ₹38 lakh through RTGS. The money was credited to the jeweller’s account and the transaction was confirmed by the bank. After the men took the jewellery, however, police informed the jeweller that the account had been frozen because the money transferred to him was linked to cyber fraud.
Authorities are increasingly turning to technology to detect suspicious transactions and mule accounts.
The Department of Telecommunications has introduced the Financial Fraud Risk Indicator (FRI), which assesses the risk associated with mobile numbers reported in connection with financial fraud. Such numbers can be categorised as having medium, high or very high risk. The information can be shared with banks, payment platforms and financial institutions, enabling them to generate alerts when flagged numbers are used for financial transactions.
The RBI Innovation Hub has also developed MuleHunter, an AI-based tool designed to help banks and financial institutions identify suspicious accounts. The system analyses banking data for patterns such as sudden spikes in transaction volumes, repeated transfers to multiple accounts, unusual activity in previously inactive accounts and suspicious login locations or IP addresses.
Investigating agencies are also examining shortcomings in the account-opening and KYC processes. Large networks of mule accounts can sometimes be traced to particular bank branches and intermediaries, raising questions about compliance with prescribed verification procedures.
The transcript notes that strict KYC, face-to-face verification and video KYC can help prevent fraudulent accounts from being opened.
Authorities have advised customers to regularly monitor their bank accounts and immediately report unexplained transactions. Individuals have also been cautioned against sharing Aadhaar details, biometric information, cheque books, ATM or debit cards, SIM cards and banking credentials with unknown persons.
Any suspicious cybercrime-related activity can be reported through the 1930 cybercrime helpline or the National Cyber Crime Reporting Portal.
With mule accounts playing a critical role in the movement of fraudulent funds, stronger KYC procedures, financial intelligence and technology-based monitoring are being used to disrupt cybercrime networks and prevent illicit money from being moved through the banking system.




