Wiretel



On June 23, Delhi Police arrested a 40-year-old man from Amritsar for allegedly acting as a mule account holder in a cyber fraud case involving former Member of Parliament Naresh Gujral, reported The Indian Express. Days earlier, cyber police in Gujarat arrested members of a gang accused of laundering proceeds from online scams through a network of mule accounts. Similar arrests have been reported across the country as law enforcement agencies intensify crackdown on cybercrime.

 


The scale of the problem is staggering. According to the Indian Cyber Crime Coordination Centre (I4C), more than 2.47 million Layer-1 mule accounts had been flagged as of early 2026.

 
 


So, what exactly are mule accounts, why have they become central to cybercrime, and what are regulators doing to stop them?

 


What is a mule account?

 


A mule account is a bank account used to receive, transfer or launder money obtained through illegal activities. According to the Reserve Bank of India (RBI), such accounts are often opened or operated by individuals who are lured, deceived or coerced into becoming part of a criminal network.

 


The Indian Banks’ Association identifies several common characteristics of mule accounts, including frequent transactions, an unusually high number of counterparties, rapid movement of funds and sudden spikes in account activity. These patterns make it difficult for investigators to trace stolen money and recover it.

 


At the centre of most such schemes is a money mule, sometimes referred to as a ‘smurfer’, a person who transfers illegally obtained money through the banking system on behalf of criminals. In many cases, the account holder may not even know that the funds originate from unlawful activities.

 


Others are recruited through fake job offers, work-from-home schemes, loan arrangements or investment scams, and remain unaware that their accounts are being used to move illicit funds. In some cases, organised syndicates create shell entities or use stolen identities to open accounts specifically for laundering money.

 


How do criminals recruit money mules?

 


According to the RBI, money mules are recruited through a variety of channels, including spam emails, social media platforms, recruitment websites, messaging applications and even newspaper advertisements.

 


The most common route is through social media and messaging platforms such as Telegram, WhatsApp and Facebook. Users are promised easy commissions or quick income in exchange for allowing transactions to pass through their accounts.

 


Fraudsters also advertise fake jobs under titles such as “payment processor”, “financial assistant” or “business coordinator”. Recruits are instructed to receive money and forward it elsewhere, often believing they are performing legitimate work.

 


Another growing trend involves the purchase of complete banking kits that include bank accounts, debit cards, PINs, internet banking credentials and linked SIM cards. Such kits are frequently sourced from students, daily wage workers and financially vulnerable individuals willing to sell account access for a small payment. Fraudsters also exploit stolen Aadhaar, PAN and other KYC documents to create accounts using synthetic or fabricated identities.

 


How does money move through a mule account network?

 


According to media reports, mule account operations typically follow a four-stage process:

 


Account creation: Fraudsters either persuade someone to open an account on their behalf or gain access to an existing account. Financially vulnerable individuals are often targeted.

 


Warm-up phase: Before moving large sums, criminals route small transactions through the account to establish a transaction history and reduce the likelihood of triggering anti-money laundering alerts.

 


Money movement: Once the account appears legitimate, stolen funds begin flowing through it. The money is often transferred rapidly across several accounts, sometimes within minutes.

 


Withdrawal and conversion: Funds are withdrawn as cash, transferred across borders or converted into cryptocurrencies. At this stage, tracing the money becomes significantly more difficult.

 


Victim transfer → first mule account → splitting into smaller amounts → multiple accounts → cash withdrawal/crypto/purchases → recovery becomes difficult

 


Why is recovering stolen money so difficult?

 


Recovering money routed through mule accounts is challenging as cybercriminals move funds much faster than victims can report fraud.

 


According to a PwC India report, fraudsters exploit rapid transaction speeds, multiple account layers and quick conversion into cash or cryptocurrency. By the time a victim realises they have been scammed, the money may already have passed through several accounts.

 


Even after a complaint is filed, banks, payment service providers and law enforcement agencies must coordinate to identify and freeze the accounts involved. The challenge becomes even greater when transactions span multiple banks, states or jurisdictions. As a result, only a small portion of stolen funds is usually recovered before it disappears beyond the reach of investigators.

 


How fraudsters exploit banking systems

 


Banks matter because they are the primary entry and exit points for illicit funds. Every cyber fraud, from phishing scams and fake investment schemes to impersonation frauds, ultimately relies on bank accounts to receive, move and withdraw stolen money.

 


Mule accounts exploit gaps in customer onboarding, KYC verification, transaction monitoring and dormant account surveillance. Criminals use forged or stolen identity documents to open accounts, while networks of mule accounts help disguise suspicious transactions by routing funds through multiple layers before detection.

 


The RBI has repeatedly cautioned that while financial inclusion has expanded rapidly, financial and digital literacy have not always kept pace. This gap leaves many customers vulnerable to scams that trick them into sharing account access, banking credentials or KYC documents, which can then be misused to create mule accounts.

 


What are regulators doing to tackle mule accounts?

 


Indian authorities have stepped up efforts to identify and dismantle mule account networks.

 


The RBI and the Financial Intelligence Unit–India (FIU-IND) have strengthened information-sharing arrangements to improve detection of suspicious transactions. Banks have been directed to tighten KYC controls, strengthen monitoring systems and report suspicious activities more proactively. In April, the RBI proposed additional safeguards, including limits on aggregate credits into accounts where satisfactory business relationships have not yet been established.

 


A recent major development has been the collaboration between the Indian Cyber Crime Coordination Centre (I4C) and the Reserve Bank Innovation Hub (RBIH). The partnership aims to improve fraud-risk intelligence sharing, operational coordination and proactive fraud detection.

 


The RBI has also developed MuleHunter.ai, an artificial intelligence (AI) and machine learning-based system designed to identify suspected mule accounts. According to the Ministry of Finance, the platform is already operational across 26 banks and is being expanded further. It analyses transaction patterns and account behaviour to flag potential mule networks before significant damage occurs.

 


Meanwhile, the Department of Telecommunications (DoT) has also tightened SIM card issuance norms, making Aadhaar authentication mandatory for new connections. The move aims to curb misuse of mobile numbers, which often serve as critical infrastructure in cyber fraud operations.



Source link