
Criminals don’t keep stolen money in their own accounts. They move it through yours — or someone exactly like you. Here’s how the mule network actually works.
Category: Cyber crime Investigation | Reading time: ~10 minutes
When a scam succeeds — a UPI fraud, a fake investment scheme, a phishing attack — the stolen money doesn’t sit quietly in some hacker’s account waiting to be found. It moves. Fast. And it moves through a layer of banking infrastructure that law enforcement calls the “mule network.”
Understanding mule accounts is essential to understanding why cybercrime is so hard to prosecute, why victims rarely get their money back, and why ordinary people with clean records sometimes find themselves at a police station answering questions about transactions they didn’t make.
What Is a Mule Account?
A mule account is a bank account — completely real, KYC-verified, linked to a legitimate person — that is used to receive, hold, and forward stolen funds on behalf of cybercriminals. The account holder is the “mule.” They may be:
- Recruited knowingly — fully aware they’re helping launder money, paid for access
- Deceived into participating — tricked through fake job offers or romance scams
- Identity theft victims — whose credentials were stolen and used without their knowledge
- Dormant account holders — accounts abandoned and taken over through credential stuffing
The criminal never touches a bank. The mule does all the dirty work — often without fully understanding it. By the time investigators trace the money, it has already jumped through three, five, sometimes ten accounts across different banks and states.
How the Money Moves: The Layering Chain
Step 1 — Placement: stolen money enters the system
Fraud proceeds land in the first mule account — often a savings account opened with a fake or borrowed identity. This is the most exposed point. If the 1930 helpline is called fast, this transfer can sometimes be frozen.
Step 2 — Layering: the money fragments and scatters
Within minutes to hours, the first mule splits the amount and forwards it to 5–15 other accounts — across banks, states, even countries. Each hop dilutes the paper trail. Investigators must now chase multiple threads simultaneously.
Step 3 — Integration: cash is extracted or converted
At the final layer, money is either withdrawn as cash at ATMs (often across multiple cities in the same night), converted to cryptocurrency, transferred abroad via hawala-adjacent channels, or used to buy goods that are immediately resold. At this point, recovery becomes nearly impossible.
“By the time a victim calls the bank, the money has already been split six ways and is halfway to a crypto exchange.”
Who Becomes a Mule — And How
This is where the story gets uncomfortable. Mules aren’t always criminals. In India, a significant portion of mule accounts belong to people who were tricked. Common recruitment methods include:
Fake job offers
“Work from home” or “payment processing agent” roles that ask you to receive money and forward it, keeping a percentage commission. Targets are often students or job seekers desperate for income.
Romance scams
A fabricated romantic relationship leads to a request: “can you receive this money for me and forward it? I can’t access my account right now.” The victim becomes a mule without realizing it.
KYC credential theft
Criminals use stolen Aadhaar, PAN, and bank details — obtained through phishing or data breaches — to open accounts in victims’ names without their knowledge. These “ghost mule” accounts are the hardest to detect because the real person has no idea the account exists.
Account rental
Some people knowingly rent their accounts for cash — handing over net banking credentials to criminal operators for a daily fee. This is a criminal offense, even if the person didn’t know exactly what fraud was being committed.
⚠️ Legal Warning: Being a Mule — Knowing or Unknowing — Can Land You in Prison
Under the IT Act, IPC, and Prevention of Money Laundering Act (PMLA), receiving and forwarding proceeds of crime is a criminal offence regardless of whether you knew the money was stolen. Courts have held that willful blindness is not a defence. Multiple innocent people have been arrested and had their accounts frozen for months because they “just forwarded” money at someone’s request.
The Scale of the Problem in India
- 66% of cybercrime funds in India pass through mule accounts before leaving the banking system
- 4–10 average number of accounts a single fraud transfer passes through before cash-out
- ₹7,061 crore in financial losses reported from cybercrime in India in 2023 (MHA data)
- Less than 5% estimated recovery rate for funds that have entered the mule network
Why Banks Struggle to Catch Mules in Real Time
Banks have transaction monitoring systems, but mule networks are engineered to evade them. Criminals deliberately keep individual transfers below suspicious transaction thresholds. They use accounts that have had months of normal activity before activation. They rotate mule accounts constantly — a single fraud operation may use hundreds of accounts simultaneously across dozens of banks.
The Reserve Bank of India has pushed banks to improve ML-based fraud detection, and NPCI has introduced velocity checks on UPI. But the attackers adapt faster than the systems can be updated. A mule account activated for 48 hours and then abandoned may never trigger any flag at all.
What Investigators Actually Do — And Why It’s Slow
When a cybercrime complaint comes in with a transaction ID, investigators must first freeze the destination account. That requires contacting the receiving bank’s nodal officer — a process that can take hours to days depending on the bank and the time of day. By then, the money may already be three hops away.
Each subsequent account requires a separate court order or bank communication. Each bank operates in a different state jurisdiction. The mule holder may be in one state, the criminal operator in another, and the server they used in a third. No single authority owns the full picture.
Red Flags: How to Know If You’re Being Targeted for Mule Recruitment
Watch out for these warning signs:
- ⚠️ Someone you met online asks you to receive money in your account and “forward it” — for any reason
- ⚠️ A “job” that pays you a commission just to process transactions through your bank account
- ⚠️ Requests to share your net banking login, debit card, or UPI PIN with anyone — ever
- ⚠️ Unsolicited large deposits in your account from people you don’t know
- ⚠️ Pressure to withdraw cash immediately after receiving a transfer
If any of these happen: Do not touch the money. Contact your bank’s fraud helpline immediately and call 1930. Document everything — screenshots, chat logs, call records.
What Needs to Change Systemically
Tackling the mule network requires action on three fronts at once.
Banks need real-time cross-bank communication infrastructure — currently, banks can’t see what’s happening in other institutions’ systems fast enough to stop layering in progress. Law enforcement needs legal authority to freeze across multiple accounts simultaneously with a single order, rather than chasing one bank at a time. And KYC processes need to be hardened against identity theft — biometric verification at account opening is a start, but not sufficient when the source documents themselves are compromised.
The I4C (Indian Cybercrime Coordination Centre) has begun building a centralized mule account database that banks can query in real time. If implemented at scale, this could significantly reduce how long a single mule account stays active before being flagged. But the database is only as good as the reporting speed of the banks feeding it.
The Money Is Gone. The Mule Is Left Holding the Consequences.
Cybercriminals architect systems where they are invisible. Mules — willing or not — take the legal and financial risk. Understanding how this works is the first step toward dismantling it.
Share this. The more people recognize mule recruitment tactics, the narrower the criminal network becomes. Your awareness is part of the defence.
National Cybercrime Helpline: 1930 | Report online: cybercrime.gov.in