What Is a Mule Account? How Banks Detect Them and Why They Are Hard to Spot
The rise of mule accounts in the financial ecosystem
A mule account is a real bank account opened with legitimate details or a stolen identity, then lent, sold, or set up specifically to move money from criminal activity without triggering the checks banks rely on to catch it.
Europol just proved that at scale. In June 2026, the agency dismantled a cryptocurrency-laundering service that had moved more than €336 million over three years for ransomware gangs. The piece holding the whole operation together wasn’t the criminals who designed it, but more than 6,000 mule accounts opened by intermediaries recruited specifically for that purpose.
The problem isn’t limited to one case, either. According to the 2026 Risk Officer Report from Federal Reserve Financial Services, more than half of the U.S. financial institutions surveyed (53%) had experienced mule-account-related fraud, and 9% said their exposure was growing. Close to two-thirds of those cases involved legitimate customers who had been deceived.
This article covers the types of mule accounts that exist, the signals banks use to detect them today, and why no single institution, on its own, sees the full pattern.
What is a mule account?
A mule account works precisely because, at first glance, it looks like any other account. It belongs to a real person, its history in the first weeks is no different from any other legitimate customer’s, and it clears account-opening checks without raising a single alarm. That appearance of normality is what makes it so hard to stop.
Behind that account sit three distinct situations, and they shouldn’t be blurred together.
- The account holder may have no idea their account is being used to move illicit funds.
- They may know exactly what’s happening and be collecting a fee for lending it.
- Or there may be no real person behind it at all: the account was opened with a fabricated identity.
Recruitment for the first two profiles usually happens through social media, fake job offers, or well-built phishing campaigns. Many victims fall for it convinced they’re taking part in something legitimate, which delays detection even further: not even the account holder has a reason to suspect their own account.
Fraud Intelligence Report
Discover how digital fraud is evolving and protect your customers’ identities
The three types of mule account
That distinction over who knows what, and how much, is also what determines how each profile gets detected.
- Deceived accounts give themselves away through the contrast with a normal prior history.
- Willing accounts, through movements with no economic justification.
- Complicit accounts, because from day one something doesn’t line up between the declared data and the real identity of whoever opened the account.
The table below summarizes the three categories:
| Type | How the person is recruited | What gives it away |
|---|---|---|
| Deceived mule accounts | Phishing, fake job offers, or romance scams that convince the victim they are taking part in a legitimate activity. | The account’s history looks normal until it starts receiving and transferring sums that do not match the holder’s profile. |
| Willing mule accounts | Direct recruitment in exchange for a fee, usually through social media or ads. | Fast, repeated deposits and withdrawals with no visible economic justification in the holder’s profile. |
| Complicit mule accounts | No real person is recruited: the account is opened directly with a synthetic or stolen identity. | Discrepancies between the data declared at opening and verified biometric or documentary signals. |
How banks detect mule accounts
For years, the first line of defense was manual checks and static rules: blocklists, fixed transaction thresholds, and human review of flagged cases. That worked as long as criminals hadn’t learned to dodge it, and today they dodge it with the same ease they use to split a transfer to stay under a reporting threshold.
Detection that actually works combines two distinct moments in the account’s lifecycle, opening and subsequent activity, because neither one, seen in isolation, gives a complete picture.
Signals at account opening
Before an account moves a single euro, there can already be signals worth flagging. Some show up in the registration itself: the same phone number tied to different applications, a recycled document with small variations, or the same mailing address used by several applicants who, on paper, have no connection to each other.
There can also be inconsistencies in the declared source of funds: income that doesn’t match the applicant’s economic activity, an occupation that doesn’t justify the declared income level, or information with no documentary backing at all.
And there are device networks: the same phone, the same network, or the same location behind several account openings that, on paper, shouldn’t have anything to do with each other.
None of these signals, on its own, means an account is fraudulent. What they do is raise the level of review and friction from the start, so the account’s first real activity gets watched more closely.
Signals after account opening
Once an account is open, what gives it away is the contrast between its history and its recent behavior. Money that enters and leaves in very short windows, without the balance ever settling: the account acts as a pass-through, not as the final destination for those funds. A transactional pattern that breaks abruptly with what the account had shown for months, in amount, frequency, or the type of counterparty it deals with.
These behavioral anomalies are exactly the kind of signal picked up by behavioral biometrics systems, which compare how a user interacts with their device today (typing speed, how they hold the phone, navigation rhythm inside the app) against how they interacted before.
Warning signs, and why none is conclusive on its own
Each of these indicators, taken in isolation, generates false positives, and that is precisely what makes a fraud analyst’s job difficult:
- Unusual speed of funds moving in and out.
- An abrupt change in the usual transaction pattern of an account with a stable history.
- Inconsistency between the usual location or device and the one used in a specific operation.
- An account inactive for months that suddenly concentrates activity.
- Structured transactions that, combined, stay under standard reporting thresholds.
None of these indicators proves, on its own, that an account is a mule account: all of them have legitimate explanations. Someone can inherit money, move to a new city, or buy a new phone without any of that meaning fraud.
What reduces false positives is combining several signals, read together with the context of the account’s opening. That is where a real mule account gets told apart from a customer who simply has an unusual week.
Tactics that are making detection harder
Fraud patterns keep changing too. Several trends are eroding the response window traditional systems used to rely on:
- Instant payments. Settlement in seconds leaves analysts without the manual review window that traditional transfer systems used to allow: money can leave the account before any review is completed.
- Simulated behavior. Some fraud schemes deliberately mimic legitimate usage habits to go unnoticed by systems that only compare aggregate averages.
- Social engineering and manipulation. Phishing and recruitment schemes don’t always require taking full control of an account, which makes them harder to tell apart from a genuine operation by the account holder.
- Multichannel attacks. The same fraud scheme spread across mobile banking, web, and transfers can go unnoticed if each channel is analyzed in isolation.
- Patterns designed to look legitimate. Operations structured specifically to avoid triggering standard transaction-monitoring thresholds.
Why one bank rarely sees the whole picture
A mule account network rarely operates within a single institution, and that’s not a coincidence. Money gets split and moved across different banks precisely so that no single one, on its own, sees the full pattern. Each institution only observes the leg of the operation that passes through its own accounts.
A simplified example shows why this matters: fraud proceeds enter Bank A, get transferred within minutes to Bank B, then move out to an account at Bank C before converting to cryptocurrency. Each bank, on its own, sees only a third of the story, an anomalous deposit, or a fast withdrawal, or a transfer to a new account, and none of those three fragments, in isolation, looks suspicious enough to block the operation.
That’s why collaboration between institutions, through data consortiums that share fraud signals without compromising user privacy, has become an increasingly important piece for closing that blind spot.
Facephi’s advanced strategies to stop mule accounts
The point where detection fails is isolation: analyzing account opening on one side and subsequent activity on the other, in systems that don’t talk to each other. That produces the same blind spot described between banks, but inside a single institution.
Our solution correlates both moments (opening and subsequent activity) within a single flow. Each isolated signal (a recycled document, a transactional pattern that breaks with the account’s history, a role that doesn’t fit the scheme) is weighed together with the rest to assign a risk level to the profile, instead of being evaluated separately.
On that basis, every account is automatically classified into one of three operational categories: regular, victim, or mule. This classification describes the role the account plays at the moment of analysis; it is different from the three types of mule account (deceived, willing, complicit) described above, which explain how the fraud originated, not how the system labels it.
To close the blind spot between institutions described in the previous section, the solution also allows fraud signals to be shared securely between institutions, without exposing customer data.
You can learn more about our mule account detection solution and how it fits into your institution’s onboarding and transaction-monitoring flow.
The key: staying ahead of fraud
What sets apart the institutions that manage to stop mule accounts in time isn’t a single tool, but having stopped treating detection as an isolated event.
Continuous monitoring, from the first onboarding form to the last transaction, is what closes the gap left by static rules and manual controls.
If you want to see how we apply this approach, check out our mule account detection solution and how it adapts to your institution’s flow.
A mule account is a bank account used to move funds obtained through fraud or other criminal activity. Some belong to people who were deceived, others to willing accomplices, and others are opened with stolen or synthetic identities.
Deceived mule accounts belong to victims who were manipulated without realizing it; willing accounts belong to people who hand over their account in exchange for a fee; and complicit accounts are created directly with a fake or stolen identity.
By combining signals at the time of account opening with signals from subsequent activity. Both are read together: on their own, neither gives a reliable picture.
Among others: unusual speed of funds movement, abrupt changes in transaction patterns, device or location inconsistencies, dormant accounts that suddenly become active, and structured transactions. None is conclusive in isolation.
A mule account is the instrument: the vehicle that moves the money. Money laundering is the goal: the process of giving illegally obtained funds the appearance of legitimacy. A mule account can be one piece of a laundering scheme