Mule Account Detection with AI: How to Identify Synthetic Identities in Real Time
Mule accounts are no longer just the favor a friend does to move money of dubious origin. In 2026, many of these accounts Mule accounts are no longer just the favor a friend does to move money of dubious origin. In 2026, many of these accounts are opened using identities that belong to no one: combinations of real and fabricated data designed to pass Know Your Customer (KYC) checks and mature for months before being activated.
Artificial intelligence has changed both sides of this equation. Fraudsters use it to generate more convincing documentation and identities. Financial institutions use it to detect patterns no human analyst could catch in time.
This article covers what synthetic mule accounts are, what verified data says about their real scale, and which machine learning techniques can identify them before the fraud materializes.
The lifecycle of a synthetic mule account
A synthetic identity is not a stolen identity. It’s a fabricated one: built by combining one real data point, such as a valid ID number, with invented information, until it creates a profile capable of passing basic onboarding checks.
The difference from a traditional mule account matters. In a classic mule case, there’s a real person, deceived or complicit, behind the account. In a synthetic mule account, there’s no one to protect and no one to report the fraud, which makes it far harder to catch with standard alert systems.
Fraud doesn’t happen all at once. It unfolds in stages, and each one leaves distinct signals that AI-driven mule account detection can capture before the account is used to move illicit funds.
| Stage | What happens | Detectable pre-fraud signal |
| Identity creation | Real and invented data are combined to build a profile | Inconsistencies across data sources, AI-generated or altered documents |
| Account opening (onboarding) | The profile passes basic KYC checks | Irregular typing speed, a device already linked to other accounts |
| Maturation (6 to 18 months) | The account builds history and operational trust | Transaction patterns that are unusually regular or repetitive |
| Exploitation | Credit is requested or illicit funds are moved | Spikes in activity, sudden behavioral changes |
| Abandonment | The account is discarded once it has served its purpose | Sudden inactivity after intense activity |
That maturation window, which can stretch beyond a year, is why controls that only act at account opening are consistently too late.
Synthetic identity fraud and mule accounts, in numbers
Available data is partial, because a synthetic identity has no real victim to report it. Even so, the figures that do exist give a sense of the problem’s scale.
In March 2025, a secure payments official at the Federal Reserve Bank of Boston explained in an official interview that the estimated losses from synthetic identity fraud in the US have kept climbing every time they’ve been remeasured: from around $8 billion in 2020 to more than $30 billion in the most recent figures.
| Metric | Figure | Source |
| Synthetic identity fraud losses in the US, latest estimate | Over $30 billion | Federal Reserve Bank of Boston, March 2025 |
| Financial institutions reporting mule account activity as increasing or persistent | ≈47% of respondents | Federal Reserve Financial Services annual risk survey, April 2025 |
| Year-over-year increase in concern about mule accounts | +12% (2024 vs. 2023) | Federal Reserve Financial Services, April 2025 |
| Fraud reports handled by the FTC (2024) | 6.5 million | FTC Consumer Sentinel Network, 2025 |
| Total reported fraud losses in the US (2024) | $12.5 billion | FTC Consumer Sentinel Network, 2025 |
| Mule accounts identified in Operation EMMA 9 | 10,759, across 26 countries | Europol, 2023 |
The most striking figure isn’t any single number, it’s the trajectory. Every time the Federal Reserve has remeasured synthetic identity fraud, the estimate has gone up, from $8 billion to over $30 billion in five years.
That suggests earlier estimates were probably undercounts too, not because fraud spikes year over year, but because much of it stays undetected long after it happens.
What the data shows, and what it hides
The usual headline is “billions are laundered through mule accounts.” What that headline leaves out is how much of that money is actually recovered.
The ninth European Money Mule Action (EMMA 9), coordinated by Europol, Eurojust, and Interpol in 2023 with the cooperation of more than 2,800 banks, shows that gap in concrete numbers.
| EMMA 9 indicator (Europol, 2023) | Figure |
| Mule accounts identified | 10,759 |
| Recruiters identified | 474 |
| Arrests | 1,013 (≈9.4% of identified accounts) |
| Losses already materialized and revealed | Over €100 million |
| Losses prevented through intervention | Over €32 million (≈24% of total exposure) |
Identifying a mule account isn’t the same as stopping it in time. Only about one in ten identified cases ended in an arrest, and of every four euros of exposed fraud, three had already been lost before the operation could intervene.
Europol described the action as a coordinated effort against networks profiting from multiple types of criminality, from business email compromise to the fraudulent use of artificial intelligence to generate fake identities and bypass KYC controls when opening accounts online, a pattern the operation itself flagged as an emerging trend.
“As a coordinated action conducted across Europe and the globe, EMMA aims to fight money mule networks benefiting from different types of criminality, such as cyber-enabled fraud against financial institutions and their customers.”
— Europol, official statement on Operation EMMA 9
From static rules to continuous verification: how AI acts
For years, fraud detection relied on fixed rules applied at a single moment: onboarding. That model is no longer enough.
As Facephi’s analysis of industrialized financial fraud explains, fraud today behaves like an industry, with fraud-as-a-service kits, specialized criminal roles, and AI-driven automation that make campaigns faster, more credible, and harder to detect.
Machine learning applied to mule account detection combines three layers of signals:
- Pre-fraud signal analysis at registration: irregular patterns in the source of funds, networks of devices shared across multiple accounts, and connections to suspicious activity detected through honeypots.
- Behavioral biometrics during the session: typing speed, navigation patterns, and consistency between initial biometrics and later interactions, which helps flag anomalous access even when credentials are correct.
- Dynamic risk scoring: the system continuously re-evaluates the account throughout its entire lifecycle, adjusting friction based on the risk detected at each moment.
This combination is what makes it possible to distinguish a victim account, used without its holder’s knowledge, from a complicit or fully synthetic one, a classification static KYC controls can’t make on their own.
The financial sector’s pain points around synthetic fraud
| Pain point | Why it matters | What AI delivers |
| KYC controls only act at account opening | A synthetic identity can look legitimate for over a year | Dynamic risk models that re-evaluate the account throughout its lifecycle |
| Fraud no longer concentrates at onboarding | Attackers also operate within the session and at the transaction | Continuous verification based on biometrics, behavior, and context |
| Fraud teams analyze accounts in isolation | Mule networks share devices, IPs, or behavioral patterns | Device network analysis and shared intelligence consortiums between banks |
| False positives overwhelm analysts | Every mis-scored alert costs time and budget | Explainable risk scoring that prioritizes the cases most likely to be real fraud |
According to the FTC Consumer Sentinel Network, reported fraud in the US exceeded $12.5 billion in 2024, an increase of more than $2 billion over the previous year. But that figure only captures fraud someone actually reported.
Synthetic identity fraud, precisely because it has no victim to report it, is systematically left out of that count. The real figure is likely higher than any reporting statistic can reflect.
Collaboration between institutions strengthens detection further. Initiatives like bank consortiums that share fraud signals in real time make it possible to spot patterns no single bank would see working in isolation, because the same synthetic identity network often operates against several institutions at once.
Frequently asked questions about AI mule account detection
It’s a bank account used as an intermediary to move funds of illicit origin. It can belong to a deceived person, an accomplice who lends their account for a fee, or a synthetic identity created specifically for that purpose.
A traditional mule account belongs to a real person, even if deceived or complicit. A synthetic mule account is opened with a fabricated identity combining real and invented data, so there’s no real person behind it who could report the fraud.
Because classic KYC controls verify identity only once, at account opening. A well-built synthetic identity can pass that initial check and mature for months, sometimes over a year, before being activated for fraud.
By combining pre-fraud signals at registration, behavioral biometrics during the session, and dynamic risk scoring across the account’s entire lifecycle, instead of evaluating identity just once.
They allow fraud signals to be shared between institutions in real time, helping identify networks that operate against several banks simultaneously and that would otherwise stay invisible if each institution analyzed its data in isolation.
In Operation EMMA 9, coordinated by Europol in 2023, 10,759 mule accounts and 474 recruiters were identified across 26 countries, though only 9.4% of identified cases resulted in an arrest, illustrating the gap between detecting fraud and neutralizing it in time.