← Industry Insights

How to Detect a Mule Account: A Detection Playbook for Indian Banks and Fintechs

Sep 2026 · 12 min read
SHAREinXf
A network diagram illustrating mule-account detection

How to detect a mule account is a rails question in India before it is a typology question. The detection logic sold into Indian institutions assumes a payment system that clears in a day and aggregates overnight, leaving an analyst a working window before the money moves on. India's rails supply no such window. A UPI payment settles instantly and cannot be recalled once initiated. NEFT has run on a 24x7x365 basis since December 2019, and RTGS round the clock since 14 December 2020.

An account that takes in stolen funds at 02:40 on a Sunday and empties itself four minutes later arrives in the Monday queue as history. Working under that constraint relocates the scoring itself. It also changes the unit that scoring aggregates on, and forces an advance decision about what the institution does while a payment is still in flight.

What a mule account is, and the five shapes it takes

A mule account sits inside the regulated system and exists to receive and forward the proceeds of someone else's crime. That definition settles very little. Provenance decides whether an institution has any chance of catching one, because it determines which control is positioned to see it.

Five provenance types of mule accounts — Recruited, Synthetic Identity, Duplicate Identity, Compromised Account, and Dormant Reactivation


Five shapes account for nearly everything a detection team meets.

  • Recruited. A real person opens a genuine account, then hands over the credentials or runs it on instruction. Some answer an advertisement offering payment; others believe they are processing receipts for an employer. Everything presented at onboarding is authentic, so onboarding controls pass them.
  • Synthetic identity. An application built from genuine and fabricated attributes, engineered to survive verification rather than to describe a person. No single field gives it away. The tell lies in the combination, and in attributes that recur across unrelated applications.
  • Duplicate identity. One individual behind several accounts. Artefacts expose this more reliably than data does: one photograph submitted against two different documents, one document submitted under two different photographs, or a device fingerprint recurring across files that share no other attribute.
  • Compromised legitimate account. A genuine customer's account taken over through credential theft or social engineering. The onboarding history is clean because it was clean at the time, and nothing at account opening will ever surface this one.
  • Dormant reactivation. An account untouched for months or years resumes activity at high velocity, often after a device change and a new contact number registered days earlier.

Two of the five are invisible to onboarding controls by construction, which settles the architecture question before a team reaches it. Mule detection cannot live at the front door.

Why mule detection is a lifecycle problem

Four layers of evidence are available to a money mule detection programme, and every one is weak on its own. Account-creation signals catch fabricated and duplicated identities, then miss everything else. Behavioural signals are good at takeover and reactivation, at the cost of noise on any customer who changes phone or city. Transaction patterns describe the movement, though only once value has landed. The fourth, network position, discriminates best and costs the most to compute. Scored together, the four are decisive. Taken separately, each produces an alert queue nobody can clear.

Fixed thresholds fail structurally, and tuning does not repair that. An account engineered to sit beneath a threshold stays beneath it indefinitely, and an operator who does not know the number will establish it by experiment inside a few transactions. Indian law recognises the pattern in the cash context. Rule 3(1)(B) of the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 requires a reporting entity to maintain records of a series of cash transactions integrally connected to each other, each individually valued below ten lakh rupees, occurring within a month and aggregating over that month to more than ten lakh rupees. Rule 8(1) then requires those transactions to be furnished to the Director, FIU-IND by the 15th day of the succeeding month. The drafting anticipates structuring, which is more than can be said for a great deal of production monitoring logic.

A second failure is narrower and does more damage. A rule evaluating one account in isolation cannot see a ring at all. Forty accounts taking modest credits from unrelated payers and pushing them on to two shared downstream beneficiaries look unremarkable one at a time. In aggregate the structure is obvious.

How to detect a mule account on India's payment rails

What instant, irrevocable settlement does to the intervention window

NPCI describes UPI payments as instant and available 24/7 regardless of a bank's working hours. Once initiated, such a payment cannot be stopped. IMPS, which NPCI describes as an instant 24x7 interbank electronic fund transfer service, runs on the same round-the-clock basis. The interval between a suspicious credit and its exit is therefore measured in seconds rather than in review cycles.

A stack that raises an alert for next-day analyst review is producing a post-mortem. Recovery then runs through a dispute or a law-enforcement process instead of a recall, and by the time either begins the funds have cleared two or three further hops.

For the highest-risk segment at least, scoring has to sit inside the authorisation path. The harder half is deciding in advance what a real-time high score does. Step-up authentication is one answer. So is a hold on the outward leg for a defined interval, a cap, or an outright decline. Having no answer means the institution has built a reporting capability and called it detection.

Round-the-clock settlement breaks the daily counter

NEFT settles round the clock throughout the year in half-hourly batches. RTGS has run on a 24x7x365 basis since 00:30 hours on 14 December 2020. The overnight boundary that daily-aggregation rules were keyed to has stopped existing as an operational fact, though it survives inside plenty of monitoring configurations written before 2019.

A velocity rule that resets at a business-day cut-off carries a seam, and one observation is enough for an operator to find it. Splitting a sweep across the boundary leaves each side looking ordinary. Windows belong on a rolling basis, reaching well past a single day: rolling 1-hour, 24-hour and 7-day counts computed together separate a genuine burst from a merely busy customer far more reliably than a daily counter.

The identifier problem

Under NPCI's UPI Procedural Guidelines a virtual payment address takes the form username@psp. The payment service provider issues it and resolves it at its own local mapper against the underlying account number and IFSC. The address is an overlay, and the overlay is where money actually moves.

A single underlying account can be reachable through several addresses issued by several providers, none visible to the others. Monitoring keyed only to the account number under-counts velocity, since an institution sees only what arrived through addresses it can resolve. The damage to the graph is worse. One node appears as three unrelated nodes, and a cluster that should have been obvious never forms.

Aggregation belongs on a resolved entity instead, assembled from the account, every payment address mapped to it, the registered mobile number, device fingerprints observed on it and the identity artefacts captured at onboarding. It is dull infrastructure work, and every signal downstream inherits its accuracy.

A rail-aware pattern set

Five patterns are worth computing explicitly. Each is specific to how value moves on these rails.

  • Fan-in from unrelated payers. Small credits arrive in quantity from payers with no prior relationship to the account holder and none to each other, all inside a short window. The absence of relationship carries the signal; the amounts are beside the point.
  • Near-complete sweep-out. A credited balance leaves almost entirely within 24 to 72 hours, usually through transfers sized below whatever the account's own history has made unremarkable. The feature worth computing is the ratio of outflow to preceding inflow, and the elapsed time between them.
  • Structuring beneath two separate ceilings. Operators keep each transfer below the ceiling their rail and their bank impose, and below the cash-transaction reporting threshold whenever the exit is cash. Precision matters on the second. Rule 3(1)(A) of the PML (Maintenance of Records) Rules, 2005 covers cash transactions of more than ten lakh rupees, and Rule 8(1) carries them to FIU-IND monthly, which makes ten lakh a cash-reporting threshold under the PML Rules. It is not a UPI or IMPS limit, and material treating it as one is describing a control that does not exist.
  • P2P leg followed immediately by a cash-out or a merchant leg. A person-to-person credit that turns into cash at an ATM within minutes, or moves into a merchant category just as fast, is a layering step with a purpose. The transition between the legs tells a detection team more than either leg alone.
  • Dormancy followed by a burst. Months of inactivity, then a device or contact change, then movement at high velocity. Establishing the dormancy requires a lookback long enough to contain it, which rules out a 90-day monitoring window.

The behavioural and device signals that identify a money mule account

Session and device telemetry catches the two account types onboarding never will. The useful signals are concrete: a login after extended dormancy, access from a device never seen on the account, or one device authenticating into several unrelated customers. Emulator use and VPN or proxy access belong on the list, as does a handset carrying several banking applications alongside the institution's own. So do sessions that recur without transacting, logins from locations too far apart for the interval between them, and failed authentication attempts spiking just before a successful one.

Onboarding artefacts supply the other half, and their evidential value survives long after the account opens. The photograph and document mismatches described earlier indicate an identity being reused rather than presented, and device fingerprints or contact details recurring across applications that share nothing else point the same way. Where address or employer values cluster across applications filed within days of one another, a second look is warranted even where each reads clean.

The strongest indicator is almost never a single signal. It is co-occurrence across layers, such as a reused onboarding artefact followed weeks later by a behavioural departure on the same resolved entity. Either alone is noise; the pair is a case.

Network analysis: finding the ring

A cluster is only as good as the keys it joins on. Shared device fingerprints produce useful mule clusters, and so do shared beneficiary accounts, contact details and addresses. Converging downstream destinations do the same, as do cyclical flows returning value to its origin through intermediaries. Every join is a graph edge. The question stops being whether an account looks suspicious and becomes whether it sits inside a subgraph that does.

Consider a constructed illustration. Eleven accounts opened across four branches over six weeks share no names and no addresses. Three were opened from one device, and two others carry a common contact number. Each receives credits from between nine and thirty unrelated payers, and within seventy-two hours each forwards more than ninety per cent of its balance. The outward transfers converge on two accounts, which move value to a third that cashes out. Every one of the eleven passes a per-account threshold test. The subgraph is unambiguous, and the two convergence points are where intervention repays its cost.

Computing it depends on capabilities an institution either has or lacks. Entity resolution has to replace the account number as the unit of analysis, and the transaction graph has to persist rather than being reassembled by a warehouse query on demand, with a lookback long enough to span a dormancy. Institutions increasingly run these signals on one platform so that onboarding, behavioural and transaction evidence resolves to a single entity, which is the practical argument for treating fraud prevention across onboarding and transactions as one problem rather than two.

Two regulatory developments that change the signal set

Both matter less for any new obligation than for what they change about the evidence available.

The Financial Fraud Risk Indicator is a metric developed by the Department of Telecommunications and rolled out on 22 May 2025 by its Digital Intelligence Unit. It classifies a mobile number as carrying Medium, High or Very High risk of financial fraud, drawing on reporting to I4C's National Cybercrime Reporting Portal, on DoT's Chakshu platform, and on intelligence shared by banks and financial institutions. RBI's advisory of 30 June 2025 directs all Scheduled Commercial Banks, Small Finance Banks, Payments Banks and Co-operative Banks to integrate the indicator and to respond in real time, which the Department describes as declining suspicious transactions, issuing alerts or warnings to customers, and delaying flagged transactions. The metric belongs to DoT; the integration advisory is RBI's. For a detection stack, the point is that an externally maintained risk classification now attaches to the registered mobile number, one of the few identifiers that survives across institutions.

The second development is the memorandum of understanding signed on 12 May 2026 between the Indian Cyber Crime Coordination Centre and the Reserve Bank Innovation Hub. It covers fraud-risk intelligence sharing, analytical support and operational coordination, and under it I4C shares mule-account intelligence and suspect identifiers from its Suspect Registry. Intelligence about mule networks is moving out of institution-local files and into shared national infrastructure.

Where suspicion is confirmed, the obligation is fixed and worth stating once. Rule 8(2) of the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 requires the Principal Officer to furnish information on a suspicious transaction to the Director, FIU-IND promptly and not later than seven working days on being satisfied that the transaction is suspicious. Under Rule 2(1)(g) a suspicious transaction includes one made in circumstances of unusual or unjustified complexity, or one appearing to lack economic rationale or bona fide purpose. What a detection system owes that process is reconstructability after the fact, which is what a single regulator-ready audit trail across onboarding, monitoring and case management produces. None of this is legal advice, and no configuration should be represented internally as satisfying a regulator.

The cost of getting the threshold wrong

Published discussion of mule account detection argues almost uniformly for catching more. The other side of the trade goes largely unaddressed, and that is the side practitioners operate under.

Tight tuning freezes legitimate accounts. In India that cost lands immediately and unevenly. A salaried customer locked out of a UPI handle on a Friday evening has no alternative rail until Monday, the complaint reaches a regulator's grievance channel quickly, and reputational damage does not scale down with the size of the error. A model tuned loosely fails in the opposite direction; the ring goes unnoticed, and the mule surfaces once the money has left.

The resolution lies in graduated response rather than a better threshold, tied to score bands and the confidence behind each one. Step-up authentication on the next session, or a temporary cap on outward transfers, is proportionate to a moderate score. Where a high score arrives with corroborating network evidence, holding the outward leg and putting an analyst on it inside a defined window is defensible. A full freeze belongs to the highest band alone, carrying a documented review path and a service-level commitment, since the cost of an error there falls on a customer who did nothing.

Alert volume is the binding constraint on all of it. A programme generating more alerts than its analysts can clear in a day will miss mules, because the queue ages past the point where clearing it helps. Consolidating signals against a resolved entity is what makes the arithmetic work: KYC Hub records a 62% reduction in alert volume where screening, monitoring and case management run against one shared data model instead of separate systems. Precision at the alert level, measured honestly and reviewed monthly, is the more useful operating metric, and catch rate the more flattering one.

Where the detection advantage is moving

As shared intelligence accumulates, the advantage shifts away from whichever institution holds the most data. What separates detection programmes will be the speed at which a suspect identifier arriving from outside resolves into an entity the institution already knows, and the depth of history that entity carries when the identifier lands. That is an entity-resolution problem, and it is solvable before the next circular arrives.

Most detection stacks bury good analysts under false positives. KYC Hub's AML screening and monitoring brings that down with sharper matching and continuous monitoring, so review time lands on cases like the eleven-account cluster above, not noise. See a demo.

[ FREQUENTLY ASKED QUESTIONS ]

Any questions? We got you.

How do banks detect mule accounts?

Banks combine four layers of evidence instead of relying on any single rule. Account-opening signals form the first, and behavioural drift in how the account is accessed the second. Transaction patterns such as rapid in-and-out movement or fan-in from unrelated payers follow, then the account's position in a network of shared devices, beneficiaries and contact details. Any single layer produces false-positive volumes you cannot work through. Scored together against a resolved entity rather than an account number, they yield a reviewable queue and a case file an analyst can act on.

How do you detect money laundering, and where does mule detection differ?

Anti-money-laundering transaction monitoring looks for the shape of laundering across a customer's activity over time and reports whatever meets the suspicion standard. Mule detection is both narrower and earlier. It targets an account being used as a conduit, often within hours of the first illicit credit, and it leans on fraud-side evidence that classical AML scenarios never read: device telemetry, session behaviour, onboarding artefacts, network position. The two converge at the reporting stage, since a confirmed mule normally produces a suspicious transaction report.

What is a suspected mule account?

It is a designation an institution applies when signals cross an internal threshold while the evidence falls short of a confirmed finding. What it triggers is a response tier rather than a verdict: additional authentication on the next session, a hold or a cap on outward transfers, closer scrutiny of incoming credits, and a case file assigned for review. The designation stays internal, time-bound and reversible. If review clears the account, the restrictions lift; if it does not, the file goes to the Principal Officer for a reporting decision.

Can machine learning detect mule accounts?

Yes, and it is strongest precisely where static rules are weakest, in graph structure and event sequence. A model evaluates a subgraph or a transaction sequence as a whole and surfaces combinations no analyst would have written as a rule. The algorithm is almost never the constraint. Without resolved entities the graph stays fragmented, and where confirmed outcomes are not fed back as labels, the model reproduces the existing alert queue instead of improving on it.

How is mule account detection different in India?

The rails change the problem. UPI and IMPS settle instantly, and a UPI payment cannot be recalled once initiated, which leaves you seconds rather than a review cycle and pushes scoring into the payment path for high-risk segments. Because NEFT and RTGS run round the clock, any aggregation window keyed to a business-day boundary leaves a seam an operator can split a sweep across. A UPI address is an overlay that a payment service provider resolves against an underlying account, so velocity and network analysis computed on account numbers alone understate both.

[ KYC HUB ]

Stop fraud before it reaches your customers

Detect and prevent fraud across onboarding and transactions with device, behaviour and identity signals.

Explore the fraud preventionBook a demo