Money mule

An account in a third party's name that receives and disperses funds of illicit origin. How it's recruited, why the one recruited by deception and the deliberate one require different controls, and where fraud crosses paths with anti-money-laundering.

What a money mule is

A money mule is a person whose account is used to receive funds of illicit origin and move them again, usually in few steps and in little time. The account may be the person's own and opened for that purpose, their own and handed over in exchange for a payment, or opened in that person's name without their involvement.

The mule's function is to break the trail. The money that comes out of a fraud can't go straight to whoever committed it, so it passes through third-party accounts that have no apparent relationship with each other or with the original event. Each hop adds distance.

From the institution's side, the problem has an uncomfortable shape: the account is real, the holder exists, and in many cases the identity was verified correctly. What fails isn't who opened the account, but what it's being used for.

The one recruited by deception and the deliberate one aren't the same case

The distinction matters because it changes which control applies, and because it changes what the institution can do when it detects it.

  • Mule recruited by deception — the person believes they're accepting a job, helping someone they met online, or receiving a legitimate payment. They usually don't know they're taking part in something illicit until the institution contacts them or the investigation reaches them. The effective control is early detection of the pattern and interruption before the operation consolidates, plus preventive communication to the user.
  • Deliberate mule — the person knows what they're doing and gets paid for it. The identity is genuine and verification at signup approves it rightly. Here the control is about behavior and network: what the account does, who it connects with and what it shares with other accounts in the same group.
  • Account opened with someone else's or a synthetic identity — there's no recruited person, there's a fabricated or stolen identity. It's the only one of the three cases where the signup control is decisive, and it overlaps with synthetic identity and with onboarding fraud.

Confusing the three leads to a frequent wrong conclusion: that more demanding identity verification reduces mules. It reduces the third case. On the first two it has no effect, because the identity isn't what's wrong.

How the recruitment and the movement run, step by step

The sequence repeats with few variants, and each step leaves a different signal.

  1. Recruitment. A remote job offer as a "payment manager" or "financial representative", a contact through messaging, an emotional bond built online, or a direct offer of payment for the use of the account. The pitch always justifies why the money has to pass through a personal account.
  2. Opening or handing over the account. The person opens a new account, enables a product at an institution where they're already a customer, or hands over the credentials and card of an existing account. In that last case there's no signup event to observe.
  3. Receiving the funds. A transfer comes in from a previous fraud: a scam against a third party, a diverted payment, the proceeds of a taken-over account. The amount is usually disproportionate to that account's historical behavior.
  4. Dispersal. The money leaves within hours: cash withdrawal, purchase of digital assets, transfers to other accounts in the same network, sometimes split below the thresholds that trigger a report. The speed between the inflow and the outflow is the most consistent signal of all.
  5. Discard. The account becomes unusable and the network moves on to the next one. The recruited person is left as the holder before the investigation, with their name on the operation's record.

Step 4 is the one the institution can see in real time. Step 1 happens outside any system the institution controls.

Where fraud crosses paths with anti-money-laundering

A mule account belongs to two disciplines at once, and in many organizations to two teams that don't share a screen.

For the fraud team it's the destination of the money from a previous event, and its priority is to cut off the outflow. For the compliance team it's an unusual operation that may require a report, within the anti-money-laundering obligations that apply to the institution as an obliged entity.

Both readings are correct and lead to different actions. Cutting off the outflow quickly protects the victim of the original fraud; documenting and reporting fulfills the regulatory obligation and feeds the investigation. An organization that treats the case only as fraud complies halfway, and one that treats it only as compliance lets the money out while it builds the file.

Who it affects and what it costs

  • Financial services — it's where the case lives. The cost isn't only the amount that isn't recovered: it's the investigation burden, the response to the victim, the report to the authority and the institution's position before its regulator.
  • Wallets and payment platforms — fast signup and immediate sending are exactly the conditions a mule network looks for. The speed that wins users is the same speed that disperses funds.
  • Digital asset platforms — they appear as the exit step in step 4, with the same problem of irreversibility.
  • Merchants with payment or advance programs — when the product allows receiving and transferring, it enters the chain even if it isn't a bank.

There's a cost that gets overlooked: the person recruited by deception is, at the same time, a customer of the institution and an involuntary participant in a crime. How the organization handles that case defines whether it ends up with a warned customer or with a customer who finds out through a summons.

Which controls detect a mule account

Almost all the controls that work here are behavioral, and a good part of them aren't provided by an identity vendor. Naming the full list is what makes it useful.

  • Transaction monitoring — detection of inflows disproportionate to the history, immediate outflows, splitting, and same-day in-and-out patterns. It's the central control, and it belongs to the fraud team or the compliance team, not to the verification vendor.
  • Network and graph analysis — identifies accounts that share recipients, devices, addresses, phones or emails. An isolated mule is hard to qualify; a group of twenty with shared attributes is obvious.
  • Compliance unit rules and suspicious operation reporting — the formal procedure that obliged-entity status imposes, with its deadlines and formats by country.
  • Restrictive lists and checks against official sources — they add context in some cases and don't detect the typical mule, who appears on no list.
  • Device and session signals — the same device operating several accounts, geolocation inconsistent with the declared address, remotely controlled sessions. They usually come from a layer other than identity verification.
  • Biometric deduplication at signup — detects that the same person opens accounts under different identities. It covers the third case, the one with someone else's or a synthetic identity, and not the other two.
  • Identity verification at signup — establishes that whoever opens the account is who they claim to be. Against the deliberate mule it doesn't provide prevention, because the identity is genuine; it provides certainty about whom the account belongs to when the investigation comes.
  • Recruitment detection and communication to the user — in-product notices, alerts about job offers that ask to use a personal account, and collaboration with law enforcement. It's not a system control and in several markets it's the only thing that acts on step 1.
  • Information sharing between institutions — the sector schemes for flagging compromised accounts, where they exist. No institution sees the whole network on its own.

An identity verification vendor doesn't detect mules. It detects identities that don't match whoever presents them, which is one part of the problem and not the largest. A team that buys verification expecting its mule account rate to drop is going to look at the wrong number.

How VU approaches it

What VU contributes is at signup and in the account's signals, not in transaction monitoring.

Verify establishes that the person opening the account is the holder of the document they present, and biometric deduplication detects that the same person is trying to open several accounts with different identities. That acts on accounts opened with someone else's or a fabricated identity.

Protect against fraud provides device and session signals, which is the material the fraud team uses to build the network pattern.

On the deliberate mule, with their own verified identity, VU's contribution is limited and it's worth saying so: the account was opened correctly, and the case is resolved in the transactional layer.

Frequently asked questions

It's a person whose account is used to receive funds of illicit origin and move them again quickly, with the aim of breaking the trail between the crime and whoever committed it. The account may be their own and opened for that purpose, their own and handed over in exchange for a payment, or opened in their name without the person's involvement. From the institution's side, the distinctive trait is that the identity is usually genuine: what's irregular is the use of the account, not who opened it.

By what they know and by what the institution can do about it. The one recruited by deception believes they're accepting a job or helping someone, and usually responds to a preventive communication before the operation advances. The deliberate one gets paid for the use of the account and isn't stopped by information: they're detected by behavior and by network analysis, observing what the account does and which attributes it shares with others in the same group.

Only in one case out of three. It reduces accounts opened with a stolen or fabricated identity, which is where verification and biometric deduplication act. It doesn't reduce the accounts of real people who hand over their account or open it knowingly, because in those cases the identity is genuine and verification approves correctly. That segment is detected with transaction monitoring and network analysis.

It's the point where the two disciplines touch. For the fraud team, the account is the destination of the money from a previous event and the priority is to cut off the outflow. For compliance, it's an unusual operation that may require a formal report to the authority, within the obligations the institution has as an obliged entity. Both readings are valid and demand different actions, which are best coordinated before the case shows up.

One identity, one SDK

VU ONE brings identity verification, authentication and fraud protection together on a single identity graph.

The verification you run at signup stays available to authentication and to your fraud rules, with no repeated processes and no duplicated data.

Verify, Authenticate and Protect, consolidated in one place.

Request a demo