Mule Accounts and Instant-Payment Fraud: What Victims and Finance Teams Must Do
A mule account is used to receive or move suspected criminal proceeds, sometimes by a willing participant and sometimes by a person deceived into lending an account. Instant payments allow funds to be layered quickly, so prevention and immediate response matter more than waiting for a complete internal investigation.
Finin2min Summary
- Never rent, sell or lend a bank account, SIM, UPI ID or company payment access.
- A request to receive money and forward it for commission is a major mule-account warning sign.
- Victims should contact the bank and official cybercrime channel immediately and preserve evidence.
- Businesses need beneficiary verification, payment limits and alerts for master-data changes.
- Account freezes can affect innocent parties in a transaction chain; documentation and legal process matter.
Mule networks exploit students, job seekers, small businesses and dormant accounts. Common stories include work-from-home commissions, crypto conversion, refund processing and 'account testing'. A corporate account can also become a mule if credentials are compromised or staff route fraudulent receipts. Finance teams need controls on both outgoing payments and unusual incoming funds.
Recognise recruitment patterns
Warning signs include payment for opening accounts, instructions to share OTPs or SIMs, receiving unknown funds, rapidly forwarding money, converting funds to crypto or cash, and promises that the activity is legal because no investment is required. A legitimate employer does not need an employee's personal account to route third-party money.
Act quickly after a transfer
Contact the remitting bank's fraud channel, provide the transaction reference and request appropriate action. Report on the National Cyber Crime Reporting Portal or helpline as applicable and preserve messages, phone numbers, account details, URLs and device evidence. Do not continue negotiating with the fraudster from a compromised device.
Strengthen corporate beneficiary controls
New vendors and bank changes should require independent verification using pre-existing contact details, maker-checker approval and a cooling or enhanced-review period. Monitor a master change followed by an urgent payment, split payments, new geography or unusual time. Payment files should be reconciled to approved invoices and beneficiaries.
Handle freezes with evidence and counsel
Banks and law-enforcement agencies may place holds or freezes while tracing proceeds. A legitimate account holder should collect invoices, contracts, delivery proof, bank statements and communication showing the commercial basis of the receipt. Do not pay an intermediary promising an unofficial unfreeze. Use the bank, investigating agency and legal process.
What the Viral Version Usually Misses
Fraud-awareness posts sometimes blame every mule as a mastermind or promise that money will be recovered if reported within a fixed number of minutes. Speed improves the possibility of intervention but does not guarantee recovery. Some account holders are complicit, others negligent and others deceived; liability and release require facts and due process.
Worked Scenario: Vendor email compromise
An accounts-payable team receives an email changing a supplier's bank account and sends ₹18 lakh. The genuine supplier calls the next morning. The company immediately contacts its bank, files the cyber report, preserves email headers and checks whether the mailbox was compromised. The payment-control review finds that the employee verified the change using the new number in the fraudulent email. The remediation is independent call-back to the vendor master contact, dual approval and a first-payment alert—not merely more phishing training.
Practical Decision Checklist
- Do not lend accounts, SIMs, OTPs or payment credentials.
- Verify beneficiary changes through an independent trusted channel.
- Use maker-checker approval and transaction-value alerts.
- Contact the bank immediately after suspected fraud.
- Report through the official cybercrime channel and preserve evidence.
- Document the legitimate source of unusual incoming receipts.
Article-Specific Q&A
Can I keep a commission for receiving and forwarding money?
That pattern is a serious warning sign and can expose the account holder to criminal, banking and tax consequences. Do not participate.
Will reporting within an hour guarantee recovery?
No. Early reporting can improve intervention chances, but funds may already be layered or withdrawn. Act immediately without assuming a guarantee.
What if my account is frozen because a customer paid me?
Collect the invoice, contract, delivery and communication evidence, contact the bank and investigating authority, and obtain legal advice where needed.
Should a company call the new bank number supplied by the vendor?
No. Verify through a number already held in the approved master or another independently sourced channel.
Can a mule account be a company account?
Yes. Compromise, collusion or sham transactions can route criminal proceeds through business accounts.
What should not be deleted after fraud?
Messages, emails and headers, transaction references, call records, URLs, invoices, system logs and suspicious files should be preserved according to incident guidance.
Sources and Verification Trail
- National Cyber Crime Reporting Portal: Official cybercrime reporting channel. — https://cybercrime.gov.in/
- Indian Cybercrime Coordination Centre: Official cybercrime prevention and coordination resources. — https://i4c.mha.gov.in/
- Reserve Bank of India — Customer Protection: Primary banking rules and customer-liability context. — https://www.rbi.org.in/
- CERT-In: Official cyber-security advisories and incident directions. — https://www.cert-in.org.in/