Skip to main content
Mule Accounts: What Your Fraud Team Keeps AskingFraud Typologies
6 min readFor Fraud Risk Managers

Mule Accounts: What Your Fraud Team Keeps Asking

Fraud operations teams, AML analysts, and compliance managers often encounter suspicious account activity but struggle to identify it or coordinate a response. These questions arise during incident reviews, cross-functional meetings, and late-night discussions when someone spots a pattern that doesn't fit existing detection rules.

Q1: How do I tell the difference between a legitimate account that's been compromised and someone who knowingly became a mule?

It's not always clear from a single transaction, and that's the challenge.

Start by tracking behavior changes over time. A compromised account usually shows an abrupt shift: new beneficiaries appear, transaction velocity spikes, or login patterns change suddenly. A knowing participant often shows gradual escalation, testing small amounts first, then increasing volume as they gain confidence.

Check your access logs. Multiple IP addresses accessing the same account quickly suggests credential sharing or remote access tools. Logins from residential IPs in different states within hours are a red flag regardless of intent.

The harder question is whether intent matters for your response. From an AML perspective, both scenarios require a Suspicious Activity Report (SAR) if the activity meets your filing thresholds. Your fraud team needs to close the vulnerability either way. Save the intent analysis for law enforcement.

Q2: Our fraud team flagged an account, but AML cleared it last month during their review. What gives?

This is the silo problem.

Your fraud team likely reviewed a specific transaction or claim. Your AML team evaluated the account against their transaction monitoring rules at a point in time. Neither team saw what the other saw, and neither had visibility into the full timeline of account behavior.

Mule accounts exploit this gap. Criminals structure activity to stay under individual team thresholds while building a pattern that's obvious when you connect the dots. A $2,000 wire transfer looks clean to fraud. A series of small ACH deposits looks normal to AML. Put them together with login data and counterparty analysis, and you've got a textbook mule operation.

You need shared case management infrastructure where fraud, AML, and operations can see each other's flags and notes on the same account. This doesn't mean merging teams. It means giving each team read access to the others' systems and establishing escalation protocols for accounts that trigger multiple teams.

Q3: What specific behavioral changes should trigger a mule investigation?

Track these patterns in your transaction monitoring rules:

Velocity shifts: An account that averaged two transactions per month suddenly processes fifteen in a week. This signals a change in account purpose.

Counterparty rotation: Funds arrive from a new source, stay briefly, then move to a different beneficiary. The account becomes a pass-through rather than a destination.

Access concentration: Multiple accounts accessed from the same IP address or device within a short window. This indicates centralized control rather than individual account holders acting independently.

Timing patterns: Transactions cluster around specific times of day or follow a regular cadence. Legitimate users show more randomness. Mule networks often operate on schedules.

Dormancy breaks: An account sits inactive for months, then suddenly activates with high-value transactions to unfamiliar parties. This suggests the account was purchased, compromised, or recruited.

Don't wait for all five signals. Any two should trigger manual review.

Q4: We keep shutting down mule accounts, but new ones appear immediately. Are we just playing whack-a-mole?

Yes, and that's by design.

Criminals prepare alternate accounts in advance because they expect detection and closure. When you shut down one mule account, they've already recruited or compromised three more. This is why individual account closures don't disrupt mule networks.

Shift from account-level response to network-level analysis. When you identify one mule account, map its transaction graph: who sent money in, where did it go, what other accounts share those counterparties? Use that intelligence to identify the broader network before taking action.

Some banks coordinate closures across multiple accounts simultaneously to disrupt the entire operation rather than forcing criminals to pivot one account at a time. This requires cross-institutional intelligence sharing, which brings us to the harder problem: most banks don't have formal mechanisms to share mule network data with other institutions.

Industry working groups and Financial Services Information Sharing and Analysis Center (FS-ISAC) channels exist for this purpose, but adoption remains inconsistent. If you're not participating in these networks, you're fighting with partial visibility.

Q5: What should we tell customers who claim they were just "helping a friend" move money?

Be direct about consequences, not intent.

Many people don't realize that allowing someone else to use their account for fund transfers is illegal, regardless of the story they were told. Your messaging should focus on what happens next, not whether they knew better.

Explain that their account will be closed, they may face difficulty opening accounts at other institutions, and they could be held liable for funds moved through their account. If the activity meets SAR thresholds, tell them you're required to file with FinCEN.

Don't try to determine guilt during this conversation. That's not your role. Your job is to protect your institution and make clear that this behavior has consequences even if the customer didn't understand what they were participating in.

Some banks include mule warning language in account opening disclosures and send periodic reminders to customers in high-risk demographics (younger account holders, recent account openers). This creates a paper trail showing you attempted education, which matters if you later need to demonstrate due diligence.

Q6: How do we get our fraud and AML teams actually working together instead of just sharing reports?

Start with joint case reviews, not system integration.

Pick five accounts that triggered both fraud and AML flags in the past quarter. Put both teams in a room and walk through what each team saw, when they saw it, and what action they took. You'll quickly identify where information gaps created risk.

Then establish a weekly triage meeting where both teams bring their top uncertain cases. The goal isn't to transfer ownership but to get a second perspective before closing or escalating. This builds working relationships before you tackle the harder work of system integration.

For technology changes, prioritize shared visibility over shared systems. Give your fraud team read access to your AML transaction monitoring alerts. Give your AML team visibility into fraud case notes and device intelligence. You don't need a single unified platform; you need each team to see what the other is looking at.

Create explicit escalation paths for accounts that show characteristics of both fraud and money laundering. Define who owns the investigation, who provides support, and what triggers a SAR versus a Suspicious Activity Report (SAR) versus both.

Where to go for more

FinCEN publishes advisories on money mule typologies and red flags. Start with their guidance on funnel accounts and structuring patterns. Your AML compliance officer should already receive these, but fraud teams often don't see them.

The Wolfsberg Principles include guidance on correspondent banking and payment transparency that applies to mule detection, particularly for cross-border activity. If you're a bank handling international wires, these principles inform your monitoring obligations.

For behavioral analytics and continuous monitoring approaches, NIST SP 800-63B covers authentication assurance levels that affect how you verify account access patterns. It's written for identity verification, but the frameworks apply to ongoing account monitoring.

Most importantly, talk to your counterparts at other institutions through industry working groups. Mule networks operate across banks. Your detection program can't be limited to your own walls.

You Might Also Like