The Account That Was Never Fraudulent

The account was never fraudulent, until it was.

Ask most compliance teams to describe a mule account and they'll describe how it gets opened: a synthetic identity, a burst of activity from day one, nothing real behind it. That picture is increasingly the wrong one. In a 2026 industry survey of over 500 fraud, risk, and AML professionals, Incognia found 81% of institutions reporting more mule account handovers, real accounts, opened by real people, taken over mid-life rather than built for fraud from the start. Only 16% of institutions in the same survey catch the handover before any suspicious transaction actually moves, which means most only see it after the money is already gone.

The other half of the problem is speed. Under Regulation (EU) 2024/886, an in-scope euro transfer must settle within 10 seconds, 24 hours a day, with no exceptions. Traditional transaction monitoring, built around an overnight batch cycle, was never designed to intervene inside a window that short. A mule network doesn't need a weak control anymore, it just needs a control that runs on the wrong clock.

A real network, not a hypothetical one

Leicestershire Police built Operation Kilo over four years, eventually tracing more than £53 million through a mule account network that moved into cryptocurrency and out through Post Office branches across Leicester between 2019 and 2021, a genuine account-network case rather than a cash-courier one. The investigation ended in five convictions carrying a combined sentence of over 35 years, the heaviest for Jigar Gheewala, who received 11 years and 10 months in prison and a 14-year ban from acting as a company director.

How to use this guide

Read the five patterns and the process chain first. Then work each scenario, make your call, and read why, both for the right answer and every wrong one. The knowledge check at the end pulls the same patterns from new angles. Do not skip ahead.

Five Patterns

Five patterns, five cards

Most mule-network misses trace back to one of these five shapes. Learn to recognise them before the scenarios test them.

💤
The Sleeper Account
A real account, years old and unremarkable, becomes a mule account without ever looking freshly opened.

Most detection logic still assumes a mule account looks new, thin history, no established pattern, activity from day one. Increasingly it doesn't. Industry survey data puts the majority of institutions now reporting more mule account handovers, genuine accounts, taken over mid-life through coercion, recruitment, or compromise, not built for fraud from the start. An account with years of stable history isn't protective once a real behavioural break appears, if anything it makes the break more diagnostic, because there's more baseline for it to depart from.

Trap
Assuming account age equals trust.
Tell
A sudden behavioural break from years of stable pattern.
Do
Baseline against the account's own history, not a generic risk score.
The Ten-Second Gap
By the time an overnight batch cycle runs, the money and the account access are both already gone.

Under Regulation (EU) 2024/886, an in-scope euro transfer must settle within 10 seconds, 24 hours a day, with no exceptions. A control built around a nightly batch job was never designed to intervene inside a window that short, and a rapid receipt-then-disperse cycle, money in, cash or card spend out within minutes, can complete and clear long before any next-day review even runs.

Trap
Relying on next-cycle batch alerts.
Tell
Rapid receipt-then-disperse within minutes on an instant rail.
Do
Real-time velocity rules, not overnight batch review.
🏢
The Business Front
KYB verifies who a company is at onboarding. It says nothing about what the account does a year later.

A business account that matched its declared activity at onboarding can still drift into a materially different pattern months or years afterward, irregular payments from unconnected individuals, no invoice trail, transfers straight out to a director's personal account. UK and Thailand regulators have both separately flagged business accounts increasingly drawn into muling for exactly this reason. Treating the onboarding check as the whole answer misses that the mismatch, not the incorporation date or the account type, is what actually needs monitoring.

Trap
Treating KYB as a one-time onboarding check.
Tell
Transaction pattern doesn't match the declared business activity.
Do
Monitor SME accounts against their own declared profile continuously.
🔇
The Silent Handoff
The same account can be a fraud victim's payee and an AML team's open suspect, with neither team aware of the other.

APP fraud reimbursement claims and AML suspicious-activity monitoring are handled by different teams for good reason, they carry different obligations and need different expertise. But when both teams hold an open case on the same receiving account and neither can see the other's, the firm is sitting on a genuinely shared piece of information it isn't using. Merging the casework itself is not the fix, that's a documented way convergence backfires, but merging visibility is exactly the fix that costs nothing to get right.

Trap
Treating fraud and AML alerts as separate queues by default.
Tell
A fraud victim's payee and an AML mule suspect can be the same account, seen by two different teams.
Do
Shared visibility across teams, not merged casework.
🕸️
The Herder's Network
A mule herder rarely runs one account. Looking at accounts one at a time is exactly how the network stays invisible.

Individual mule accounts, reviewed one at a time, can each look like an isolated, borderline case. The pattern that actually matters, several accounts sharing a device, an IP address, a recruitment channel, or a timing signature, only becomes visible once accounts are linked to each other rather than assessed alone. Network-level analysis is what turns a handful of ambiguous individual alerts into a single, well-evidenced case against the herder running all of them.

Trap
Looking for one bad account at a time.
Tell
Several ostensibly unconnected accounts sharing subtle links, device, IP, timing.
Do
Network-level linkage analysis, not account-by-account review.
The Detection Chain

The process, end to end

Four stages, no branching. The scenarios above already carry the decision nuance, this is the sequence a case moves through once a pattern actually breaks.

Stage 1 · Identify
A pattern breaks against a baseline
An established account's own history, a business's declared activity, or a velocity threshold on an instant rail.
Stage 2 · Assess
Witting or unwitting
Newly opened for fraud, or a real account taken over mid-life. The mechanism changes both the investigative approach and any vulnerable-customer duty owed.
Stage 3 · Contain
Act inside the window that actually applies
Same-day for an instant rail, not the next batch cycle.
Stage 4 · Report and trace
File the SAR, then look for the network
Shared devices, shared timing, shared recruitment patterns linking it to other accounts, since a single mule is rarely operating alone.

Stage 1, identify

A pattern breaks against a baseline: an established account's own history, a business's declared activity, or a velocity threshold on an instant rail.

Stage 2, assess

Witting or unwitting. Newly opened for fraud, or a real account taken over mid-life. The mechanism changes both the investigative approach and any vulnerable-customer duty owed.

Stage 3, contain

Act inside the settlement window that actually applies, same-day for an instant rail, not the next batch cycle.

Stage 4, report and trace

File the SAR on the individual account, then look for the network: shared devices, shared timing, shared recruitment patterns linking it to other accounts, since a single mule is rarely operating alone.

💤
Scenario 01 · Account age vs. behavioural change
The Sleeper Account
The Sleeper Account
⚖️
What do you do? Make the call

A personal current account, seven years old, has carried a single monthly salary credit of around 1,600 GBP and nothing else the whole time, no prior alerts. Over nine days it receives five payments from unconnected senders, 300 to 450 GBP each, and each one is withdrawn in cash within a few hours, leaving only a small balance behind every time.

Scenario 02 · Velocity vs. batch monitoring
The Ten-Second Gap
The Ten-Second Gap
⚖️
What do you do? Make the call

A retail customer's account receives an instant payment of 2,400 GBP at 14:32 on a Saturday. By 14:41, nine minutes later, the full balance has been withdrawn through three separate ATM transactions at two different machines. The firm's transaction monitoring runs on an overnight batch cycle.

🏢
Scenario 03 · KYB as ongoing monitoring
The Business Front
The Business Front
⚖️
What do you do? Make the call

A limited company account, incorporated eighteen months ago and declared as an online consultancy, begins receiving irregular payments from six different individuals over three weeks, none with an invoice reference, each followed by a transfer to the director's personal account.

🔇
Scenario 04 · Fraud-AML convergence
The Silent Handoff
The Silent Handoff
⚖️
What do you do? Make the call

A customer reports themselves as an APP fraud victim, tricked into sending 3,000 GBP to another account at the same bank. Separately, unknown to the fraud team, the AML team has an open low-level alert on the receiving account for unusual third-party receipts. Neither team knows the other's case exists.

Knowledge Check
Five questions. Would you catch the handover, or only see it after the money moved?
1. Why is a mule account's age a weak signal on its own?
2. Under Regulation (EU) 2024/886, what must happen to an in-scope euro transfer?
3. What's the real risk of merging fraud and AML casework into one combined queue?
4. In the Business Front scenario, what specifically made the pattern suspicious?
5. Why does a nine-minute deposit-then-withdrawal cycle matter more on an instant rail than a traditional one?
0/5
Frequently Asked

FAQ

What's the difference between a witting and an unwitting mule? +
A witting mule knowingly allows their account to be used, often for a cut of the funds. An unwitting mule has been coerced, groomed, or had their account taken over without full understanding of what it's being used for. The distinction affects both the investigative approach and how the individual is treated, not just how the SAR is worded.
How does the EU Instant Payments Regulation change what "in time" means for AML monitoring? +
Under Regulation (EU) 2024/886, an in-scope euro transfer must settle within 10 seconds, 24 hours a day, with no exceptions. A control that only runs on the next overnight batch cycle has already missed the window by the time it fires.
Is a mule account always opened for fraud, or can a genuine account become one? +
Increasingly the latter. Industry survey data from 2026 found the majority of institutions reporting more mule account handovers, real accounts taken over mid-life, not opened fraudulently, and most institutions only catch the handover after money has already moved.
What does effective fraud-AML convergence actually require, beyond shared tooling? +
Shared visibility between teams on the same account, while keeping each team's own process and expertise distinct. Merging the actual casework into one generalist queue is a documented way convergence backfires, slowing decisions rather than sharpening them.
Does the UK's mandatory APP fraud reimbursement scheme change mule detection incentives? +
Since October 2024, most UK victims of authorised push payment fraud have a legal right to reimbursement from their bank, subject to an 85,000 GBP cap per claim under the Payment Systems Regulator's rules. That cap held through the PSR's own 2026 review of the scheme's first year of operation. It shifts more of the direct financial cost of a mule account's activity onto the sending bank, not just the receiving one.
Quick Reference

At a glance

Five patterns, the trap that makes each one look routine, the tell that actually gives it away, and the response that fits.

💤
The Sleeper Account
A real account, years old and unremarkable, becomes a mule account without ever looking freshly opened.
Trap
Assuming account age equals trust.
Tell
A sudden behavioural break from years of stable pattern.
Do
Baseline against the account's own history, not a generic risk score.
The Ten-Second Gap
By the time an overnight batch cycle runs, the money and the account access are both already gone.
Trap
Relying on next-cycle batch alerts.
Tell
Rapid receipt-then-disperse within minutes on an instant rail.
Do
Real-time velocity rules, not overnight batch review.
🏢
The Business Front
KYB verifies who a company is at onboarding. It says nothing about what the account does a year later.
Trap
Treating KYB as a one-time onboarding check.
Tell
Transaction pattern doesn't match the declared business activity.
Do
Monitor SME accounts against their own declared profile continuously.
🔇
The Silent Handoff
The same account can be a fraud victim's payee and an AML team's open suspect, with neither team aware of the other.
Trap
Treating fraud and AML alerts as separate queues by default.
Tell
A fraud victim's payee and an AML mule suspect can be the same account, seen by two different teams.
Do
Shared visibility across teams, not merged casework.
🕸️
The Herder's Network
A mule herder rarely runs one account. Looking at accounts one at a time is exactly how the network stays invisible.
Trap
Looking for one bad account at a time.
Tell
Several ostensibly unconnected accounts sharing subtle links, device, IP, timing.
Do
Network-level linkage analysis, not account-by-account review.
The Account Is the Case

The account was the whole case, the network was the bigger one.

FinCrimeRadar's Scenario Lab puts the same investigative decisions in front of you under real time pressure and partial information, free, no signup required.

Want to practise the decisions rather than read about them? Free. No account needed. Work real cases under time pressure and partial information.
Open the Scenario Lab →