Money mules, in plain terms
Criminals who steal money, through scams, account takeover or payment fraud, cannot simply wire it to themselves. The receiving account would lead investigators straight to them. So they route the funds through other people's accounts first. Those accounts, and the people behind them, are money mules.
A mule is a layer of distance. The money lands in the mule's bank, e-wallet or exchange account, stays there for hours or minutes, then leaves again in smaller amounts to more mules, to a crypto wallet or to a cash machine. The mule usually keeps a small cut. In most countries, knowingly acting as a mule is money laundering, and even unwitting mules can lose their accounts and credit standing.
Types of money mules
Not every mule knows what they are doing. The type matters for how you respond.
| Type | Who it is | Typical signs |
|---|---|---|
| Unwitting mule | A real customer tricked by a fake job, a romance scam or a fake refund | Normal history, then a sudden change in how money flows |
| Witting mule | A real person who rents out their account for a fee | Logins from new devices or other people's networks after onboarding |
| Complicit mule | Someone who opens accounts on purpose to launder money | Several accounts, one device, fast in-and-out transfers |
| Fake or synthetic mule | An account opened with stolen or synthetic identity data | Scripted onboarding, shared devices and networks with other new accounts |
How a money mule scheme works
- 01
Recruit or create
Operators post fake work-from-home jobs, contact people on social media, or simply open accounts themselves with bought identity data.
- 02
Hand over control
The mule shares login details, or the operator logs in from their own device. This is where many mule accounts first look wrong.
- 03
Receive the funds
Stolen money arrives from scam victims, taken-over accounts or fraudulent payments, often in amounts chosen to avoid review thresholds.
- 04
Move it on fast
Within hours the balance is split and sent onward, converted to crypto or withdrawn, before the victim's bank can recall it.
How mule accounts show up in real traffic
Mule activity is usually judged on transactions, but the account often gives itself away earlier, in how it is opened and used. That matters most in fintech and banking, where money leaves in minutes and recalls rarely succeed.
- One device or browser profile signing up or logging in to many accounts, a pattern shared with multi-accounting.
- Onboarding completed at scripted speed, with pasted values and no reading time.
- An account that behaved normally for months, then starts logging in from a new device on a different network right before large incoming transfers.
- Residential proxies or VPNs used to make the login look local.
- Short dwell time: money in, money out, balance back near zero.
How to detect and stop money mules
Transaction monitoring sees the money. Device and session signals see who is holding the account. Combining both lets you catch mule accounts at onboarding, when a handover happens, and before a withdrawal clears. Compare every login with the account's own history, link accounts that share a real device, and step up verification when control appears to change hands.
Kavra gives each signup and login an explained risk assessment: the real device behind the browser, the network it came from, and links to other accounts on the same actor. Your team sees mule clusters instead of single alerts. See how it works for fake account creation and account takeover.