Fraud proceeds rarely remain in the account where they first arrive. Money stolen through scams, account takeovers and payment fraud can be transferred through multiple money mule accounts, split between beneficiaries, consolidated and eventually withdrawn, spent or converted into another form of value. For financial institutions, this means identifying the first suspicious recipient is only part of the challenge.
ZIGRAM’s analysis of money mule activity highlights the importance of following funds beyond the initial account, particularly as criminal proceeds can move through chains of accounts before reaching a cash-out point. Recent analysis from the Financial Conduct Authority (FCA) found that while some mule chains extended across many accounts, cash-out activity was concentrated between the second and fifth mule accounts, with the greatest concentration at the second account. The findings suggest that detection opportunities can extend well beyond the first mule.
A money mule is a person or account used to receive, transfer or withdraw criminal funds on behalf of another party. Some individuals knowingly participate in exchange for payment, while others are recruited through fake job offers, social media approaches, romance scams or promises of easy money. Criminals can also take control of legitimate accounts or create accounts using fraudulent identities.
Whatever the route, the purpose is broadly the same: to create distance between the original fraud and the people ultimately controlling the proceeds. This places money mule activity at the intersection of fraud and money laundering, with the initial fraud generating the funds and the mule network helping to move them.
Money mule networks do not always follow a straightforward path, but the movement of funds often follows a recognisable pattern. First, fraud proceeds enter a mule account. A victim may send money directly, or stolen funds may be transferred into an account controlled or accessed by the criminal network. The transaction may not immediately appear suspicious, particularly if the account belongs to a genuine customer with an established history of normal activity.
The risk can become more apparent once the funds begin moving again. Rather than transferring money directly to a final beneficiary, criminals may use additional mule accounts to create greater distance from the original fraud.
Real networks can be considerably more complex. Funds may be divided among several accounts, transferred through different payment channels and sent to multiple recipients before being brought together again. This fragmentation can make individual transactions appear relatively ordinary.
For example, five seemingly unrelated accounts could repeatedly send funds to the same two recipients. Examining each account separately could produce five separate alerts without revealing the wider relationship between them. Viewed as a network, however, those relationships can become more significant. Research from the Royal United Services Institute (RUSI) has similarly highlighted the importance of tracing cybercrime proceeds through chains of mule accounts rather than treating each account as an isolated event.
The final stage of a mule chain is the extraction or use of the funds. The FCA found that card payments were the most common cash-out method in the cases it analysed, followed by cash withdrawals, international transfers and cryptocurrency.
Identifying these cash-out points can provide another opportunity to understand how apparently separate accounts connect. Several mule accounts feeding the same beneficiary, merchant, wallet or withdrawal pattern may indicate that funds are being consolidated before they leave the network.
Cryptocurrency can form part of this process, although it is not present in every money mule scheme. Funds moving through bank or payment accounts may eventually reach a virtual-asset service, while criminal proceeds originating in crypto can also enter the traditional financial system.
The presence of a crypto transaction alone does not establish suspicious activity. A legitimate customer may transfer money to a crypto platform for investment or another lawful purpose. The activity becomes more meaningful when considered alongside rapid pass-through behaviour, unexplained counterparties, repeated connections to suspicious accounts or other unusual activity.
Money mule activity is unlikely to be identified through one definitive indicator. Instead, financial institutions need to consider how multiple signals interact. Rapid onward movement of funds can indicate that money is entering and leaving an account without an obvious economic purpose. Multiple unrelated senders may suggest a sudden change in how an account is being used, while repeated payments between apparently unrelated accounts and common beneficiaries can reveal connections within a wider network.
Other indicators can include sudden changes in account activity, unusually high transaction velocity, shared devices or identifiers, and repeated cash-out activity following incoming payments. An urgent request to use another person’s account to receive or move funds can also be a warning sign.
However, none of these indicators proves that an account is being used as a mule. Legitimate businesses can receive payments from multiple customers, customers can legitimately share devices or addresses, and individuals can lawfully transfer money to crypto platforms. The value comes from assessing several signals together and understanding whether they form a wider pattern.
Fragmentation is one of the biggest challenges for financial institutions. One firm may see the victim’s payment, another may hold the first mule account and a third may hold the beneficiary receiving funds from several mules. No individual institution necessarily has visibility of the entire chain.
Criminals can also divide larger amounts into smaller transfers, reuse established mule accounts across different fraud types and mix legitimate-looking activity with criminal transactions. Evidence that suspected mule accounts can be used repeatedly across different types of fraud suggests that some accounts form part of established criminal infrastructure rather than representing one-off misuse.
Traditional KYC checks can help verify a customer’s identity when an account is opened, but they may not reveal how that account is subsequently used. Detecting mule activity therefore requires financial institutions to continue assessing customer behaviour after onboarding.
Transaction monitoring can help investigators understand how quickly funds move, where they go next and whether the same beneficiaries or transaction routes appear repeatedly. Customer behaviour is also important. A transaction does not need to be unusually large to be unusual for a particular customer.
A previously low-activity account that suddenly receives payments from multiple unfamiliar parties before transferring the funds elsewhere presents a different risk from a business account with an established history of similar activity. Changes in velocity, counterparties, payment channels and account usage can provide additional context.
Financial institutions can also connect accounts through beneficiaries, devices, IP addresses, contact details, bank details, counterparties and transaction routes. Graph analytics can help identify clusters and convergence points that may be difficult to detect when alerts are assessed individually.
A shared identifier does not prove that accounts are controlled by the same criminal network. But when several meaningful relationships appear alongside suspicious fund movements, they can provide additional context for an investigation.
Money mule chains do not fit neatly into either a fraud or an AML category. The original event could involve a scam or account takeover, while subsequent activity may generate behavioural or transaction-monitoring alerts. Network analysis can then reveal connections between accounts that initially appeared unrelated.
These signals describe different stages of the same movement of criminal proceeds. Bringing fraud and AML intelligence together can therefore give investigators a more complete view of the activity.
ZIGRAM’s Complete FRAML System brings together fraud monitoring, transaction monitoring, entity intelligence and screening to provide a connected view of financial crime activity. For mule investigations, this can help teams assess the account, movement of funds and relationships surrounding it rather than relying on individual alerts in isolation.
The objective is not to automatically label a customer as a money mule. Instead, it is to identify accounts and connections that warrant closer investigation and give institutions the context to act before proceeds move further through the network.
ZIGRAM’s analysis reinforces why the first mule account should not be treated as the end point of an investigation. With the FCA finding that cash-out activity can peak several stages into a mule chain, financial institutions need to follow the movement of funds, identify consolidation points and connect related accounts. Seeing the wider network can give fraud and AML teams a better opportunity to disrupt criminal proceeds before they reach the final cash-out stage.
Copyright © 2026 FinTech Global









