A mule account is a bank or payment account used to receive dirty money and pass it on, acting as a relay point in the laundering chain. It may be opened with a real, synthetic, or coerced identity, and its whole purpose is to move value onward, not to hold it.
What is a mule account, in plain English?
A mule account is an account whose real job is to be a relay. Stolen or illicit money lands in it, sits briefly, and moves out again, usually to another account, a cash withdrawal, or a crypto purchase. The account exists to add a hop between the criminal and the destination, so the trail is harder to follow and the money looks like it came from a normal customer.
The account behind it can be opened several ways. It may belong to a real person who was recruited or tricked, it may be built on a synthetic identity assembled to pass onboarding, or it may be a coerced or bought account taken over from its rightful owner. What they share is behavior: fast in-and-out flows, a low resting balance, and activity that does not match the account's stated purpose.
Mule accounts rarely operate alone. They tend to appear in clusters, feeding funnel accounts and forming the visible edge of a wider mule network. The single account is the thing your monitoring flags; the network is what actually matters, which is why linking accounts is central to working these cases.
How a mule account is set up and used
- Obtain — Get an account. A recruit opens it, a synthetic identity passes onboarding, or an existing account is bought or taken over.
- Wait — Sit quietly. The account often stays low-activity or dormant for a while so it looks aged and ordinary.
- Receive — Take in dirty funds. A large or unusual inbound payment lands, out of step with the account's history.
- Forward — Move it on fast. The money is pushed out quickly to the next hop, leaving little balance behind, then the cycle repeats.
Who is involved?
Who | Their role |
The account holder | The named owner, who may be a willing mule, a tricked victim, a synthetic identity, or a coerced party. |
The herder | Controls or directs the account, supplies the onward instructions, and reuses it across the operation. |
The funnel or next hop | The downstream account that receives the forwarded funds and consolidates the flow. |
The bank | Holds the account and is best placed to spot the in-and-out pattern and shared identifiers. |
What it looks like in practice
In practice
An account opened eight months ago has barely moved, holding a small balance and generating a couple of small purchases a month. One morning it receives a four-figure transfer from an unrelated person, and within an hour it sends almost the whole amount to a second account, leaving a few dollars behind.
Reviewed in isolation, it is one odd transaction. But the receiving second account also takes matching hops from five other accounts, all of which were logged in from the same device and share a recovery phone number. The single account is a mule account; the shared identifiers are what expose the ring behind it.
Why it is hard for operators
The trap is reviewing each flagged account on its own. In isolation, a mule account can look like a customer who received a one-off payment and moved it along, and there is often a plausible story attached. Closed as a single alert, it teaches you nothing and the network keeps running through its other accounts.
The leverage is in linking. Shared devices, IPs, phone numbers, addresses, funding sources, and payment references tie accounts together that otherwise look unrelated. Once you cluster them, the in-and-out behavior repeats across the group and points to a common controller, which is a far stronger case than any one account and a route toward the herder.
What to watch in the data
- Dormant then active. Sudden movement after a long quiet spell, especially a large inbound payment out of nowhere.
- Fast in, fast out. Funds arrive and leave quickly, with a persistently low resting balance.
- Purpose mismatch. Activity that does not fit the account type, the stated use, or the customer's profile.
- Shared identifiers. Common devices, IPs, phone numbers, or addresses across several accounts moving money alike.
- Reused references. The same payment narratives or beneficiary details recurring across supposedly separate accounts.
Quick questions
What is the difference between a money mule and a mule account?
The money mule is the person; the mule account is the account they use. One person can control several mule accounts, and understanding both is needed to see the full operation.
Are mule accounts always opened with fake identities?
No. They can be real accounts belonging to recruited or tricked people, synthetic identities built to pass onboarding, or accounts bought or taken over from their true owners. The identity behind it varies; the behavior is the constant.
Why keep an account dormant before using it?
An aged account with some history reads as lower risk than a brand-new one. Sitting quiet first lets the account build apparent legitimacy before it is used to move money.
Why does reviewing one account at a time fail?
In isolation a mule account often looks like a customer with a single unusual payment. The scheme only becomes clear when you link accounts through shared identifiers and see the same pattern repeat across a cluster.
What identifiers link mule accounts together?
Devices, IP addresses, phone numbers, addresses, funding sources, and reused payment references are common threads. Consortium and cross-institution data extend the view when the network spans several banks.
What should a team do with a confirmed mule account?
Restrict or freeze as policy allows, file suspicious activity reporting where the standard is met, and pivot the investigation to the linked accounts and the consolidation point to reach the network rather than stopping at one account.

