SardineCon SF/2026

Learn More
Fraud types4 分で読めます

Second-party fraudとは?

SUBSCRIBE

Second-party fraud is fraud enabled by an account holder who knowingly lets someone else use their identity or account. It blurs the line between victim and accomplice, which muddies both liability and detection, and it sits at the heart of money-mule activity.

What is second-party fraud, in plain English?

Second-party fraud happens when a real account holder knowingly hands over their account or identity for someone else to misuse. The account is genuinely theirs and they passed the original checks, but they let a third party operate it, usually for a cut. The classic case is being recruited as a money mule: your account receives and forwards other people's fraud or laundering proceeds.

What makes it distinct is willing complicity by the account owner. In third-party fraud, a victim's account is used without their knowledge. In first-party fraud, the account holder is the fraudster acting for their own gain. Second-party fraud is the middle case: the account holder is not the mastermind, but they consented to their account being used to commit fraud.

That ambiguity is the whole problem. The person may be a naive recruit lured by a job scam or a deliberate participant selling access, and the same account behavior can describe both. It is central to mule detection and overlaps with first-party and third-party fraud, which is why classification is genuinely hard.

First, second, and third-party fraud

These three labels turn on who the account holder is and what they knew:

What changes

Second-party fraud

First / third-party fraud

Account ownership

Real owner, genuinely theirs

First: real owner. Third: victim's, misused without consent

Owner's knowledge

Knowingly lets another use it

First: is the fraudster. Third: unaware

Who benefits

Mostly the third party, owner takes a cut

First: the owner. Third: the outside attacker

Victim status

Blurred, possibly complicit

First: none. Third: a clear victim exists

Typical role

Money mule, credential sharer

First: bust-out. Third: ATO, stolen-identity fraud

Who is involved?

Who

Their role

The account holder

Knowingly provides their real account or identity for another party to use, for a cut.

The recruiter or herder

Finds and directs mules, supplying the funds and instructions that move through the account.

The underlying fraudster

The party whose fraud or laundering proceeds actually flow through the account.

The institution

Holds the account, must spot the pass-through behavior, and decides how to classify it.

What it looks like in practice

In practice

A quiet personal account that has held a small, steady balance for years suddenly receives a large transfer from a sender the customer has no obvious connection to. Within hours, most of the money is moved out again, split across a couple of onward transfers, and the account goes quiet.

The account holder passed KYC when they opened it and is entirely real, but the incoming funds trace back to a scam victim, and the fast pass-through matches known mule behavior. When contacted, the customer explains they were offered easy money to "help process payments," leaving the team to decide whether they were a duped victim or a willing participant.

Why it matters to operators

Second-party fraud is hard because your usual defenses assume the account holder is either innocent or guilty, and here they are somewhere in between. Identity checks pass because the person is real. Victim signals are weak because the account holder is not complaining. The fraud shows up only in the behavior of the money: funds arriving from unknown senders and leaving almost immediately.

It also drives loss classification and liability. Whether you treat the account holder as a mule, an accomplice, or a victim shapes how you report it, whether you file a suspicious activity report, and what happens to the account. Getting it wrong either punishes a duped person or lets a knowing participant off the hook, so the pass-through pattern deserves careful, case-by-case handling.

What to watch in the data

  • Behavior that does not fit the owner. Activity out of character for the stated account holder's profile and history.
  • Unknown inbound senders. Money arriving from parties with no plausible relationship to the account holder.
  • Fast pass-through. Funds in and quickly back out, the signature rhythm of a mule account.
  • Links to mule networks. Connections to accounts or counterparties already tied to known mule activity.
  • Sudden activity on a quiet account. A long-dormant or low-activity account abruptly moving significant sums.

Quick questions

How is second-party fraud different from third-party fraud?

In third-party fraud, a victim's account or identity is used without their knowledge. In second-party fraud, the real account holder knowingly lets someone else use it. The key difference is the owner's consent and awareness.

Is a money mule always committing second-party fraud?

A knowing mule is a textbook second-party case, since they consent to their account moving illicit funds. An unwitting mule who was fully deceived sits closer to a victim, which is exactly the classification ambiguity this term captures.

Why is intent so hard to determine?

The same account behavior, funds in and quickly out, describes both a duped recruit and a willing participant. Without evidence of what the account holder understood, teams must infer intent from context, communications, and repetition.

How does it affect a suspicious activity report?

Pass-through mule behavior is commonly reportable regardless of the account holder's intent, because the funds themselves are suspicious. Classification affects how the account is handled, but the underlying money movement usually warrants scrutiny.

What is the strongest detection signal?

Fast pass-through of funds from unknown senders on an account whose behavior does not match its owner, especially with links to known mule networks. Money movement, not identity, is where second-party fraud reveals itself.

Can someone commit it without realizing?

By definition second-party fraud involves knowing consent, but the line is fuzzy. Many recruits are misled about what they are doing, which is why some are treated as victims and others as accomplices depending on the evidence.

Go deeper

  • FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
  • FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

Second-party fraudと併せて知っておきたい用語