Fraud Detection8 min readJune 2026

How AI and Graph Analytics Improve Mule Account Detection

A fraud team traced a loan app scam back to its settlement layer and found something they did not expect.

The money had not gone to one account. It had passed through eleven - each belonging to a real person, each with a clean transaction history, each onboarded through standard KYC. A delivery driver in Nagpur. A college student in Indore. A retired schoolteacher in Kanpur. None of them had committed fraud, technically. They had opened bank accounts, been paid a small sum, and let someone else move money through them.

By the time the fraud team mapped the full chain, the funds were gone - layered through eleven accounts and out the other side in under six hours.

Every one of those accounts had passed fraud screening individually. None looked suspicious on its own. That is not a detection failure in the usual sense. It is a detection design failure - and it is the specific problem mule networks are built to exploit.

Why Mule Accounts Are Hard to Catch One at a Time

A mule account, by design, does not look like fraud. It belongs to a real person with real KYC. Its transaction pattern - money in, money out - can look identical to a small business owner paying a supplier.

Rules-based monitoring evaluates each account against its own history: is this transaction unusual for this account? A mule account used once and abandoned has no prior history to compare against. There is nothing "unusual" about a new pattern when there was no old pattern to begin with.

The fraud is not visible in any single account. It is visible in the fact that eleven supposedly unconnected accounts moved the same money, in sequence, within hours of each other - a pattern that exists only at the network level, not the account level.

This is the same blind spot legacy systems have with fraud rings and synthetic identities: the detection unit of analysis is the individual entity, and the fraud unit of analysis is the network.

What Graph Analytics Adds

Graph analytics treats accounts, devices, phone numbers, and beneficiaries as connected nodes rather than isolated records. Instead of asking "is this account behaving normally," it asks "how does this account relate to others, and does that relationship resemble known mule layering structures." This is the core question behind mule network detection - and it requires a fundamentally different analytical architecture to answer.

  • Money flow tracing: Graphs reconstruct the path funds take across accounts - not just the immediate sender-receiver pair, but the full chain. Layering, where funds move rapidly through several accounts before reaching a final destination, becomes visible as a shape rather than requiring an analyst to trace transaction-by-transaction.
  • Shared attribute detection: Mule accounts recruited by the same network often share subtle connections - a common device used to open several accounts, a recruiter's phone number appearing across multiple onboarding records, the same IP funding accounts that otherwise look unrelated. These links are invisible to per-account review and immediately visible in a connected graph.
  • Structural pattern matching: Mule networks have recognisable topologies - a fan-in, fan-out structure where many small deposits converge into one account before rapidly dispersing, or a linear chain built to add distance between origin and destination. Graph algorithms can be trained to recognise these shapes, flagging structural anomalies rather than waiting for one account to look bad.

Where AI Adds the Second Layer

Graphs reveal structure. AI adds judgment about which structures matter.

  • Network-position scoring: Models trained on historical mule typologies can score not just individual accounts but network positions - identifying which node in a cluster is acting as a collection point, a pass-through, or a cash-out point.
  • Behavioural sequencing: AI can learn the timing signatures of mule layering - funds typically move within minutes or hours, not days - and flag chains matching this pattern even when individual transaction values fall below any static threshold.
  • Adaptive learning: Mule networks change tactics once old patterns get flagged. Models that retrain on emerging typologies stay closer to current fraud behaviour than fixed thresholds can.
  • Recruitment pattern detection: Many mule networks recruit through job scams, onboarding batches of individuals within short windows. AI can flag unusual onboarding velocity from common referral sources or geographic clusters - catching the recruitment pattern before the accounts are even used.

How Verafye Approaches Mule Account Detection

Verafye's mule account detection capability is built on graph-native intelligence - treating accounts, devices, phone numbers, beneficiaries, and behavioural fingerprints as connected nodes, not isolated records.

When a new account is onboarded, Verafye maps its identity attributes against the existing network across your portfolio. A phone number that appeared in three other onboarding records in the past month connects immediately - before the first transaction. A device fingerprint shared with accounts already flagged for suspicious activity surfaces at the point of onboarding, not after settlement.

When a mule chain forms, Verafye's graph-native network risk intelligence maps the money flow structure in real time - the fan-in, fan-out topology, the layering chain, the accounts acting as collection points versus pass-throughs. Analysts see the network, not eleven separate account alerts that nobody connected.

The investigation case that results is already assembled when the analyst opens it: account connections, fund flow path, network structure, and the full audit trail from detection to decision. For regulated entities under PMLA and RBI obligations, that trail is what satisfies both the operational requirement and the examination question.

To see where mule account patterns currently exist in your portfolio - connections that per-account review has not surfaced - the Verafye Risk Shadowing Review runs a scoped assessment across your existing signal coverage with no commitment required.

Why This Matters for Indian PSPs and Banks

UPI's real-time settlement means mule layering that once took days now takes hours - sometimes minutes. By the time an STR would traditionally be filed, funds have often cleared the entire chain and left the regulated system.

The scale of loan app fraud and job-fraud recruitment in India has made mule account supply a commodity - recruited, paid, and rotated faster than static rules can be updated. RBI's expectations around ongoing transaction monitoring assume institutions can detect these patterns before settlement completes, not after a manual investigation weeks later.

Graph and AI-based detection is not an upgrade in this environment. It is the only architecture capable of matching the speed and structure of the threat.

The Question Worth Asking

Not "does our system flag suspicious accounts." Nearly every system does that.

The real question: can our system see that eleven individually clean accounts moved the same money in the same six hours - and would it have caught that in time to stop the fifth transfer, not just document the eleventh?

If the honest answer involves a manual trace after the fact, the system is documenting mule fraud. It is not preventing it.

S

Sudeendra

Co-Founder & COO, Verafye

Verafye is a graph-native network risk intelligence platform built for lean fraud, AML, and risk teams at payment aggregators, PSPs, MSBs, and regulated fintech platforms.

Explore on Verafye

Mule Account DetectionMule Network DetectionGraph IntelligenceRisk Shadowing Review

See where your monitoring stack has blind spots

The Risk Shadowing Review maps your current coverage against relationship-level gaps.

Request a Review

Related Articles

12 min read · July 2026Graph Intelligence for Fraud Detection: Why Payment Aggregators Need More Than Rule-Based Systems6 min read · July 2026AI-Powered Transaction Monitoring: Why Payment Aggregators Need Relationship-Based Fraud Detection
Back to Blog