A fraud team traced a loan app scam back to its settlement layer and found something they did not expect.
The money had not gone to one account. It had passed through eleven - each belonging to a real person, each with a clean transaction history, each onboarded through standard KYC. A delivery driver in Nagpur. A college student in Indore. A retired schoolteacher in Kanpur. None of them had committed fraud, technically. They had opened bank accounts, been paid a small sum, and let someone else move money through them.
By the time the fraud team mapped the full chain, the funds were gone - layered through eleven accounts and out the other side in under six hours.
Every one of those accounts had passed fraud screening individually. None looked suspicious on its own. That is not a detection failure in the usual sense. It is a detection design failure - and it is the specific problem mule networks are built to exploit.
A mule account, by design, does not look like fraud. It belongs to a real person with real KYC. Its transaction pattern - money in, money out - can look identical to a small business owner paying a supplier.
Rules-based monitoring evaluates each account against its own history: is this transaction unusual for this account? A mule account used once and abandoned has no prior history to compare against. There is nothing "unusual" about a new pattern when there was no old pattern to begin with.
The fraud is not visible in any single account. It is visible in the fact that eleven supposedly unconnected accounts moved the same money, in sequence, within hours of each other - a pattern that exists only at the network level, not the account level.
This is the same blind spot legacy systems have with fraud rings and synthetic identities: the detection unit of analysis is the individual entity, and the fraud unit of analysis is the network.
Graph analytics treats accounts, devices, phone numbers, and beneficiaries as connected nodes rather than isolated records. Instead of asking "is this account behaving normally," it asks "how does this account relate to others, and does that relationship resemble known mule layering structures." This is the core question behind mule network detection - and it requires a fundamentally different analytical architecture to answer.
Graphs reveal structure. AI adds judgment about which structures matter.
Verafye's mule account detection capability is built on graph-native intelligence - treating accounts, devices, phone numbers, beneficiaries, and behavioural fingerprints as connected nodes, not isolated records.
When a new account is onboarded, Verafye maps its identity attributes against the existing network across your portfolio. A phone number that appeared in three other onboarding records in the past month connects immediately - before the first transaction. A device fingerprint shared with accounts already flagged for suspicious activity surfaces at the point of onboarding, not after settlement.
When a mule chain forms, Verafye's graph-native network risk intelligence maps the money flow structure in real time - the fan-in, fan-out topology, the layering chain, the accounts acting as collection points versus pass-throughs. Analysts see the network, not eleven separate account alerts that nobody connected.
The investigation case that results is already assembled when the analyst opens it: account connections, fund flow path, network structure, and the full audit trail from detection to decision. For regulated entities under PMLA and RBI obligations, that trail is what satisfies both the operational requirement and the examination question.
To see where mule account patterns currently exist in your portfolio - connections that per-account review has not surfaced - the Verafye Risk Shadowing Review runs a scoped assessment across your existing signal coverage with no commitment required.
UPI's real-time settlement means mule layering that once took days now takes hours - sometimes minutes. By the time an STR would traditionally be filed, funds have often cleared the entire chain and left the regulated system.
The scale of loan app fraud and job-fraud recruitment in India has made mule account supply a commodity - recruited, paid, and rotated faster than static rules can be updated. RBI's expectations around ongoing transaction monitoring assume institutions can detect these patterns before settlement completes, not after a manual investigation weeks later.
Graph and AI-based detection is not an upgrade in this environment. It is the only architecture capable of matching the speed and structure of the threat.
Not "does our system flag suspicious accounts." Nearly every system does that.
The real question: can our system see that eleven individually clean accounts moved the same money in the same six hours - and would it have caught that in time to stop the fifth transfer, not just document the eleventh?
If the honest answer involves a manual trace after the fact, the system is documenting mule fraud. It is not preventing it.
Sudeendra
Co-Founder & COO, Verafye
Verafye is a graph-native network risk intelligence platform built for lean fraud, AML, and risk teams at payment aggregators, PSPs, MSBs, and regulated fintech platforms.
See where your monitoring stack has blind spots
The Risk Shadowing Review maps your current coverage against relationship-level gaps.