A mule account looks harmless on its own.
Clean KYC. No prior fraud flags. Transaction history that falls below every threshold. Viewed individually, it does not register as a risk. Viewed alongside the eleven other accounts it was recruited into the same network with, it is the fourth link in a layering chain that moved Rs 40 lakh out of the regulated system in six hours.
That gap - between what an account looks like alone and what it is doing as part of a network - is the exact gap account-level controls were never built to close. And for payment aggregators operating at scale, across thousands of merchants and sub-merchants, it is the gap mule networks are specifically designed to exploit.
Traditional controls - velocity checks, blocklists, static threshold rules - still have value. But they are built to evaluate one account at a time, not a coordinated fraud network.
Mule networks are engineered to exploit that architecture. Activity gets spread across multiple accounts so that no single account crosses a threshold that would trigger a review. One account shows normal volume. Another shows normal frequency. A third shows normal beneficiary patterns. The pattern that reveals the fraud only exists when all three are compared against each other - and comparison across accounts is not what per-account rules do.
This is the structural limitation. Account-level controls can tell you whether one account is behaving unusually relative to itself. They cannot tell you whether several accounts are behaving like a coordinated group.
Payment aggregators onboard merchants and sub-merchants at speed. That velocity supports growth. It also creates exposure. A sub-merchant that clears onboarding may show its real warning signs only later - when multiple accounts share the same device fingerprint, the same IP range, the same settlement account, or the same beneficial owner. If those signals are reviewed separately, by separate teams on separate timelines, the connection stays hidden exactly long enough for the fraud to complete. This is the mule network detection problem specific to payment aggregators: the risk is not in any single merchant file. It is in the relationships between merchant files - and those relationships are invisible when fraud controls are too narrow.
RBI has acknowledged this directly. MuleHunter.AI is live across 26 banks in India, and RBI has indicated that institutions should use real-time monitoring, AI and ML tools, and network analytics to identify mule networks and suspicious patterns. The direction of travel is clear: account-level screening was the starting point, not the destination.
Static rules are useful for catching known patterns. They are poorly suited to catching fraud rings that have learned to stay below every threshold.
Fraud rings regularly use account splitting - distributing transaction volume across accounts to avoid any single one triggering a velocity rule. They use shared infrastructure - common devices, IP ranges, beneficiary accounts - managed carefully enough that no individual link appears in the same review. They use small, frequent transactions structured to stay beneath reporting thresholds individually while accumulating meaningful volume collectively.
The pattern these tactics create is not visible inside any single account. It is visible in the structure of the activity across accounts - and that is the question static rules cannot ask.
Network-aware fraud detection changes the unit of analysis from the account to the network. Instead of reviewing each account separately, it connects accounts that share devices, beneficiaries, settlement patterns, onboarding attributes, or other linked signals - mapping the structure of the activity rather than evaluating each data point in isolation.
That shift enables earlier detection - identifying the link between accounts before the network has moved meaningful volume. It enables faster investigation - because the case already shows the relationships, rather than requiring an analyst to manually trace them after the fact. And it produces a cleaner audit trail, because the structure of the finding is documented from the moment it was identified, not reconstructed later.
Verafye approaches mule account detection as a network problem, not an account problem. Rather than evaluating each merchant or sub-merchant against its own history in isolation, Verafye maps the connections between entities across the full portfolio - shared devices, shared beneficiary accounts, shared onboarding attributes, shared settlement patterns.
When a new sub-merchant is onboarded, Verafye checks its identity attributes and device fingerprint against existing records. A phone number that appeared in two other onboarding applications filed the same week surfaces immediately - before the first transaction clears. A device fingerprint shared with an account already under investigation appears at the point of onboarding, not after settlement.
When a mule network forms across an aggregator's merchant book, Verafye's graph-native network risk intelligence maps the structure: which accounts are acting as collection points, which are pass-throughs, which share infrastructure with prior fraud cases. The analyst sees the cluster, not eleven separate accounts that happened to trigger different rules on different days.
The investigation case Verafye produces is already assembled - account connections, fund flow structure, shared attributes, and the full audit trail from detection to decision. For payment aggregators managing PMLA and RBI obligations, that assembled case is both faster to process and more defensible when an examiner asks how a mule network was identified. To see where mule connections currently exist in your merchant book undetected, the Verafye Risk Shadowing Review provides a scoped assessment with no commitment required.
The next step for payment aggregators is not just stronger onboarding checks. It is better visibility across the full lifecycle of an account - combining onboarding data, device intelligence, transaction behavior, and settlement links into one connected view.
When those signals are connected, fraud teams can identify mule activity earlier and act before the risk scales. They can investigate with more confidence because the case is built around relationships, not isolated alerts. And they can demonstrate to examiners that the monitoring programme operates continuously, not just at the point of application.
Mule fraud is not a single-account problem. Payment aggregators that approach it with single-account controls will keep missing the networks that matter most.
What is mule account detection?
Mule account detection is the process of identifying accounts being used to move illicit funds through a financial system - typically by looking for linked activity across accounts, devices, and transaction patterns rather than evaluating each account in isolation.
Why are account-level controls not enough for mule fraud?
Account-level controls can spot suspicious behavior in one account, but mule networks are built across many accounts. The real pattern only becomes visible when those accounts are analyzed together - which per-account rules are not designed to do.
Why are payment aggregators at higher mule risk than banks?
Payment aggregators onboard merchants and sub-merchants at speed, creating more surface area for fraudulent actors to blend into a portfolio of legitimate merchants. The shared-device and shared-beneficiary signals that reveal mule networks only appear when accounts are compared across the full merchant book.
What signals help detect mule accounts?
Common signals include shared device fingerprints, shared IP addresses, overlapping beneficiary accounts, repeated settlement behavior across unrelated merchants, and multiple accounts showing similar transaction timing and structure.
How does network-aware fraud detection differ from rules-based monitoring?
Rules-based monitoring evaluates each account against its own history or fixed thresholds. Network-aware detection maps relationships between accounts - identifying clusters of connected activity that no single account would reveal on its own.
Abhishek Tuppada
Founder & CEO, Verafye
Verafye is a graph-native network risk intelligence platform built for lean fraud, AML, and risk teams at payment aggregators, PSPs, MSBs, and regulated fintech platforms.
See where your monitoring stack has blind spots
The Risk Shadowing Review maps your current coverage against relationship-level gaps.