Skip to main content

BankingAML & transaction monitoring2 of 28

Mule rings

Networks of accounts, recruited or controlled by one organizer, that receive criminal proceeds and pass them on to break the audit trail.

Many receiving accountsSource account
Illustrative patternProceeds land in a first account and are split across several mule accounts, each of which forwards or withdraws them within hours.

How it works

A money mule receives funds into their own account and moves them on by transfer, cash withdrawal or crypto purchase, usually for a fee. Mules are recruited through fake job offers, social media posts promising easy money and romance scams, or they sell access to their accounts outright. Some are unwitting, many are complicit, and some accounts are opened specifically for the purpose with stolen or synthetic identities.

A ring is a group of mules handled by the same organizer. Each account on its own may look like a modest personal account with an unusual inflow. The ring becomes visible when the accounts are linked by a common device, phone number, IP address, employer or address, or by the same beneficiaries further down the chain.

Proceeds typically come from scam victims, account takeover or invoice fraud, and leave within hours of arriving. In mobile-money markets, mule wallets are often registered on SIM cards bought in bulk or registered in other people's names, and cash out through agents in a different town from the one where the funds landed.

Red flags

  • Newly opened or long-quiet accounts receiving sudden inbound transfers from unrelated senders
  • Funds forwarded or withdrawn shortly after arrival, leaving a near-zero balance
  • Several customers logging in from the same device or IP address, or sharing a phone number or email
  • An account holder profile, such as a student or unemployed person, inconsistent with the value moving through the account
  • Several accounts paying the same small set of beneficiaries, wallets or crypto exchanges
  • Inbound payments followed by fraud claims or recall requests from the sending institutions

Signals the engine evaluates

  • Pass-through ratio: the share of inbound value sent out again within a short window, against the account's baseline
  • Accounts that entity resolution links through shared devices, phones, emails, addresses or ID numbers
  • Common downstream beneficiaries across otherwise unrelated accounts
  • Time from account opening to the first high-value inbound transfer, and the diversity of first-time senders

Investigation and response

  1. 01Resolve the ring: expand from the alerted account to every account sharing a device, phone, address or beneficiary, and review them together.
  2. 02Review onboarding and KYC data for each member, looking for identity documents, photos or employer details reused across accounts.
  3. 03Restrict outbound payments where policy allows, and coordinate recalls with the sending institutions for victim funds still in the ring.
  4. 04Manage the ring as one case and file suspicious transaction reports covering all linked accounts with the financial intelligence unit, such as FinCEN in the US or the FIC in South Africa.
Get started

Catch mule rings before the loss

See how FinCrimes scores this pattern against your own historical data in a backtest, before anything goes live.

Browse the library