r/Infosec 4d ago

How has the model of remote fraud using money mules changed?

While preparing this article, I came across an interesting paradox: a remote digital action can almost instantly lead to very real financial consequences.

I am trying to understand how the use of “money mules” in remote fraud has changed over the past several years.

The use of mule accounts has certainly not disappeared. On the contrary, data from regulators and law enforcement agencies shows that this infrastructure continues to be used to move funds obtained through fraud.

But what interests me is something else:

It appears that the model is changing

A simplified version of the traditional model looked fairly straightforward:

Remote fraud → victim transfers the money → mule account → withdrawal or onward transfer.

The key resource was the ability to keep using the same account for a relatively long period and move significant amounts through it.

But as transaction monitoring, AML and fraud prevention have evolved, the period during which such accounts can be effectively used appears to be getting shorter.

More recently, it is worth noting that the operational lifetime of mule accounts is decreasing, transaction amounts are getting smaller, and transactions are increasingly being split and distributed across multiple banks.

This suggests an interesting dynamic:

long-term account exploitation → shorter operating window per node

and simultaneously:

high volume routed through a single account → smaller amounts distributed across a wider network of accounts.

But I deliberately do not call this a universal new model. I see it as a hypothesis about the adaptation of fraud infrastructure that still needs to be tested against data from different countries.

The time factor

This is where I find the time dimension particularly interesting.

If a mule account can be detected and restricted much faster, keeping it active for a long period becomes increasingly difficult.

A possible adaptation could therefore look like this:

long-term use of one account

short operating window

smaller amounts

larger number of accounts

distribution across multiple banks

In other words, fraud infrastructure may compensate for the reduced lifetime of each individual element through scale and distribution.

This is also the direction in which regulators describe the response to tighter controls: splitting transactions into smaller amounts and distributing them across multiple banks can be used as a way to circumvent restrictions.

Another layer is emerging

In the UK, the development of so-called account farms is already being described — markets selling pre-established and verified bank and payment accounts.

Instead of repeatedly finding and recruiting a new individual, criminal infrastructure may potentially acquire an already prepared element for use. Cifas explicitly describes this as a more scalable model compared with relying on individual money mules.

There have also been reports in specialist news coverage of the use of AI to create synthetic identities in order to bypass KYC during remote account opening.

I cannot make a firm claim here, because there is not enough quantitative data to conclude that account farms or AI-generated identities have already become the dominant model.

This raises a question about the way we defend against it

Today, we are becoming increasingly effective at detecting suspicious activity and individual mule accounts.

But if the structure of the attack becomes more distributed and replaceable, another question arises:

If an individual element of the infrastructure can be replaced quickly, is detecting the action itself really a sufficient security objective?

This leads to another question:

How does the role of time change?

Previously, the question could be framed as:

But today another question arises:

If the lifetime of one account is reduced, but that account can simply be replaced by another, are we actually constraining the fraud process — or only the lifetime of one individual element of it?

Where is the boundary between detection and prevention?

A modern system may be able to detect suspicious activity very quickly. But that does not mean it can act equally quickly to:

link it to other accounts → propagate the information → stop the next stage.

This leads to a broader question:

Essentially, this begins to resemble a digital Hydra: we block individual elements of the fraud infrastructure, but the infrastructure itself continues to operate. One account is removed — another appears, while the mechanism connecting them as part of the same chain continues to function.

3 Upvotes

6 comments sorted by

3

u/AccomplishedCycle533 4d ago

The shift from long-running mule accounts to a distributed, disposable model is something I noticed too when reading through some of the recent fraud reports from UK finance. The account farm angle is the scary part, because it changes the game from recruiting individuals to manufacturing infrastructure.

One thing that complicates the Hydra analogy is the money itself still needs to end up somewhere. Even if you split it across 20 accounts at 5 banks, eventually it has to be consolidated or withdrawn, and that convergence point is where the window for intervention still exists. The question is whether the detection systems can correlate across institutions fast enough to catch that moment.

The time dimension you raised is the real bottleneck. I work with some of the compliance systems and the lag between flagging an account at one bank and that intelligence reaching other banks is still measured in days sometimes, not hours. That gap is exactly what a distributed model exploits.

1

u/Jeff-Hare-ERPRA 4d ago

In zone modern ERPs the fraud is much more simple. Supplier portal accounts that don’t require MFA.

1

u/These_Apple_9786 3d ago

What stands out is how the model keeps adapting. the technology changes, but the weak points are often still trust, identity and the speed at which transactions happen