For compliance teams, identifying the first account to receive fraud proceeds is only one part of the investigation. Money stolen through scams, account takeovers and payment fraud can move through several mule accounts, be split between beneficiaries, consolidated and eventually withdrawn, spent or converted into other assets.
ZIGRAM’s analysis highlights the risk of institutions focusing on the initial suspicious recipient without tracing what happens to the funds afterwards. Data from the Financial Conduct Authority (FCA) supports the need for a broader view. While some of the mule chains examined by the FCA extended across many accounts, cash-out activity was concentrated between the second and fifth accounts, with the highest concentration at the second account. This means detection opportunities can remain well beyond the account where fraud proceeds first enter the financial system.
A money mule is a person or account used to receive, transfer or withdraw criminal funds on behalf of another party. Some participants knowingly move funds in return for payment, while others are recruited through fake job advertisements, social media approaches, romance scams or promises of easy money. Criminals may also compromise legitimate accounts or create new accounts using fraudulent identities.
In each case, the account can create distance between the original offence and the people ultimately controlling the proceeds. This places mule activity at the intersection of fraud and money laundering, with fraud generating the proceeds and mule accounts helping to move them through the financial system.
The movement of funds can follow a recognisable pattern, although mule networks are rarely linear. Proceeds may initially enter an account that belongs to a genuine customer and has an established history of normal activity. The risk can become clearer when the funds begin moving again, particularly where they are transferred through multiple accounts or payment channels.
Funds may also be split between several recipients before being consolidated elsewhere. Five apparently unrelated accounts repeatedly sending money to the same two recipients, for example, could generate separate alerts when each account is reviewed individually. A network view could reveal that the accounts are connected. Research from the Royal United Services Institute (RUSI) similarly highlights the importance of tracing proceeds across chains rather than treating accounts as isolated events.
The cash-out stage provides another opportunity for detection. The FCA found that bank card payments were the most common cash-out method in the cases it analysed, followed by cash withdrawals, international transfers and cryptocurrency. The findings indicate that investigators should consider not only where money enters a mule network, but also where and how it ultimately leaves.
Cryptocurrency can form part of a mule chain, although it is not present in every scheme. A transfer to a crypto exchange is not inherently suspicious and can have a legitimate purpose. Its significance increases when it appears alongside rapid pass-through activity, unexplained counterparties, repeated connections to suspicious accounts or other unusual behaviour.
There is also no single red flag that confirms an account is being used as a mule. Rapid onward transfers, multiple unrelated senders, repeated common beneficiaries, sudden changes in account behaviour, high transaction velocity, shared devices or identifiers and repeated cash-out activity can all provide useful signals. However, each can also have legitimate explanations, making the wider context important for compliance teams.
Fragmentation remains a significant obstacle to identifying mule networks. A victim’s payment may be visible to one institution, the first mule account may be held at another and a consolidating beneficiary may sit with a third. No individual institution necessarily has visibility of the complete movement of funds.
Mule accounts may also be reused across different types of fraud, suggesting that some form part of established criminal infrastructure rather than being used for a single incident. Meanwhile, KYC checks performed during onboarding can establish who a customer is without necessarily revealing how the account will subsequently be used. Ongoing behavioural and transaction monitoring is therefore important for identifying later misuse.
For compliance teams, following the sequence of transactions can provide additional context. The speed at which funds move, the beneficiaries involved, repeated transaction routes and changes in account activity can help establish whether apparently ordinary payments form part of a wider pattern.
Connecting accounts can provide another layer of visibility. Beneficiaries, devices, IP addresses, contact details, counterparties and transaction routes can reveal relationships between accounts that may otherwise appear unrelated. Graph analytics can help identify clusters and points where funds converge, although a shared identifier alone does not establish criminal control.
ZIGRAM recommends combining transaction monitoring, customer behaviour analysis and graph analytics to identify these relationships. Its Complete FRAML System brings together fraud monitoring, transaction monitoring, entity intelligence and screening, allowing fraud and AML teams to assess related signals within a connected financial crime environment.
The objective is not to automatically classify a customer as a money mule. Instead, connecting the movement of funds with account relationships can help investigators identify activity that warrants closer examination and intervene before proceeds reach their final cash-out point.
ZIGRAM’s analysis ultimately points to a wider challenge for AML monitoring: the first suspicious account may reveal where fraud proceeds entered the network, but not where they are going. With FCA data showing that cash-out activity can remain concentrated several accounts into a chain, compliance teams need visibility across the wider network to identify consolidation, connect related activity and understand where criminal proceeds ultimately leave the financial system.
Copyright © 2026 FinTech Global
Copyright © 2026 RegTech Analyst





