MULE BANK Accounts and mule SIM cards are the basic tools that make cybercrime possible. Most of the mules are manipulated into joining the network. When caught by the police, they suffer a lot due to the legal consequences and the taboo. THE WEEK spoke to a few mules to understand their side of the story.
Ramesh Kumar, who runs an electronics shop in Hyderabad, has three FIRs pending against him. Last November, an acquaintance named Raju offered him an exciting deal—lend his bank account and receive 2 per cent of the proceeds. Ramesh agreed almost immediately.
They went to a bank and opened a current account. On Raju's recommendation, the bank’s deputy manager raised its daily transaction limit to Rs1 crore (Rs365 crore annually), even though Ramesh's GST certificate showed an annual turnover of just Rs22 lakh. (Later, during police questioning, the deputy manager said customers could request transaction limits up to 1,000 times higher. The police have since written to the bank's board, questioning how such a limit was approved with virtually no scrutiny.)
The account initially handled only small transactions for three months as part of “seasoning”, a tactic used by cybercriminals to make new accounts appear genuine and bypass banks' anti-money laundering checks. One day, Ramesh was summoned to Mumbai, where two men took away his phone and confined him in a hotel room for three days. During that period, Rs2.6 crore was laundered through his account, and Rs19 lakh was withdrawn from it.
In another case, the police arrested a 24-year-old engineering graduate. His former workmates had befriended him and forged documents—GST registration, UDYAM certification and rental agreements—to set up a shell enterprise in his name. Using these, he opened multiple current accounts and handed them over to cybercriminals. He was flown to New Delhi and put up in a hotel for several days while fraud proceeds were routed through one account.
By the time he returned to Hyderabad, nearly Rs2 crore had passed through it.
These kinds of mules are called complacent mules, who lend their bank accounts and SIM cards for money. They agree to an upfront payment of Rs5,000 to Rs40,000 and a commission of 1.5 to 2 per cent on the crime proceeds.
The police say not all of them are criminals by nature; many of them opted for muling because of their poor financial condition or sudden unemployment.
There are two other two types of mules: deceived mules and synthetic mules. Deceived mules are people who are manipulated, and bank accounts and SIM cards are opened in their names. Cybercriminals would lure them with various proposals and never reveal how their accounts or SIM cards would be used.
Take, for instance, the case of Naresh Yadav from Mahabubnagar, whose interior decoration business in Mumbai was sluggish. A “friend” offered to get him “project funding” of Rs2 crore from a bank. The friend introduced his own friends, who made him open a current account. They kept control of it, saying it would help them speed up the funding. They also sought his SIM card. “At this point, I was very uncomfortable, and I did not want to give my SIM. But I thought about the loan and cooperated with them,” Naresh said.
They used his account for about a month until it got frozen. The police arrested him after an amount linked to a case in Hyderabad was deposited into his account. Convinced of his innocence, the police have decided to treat him as a witness because he had made no money from the transactions.
The most concerning category is the synthetic mule—one who does not even know that a bank account has been opened in one’s name, using stolen or fabricated KYC credentials. Fraudsters exploit gaps in customer verification to open bank accounts and obtain SIM cards in another person's name, leaving innocent people to face scrutiny while the real operators remain hidden.
All three types of mules serve the same purpose—providing the first layer through which stolen money enters the banking system. Once the funds reach a mule account, the account holder's role is largely over. The money is immediately pushed through a complex laundering chain designed to distance the fraudsters from both the crime and the proceeds.
Ramesh Kumar's case illustrates how that process works. Tracking him down, investigators traced the money to an investment scam running through trading websites and a money-laundering operation. The funds had moved through 13 distinct layers, in 2,487 individual transactions, across 600-plus unique bank accounts. Once money reached the first layer, it didn't linger there—it was broken into smaller amounts and dispersed across hundreds of accounts in different states. The speed meant that even if one account was frozen, only a fraction of the money could ever be recovered.
The depth of layering—particularly between layers three and five, where hundreds of accounts each received small amounts of Rs500 to Rs5,000—is what investigators call a smurfing architecture: fragment the trail into thousands of tiny transactions, push the money through hundreds of accounts, and overwhelm anyone trying to trace it. Each individual transfer falls below the threshold that would normally trip a bank's automated fraud alert, so the very system built to catch large suspicious transfers never sees the thousands of small ones moving past it. The funds would eventually be laundered through bulk payouts, cheques, ATM withdrawals in remote corners of the country and cryptocurrency before reaching accounts abroad.
"For the police, it would be impossible to trace those 600-plus bank accounts spread across the country," V.C. Sajjanar, police commissioner of Hyderabad, told THE WEEK. "The fraudsters have developed mule-account creation into an industry. It is a regular industry now. They have their own offices, HR, work-from-home—teams continuously work to replace one lost mule account with ten new ones."
These players have different roles and departments. There are mule recruiters, scam artists, platform seeders, SIM providers, and tech partners who provide SIM boxes, IP randomisation, spoofing, etc.
The supply of mule accounts keeps growing because recruitment has been perfected. Cyber fraud gangs recruit thousands of new accounts every month through social media, messaging apps, local agents and personal networks. Students, unemployed youth, migrant workers and small businessmen are the most common targets—a few thousand rupees is often all it takes.
The loss of a few hundred accounts in a month means little to a network that can recruit thousands more. The result is a constantly replenished pool that is activated whenever a new fraud requires a fresh layer.
For men like Ramesh, the irony cuts deep: a 2 per cent commission has left them with pending cases, frozen bank accounts and the label of money launderers—while the men who pocketed the 98 per cent move on, untraceable, to recruit the next mule.