Unlike a direct transaction, scamsters run numerous “mule accounts” network, where the money passes through several accounts — sometimes spread across different banks and States — before being withdrawn or transferred further. Recent investigations by Mumbai Police illustrate the scale of such networks.
In one case, Dongri Police said they identified 110 bank accounts in an alleged interstate network supplying accounts for cyber fraud. In another, Khar Police traced 22 accounts that were linked to 42 cybercrime complaints involving around ₹7.42 crore.
Nationally, the Indian Cyber Crime Coordination Centre (I4C) had shared details of 32.08 lakh Layer-1 mule accounts with entities participating in its Suspect Registry as of June 30, 2026, according to the Union Ministry of Home Affairs (MHA).
What is a mule account?
A mule account is essentially an account used as an intermediary to receive or move money connected to fraud.If a victim is induced to transfer ₹5 lakh, for instance, the account number supplied by the fraudster may not belong to the person actually orchestrating the scam. It could belong to someone who has handed over control of the account, someone recruited to open one, or an individual whose identity or KYC credentials have been misused.
The account directly receiving money from the victim is commonly described as a Layer-1 mule account. Money can then be transferred from that account into additional accounts, creating further layers in the transaction trail.
The arrangement serves two purposes: it distances those controlling the fraud from the account initially receiving the proceeds and allows the money to be moved before the victim, bank or police can intervene.
An account appearing in such a trail, however, does not by itself establish that its holder knowingly participated in the fraud. Establishing whether the account was deliberately supplied, operated by somebody else or used without the holder’s knowledge remains part of the investigation.
Where do fraudsters get access to such accounts?
Recent cases indicate that supplying bank accounts can itself operate as a separate layer of the cybercrime ecosystem.In the Dongri case, for example, police alleged that intermediaries approached people who needed money, induced them to open bank accounts in exchange for incentives and subsequently obtained their banking documents. Three alleged agents were arrested, and police recovered 42 passbooks, 70 debit cards and 36 SIM cards, among other material.
Police said they identified 110 such accounts while investigating the network. Information initially received for 17 of those accounts linked them to 38 cybercrime complaints across several States and transactions of approximately ₹25.45 crore.
A separate Khar Police investigation similarly found what police described as a network of accounts allegedly being provided for cyber fraud. The investigation began with a ₹4.07-lakh online-task fraud complaint but eventually identified 22 accounts linked to 42 cybercrime complaints across India involving around ₹7.42 crore.
Why are there so many layers?
Receiving the money is only the first step. Once it reaches the first mule account, fraudsters tranfer it to another account, and then to another one, and the list goes on. The process also means one bank account can contain money connected to several victims, while one victim’s money can be scattered across several accounts. As the number of transactions increases, probe gets trickier as investigators must follow the proceeds through each subsequent layer while attempting to identify where funds remain available to be frozen.A CBI investigation handled by its Economic Offences Branch in Mumbai provides an official example of the scale layering can reach. The agency said in July 2025 that one mule account received ₹3.81 crore from several cyber-fraud victims in a single day. The money was transferred to more than 100 first-layer mule accounts and subsequently layered through thousands of accounts before reaching the alleged fraudsters.
Bank accounts are just a part of the cyber fraud infrastructure. Operating such accounts can also involve control over phone numbers, OTPs and other authentication mechanisms. DCP (Cyber Crime) Bajrang Bansode said at least 18,000 bogus SIM cards have been blocked since 2022.
The connection was visible in a recent Mumbai “boss scam”, in which an accountant was allegedly deceived into transferring ₹48.60 lakh after receiving WhatsApp messages from someone impersonating his company’s CEO.
According to Mumbai Cyber Crime Police, an accused allegedly used a bogus SIM and altered the WhatsApp name and photograph to impersonate the executive. The money was transferred into an account in Kolkata that police identified as a mule account. During the subsequent investigation, police alleged that they traced the SIM to a vendor in Bihar who had misused e-KYC information to activate SIM cards. Police said 161 SIM cards were seized in the case.
The case demonstrates how the infrastructure surrounding a cyber fraud can extend beyond the person actually communicating with the victim: one set of credentials can facilitate the communication while a separate bank account receives the proceeds.
What happens when a victim calls 1930?
When a complaint is received after the money is transferred, police and banks face a race against further movement through the mule-account chain.Mr. Bansode explained that financial cyber-fraud complaints reported through the 1930 helpline are entered into the Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS), through which transaction details are traced and information is communicated to banks.
Where money remains available in an account identified in the transaction trail, it can be placed on hold while the complaint is processed and investigated. The first few hours following a fraudulent transaction is the “golden hour”, since the possibility of intercepting money diminishes as it travels further through the chain.
According to the MHA, CFCFRMS had helped save more than ₹11,158 crore across over 32.80 lakh complaints nationally as of June 30.
What happens to accounts caught in the trail?
Rapidly following and freezing accounts creates a second issue: not everyone whose account appears in the transaction chain may necessarily be a willing participant.Mr. Bansode said the Grievance Redressal Mechanism (GRM) deals with grievances arising from bank accounts that have been frozen or amounts placed under lien during cybercrime investigations.
The mechanism provides a process through which an account holder can seek review involving banks and investigating authorities. It is separate from determining whether the person knowingly participated in the fraud.
The Money Restoration Module (MRM), on the other hand, serves a different purpose, Mr. Bansode said. Started in June 2026 in Mumbai, it deals with returning money that has already been intercepted or frozen to the cyber-fraud victim. It is intended to streamline coordination between the investigating officer, beneficiary bank, victim’s bank and the claimant, particularly in cases where funds are spread across multiple accounts or where several victims have claims over money frozen in the same account.
According to the MHA, both mechanisms became operational in April 2026 as part of the NCRP-CFCFRMS framework.
Mr. Bansode said that over 29,000 mule bank accounts have been frozen so far, and around ₹24 crore remains held in bank accounts pending restoration to victims. Of this, around ₹7 crore has been restored to victims.
The distinction is important because stopping a transaction and recovering the victim’s money are not necessarily the same thing. Money may be frozen somewhere along a chain involving multiple accounts and potentially claims from several victims before authorities establish how much can be restored and to whom.
For a cyber-fraud victim, therefore, what appears initially to be one bank transfer can become a much larger financial trail. The account receiving the payment may only be the first stop — and every subsequent transfer increases the number of accounts investigators must follow before the money is withdrawn or moved beyond their immediate reach.
