Bank Accounts Supplied to Cyber Fraudsters Highlight Growing Mule-Account Risk

Rourkela police have arrested two men, aged 22 and 24, for allegedly procuring and supplying bank accounts to cyber fraudsters. According to the Times of India report, the accused allegedly lured individuals with promises of money and jobs to open accounts in their names, collected their banking credentials and handed them to cybercriminals. Police said the accused received around ₹15,000 per account, while several of the accounts were allegedly linked to cyber-fraud transactions amounting to about ₹25 lakh. The investigation has identified links to complaints in Delhi, Haryana, Karnataka, Maharashtra and Rajasthan.

The case illustrates how mule accounts can become the financial infrastructure for cyber fraud. RBI guidance describes money mules as third parties recruited to receive and transfer proceeds of fraud, and requires regulated entities to undertake due diligence and meticulous monitoring to identify such accounts and take appropriate action, including filing Suspicious Transaction Reports where warranted. RBI guidance also identifies indicators such as high account turnover inconsistent with balances, unusual transaction patterns and third-party deposits followed by large withdrawals.

For banks, the incident shows why cyber-risk management cannot focus only on preventing attacks against the bank’s own systems. Mule-account detection needs to be part of fraud risk, AML and transaction-monitoring frameworks. Banks can strengthen controls by combining KYC and customer-risk information with behavioural transaction analytics, monitoring sudden changes in account activity, identifying networks of linked accounts and rapidly escalating suspicious patterns. RBI guidance also permits regulated entities to use AI and machine learning to support ongoing transaction monitoring, providing scope for more sophisticated detection of unusual account behaviour.

What This Means for Cyber Risk Management in Banks

1. KYC alone is not enough.
An account can be opened using apparently valid identity documents and subsequently be handed over to criminals. Banks therefore need continuous customer due diligence, not just onboarding verification.

2. Transaction behaviour becomes a critical risk signal.
An account showing sudden high-value inflows, rapid onward transfers, multiple unrelated counterparties or activity inconsistent with the customer’s stated profile should attract enhanced scrutiny. RBI specifically highlights unusual patterns and high turnover inconsistent with account balances as monitoring concerns.

3. Banks need network-level monitoring.
The reported accounts were allegedly connected with cybercrime complaints across five states. This illustrates why looking at individual transactions in isolation may be insufficient. Linking accounts, beneficiaries, devices, mobile numbers, IP information and transaction counterparties can help identify broader fraud networks.

4. Fraud risk and cyber risk need to work together.
A cyber-fraud event may ultimately be executed through legitimate banking infrastructure. The control framework therefore needs coordination between Cybersecurity, Fraud Risk Management, AML/KYC, Operations and Compliance rather than treating cyber incidents and financial crime as separate problems.

5. Early intervention matters.
Once a mule account begins receiving fraudulent proceeds, rapid detection and escalation can potentially limit onward movement of funds. Strong transaction monitoring, alert prioritisation and clearly defined escalation procedures are therefore important components of banking cyber resilience.

The broader lesson is that the account itself can become an attack surface. Banks need to assess not only whether customer credentials and systems are secure, but also whether legitimate accounts are being recruited, controlled or misused as part of cybercrime networks. The Rourkela case, involving an alleged ₹25 lakh in linked cyber-fraud transactions, demonstrates the importance of combining KYC, AML, fraud analytics and cyber-risk controls into a coordinated defence framework.

Want to deepen your expertise beyond today’s news?

Explore practical certification courses designed for banking, risk, insurance, compliance, ESG, AI, and emerging technologies professionals.

Learn from industry experts and earn certifications from RMAI and BFSI Sector Skill Council of India.

#Riskmanagementnews

author avatar
RMA INDIA

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.