Fraudsters targeting Indian consumers are increasingly relying on India-based money mule accounts to route stolen funds, marking a significant shift from previous practices where overseas accounts in Southeast Asia were preferred. This change is driven by intensified crackdowns on scam centers in countries like Myanmar, Cambodia, and Laos, according to BioCatch's Digital Banking Fraud Trends in India 2026 report.
Shift from Overseas to Local Mule Accounts
Over the past two years, the report highlights a noticeable shift in the routing of fraud proceeds. Previously, mule accounts receiving these transfers were located in other Southeast Asian countries. However, data now shows a substantial increase in transfers to potential lower-level mule accounts within India. This trend underscores how enforcement actions have displaced rather than dismantled fraud networks.
The United Nations Office on Drugs and Crime (UNODC) has led operations against scam centers in Myanmar, Cambodia, and Laos, but these have pushed criminal networks to adopt more distributed operating models. These models are supported by wider money-laundering networks, data brokers, malware providers, deepfake and AI-driven services, and other crime-as-a-service facilitators, the report notes.
Mule-as-a-Service Model
BioCatch explains that most scam center operations now depend on recruiting lower-level mules and mule handlers within India. This "mule-as-a-service" infrastructure consolidates stolen funds, converts them into cryptocurrency, and routes them to wallets associated with scam centers. Mule accounts often appear legitimate because they belong to real customers using valid credentials and authorized transactions. Suspicious activity becomes apparent only when banks analyze behavioral, session, device, and network intelligence together rather than viewing transactions in isolation.
The report emphasizes that with mule networks becoming more organized, proactive detection will depend on connecting behavioral, device, and network intelligence in real time. Banks need to detect mule activity much earlier in the account lifecycle to prevent fraud before customers lose money.
Government Initiatives to Combat Mule Accounts
The findings come as the Indian government has stepped up efforts to curb the use of mule accounts in cyber fraud. In May 2026, the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs signed a Memorandum of Understanding with the Reserve Bank Innovation Hub (RBIH) to strengthen AI-based detection of mule accounts through intelligence sharing from the I4C's Suspect Registry.
Union Home Minister Amit Shah stated that "mule accounts are big hurdles in curbing cybercrimes." According to a Lok Sabha reply by the Ministry of Home Affairs, as of January 31, 2026, the I4C's Suspect Registry had identified and shared details of 27.37 lakh Layer-1 mule accounts with participating entities, helping prevent transactions worth more than Rs 9,518 crore.
Detection Challenges and Recommendations
BioCatch's analysis reveals that mule accounts often blend in with normal banking activity, making them hard to detect through traditional transaction monitoring alone. The shift to India-based accounts means that fraudsters are leveraging local banking infrastructure, including payment rails, devices, and SIM cards, to launder money. The report recommends that banks employ advanced analytics combining behavioral, device, and network intelligence in real time to identify suspicious patterns early.
The report concludes that while enforcement actions have disrupted some scam centers, they have also pushed criminals to innovate. The increasing reliance on India-based mule accounts signals a need for heightened vigilance among Indian banks and law enforcement agencies. Collaborative efforts, such as the I4C-RBIH partnership, are crucial to staying ahead of evolving fraud tactics.



