What is a UPI mule account?
A UPI mule account is a real, KYC-verified bank account whose UPI VPA (e.g.,deposit88@ybl) has been handed to fraudsters and is actively used as a collection point for stolen money. The account passes every identity check because it belongs to a real person — what makes it a mule is how it is used, not who it belongs to.
Mule accounts serve as the first stop in a money-laundering chain. Once funds arrive, they are immediately broken up and forwarded to a second or third layer of accounts, crypto wallets, or cash withdrawal points — a process sometimes completed in under two minutes, long before a victim or bank can raise an alert.
The term “mule” comes from the role the account plays: carrying illicit funds across the financial system on behalf of the fraudster, shielding the real beneficiary from direct exposure.
How mule accounts are used
When a fraud operation — an illegal betting site, a scam investment app, or a phishing campaign — needs to collect payments, it needs a real UPI VPA to show victims. The fraudster posts that VPA as the “deposit address” on their platform. Victims send money to it believing they are paying for a legitimate service or investment. The mule account holder’s bank receives the transfer, and within seconds a second UPI transfer or IMPS move drains it forward. A single mule VPA can process tens of thousands of rupees per hour during a live fraud campaign, then go dormant until the next operation.Why traditional fraud checks miss them
Standard payee-screening methods check whether:- The VPA resolves to a real, active bank account ✅
- The account holder’s name matches KYC records ✅
- The account has no prior dispute or freeze flag ✅
How FraudTrace detects mule accounts
FraudTrace runs a continuous OSINT (open-source intelligence) pipeline that crawls and monitors the sites and channels where fraud actually happens. When a VPA appears as a deposit address on any monitored source, FraudTrace:- Extracts the VPA and surrounding context (page category, timestamp, co-occurring VPAs)
- Takes a screenshot and archives the evidence
- Computes a confidence score (0.0–1.0) based on the number and quality of sightings
- Assigns the VPA to a cluster of related accounts
- Makes the record available for real-time lookup via the
/v1/verify/upiAPI
The mule lifecycle
Understanding the lifecycle helps you decide at which stage to apply FraudTrace screening.1
Recruitment
Fraudsters recruit mule account holders through Telegram groups, social media job ads (“earn ₹500 per transaction — just share your UPI”), or by compromising existing accounts through phishing. The recruited person shares their UPI VPA and, sometimes, net banking credentials.
2
Activation
The VPA is published on fraud infrastructure: a gambling or betting site’s deposit page, a Telegram channel pinned message, a phishing landing page, or a fake investment app. This is the moment FraudTrace’s crawlers first detect it.
3
Flagging by FraudTrace
FraudTrace indexes the VPA, links it to its source(s), scores its confidence, and clusters it with related accounts. The record becomes queryable immediately. Banks and fintechs that run pre-transaction screening will now receive a
FLAGGED response for any payment to this VPA.4
Fraud campaign runs
Victims make payments to the VPA. Each new sighting on additional sources increases the confidence score. Cluster membership may expand as co-appearing VPAs are discovered.
5
Detection and blocking
Every bank or fintech integrated with FraudTrace that screens outgoing payments catches the VPA at this step and blocks or escalates the transaction before funds leave the sender’s account.
6
Dormancy or rotation
After a campaign ends or the account is frozen by the mule’s bank, the VPA goes dormant. FraudTrace retains the historical record. Fraudsters often rotate to new mule accounts — which restart the lifecycle at step one.
How this protects your customers
By integrating FraudTrace into your payee-screening flow, you intercept the fraud signal at the exact point where it can still be acted on — before the payment instruction is submitted to NPCI. This means:- Banks can block or step-up-authenticate outgoing UPI transfers to flagged VPAs
- PSPs and wallets can surface an in-app warning before the user confirms payment
- Fintechs can refuse to onboard a merchant VPA that appears in the mule database