Skip to main content
A UPI mule account is an ordinary-looking bank account that fraudsters have co-opted to receive and rapidly forward stolen funds. The account holder is often a willing recruit or an unwitting victim of social engineering, and the account itself clears every standard KYC check — making mule detection one of the hardest problems in payment fraud. FraudTrace solves it not by looking at the account in isolation, but by tracing where the VPA (Virtual Payment Address) has appeared across the open internet: gambling deposit pages, scam Telegram channels, phishing portals, and dark-web forums.

What is a UPI mule account?

A UPI mule account is a real, KYC-verified bank account whose UPI VPA (e.g., deposit88@ybl) has been handed to fraudsters and is actively used as a collection point for stolen money. The account passes every identity check because it belongs to a real person — what makes it a mule is how it is used, not who it belongs to. Mule accounts serve as the first stop in a money-laundering chain. Once funds arrive, they are immediately broken up and forwarded to a second or third layer of accounts, crypto wallets, or cash withdrawal points — a process sometimes completed in under two minutes, long before a victim or bank can raise an alert.
The term “mule” comes from the role the account plays: carrying illicit funds across the financial system on behalf of the fraudster, shielding the real beneficiary from direct exposure.

How mule accounts are used

When a fraud operation — an illegal betting site, a scam investment app, or a phishing campaign — needs to collect payments, it needs a real UPI VPA to show victims. The fraudster posts that VPA as the “deposit address” on their platform. Victims send money to it believing they are paying for a legitimate service or investment. The mule account holder’s bank receives the transfer, and within seconds a second UPI transfer or IMPS move drains it forward. A single mule VPA can process tens of thousands of rupees per hour during a live fraud campaign, then go dormant until the next operation.

Why traditional fraud checks miss them

Standard payee-screening methods check whether:
  • The VPA resolves to a real, active bank account ✅
  • The account holder’s name matches KYC records ✅
  • The account has no prior dispute or freeze flag ✅
All three checks pass for a mule account at the time of recruitment, because the account is legitimate. The fraud signal lives entirely outside the banking system — on a gambling site’s deposit page or inside a Telegram channel — and never appears in any CIBIL, CKYC, or internal bank database.

How FraudTrace detects mule accounts

FraudTrace runs a continuous OSINT (open-source intelligence) pipeline that crawls and monitors the sites and channels where fraud actually happens. When a VPA appears as a deposit address on any monitored source, FraudTrace:
  1. Extracts the VPA and surrounding context (page category, timestamp, co-occurring VPAs)
  2. Takes a screenshot and archives the evidence
  3. Computes a confidence score (0.0–1.0) based on the number and quality of sightings
  4. Assigns the VPA to a cluster of related accounts
  5. Makes the record available for real-time lookup via the /v1/verify/upi API
When your payment system queries that VPA before processing a transaction, FraudTrace returns the flag in under 200 ms — fast enough to act before the payment completes.

The mule lifecycle

Understanding the lifecycle helps you decide at which stage to apply FraudTrace screening.
1

Recruitment

Fraudsters recruit mule account holders through Telegram groups, social media job ads (“earn ₹500 per transaction — just share your UPI”), or by compromising existing accounts through phishing. The recruited person shares their UPI VPA and, sometimes, net banking credentials.
2

Activation

The VPA is published on fraud infrastructure: a gambling or betting site’s deposit page, a Telegram channel pinned message, a phishing landing page, or a fake investment app. This is the moment FraudTrace’s crawlers first detect it.
3

Flagging by FraudTrace

FraudTrace indexes the VPA, links it to its source(s), scores its confidence, and clusters it with related accounts. The record becomes queryable immediately. Banks and fintechs that run pre-transaction screening will now receive a FLAGGED response for any payment to this VPA.
4

Fraud campaign runs

Victims make payments to the VPA. Each new sighting on additional sources increases the confidence score. Cluster membership may expand as co-appearing VPAs are discovered.
5

Detection and blocking

Every bank or fintech integrated with FraudTrace that screens outgoing payments catches the VPA at this step and blocks or escalates the transaction before funds leave the sender’s account.
6

Dormancy or rotation

After a campaign ends or the account is frozen by the mule’s bank, the VPA goes dormant. FraudTrace retains the historical record. Fraudsters often rotate to new mule accounts — which restart the lifecycle at step one.

How this protects your customers

By integrating FraudTrace into your payee-screening flow, you intercept the fraud signal at the exact point where it can still be acted on — before the payment instruction is submitted to NPCI. This means:
  • Banks can block or step-up-authenticate outgoing UPI transfers to flagged VPAs
  • PSPs and wallets can surface an in-app warning before the user confirms payment
  • Fintechs can refuse to onboard a merchant VPA that appears in the mule database
Screen VPAs at the moment a user adds a new payee, not just at the point of transaction. Blocking a mule VPA from being saved to a contact list prevents the entire future payment attempt.
A CLEARED response means the VPA has not been observed on any source monitored by FraudTrace. It is not a guarantee of legitimacy. Apply your own additional risk controls for high-value transactions.