TL;DR: Mule account activity is increasingly organised as a networked fraud pattern, with rapid transfers, layered movement and distributed payouts making account-level monitoring too slow and too narrow, according to Fingerprint. The core problem is not the transaction itself but the coordinated relationship between accounts, devices and infrastructure, which is where fraud governance now needs to evolve.
NHIMG editorial — based on content published by Fingerprint: LLMjacking: How Attackers Hijack AI Using Compromised NHIs
By the numbers:
- Nearly €9.4 million was laundered through mule accounts in the 12 months leading up to mid-2025, according to the Banking & Payments Federation Ireland.
- Fingerprint says its device intelligence platform collects more than 100 signals from browsers, devices, and networks to build persistent visitor identifiers.
Questions worth separating out
Q: How should fraud teams detect mule account networks instead of isolated suspicious accounts?
A: Fraud teams should combine transfer timing, beneficiary chains, device fingerprints, and infrastructure signals to identify connected account clusters.
Q: Why do KYC checks miss many mule account cases?
A: KYC validates identity at onboarding, but mule abuse often begins after a legitimate-looking account is opened.
Q: What breaks when transaction monitoring cannot see account relationships?
A: It misses the layer where the fraud actually lives.
Practitioner guidance
- Implement network-aware mule detection Correlate incoming transfer bursts, rapid outbound movement, and linked beneficiary patterns across multiple accounts before deciding on account-level disposition.
- Add persistent device correlation to fraud workflows Link browser and device fingerprints to fraud cases so investigators can see when one operator is cycling through many accounts from the same environment.
- Separate onboarding verification from ongoing abuse monitoring Treat KYC as an entry control, not a fraud outcome.
What's in the full article
Fingerprint's full article covers the operational detail this post intentionally leaves for the source:
- How its device intelligence platform links 100-plus browser, device, and network signals into persistent visitor identifiers.
- The Smart Signals combination it uses for VM detection, proximity location, bot detection, and developer tool usage.
- Examples of how shared device activity and network clustering surface mule rings that transaction monitoring misses.
- The fraud-investigation workflow details behind account linkage and cluster-based analysis.
👉 Read Fingerprint’s analysis of mule account networks and device intelligence →
Mule account networks: what fraud teams miss without device signals?
Explore further
Account-level fraud control is no longer sufficient. Mule activity defeats monitoring when each transaction looks benign in isolation but becomes suspicious only across a network of accounts. That means the control failure is not just weak rules, but a programme design that treats the account as the unit of risk. Fraud teams should move toward network-aware detection and investigation.
A question worth separating out:
Q: Who is accountable when a verified account is used as a mule?
A: Accountability is shared across onboarding, fraud operations, and platform risk ownership. Verification controls may have worked correctly at opening, but if ongoing monitoring fails to detect layering, the control gap sits in lifecycle oversight. Regulators and internal reviewers will usually ask whether the institution had continuous detection, not just initial proofing.
👉 Read our full editorial: Mule account networks expose the limits of account-only fraud detection