In September 2026, a resident of Peenya in Bengaluru reported losing ₹.93.58 lakh to an online trading scam. One victim, one fake investment app. When the Bengaluru Cyber Crime Police followed the money, it did not lead to one account. It led to 507.

Every one of those accounts was real. Every holder was a real person who had passed KYC. The pool included current, corporate and trust accounts, each with its own SIM. Holders had reportedly been paid ₹.1.5 lakh to ₹.2 lakh each to hand them over. Three people were arrested on 8 and 9 September, and six phones were recovered running SMS forwarding apps that pushed OTPs and bank alerts to the operators. Digital links reached Kolkata, Hong Kong and California.

The problem: KYC answers the wrong question

A mule account is a legitimate bank account used to receive, hold or forward the proceeds of fraud on behalf of someone else. The RBI’s September 2026 draft KYC amendment uses the same definition: an account used, knowingly or unknowingly, to receive, layer or transfer the proceeds of cyber enabled financial fraud for another person.

The word that matters is layer. A single large transfer to a single account gets frozen within hours. Spread it across hundreds of accounts, move it again, convert part of it to crypto, and no account holds enough for long enough to trip a freeze. That is what 507 accounts buy: time.

Here is the uncomfortable part. Nothing in the KYC process failed. KYC asks one question: is this a real, identifiable person? For all 507, the answer was yes. The documents were real. The face match passed. The phone received the OTP. The checks did what they were designed to do.

The things that were actually wrong were never checked:

  • Whether the phone number on the account was already known to fraud registries or rated high risk by the telecom department.
  • Whether the person who passed KYC would be the person operating the account, or whether control had moved to someone else via SIM handover or a forwarding app.
  • Whether the bank account added for payouts actually belonged to the verified person.
  • Whether hundreds of unrelated applicants shared the same devices, number histories, referral paths or timing.

Identity verification confirms a person exists. It does not tell you whether that person, that number and that account should be trusted together. The Bengaluru case is the gap between those two questions, at scale.

How Secure ID closes the gap

Cashfree Secure ID adds a risk layer on top of identity verification, at the two moments that matter most: when the account is opened and before the first payout. Each check removes a slice of a mule network, and the slices compound.

Phone Risk Intelligence at signup. Before the OTP is even sent, the number is checked against the DoT’s revocation list, the Financial Fraud Risk Indicator and cybercrime complaint data, and read for age, recycling, activity pattern and network quality. Mule networks reuse numbers and SIM pools, so a number that is three weeks old, recently recycled, or mostly connected to known spam numbers is a flag before any money moves. The forwarding app phones in the Bengaluru case were ordinary handsets with ordinary numbers; their histories were not.

Reverse Penny Drop and UPI Penny Drop before the first payout. The customer approves a ₹1 UPI payment with their PIN, or shares a UPI ID, and the rail returns the account number, IFSC and name at the bank. The account is proven to belong to the person you verified, because they just controlled it. That closes the gap between the identity and the account, and leaves a clean ownership record for the day the police ask.

Mule Sentinel at the gate. This is where the Bengaluru pattern becomes visible. Mule Sentinel reads behavioural, transactional and network signals across five dimensions and returns a 0 to 100 Mule Score at onboarding. Shared devices, fresh accounts, number histories and profile mismatches raise the score before the applicant is approved. The question it asks is not who this is, but should you trust them in the first place.

All three run through the same Secure ID integration, so a lender, marketplace or platform can step up a risky applicant, ask for more, or decline, in the same session, without adding a form.

Why this matters for your business

You may never see a case this size. You will see its pieces: a new seller whose payout account was added yesterday, a borrower whose number was issued a month ago, a customer whose profile does not match the way they transact. The 507 accounts in Bengaluru were, at some point, 507 ordinary onboardings at ordinary institutions. Each one passed.

KYC is not broken. KYC is the floor. The decisions that protect your money happen in the layer above it, and that layer is what Secure ID is for.


Would your next applicant pass the mule check?

Run your onboarding flow through Mule Sentinel and see what KYC alone may miss.

Connect with us  →

FAQs

What happened in the Bengaluru 507 mule account case? In September 2026 Bengaluru Cyber Crime Police investigated a ₹93.58 lakh online trading scam reported by a Peenya resident and traced the money to 507 mule bank accounts. Three people were arrested on 8 and 9 September 2026 and six phones with SMS forwarding apps were recovered.

What is a mule account? A real bank account used to receive, hold or move money from fraud on behalf of someone else. The holder may be paid, deceived, or may have sold the account.

Why do mule accounts pass KYC? Because the holder is a real person with genuine documents. KYC verifies identity. It does not verify who controls the account afterwards or how it will be used.

How do fraudsters control mule accounts remotely? By taking the SIM, or by installing SMS forwarding apps so OTPs and bank alerts reach the operator. Six such phones were recovered in the Bengaluru case.

How can businesses detect mule accounts before onboarding? By checking phone numbers against revocation and fraud risk data, verifying bank account ownership through the payment rail, and scoring applicants on behavioural, transactional and network signals before approval. Cashfree Secure ID covers these with Phone Risk Intelligence, Reverse Penny Drop and UPI Penny Drop, and Mule Sentinel.

What is the RBI doing about mule accounts? In September 2026 the RBI published a draft KYC amendment with a standard procedure for suspected mule accounts: a temporary debit hold, customer notice, 20 days to explain, 10 days to decide, and a 60 day outer limit, proposed to take effect on 1 April 2027.

Author

Get 0% MDR*

Discover more from Cashfree Blog

Subscribe now to keep reading and get access to the full archive.

Continue reading