The KYC Mule: When Verified Identity Becomes the Product

When police in Minnesota subpoenaed Binance last year, after a father lost $1.5 million to a romance investment scam, the exchange included two account files. One belonged to a woman with a home address in a small Chinese village; paperwork showed she had moved around $7 million through the account in a few months. The other belonged to a 24-year-old woman with a home address in rural Myanmar, who had moved more than $2 million over nine months — over 1,000 times the average annual salary there. In both cases, the women are likely money mules, individuals whose personal data may have been harvested and used by scammers to open the accounts in the first place. It is uncertain whether either woman knew her name was on an account moving scam proceeds.

That uncertainty is becoming more of the main story. Last year, reporters from The Times and the International Consortium of Investigative Journalists spent a year tracing at least $28 billion tied to illicit activity into major crypto exchanges — Binance, OKX, Bybit, HTX and others. A meaningful share of that money moved through accounts that had already cleared know-your-customer (KYC) checks and were opened in the names of real people. The question the investigation couldn’t always answer is the one that matters most for anyone trying to stop it: whether the person on file for the account ever knew what it was being used for.

Second-Party Fraud

Fraud teams have long sorted account fraud into two buckets. First-party fraud is when the account holder is the fraudster — someone misrepresents their own creditworthiness, or disputes a charge they authorized. Third-party fraud is when a stranger opens or seizes an account in someone else’s name without that person’s knowledge — classic identity theft or account takeover.

The accounts behind the Minnesota case, and the meaningful share of money traced in the investigation, sit in a category in between, one that risk teams have a name for but rarely build controls around: second-party fraud. This is where the account is real and either a verified owner knowingly, semi-knowingly or unknowingly lets someone else operate it. Nothing is stolen in the traditional sense. The person who passed the check handed the keys to someone else — for money, under pressure or without fully understanding what they had agreed to.

In fraud, a money mule moves someone else’s money. A KYC mule is an emerging term for what comes one step earlier, moving a verified identity. The job here is to look legitimate long enough to clear KYC or security checks, then transfer the resulting account over to whoever paid for it.

Two Ways In — and a Third You Can’t Always Rule Out

There are two distinct ways a launderer ends up holding an account that was never theirs, and conflating them misdirects the defense. The first is synthetic: a fabricated identity or a real person’s stolen data, paired with forged documents or a deepfaked selfie, designed to defeat a verification system built to catch exactly that. Liveness checks, document forensics and deepfake detection exist because of this route, and they work reasonably well against it.

The second route doesn’t try to beat the check at all. A real person, using their own name, face and documents, opens the account and passes verification cleanly because they are exactly who they say they are. What happens next is where the fraud lives. Some are paid outright: recruitment ads offering quick cash to rent a bank account or a gig-work profile are common enough that consumer-protection regulators publish warnings about them

Some are duped: told they are helping a new employer receive a payroll deposit or assisting a foreign business partner, with no idea that the money is the proceeds of a scam. And some are coerced: reporting on Southeast Asia’s scam compounds has documented workers trafficked into these operations and forced to run accounts and scripts under threat.

An investigator working from the account alone often can’t tell a rented identity from a stolen one. That reflects the actual state of the evidence in most of these cases. Account behavior often cannot reliably distinguish a complicit participant from a victim, so effective controls should account for that evidentiary ambiguity rather than depend on a clean categorical split.

Verification Answers the Wrong Question

Every version of this exploits the same design gap. Identity verification answers one question at one moment: is this a real, eligible person opening this account? It was never built to answer the question that determines everything after: is the person operating this account still the person who was verified?

NIST’s digital identity guidelines have always kept the two questions apart, scoring identity proofing at enrollment and authentication over the life of the account on separate scales in separate documents. The architecture assumes something is watching after the first check clears.

Gartner’s Continuous Adaptive Risk and Trust Assessment framework, CARTA, explains that the underlying principle is that trust is neither binary nor static. Trust rises and falls with behavior and context, and a one-time verdict, by definition, cannot do that. The interval between that verdict and the next time anyone looks is exactly the space the rental market operates in — and exactly the space Binance’s own compliance team was working from when they could only hand over a photo and an address, not an answer.

The Same Asset, Priced in Banking

Regulators outside of crypto are starting to treat this as its own category of exposure, and not a subset of ordinary fraud. The Reserve Bank of India proposed in April to cap how much money can flow into a newly verified account before triggering a fresh check: annual credits above 2.5 million rupees (about $28,000) would sit as a shadow credit; the customer can see it but cannot spend it, released only after the bank re-verifies the relationship and reversed after 30 days if it can’t.

Operation Chakra-V, a sweep the Central Bureau of Investigation ran across 42 locations in five states in June 2025, found roughly 850,000 mule accounts opened at more than 700 bank branches without proper KYC checks or customer due diligence. The Indian Cyber Crime Coordination Center had flagged about 2.5 million first-layer mule accounts by early 2026. Europol’s European Money Mule Action, a coordinated international sweep, identified 8,755 money mules and 222 recruiters over three months in 2022 and made 2,469 arrests. A ratio of 222 recruiters to 8,755 accounts describes a supply chain rather than a scattering of opportunists.

Handover Leaves Evidence

A handover leaves a trail, even when the identity behind the account never changes, and even when no one can say how willingly it changed hands. The earliest signals are mechanical: a login from an unfamiliar device or emulator, an IP address that no longer matches the account’s history even behind a familiar proxy, a burst of password, recovery email or phone number changes clustered in the hours after that first unfamiliar login.

Behavioral signals are harder for a buyer to fake, but slower to firm up, since a single onboarding session leaves only a thin baseline. Heavier onboarding doesn’t reach any of this. The friction lands on the legitimate applicant standing in front of you, never on the person who takes over the account next month with credentials that have already been cleared. The workable answer is to treat identity as a signal that continues to be reported after approval, not as a question settled once at the door.

Who Is Renting the Account

Money launderers have already priced what most institutions still treat as settled at onboarding: a verified identity and the person using it are two separate facts, and only one of them was ever checked. Whether that separation happened by payment, by deception, by coercion or by theft may never be knowable from the account alone — which is exactly why the response can’t depend on knowing it.

The same defect shows up wherever a checked identity outlives the check, which is why gig-work platforms that feed AI models are fighting an almost identical rental market for a different kind of account. In every version, the buyer isn’t paying for access. They are paying for a clean history somebody else already built, attached to a check that will never be asked to run twice.

Take the First Step Toward Transformative Fraud Prevention