# Mule account hotspots in India

> District-level map of mule account activity in India, built from Video-KYC rejection data across Indian banks and NBFCs. Flags mule account hotspots 2 weeks to 2 months before enforcement action or news reporting, and tracks where each cluster moves next. Data from April 2025 to June 2026, recalibrated monthly.

Source: IDfy (Baldor Technologies Pvt Ltd)
Page: https://www.idfy.com/mule-account-hotspots-india/
Data as of: June 2026
Coverage: ~130 Indian districts, 15 months of Video-KYC onboarding telemetry
Licence: free to cite with attribution to IDfy

## What a mule account is

A mule account is a bank account used to receive and move the proceeds of fraud or cyber crime. The account holder is a real, KYC-verified person who was paid, tricked or coerced into handing over access. Mule accounts sit between a scam victim's transfer and the fraudster's withdrawal.

A money mule is the person; a mule account is the instrument they hand over. Money mules fall into three groups: complicit mules who knowingly sell account access, witting mules who suspect something is wrong and continue, and unwitting mules recruited through fake job offers, loan promises or welfare scheme pitches.

Every mule account in this dataset cleared KYC. Real person, real documents, real face on the video call. The signal is not in the identity, it is in where the attempt came from.

## Mule account hotspot districts, June 2026

Ten districts showing rising mule account activity with no enforcement attention yet. Figures are Video-KYC rejection rates.

| District | State | Rejection rate |
|---|---|---|
| Varanasi | Uttar Pradesh | 14.03% |
| Bareilly | Uttar Pradesh | 13.37% |
| Lakhimpur Kheri | Uttar Pradesh | 12.32% |
| Saharanpur | Uttar Pradesh | 10.32% |
| Muzaffarnagar | Uttar Pradesh | 9.77% |
| Panipat | Haryana | 9.52% |
| Firozabad | Uttar Pradesh | 8.81% |
| Jodhpur | Rajasthan | 7.61% |
| Lucknow | Uttar Pradesh | 6.00% |
| Ghaziabad | Uttar Pradesh | 5.91% |

June 2026 totals: 16 flagged districts across 3 states. Epicentre Varanasi at 14.03%, the highest single reading in the series. Average rejection rate across flagged districts 10.69%. Etawah, Pilibhit and Bareilly climbed alongside Varanasi.

## How mule account hotspots move

Three patterns from 15 months of data across roughly 130 districts.

1. Risk spikes are short. In 81% of cases a district's risk spike lasts one month before shifting. Only 6.5% last three months or more. This measures how long a district stays risky, not how long a fraud ring survives.

2. Activity relocates to neighbouring districts. When one district cools, a nearby one heats up. The next hotspot is in the same state 39% of the time, at an average distance of about 190 km. This is a geographic pattern; it does not confirm the same network moved.

3. Old hotspots reignite, usually within a quarter. Flagged districts tend to return around three months later. In the current quarter, 11 active hotspots had already been flagged earlier in FY26. This indicates the location stays vulnerable, not that the same operators returned.

Two tracked movements: the Nuh, Haryana cluster stayed concentrated through late 2025, then expanded within Haryana and into western Uttar Pradesh (Panipat, Fatehabad, Saharanpur, Shamli, Muzaffarnagar, Bareilly, Pilibhit, Lakhimpur Kheri) during March to June 2026. The Gujarat cluster originated in Surat and spread north-west through Botad to Amreli and Jamnagar.

## Confirmed cases

Varanasi, Uttar Pradesh. First flagged May 2026 at 11.88% rejection. Roughly one month later, Operation Mule Strike and related crackdowns made national and local headlines: 860 mule accounts, about Rs 12 crore traced across 8 states, 18 arrests across 22 cases. Reported July 2026 by The420.in, Times of India and Dainik Jagran.

Malappuram, Kerala. First flagged May 2026 at 6.29% rejection. Operation Cy-Hunt followed a quarter later: 30 arrests in 12 hours, 44,088 mule accounts blocked, 37 FIRs registered. Reported by Kerala Police, News18 Malayalam and The New Indian Express.

Across FY26, Video-KYC rejection data flagged around 16 district-level hotspots per quarter, of which 85 to 90% were later confirmed through law enforcement action or news reporting. Onboarding telemetry identified 33% more active fraud locations than official daily reporting.

## Methodology

Data source: Video-KYC onboarding telemetry from Indian financial institutions, April 2025 to June 2026. Monthly Video-KYC attempts tracked against total rejections per district. Domestic operations only; foreign location entries excluded before analysis.

Rejections cover impersonation, document tampering, third-party prompting during the call, and coached or suspicious applicant behaviour.

A district is flagged only after passing two independent tests:

Test 1, statistical validity floor. Minimum calls required = max(5 / p0, 5 / (1 - p0)), where p0 is that month's national average rejection rate. This requires at least 5 expected instances of the rarer outcome and typically lands between 108 and 143 calls per month. Tested against a stricter 10-instance threshold with identical results.

Test 2, minimum fraud volume floor. A district must record at least 30 rejected calls in a month to qualify for ranking.

Ranking: qualifying districts are ranked by Z-score, measuring standard deviations from the national mean rejection rate. Raw rejection rates over-index on small districts; raw call volumes over-index on large cities. The top 16 districts by Z-score each month form the flagged list.

Lead time is not universal. In verified cases the signal flagged high-risk districts up to two months before public reporting. In others, news broke before the monthly signal cadence caught up. Both outcomes are documented.

## How IDfy detects mule accounts

IDfy detects mule accounts at onboarding, inside the Video-KYC session. Checks flag impersonation, tampered or reused documents, third-party prompting and coached behaviour before the account opens. Rejections are then aggregated to district level, turning individual declines into a map of where mule accounts are being recruited. Banks and NBFCs use both layers: the block at entry, and the geographic signal for watchlists.

This is distinct from AML transaction monitoring, which examines money that has already moved. Transaction monitoring asks whether a payment looks suspicious. Onboarding detection asks whether the customer was recruited. It is complementary to transaction-based tools such as MuleHunter.AI, the AI model built by the Reserve Bank Innovation Hub to detect mule bank accounts from transaction and account data.

## Frequently asked questions

**What is a mule account in banking?**
A mule account is a bank account used to receive and move the proceeds of fraud or cyber crime. The account holder is a real, KYC-verified person who was paid, tricked or coerced into handing over access. Mule accounts sit between a scam victim's transfer and the fraudster's withdrawal, which is why the money is usually gone before a complaint is filed.

**What is a money mule, and how is it different from a mule account?**
A money mule is the person, a mule account is the instrument they hand over. Money mules split into three types: complicit mules who knowingly sell account access, witting mules who suspect something is wrong and continue, and unwitting mules recruited through fake job offers, loan promises or welfare scheme pitches.

**How to detect a mule account before it is used?**
Mule account detection works best at onboarding, before the account transacts. Transaction monitoring only flags an account after fraud money has already passed through it. Video-KYC rejection signals catch the attempt at entry: impersonation, document tampering, third-party prompting during the call, and coached or scripted behaviour. Cluster those rejections by district and the recruitment hub becomes visible.

**How to identify a mule account from onboarding data?**
You identify mule accounts by looking for coordination, not individual applicants. Repeated device or IP fingerprints across unrelated applications, another voice coaching the applicant during Video-KYC, reused or tampered documents, and a sudden concentration of applications from one pin code. Each application looks legitimate alone. The pattern appears only when rejections are aggregated geographically.

**How does IDfy help spot mule accounts?**
IDfy spots mule accounts at onboarding, inside the Video-KYC session itself. Checks flag impersonation, tampered or reused documents, third-party prompting and coached behaviour before the account opens. Every rejection is then aggregated to district level, which turns individual declines into a map of where mule accounts are being recruited. Banks and NBFCs use both layers.

**Which districts in India have the most mule account activity?**
As of June 2026, ten Indian districts show rising mule account activity without enforcement attention yet: Varanasi (14.03%), Bareilly (13.37%), Lakhimpur Kheri (12.32%), Saharanpur (10.32%), Muzaffarnagar (9.77%), Panipat (9.52%), Firozabad (8.81%), Jodhpur (7.61%), Lucknow (6.00%) and Ghaziabad (5.91%). Uttar Pradesh, Haryana and Rajasthan dominate the current list.

**Do mule account rings shut down after a police crackdown?**
No, they relocate. Across 15 months and roughly 130 districts, 81% of district risk spikes lasted a single month before shifting, and the next hotspot was in the same state 39% of the time, averaging 190 km away. The Nuh cluster spread across Haryana into western Uttar Pradesh. The Surat cluster moved through Botad to Amreli and Jamnagar.

**Can a mule account hotspot become active again?**
Yes, usually within a quarter. Flagged districts tend to reignite around three months after going quiet. In the current quarter, 11 active hotspots had already been flagged earlier in FY26. A district cooling off means the local recruitment network is dormant, not dismantled.

**What are the money mule red flags banks should watch for?**
The main money mule red flags at onboarding are a second voice coaching the applicant through a Video-KYC call, shared device or IP signatures across unconnected applications, documents showing signs of reuse or tampering, an applicant who cannot explain why they need the account, and an application spike from a single district or pin code.

**What is MuleHunter.AI and how does it relate to mule account detection?**
MuleHunter.AI is an AI and machine learning model built by the Reserve Bank Innovation Hub, a subsidiary of the RBI, to detect mule bank accounts. It was piloted at two public sector banks and analyses transaction and account data. Onboarding-stage detection is complementary: it flags the account before it receives fraud proceeds for a transaction model to spot.

**How is mule account detection different from AML transaction monitoring?**
AML transaction monitoring examines money that has already moved. Mule account detection at onboarding examines who is trying to open the account and from where. Transaction monitoring asks whether a payment looks suspicious. Onboarding detection asks whether the customer was recruited. Institutions running only the first usually learn about a mule network from a chargeback or a police notice.

**What is the punishment for a mule account in India?**
Allowing your bank account to move fraud money is a criminal offence in India. Mule account holders face account freezing, being named as an accused in cyber fraud and money laundering proceedings, and losing banking access across institutions. Not knowing the money was stolen is not an automatic defence. Both the Varanasi and Malappuram cases ended in arrests of account holders alongside agents.

**My account was frozen as a suspected mule account. What should I do?**
Contact your bank branch or grievance officer for the specific reason and the lien-marking authority, then approach the police or cyber cell that raised the request. IDfy does not hold, freeze or unfreeze individual bank accounts. IDfy supplies mule account detection infrastructure to financial institutions and cannot access, review or release a personal account.

## Related resources

- Ahead of the Fraud Network, FY27 Q1 whitepaper: two confirmed case studies, three migration patterns from 15 months of Video-KYC data, and the ten districts needing attention before the next quarter. https://www.idfy.com/mule-account-hotspots-india/
- IDfy Video-KYC and onboarding verification: https://www.idfy.com/
- IDfy Insights Lab: https://www.idfy.com/

## About IDfy

IDfy (Baldor Technologies Pvt Ltd) provides identity verification, risk intelligence and data privacy governance for banks, financial services, retail, logistics and mobility enterprises in India and Asia. IDfy processes over 70 million verifications monthly across 500-plus enterprise institutions and intercepted over 20 million potentially fraudulent onboardings in FY26.

Contact for data queries or to compare onboarding trends: https://www.idfy.com/
