FinHub Risk & Fraud Desk
Fraud & risk analytics · 24 March 2026 · 9 min read
Last updated 16 August 2026
Two fraud patterns dominate India's digital-lending and payments risk conversations: mule accounts and synthetic identities. They're distinct problems, but they often appear together, and document verification alone catches neither. Understanding how they work — and how the ecosystem is responding — is the starting point for defending against them.
What a mule account is
A mule account is a bank account used as an intermediary in financial crime. Fraud proceeds land in it and are quickly moved onward — often split across many accounts and layered through several hops — to obscure the trail and defeat recovery. The account holder may be complicit (renting out their account) or an unwitting victim recruited through a fake job or 'investment' scheme. Investigators describe the first accounts to directly receive victim funds as 'Layer-1' mule accounts, since the money is layered outward from there.
What a synthetic identity is
Synthetic identity fraud fabricates a person who doesn't exist by combining real and fake data. A common recipe pairs a genuine identifier — say, a real PAN — with a fabricated name, address and phone number. The result passes point-in-time document checks because the individual elements look legitimate, but the composite 'person' is fictional. Fraudsters build these identities up, pass eKYC at multiple lenders, draw small-ticket loans or BNPL credit, and default with no real person to pursue. This is distinct from first-party fraud, where a genuine applicant misrepresents their own details or never intends to repay.
The regulatory and ecosystem response
India's response has moved quickly from rules to active detection. The RBI, through the Reserve Bank Innovation Hub, built MuleHunter.AI — an AI/ML system that analyses transaction and account behaviour to flag mule accounts, trained by studying a wide set of distinct mule-account behaviour patterns. It moves detection beyond static rules, and adoption has spread across a growing number of banks (well over twenty had implemented it by late 2025, with continued expansion since). In parallel, the Indian Cyber Crime Coordination Centre (I4C) has flagged millions of suspected Layer-1 mule accounts and coordinated freezes, and has been onboarding banks to shared fraud-intelligence infrastructure so signals can be acted on across institutions rather than in isolation.
Why documents alone don't catch either
Both patterns are engineered to survive document checks. A mule account is a real account with real KYC. A synthetic identity is assembled from elements that individually verify. The signals that actually catch them sit outside the document.
The signals that work
Cross-field consistency is the first layer: does the PAN name match the Aadhaar name match the application name? Synthetic identities frequently fail this fuzzy cross-check even when each document is individually valid. Bank-account verification with name-match catches disbursal accounts that don't belong to the borrower — a mule tell. Beyond identity, device and behavioural intelligence adds signals documents can't: a single device tied to many applications, emulators and remote-access tools, spoofed location or impossible-travel patterns, and SIM-age or phone-number-tenure anomalies. Behavioural biometrics — typing rhythm, navigation hesitation, how a form is actually filled — help distinguish a genuine applicant from a scripted or coached session. And at the network level, graph analytics surface rings: accounts and identities that cluster around shared devices, addresses or money flows.
Layered defence, not a single check
No single control is sufficient. The institutions with the lowest fraud losses combine identity cross-verification, account verification, device and behavioural signals, and network analytics — then route only genuinely ambiguous cases to human review. The goal isn't to add friction for everyone; it's to concentrate scrutiny where the signals actually point.
FinHub brings these layers together — PAN and Aadhaar name-matching, bank-account verification, and AML screening — so you can catch the fraud that clean-looking documents are designed to hide.