Cyber fraud: How customers can prevent their bank accounts from being used as mule accounts
Three people were recently arrested in Delhi for allegedly supplying and using mule bank accounts to facilitate cyber fraud. According to the allegations, the account holders provided access to their bank accounts to receive proceeds from cyber fraud in exchange for commissions.
In a separate case, police in Maharashtra’s Thane district busted a cyberfraud syndicate allegedly involved in fraudulent transactions worth ₹57.25 crore through several mule accounts.
A mule account is a bank or financial account used by criminals to receive, hold or transfer illegally obtained money. Such accounts can be operated by the criminals themselves or by individuals who knowingly or unknowingly allow their accounts to be used for suspicious transactions.
Customers can become involved in such arrangements through fake job offers, easy-money schemes, fraudulent investment opportunities or low-interest loan offers. Unused or dormant bank accounts can also pose a risk if they are not regularly monitored.
Experts advise customers to be particularly cautious about unsolicited job offers, schemes promising easy money and requests to “rent” or “lend” a bank account.
Never allow anyone else to use your bank account
Shailendra Awasthi, Leader Technology at chartered accountancy firm Bhuta Shah & Co LLP, said customers should not treat their bank accounts as facilities that can be lent to others.
“The biggest mistake customers make is treating their bank account as a facility that can be ‘lent’ to someone else. Your bank account should only be used for transactions that you personally understand and are responsible,” Awasthi said.
He advised customers never to allow another person to use their account to receive or transfer money, even if they are promised a commission.
According to Awasthi, fraudsters are increasingly recruiting people through fake jobs, investment opportunities, social media and messaging platforms and asking them to receive and transfer funds.
He added that such money-mule arrangements can result in account suspension, financial losses and potential legal consequences.
Do not leave dormant bank accounts unmonitored
Paritosh Desai, Chief Product Officer and Chief Marketing Officer at IDfy, said customers should treat their bank accounts like any other financial credential.
“An account that is rarely used should not be left unmonitored, as fraudsters may attempt to gain access to dormant or low-activity accounts through phishing, social engineering or by offering money in exchange for account access,” Desai said.
“If an account is no longer required, consider formally closing it rather than leaving it dormant and unattended,” he added.
What should you do if your account is used for cyber fraud?
Customers who suspect that their bank account has been used in a fraudulent transaction should act immediately.
The first step should be to contact the bank and report the suspicious activity. Customers should ask the bank to secure the account and provide guidance on the next steps.
If an unauthorised transaction is detected, the incident should also be reported immediately through 1930, the National Cyber Crime Helpline, and the National Cyber Crime Reporting Portal.
The Reserve Bank of India (RBI) advises customers to report unauthorised electronic transactions to their bank at the earliest. Prompt reporting can help limit the risk of financial loss.
Simple precautions to protect your bank account
Experts recommend the following precautions to reduce the risk of cyber fraud:
- Never share internet banking credentials, OTPs, PINs, passwords or UPI PINs with anyone.
- Do not hand over your debit card, cheque book, SIM card or banking credentials to another person to operate your account.
- Never receive money into your account and transfer it to a third party merely in exchange for a commission.
- Regularly check SMS and email alerts and bank statements, especially for dormant or rarely used accounts.
- Keep your KYC details and registered mobile number and email address updated with the bank.
- If an unexpected credit appears in your account, do not transfer the money based on instructions from an unknown caller. Contact the bank through its official channel and seek guidance.
What precautions should customers take during eKYC or video KYC?
Customers should exercise the same level of caution during eKYC and video KYC as they would while visiting a physical bank branch, Awasthi said.
KYC should be initiated only through the bank or financial institution’s official website, mobile application or a verified communication channel.
Customers should not click on KYC links received from unknown WhatsApp numbers, SMS messages, emails or social-media accounts.
A genuine KYC process should not require customers to disclose their OTP, UPI PIN or password to an individual.
Customers should also avoid completing KYC procedures over public Wi-Fi or using an unknown or shared device, particularly when sensitive identity documents are involved.
Key takeaway for bank customers
A bank account should never be rented, lent or used to receive and transfer money on behalf of another person in exchange for a commission. Regular monitoring of accounts, including dormant accounts, can help customers identify suspicious activity early.
If an account holder notices an unauthorised transaction or suspects that the account has been linked to cyber fraud, reporting the matter to the bank and the cybercrime authorities immediately can help establish that the activity was not knowingly authorised and limit potential losses.