Could a mule account also be a victim account?¶
Yes. An account used to receive and move criminal funds may also belong to a person who has been deceived, coerced or compromised.
Avoid the dangerous assumption¶
The dangerous assumption is that suspicious movement through the account means the holder willingly acted as a money mule.
An offender may take over an existing account through phishing, malware, stolen credentials, SIM swapping or remote-access software.
A victim may also be manipulated into receiving and forwarding money under a false explanation.
They may believe they are processing wages, refunds, investment returns, charitable payments or business transactions.
The account can therefore be both part of the fund movement and evidence of an offence against its holder.
Relevant evidence may include new devices, unusual IP addresses, account recovery, password resets, remote-access software, messages, calls and changes to beneficiaries or contact details.
Compare the disputed activity with the holder’s normal transactions and devices.
Establish who initiated each payment and who controlled the account during the relevant period.
Do not treat the holder’s denial as proof of compromise.
Test it against provider, device and communication evidence.
Equally, do not dismiss victimisation because the holder completed some actions personally.
A deceived person may genuinely authorise transfers without understanding the criminal purpose.
Preserve the account and device evidence before security changes remove active-session or device information.
When reporting, distinguish technical account use, personal actions, deception, knowledge and benefit.
Operational takeaway¶
Keep open the possibility that a suspected mule account is also a victim account and test control, deception and knowledge through provider, device and communication evidence.