Could a mule account also be a victim account?¶
Yes. An account can carry criminal funds while its holder is deceived, coerced or excluded by technical compromise. The movement role and the holder's culpability are different questions.
Victimisation can still involve personal actions¶
An offender may take over access through credentials, malware, account recovery or remote control. Alternatively, the holder may personally forward payments while believing a false explanation about wages, refunds, investments or business activity.
Neither denial nor personal authorisation resolves whether the holder understood the purpose.
Test control, explanation and benefit¶
Compare disputed events with normal transactions, endpoints and locations. Examine new sessions, recovery, contact and beneficiary changes, remote-access artefacts, messages and calls. Establish who initiated each step and who retained value.
Preserve session and endpoint records before safeguarding changes where possible. Report technical account use, the holder's actions, deception, knowledge and benefit separately.
The point to remember
Keep victimisation open as an explanation and test it against provider, endpoint and communication evidence rather than the transaction pattern alone.