Cyberoo logo
Home
|
About
|
Products
|
Solutions
|
Insights
|
Contact
Cyberoo logo
Leading the fight against scammers, supporting organisations globally in detecting and disrupting scams, including those preparing for regulatory frameworks such as Australia's Scams Prevention Framework
Menu
HomeAboutInsightsContact
Products
NothingPhishyScams.ReportMuleHunt
Solutions
SPF Compliance for Scam PreventionScam Detection & Threat IntelligenceDigital Risk & Infrastructure DisruptionWebsite Takedown & Digital Risk ProtectionPayment Scam & Mule Account IntelligenceScam Awareness & Behavioural Defence
Contact
Level 1/63 Ann Street,
Surry Hills
NSW 2010
info@cyberoo.ai
© All rights reserved | Cyberoo Pty LtdPrivacy PolicyTerms of Use
← ALL POSTS

The Bank Account Has Become Criminal Infrastructure

Criminal groups do not need to steal every account. They can recruit, rent, purchase or take control of accounts that already look legitimate.

July 17, 2026 | Cyberoo Research & Analysis Team

Systems map showing a bank account as one component of a wider fraud-as-a-service supply chain.
Click to view full size

From target to tradable asset

A bank account has traditionally been viewed as something criminals try to compromise. That remains true, but it is no longer the only model. Accounts can now be recruited, rented, sold, handed over or operated on behalf of another party. In that sense, the account becomes a tradable component of a wider criminal service chain.

The shift matters because the account may be genuine. It may have been opened using real identity documents, used normally for months and connected to an established customer profile. Standard onboarding checks may have worked exactly as intended. The risk appears later, when control, purpose or usage changes.

Mule markets lower the cost of fraud

Modern scam operations can source much of what they need as a service. Domains, hosting, phishing kits, advertising access, messaging accounts, residential proxies, SIM services and cryptocurrency conversion can all be acquired or outsourced. Receiving accounts fit into the same model.

A fraud operator can recruit an account holder through a fake job, pay a willing participant, purchase an established account, use stolen identity documents or direct a manipulated victim to move funds. The result is a pool of payment destinations that can be rotated as accounts are detected or restricted.

This creates a form of resilience. Removing one website or closing one account may interrupt a case without materially reducing the capacity of the network.

Timeline showing a legitimate bank account changing control and becoming involved in money mule activity.
Click to view full size

Account risk can emerge long after successful identity verification.

The marketplace is not always hidden

Account recruitment and sale can occur in places that appear ordinary: social media groups, public posts, messaging applications, student networks, informal employment channels and community marketplaces. The conversation may begin openly and then move to encrypted messaging or a private group.

This is important for prevention. The earliest signal that an account may become criminal infrastructure may not arise inside the bank. It may be an advertisement seeking Australian bank accounts, a fake employment campaign, a request for identity documents, or a message offering payment for temporary access.

Why established accounts are valuable

An established account can carry characteristics that are useful to criminals. It may have passed identity verification, accumulated normal transaction history, retained trusted device relationships and avoided the immediate scrutiny applied to newly created accounts. It may also have access to faster payments, higher limits or cryptocurrency services.

Account handover exploits the gap between identity at onboarding and control over time. The customer remains the recorded owner, while another party may direct activity or gain access. Even where the original customer continues to log in, the economic purpose of the account may have changed.

A receiving account is part of the scam infrastructure

The beneficiary account is often treated as the final destination of a suspicious transaction. Operationally, it should also be treated as infrastructure that enables the scam. It receives value, separates the fraudster from the victim, supports rapid movement and can be reused across multiple campaigns.

This changes the investigative question. Instead of asking only whether a transfer is unusual for the sender, institutions should also ask whether the receiving destination has been exposed through a confirmed scam journey, advertised for sale, linked to multiple deceptive sites or reused across unrelated victim reports.

Network diagram connecting a receiving account to scam reports, websites, recruitment activity and payment destinations.
Click to view full size

A receiving account becomes more actionable when linked to the scam network around it.

What defenders need to see

Internal controls can identify changes in devices, location, transaction velocity, counterparties and cash-out behaviour. External intelligence can add recruitment posts, scam websites, fake job offers, payment instructions, screenshots and links between destinations and campaigns.

The strongest view connects both sides. It treats the bank account not as an isolated customer record but as one node in a changing scam network. This supports earlier beneficiary warnings, receiving-account review, related-account discovery, customer contact and disruption.

The control objective is continuous trust

Know-your-customer controls establish identity at a point in time. Mule risk requires institutions to keep asking whether control and purpose still match that identity. That does not mean treating every change as criminal. It means recognising that an account can remain technically authentic while becoming operationally hostile.

The market for legitimate-looking accounts makes continuous trust, cross-channel intelligence and receiving-side accountability central to modern scam prevention.

Key point: The bank account is no longer only a target of fraud. It can be acquired and operated as criminal infrastructure.

Frequently Asked Questions

What is an account handover?

It is a change in practical control or use after an account has been legitimately opened. The account holder may sell, rent or surrender access, or may continue operating the account under another person's direction.

Why would criminals prefer an established account?

It may already have trusted history, verified identity, payment access and fewer indicators associated with a newly created account.

Does account sale only occur on the dark web?

No. Recruitment and sale can begin on mainstream social platforms, public groups, messaging services and fake employment channels.

How should banks respond?

Banks need continuous controls that combine customer and transaction signals with intelligence about recruitment, scam infrastructure, beneficiary exposure and linked campaigns.

Cyberoo perspective

MuleHunt is designed to help organisations structure scam-linked beneficiary intelligence and connect receiving destinations to the wider scam context. Public communications should focus on the intelligence value, not on internal collection or engagement methods.

References

  • Australian Federal Police / ABC News reporting on money mule recruitment and Australian account sales
  • Victoria Police — Money muling
  • Commonwealth Bank — Fake job offers and money mule risk
  • Incognia — The State of Mule Account Handovers in 2026
  • FATF — Cyber-Enabled Fraud: Digitalisation and ML/TF/PF Risks