Verihubs Logo
Home Blog Money Mule in the Philippines: How Mule Accounts Work and How Banks Detect Them
14 min read KYC Published on August 19, 2026

Money Mule in the Philippines: How Mule Accounts Work and How Banks Detect Them

Money Mule in the Philippines: How Mule Accounts Work and How Banks Detect Them

A money mule is a person who receives and moves criminal proceeds through a financial account, making illicit funds appear to move through legitimate channels.

In the Philippines, money muling is a criminal offence under Section 4(a) of Republic Act No. 12010, the Anti-Financial Account Scamming Act (AFASA), which was signed into law on 20 July 2024.

Money muling activities carry imprisonment of six to eight years and a fine of PHP 100,000 to PHP 500,000, or both. Recruiting another person to act as a money mule is also covered under the same provision.

For banks, fintech companies, and other financial institutions, the bigger concern is not only the person behind the mule account. It is how mule networks use legitimate customer accounts to move stolen funds, making traditional KYC checks less effective.

What Is a Money Mule?

A money mule is a person whose financial account is used to receive, hold, and transfer proceeds derived from crime so that the funds can reach their destination through channels that appear legitimate.

The mule is not necessarily the person who committed the underlying fraud or scam. In many cases, the account holder is simply part of the movement layer. This separation makes the money harder to trace. If stolen funds remain in an account directly linked to the scammer, investigators can more easily connect the account to the original offence. When funds move through several unrelated accounts, tracing the flow becomes more difficult.

Under AFASA, the definition is broader than simply receiving suspicious funds. Section 4(a) covers acts such as obtaining, receiving, depositing, transferring, or withdrawing proceeds known to be derived from crimes, offences, or social engineering schemes. It also covers using, borrowing, or allowing another person to use a financial account, opening an account under a fictitious name, using another person’s identity or identification documents, and recruiting or inducing others to perform these acts. This creates an important connection between money mule activity and account onboarding.

A customer does not necessarily need to create a fake identity for the account to become part of a mule network. A genuine person using a genuine identity can still become involved when their account is used to move illicit funds.

Witting vs Unwitting Money Mules: Does Intent Matter?

One of the most important questions in money mule cases is whether the account holder knew that the funds were connected to criminal activity. Under AFASA, knowledge matters because the provision refers to proceeds known to be derived from crimes, offences, or social engineering schemes.

However, simply saying that an account was “only lent” to someone does not automatically resolve the issue. The surrounding evidence and circumstances remain important. For financial institutions, this creates a practical challenge.

A person who knowingly participates in a mule scheme and a person who was genuinely deceived can produce very similar transaction patterns. The account may receive funds from multiple unrelated people, move the money shortly after receipt, and eventually become inactive. This means detection should not depend on trying to determine the customer’s intent from a single transaction.

Witting muleUnwitting participant
Knows or strongly suspects the funds are illicitGenuinely believes the arrangement is legitimate
May be paid for providing account accessMay be recruited through a fake job or romance scam
May knowingly participate in moving fundsMay be deceived into receiving or forwarding funds
Legal exposure depends on the applicable facts and evidenceKnowledge and surrounding circumstances remain important

For banks and fintechs, behavioural and network signals can therefore be more useful for initial detection than trying to classify customers based on intent alone.

How Mules Are Recruited in the Philippines

Money mule recruitment often targets people who have legitimate financial accounts but may be willing to receive or transfer money for someone else.

Money mule recruitment patterns and detection signals at onboarding and in transaction monitoring for Philippine institutions

Fake Job Offers

Remote roles advertised as payment processing, financial admin, or logistics coordination, where the job is receiving transfers and forwarding them minus a commission. The PNP Anti-Cybercrime Group’s advisory on money muling frames easy-money offers online as a common recruitment route.

Direct Account Rental or Sale

Straightforward payment for the use of an account, often targeting students, workers between jobs, and people in financial difficulty.

Romance and Relationship Scams

A trusted contact asks for help receiving funds. Emotional pressure substitutes for payment, and the victim often continues after suspicion sets in.

Social Pressure Within Personal Networks

Family or community requests where refusing carries a social cost, and the person may never characterise what happened as a crime.

What unites them: the account is genuine, the holder is a real person whose identity verifies cleanly, and nothing about onboarding looks wrong. Mule accounts are not typically fake accounts. That is what makes them useful.

Money Mule Liability Under AFASA

RA 12010 establishes penalties for different types of prohibited activity.

OffenceImprisonmentFine
Money muling activities (Sec. 4(a))6 to 8 yearsPHP 100,000 to PHP 500,000, or both
Social engineering schemes10 to 12 yearsPHP 500,000 to PHP 1 million
Economic sabotageLife imprisonmentPHP 1 million to PHP 5 million, or both

Recruitment sits inside the money muling provision rather than alongside it. Recruiting, enlisting, contracting, hiring, utilising, or inducing another person to perform mule acts is itself money muling under Section 4(a), which reaches organisers who never touch an account.

AFASA also changed what institutions must do rather than only what individuals may not do. It grants the BSP authority to examine and investigate accounts involved in prohibited acts, and Section 8 requires institutions and account owners to initiate a coordinated verification process on a disputed transaction, whether triggered by a complaint, information from another institution, or internal detection, and regardless of whether the funds remain in the banking system.

That last clause is unusual and worth noting. The obligation does not lapse because the money has already left.

How Banks and Fintechs Can Detect Mule Accounts

Mule detection generally happens at two stages: onboarding and transaction monitoring. Each stage can reveal different signals.

Signals at Onboarding

Some mule accounts are opened specifically for fraudulent activity. Potential signals can include:

  1. The same device or IP address being used for multiple unrelated applications
  2. Multiple customers sharing the same address or phone number without an apparent relationship
  3. Several account applications being submitted within a short period
  4. Identity documents that verify successfully but appear to belong to someone other than the applicant
  5. Multiple identities being associated with the same biometric profile

The important point is that each individual application may look legitimate when assessed on its own. The risk can become visible only when the institution connects the applications and identifies relationships between them.

Signals in Transactions

Once an account is active, transaction behaviour can reveal additional mule indicators. Common patterns include:

  1. Funds entering and leaving the account shortly afterwards
  2. Little balance being retained despite significant transaction volume
  3. Multiple inbound transfers from unrelated senders
  4. A dormant account suddenly becoming highly active
  5. Transaction activity that does not match the customer’s declared profile
  6. Rapid movement of funds toward cash-out points
  7. Short periods of intense activity followed by account inactivity

This type of pass-through behaviour can be particularly useful for detecting mule accounts. A mule account may have a relatively short useful life. Once the account is frozen or the arrangement ends, the activity may stop altogether. That makes account age, transaction velocity, and behavioural consistency useful signals alongside transaction value.

Money Mule Networks vs Smurfing: What’s the Difference?

These get conflated because both involve moving money through multiple accounts, but they solve different problems for the criminal.

Smurfing is about amount. Large sums are broken into pieces small enough to stay below reporting thresholds, and the accounts are a means to that end.

Money muling is about distance. The objective is separating funds from the person who obtained them, and the amounts may be entirely unremarkable.

They combine in practice, which is where the confusion starts: a network of mules receiving structured amounts achieves both at once. But a mule can move one large transfer and still be a mule, and a smurf can split deposits within accounts they control without any mule involved.

The detection implication differs too. Threshold-based rules catch structuring. Mule detection needs relationship and behavioural signals, because no individual transaction in a mule chain necessarily looks unusual.

Why Identity Deduplication and Device Intelligence Matter

Mule networks have one structural weakness: they need many accounts, and accounts need people.

Recruiting a genuinely distinct person for every account is slow and expensive, so operators reuse what they can. One person opens accounts across institutions, or repeatedly within one. A single device submits many applications. The same address or contact number appears across customers who claim no connection.

Standard verification does not see any of this, because it evaluates each application in isolation and each one passes. Biometric deduplication asks the different question: has this face already enrolled here under another identity. Combined with device and network signals, it surfaces the relationship structure that individual checks cannot.

Section 4(a)(2) of AFASA is the direct connection to identity verification. Opening an account under a fictitious name or using another person’s identity documents is money muling in itself, which means a synthetic or stolen-identity account is not merely a KYC failure. It is the commission of a criminal offence inside your onboarding flow, and our guide to identity fraud covers how those identities are assembled.

Frequently Asked Questions About Money Mules

What does money mule mean?

A money mule is a person who receives and moves proceeds derived from crime through a financial account, helping illicit funds travel through channels that appear legitimate. Under Philippine law it is defined and penalised in Section 4(a) of RA 12010, the Anti-Financial Account Scamming Act.

Is being a money mule a crime in the Philippines?

Yes. Money muling activities under Section 4(a) of RA 12010 carry imprisonment of six to eight years and a fine of PHP 100,000 to PHP 500,000, or both. AFASA was signed into law on 20 July 2024.

What if someone did not know the money was illegal?

Knowledge is an element of the offence, since the statute refers to proceeds known to be derived from crimes, offences, or social engineering schemes. However, statements such as having only lent an account do not automatically provide a defence where the surrounding evidence shows knowledge or deliberate participation. Equally, receiving suspicious money is evidence rather than conclusive proof of guilt.

Is lending your bank account to a friend illegal?

It can be. Using, borrowing, or allowing the use of a financial account is one of the acts listed under money muling in Section 4(a) of AFASA where it is done for the purpose of moving proceeds known to derive from crime or a social engineering scheme.

Is recruiting money mules a separate offence?

It sits within the same provision. Recruiting, enlisting, contracting, hiring, utilising, or inducing another person to perform mule acts is itself money muling under Section 4(a), which reaches organisers who never handle an account themselves.

How do banks detect mule accounts?

Through a combination of onboarding signals such as shared devices, addresses, and contact details across unrelated applications, and transaction signals such as pass-through behaviour, dormancy followed by burst activity, inbound transfers from multiple unrelated parties, and rapid movement toward cash-out points.

Why Traditional KYC Alone May Not Catch a Mule Account

Fraud controls are generally built to detect people who are not who they claim to be. A mule is exactly who they claim to be. The identity is real, the documents are genuine, the selfie matches, and the account opens without incident because nothing about it is wrong at that moment.

What is wrong is the relationship: to an operator who recruited them, to other accounts opening on the same device, to a network the individual application cannot reveal. That is a different question from identity verification, and it needs a different check.

Verihubs eKYC API covers both sides for Philippine institutions: government ID verification across 15+ document types with biometric liveness and deepfake detection to stop the fictitious-identity accounts that Section 4(a)(2) itself criminalises, and face deduplication to surface the repeat enrolments that mule networks depend on.

Talk to the Verihubs team about detecting mule account patterns at onboarding.

View Blog