Mule Account Detection Using Device and Transaction Behavior

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively detect and mitigate the use of 'mule bank accounts' for illegal activities such as money laundering and terror funding, as they lack the ability to identify suspicious transaction patterns and user behaviors that indicate fraudulent activity.

Innovation Solution

A computerized system monitors user interactions and device properties to identify patterns indicative of mule accounts by comparing them to predefined playbooks and profiles, generating alerts and triggering fraud mitigation measures when suspicious activity is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional monitoring systems are used to track bank account transactions, then basic transaction recording is achieved, but the system fails to detect suspicious patterns indicative of mule accounts and money laundering

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the detection process into multiple independent analysis modules: device property analysis, user behavior analysis, transaction pattern analysis, and playbook matching. Each module processes specific aspects of account activity separately, then integrates results to form a comprehensive risk assessment. This segmentation enables sophisticated detection without overwhelming system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by pre-defining playbooks that encode known money laundering patterns and suspicious behaviors. These playbooks are created in advance based on forensic analysis of mule account activities. During monitoring, the system matches observed patterns against these pre-prepared playbooks, enabling rapid detection without requiring complex real-time analysis of every transaction detail.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive user interaction monitoring is implemented to identify fraudulent behavior, then detection capability improves, but processing time and computational resources increase

Engineering Contradiction:
Improvefraud detection reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies partial monitoring by focusing computational resources on specific high-risk indicators rather than analyzing every user interaction in detail. It monitors device properties, transaction patterns, and behavioral metrics selectively based on risk thresholds. When anomalies are detected, the system performs deeper analysis only on those specific aspects, rather than re-analyzing all account data, thus reducing processing time while maintaining detection reliability.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system implements feedback mechanisms where detection results from initial pattern matching trigger targeted follow-up analyses. When a playbook match indicates suspicious activity, the system automatically initiates additional verification steps focused on that specific risk. This feedback loop enables efficient resource allocation by intensifying analysis only where needed, rather than applying uniform comprehensive monitoring to all accounts.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If the system monitors and analyzes all user interactions and device properties, then detection accuracy improves, but the complexity of data processing and analysis increases

Engineering Contradiction:
Improvesuspicious pattern identification accuracyVSAvoiddata processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts and isolates specific critical indicators from the vast array of available data. It focuses on key device properties (OS version, device model, installed applications), specific user interaction metrics (click patterns, typing speed, session duration), and transaction characteristics (amount, frequency, recipient patterns). By extracting only these relevant indicators rather than processing all available data, the system maintains high detection accuracy while reducing processing complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system transforms raw monitoring data into standardized risk parameters that can be efficiently compared against playbook thresholds. User interactions are converted into behavioral scores, device properties into risk categories, and transaction patterns into risk indicators. This parameter transformation enables complex multi-dimensional data to be processed through simpler comparison operations, reducing analytical complexity while preserving detection precision.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12380455B2Method, device, and system of detecting mule accounts and accounts used for money laundering
Publication Date: 2025.08.05 BIOCATCH
  • US12380455B2 patent drawing

AI summary

Method, device, and system of detecting a mule bank account, or a bank account used for terror funding or money laundering. A method includes: monitoring interactions of a user with a computing device during online access with a bank account; and based on the monitoring, determining that the bank account is utilized as a mule bank account to illegally receive and transfer money, or is used for money laundering or terror funding. The method takes into account one or more indicators, such as, utilization of a remote access channel, utilization of a virtual machine or a proxy server, unique behavior across multiple different accounts, temporal correlation among operations, detection of a set of operations that follow a pre-defined mule account playbook, detection of multiple incoming fund transfers from multiple countries that are followed by a single outgoing fund transfer to a different country, and other indicators.