Synthetic Identities and Mule Accounts: Why KYC Alone Is No Longer Enough
AO commentary on Facephi research into synthetic identity and mule account detection
Facephi has published research on detecting mule accounts opened with synthetic identities. AO looks at what that means architecturally: identity verification and transaction monitoring can no longer be run as two unrelated controls.
Based on an original publication by Facephi

Facephi has published research on how mule accounts are increasingly opened using synthetic identities rather than stolen ones, and on the signals that can help detect them. It is worth reading in full. What we want to add is the architectural consequence for banks and payment providers, because it is uncomfortable: the way most institutions have separated identity from monitoring is the weakness being exploited.
What is a synthetic identity?
A stolen identity impersonates someone who exists. A synthetic identity does something subtler. It assembles a plausible person out of parts, some real, some invented, some borrowed from more than one source. Nobody reports it stolen, because there is no victim to notice. It has no complaint history, no disputed transactions, and no contradicting behaviour anywhere else in the system.
That is why it survives controls designed to validate attributes. The data checks out. The person does not exist.
What is a mule account?
A mule account is a conduit. Its purpose is to receive funds and pass them onward quickly enough, and through enough hops, that the connection between the victim and the beneficiary becomes hard to reconstruct.
The valuable property of a mule account is ordinariness. An account that behaves strangely from day one is easy to catch. An account that opens cleanly, sits quietly, receives a salary-shaped credit or two, and only becomes a conduit months later is not.
Why onboarding-only KYC can be insufficient
Most onboarding stacks were designed around a single question: is this identity genuine at the moment of application? Answer it well, and the account is trusted from then on.
That model has two problems. The first is that a synthetic identity is engineered to answer that question correctly. The second is more fundamental: a correct answer at onboarding says nothing about who is operating the account eighteen months later. Accounts get sold. Customers get recruited. Credentials get compromised. Genuine customers become mules without ever changing a single onboarding attribute.
Identity is a lifecycle, not an event
The more useful framing is that identity assurance decays. It is high immediately after a verified, biometric-backed onboarding, and it erodes with every change of device, every unusual session, every behavioural shift and every period of dormancy followed by sudden activity.
Continuous verification is not about re-onboarding customers every quarter. It is about being able to answer a second question alongside the first:
- Is this identity genuine?
- Is this account still behaving like the genuine customer we originally verified?
From identity intelligence to transaction intelligence
Architecturally, the two questions belong on the same chain of evidence.
- Identity
- Device / Session
- Behaviour
- Transaction
- Risk Score
- Alert / Action
Each layer contributes context the next one needs. An identity decision without device context cannot tell you that thirty accounts were opened from the same handset. A transaction alert without identity context forces an investigator to reconstruct the customer from scratch. A behavioural signal with neither is a curiosity.
Where institutions separate these systems, they usually separate the teams too, and then the data. The result is not that the signals are missing; it is that nobody can see them together in time to act.
Why behavioural signals matter
Behavioural intelligence covers a wide range of signals, and no single implementation uses all of them. Depending on the platform and the regulatory context it can include how a session is navigated, how data is entered, relationships between devices and accounts, changes in customer patterns over time, and the shape of transaction activity relative to the account history.
Two cautions. Behavioural signals are probabilistic, so they belong in scoring and prioritisation rather than in unilateral account closure. And they are personal data, so consent, purpose limitation, retention and transparency have to be designed in, not retrofitted.
Where AI genuinely helps, and where it does not
AI can help correlate weak signals that no analyst would connect manually, prioritise a queue so the highest-risk cases surface first, and identify emerging patterns before a rule exists for them. Those are real gains.
What AI does not do is remove the need for investigation, governance and evidence. A model that flags an account cannot explain itself to a regulator; a case file can. We would encourage institutions to treat AI as assistance that raises the quality of human decisions, and to invest as heavily in the surrounding operating model as in the model itself.
The AO perspective
AO works at the integration layer of this problem. Our view of the target architecture is deliberately sequential:
- Know the customer
- Understand the transaction
- Understand the behaviour
- Take the appropriate action
Identity capability such as Facephi, real-time monitoring in the payment flow, and behavioural intelligence in the customer relationship each solve a different part of it. The value appears when they share context. That is an architecture and integration problem before it is a product problem, and it is the work AO does: designing the flow, integrating the platforms, mapping the data, and building the operational tooling investigators actually use.
We are describing an architecture AO can design and integrate for a bank, not a single packaged product. Explore Connected Banking, AO Transaction Monitoring, Behavioural Banking or our Identity and eKYC capability for the component parts.
Related reading
Our commentary on what Tazama 4.0 means for real-time fraud and transaction monitoring covers the monitoring half of this chain in more depth.
Frequently asked questions
- What is a synthetic identity?
- A synthetic identity is an identity constructed by combining genuine data points, such as a valid-looking identifier or a real address, with fabricated or borrowed details. Because the combination is internally coherent, it can pass checks that verify individual attributes rather than verifying that a real, living person is present and consenting. Facephi research describes how such identities are used to open accounts that are later exploited.
- What is a mule account?
- A mule account is an account used to receive and move funds on behalf of someone else, usually to break the trail between a victim and the ultimate beneficiary. Some are opened by criminals using false or synthetic identities; others belong to real people who have been recruited, coerced or deceived. Either way, the account behaves as a conduit rather than as a normal customer relationship.
- Why can a synthetic identity pass KYC?
- Most onboarding controls are designed to test whether the documents and data presented are valid and consistent. A well-constructed synthetic identity is built precisely to satisfy those tests. Controls that additionally check liveness, biometric match to a verified document and device or session risk make that harder, but no single check should be treated as conclusive.
- What is continuous identity verification?
- It is the practice of treating identity assurance as something that decays and must be refreshed, rather than as a one-off event. In practice that can mean re-authenticating for sensitive actions, monitoring for changes in device, location or behaviour, and re-scoring risk across the account lifecycle. Implementations vary widely and should be proportionate to risk and applicable regulation.
- How do transaction monitoring and KYC work together?
- KYC establishes who the customer is said to be. Transaction monitoring observes what the account then does. Used together, an identity signal can raise the sensitivity of monitoring for an account, and a monitoring alert can trigger a step-up identity check. The practical requirement is shared context: identity, device, session, behaviour and transaction data available to the same risk decision.
- How can AI help detect mule accounts?
- AI can help correlate weak signals across accounts, devices and payment patterns, prioritise alerts for investigators and surface relationships a rule set would miss. It does not eliminate fraud, and it should be governed with clear model oversight, explainability appropriate to the regulatory context and human review of consequential decisions.
Source & attribution
This article contains AO commentary based on an original publication by Facephi. The underlying announcement and statements regarding Facephi, its technology and partnerships originate from Facephi.
The source article, and all statements about Facephi products, research and results, originate from Facephi. AO is an integration and delivery partner and did not author the original publication.
- Original source:
- Facephi
- Original publication:
- Mule Account Detection with AI: How to Identify Synthetic Identities in Real Time
- Original publication date:
- 30 July 2026
- Original author:
- Facephi Observatory
Sources and references
- Mule Account Detection with AI: How to Identify Synthetic Identities in Real Time — Facephi. Original publication by the Facephi Observatory. AO commentary is independent and does not reproduce the original text.
Planning something like this?
Book a Discovery Call with the AO team and we will work through it with you.
Related from AO

Digital Identity and the Next Phase of Financial Inclusion in South Africa
Facephi has published an analysis of collaborative fintech and financial inclusion in South Africa. AO looks at inclusion as an architecture problem: identity, payments, data, risk, channels and regulation have to connect before access becomes useful.

ThitsaWorks and Tazama Partner to Advance Real-Time Fraud Protection
The ThitsaWorks and Tazama partnership highlights an important challenge for digital finance: expanding access and accelerating payments while strengthening the technology used to identify and respond to financial crime.

What Tazama 4.0 Means for Real-Time Fraud and Transaction Monitoring
Tazama has released Version 4.0 of its open-source fraud transaction-monitoring platform, adding case management, rule and connection tooling, analytics and AI-assisted intelligence. AO looks at why transaction monitoring is becoming fraud-management infrastructure, and what that means for implementation.
