The account passed KYC. Then it moved Rp2 billion in 47 minutes.
This is not a hypothetical scenario. It is what happened at a major Indonesian bank in early 2026. The customer had valid e-KYC. The account sat dormant for 98 days. Then, in less than an hour, funds arrived from three different sources and were dispersed through five channels: BI-FAST transfer, QRIS payment, e-wallet top-up, card transaction and cash withdrawal.
By the time the fraud team received an alert, the money was gone.
This is the dormancy-to-activation gap, and it is the single biggest blind spot in Indonesian banks’ fraud and AML controls today.
This brief is for: Chief Compliance Officers, Heads of Fraud Risk, AML leaders, Chief Risk Officers and Digital Banking executives at Indonesian banks who need to close the gap between onboarding controls and real-time fraud detection.
The numbers that should worry every bank CXO
Indonesia’s scam response system shows both the scale of the problem and why speed matters.
From 22 November 2024 to 28 December 2025, the Indonesia Anti-Scam Centre (IASC) received 411,055 reports involving reported losses of Rp9 trillion. Around Rp402.5 billion was blocked or saved. CNBC Indonesia
By January 2026, OJK reported 432,637 complaints, reported losses of Rp9.1 trillion and Rp436.88 billion blocked. OJK also confirmed that Rp161 billion had been returned to 1,070 victims through funds blocked across 14 banks. CNBC Indonesia – Fund Recovery
In June 2026, media reports cited IASC figures of 608,168 reported accounts and Rp674 billion frozen, with approximately Rp200 billion returned to victims. Jakartaglobe
These are not just consumer protection statistics. They show how quickly fraud proceeds move through Indonesian bank accounts, virtual accounts, e-wallets and payment channels.
The central question for bank leaders: Can your bank recognise a risky change in account behaviour before the money leaves?
Why mule accounts pass your onboarding checks
A compliance head at a top-10 Indonesian bank put it plainly at a recent industry roundtable:
“Onboarding checks verify who a customer is, but not what the account will ultimately be used for.” Regulation Asia
This is the core problem. Mule networks in Indonesia are not relying on forged identities or fake documents. They are exploiting the gap between:
- Day 1 verification (KYC, CDD, initial risk rating)
- Day 90+ behaviour (dormancy, activation, cross-channel movement)
A mule account can sit inside your system for 90 to 120 days with:
- A validated identity
- A clean compliance record
- No transaction red flags (because there are no transactions)
Then, almost overnight, it becomes a conduit for layered fund movement and rapid outflows.
The four-stage mule lifecycle in Indonesia
Mule networks follow a predictable pattern. Understanding this pattern is the first step to detecting it earlier.
Stage 1: Recruitment (Weeks 1-2)
The account holder is recruited, often through social media, informal intermediaries or false employment opportunities. They open the account believing it serves a legitimate purpose such as side income or delivery work.
Stage 2: Dormancy (Months 1-4)
Nothing happens. No transactions. No alerts. Nothing for a monitoring system to catch, simply because there is nothing to catch yet.
This is where most banks’ controls fail. Dormancy is treated as low risk by default. But for mule networks, dormancy is a feature, not a bug.
Stage 3: Activation (Hours 0-48)
Funds arrive from a compromised business account or an investment scam victim. Within 24 to 48 hours, the mule moves money across channels:
- Core banking to e-money wallet
- Wallet to card
- Card to wire transfer
- Multiple BI-FAST transfers
- QRIS payments
This fragmentation is deliberate. It is built to break the continuity of a monitoring trail that expects one channel at a time.
Stage 4: Exit (Hours 2-24)
Money leaves through remittance corridors, digital asset platforms, or trusted networks, often before any batch report or investigation has a chance to catch up.
Indonesia’s real-time payment rails make the exit phase especially fast. With BI-FAST (Bank Indonesia’s real-time interbank transfer system) and QRIS enabling instant, 24/7 transfers, the window between activation and exit has compressed from days to minutes. Bank Indonesia
Why your current monitoring misses this
Most Indonesian banks have strong transaction monitoring systems. But they have three structural gaps:
Gap 1: Channel isolation
E-money wallet movement and core banking movement get reported separately. A suspicious pattern only becomes visible when the events are connected.
Gap 2: Static risk profiles
A customer’s risk rating is set at onboarding and rarely updated based on behavioural changes. A low-risk customer can become high-risk within hours, but the system still treats them as low-risk.
Gap 3: Batch-based detection
Many banks still rely on end-of-day or end-of-week batch reports. A mule account that would previously have been caught in batch controls can now move funds across banks, e-money wallets and remittance channels before the batch ever fires.
What OJK and Bank Indonesia are watching
OJK and Bank Indonesia are not yet framing this specifically as a dormancy problem. But enforcement focus is shifting.
Based on current supervisory discussion and international pressure on Indonesia’s AML effectiveness, banks should prepare for:
- Continuous risk assessment extending well past initial CDD, requiring banks to reassess account usage against declared purpose throughout the relationship
- Dormancy-to-activation monitoring becoming an explicit supervisory expectation, flagging accounts that jump from dormant to high-activity after 60 or more days of inactivity
- Cross-channel visibility rules requiring banks to see core banking, e-money and card activity simultaneously rather than reconciling it in batch
- Predefined red flags for known mule typologies, such as dormancy followed by rapid outflow or simultaneous multi-channel movement
Banks that build these controls now, ahead of formal guidance, put themselves in a stronger position with regulators.
Five actions your fraud desk should take now
Build dormancy profiles by customer segment
A student account sitting untouched for six months may be normal. A business account doing the same may not be. Calibrate dormancy thresholds by segment, product type and historical behaviour.
Create an activation risk signal
When a dormant account suddenly activates, assess:
- How long was the account inactive?
- What triggered the first activity?
- Who sent the money?
- How quickly did the funds leave?
- Were several channels involved?
- Does the activity match the customer’s declared purpose?
Connect channels in real time
Set up real-time correlation: when an account receives funds in core banking and shows outflow activity in a mobile wallet within two hours, treat that as one suspicious pattern, not two separate transactions.
Validate incoming fund sources
Mule accounts often receive funds from recently compromised business accounts or known investment-scam recipients. Maintain a live list of flagged source accounts and review any dormant account that receives funds from them upon activation.
Reconcile activity with purpose
Compare how an account is actually used against what the customer declared at onboarding. A customer who said they were opening an account for e-commerce purchases should not suddenly be receiving large transfers from multiple unrelated sources.
The business case for early action
Banks that move first on post-onboarding risk reassessment and cross-channel correlation stand to gain:
Regulatory credibility
When OJK eventually issues guidance on these controls, early movers will have months of operational data and maturity to show for it.
Reputation and trust
Banks that act early get to define their own reputation on this issue with customers and regulators alike.
Operational efficiency
A fraud desk that can identify mule accounts at activation, rather than weeks into the layering cycle, files more actionable Suspicious Transaction Reports (STRs) with Indonesia’s Financial Transaction Reports and Analysis Centre (PPATK).
How Clari5 approaches this problem
Clari5, a Perfios company, has been recognised across key industry benchmarks. In Chartis Research‘s Enterprise & Payment Fraud Solutions 2026 Quadrant Report, Clari5 was named a Category Leader across all three quadrants. In 2025, it was also named a Category Leader across four Chartis fraud quadrants, including Identity & Verification (ID&V). Most recently, Clari5 secured a Top 50 position in the Chartis Research FCC50 2026 rankings.
Our approach is built around Indonesia’s dormancy-and-activation reality:
- Persistent customer risk profiles that update through every lifecycle stage, from onboarding through dormancy, activation and active use
- Real-time cross-channel correlation across core banking, card and e-money channels
- Behavioural machine learning trained on known mule-activation typologies
- Post-activation risk reassessment that compares current usage against declared purpose
- Explainable, auditable models so compliance and internal audit teams can trace why an account was re-rated as high risk
This is not about replacing your existing controls. It is about extending the same rigor you apply at onboarding further into the account lifecycle.
Key takeaway for bank leaders
Your onboarding controls have already done their job well. The next place to focus is the dormancy-to-activation transition, where purpose drift actually shows up.
A clean account can become a risky account.
The bank that detects that change early can protect the customer, preserve more funds and give investigators a better chance of disrupting the wider network.
That is the real purpose of lifecycle-based fraud and AML monitoring: not to distrust customers, but to protect legitimate financial activity when criminal behaviour enters the system.
Frequently asked questions
What is a mule account in Indonesia?
A mule account is a bank or payment account used to receive, hold or transfer funds obtained through fraud, scams or other financial crime. The account may belong to a recruited participant, a victim whose credentials were compromised or a person knowingly allowing others to use the account.
Why do mule accounts pass KYC checks?
KYC verifies identity and customer information at onboarding. It does not always reveal how an account will be used months later. Continuous monitoring is needed to identify changes in behaviour, purpose and transaction patterns.
What is dormancy-to-activation monitoring?
It is the monitoring of accounts that remain inactive for a defined period and then begin transacting suddenly or intensively. The risk assessment considers the dormancy period, first transaction, source of funds, velocity, beneficiaries and cross-channel activity.
How should Indonesian banks detect mule accounts?
Banks should combine customer lifecycle data, transaction monitoring, device and channel information, network relationships, external intelligence from IASC and investigator review. No single threshold is sufficient for every customer segment.
How does IASC support scam response in Indonesia?
IASC provides a coordinated channel for handling reports of financial scams and supporting the blocking and recovery of suspected funds. Customers should report scams through the official IASC website as soon as possible. CNBC Indonesia
Does stronger mule-account detection require blocking more customers?
Not necessarily. Risk-based controls can use step-up verification, temporary holds, customer confirmation and targeted investigation instead of automatically blocking every unusual transaction.
What will OJK expect from banks on mule accounts?
While OJK has not issued specific dormancy guidance, banks should prepare for closer supervisory attention to continuous customer risk assessment, behavioural monitoring and speed of response. Any future OJK or Bank Indonesia guidance should be treated as authoritative when issued.
How can banks measure success in mule-account detection?
Track time from activation to detection, time from detection to intervention, funds prevented from leaving, recovery rate, repeat use of linked accounts, number of related accounts identified, quality and timeliness of STR escalation, and customer impact and false-positive rates.