Mule accounts and digital smurfing: the mule mesh that drains the scam
The operation that rented +62% more accounts in the last year — and the risk to the CPF/CNPJ that accepts "extra income".
Audience: Companies and Operations · Risk level: ATTENTION
Blindfy Intelligence Unit · Technical review by Blindfy
Scenario
A company employee agrees to "rent out" his checking account to receive and forward money — a promise of easy commission. Within weeks, the account is used to funnel Pix from frauds. The result: account frozen by court order, a judicial lock on the CPF and a criminal investigation for money laundering.
How the scam works
Gangs recruit individuals and MEIs (micro-entrepreneurs) on social networks and Telegram with promises of "extra income". The account becomes a pass-through point (smurfing) — it receives fragmented amounts from victims and sprays them into other accounts. A recent survey showed +62% growth in mule accounts, with 2.6 million CPFs at risk of involuntary involvement.
Common mistake
Treating it as "easy money" rather than participation in a criminal organization. For the courts and the Central Bank, the account holder's liability is strict.
Impact
A total freeze of the CPF/CNPJ's assets, registration in the Central Bank's credit information system, a money laundering investigation and being barred from opening an account at any financial institution for years.
What works
Blindfy provides digital due diligence for companies that need to vet employees and partners, monitors employee exposure to suspicious recruitment and structures an internal anti-mule policy with specific contract clauses.
Protection checklist
- Include an anti-mule clause in employment contracts
- Train employees on the criminal and financial risk
- Monitor atypical movements in company payment accounts
- Vet corporate suppliers via digital due diligence
- Block payments to CNPJs with no operating history
- Keep an anonymous internal reporting channel
- Report suspicious approaches to COAF and the police
Editorial sources
- CERT.br / NIC.br — Cartilha de Segurança para Internet
- ENCCLA / Ministério da Justiça — Enfrentamento a golpes digitais
The criminal doesn't need to breach your system — corrupting one employee is enough. Internal policy is the first layer of protection.