Direct Answer
A money mule is someone who allows a scammer to use their bank account, Singpass-linked access, SIM card, payment wallet, or cryptocurrency account to receive or move criminal proceeds. In Singapore, “I was only helping” or “I did not know where the money came from” may not protect you: knowingly or recklessly allowing your account to be used can expose you to police investigation, account restrictions, money-laundering offences, and serious criminal penalties.
Introduction
Money mule recruitment is the hidden logistics layer behind many scams in Singapore. Victims may believe they are accepting a temporary job, helping a friend, receiving a commission, or completing simple transfers for an online business. In reality, their account becomes a transit point between a victim’s payment and a scam syndicate’s operators. The mule may never speak to the original victim, yet their name, phone number, device, and bank account can be the first trail investigators follow.
The risk is especially serious because recruitment is often dressed up as legitimate work. Posts on Telegram, WhatsApp, Instagram, TikTok, and job platforms may promise fast cash for “payment processing”, “e-commerce order fulfilment”, “account testing”, or “local collection agent” work. A recruiter may request a bank account, ATM card, internet-banking credentials, a one-time-password, or access to a corporate payment account. Some ask recruits to open new accounts or register wallets on their behalf. These are not normal employment requirements.
Singapore’s anti-scam system combines the Singapore Police Force (SPF), the Anti-Scam Command, banks, the Cyber Security Agency of Singapore (CSA), ScamShield, and financial-intelligence controls. Those systems can trace flows across accounts and platforms. They also mean that a mule’s account can be frozen while police establish what happened, causing disruption to salary payments, bills, business operations, and family finances.
How This Scam Works in Singapore
1. Recruitment begins with an attractive, low-friction offer
The first message often sounds harmless: earn S$300 a day, help a company receive local payments, test a bank transfer, or become a “financial assistant”. The recruiter may use a polished business profile, a copied company name, a fake contract, or testimonials from accomplices. Pressure to act quickly is common because the syndicate wants access before the recruit checks the employer.
Young adults, students, job seekers, migrant workers, financially stressed households, and small-business operators can be targeted. A legitimate employer should not ask an employee to hand over full banking control or to receive money for unknown third parties.
2. The recruit is asked for access, not just an account number
A dangerous request may involve an ATM card, PIN, internet-banking username and password, OTP, Singpass credentials, device access, or permission to install remote-control software. Fraudsters may say the information is needed for payroll, verification, “KYC”, or payment testing. It is not.
Even when the recruit shares only an account number, the account can be used to receive scam proceeds. If the recruit then forwards the funds, withdraws cash, buys cryptocurrency, or sends the money overseas, the account becomes part of the laundering chain.
3. The mule is given instructions to move funds
The money may arrive from victims of e-commerce scams, investment scams, job scams, government-official impersonation scams, or business email compromise. The mule is told to transfer it to another bank account, cash deposit machine, cryptocurrency exchange, payment wallet, or foreign remittance channel. They may keep a commission and send screenshots as proof.
This “layering” makes the syndicate harder to identify. It does not make the mule invisible. Banks monitor unusual transaction patterns, rapid pass-through activity, multiple unrelated payers, new-device logins, and transfers inconsistent with a customer’s normal profile.
4. The account is linked to a victim and investigated
When a scam victim reports a transfer, the bank and police may trace the destination account. The mule’s account can be restricted or frozen. Investigators may examine messages, call logs, device data, transaction records, recruitment posts, and the mule’s relationship with other account holders.
A mule might be a deliberate participant, a reckless account lender, or someone deceived by a fake employer. The facts matter, but the consequences can still be severe. Never assume that receiving a “small” amount makes the arrangement safe.
Real-World Impact and Statistics
Singapore recorded 37,308 scam cases and about S$913.1 million in losses in 2025, according to the ScamShield Annual Scams and Cybercrime Brief 2025. That was a decline in total cases and losses, but the scale remains enormous. Every successful transfer requires a destination account, and money mules help syndicates convert digital theft into usable funds.
Government Official Impersonation Scams alone accounted for S$242.9 million in losses in 2025, while investment scams accounted for S$336.2 million and job scams S$123.5 million, according to ScamShield’s public scam-threat figures. These categories frequently involve multiple bank accounts and payment channels rather than a single direct transfer to an overseas criminal.
The SPF’s Operation FRONTIER+ III, described in the July 2026 planning brief, linked more than 3,000 cases and about S$69.3 million in losses to a transnational scam operation. More than 130 people were arrested in a multi-country enforcement effort. Such operations demonstrate why “local account holder” does not mean “minor helper”: the local account may be a critical operational link.
Singapore also introduced stronger consequences for scam-related conduct through amendments to criminal law. ScamShield explains that scammers can face mandatory caning of between six and 24 strokes depending on the offence and circumstances, while money mules may face discretionary caning of up to 12 strokes where the legal requirements are met. Penalties depend on the charge, evidence, role, and court findings; this article is not legal advice.
The damage extends beyond criminal exposure. Banks may close accounts, delay transactions, restrict digital banking, or refuse future services after risk assessments. A business may miss payroll or supplier payments. A student may lose access to a savings account. Personal particulars exposed during recruitment can also be reused for identity fraud, phishing, or further account opening attempts. Under the Personal Data Protection Act (PDPA), organisations must handle personal data responsibly, but individuals should still avoid sharing identity and banking credentials with unverified parties.
How to Protect Yourself
- Treat “easy money” account jobs as a major warning sign. Do not accept payment-processing work that requires your personal account to receive or forward money for strangers.
- Never share banking credentials. Banks will not require your password, full OTP, card PIN, or remote device access for an employer or recruiter.
- Verify the employer independently. Search the company through ACRA and use contact details from its official website, not the recruiter’s message. Ask what the role does and why payments cannot use the company’s own account.
- Do not open accounts for another person. A request to register a bank account, wallet, SIM, exchange account, or Singpass service on someone else’s behalf is a serious red flag.
- Use transaction alerts and limits. Enable notifications, review payees, and set conservative transfer limits. SMEs should use dual approval, separate operating accounts, and documented callback verification.
- Protect your phone and identity. Keep operating systems updated, install apps only from official stores, and do not install remote-access software at a recruiter’s request. CSA’s cyber-hygiene resources are useful for households and businesses.
- Check suspicious messages. ScamShield can help identify suspicious calls and messages, and the ScamShield Helpline is available at 1799. Do not click links or scan QR codes sent by an unverified recruiter.
- Pause before moving unexpected money. If funds arrive from an unknown person, do not forward or withdraw them. Contact your bank through its official hotline and explain the situation.
What to Do If You Are Targeted
If you have shared account access, credentials, or received suspicious funds, act quickly:
- Stop all transfers and communication with the recruiter. Do not warn the syndicate, negotiate, or delete messages.
- Call your bank immediately using the number on its official website or card. Ask the bank to secure the account, review transactions, and advise on changing credentials or replacing cards.
- Change passwords from a clean device. Revoke unfamiliar sessions, remove remote-access applications, and contact Singpass if your credentials may be exposed.
- Preserve evidence. Keep usernames, phone numbers, advertisements, contracts, wallet addresses, screenshots, transaction references, and dates. Do not edit or fabricate records.
- Report to the police. Make a police report and provide the full timeline. If there is immediate danger or an offence in progress, call 999. ScamShield’s “I’ve been scammed” guidance can help you identify next steps.
- Inform affected parties honestly. If an employer, customer, friend, or business account may have been exposed, tell them and follow the bank’s instructions.
- For cyber incidents, consider CSA/SingCERT resources. Malware or compromised devices may require additional containment and technical support.
- Assuming a recruiter’s professional language proves legitimacy.
- Believing that a commission makes a suspicious transfer legal.
- Giving an OTP because the other person says it is only for verification.
- Using a personal account for business collections without proper controls.
- Moving money onward after a bank has asked you to stop.
- Deleting chats, resetting a phone, or disposing of a SIM card after a suspicious transaction.
- Trying to solve the matter privately instead of contacting the bank and SPF.
- Sharing your NRIC, selfie, Singpass login, or bank details in a group chat.
If police contact you, cooperate and seek qualified legal advice before making decisions about a potential offence. Do not pay a second “recovery agent” who claims to be able to unlock your account or retrieve funds for an upfront fee; that is often a recovery scam.
Common Mistakes to Avoid
FAQ
Is it illegal to let someone use my bank account in Singapore?
It can be. The legal outcome depends on what you allowed, what you knew or should reasonably have suspected, the funds involved, and your role. Lending an account for unknown payments is unsafe even if you did not personally scam anyone.
Can I be a money mule without knowing it?
Yes, a person can be deceived by a fake job or romance contact. However, investigators and courts examine the circumstances, including warning signs, instructions received, benefits kept, and whether the person ignored obvious risks. Report suspicious activity immediately rather than continuing to move funds.
What should I do if money enters my account by mistake?
Do not spend, withdraw, or return it to a different account based on a message. Contact your bank through an official channel, provide the transaction details, and follow its instructions.
Do banks freeze money mule accounts?
Banks may restrict or review accounts when transactions appear linked to scams or money laundering. A restriction is not the same as a conviction, but it can have serious practical effects while the bank and authorities investigate.
Are students and young people targeted as money mules?
Yes. Flexible-work offers, social-media recruitment, gaming communities, and peer referrals can make young people attractive targets. Parents, schools, and educators should explain that receiving or forwarding money for strangers is not a normal side job.
Does the Computer Misuse Act apply to money mule activity?
Potentially, depending on the conduct. Accessing systems without authorisation, sharing credentials, or facilitating unauthorised access can raise computer-misuse issues, while handling criminal proceeds may involve other offences. Get legal advice for a specific case.
Where can I check whether an offer is a scam?
Use ScamShield resources or call the 24/7 ScamShield Helpline at 1799. Verify employers independently, contact your bank, and report suspected criminal activity to SPF rather than relying on the recruiter’s assurances.
Conclusion
Your bank account is not a harmless favour or a spare tool for someone else’s business. In Singapore’s connected payment system, it can become the traceable bridge between a victim’s loss and a scam syndicate’s control. Reject account-lending requests, protect your credentials, verify every job offer, and contact your bank and SPF at the first sign that your account has been used for suspicious funds. A quick report can protect your finances, preserve evidence, and prevent further victims.