The Company Was Real. The Business Wasn’t: Thailand’s Corporate Mule Account Risk
A company name can make a payment look legitimate.
A business account can make scam proceeds look like revenue.
But when the company has no real operations, the account may not be a business account at all. It may be a corporate mule account.
That is the key lesson from a recent case in Thailand, where cyber police arrested a woman accused of supplying corporate mule bank accounts to a Chinese scam network. Investigators said the accounts were opened in the names of companies and limited partnerships with no genuine business activity, then sold to scammers and linked to more than 27 reported fraud cases, including fake-activity scams and investment fraud.
At first glance, this is a mule-account case. But for banks, payment firms and compliance teams, the deeper issue is how fake companies can make scam proceeds look like ordinary business payments.
The company may be registered.
The money trail may still be criminal.

What Happened in Thailand?
Cyber police arrested Ranwarat Phumphanwarangkul, also known as Pim, aged 31, after searching a house in Phasi Charoen, Bangkok. She is accused of acting as an agent who supplied corporate mule accounts to a Chinese scam network.
Investigators said the accounts were opened under the names of companies and limited partnerships that had no real business operations. These accounts were allegedly sold to scam groups and later linked to more than 27 fraud cases reported by victims across Thailand.
The reported fraud types included fake-activity scams and investment fraud. In one case, a victim in the solar-panel business was allegedly deceived into transferring funds to what appeared to be a legitimate limited partnership account.
That detail matters. A payment to an individual may raise suspicion. A payment to a company or limited partnership can feel more credible to a victim and may appear more normal to a financial institution.
Investigators said the suspect allegedly sold corporate accounts for around 80,000 to 150,000 baht per account, depending on how ready they were for use. She reportedly claimed to earn more than 100,000 baht per month and communicated with a Chinese contact through Line and Telegram.
For financial institutions, the case shows how mule networks are evolving. Scam proceeds are not only moving through personal accounts. They are also being routed through business names, corporate structures and inactive entities.
How Fake Companies Turn Scam Proceeds into Business-Looking Payments
Corporate mule accounts are harder to detect than personal mule accounts because they carry a layer of business credibility.
A transfer to a company account may look like payment for goods, services, investment, supplier settlement or commercial fees. If the account is opened under a registered company or limited partnership, the beneficiary can appear more credible than an individual recipient.
That is what makes corporate mule accounts attractive to scam networks.
A scammer can instruct a victim to transfer money to a company name rather than a personal account. The victim may feel reassured because the beneficiary appears formal. The transaction may also look more consistent with a business purpose, especially in fake investment, fake task, fake activity or fraudulent service scams.
But the corporate label can hide the real risk.
If the company has no genuine operations, no meaningful revenue profile, no business expenses, no payroll and no legitimate reason to receive funds from unrelated victims, the account may simply be a mule account with corporate paperwork.
Once received, the funds may move quickly. They can be withdrawn in cash, transferred to connected accounts, split across multiple beneficiaries, sent to wallets, routed overseas or used to purchase assets. In some cases, the corporate account may act as a collection point before funds are layered through other accounts.
This is where fake businesses create AML risk. They separate the victim-facing story from the underlying money movement. The victim sees a company. The bank sees a corporate account. But the actual behaviour may indicate scam collection, mule-account movement and laundering.
The Thailand case also highlights the value of account readiness. Investigators said the accounts were priced depending on how ready they were for use, suggesting scam networks value corporate mule accounts that can receive funds, access online banking and transfer money quickly.
For banks and payment firms, the core question is whether the account behaves like a real operating business after onboarding.
Corporate Mule Account Red Flags
Corporate mule accounts can generate warning signs across onboarding, transactions, counterparties and network behaviour.
Key red flags may include:
- Companies or limited partnerships with little or no genuine business activity
- Newly opened corporate accounts receiving funds from many unrelated individuals
- Business accounts receiving payments inconsistent with their stated industry or purpose
- Sudden inflows followed by rapid transfers, cash withdrawals or overseas movement
- Corporate accounts linked to fake-task, fake-investment or fake-activity scam complaints
- Multiple companies sharing the same directors, addresses, devices, phone numbers or introducers
- Similar transaction patterns across unrelated corporate entities
- Payments from victims referencing investments, tasks, commissions, deposits or platform activity
- Accounts receiving funds but showing no normal operating expenses, payroll, supplier payments or tax-related behaviour
- Corporate accounts connected to known mule-account networks, suspicious beneficiaries or law-enforcement enquiries
Individually, these signals may not prove criminal activity. Together, they can reveal a corporate account being used as a scam collection point.
Traditional monitoring may miss this risk if it treats a company account as inherently more legitimate than a personal account. The stronger approach is to compare the account’s behaviour with the business’s stated purpose, expected activity and wider network connections.
The question is simple:
Does this look like a real business?
Or does it look like a mule account with a company name?

What This Means for Banks and Payment Firms
The Thailand case reinforces five practical lessons for financial institutions.
First, corporate accounts need ongoing behavioural monitoring. A company may appear legitimate at onboarding, but its actual account activity may tell a different story.
Second, business activity should match transaction behaviour. If a company has no visible operations but receives funds from unrelated individuals and moves them quickly, the account should be reviewed.
Third, beneficiary monitoring is critical. Scam victims may be instructed to send funds to corporate accounts because they appear more credible than personal accounts.
Fourth, network intelligence matters. Multiple companies linked by shared directors, addresses, devices, phone numbers, IP patterns or beneficiaries may indicate organised mule-account activity.
Fifth, fraud and AML teams need a shared view. A victim complaint, suspicious corporate inflows, rapid fund movement and linked entities should not be treated as separate signals. Together, they may point to a wider scam proceeds network.
The broader lesson is that financial institutions need controls that look beyond the company name and examine the behaviour behind the account.
How Tookitaki Helps Detect Corporate Mule Accounts
Tookitaki helps financial institutions move from isolated alerts to connected financial crime detection.
FinCense brings together customer risk, transaction monitoring, screening, alert management and case investigation so compliance teams can identify suspicious behaviour across customers, companies, accounts, counterparties and networks.
In corporate mule-account cases, risk may appear through a combination of signals: inactive business profiles, unusual inbound flows, rapid fund movement, shared directors, linked addresses, common beneficiaries, scam-related payment references and account networks connected to suspicious counterparties.
FinCense helps institutions connect these signals, prioritise higher-risk alerts and give investigators a clearer view of how funds move across entities and accounts.
Through the AFC Ecosystem, Tookitaki also helps institutions stay closer to emerging typologies involving corporate mule accounts, shell companies, fake businesses, scam proceeds movement and cross-border laundering.
The goal is to detect the right patterns earlier, identify connected accounts and support faster investigation outcomes.
The Bigger Lesson: A Company Name Can Hide a Mule Account
The Thailand case shows how scam networks can use corporate structures to create credibility.
A company name can reassure a victim. A limited partnership can make a transfer appear commercial. A business account can make suspicious inflows look like revenue.
But if there is no real business behind the account, the corporate label becomes part of the deception.
For financial institutions, the key questions are behavioural: who is sending money, whether the activity matches the stated business, how quickly funds move out, and whether linked companies share the same people, devices or beneficiaries.
The scam may begin with a fake opportunity.
But the AML risk is revealed when a fake company starts moving real money.
Experience the most intelligent AML and fraud prevention platform
Experience the most intelligent AML and fraud prevention platform
Experience the most intelligent AML and fraud prevention platform
Top AML Scenarios in ASEAN

The Role of AML Software in Compliance

The Role of AML Software in Compliance





