Detect mule accounts and risky payment identifiers before losses occur
Antifraud.in provides access to Antid Cover — a payment risk intelligence service that helps banks, PSPs, and compliance teams detect suspected mule accounts, risky payment identifiers, and fake merchant fronts before losses escalate.
Payment risk moves faster than transaction monitoring.
Payment ecosystems are fast and fragmented. Mule operators reuse bank accounts, payment identifiers, QR codes, and fake merchant pages across channels — and rotate them before internal systems catch up.
By the time an identifier appears in your monitoring, it has already been used — often somewhere you can't see.
Cover Service moves fraud teams earlier in the detection cycle by turning external mule-risk signals into structured, evidence-backed intelligence.
Traditional monitoring watches your side of the transaction. COVER watches the infrastructure behind it.
Transaction monitoring tells you something went wrong after money has already moved. External intelligence tells you an account, identifier, or payment page was already suspicious — often before it ever reaches your systems.
Like a CTI feed — for payment fraud.
Security teams use cyber threat intelligence to detect malicious infrastructure. Cover applies the same model to financial crime, delivering Mule & Payment Risk Signals ready for your fraud and AML workflows.
Mule & Payment Risk Signals
Suspicious accounts, UPI IDs, cards, wallets, phones, merchants, URLs, Telegram handles, and the source links that tie them together.
Risk & context
Each indicator carries a risk level, source context, first-seen data, status, screenshots, related entities, and analyst notes.
Evidence-backed review
Analysts see why an identifier is suspicious, where it appeared, and how it connects to broader payment infrastructure.
From sources others can't reach.
Cover monitors high-risk digital environments where suspicious payment identifiers surface first — long before they reach internal systems.
Deposit and payout handles used by unlicensed betting platforms — frequently reused as mule infrastructure once a book folds or rebrands under a new name.
Recruitment posts, channel admins, and the payment handles shared to pay drops for handing over account access or receiving funds.
Checkout pages and fake merchant fronts that clone real brands to harvest card, UPI, and OTP details from unsuspecting buyers.
Wallets and P2P exchange handles used to fragment and launder proceeds across many small transfers, then consolidate downstream.
Confirmed cases submitted directly by banks and PSPs — reviewed by analysts and merged into the same feed as OSINT-derived indicators, with the evidence trail your team can reference for regulatory filings.
What Cover tracks.
The entities fraud networks use to receive, move, monetize, and reuse stolen payment details.
Built for financial crime and risk teams.
Cover supports the institutions and teams responsible for detecting, investigating, and reporting payment fraud across the ecosystem — including regulated entities filing suspicious activity reports with their local financial intelligence unit.
From raw signal to verified intelligence.
Cover is a workflow, not a list — collection, verification, enrichment, scoring, monitoring, and reporting.
Fraud signals don't arrive structured. We make them that way.
Fraud infrastructure is advertised in plain sight — in channels, on scam pages, in cashout groups. It arrives as unstructured text. This is what happens to it before it reaches your systems.
A workspace for financial crime teams.
Search, filter, and review suspicious identifiers with evidence, entity relationships, status management, and reporting — built for analysts, not developers.
Every indicator rolls up into a case.
Link accounts, cards, and other indicators to a case as your team investigates, track status, priority, and ownership, and keep a timestamped record you can hand to a regulator or auditor.
| Value | Type | Geo | Status | Score | Tags | Evidence |
|---|---|---|---|---|---|---|
| merchant1@bankX | account | IN | 81 | gaming, scam |
i
Captured evidence
pay-secure-verify[.]in
₹4,999.00
|
|
| priya@bankY | account | IN | 90 | darknet |
i
Captured evidence
forum post · drop recruitment thread
|
|
| rahul.k | account | IN | 90 | gaming |
+
Add evidence
Drag & drop or click to upload
|
|
| acc17@bankX | account | GB | 90 | gaming, fraud |
i
Captured evidence
bank statement extract
|
|
| corpacc@bankZ | account | BD | 80 | betting |
+
Add evidence
Drag & drop or click to upload
|
Built to plug straight into your systems.
Every indicator ships as structured JSON or CSV — continuously updated, scored, and ready to drop into transaction monitoring, AML case tools, or an internal risk engine. No manual copy-paste, no PDFs to parse.
{
"id": "iof_8f31c0a7",
"type": "upi_id",
"value": "rohit****@okaxis",
"risk_level": "high",
"risk_score": 92,
"status": "verified",
"region": "IN",
"first_seen": "2026-06-21T08:14:09Z",
"last_seen": "2026-06-28T17:02:44Z",
"sources": [
{ "channel": "scam_payment_page", "url": "pay-secure-verify[.]in" },
{ "channel": "telegram", "handle": "@drop_recruit_in" }
],
"related": [
{ "type": "bank_account", "value": "****8842", "bank": "HDFC" },
{ "type": "phone", "value": "+91 98****1207" }
],
"evidence": 3, // screenshots + source links
"confidence": "verified_by_analyst"
}
id,type,value,risk_level,risk_score,status,region,first_seen,last_seen,sources,related,evidence,confidence
iof_8f31c0a7,bank_account,****8842 HDFC,high,92,verified,IN,2026-06-21T08:14:09Z,2026-06-28T17:02:44Z,"scam_payment_page;partner_report","upi:rohit****@okaxis;card:481234******5678",3,verified_by_analyst
iof_2b91f4c3,upi_id,rohit****@okaxis,high,88,verified,IN,2026-06-19T11:32:07Z,2026-06-28T09:15:00Z,"scam_payment_page;telegram","bank_account:****8842;qr_code:fake9284@ybl",3,verified_by_analyst
iof_c9a3f701,card_bin,481234******5678,high,90,verified,IN,2026-06-20T05:40:12Z,2026-06-27T22:10:03Z,"partner_report","bank_account:****8842",2,verified_by_analyst
iof_7d5e2b64,wallet_address,bc1q7f...a92d,high,85,monitored,Global,2026-06-17T02:55:40Z,2026-06-28T14:22:11Z,"shadow_payment_network","upi:rohit****@okaxis",1,analyst_flagged
iof_a170de56,iban,GB29 NWBK 6016 1331 9268 19,medium,74,review,GB,2026-06-22T14:05:33Z,2026-06-27T19:40:12Z,"partner_report","merchant_account:QuickPay Solutions",2,pending_review
iof_c39a1e88,qr_code,upi://pay?pa=fake9284@ybl,high,81,verified,IN,2026-06-24T10:02:15Z,2026-06-26T21:47:03Z,"scam_payment_page","upi:rohit****@okaxis",1,verified_by_analyst
iof_58d2b6f0,merchant_account,"QuickPay Solutions",medium,68,review,IN,2026-06-20T09:00:00Z,2026-06-26T12:30:00Z,"partner_report","bank_account:****8842",1,pending_review
iof_9f42c7a1,ifsc,HDFC0001234,low,38,monitored,IN,2026-06-18T00:00:00Z,2026-06-25T00:00:00Z,"internal_watchlist","bank_account:****8842",0,analyst_flagged
iof_d84f21a6,nagad_number,+880 1911-***223,medium,64,monitored,BD,2026-06-25T05:12:00Z,2026-06-28T11:40:00Z,"telegram","wallet_address:bc1q7f...a92d",0,network_inferred
iof_e93b7d12,routing_number,021000021 · Chase mule acct,high,87,verified,US,2026-06-14T16:20:00Z,2026-06-27T08:55:00Z,"partner_report","bank_account:****4471",2,verified_by_analyst
iof_44a9c8f0,swift_bic,DEUTDEFF500,medium,70,review,DE,2026-06-16T10:00:00Z,2026-06-25T09:30:00Z,"partner_report","iban:GB29 NWBK 6016 1331 9268 19",1,pending_review
iof_2f7c5e91,pix_key,cpf:***.456.789-**,high,83,verified,BR,2026-06-22T13:45:00Z,2026-06-28T20:10:00Z,"scam_payment_page","wallet_address:bc1q7f...a92d",2,verified_by_analyst
iof_b016d3a4,mpesa_number,+254 7**-***821,medium,62,monitored,KE,2026-06-19T09:15:00Z,2026-06-26T14:05:00Z,"telegram","merchant_account:QuickPay Solutions",0,network_inferred
iof_9a51ef3c,paypal_email,payout.****@proton.me,high,79,review,Global,2026-06-21T04:30:00Z,2026-06-27T22:50:00Z,"scam_payment_page;partner_report","card_bin:481234******5678",1,pending_review
Subscribe to mule-risk signals that matter.
Subscribe to the indicators that matter — filtered by risk level, type, or region — and receive updates automatically by email or through the API, on a schedule that fits your workflow.
Filtered subscriptions
Subscribe by risk level, entity type, region, or source, so you only receive indicators relevant to your team.
Regular delivery
Receive updates in real time, hourly, or as a daily digest — depending on your team's workflow.
Email & API delivery
Every subscription can be delivered as an email digest, or pulled and pushed directly through the API.
Built for fraud and AML workflows.
Enrich investigations, prioritize alerts, and monitor suspicious payment infrastructure across the digital payment ecosystems your team monitors.
Mule account detection
Identify accounts, payment identifiers, and wallets that surface in fraud-linked environments.
Payment identifier intelligence
Detect aliases, QR codes, and payment identifier signals tied to scam pages and fake merchants.
Investigation support
Give analysts evidence-backed context for alerts, reviews, and case work.
Infrastructure monitoring
Track websites, channels, and merchant fronts reusing suspicious details.
AML & compliance enrichment
Enrich regulatory reviews with external intelligence on high-risk identifiers, aligned with your compliance reporting requirements.
Partner intelligence sharing
Structured, evidence-backed reporting for authorized financial crime teams.
Questions fraud and compliance teams usually ask.
Transaction monitoring looks at what happens inside your own systems, after money has already moved. Antid Cover monitors the mule accounts, payment identifiers, and fraud infrastructure being built and shared outside your institution — in Telegram channels, scam pages, and underground forums — so an indicator can reach you before it ever appears in your transaction data.
Indicators are collected from illegal online casinos, Telegram fraud channels, underground forums, shadow payment networks, scam and phishing infrastructure, and reports submitted by partner institutions. Collection focuses on identifying and structuring signals already circulating in these channels, not on accessing private or protected systems. Every indicator is enriched with source context so your analysts can see exactly where it came from.
Every indicator carries a risk score, source context, and supporting evidence, and goes through mandatory analyst review before being marked verified — nothing is auto-published into your feed unreviewed. Precision genuinely varies by indicator type and source, which is why we'd rather show you the review process than quote a single blanket number.
No. Antid Cover is designed to sit alongside what you already run. Indicators arrive through the API, a machine-readable JSON/CSV feed, or the analyst portal, so they can be dropped into your existing transaction monitoring, case management, or SAR workflow rather than requiring a new system.
Yes — cases built in the platform capture the linked indicators, evidence, and analyst notes tied to an investigation, giving your team a timestamped record to support a suspicious activity report to your local financial intelligence unit, rather than reconstructing that trail after the fact.
Most teams start with a scoped pilot — typically 14–30 days. Request a demo and we'll walk through what a pilot would look like for your team.
See suspicious payment infrastructure before it's reused.
Explore how Cover supports mule account monitoring, payment fraud intelligence, and evidence-backed investigations.
Thanks — request received.
Our team will reach out to the email you provided. In the meantime, the product brief is available above.