Antifraud.in / Platform
Request demo
Payment Risk Intelligence

Detect mule accounts and risky payment identifiers before losses occur

Antifraud.in provides access to Antid Cover — a payment risk intelligence service that helps banks, PSPs, and compliance teams detect suspected mule accounts, risky payment identifiers, and fake merchant fronts before losses escalate.

Mule & Payment Risk Signalscontinuously updated & scored
Payment Identifier Coverageidentifiers, wallets, merchants
Feed & APIJSON / CSV integration
Compliance-supporting intelligenceevidence-backed indicators, source context, audit trail
Problem

Payment risk moves faster than transaction monitoring.

Payment ecosystems are fast and fragmented. Mule operators reuse bank accounts, payment identifiers, QR codes, and fake merchant pages across channels — and rotate them before internal systems catch up.

By the time an identifier appears in your monitoring, it has already been used — often somewhere you can't see.

Cover Service moves fraud teams earlier in the detection cycle by turning external mule-risk signals into structured, evidence-backed intelligence.

01
Mule and rented bank accountsUsed to receive, move, and disguise fraud proceeds across institutions.
02
Payment identifiers, QR codes, and aliasesDistributed across scam pages, channels, and high-risk payment flows.
03
Fake merchants and payment pagesShort-lived infrastructure that disappears before manual review.
Why intelligence, not just monitoring

Traditional monitoring watches your side of the transaction. COVER watches the infrastructure behind it.

Transaction monitoring tells you something went wrong after money has already moved. External intelligence tells you an account, identifier, or payment page was already suspicious — often before it ever reaches your systems.

Detects suspicious transactions
Detects suspicious payment infrastructure
Limited to your institution
Correlates signals across external sources
Reactive investigations
Early intelligence before transactions escalate
Alerts with limited context
Evidence-backed indicators with linked entities
Internal visibility
Cross-source intelligence and analyst review
Risk signals

Like a CTI feed — for payment fraud.

Security teams use cyber threat intelligence to detect malicious infrastructure. Cover applies the same model to financial crime, delivering Mule & Payment Risk Signals ready for your fraud and AML workflows.

01

Mule & Payment Risk Signals

Suspicious accounts, UPI IDs, cards, wallets, phones, merchants, URLs, Telegram handles, and the source links that tie them together.

02

Risk & context

Each indicator carries a risk level, source context, first-seen data, status, screenshots, related entities, and analyst notes.

03

Evidence-backed review

Analysts see why an identifier is suspicious, where it appeared, and how it connects to broader payment infrastructure.

Data sources

From sources others can't reach.

Cover monitors high-risk digital environments where suspicious payment identifiers surface first — long before they reach internal systems.

01Illegal betting and unlicensed casino ecosystems
Betting & casino ecosystemsHigh · 79

Deposit and payout handles used by unlicensed betting platforms — frequently reused as mule infrastructure once a book folds or rebrands under a new name.

Example indicator
upi · deepak.wins007@paytm
deposit handle · 4 unlicensed platforms
Continuously monitored for reused infrastructure
02Telegram fraud channels and drop recruitment groups
Telegram recruitment channelsHigh · 84

Recruitment posts, channel admins, and the payment handles shared to pay drops for handing over account access or receiving funds.

Example indicator
tg · @easycashjobs_in
recruitment channel · 1,240 members
Actively monitored for new recruitment activity
03Scam websites and fake merchant pages
Scam & fake merchant pagesHigh · 90

Checkout pages and fake merchant fronts that clone real brands to harvest card, UPI, and OTP details from unsuspecting buyers.

Example indicator
url · secure-payzone[.]shop
cloned courier checkout · live 6 days
Monitored on an ongoing basis
04Shadow payment networks and cashout infrastructure
Cashout infrastructureHigh · 87

Wallets and P2P exchange handles used to fragment and launder proceeds across many small transfers, then consolidate downstream.

Example indicator
wallet · bc1q7f...a92d
fragmented transfers · 6 known mule accounts
Under continuous surveillance
05Partner-submitted reports and investigation evidence
Partner intelligence pipelineVerified pipeline

Confirmed cases submitted directly by banks and PSPs — reviewed by analysts and merged into the same feed as OSINT-derived indicators, with the evidence trail your team can reference for regulatory filings.

Reports this month
136
Converted to indicators
78%
Contributing institutions
17
Median review time
4.2 hrs
Available to authorized financial crime teams
Detection coverage

What Cover tracks.

The entities fraud networks use to receive, move, monetize, and reuse stolen payment details.

Tracking Mule Accounts used by
Illegal Casinos
Built for

Built for financial crime and risk teams.

Cover supports the institutions and teams responsible for detecting, investigating, and reporting payment fraud across the ecosystem — including regulated entities filing suspicious activity reports with their local financial intelligence unit.

Banks
PSPs & payment aggregators
Payment gateways
Fintech risk teams
AML & compliance teams
Investigation units
Detection flow

From raw signal to verified intelligence.

Cover is a workflow, not a list — collection, verification, enrichment, scoring, monitoring, and reporting.

01Collect
Monitor high-risk sources and fraud-linked environments. Example: illegal casino site flagged, added to source list.
02Normalize
Structure identifiers into consistent records. Example: "rohit****@okaxis" parsed as upi_id, region IN.
03Verify
Review evidence and source context. Example: cross-checked against 3 sources, screenshot attached.
04Enrich
Add bank, region, type, and entity context. Example: matched to HDFC Bank, linked phone number.
05Score
Prioritize by risk and confidence. Example: risk_score 92 — high, verified by analyst.
06Report
Feed investigation and compliance workflows. Example: pushed to JSON feed, webhook notified.
Signal engine

Fraud signals don't arrive structured. We make them that way.

Fraud infrastructure is advertised in plain sight — in channels, on scam pages, in cashout groups. It arrives as unstructured text. This is what happens to it before it reaches your systems.

01
Raw captureFragments collected from monitored channels, marketplaces, and scam infrastructure.
02
Parse, classify, scoreEach fragment is typed, normalized, and assigned a risk level.
03
ExportThe result is a structured indicator, ready for your API or feed.
Platform

A workspace for financial crime teams.

Search, filter, and review suspicious identifiers with evidence, entity relationships, status management, and reporting — built for analysts, not developers.

Filters
Risk level
IdentifierBank
SourceScam / Telegram
StatusVerified
RegionIndia
Records · 3 of 1,284 Verified
Suspicious payment identifier
source context · evidence attached · 3 related entities
High risk
upi · rohit****@okaxisHigh · 92
Source Linked Linked
UPI ID
rohit****@okaxis
URL
pay-secure-verify[.]in
Bank acct
****8842 · HDFC
Phone
+91 98****1207
3 of 12 known connections
Mule account candidate
multiple appearances across high-risk sources
Review
acct · ****8842 · HDFCReview · 74
Linked Linked Context
Bank acct
****8842 · HDFC
UPI ID
rohit****@okaxis
Phone
+91 98****1207
Telegram
@drop_recruit_in
3 of 7 known connections
Fake merchant payment page
scam infrastructure · 2 related identifiers
High risk
url · pay-secure-verify[.]inHigh · 88
Linked Linked Source
URL
pay-secure-verify[.]in
UPI ID
rohit****@okaxis
Bank acct
****8842 · HDFC
Telegram
@drop_recruit_in
2 of 9 known connections
No records match this risk level in the sample.
Case management

Every indicator rolls up into a case.

Link accounts, cards, and other indicators to a case as your team investigates, track status, priority, and ownership, and keep a timestamped record you can hand to a regulator or auditor.

Machine-readable feed

Built to plug straight into your systems.

Every indicator ships as structured JSON or CSV — continuously updated, scored, and ready to drop into transaction monitoring, AML case tools, or an internal risk engine. No manual copy-paste, no PDFs to parse.

JSON
Records & webhooksPull on a schedule or receive new high-risk indicators as they're verified.
CSV
Bulk exportLoad into spreadsheets, blocklists, or batch screening jobs.
API
Direct lookupQuery a single identifier in real time during onboarding or payment review.
Notifications

Subscribe to mule-risk signals that matter.

Subscribe to the indicators that matter — filtered by risk level, type, or region — and receive updates automatically by email or through the API, on a schedule that fits your workflow.

Filtered subscriptions

Subscribe by risk level, entity type, region, or source, so you only receive indicators relevant to your team.

Regular delivery

Receive updates in real time, hourly, or as a daily digest — depending on your team's workflow.

Email & API delivery

Every subscription can be delivered as an email digest, or pulled and pushed directly through the API.

Use cases

Built for fraud and AML workflows.

Enrich investigations, prioritize alerts, and monitor suspicious payment infrastructure across the digital payment ecosystems your team monitors.

Mule account detection

Identify accounts, payment identifiers, and wallets that surface in fraud-linked environments.

Payment identifier intelligence

Detect aliases, QR codes, and payment identifier signals tied to scam pages and fake merchants.

Investigation support

Give analysts evidence-backed context for alerts, reviews, and case work.

Infrastructure monitoring

Track websites, channels, and merchant fronts reusing suspicious details.

AML & compliance enrichment

Enrich regulatory reviews with external intelligence on high-risk identifiers, aligned with your compliance reporting requirements.

Partner intelligence sharing

Structured, evidence-backed reporting for authorized financial crime teams.

FAQ

Questions fraud and compliance teams usually ask.

Transaction monitoring looks at what happens inside your own systems, after money has already moved. Antid Cover monitors the mule accounts, payment identifiers, and fraud infrastructure being built and shared outside your institution — in Telegram channels, scam pages, and underground forums — so an indicator can reach you before it ever appears in your transaction data.

Indicators are collected from illegal online casinos, Telegram fraud channels, underground forums, shadow payment networks, scam and phishing infrastructure, and reports submitted by partner institutions. Collection focuses on identifying and structuring signals already circulating in these channels, not on accessing private or protected systems. Every indicator is enriched with source context so your analysts can see exactly where it came from.

Every indicator carries a risk score, source context, and supporting evidence, and goes through mandatory analyst review before being marked verified — nothing is auto-published into your feed unreviewed. Precision genuinely varies by indicator type and source, which is why we'd rather show you the review process than quote a single blanket number.

No. Antid Cover is designed to sit alongside what you already run. Indicators arrive through the API, a machine-readable JSON/CSV feed, or the analyst portal, so they can be dropped into your existing transaction monitoring, case management, or SAR workflow rather than requiring a new system.

Yes — cases built in the platform capture the linked indicators, evidence, and analyst notes tied to an investigation, giving your team a timestamped record to support a suspicious activity report to your local financial intelligence unit, rather than reconstructing that trail after the fact.

Most teams start with a scoped pilot — typically 14–30 days. Request a demo and we'll walk through what a pilot would look like for your team.

Request demo

See suspicious payment infrastructure before it's reused.

Explore how Cover supports mule account monitoring, payment fraud intelligence, and evidence-backed investigations.

Please enter your name.
Please enter a valid work email.
Please enter your company.
Product brief