- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,425
Your bank thinks it's checking a living person, but actually a diplomatic label with a passport from a Telegram.

Cybercriminals have turned money laundering into a full-fledged shadow service with “technical support”, automation and artificial intelligence. KELA experts found out that scammers are increasingly not looking for front persons manually, but buy ready-made infrastructure to withdraw money through Telegram, darknet and closed forums.
The scheme is called Mule-as-a-Service or MaaS. In fact, criminals rent already prepared bank accounts, cryptocurrency wallets and financial services accounts registered for stolen or fake personalities. Such sites work almost as legal online services. Sellers offer guarantees, replacement of blocked accounts and even round-the-clock customer support.
Cash “multimes” help to hide the origin of the stolen funds. Through their accounts, the money received from phishing, ransomware, hacking of bank accounts and investment fraud passes through their accounts. The funds are quickly split into many transfers, drive through different banks and cryptocurrency services, after which they withdraw in the form of cash or digital assets.
The authors of the report note that criminal groups are increasingly using artificial intelligence to bypass bank checks. Generating models help create fake passports and driver’s licenses with realistic protective elements. To undergo video checks, attackers use deepfakes, and voice checks bypass by cloning speech. On underground forums, instructions are already being published on how to use ChatGPT and RunwayML to create videos with “live” persons undergoing identity verification.
Another trend is related to automation. Special programs imitate the behavior of an ordinary client of the bank. They pay for utilities, make small purchases and gradually form a “reliable” history of operations. After such a “warming up” of the bills is used to transfer large sums.
Special attention was paid to Latin America. In Brazil, criminals massively use the so-called Contas Laranja – invoices issued on front persons or stolen from real owners. The popularity of the instant payment system PIX greatly simplified the withdrawal of money. According to KELA, only in Telegram found about 250 thousand messages related to the purchase, sale and lease of such accounts.
A similar situation is observed in Argentina and Colombia. There, attackers actively use local digital wallets and banking services to quickly transfer funds and convert money into cryptocurrency. In underground communities, bank accounts, instructions for bypassing checks and even ready-made sets of documents are openly sold to register new accounts.
According to KELA experts, traditional systems for tracking suspicious transfers to banks are no longer enough. Financial institutions will have to pay more attention to user behavior analysis, digital identity verification of customers and monitor underground sites where they sell tools to circumvent protection.

Cybercriminals have turned money laundering into a full-fledged shadow service with “technical support”, automation and artificial intelligence. KELA experts found out that scammers are increasingly not looking for front persons manually, but buy ready-made infrastructure to withdraw money through Telegram, darknet and closed forums.
The scheme is called Mule-as-a-Service or MaaS. In fact, criminals rent already prepared bank accounts, cryptocurrency wallets and financial services accounts registered for stolen or fake personalities. Such sites work almost as legal online services. Sellers offer guarantees, replacement of blocked accounts and even round-the-clock customer support.
Cash “multimes” help to hide the origin of the stolen funds. Through their accounts, the money received from phishing, ransomware, hacking of bank accounts and investment fraud passes through their accounts. The funds are quickly split into many transfers, drive through different banks and cryptocurrency services, after which they withdraw in the form of cash or digital assets.
The authors of the report note that criminal groups are increasingly using artificial intelligence to bypass bank checks. Generating models help create fake passports and driver’s licenses with realistic protective elements. To undergo video checks, attackers use deepfakes, and voice checks bypass by cloning speech. On underground forums, instructions are already being published on how to use ChatGPT and RunwayML to create videos with “live” persons undergoing identity verification.
Another trend is related to automation. Special programs imitate the behavior of an ordinary client of the bank. They pay for utilities, make small purchases and gradually form a “reliable” history of operations. After such a “warming up” of the bills is used to transfer large sums.
Special attention was paid to Latin America. In Brazil, criminals massively use the so-called Contas Laranja – invoices issued on front persons or stolen from real owners. The popularity of the instant payment system PIX greatly simplified the withdrawal of money. According to KELA, only in Telegram found about 250 thousand messages related to the purchase, sale and lease of such accounts.
A similar situation is observed in Argentina and Colombia. There, attackers actively use local digital wallets and banking services to quickly transfer funds and convert money into cryptocurrency. In underground communities, bank accounts, instructions for bypassing checks and even ready-made sets of documents are openly sold to register new accounts.
According to KELA experts, traditional systems for tracking suspicious transfers to banks are no longer enough. Financial institutions will have to pay more attention to user behavior analysis, digital identity verification of customers and monitor underground sites where they sell tools to circumvent protection.