From Stolen Data To Frozen Bank Account
Vinitha Balakrishnan
1 Oct 2026 12:00 PM IST

Cyber fraud frequently begins with compromised personal data and ends in accounts belonging to persons unaware of the scheme. This article examines the protections and liabilities that arise along that chain.
A friend, a neighbour, a hostel mate or someone otherwise known to you comes with what seems a very simple request. “My account is not working. I need to withdraw some cash. I have a tax refund being credited. Can I use your account just for this? I will take out the amount once it is credited.” Nothing in the request appears threatening or criminal. It is presented as a small favour for someone you know.
An account used in this way is called a mule account. It receives money obtained through fraud and passes it on so that the trail back to the fraudster is broken. The person who holds the account is called a money mule. Such an account often belongs to a student. Young persons increasingly figure in cases involving suspected mule accounts. The Kerala High Court, in Sinana Farvin v. Kerala Gramin Bank (W.P.(C) No. 43188 of 2025, decided on 10 July 2026; 2026:KER:50777; 2026 LiveLaw (Ker) 375), while dealing with the case of a 21-year-old account holder, referred to a broader pattern in which persons who had just crossed the age of majority had opened multiple bank accounts which were then used as money mules. The Court also observed that substantial amounts could be channelled through such accounts within a short period after they were opened. A student is approached because the account is new, is a zero-balance or student account, or has otherwise been identified as one through which money can be received and withdrawn. The student often has no idea where the money is coming from or whose money it is.
The next part of the story unfolds quickly. Money is credited into the student's account. The person who asked for the favour returns and says “The money has come. Shall we go and withdraw it?” The student either accompanies that person or allows him to operate the account. If the bank raises a suspicion or stops the transaction, the person who arranged it disappears. Another ATM or another account is tried. Where some amount remains, an attempt is made to withdraw it by cash or cheque. RBI has described money mules as persons recruited to receive and transfer funds obtained through fraud, including phishing and identity theft. RBI has also recognised that some such persons are themselves innocent, while others are complicit. Its public awareness material, “Your Bank Account, Only your Money!”, warns in simple terms that allowing others to operate one's bank account for movement of funds can have serious legal consequences and can even lead to imprisonment.
One fraud thus leaves two sets of people to face its consequences. The first is the person who lost the money. The second is the student who lent the account. He, too, is in a sense a victim. Once the transaction is detected his account is frozen. He has to explain the transactions to the bank and the police and, depending upon the material collected, could face an FIR, interrogation, arrest and criminal proceedings. The family is drawn in when the disputed amount has to be restored and the parents step in to protect him. Meanwhile the people who planned the transaction stay out of sight. Once the amount is restored and the bank dispute ends there is strong pressure to treat the matter as closed. But returning the money does not tell anyone who obtained it, who recruited the account holder or who organised the transaction.
The fraud does not begin at the bank account. By the time money reaches a student's account it has usually travelled some distance. In most cases someone's personal information has been obtained and misused. The victim has been contacted by a phone call, a message or a social-media post. A false identity or a phishing link has been used. The victim has been persuaded to share an OTP or other details or to make a payment. The money has then passed through several accounts before it reaches the one that the bank or the police finally identify.
Digital payments have made this movement of money much easier. UPI allows instant transfers between bank accounts and is now part of everyday life. NPCI itself warns users about fake links, QR-code fraud, unknown apps and callers who pose as officials. This does not mean that Google Pay or PhonePe cause
these frauds or that every such transaction results from a leak in a particular payment app. The problem lies elsewhere. A person's mobile number, identity documents, bank details and transaction history now sit with many different companies. When any of this information leaks or is stolen it becomes a tool in the hands of the fraudster.
This is where privacy enters the picture. In Justice K.S. Puttaswamy (Retd.) v. Union of India (W.P.(C) No. 494 of 2012, decided on 24 August 2017) the Supreme Court held that privacy is a fundamental right and linked it to dignity, autonomy and liberty. In the Aadhaar judgment (K.S. Puttaswamy (Retd.) v. Union of India, W.P.(C) No. 494 of 2012, decided on 26 September 2018) the Court recognised informational privacy as a part of that right. It noted that the threat to privacy comes not only from the State but also from private parties. It also said that the country needed a strong law to protect personal data. That need is easy to see today. A person's identity is no longer a single paper document. It is spread across phones, email accounts, bank accounts, UPI records, photographs, passwords and social-media profiles.
The Digital Personal Data Protection Act, 2023 (Act 22 of 2023) is the law Parliament enacted in response. It is being brought into force in stages. The Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), were notified on 13 November 2025. Most of the substantive provisions take effect eighteen months later, by 13 May 2027. The Act has nothing to do with mule accounts. It does not make lending an account an offence and it does not decide when the police or a bank can freeze an account. Its role lies at the start of the chain, where personal data is collected and stored. Banks, payment apps, telecom companies, e-commerce platforms and other entities that decide how personal data is processed are “Data Fiduciaries” under the Act. Section 8(5) requires them to take reasonable security safeguards to prevent a personal data breach. Section 8(6) requires them to report any breach to the Data Protection Board and to each affected person. Failure to take reasonable safeguards can attract a penalty of up to ₹250 crore. Failure to report a breach can attract a penalty of up to ₹200 crore. Timely notice matters to the ordinary person. Someone who learns early that his data has leaked can change passwords, alert the bank and treat unexpected calls with suspicion before a fraudster uses the information.
The Act also places duties on individuals. Section 15 forbids a person from impersonating another while providing personal data. A fraudster who uses someone else's identity acts in breach of this duty. At the same time Section 17 exempts processing for the prevention, detection, investigation or prosecution of offences from most of the Act's obligations. The Act therefore does not stand in the way of a bank or the police tracing the money. One gap remains. Section 44 omits Section 43A of the Information Technology Act, which allowed a person to claim compensation from a company that negligently failed to protect sensitive personal data. The DPDP Act provides no such compensation. Penalties imposed by the Board go to the Government. A person whose data leaked and who later lost money to fraud must look to other remedies for recovery.
The law therefore has to protect several interests at once. The victim's money has to be secured and where possible returned. Personal data has to be kept safe. Banks and payment systems have to spot suspicious transactions and act on them. At the same time a person whose account was used as a mule cannot be treated as guilty only because the account is in his or her name. The question becomes most pressing when the account is frozen. Section 102 of the Code of Criminal Procedure allowed the police to seize property alleged or suspected to be stolen or found in circumstances that created suspicion of an offence. In State of Maharashtra v. Tapas D. Neogy (Criminal Appeal No. 947 of 1999, decided on 16 September 1999; 1999 INSC 417) the Supreme Court held that a bank account is “property” under Section 102. The police could therefore stop its operation where the account had a direct link with the offence under investigation. In Teesta Atul Setalvad v. State of Gujarat (Criminal Appeal No. 1099 of 2017, decided on 15 December 2017; 2017 INSC 1239) the Court repeated that a bank account could be seized under Section 102 and that the account holder need not be given notice first.
The power has limits. In M.T. Enrica Lexie v. Doramma (Civil Appeal No. 4167 of 2012, decided on 2 May 2012) the Supreme Court held that the property seized must have a real connection with the offence. An account cannot be treated as tainted only because it belongs to someone linked to the investigation. In Shento Varghese v. Julfikar Husen (Criminal Appeal Nos. 2531–2532 of 2024, decided on 13 May 2024;
2024 INSC 407; 2024 LiveLaw (SC) 371) the Court examined the duty to report a seizure to the Magistrate and the effect of failing to do so. These decisions continue to guide the courts under the BNSS.
The Bharatiya Nagarik Suraksha Sanhita, 2023 now contains the corresponding provision in Section 106. Section 107 separately deals with attachment, forfeiture and restoration of property believed to be derived from criminal activity. The Kerala High Court considered the difference between the two in Headstar Global Pvt. Ltd. v. State of Kerala (Crl.M.C. No. 3740 of 2025, decided on 2 June 2025; 2025:KER:39285; 2025 LiveLaw (Ker) 339). The case related to a third-party company's account into which money had allegedly travelled after a cheating transaction. The Court held that a police officer can seize under Section 106 and report to the Magistrate afterwards. Attachment under Section 107 can be made only on the orders of the Magistrate. The procedure under Section 107 cannot be bypassed by invoking Section 106. The Supreme Court dismissed the State's special leave petition (SLP (Crl.) No. 13433 of 2025) on 11 September 2025, declining to interfere on the peculiar facts of the case.
A Division Bench of the Bombay High Court at Nagpur followed Headstar Global in Kartik Yogeshwar Chatur v. Union of India (Criminal Writ Petition No. 321 of 2025 and connected cases, decided on 20 November 2025; 2025:BHC-NAG:12612-DB). The Bench held that an investigating agency could not debit-freeze or attach a bank account under Section 106 as a substitute for the procedure under Section 107. The Delhi High Court, in Neelkanth Pharma Logistics (P) Ltd. v. Union of India (W.P.(C) No. 17905 of 2024, decided on 20 February 2025; 2025 LiveLaw (Del) 236), also cautioned against freezing an entire account where only a small and identifiable amount was disputed. The caution applies with greater force where the account holder is neither an accused nor a suspect.
A freeze imposed by the bank on its own suspicion must not be confused with a police seizure. The Kerala High Court dealt with this situation in Abdul Azeez v. Union of India (W.P.(C) Nos. 32516 and 32291 of 2024, decided on 19 November 2025; 2025:KER:88312; 2025 LiveLaw (Ker) 764). The Court permitted a bank to impose a debit freeze without prior notice where it had reason to believe that the transactions were suspicious. The bank had to communicate the reasons to the account holder and give an opportunity to explain. The freeze could continue for three months and had to be lifted if no law-enforcement action followed within that period.
The Court revisited these guidelines in Ajith P.R. v. Union of India (W.P.(C) No. 48300 of 2025, decided on 14 July 2026; 2026:KER:52379; 2026 LLBiz HC(KER) 135). It recorded that the Indian Cyber Crime Coordination Centre had formulated an SOP on the NCRP-CFCFRMS system and that the earlier guidelines were being misused. Under the revised guidelines a bank that suspects an account is being used as a money mule can impose a debit freeze. It must promptly inform the account holder by SMS or email and send the reasons by registered post within three working days. The account holder has one month to submit an explanation. If the bank is satisfied with it, the account has to be unfrozen. If not, further action follows.
The revision followed the Court's earlier judgment in Sinana Farvin. There the Court found that the material prima facie indicated the use of the account as a money mule. It directed registration of an FIR under Section 111 of the Bharatiya Nyaya Sanhita and investigation. The Court also noted a troubling pattern in the litigation itself. Near-identical writ petitions seeking unfreezing had resulted in uniform orders permitting account holders to operate their accounts subject only to a lien on the disputed amount. Mule account holders were then using such orders to resume their activities. Section 111 requires care, however. In Ajith P.R. the Court, referring to Sinana Farvin, observed that cyber-crimes fall within the definition of organised crime. It would still be wrong to say that every person whose account receives money from a cyber fraud has committed organised crime. Section 111 requires continuing unlawful activity, an organised crime syndicate and material benefit, amongst other things. Those ingredients have to be established in each case.
Other penal provisions also arise depending upon the facts. Section 318 of the Bharatiya Nyaya Sanhita deals with cheating. Section 66D of the Information Technology Act deals with cheating by personation using a communication device or computer resource. These provisions have different ingredients and are not interchangeable. More than one of them is often invoked depending upon how the fraud was carried out and the role attributed to each person. This matters for young account holders. A person who knowingly
opens and operates an account to receive and pass on fraudulent funds stands in a very different position from one whose account was used without his knowledge or who was deceived into lending it. Knowledge and participation have to be proved from the evidence. The mere fact that money passed through the account is not enough. Freezing the account protects the victim's money. But the investigation cannot stop there. The person who recruited the account holder, the persons who withdrew or moved the money and those who committed the original fraud are all part of the chain. The National Cyber Crime Reporting Portal and the Citizen Financial Cyber Fraud Reporting and Management System exist precisely to follow the money trail beyond the first account identified.
For an ordinary account holder the lesson is simpler. If an unknown amount is credited to the account, do not withdraw or transfer it because somebody telephones and asks for it. This applies equally when the person who borrowed the account comes back to say the money has arrived. Inform the bank at once in writing. Report the matter on the National Cyber Crime Reporting Portal or by calling 1930. Preserve messages, call records, bank statements and transaction details. RBI itself gives the same advice. Let the bank and the investigating authorities verify the source and deal with the money in accordance with law. There is a lesson here for parents and educational institutions too. A young person often believes that lending a bank account to a friend is no more serious than lending a phone. It is not. A bank account is linked to the person's identity and financial history. Its use leaves a digital trail. A favour can have consequences far beyond the amount received.
Awareness about cybercrime can no longer be separated from awareness about privacy. The protection of a person's money begins with protecting the information that identifies that person. The story of the mule account is not simply a story about a frozen bank account. It can begin with leaked personal data and end in the account of a student who did not understand what was happening. By the time that account is frozen the fraud has already travelled a long way.
The real challenge for the law is not merely to freeze the last account through which the money passed. It is to protect the first victim, distinguish the exploited account holder from the knowing participant, recover the stolen money and trace the chain far enough to reach those who planned the fraud. A favour takes only a few seconds to offer. Its consequences can last much longer.
Author is an Advocate practicing at Kerala High Court. Views are personal.

