Modus operandi
A mule account is opened with genuine documents by a real person, recruited for ₹5,000 to ₹30,000 to lend their identity. It clears every KYC check, stays dormant, then activates as a pass-through for stolen funds.

Every credential is genuine. Device, footprint, behaviour and location say the intent is not.
Fraud in Indian BFSI has moved from forged documents to genuine credentials used with fraudulent intent. Sign3 reads the device, behaviour, network, footprint and image signals your current stack was never designed to carry — and surfaces intent before a single rupee is committed.




























Indian financial fraud has undergone a structural shift. The era of forged documents and impersonated identities is being replaced by a more sophisticated pattern: fraud committed with genuine credentials. Synthetic identities are assembled from valid fragments. Mule accounts are opened with fully compliant KYC. Account takeovers are executed with legitimate login credentials. In each case, the verification infrastructure confirms the identity. What it does not confirm, and was never built to confirm, is the intent behind it.

The result is a category of loss that traditional fraud systems are architecturally unable to prevent. Not because they are poorly configured, but because they answer a question that no longer separates legitimate customers from fraudulent ones.
For each: how it works, why current systems miss it, how Sign3 catches it — and what it measured in production.

A mule account is opened with genuine documents by a real person, recruited for ₹5,000 to ₹30,000 to lend their identity. It clears every KYC check, stays dormant, then activates as a pass-through for stolen funds.
KYC confirms the identity is authentic, not why the account is being opened. Bureau returns no negative history, so detection happens only after the money has moved.
Sign3 reads the digital and behavioural profile at account opening — recently activated phone, minimal footprint, shared device, coached session. Individually flags; together, a conviction.
73%
of money mules flagged at onboarding — 3× better than the legacy system it replaced.
Banking client, production deployment
Fraud evolves faster than the controls built to stop it, and it exploits the gaps between them. Each check below is necessary. None of them is sufficient.
Sign3 lives in that white space too.
Device, behaviour, network and digital-footprint signals resolved into one applicant profile — the inputs a credit file never captures.





Cumulative outcomes from live deployments across banking, lending, and credit card portfolios.
73%of money mules flagged at onboarding
Banking client.
78%of fraudsters in the riskiest 5% of applicants
Personal loan provider.
503distinct fraud rings surfaced
From 69,646 numbers in one analysis window.
84%reduction in fraud approvals at onboarding
Leading fintech.
₹25 Crsaved in fraudulent disbursements
Single quarter, leading NBFC.
150accounts on a single device detected
Preventing layering of ₹2.3 Cr in fraudulent funds.




























Indian financial fraud has undergone a structural shift. The era of forged documents and impersonated identities is being replaced by a more sophisticated pattern: fraud committed with genuine credentials. Synthetic identities are assembled from valid fragments. Mule accounts are opened with fully compliant KYC. Account takeovers are executed with legitimate login credentials. In each case, the verification infrastructure confirms the identity. What it does not confirm, and was never built to confirm, is the intent behind it.
The result is a category of loss that traditional fraud systems are architecturally unable to prevent. Not because they are poorly configured, but because they answer a question that no longer separates legitimate customers from fraudulent ones.

For each: how it works, why current systems miss it, how Sign3 catches it — and what it measured in production.
A mule account is opened with genuine documents by a real person, recruited for ₹5,000 to ₹30,000 to lend their identity. It clears every KYC check, stays dormant, then activates as a pass-through for stolen funds.
KYC confirms the identity is authentic, not why the account is being opened. Bureau returns no negative history, so detection happens only after the money has moved.
Sign3 reads the digital and behavioural profile at account opening — recently activated phone, minimal footprint, shared device, coached session. Individually flags; together, a conviction.
73%
of money mules flagged at onboarding — 3× better than the legacy system it replaced.
Banking client, production deployment
A fabricated persona assembled from real fragments: valid Aadhaar, fresh phone, new email, clean selfie. No negative history, because the person never existed. Sophisticated variants warm up with small transactions first.
Each document is individually valid. Bureau returns nothing, and absence of history reads as absence of risk. The identity passes because there is nothing to fail against.
Digital Footprint tests whether the identifiers belong to a person with an established presence. A genuine identity leaves years of traces across 100+ platforms. A synthetic one does not.
78%
of fraudsters concentrated in the riskiest 5% of applicants scored.
Personal loan provider
An unauthorised party takes control of a legitimate account using valid credentials from phishing, social engineering, or a SIM swap. The login succeeds. The session behaviour changes.
Authentication verifies credentials, not the person using them. Once the login succeeds, the session is treated as legitimate for its full duration.
Behavioural Biometrics baselines how each holder interacts with their device and scores deviation in real time — inside the session, not after the transfer clears.
<30s
from session deviation to block on takeover attempts in production.
Live deployment, retail banking
A coordinated network of accounts run by a handful of people or devices. Every account passes individual verification; the coordination shows only across the network — shared devices, clustered IPs, linked funding.
Per-account scoring treats each application as independent. One account inside a 200-account ring looks ordinary. The ring is invisible to any system evaluating one at a time.
Sign3 maps relationships across accounts, devices, numbers and funding paths continuously. The ring surfaces not because one account is suspicious, but because the connections are.
503
distinct fraud rings surfaced from 69,646 numbers; one device operating 150 accounts.
Single analysis window
In Tier 2/3 markets, agents fill forms, operate devices and take selfies for applicants. The KYC documents are genuine. The person completing the application is not the applicant.
Face match confirms the selfie matches the Aadhaar and liveness confirms a real person. Neither confirms the person holding the device is the applicant.
Image Intelligence reads background scene, device metadata and Face Vault history; Behavioural Biometrics detects coached capture. Right documents, wrong behavioural signature.
7.1%
of approved selfies flagged as assisted captures; 1,400+ duplicate identity clusters found.
19,986 KYC selfies reviewed





Fraud evolves faster than the controls built to stop it, and it exploits the gaps between them. Each check below is necessary. None of them is sufficient.
Sign3 lives in that white space too.
Device, behaviour, network and digital-footprint signals resolved into one applicant profile — the inputs a credit file never captures.





Cumulative outcomes from live deployments across banking, lending, and credit card portfolios.
73%of money mules flagged at onboarding
Banking client.
78%of fraudsters in the riskiest 5% of applicants
Personal loan provider.
503distinct fraud rings surfaced
From 69,646 numbers in one analysis window.
84%reduction in fraud approvals at onboarding
Leading fintech.
₹25 Crsaved in fraudulent disbursements
Single quarter, leading NBFC.
150accounts on a single device detected
Preventing layering of ₹2.3 Cr in fraudulent funds.
We'll score it, surface the fraud patterns your current stack missed, and walk you through what we found. Your data, our scoring. No commitment, no integration, no decision required until you've seen the result.