Group-IB reported a fraud operation targeting B2B fintech platforms in France, where criminals created mule accounts to receive and move illicit funds. The activity focused on abusing business onboarding processes, allowing attackers to register accounts that appeared legitimate and could be used as intermediaries in broader financial crime schemes.
The operation highlights how fintech services can be exploited through fraudulent account creation rather than direct system intrusion. By establishing mule accounts on business-focused payment platforms, the actors gained infrastructure for laundering proceeds, obscuring transaction trails, and supporting downstream fraud against financial institutions and their customers.

See the actors and campaigns active against you right now.
1 event from the most recent confirmed update back to the earliest known activity.
Group-IB published a blog post detailing a fraud operation involving mule account creation on B2B fintech platforms in France. No earlier discrete real-world events are described in the provided reference content.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.