Leader of 15,000-strong money mule network for cybercriminals pleads guilty in US
Oleg Korniev, a Ukrainian-Russian dual citizen, admitted helping run Your Mule Cashout, which laundered millions stolen from US bank accounts through unwitting money mules.
At a glance
- Oleg Korniev, 42, pleaded guilty to money laundering, computer fraud conspiracy and aggravated identity theft charges, according to The Record and BleepingComputer.
- Your Mule Cashout used more than 15,000 unwitting mules recruited through fake job offers.
- The network processed over $10 million stolen from more than 750 US bank accounts compromised with malware.
- Korniev faces between 2 and 50 years in prison; no sentencing date has been reported.
Oleg Korniev, a 42-year-old dual citizen of Ukraine and Russia, has pleaded guilty in US federal court to helping lead Your Mule Cashout (YMCO), a network that laundered money stolen by cybercriminals through more than 15,000 unwitting money mules, The Record and BleepingComputer reported on October 9. The plea came on Thursday, October 8, and closes another chapter in a case that began more than a decade ago.
What happened
According to BleepingComputer, Korniev pleaded guilty to money laundering, aggravated identity theft, conspiracy to commit money laundering, conspiracy to commit computer fraud and conspiracy to commit access device theft. He faces a minimum of two years and a maximum of 50 years in prison. Neither publication reported a sentencing date.
The Record said Korniev was arrested in North Carolina last December, nearly nine years after a grand jury indicted him alongside Moldovan national Serghei Ivanovich Tomuz, who allegedly ran the cash-out team in Moldova. Tomuz's US case was terminated in May, the outlet reported.
How the scheme worked
YMCO operated from 2007, according to both reports. The group recruited mules through spam emails and fake company websites advertising jobs, running an apparently legitimate hiring process that required applicants to provide their bank details. Recruits were told they would be processing payments for legitimate businesses.
Cybercriminals who had used malware to break into victims' bank accounts transferred the stolen funds into the mules' accounts. The mules then wired the money, mostly through Western Union and MoneyGram, to "cash-out contractors" in Moldova, Ukraine, Russia or Latvia, who passed it back to YMCO in exchange for a cut, BleepingComputer reported.
According to BleepingComputer, YMCO processed more than $10 million stolen from over 750 US bank accounts at more than 35 banks, with actual and intended losses to confirmed victims exceeding $14.7 million. Korniev confirmed he laundered at least $7 million of the $9.7 million received from cybercriminals. The network also allegedly ran similar schemes in Germany, Italy, the United Kingdom and Australia.
Assistant Attorney General A. Tysen Duva said that money mules play crucial roles in cybercrime, BleepingComputer reported.
Earlier prosecutions
Four other YMCO members were arrested abroad more than a decade ago, extradited to the Western District of North Carolina and sentenced in 2018 to between 37 and 63 months in prison after pleading guilty to conspiracy to commit money laundering. Each was also ordered to pay more than $9.1 million in restitution, according to BleepingComputer.
Why it matters
The case shows how banking malware operations depend on laundering networks that exploit job seekers. Fake remote job offers asking applicants to receive and forward payments remain a common recruitment method, and people who take part can face criminal liability even if they did not know the money's origin.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



