By Joshua Clouston, Head of Product, ezyshield

News 8 min read

When PayTo Mandates Go Rogue: Inside Australia's $3 Million Zombie Account Fraud

250 zombie mule accounts. $3 million stolen. How fraudsters abused Revolut's PayTo feature weeks after launch - and what account verification would have stopped.

A businessperson's hand holding a smartphone up to tap on a contactless payment terminal, with a blurred retail interior in the background

Revolut launched PayTo in March 2026 with the tagline “a smarter, safer way to move money.” Within eight weeks, approximately 250 pre-staged mule accounts had been used to siphon roughly $3 million from Australian customers through fraudulent PayTo mandates. Revolut disabled the feature’s inbound top-up capability in early May. It has not named a date for restoring it.

The incident is a clear-eyed demonstration of how quickly a new payment rail can be weaponised - and a direct argument for why verifying the account at the other end of any mandate is not optional infrastructure. It is the minimum.

What PayTo Is - and Why Fraudsters Want In

PayTo is an account-to-account payment authorisation framework built on Australia’s New Payments Platform (NPP). Unlike a direct debit - where funds move on a delay with limited real-time visibility - a PayTo agreement is a mandate: a customer authorises it at their bank, and once live, funds move instantly when triggered by the receiving party.

For legitimate use cases - rent, subscriptions, recurring business billing - this is a genuine upgrade. Payers can see active mandates in their banking app, pause them, or revoke them entirely. It is purpose-built for a world where people want more control over recurring payments.

For fraudsters, PayTo offers something equally attractive: a bank-sanctioned, credentialed pipe into the real-time payments system. Once a mule account holds a valid PayTo mandate, money arrives automatically - from victims who believe they are paying someone they trust.

The new, real-time rail creates a new, real-time fraud vector. That is not a reason to avoid it. But it is a reason to build verification into the mandate authorisation step, not bolt it on later.

How the Zombie Account Attack Worked

The mechanics, pieced together from reporting by Payday News and Banking Day, appear to have run as follows.

Fraudsters created or acquired approximately 250 “zombie” or sleeper mule accounts at Revolut. These accounts sat dormant - no suspicious transaction history, no velocity flags, nothing to trigger routine monitoring - until they were needed.

Victims were then socially engineered into authorising PayTo mandates at their own banks. The most likely vector is a scam variant of the trusted-entity playbook: the victim believes they are setting up a legitimate recurring payment to a landlord, supplier, or biller. The BSB and account number they are directed to, however, belongs to a zombie mule account, not the payee they have in mind.

Because Revolut’s PayTo top-up feature had launched only weeks earlier, neither the banks holding victims’ accounts nor Revolut’s own systems had mature pattern-recognition in place for this specific attack surface. The mandates looked, to every node in the chain, like normal PayTo authorisations. They were processed accordingly.

Banking Circle - which acts as Revolut’s NPP sponsor and infrastructure provider in Australia - is part of the picture too. Industry sources cited by Banking Day point to issues within Banking Circle’s tech stack, raising questions about where in the mandate-processing chain the fraud persisted undetected and for how long.

Money moved. In real time. Into accounts that had been staged for exactly this moment.

Why “No Accounts Compromised” Misses the Point

Revolut’s public statement after suspending PayTo top-ups was carefully worded: “No Revolut customer accounts have been compromised.”

That is technically accurate. The mule accounts that received the funds were not the victims’ accounts - they were separate accounts established by the fraud network. Revolut’s own customer data was not breached in the conventional sense. No passwords were stolen. No account takeovers occurred.

But this framing sidesteps the more fundamental question. The compromise happened before Revolut ever saw the money. It happened at the moment a PayTo mandate was authorised - when no system in the chain asked the most basic question: does the destination account actually belong to the person or business the payer believes they are paying?

Confirmation of Payee (CoP) is a real-time account name verification check. Before a payment or mandate is confirmed, the payer’s bank sends a query to the destination bank: does this account number match this account name? The answer comes back as a match, a close match, or a mismatch.

If victims’ banks had run a CoP check before confirming the PayTo mandate, the name returned for that Revolut BSB and account number would not have matched the landlord, supplier, or biller the victim expected to see. The mandate would have flagged. The victim would have been prompted to stop and verify. The money would not have moved.

Australian banks are rolling out CoP now under the $100 million Scam-Safe Accord investment. But rollout is still in progress - and critically, PayTo mandates have not been consistently covered by the CoP checks that do exist for push payments. The Revolut incident landed in that gap.

The $600,000 Footnote: Gold Bullion, Mule Networks, and NAB’s Tip-off

The Revolut PayTo fraud did not arrive alone. In the same week, NSW Police Cybercrime Squad detectives charged three people over an alleged $600,000 business email compromise (BEC) scam, following a tip-off from National Australia Bank.

The method was a textbook BEC playbook: intercept or impersonate a trusted supplier’s email, alter the payment instructions with a mule account’s BSB and account number, wait for the victim business to send a legitimate invoice payment to the wrong place. The funds landed in a NAB account held by the fraud network.

What makes this case notable is the cash-out method. Rather than rapidly transferring the funds through multiple accounts to obscure the trail - which modern bank monitoring increasingly catches - the alleged mule network converted the money into physical gold. A 20-year-old woman made five separate $100,000 purchases of gold bullion at a Sydney CBD dealership over two weeks, totalling $500,000 in transactions (iTnews).

It was the gold purchases that triggered the alert. NAB’s transaction monitoring identified the pattern and provided information to Operation Dolos under Strike Force Downstream. Detectives, with JPC3 support, arrested all three at the dealership at 2:30pm on 14 May 2026. Around $300,000 was recovered; $34,000 in cash was seized from their vehicle. The trio appeared at Downing Centre Local Court, with the next hearing scheduled for 28 May.

BEC scams cost Australian businesses $12.17 million across 2,510 reported incidents in 2025 (Information Age). That figure captures only what was reported. The underlying exposure is higher.

The Pattern Is Not Coincidence

Two major Australian fraud incidents in one week, both traceable to the same structural gap: the destination account was never verified before money moved.

In the PayTo case, the gap was a mandate authorised against an account that was not owned by the intended payee - because no CoP check confirmed the match at the point of authorisation.

In the BEC case, the gap was a payment instruction sent to an account that had nothing to do with the legitimate supplier - because the paying business sent funds on altered payment details without checking the account name against the account number.

Different attack vectors. Same missing step.

This is not a new problem in isolation. The UK introduced mandatory Confirmation of Payee for the six largest banks in 2020, and has progressively extended it since. Authorised Push Payment (APP) fraud reimbursement rules, which came into force in October 2024, have added financial accountability that is driving even faster CoP adoption.

Australia is moving in the same direction - the Scam-Safe Accord’s CoP investment is real progress. But the Revolut incident demonstrates that new payment features can launch and scale faster than verification coverage extends to them. The window between “feature live” and “CoP coverage in place” is exactly the window that fraud networks look for.

What Needs to Change

Three things would directly reduce the exposure these incidents reveal.

CoP checks must extend to PayTo mandate authorisation. Confirmation of Payee was designed for push payments. The same logic applies to mandates: before a customer authorises a PayTo agreement, the destination account name should be verified against the account holder’s registered name. A mismatch should pause the authorisation and prompt the customer to verify directly. This is not an enhancement - it is a baseline.

Dormant account monitoring needs to watch receiving patterns, not just sending. Zombie accounts are engineered to look clean before a fraud event. Monitoring that scores accounts on inbound mandate velocity - especially new mandates on accounts with thin transaction histories - catches the staging phase rather than the cash-out phase. Catching it earlier means less money moves.

Fintechs entering the NPP ecosystem need clear standards for account holder aggregation risk. Revolut’s individual-account KYC may be entirely adequate. The question is whether 250 accounts sharing similar attributes - account age, activity pattern, linked device or identity markers - should have triggered an aggregated-level flag before the fraud reached $3 million. Sponsor banks and NPP participants need risk frameworks that operate at the account-population level, not only the individual account level.

PayTo is a genuinely better payments product. The answer to this incident is not to retreat from real-time rails - it is to ensure the verification infrastructure catches up to the payment infrastructure before the next fraud network finds the next gap.


ezyshield is on a mission to eliminate payment fraud in Australia. We verify the person, the business, and the bank account before money moves - so payments only ever land with who they’re meant to. Learn more

Stop payment fraud before money moves

Verify the person, business, and bank account before any payment leaves your account.