YMCO Fake Jobs Turned Personal Bank Accounts Into a Cash-Out Service

Daniel Zimmermann
6 Min Read
A job document turns into a yellow cash conveyor: Fake Job, Stolen Money.
A fake job offer makes the recruit’s bank account part of the money trail.

A supposed job receiving company payments was really the exit route for money stolen from American bank accounts. On October 8, Oleg Korniev pleaded guilty to helping run Your Mule Cashout (YMCO), a laundering service that recruited more than 15,000 U.S.-based people through false promises of legitimate work, according to the U.S. Department of Justice.

The organization laundered at least $10 million stolen by hackers from more than 750 U.S. bank accounts. The revealing part of the case is what the recruits were asked to contribute: their own bank accounts, cash withdrawals, and transfers to supposed business partners overseas. A job offer that makes your personal account a payment channel deserves an immediate stop, even when the money arrives before anyone asks you to send it onward.

The hackers needed a way to cash out

DOJ describes two connected operations. Hackers stole money from the accounts of U.S. companies; YMCO supplied the people and online infrastructure to move those proceeds abroad, primarily to Eastern Europe. The hackers paid the organization a percentage of the stolen money for that service.

That division of labor matters. Stealing access to an account and collecting spendable proceeds are separate problems. YMCO connected the two by persuading U.S. residents to perform the visible banking transactions while believing they were doing paid work.

The October 8 development is Korniev’s guilty plea. The release describes the underlying laundering scheme; it does not announce that 15,000 people were newly recruited this week or establish that the network is still operating.

A personal account became the company’s payment desk

Recruits were told they worked for legitimate companies. Their supposed duties were to receive business payments into personal bank accounts, withdraw the money, and wire it to the company’s overseas partners. In fact, they were receiving hackers’ stolen proceeds and forwarding them to other YMCO conspirators.

The account holder provided the bridge between the hacked business and the overseas recipient. The false employment relationship supplied an explanation for each instruction, turning a suspicious financial favor into an apparent work assignment. DOJ says the recruits never received payment for their services.

YMCO money flow: hacked business account, recruit’s personal account, cash and overseas wire.
Explanatory diagram of the laundering sequence described by the U.S. Department of Justice; it is not a transaction record.

The report’s figure of more than 15,000 refers to people recruited by the organization. It should not be read as proof that every recruit completed a transfer. Likewise, the figure of more than 750 refers to bank accounts from which hackers stole money, not the number of banks breached.

Korniev managed the service behind the transfers

Korniev helped set policies and procedures, hired and fired employees, and rewarded or punished them according to performance, DOJ says. Those details show a managed cash-out business rather than a collection of unrelated fraudulent vacancies.

As part of his plea, he admitted laundering at least $7 million himself. That personal amount is distinct from the organization’s at least $10 million total. He also agreed to restitution for known victims and forfeiture of cash seized when he was arrested in Georgia. Sentencing has not yet been set; the release does not establish that victims have already been repaid.

The warning sign is the requested transaction

A familiar company name or a convincing recruiter profile cannot make this duty safe: receiving other people’s payments into your own account and forwarding them at an employer’s direction. The same broad use of intermediaries appears in the separate Vinnytsia money-mule investigation, although that case concerns different suspects and alleged bank-block circumvention.

If you have only received an offer, do not provide account access or agree to process the transfers. If money has already arrived, DOJ’s Money Mule Initiative advises stopping communication with the person giving instructions, keeping the funds from being forwarded, notifying your financial institution, and reporting the suspicious activity to law enforcement. Tell the bank what happened rather than trying to resolve the transfer through the supposed employer.

This is also a different trap from a fake interview that asks you to install software. The YMCO release does not identify a malicious installer or a malware family. Here, the critical boundary was permission to use a real person’s bank account.

The case exposes a job scam in which the promised salary never arrived, but the financial transactions were real. The practical test is the work itself: an employer asking you to receive and forward strangers’ money is asking for control over a financial channel in your name.

References

  1. U.S. Department of Justice, Office of Public Affairs. “Ukrainian-Russian Dual Citizen Pleads Guilty to Running International Money Laundering Organization for Cybercriminals.” October 8, 2026. Case announcement.
  2. U.S. Department of Justice, Civil Division. “Money Mule Initiative.” Updated October 21, 2024; accessed October 11, 2026. Recognition and response guidance.
Share This Article
With a strong background in consumer safety and fraud prevention, Daniel specializes in providing actionable tips and advice to users. His focus is on helping individuals understand the risks of interacting with fraudulent sites and services
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?