YMCO leader pleads guilty to running 15,000 money mules
Oleg Korniev, a principal of the 'Your Mule Cashout' service, pleaded guilty to laundering proceeds from compromised US bank accounts using more than 15,000 money mules.
Oleg Korniev, 42, a dual citizen of Ukraine and Russia, has pleaded guilty to his role running Your Mule Cashout (YMCO), a cash-out service that laundered proceeds from compromised US bank accounts for cybercriminals, BleepingComputer and Recorded Future News both report. The DOJ announced the plea; a press release was not locatable at a public URL as of writing, so this post is based on reporting from both outlets, which independently name Korniev and the operation.
The operation
YMCO ran from 2007 to 2014 and used more than 15,000 money mules in the US. According to the reporting, it processed over $10 million stolen from more than 750 US bank accounts at 35-plus banks, moving funds for hackers who used malware to break into the accounts.
Mules were recruited through spam emails from fake companies, then wired the stolen funds via Western Union and MoneyGram to "cash-out contractors" in Moldova, Ukraine, Russia, and Latvia. The service allegedly ran parallel schemes in Germany, Italy, the UK, and Australia.
The plea
Korniev admitted to:
- money laundering;
- conspiracy to commit money laundering;
- conspiracy to commit computer fraud;
- conspiracy to commit access device theft;
- aggravated identity theft.
He confirmed the operation was behind more than $14.7 million in actual and intended losses to confirmed victims, and that he personally laundered at least $7 million of the roughly $9.7 million YMCO received from cybercriminals. He faces a statutory range of two to 50 years. Recorded Future reports he was arrested in North Carolina last December, nearly nine years after a grand jury indictment, and the case sits in the Western District of North Carolina.
Korniev is not the first YMCO figure in US custody: four Ukrainians tied to the service were sentenced in 2018 to between 37 and 63 months and ordered to pay more than $9.1 million each in restitution. Co-indicted Moldovan national Serghei Ivanovich Tomuz's case was terminated in May.
What to do today
The mule layer is where stolen credentials become cash; it's also where the fraud becomes visible to defenders.
- Watch for mule-pattern transfers — rapid inbound ACH followed by same-day Western Union/MoneyGram outflows to the named corridors.
- Flag "work from home payment processor" recruitment lures reaching staff; that spam is the top of this funnel.
- Treat account-takeover fraud and money-laundering telemetry as one investigation, not two queues — the cash-out service is the bridge.
Context
Takedowns keep landing on the infrastructure that monetizes cybercrime rather than the intrusions themselves — the arrests of Ploutus ATM-jackpotting developers followed the same logic. Korniev's case is a decade-delayed close on a scheme that predates most of the malware families defenders track today; the slow clock is the point DOJ keeps making — extraditions on cybercrime indictments can take nine years, but they still arrive.