A Ukrainian-Russian dual national who spent years overseeing one of the most operationally sophisticated money laundering rings in recent cybercrime history pleaded guilty last Thursday in a federal court in North Carolina, admitting to routing stolen funds through tens of thousands of ordinary Americans before shipping the cash to criminal operatives in Eastern Europe.
Oleg Korniev, 42, was a principal at Your Mule Cashout, or YMCO, a criminal outfit that ran from September 2007 through 2014 and maintained a network of more than 15,000 money mules across the United States. The plea came roughly a decade after a grand jury first indicted him, and about 10 months after U.S. authorities caught up with him and arrested him in North Carolina in December 2025.
Not a side player
Federal prosecutors did not describe Korniev as a peripheral figure. He managed YMCO's daily operations, hired and fired staff, and handed out rewards or penalties depending on performance. He also helped design the procedural framework that kept the organization functioning across multiple countries simultaneously.
YMCO's approach was simple in concept but deliberately layered in practice. The group posed as legitimate staffing or payment-processing companies and sent spam emails to Americans advertising open positions. What followed was a carefully staged recruitment process built to look real: job applicants went through an employment test, reviewed a contract, and were walked through what appeared to be standard company policy. They were then asked to upload their bank details to a fictitious company website and told their job was to receive payments into their personal accounts and wire the money to company accounts overseas.
The money they were receiving was stolen. Hackers had broken into U.S. bank accounts using malware, funneling the proceeds into the mules' accounts and relying on those individuals to move the funds out of the country before anything flagged.
How the cash moved
From the mules' accounts, the money traveled through Western Union and MoneyGram to what YMCO called "cash-out contractors" in Moldova, Ukraine, Russia, and Latvia. These operators received a cut of each transfer for their role and passed the remainder back to the organization. Running stolen money through a human relay network like this put distance between the hackers and the funds, making the trail harder to reconstruct.
According to court documents, YMCO processed more than $10 million drained from over 750 U.S. bank accounts across more than 35 financial institutions. The group also ran parallel schemes in Germany, Italy, the United Kingdom, and Australia. Korniev's plea agreement put total actual and intended losses to confirmed victims at more than $14.7 million. He personally admitted to laundering at least $7 million of the $9.7 million he received from cybercriminals as payment for YMCO's services.
A decade-long chase
Korniev was originally indicted alongside Serghei Ivanovich Tomuz, a Moldovan national who allegedly ran YMCO's cash-out operation inside his home country. Tomuz was reportedly detained at a Romanian border crossing in May 2022 and spent years fighting extradition to the United States. His case was ultimately terminated in U.S. federal court this past May.
Four other Ukrainians tied to YMCO were arrested abroad years earlier, extradited to the Western District of North Carolina, and pleaded guilty to conspiracy to commit money laundering. Sentenced in 2018, they received prison terms ranging from 37 to 63 months and were each ordered to pay more than $9.1 million in restitution to American victims.
Korniev now faces a minimum sentence of two years and a maximum of 50 years after pleading guilty to money laundering, aggravated identity theft, conspiracy to commit money laundering, conspiracy to commit computer fraud, and conspiracy to commit access device theft. His plea agreement includes a commitment to fully repay confirmed victims for their documented losses.
What prosecutors want criminals to understand
Assistant Attorney General A. Tysen Duva made the department's position on mule networks clear. "Money mules play crucial roles in cybercrime, so the Justice Department pursues mules and their recruiters wherever they operate and however long it takes," Duva said.
The case puts into focus how money mule operations function as the financial plumbing beneath large-scale cybercrime. Without them, proceeds from bank fraud and account takeovers would be far harder to extract without triggering detection.
That infrastructure is a recurring target for law enforcement. Five years ago, Europol announced that authorities from 27 countries had arrested 1,803 money mules out of 18,351 identified as part of a coordinated crackdown called the European Money Mule Action, or EMMA. Europol has consistently flagged that criminal groups recruit mules from vulnerable populations, specifically students, immigrants, and people facing economic pressure, using job
[…]
Content was trimmed to protect the source. Please visit the original article for the full text.
Read the original article:
