2026.10.02

Corporate Mule Accounts and Black-Market Phones: Why Thai Businesses Keep Getting Paid Into Shell Companies

On 2 September 2026 CCIB arrested a Bangkok woman linked to more than 27 fraud cases via shell limited-partnership accounts and black-market phones. What Thai businesses should destroy.

อ่านภาษาไทย

The Arrest: Shell Companies, Not Personal Bank Accounts

On 2 September 2026, Thailand's Cyber Crime Investigation Bureau (CCIB) arrested a 31-year-old Thai woman in Phasi Charoen, Bangkok, on warrants linked to a corporate mule-account network. Police said accounts she supplied had already been tied to more than 27 fraud cases nationwide.

According to Bangkok Post and Thairath, the suspect registered limited partnerships with no real business, opened bank accounts in those names, and sold them through Facebook groups. A Chinese financier known as "Ah Yao" allegedly paid her ฿80,000–150,000 per ready-to-use corporate account and supplied mobile phones and SIM cards from the black market so recruits could install banking apps.

How a Real Business Got Hit

The case that triggered the arrest began in August 2026. A solar-panel business owner in Chanthaburi was contacted on the shop's Line account about a large order. The "customer" then persuaded him to help buy concertina razor wire worth about ฿700,000 for a supposed military camp in Chon Buri — and to transfer the money to a limited-partnership bank account that looked legitimate. After the transfer, the contact disappeared.

That pattern matters for every Thai company that sells B2B: a corporate-looking account name is not proof of a real company. Scammers buy empty limited partnerships precisely because finance teams are more willing to trust them than a personal account.

What This Means for You

If your firm wires money, verifies suppliers, or issues phones for staff who open bank or e-wallet apps, this case is a compliance problem — not only a retail-scam story.

  • Vendor payments: Treat first-time limited-partnership accounts as high risk. Verify company registration, directors and the destination account through channels you control, not through Line chat alone.
  • Staff phones and banking apps: Phones used to register corporate or partnership banking apps hold credentials, OTPs and chat logs. When those devices are replaced, sold or lost, a factory reset is not enough.
  • Shell-company leftovers: Abandoned limited partnerships leave behind phones, SIMs and laptops. If those devices re-enter the second-hand market with recoverable data, your organisation — or your partners — can still be exposed.

The Device Angle Police Keep Highlighting

Investigators said the Chinese financier provided black-market phones and SIMs as part of the recruitment kit. That is the same pattern seen across Southeast Asia's call-centre economy: cheap handsets, prepaid SIMs and apps, not paper ledgers. When police seize those devices, they treat them as evidence. When a normal company retires the same class of equipment, the data risk does not disappear — it just moves to a recycler or a Facebook Marketplace buyer.

That is why phone and tablet data destruction belongs in the same playbook as freezing mule accounts. So does documented IT asset disposal for any laptop or desktop used to manage company banking, payroll or supplier files. If storage media leave the building, use certified hard drive and SSD destruction rather than informal "we buy old computers" shops.

A Short Checklist for Thai Companies

  1. Require dual verification before large transfers to any new limited partnership or company account.
  2. Keep a serial-number inventory of phones and laptops issued for banking, finance or sales roles.
  3. When staff leave or devices are refreshed, wipe or destroy them under a written process — do not hand them to informal buyers.
  4. Ask for a certificate of destruction showing serial number, method and date, and keep it with your PDPA records.
  5. Remember: under Thailand's PDPA, failing to secure personal data on devices you control can still be your problem even after the hardware leaves the office. See our overview of PDPA data destruction requirements.

We destroy data on phones, tablets, laptops, desktops, drives and servers for Bangkok businesses and issue a Certificate of Data Destruction for every device. We handle devices only — not paper shredding.

Get an instant quote or call 082-797-3702 if your company needs to erase or destroy devices so mule-account and scam networks cannot reuse what is left on them.

Sources: Bangkok Post, "Accused agent for corporate 'mule accounts' arrested" (2 Sep 2026); Thairath English, "Cyber Police Arrest Female Horse Stable Owner Supplying Corporate Bank Accounts to Chinese Scam Gang" (2 Sep 2026). Suspect identified in reports as Ranwarat / "Pim"; Chinese financier referred to as "Ah Yao".

Related Articles

IT Asset Disposal Bangkok

Certified, PDPA-compliant destruction in Bangkok.

Learn More