Legal & Crime

Oleg Korniev pleads guilty to laundering $9.7 million through U.S. money mules

Legal & CrimeCrypto Coin Show News Team·October 8, 2026·3 min read

Oleg Korniev, a 42-year-old dual citizen of Ukraine and Russia, pleaded guilty today to leading Your Mule Cashout, a money-laundering operation that recruited over 15,000 U.S. residents to move stolen funds out of the country. The network processed at least $10 million taken from over 750 U.S. bank accounts by hackers worldwide, with Korniev personally handling over $9.7 million in laundering activity.

  • Korniev recruited 15,000 U.S.-based money mules deceived into processing cybercriminal proceeds
  • YMCO laundered at least $10 million from over 750 U.S. bank accounts stolen by hackers
  • Korniev’s operation and four co-conspirators now face prison sentences and restitution orders totaling over $9.1 million
  • $14.7M Actual and intended losses by confirmed victims, per Korniev’s plea
  • $9.7M Korniev admitted to intending to launder from cybercriminals
  • 2-50 yrs Prison sentence range Korniev faces after guilty plea today

Oleg Korniev pleaded guilty to running Your Mule Cashout (YMCO), an international money-laundering network that used U.S. residents as unwitting conduits to move funds stolen by computer hackers, according to a Department of Justice release from the U.S. Attorney’s Office for the Western District of North Carolina today. Korniev held a leadership position in YMCO and managed policies, hired staff, and secured illegal services to support the operation’s infrastructure, which routed stolen money primarily to Eastern Europe by charging hackers a percentage fee.

How YMCO Targeted U.S. Bank Accounts and Money Mules

YMCO deceived U.S. residents into believing they were employed by legitimate companies to facilitate overseas money transfers. The mules were instructed to receive payments into personal bank accounts, withdraw cash, and wire funds to “partners overseas”, in reality, YMCO conspirators waiting to receive hacked proceeds.

The recruited mules never received payment and were unaware they were processing stolen funds.

According to court documents cited in the release, Korniev “helped develop YMCO’s policies and procedures; managed, hired, and fired employees; rewarded and punished employees based on performance.” His operation and four earlier-arrested YMCO members, extradited and convicted, collectively targeted victims across over 750 compromised U.S. bank accounts.

Charges, Sentencing and Restitution

Korniev pleaded guilty to conspiracy to commit money laundering, money laundering, conspiracy to commit computer fraud, conspiracy to commit access device theft, and aggravated identity theft. He admitted to laundering at least $7 million and intending to launder $9.7 million; the court found YMCO responsible for $14.7 million in actual and intended losses across confirmed victims.

Sentencing is scheduled at a later date. Korniev faces a minimum of two years in prison and a maximum of 50 years. He has agreed to provide full restitution to known victims and forfeit cash seized when he was arrested in the Republic of Georgia.

Four other YMCO conspirators previously extradited and convicted received sentences ranging from 37 to 63 months in prison; the court ordered each to pay over $9.1 million in restitution.

Impact on Cryptocurrency and Crime-as-a-Service Infrastructure

The YMCO operation reveals a key vulnerability in U.S. anti-money-laundering controls: the systematic recruitment and deception of domestic bank account holders as manual laundering nodes.

Unlike wire transfers or digital asset exchanges where transaction trails can be audited, money mules provide deniability, each unwitting participant appears as a legitimate retail customer making genuine transfers. The mule-recruitment business model charges a percentage fee, mirroring the fee structure of layer-one blockchain bridge operators or cross-chain swaps, but leaves no immutable ledger.

The scale, 15,000 mules, and the multi-year operational window suggest U.S. banks and FinCEN’s monitoring systems detected individual anomalies but failed to correlate recruitment patterns until law enforcement focused investigation. This gap has direct implications for regulated custodians and exchanges that rely on Suspicious Activity Reports to flag money laundering.

The case also underscores why cyber-insurance claims and ransomware payments often flow through traditional banking first: domestic mule networks remain faster and cheaper than asset conversion.

The CCS read. YMCO’s playbook, deceiving unvetted domestic account holders into becoming money mules, bypasses the transaction scrutiny applied to exchanges and custodians. The operation’s five-year run (operational scale and timeline not specified in the release) and scale of 15,000 recruited participants suggest that detection and prosecution of organized mule-recruitment remains constrained by jurisdictional limits and manual investigation. The guilty plea is a win for extraterritorial prosecution, but the absence of detail on how YMCO was first detected and monitored leaves open whether similar networks are currently operating undetected.

Sentencing will be scheduled at a later date; the federal district court judge will determine Korniev’s prison term after considering the U.S. Sentencing Guidelines. Watch for whether restitution payments will be prioritized to victims of specific hacking campaigns or distributed proportionally, and whether law enforcement disclosure of YMCO’s detection methods will reveal gaps in bank reporting systems that remain exploitable by successor operations.

Get this in your inboxThe Crypto Coin Show newsletter covers the policy and market moves institutional crypto investors are pricing in.

Subscribe