Bareilly Cyber Fraud: Money Lost Without OTP in Online Scam
A cyber fraud incident has been reported in Bareilly, where funds were allegedly siphoned from a bank account without the use of One-Time Passwords (OTP) or suspicious links.
The Case Details
The complainant, Shambhu Khan, a resident of Deoria Abdullah village under the Mirganj police station jurisdiction, disclosed that his wife, Anno Begum, maintained a bank account at the Mill branch of HDFC Bank in the neighboring Rampur district.
According to the police report, two transactions totaling ₹50,000 were executed on July 21 and July 23. Each withdrawal amounted to ₹25,000, with the victims noting that the entire sum was not removed in a single transaction but through multiple smaller withdrawals.
The family discovered the discrepancies after reviewing account activity and subsequently lodged a complaint with law enforcement.
No OTP or Suspicious Links Involved
Both the victim and her husband confirmed that they had not shared an OTP with any third party or interacted with unknown links.
This absence of typical fraud indicators has shifted the focus of the investigation toward identifying the method used to authorize the transactions.
Investigation Steps
Police are examining whether the withdrawals were executed via an ATM, debit card, internet banking, digital payment platforms, or alternative banking channels.
Investigators are also scrutinizing the destination of the funds, including potential transfers to other bank accounts or digital wallets.
Additional scrutiny will involve analyzing the timing, geographical location, and technical metadata of the transactions to determine if the account was accessed remotely or if compromised credentials were utilized.
Expert Analysis
Cybercrime experts emphasize the importance of a comprehensive technical investigation in cases where traditional fraud triggers are absent.
Prof. Triveni Singh, a renowned cybercrime analyst and former IPS officer, stated that unauthorized transactions should not be automatically attributed to OTP sharing. Instead, investigators must evaluate the entire transaction framework, including banking credentials, device activity, login records, and the subsequent movement of funds.
This approach aims to differentiate between possibilities such as credential compromise, unauthorized card usage, or exploitation of banking system vulnerabilities.
Ongoing Inquiry
The police are prioritizing the tracing of the ₹50,000 to identify the final recipients and any associated accounts or platforms.
Law enforcement will rely on bank records and technical evidence to map the transaction chain.
Investigators are also assessing whether the case is linked to previously documented cyber fraud incidents or accounts flagged for suspicious behavior.
Such connections could reveal whether the incident is an isolated event or part of a broader fraud network.
No arrests have been made at this stage, with authorities stating that the exact method of fund extraction and the identities of those responsible will become clearer once banks provide detailed transaction and technical records.
Conclusion
The case underscores the evolving nature of banking fraud, where the absence of OTPs, suspicious links, or unfamiliar applications does not preclude unauthorized access. Determining the precise authentication method and following the financial trail remain critical to unraveling the incident.
