Cyber Attackers Steal Employee Bank Funds via Paytm Transactions
A professional in Muradabad reported losing ₹2.85 lakh after unauthorized transfers through Paytm, with no evidence of shared One-Time Passwords or banking credentials.
Incident Details
Victim’s Background
The victim, an employee at a packaging and printing facility, noticed irregularities during work hours when transaction alerts appeared on his device.
Fraudulent Transactions
Four separate transfers totaling ₹2.85 lakh occurred over multiple days. These included amounts of ₹50,000, ₹45,000, and two transactions of ₹95,000 each, directed to unverified accounts.
Investigation Findings
Unauthorized Debits
Subsequent investigations revealed repeated unauthorized debits without the victim’s consent. Authorities confirmed the case and are examining mobile data logs, device activity, and transaction records.
Security Concerns
The absence of standard security alerts, such as OTP verification or two-factor authentication prompts, raises concerns about advanced hacking techniques. Investigators are exploring possibilities like device cloning, unauthorized screen mirroring, or malicious applications.
Expert Recommendations
Security Measures
Experts recommend implementing stronger authentication measures, including biometric verification and device binding, to mitigate risks. Users are advised to regularly review app permissions and disable unnecessary remote access features.
Cybersecurity Awareness
Cybersecurity agencies emphasize awareness campaigns to educate the public on safer digital practices. Authorities urge users to enable multi-layer security protections on financial applications and remain vigilant against unsolicited communications.
Ongoing Efforts
Fund Tracing
Investigations continue into transaction routing patterns and beneficiary account histories to trace the movement of stolen funds. Early findings suggest layered account transfers may have been used to obscure the money trail.
Technical Safeguards
Cybersecurity professionals advise maintaining updated operating systems and installing verified security software to reduce exposure to malware that can intercept financial data silently.
The case underscores the need for heightened vigilance in an environment where mobile-based financial fraud is increasingly prevalent.
