Cyber Crime India: Latest Scandals Shaking the Nation – October 2nd
India’s cyber and technology landscape is evolving across financial crime, quantum-resistant payments, government-linked infrastructure security, AI-enabled border defence and emerging risks from frontier AI.
1. India’s New Bankers’ Books Evidence Act Takes Effect, Modernising Digital and Cloud Banking Records
The Bankers’ Books Evidence Act, 2026, became operational on October 1, replacing the 1891 legislation. It introduces a technology-neutral framework covering banking records stored in physical, electronic, digital, virtual, and cloud-based formats, including modern storage systems. The Act allows certification through manual, digital, or electronic signatures. It also ensures electronic or digital banking records retain evidentiary value provided they meet statutory authenticity and integrity standards.
Significance of the Development
This update is vital for cybercrime, money laundering, digital-arrest, and BFSI fraud investigations. Bank statements and transaction records form the foundation of financial trails, and the new framework aligns with contemporary digital banking infrastructure, offering investigators, prosecutors, and financial institutions a robust legal foundation.
2. ED’s ₹7-Crore S.P. Oswal Digital-Arrest Investigation Exposes Mule Accounts, Crypto and Foreign Handlers
The Enforcement Directorate (ED) arrested Sohel Akhtar, alias Raju, in a money-laundering probe linked to a ₹7-crore digital-arrest fraud targeting industrialist S.P. Oswal. Akhtar was detained in Kolkata following searches in West Bengal and remanded to ED custody until October 6. He is the third individual arrested in the case. The ED alleges that mule bank accounts were provided to associates, including overseas operators, with commissions processed via virtual assets and Binance-linked accounts. Investigators reportedly discovered an application named AMMFORWARD and APKs enabling remote access to SMS and OTPs for bank accounts.
Significance of the Development
This case highlights a complex cybercrime architecture: Digital Arrest → Mule Account → SMS/OTP Forwarding APK → Remote Operator → Cash → Crypto → Foreign Controller. For digital forensics investigators, analyzing APKs, devices, SIMs, Binance records, bank logs, and encrypted communications could reconstruct the full criminal chain.
3. ED Probes ₹958.66 Crore Through Pune Fintech Accounts, With ₹341.66 Crore Reportedly Received Via Payment Gateways
The ED is examining transactions totaling ₹958.66 crore in 11 accounts tied to Pune-based Edsom Fintech Pvt Ltd. Reports indicate ₹341.66 crore was processed through payment gateways. Arrested suspect Ram Ramdhani remains in ED custody until October 3 as investigators analyze fund layering and transfers through entities and shell companies.
Significance of the Development
Fintech and payment-gateway investigations now require reconstructing: Customer/Source → Payment Gateway → Fintech Account → Layering Account → Shell Entity → Beneficial Owner. API logs, merchant IDs, settlement records, device/IP data, KYC, and bank records are increasingly critical alongside traditional forensic accounting.
4. ED Arrests Two in Alleged ₹1,417.86-Crore Investment Scheme Involving 35,759 Investors
The ED detained S. Naveen Kumar and S. Muthuselvam in a case involving an alleged ₹1,417.86-crore investment fraud targeting 35,759 individuals. The scheme promised returns tied to agricultural-export activities. The investigation originated from an FIR, but allegations remain unproven.
Significance of the Development
Large-scale investment fraud investigations demand financial forensics, corporate records, digital communications, and asset tracing. The scale of affected victims underscores the importance of data analytics in identifying common payment accounts, introducers, agents, and beneficiary entities across thousands of transactions.
5. Gurugram Police Trace Cybercrime Infrastructure to Telecom POS Agent Accused of Supplying About 50 Fraudulent SIMs
Gurugram Cyber Police arrested a telecom Point-of-Sale agent from Kanpur for allegedly reusing customer KYC documents and photographs to activate unauthorized SIM cards. Police suspect approximately 50 SIMs were distributed to cybercriminals. The investigation stemmed from a ₹1.71-lakh commercial fraud case where a fraudulently issued SIM was used.
Significance of the Development
This case underscores the need to trace cybercrime upstream from phone numbers to telecom agents. The chain includes: Fraud Number → SIM → KYC → POS Agent → Other SIMs → NCRP Correlation → Other Crimes → Criminal Network. A single compromised agent can enable multiple unrelated fraud cases.
6. Delhi Police Busts Interstate Telegram Task-and-Crypto Investment Fraud Network
Delhi Police South District Cyber Police arrested three suspects from Uttarakhand in a Telegram-based task and crypto-investment fraud. The scheme targeted individuals through Telegram groups, offering fake returns on cryptocurrency investments. A complainant lost ₹7.86 lakh after transferring funds in installments before communication ceased.
Significance of the Development
Task fraud follows a repetitive model: Social Media/Telegram → Small Task → Initial Trust → Fake Profit → Larger Investment → Crypto Narrative → Mule Account → Withdrawal Blocked. Investigators must correlate Telegram identities, domains, apps, beneficiary accounts, devices, and cryptocurrency wallets across NCRP complaints.
7. Chhattisgarh Police Investigation Reportedly Links Suspected Cybercrime Network to 176 Cases
Chhattisgarh police in Mohla-Manpur-Ambagarh Chowki district arrested three individuals, including a network controller, after linking technical evidence and banking transactions to 176 cybercrime cases. The investigation revealed how local cases can expose larger interstate networks when phone numbers, accounts, and digital identifiers are cross-referenced.
Significance of the Development
India’s cybercrime investigation model is shifting from: One Complaint → One FIR → One Accused to: One Identifier → NCRP Correlation → Hundreds of Complaints → Network → Controller. Graph analytics and national-level complaint correlation are critical for improving policing efficiency.
8. GPS-Denied Autonomous Drone Demonstrated at Indian Air Force Dronathon
Hyderabad-based PhoQtek Labs showcased a GPS-denied autonomous drone during the Indian Air Force’s Dronathon 2026 at Pokhran Field Firing Range. The capability is vital for military drones operating in contested environments where GPS/GNSS access is unreliable.
Significance of the Development
Future autonomous platforms must function under GPS jamming, spoofing, communications disruption, and electronic warfare. This drives defense technology toward Sensor Fusion + Visual/Inertial Navigation + Edge AI + Resilient Communications, creating new cybersecurity and drone-forensics requirements.
9. International Operation KillSwitch Targets KillSec Ransomware Network Linked to Around 1,000 Suspected Attacks
An international law enforcement operation led by Hamburg authorities, with support from Europol and Eurojust, disrupted the KillSec ransomware-as-a-service operation. On September 30, authorities seized control of its leak site, arrested three suspects, and searched eight properties across Greece, Romania, Spain, and the UK. Investigators recovered at least 110 terabytes of stolen data. KillSec has been linked to approximately 1,000 global attacks, including those targeting healthcare and financial services.
Significance of the Development
Ransomware disruption now focuses on dismantling the entire RaaS ecosystem: Developer → Affiliate → Infrastructure → Leak Site → Cryptocurrency → Initial-Access Broker → Victim Data. This model highlights the need for international cooperation among Indian cybercrime agencies.
10. China-Linked Hackers Impersonate AI Experts to Target Researchers in US and Japan
Cybersecurity firm Proofpoint identified a China-linked threat actor, designated TA419, impersonating prominent US AI and policy experts in phishing campaigns targeting think tanks, universities, defense contractors, and law firms in the US and Japan. The attackers used AI collaboration as a pretext to direct victims to credential-stealing infrastructure. Proofpoint’s attribution is based on malware, infrastructure, and targeting patterns, but it remains a firm assessment, not a judicial finding.
Significance of the Development
AI expertise is becoming a strategic intelligence target. Spear-phishing now exploits professional collaboration rather than crude malicious attachments. Indian defense organizations, AI laboratories, universities, and tech companies must prioritize identity verification, phishing-resistant MFA, and domain/link inspection for researchers and scientists.
Today’s strongest pattern is the convergence of digital evidence and financial intelligence. India’s new banking-evidence law modernizes transaction trail establishment, while ED cases reveal cybercrime and financial-fraud proceeds flowing through mule accounts, payment gateways, corporate entities, and cryptocurrency. At the infrastructure layer, fraudulent SIM issuance demonstrates how KYC abuse can enable multiple cybercrimes. The emerging investigation model follows: Complaint → SIM/Device → Bank/Payment Gateway → Mule Network → APK/OTP Infrastructure → Crypto → Foreign Handler → Digital Evidence → Asset Recovery.
