Cyber Crime India: Top Scandals and Latest Threats

www.news4hackers.com-cyber-crime-india-top-scandals-and-latest-threats-cyber-crime-india-top-scandals-and-latest-threats

India’s cyber and technology landscape continues to face evolving challenges, including financial crime, quantum-resistant payment systems, government infrastructure security, AI-driven border defense, and risks from advanced AI technologies.

1. Enforcement Directorate Exposes ₹734-Crore Fake GST Credit Scheme Involving 135 Shell Entities

The Enforcement Directorate (ED) arrested Gyaan Chand Jaiswal and Raaj Jaiswal following raids in Jharkhand and West Bengal.

According to ED investigations, the syndicate established 135 shell companies to generate fraudulent invoices exceeding ₹5,000 crore without actual goods or services exchanged.

This resulted in the creation of fake Input Tax Credit valued at ₹734 crore. The suspects were remanded to judicial custody after appearing before a special PMLA court in Ranchi. Digital evidence and documents were seized, with allegations of financial layering through business and personal accounts. The case remains under judicial review.

Significance

This case underscores the complexity of modern GST fraud, requiring analysis of company registrations, GSTINs, invoices, directors, bank accounts, devices, IP addresses, and beneficial ownership. Graph analytics can reveal interconnected networks disguised as independent entities.

2. Surat Cyber Crime Cell Links Mule Account to 37 Complaints and ₹7 Crore in Alleged Fraud

A 28-year-old individual in Surat was arrested for providing a bank account used in online investment fraud. The account processed approximately ₹2.72 crore, with NCRP-linked analysis connecting it to 37 cybercrime complaints across multiple states involving ₹7 crore.

According to the investigation, the fraud involved investment groups and a deceptive website offering unrealistic stock market returns.

The investigation demonstrates a scalable approach for cyber policing: tracing a single bank account to multiple complaints, states, and networks. This method shifts focus from isolated incidents to broader criminal infrastructure.

Significance

The investigation demonstrates a scalable approach for cyber policing: tracing a single bank account to multiple complaints, states, and networks. This method shifts focus from isolated incidents to broader criminal infrastructure.

3. Gurugram Cyber Police Uncover ₹4.72-Crore Crypto-Investment Scam Involving Phishing App and Mule Accounts

Two individuals in Hisar were arrested for facilitating a crypto-investment scam that defrauded a victim of ₹4.72 crore. The victim was lured via Telegram to install a malicious application that displayed fabricated investment returns.

When the victim attempted to withdraw funds, criminals demanded an additional ₹1.25 crore in fake taxes and charges. Investigators are tracing further accounts and participants.

Significance

The scam highlights a common fraud model: Telegram outreach → phishing app → fake dashboard → artificial profits → larger investment → mule accounts → withdrawal block → fabricated tax demands. DFIR teams can analyze APK files, extract servers, and correlate data with bank accounts and NCRP complaints to identify victims.

4. Coimbatore Reports ₹36.23-Crore in Cyberfraud Losses Over Nine Months, with Investment Scams as Primary Cause

Data from Coimbatore District Police indicates 4,535 cybercrime complaints between January and September 2026, resulting in ₹36.23 crore in losses. Of these, 2,078 complaints were reported via the 1930 helpline, and 2,457 through the National Cyber Crime Reporting Portal.

While online shopping fraud was prevalent, investment and trading scams caused the highest financial damage.

Significance

Complaint volume alone does not reflect the severity of cybercrime. Effective metrics should include: number of complaints, money lost, funds held, frozen, restored, and repeated infrastructure. Investment scams, though fewer in number, often cause disproportionate economic harm.

5. Moradabad Cyberfraud Involves ₹6.15 Lakh Dispersed Across 108 Bank Accounts in Five States

A Moradabad resident reported the disappearance of ₹6.15 lakh, which was fragmented into small transfers across 108 bank accounts in Uttar Pradesh, Bihar, Jharkhand, Rajasthan, and Delhi.

The victim claimed no OTP sharing or transaction alerts were received during the period. Police are collecting KYC and transaction data from the beneficiary accounts.

Significance

Cybercriminals increasingly use automated money-mule networks to evade detection. Banks must identify rapid, many-to-many fund dispersal patterns, while law enforcement requires graph-analysis tools to reconstruct networks before funds are further diluted.

6. ED Arrests Ozone Urbana Promoter in Alleged ₹927.22-Crore Homebuyer Fraud

The ED arrested S. Vasudevan, CMD of Ozone Urbana Infra Developers, in a PMLA investigation linked to a ₹927.22-crore homebuyer fraud. A special court granted the ED 14 days’ custody.

The agency alleges that funds from buyers were retained or diverted despite project delays or non-delivery. The case stems from multiple police FIRs and CBI investigations.

Significance

Large-scale financial crimes require forensic accounting, digital forensics, and beneficial-ownership analytics. Email trails, ERP systems, banking records, and related-party transactions are critical in reconstructing fund diversions.

7. UP Reports ₹874.58-Crore in Cybercrime Funds Frozen or Held

Uttar Pradesh authorities confirmed that ₹874.58 crore linked to cybercrime complaints has been frozen or placed on hold. This figure excludes funds already restored to victims, emphasizing the distinction between holding and recovery.

Significance

Cyber policing must track the full victim-centric metric: amount lost → reported → held → frozen → seized → court-released → restored. Reducing the time between complaint and account freeze is a critical challenge.

8. Indian Startups Launch AI, Thermal Imaging, and Earth Observation Payloads on SpaceX Mission

Several Indian space startups deployed payloads on SpaceX’s Transporter-18 mission on 2 October. Dhruva Space, TakeMe2Space, SatLeo Labs, and EON Space Labs demonstrated thermal imaging, Earth observation, and AI processing in orbit.

Dhruva Space’s LEAP-2 satellite was successfully deployed, while SatLeo Labs’ TAPAS-1 marked India’s first commercial thermal payload.

Significance

On-orbit AI processing reduces reliance on transmitting raw data to Earth. Potential applications include border monitoring, disaster response, and infrastructure surveillance, making satellite systems critical cybersecurity assets.

9. Critical FortiMail Zero-Day Vulnerability Actively Exploited; CISA Adds to KEV

Fortinet disclosed that CVE-2026-104286, a high-severity FortiMail vulnerability (CVSS 9.8), is being exploited. The flaw allows unauthenticated attackers to write arbitrary files via crafted HTTP/HTTPS requests, enabling code execution.

CISA has added the vulnerability to its Known Exploited Vulnerabilities list. Fortinet provided workarounds but no patches at the time of the advisory.

Significance

FortiMail protects organizational perimeters, making exploitation highly dangerous. Affected organizations should prioritize: identifying systems, restricting management access, applying workarounds, hunting indicators of compromise, preserving logs, checking for persistence, and patching when available.

10. KillSec Ransomware Takedown Reveals 16-Year-Old Administrator Arrested in Spain

A multinational operation against KillSec ransomware led to the arrest of a 16-year-old Romanian national in Spain. Europol linked him to approximately 1,000 global attacks.

The German-led Operation KillSwitch involved multiple countries, with authorities seizing the group’s leak infrastructure and 110 TB of stolen data.

Significance

The case highlights the RaaS model’s accessibility, enabling sophisticated cybercrime. Law enforcement disrupted the entire ecosystem, targeting administrators, developers, affiliates, infrastructure, and cryptocurrency proceeds.

Key Trends Today

  • Financial crime is becoming graph-shaped, with mule accounts connecting multiple complaints and funds dispersing across hundreds of accounts.
  • DFIR is shifting upstream, analyzing APKs, SIM providers, domains, and infrastructure.
  • Internationally, law enforcement is dismantling entire cybercrime ecosystems rather than focusing on individual offenders.
  • For Indian cyber policing, the evolving model involves: 1930/NCRP → bank account → SIM/device → APK/domain/IP


    About Author

en_USEnglish