A single unread text message has cost an Ahmedabad family nearly a lakh rupees, in a case that fits a pattern authorities say is becoming disturbingly routine across urban India. The victim’s wife received a message carrying a suspicious link on her phone, and within moments of it being opened, two unauthorised transactions stripped ₹99,500 from the family’s savings account. No OTP, password or banking credential was ever shared, according to the complaint, a detail that has turned the investigation toward the mechanics of the link itself rather than any lapse in the family’s caution.
A Message, a Click, and Two Transactions in Quick Succession
The incident occurred on Thursday, when the wife opened the message believing it to be routine. Almost immediately afterward, ₹90,000 was transferred out of the account, followed swiftly by a second transaction of ₹9,500.
The family noticed the withdrawals quickly and contacted the bank’s customer care to have the account blocked, a step that likely prevented further loss. They then filed complaints through the National Cyber Crime Reporting Portal and the 1930 Cyber Helpline before approaching the police to register a formal complaint.
According to the complaint, the stolen funds were moved into another bank account soon after the transactions were executed. Investigators are now working to trace that beneficiary account and establish who controls it, a step that is often the most difficult part of such cases given how quickly cybercriminals layer funds through multiple accounts and mule networks to obscure the trail.
Police Widen the Probe to the Link’s Technical Design
A case of cheating has been registered, and police are examining the victim’s mobile device, the suspicious link itself, banking transaction records and IP logs to reconstruct exactly how the fraud was carried out. Investigators are also expected to seek cooperation from the concerned bank and relevant technology service providers as the probe progresses.
Central to the inquiry is determining whether the link led to a phishing website, carried malicious software, mimicked a legitimate banking portal, or enabled some form of remote access to the device. Each possibility points to a different technical method and a different set of digital footprints for investigators to chase.
Fraudulent links of this kind are typically disguised as bank alerts, courier notifications, KYC update prompts, refund offers or reward scheme messages, all designed to create a moment of urgency that overrides a user’s usual caution. Once clicked, they can silently harvest credentials, install malware, or hand attackers a backdoor into the victim’s phone without the user ever realising it.
Part of a Sharp Rise in Mobile-Based Banking Fraud
The Ahmedabad case lands amid a documented surge in SMS-driven banking fraud across the country. A recent industry report found that India recorded a 146 percent surge in SMS-based banking scams between the second half of 2025 and the first half of 2026 compared with the same period a year earlier, with overall mobile fraud sessions rising 67 percent during the period, including an 86 percent jump on iOS devices and a 35 percent increase on Android. Fraud originating through web browsers, by contrast, declined by 10 percent, suggesting cybercriminals are deliberately shifting their focus to mobile platforms.
Analysts tracking the trend note that SMS scams remain effective precisely because they exploit a communication channel most users still instinctively trust, unlike email, which has grown more associated with spam and suspicion over the years. That trust gap is exactly what the Ahmedabad case appears to illustrate, a single message opened without a second thought, followed by a loss that unfolded in under a minute.
Police have urged the public to treat unsolicited links arriving through SMS, messaging platforms or email with heightened caution, particularly when the sender is unknown or unverified. Citizens have also been advised to check their bank accounts regularly and report any suspicious activity to their bank and cybercrime authorities without delay, since early action, as in this case, can still limit how much is ultimately lost.
