Inside the ₹646-Crore Bank Fraud: How Altered Documents Allegedly Fooled Internal Controls

The420.in Staff
6 Min Read

The alleged ₹646-crore banking fraud at IDFC First Bank’s Chandigarh branch has exposed the risks that can emerge within banking operations when multiple parties collude and bypass internal controls. The fraud, which came to light in February 2026, allegedly involved certain branch employees working with some employees of customers and individuals outside the bank to facilitate unauthorised transactions. Fake or altered documents, modified cheques and allegedly fictitious fixed-deposit certificates were among the methods identified during the forensic review.

IDFC First Bank Managing Director and Chief Executive Officer V. Vaidyanathan described the incident as serious and said in the bank’s FY26 annual report that it should not have happened. After the matter became public, he personally travelled to Chandigarh and met senior administrative officials, assuring them of the bank’s commitment to accountability and cooperation.

FCRF Launches Certified AI-Powered SOC Analyst Program to Train the Next Generation of Cyber Defence Professionals

Transactions allegedly pushed through using altered documents

According to the forensic review, the alleged fraud involved collusion between employees of the Chandigarh branch, certain employees of the affected customers and outsiders. Branch employees allegedly attached potentially modified authorisation letters, cheques and approval emails to transaction vouchers to facilitate unauthorised transactions.

In some cases, inconsistencies were reportedly found in signatures appearing on the documents. The review also identified instances involving fixed-deposit advices that allegedly did not actually exist. Interest certificates and account statements were also allegedly edited or modified and subsequently shared with customers.

The documents and altered records were allegedly used to create a different picture of account balances and investments, allowing unauthorised transactions to proceed through the banking process.

Government department’s account discrepancy exposed the fraud

The alleged fraud came to light in February 2026 when a Haryana government department attempted to close its account and transfer the funds elsewhere. A discrepancy emerged between the actual balance in the account and the amount the department believed was available.

The discrepancy triggered a review of the account and related transactions. The bank disclosed the matter on 21 February and held an analyst call the following Monday morning to explain the incident.

According to the bank’s management, once the involvement of its own employees became apparent, it did not wait for a lengthy investigation before compensating the affected party. The bank reimbursed the affected departments on the same business day and also paid applicable interest. The financial cost associated with the incident was recognised in the March quarter accounts of FY26.

Technology controls were bypassed through collusion

IDFC First Bank said it had several technological and procedural safeguards in place, including machine-learning-based systems to monitor accounts and transactions. However, the case demonstrated how coordinated action by multiple individuals can undermine even sophisticated controls.

The bank’s assessment was that the fraud was not caused by a failure of its core banking records. Instead, the alleged manipulation took place around branch-level processes, documents and transaction authorisations.

The incident has therefore highlighted a broader challenge for financial institutions: technology-based monitoring can identify unusual activity, but it may not be sufficient when insiders and external parties coordinate to circumvent established procedures.

Nationwide verification conducted after the incident

Following the Chandigarh incident, the bank conducted a nationwide verification exercise. It sent details of closing balances as of 28 February 2026 to relevant government account holders as well as customers belonging to trusts, associations, societies and clubs.

According to the bank, no other customer reported a similar discrepancy during the verification exercise.

The bank also maintained that its core banking records remained accurate throughout the episode. The institution said the alleged fraud was confined to the Chandigarh branch and involved the manipulation of documents and transaction processes rather than changes to the underlying core banking system.

CEO personally led the response

Vaidyanathan’s decision to travel to Chandigarh became a significant part of the bank’s response. He met senior administrative officials and assured them that the bank would cooperate fully and take responsibility where its employees were involved.

The bank said officials appreciated its quick response and willingness to compensate the affected parties rather than waiting for the investigation to conclude.

After the incident, IDFC First Bank strengthened its internal controls. These included additional oversight from a centralised team above branch-level authorisation. The bank also changed certain procedures governing communication with customers and the sharing of account-related information.

₹646-crore fraud affected the bank’s profitability

The fraud also had a direct financial impact on the bank. IDFC First Bank reported a 7% year-on-year increase in net profit to ₹1,636 crore for FY26. Vaidyanathan, however, described the performance as below the bank’s potential.

According to him, without the financial impact of the fraud, the bank’s profit could have been around ₹2,119 crore, representing approximately 39% annual growth.

The bank said deposits remained stable despite the incident, even as savings-account interest rates were reduced around the same period.

The Chandigarh episode has underscored that strong digital systems alone cannot eliminate banking fraud. Employee oversight, independent verification of documents, segregation of duties and centralised monitoring remain critical safeguards, particularly when fraud involves collusion between insiders, customers and external individuals.

Stay Connected