The Delhi Police has dismantled a high-profile cyber fraud syndicate with operational links to China, arresting four individuals for providing infrastructure services to overseas cybercriminals. The syndicate functioned as a critical domestic operational layer for foreign threat actors by procuring mule bank accounts, securing active SIM cards, and converting stolen fiat currency into Tether (USDT) cryptocurrency. The coordinated police crackdowns were executed across multiple locations in Haryana and Uttar Pradesh following an investigation into a task-based work-from-home scam that defrauded an Indian citizen of ₹12 lakh.
The crackdown highlights a growing structural trend in transnational cybercrime, where offshore masterminds rely on localized networks of facilitators to harvest domestic banking access, obscure financial trails, and exfiltrate funds via decentralized digital assets.
Mechanics of the Work-From-Home Task Scam
The investigation began after an e-FIR was registered on July 17, 2026, by a victim who was lured into a fraudulent work-from-home job scheme. The victim was initially contacted with promises of attractive financial returns for completing routine online tasks. To establish credibility, the operators allowed the victim to view purported earnings on an artificial online dashboard while requiring initial security deposits to unlock work assignments.
As the victim’s engagement deepened, the fraudsters continually demanded larger payments under the guise of processing fees, tax clearances, and account verification charges. Each withdrawal attempt triggered fresh demands for money without releasing the displayed profits. After transferring a total of ₹12 lakh across multiple bank accounts without receiving any returns, the victim realized the entire platform was a scheme designed for financial extortion and reported the matter to cyber crime authorities.
Technical Traceability and the Chinese Link
Specialized cyber crime investigators initiated a comprehensive audit of the digital communication channels, virtual identities, and financial accounts tied to the operation. Technical analysis of the IP addresses associated with the messaging accounts geolocated the primary traffic directly to China, confirming an offshore origin for the primary operators.
Simultaneously, financial intelligence units mapped the movement of the victim’s funds and identified a primary recipient bank account registered to Gagan Yadav, a resident of Etawah in Uttar Pradesh. Technical surveillance on the account’s transactions quickly led investigators to Geetam Singh, 29, who functioned as a primary local coordinator for the Chinese handlers. Upon his arrest, Singh confessed to acquiring mule accounts and converting fraud proceeds into USDT cryptocurrency in exchange for fixed commissions. Forensic examination of Singh’s mobile phone recovered encrypted chat transcripts confirming direct operational coordination with overseas handlers in China.
Mule Account Infrastructure and Crypto Exfiltration
Interrogation of Singh led law enforcement to execute a raid in Ghaziabad, resulting in the arrest of 21-year-old Dhruv. Police recovered nine bank passbooks, five activated SIM cards, and a physical ledger detailing commission payments earned for supplying mule accounts. Dhruv subsequently disclosed that 27-year-old Anuj Sharma had assisted in opening bank accounts and procuring linked SIM cards, leading to Sharma’s arrest in Noida. Follow-up operations led to the arrest of 26-year-old Gagan Yadav in Etawah, who admitted to leasing his account to the syndicate for financial gain.
The operational pipeline relied on a structured multi-stage laundering process. Local facilitators sourced individuals willing to rent out their bank accounts and registered linked SIM cards for receiving single-use authorization passcodes. Overseas handlers then instructed scam victims to transfer money directly into these primary mule accounts. The syndicate layered the funds across secondary domestic accounts to break immediate auditing trails before converting the accumulated capital into USDT on peer-to-peer cryptocurrency exchanges. The digital tokens were then transferred to Chinese crypto wallets, successfully bypassing traditional cross-border banking controls and international wire monitoring.
