What began as an isolated ₹1.5 Crore corporate fraud investigation in Gujarat’s commercial hub has unspooled into a complex transnational cyber syndicate spanning cross-border operational hubs in China and Pakistan. The extensive investigation by the Ahmedabad Cyber Crime Police highlights how domestic telecom infrastructure is systematically subverted by foreign syndicates to breach high-value corporate networks. At the core of the operation lies a lucrative shadow economy built on fraudulently issued SIM cards, stolen biometrics, and session-hijacking malware.
The Biometric Breach and Shadow Supply Chain
The probe originated in June when an employee at a prominent firm in Ahmedabad transferred ₹1.5 Crore following urgent payment instructions sent from what appeared to be a senior corporate executive’s messaging account. While law enforcement officials successfully recovered ₹1.3 Crore and returned it to the company, the subsequent forensic trail led investigators to West Bengal. There, police arrested two key operatives, including a former telecom sales agent who worked across major service providers including Airtel, Jio, Vi, and BSNL.
Investigators revealed that the operation procured roughly 4,500 fraudulently activated SIM cards to bypass identity verification protocols across India. By exploiting access to telecom service provider applications and misusing customers’ biometric fingerprints during routine re-verification procedures, the primary suspect activated thousands of mobile connections without subscriber knowledge. These dummy SIMs served as the foundational layer for generating authentication codes, supplying roughly 21,000 One-Time Passwords to cybercriminals at approximately ₹100 per code.
Session Hijacking and the ‘Boss Scam’ Architecture
Rather than attempting complex technical break-ins on secured banking portals, the syndicate deployed a tailored social engineering strategy known as the ‘boss scam’. Attackers transmitted malicious ZIP archives disguised as essential corporate documentation to target company personnel through WhatsApp and electronic mail. Once opened, the embedded executable files compromised the victim’s active WhatsApp Web session, granting bad actors complete administrative visibility over internal communication channels.
With internal access secured, fraudsters saved their own mobile numbers under the names of corporate directors or chief executives within the compromised interface. Posing as senior leadership, they issued high-priority payment directives to accounts department personnel, who transferred funds without independent verbal confirmation. The operation utilized Chinese-developed malware managed out of Hong Kong, while an associated operational call centre was traced directly to Islamabad, Pakistan. Financial account access was further masked through China-based Virtual Private Network services.
Inter-State Scrutiny and Federal Countermeasures
The sheer scale of the syndicate’s operational footprint has triggered nationwide law enforcement coordination alongside the Indian Cybercrime Coordination Centre under the Union Ministry of Home Affairs. Ahmedabad Police Commissioner Anupam Singh Gehlot confirmed that the network had operated clandestinely for over four years, gradually shifting operations from Telegram to encrypted WhatsApp groups to evade intelligence monitoring.
A cross-referencing of national law enforcement databases uncovered 251 formal complaints registered across 26 states and Union Territories linked directly to mobile numbers managed by the accused. In response, law enforcement agencies deactivated more than 10,000 compromised devices tied to the network and seized specialized hardware capable of operating multiple SIM cards simultaneously. Authorities noted that the illicit infrastructure provided foundational access for numerous independent fraud syndicates operating across the country.
Geopolitical Vulnerabilities and Regulatory Realities
The convergence of domestic telecom breaches with foreign cyber infrastructure underlines an escalating challenge for the State’s digital sovereignty. Law enforcement officials emphasize that stolen biometrics and illicit SIM card distribution have evolved beyond localized financial scams into sophisticated vectors for cross-border economic sabotage. The exposure of infrastructural links connecting domestic sales agents to foreign state adversaries marks a troubling evolution in tactical cyber threats.
As the Union Government imposes stricter regulatory compliance on telecom service providers and point-of-sale agents, security analysts stress that corporate entities must enforce stringent internal verification controls. Relying strictly on digital messaging for capital transfers remains a fundamental operational vulnerability. Protecting enterprise assets now demands mandatory multi-factor authentication and out-of-band verbal confirmation for all financial transactions across Indian industry.