The chain that drained ₹13.85 crore from a Gurugram businessman did not begin with a hacker in China. It began with a Delhi trader selling his firm’s current account for ₹50,000. That account changed hands four more times, each seller pocketing a modest markup, before it reached operators allegedly working out of China who used it to receive stolen money and vanish behind a Telegram handle.
Five men have now been arrested for their alleged role in this chain, accused of arranging and passing along the very accounts through which the fraud proceeds moved. Police say the resident of Sector 25 who lost the money was drawn into an investment scheme over several weeks in 2024, steadily persuaded to keep transferring funds until ₹13.85 crore was gone. He approached the Cybercrime East police station, and an FIR was registered on November 4, 2024.
Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions
A Bank Account Sold Five Times Over
What investigators have reconstructed since is less a single crime than a supply chain. Trader Neeraj Gupta allegedly sold his firm’s current account to Manjeet Dadyan for ₹50,000. Manjeet, already in custody in an earlier case, allegedly sold it on to Neeraj Kumar for ₹60,000. Kumar allegedly vetted the account, checking that it was a live current account with no prior fraud history, before passing it to Surjeet Kumar alias Manas through an intermediary named Suraj Saroj, for ₹90,000.
From there, police allege, the account became accessible to handlers operating from China, who directed its use over Telegram. Two more men, Prashant Sharma and Tej Pratap Singh Shekhawat, both residents of Jaipur, were held alongside Surjeet in Dehradun and Shimla over the weekend. Neeraj Kumar was arrested separately in Delhi. All five are between 25 and 30 years old.
Layered into this account trail, police say, was a cryptocurrency conversion system. Surjeet allegedly operated a US-based application through which the Chinese handlers transacted crypto as commission, funds that were then converted into dollars and finally into rupees before being pulled out through ATMs. It is a laundering sequence investigators across India have described with growing frequency this year, one built specifically to put distance between stolen money and the people who stole it.
Following Five Lakh Rupees Back to a Network
The break in the case came only in April this year, nearly a year and a half after the original fraud, when investigators traced roughly ₹5 lakh of the defrauded amount to accounts connected to this network. That single thread, patiently pulled, is what eventually led police to the account-selling chain and the men who ran it. Six mobile phones and ₹60 lakh recovered from various accounts represent what has been clawed back so far, a fraction of the original ₹13.85 crore.
The case has been registered under Bharatiya Nyaya Sanhita provisions covering cheating, cheating by personation and forgery, alongside sections of the Information Technology Act. Investigators are now examining whether the same accounts or intermediaries surface in other fraud complaints, a question that matters because rented accounts of this kind are rarely used only once before being discarded for a fresh one.
Why India’s Cybercrime Problem Runs Through Its Banks
The Gurugram case sits inside a pattern regulators have been documenting with increasing alarm through 2026. As of January this year, the Home Ministry’s I4C had identified and shared details of more than 27 lakh so-called Layer-1 mule accounts with banks and other institutions, helping block transactions worth over ₹9,500 crore. Separately, more than 4.5 lakh mule accounts have been frozen nationally, concentrated heavily in a handful of large banks and payment institutions.
Industry data suggests the problem is not shrinking so much as relocating. Fraud-analytics firm BioCatch has reported a marked shift in where stolen money now lands, with proceeds increasingly routed to mule accounts inside India rather than overseas, a change linked to international crackdowns on scam compounds in Myanmar, Cambodia and Laos that have displaced networks rather than dismantled them. Union Home Minister Amit Shah has himself called mule accounts one of the central obstacles to curbing cybercrime nationally.
Prof. Triveni Singh, the cybercrime expert and former IPS officer, has pointed to exactly the structure visible in the Gurugram case: specialised roles for account procurement, fund movement, crypto conversion and cash withdrawal, each handled by a different person. That compartmentalisation, he notes, is precisely what allows the operators at the top of these networks to stay hidden behind a rotating cast of intermediaries willing to sell a bank account for the price of a used motorcycle.