Cybercriminals in Madhya Pradesh are increasingly bypassing complex password hacks by tricking smartphone users into unlocking their own digital front doors. In two swift operations in Gwalior district, scammers used malicious link tactics to breach mobile devices, siphoning a combined total of over one point one six Lakh rupees from unsuspecting victims.
The technique relies on web-based traps disguised as routine promotional offers or bank reward notifications. Once a user taps the corrupted link, hidden background scripts execute malicious commands, allowing attackers to intercept banking credentials and drain funds in real time.
The Trap of Fake Gift Vouchers
The first incident unfolded in the CP Colony area of Gwalior. Forty-nine-year-old Kriti Malav, a resident of Adityanagar, received a text message containing an attractive gift voucher link from an unknown mobile number.
The message was designed to look like a genuine promotional reward from a popular retail brand. Believing the notification was authentic, the victim clicked on the link to claim her reward.
That single tap immediately compromised her smartphone’s internal security settings. Within minutes, cybercriminals initiated multiple unauthorized electronic fund transfers from her linked bank account, stealing sixty-nine thousand three hundred and ninety-two rupees before she realized her device was hacked.
Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions
Rapid Account Draining in Rural Belts
A similar digital attack struck the nearby village of Kargawan under the Bijauli police jurisdiction. Thirty-five-year-old Sanjay Singh noticed his smartphone behaving erratically before receiving sudden bank debit alerts.
Between four PM and five-thirty PM on a single afternoon, attackers compromised his mobile operating system and executed a series of rapid fund withdrawals. Within seventy-five minutes, forty-seven thousand rupees vanished from his bank account.
Bijauli police and local cyber cell investigators have launched forensic analyses on both devices to determine the exact payload used in the breaches. Authorities are tracking beneficiary account numbers, registered mobile handles, and digital IP trails to locate the perpetrators.
The Broader Surge in Link-Based Exploits
These Gwalior incidents highlight a dangerous trend spreading across central India. Scammers are moving away from traditional phone scams toward automated SMS-based malware distribution, commonly known as smishing.
In similar recent cases across Indore and Bhopal, victims lost lakhs after downloading malicious Android Application Package files disguised as electricity bill updates or festive cashback vouchers. These hidden programs quietly install Remote Access Trojans or SMS-forwarding software onto the victim’s device.
Once installed, the malware operates silently in the background. It reads incoming One-Time Passwords, captures screen inputs, and relays full device access to off-site command servers controlled by criminal rings.
Renowned cybercrime expert and former IPS officer Prof. Triveni Singh emphasized that visual professionalism in a text message is entirely deceptive. He noted that legitimate financial institutions and retail corporations never distribute reward vouchers through unverified third-party web links.
Local police have registered cases under relevant sections of the Bharatiya Nyaya Sanhita and the Information Technology Act. Officials urge citizens to report unauthorized transaction alerts to the national cybercrime portal within hours to improve recovery prospects.
What this means for you: Never click on promotional or gift voucher links sent from unknown phone numbers or messaging apps. If your phone glitches after tapping a link, immediately disconnect from the internet and call 1930.