A 32-year-old businessman in Vadodara, Gujarat, has allegedly been defrauded of ₹19.75 lakh after cybercriminals impersonated an overseas supplier and altered bank transfer details using a spoofed domain. Indrajit Basu lodged a complaint with the Cyber Crime police detailing how an ongoing commercial agreement to import fixtures from a United Arab Emirates firm was compromised. The fraud occurred between May 25 and July 13, 2026, leading to the diversion of a foreign exchange payment into an unauthorised bank account.
Deceptive Domain Infiltrates Legitimate Commercial Deal
Basu had initiated contact with Dubai-based True Sea Services FZC through its official website and legitimate corporate email address to purchase doors and windows. After negotiating the terms, he executed a genuine advance payment of US $11,216.21 to the supplier via SWIFT on March 10. While the consignment was in production, an unidentified actor established a lookalike email domain that subtly mimicked the supplier’s authentic address.
The genuine address, inquiry@trusea.ae, was replaced with inquiry@trusea-ae.com, introducing a minor variation that went unnoticed during active correspondence. Using the spoofed address, the perpetrator continued the conversation with Basu under the guise of regular trade communication.
Altered Payment Instructions Route Funds to Fraudulent Account
The fraudulent communication presented revised banking details registered under the corporate name True Sea Services F.Z.C. at First Abu Dhabi Bank PJSC, including an international bank account number and branch particulars in the United Arab Emirates. Believing the notification originated from the authentic vendor, Basu processed an online wire transfer of US $20,830 on June 9, amounting to roughly ₹19.75 lakh.
Basu subsequently realised that the transaction had been hijacked after learning the Dubai supplier had neither changed its bank particulars nor received the remittance. The perpetrators retained the diverted funds, prompting the businessman to register a formal complaint with the police naming the account holder, the user of the fraudulent email address, and associated conspirators.
Police Register FIR Under BNS and IT Act
The Cyber Crime police registered an FIR on Thursday night under relevant sections of the Bharatiya Nyaya Sanhita and the Information Technology Act. Investigators are reviewing message headers, IP trails, and electronic communications to determine how the perpetrators monitored the commercial exchange and whether the receiving account in the United Arab Emirates was previously implicated in financial offences.
The case bears the characteristics of a business email compromise attack, where bad actors intercept legitimate commercial dialogues to manipulate wire transfers. Cyber crime expert and former IPS officer Prof. Triveni Singh stated that commercial organisations must independently verify any sudden request to modify bank details before initiating funds. He emphasised that firms should authenticate altered payment instructions over verified telephone channels rather than relying entirely on email messages.