Three Meerut arrests have exposed an alleged mule account that received ₹11 lakh from a ₹1.63 crore Gwalior fraud and transactions linked to seven states.

₹1.63 Crore Gwalior Cyber Fraud Trail Leads Police to Meerut Mule Account Network

The420 Web Correspondent
7 Min Read

A bank account allegedly rented to cybercriminals for ₹5,000 a day has emerged in the investigation into a ₹1.63 crore investment fraud targeting a Gwalior businessman.

Police have arrested three men from Meerut after investigators allegedly found that nearly ₹11 lakh stolen from businessman Manish Jain had entered the current account of Zuber Telecom Meerut.

The arrested men have been identified as Mohammad Zuber, Sameer and Bilal Saifi. Investigators suspect the same account received money connected to cyber-fraud complaints across seven states.

The wider case itself is independently confirmed by Gwalior Police. An official September 1 release says Jain was cheated of exactly ₹1,63,19,900 between April 22 and July 20, 2026, after being lured into an investment scheme.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

₹11 lakh trail allegedly led investigators to Meerut

According to police information in the latest investigation, around ₹11 lakh from Jain’s stolen money reached an IndusInd Bank current account registered in the name of Zuber Telecom Meerut.

Zuber is alleged to be the firm’s director. Investigators claim he allowed the account to be used after being promised ₹5,000 for every day it remained available to the network.

Police allege that Zuber provided access to the account to Bilal Saifi at the request of his cousin Sameer.

Investigators are now trying to determine how much the account handled in total and whether the three men knew that the money entering it represented proceeds of cyber fraud.

The seven-state connection could make that question particularly important. Police reportedly found transactions associated with cyber-fraud complaints outside Madhya Pradesh while analysing the account’s banking trail.

The investigation has also moved towards Delhi.

Police say the suspects had stayed at a hotel in the Adarsh Nagar area. During that period, fraud-linked funds were allegedly transferred from an account associated with previously arrested accused Avinash Rai into the Zuber Telecom account.

Bilal allegedly moved money onwards with the assistance of another contact in Delhi.

Investigators have also found a WhatsApp contact identified as “Sadhu”, who allegedly called Bilal and others to Delhi. Police are now trying to establish who that person is and where he sits in the suspected network.

What is a mule account and why do fraudsters need one?

A mule account is a bank account used to receive, transfer or withdraw money obtained through crime.

The easiest way to understand it is as a financial relay station. The scammer who steals ₹10 lakh from a victim may not want that money sent directly into an account connected to him.

Instead, the money can first enter a business or individual account controlled by somebody else. It can then be split and transferred through several more accounts before being withdrawn or converted into another asset.

Every additional transfer makes the investigation more complicated.

Some mule-account holders knowingly rent or sell access to their accounts. Others may be recruited with promises of commissions without fully understanding what the account will be used for.

The Union Home Ministry told Parliament in March 2026 that the RBI has asked banks to strengthen real-time transaction monitoring and use AI, machine learning and network analytics to identify suspicious transactions and mule-account networks.

That is why investigators increasingly follow the money rather than only searching for the person who called or messaged the original victim.

Same ₹1.63 crore case had already exposed another account layer

The latest Meerut trail is not the first set of intermediary accounts found in the Jain investigation.

On September 1, Gwalior Police announced an earlier arrest after discovering that ₹31 lakh from the same fraud had entered a first-layer current account at Deutsche Bank belonging to Bamrai Global Textile Private Limited, Mumbai.

Police said the arrested accused had opened company accounts not only with Deutsche Bank but also with SBI, Punjab National Bank, Axis Bank and IndusInd Bank before providing them to an associate.

More significantly, investigators found him participating in WhatsApp and Telegram groups where mule bank accounts were allegedly bought and sold.

According to the police release, account holders’ ATM cards, SIM cards and cheque books could be collected so that cybercrime operators obtained effective control over the banking facilities. Investigators even found techniques involving moving registered SIM cards into other phones and using SMS-forwarding applications.

That earlier discovery provides important context for the latest Meerut arrests.

Rather than one fraudulent account receiving the entire ₹1.63 crore, investigators appear to be uncovering a network in which stolen money was distributed through multiple companies, accounts and people.

Gwalior Police encountered a similar cross-border money-moving structure in another major case in July. In that investigation, two accused allegedly used Telegram to sell USDT to a foreign, including Chinese-linked, network while moving proceeds connected to a ₹1.58 crore digital-arrest fraud.

The focus in the Jain case is now moving beyond the original investment scam towards the financial infrastructure that allegedly helped the criminals receive and disperse the money.

Tracing “Sadhu”, examining the seven-state complaint links and identifying where funds went after leaving the Zuber Telecom account could reveal whether the Meerut suspects formed one small layer of a much larger cybercrime network.

What this means for you: Never rent, sell or lend your bank account, SIM, debit card or internet-banking access for a commission. If criminals route stolen money through your account, that account can become part of a multi-state cybercrime investigation even if you never contacted the original victim.

The420 Insight: The ₹5,000-a-day allegation shows the economics behind India’s mule-account market. Cybercriminals increasingly outsource the risky banking layer to ordinary account holders and small firms, creating distance between the scammer who steals the money and the person who ultimately receives it.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected