​Bengaluru Cyber Police Freeze 507 Bank Accounts and Arrest Three in ₹93.58 Lakh Trading Scam

Rinky Rai
By Rinky Rai - A freelance journalist
5 Min Read

A Cyber Command investigation into an online trading and investment fraud amounting to ₹93.58 lakh has led to the arrest of three individuals and the uncovering of an extensive mule account syndicate. Investigators discovered that the accused allegedly procured and supplied credentials for 507 bank accounts to cyber fraudsters to receive and siphon illicit funds. All 507 identified accounts have been frozen as part of the ongoing probe.

​The case originated from a formal complaint registered on April 29, 2026, by a victim who was lured with deceptive promises of high returns through online trading. The victim was induced to transfer a total of ₹93,58,555 across multiple bank accounts. Acting on technical leads, police arrested the primary accused on September 8. Sustained interrogation led to the identification and subsequent arrest of two additional associates involved in the operation.

​Investigators secured court permission to examine six mobile phones seized from the trio. Digital forensics revealed extensive WhatsApp and Telegram communication, bank account databases, and technical evidence establishing how accounts were sourced and monetised to support online financial crimes.

Commission Model and Rogue Banking Applications

​The syndicate operated by sourcing current, corporate, and individual savings accounts from various individuals in exchange for commissions. The accused also took custody of the associated internet banking credentials and registered SIM cards. In several instances, original account holders were lodged in local hotels while their accounts were actively used for illicit transfers.

​To bypass verification checks, the accused deployed specialised Android Package files, including ZNPAY and SMS-forwarding applications, on mobile devices maintained at these locations. These applications automatically forwarded bank alerts and one-time passwords directly to remote fraudsters. This mechanism allowed remote operators to take complete control of the accounts and transfer stolen funds rapidly without triggering immediate suspicion from the holders.

​A preliminary audit of transaction logs in the current case revealed that around ₹13 lakh of the defrauded sum moved through an account in a nationalised bank, while more than ₹38 lakh was routed through a current account held with a private bank.

Data on 507 Accounts Sent for National Forensic Audit

​A forensic sweep of the seized handheld devices uncovered ledgers and records linked to 507 unique bank accounts. Police suspect that access to these accounts was systematically sold or leased to multiple fraud syndicates operating across state lines.

​The six seized mobile phones, along with the ZNPAY application, the SMS-forwarding tool, and 51 other suspicious APK files, have been forwarded to the Indian Cybercrime Coordination Centre for advanced technical analysis. Experts are working to determine the total volume of money routed through these files and evaluate how many additional accounts were breached through the automated redirection setup.

Cross-Border Trails and Search for Absconding Handlers

​The analysis of digital chats revealed connections to multiple absconding operators coordinating tasks over encrypted messaging platforms. Initial geolocation mapping and IP address tracking pointed to network footprints in Kolkata, Hong Kong, and California in the United States. Investigators are presently cross-verifying these technical coordinates with telecom and internet service provider logs.

​Detectives are currently reviewing Know Your Customer documentation, comprehensive bank statements, fund movement pathways, and prior complaint histories linked to the 507 accounts. Technical analysts are also scrutinising connected SIM card registrations, intermediary handlers, and server access logs.

​Efforts remain underway to identify the individuals behind the anonymous Telegram handles directing the scheme. The investigation is focused on establishing the specific operational hierarchy of the arrested trio, tracking down the ultimate beneficiaries of the siphoned money, and calculating the wider financial footprint tied to the frozen accounts.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected