Varanasi police say cyber fraudsters target around 30 people daily using 15 methods to steal OTPs, including call forwarding, phishing and SIM swapping. Investigators are tracing mule accounts, while ₹25 crore has been put on hold and ₹4.50 crore returned.

Fifteen Ways to Steal an OTP: How Cyber Fraud Tactics Are Evolving

The420 Correspondent
6 Min Read

Varanasi. Despite sustained action against cyber fraudsters, online fraud networks continue to operate using new mobile numbers and evolving techniques. An investigation into cybercrime in Varanasi has found that fraudsters make calls to an average of 30 people every day, either to commit fraud or attempt to deceive them. Over the past year, the cyber team identified around 10,000 mobile numbers allegedly used in cybercrime or to contact potential victims. These numbers were subsequently shut down, but fraudsters continue to target people through new numbers.

According to police, several of the identified numbers were used to make 20 to 25 calls to people. Fraudsters are not relying only on conventional phone calls but are using around 15 different techniques to obtain OTPs. These include asking victims to dial codes associated with telecom services, activating call forwarding, sending malware, using phishing websites and suspicious links, and carrying out SIM-swapping attempts.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

The constantly changing methods used by cyber fraudsters have emerged as a major challenge for investigators. In some cases, fraudsters use personal information already available about victims to gain their trust. Information obtained from leaked databases, including data reportedly available on the dark web, may be used to pose as bank employees, acquaintances, company representatives or other trusted individuals. The fraudsters then attempt to obtain OTPs or other confidential information.

The investigation has also found that the network extends beyond phone calls. In several cases, victims are first contacted by phone and then asked to click on a link, visit a website, download an application or enter a specific code on their mobile phones. In some instances, fraudsters allegedly attempt to activate call forwarding or make changes to SIM-related services. These steps can then be used in attempts to gain access to banking or other digital accounts.

The use of mule bank accounts to move proceeds of cyber fraud has also emerged as a key part of the investigation. After allegedly defrauding victims in different states, the money is not necessarily transferred directly to the main fraudsters’ accounts. Instead, bank accounts belonging to other individuals are used. Police said such accounts are allegedly provided in exchange for commissions. Once the money reaches these accounts, it may be transferred through multiple accounts or withdrawn through different channels.

Moving money through several layers makes it difficult for investigators to trace the original source and identify the eventual beneficiaries. Around 17,000 complaints linked to Varanasi have reportedly been registered on the National Cyber Crime Reporting Portal. On average, around 23 cases a day reached banks for investigation and further action. Police are now examining the links between the bank accounts, mobile numbers and digital transactions involved in these cases.

The investigation has also indicated that the cyber fraud network is not limited to Varanasi. Police, the cyber cell and cybercrime teams have found transaction links connected with Alwar in Rajasthan, Nashik in Maharashtra, Chandigarh, areas along the Bengal border and several districts of Odisha. Bank accounts and mobile numbers linked to these regions have emerged during the examination of transactions involving mule accounts. Investigators are trying to determine who provided these accounts and who was involved in transferring the money further.

Investigators are also examining transaction patterns in suspicious bank accounts. They are tracking when money entered an account, how quickly it was transferred to another account and whether it was subsequently withdrawn in cash or moved through other digital channels. Police suspect that transferring money across multiple accounts may have been an attempt to conceal its original source and the identities of the alleged fraudsters.

In different cyber fraud cases, police have managed to put around ₹25 crore on hold. However, the money cannot be returned to victims immediately, as banking and legal procedures have to be completed. Police said around ₹4.50 crore has so far been returned to victims, while the process for recovering and returning the remaining amount is continuing.

The cyber cell is also treating attempted fraud seriously. Police said that reporting a suspicious call or message at an early stage can help prevent financial losses instead of waiting until money has already been transferred. For this reason, investigators are continuously analysing the mobile numbers that have been shut down and the bank accounts linked to them.

Police have advised people to treat OTPs, banking details and mobile security codes as highly sensitive information. Dialling a code at the request of an unknown caller, activating call forwarding, opening suspicious links or installing unfamiliar applications can increase the risk of fraud. People should avoid sharing information in haste during suspicious calls and immediately report any suspected cyber fraud or attempted fraud so that the funds can potentially be put on hold and further losses reduced.

About the author — Suvedita Nath is a science student with a growing interest in cybercrime and digital safety. She writes on online activity, cyber threats, and technology-driven risks. Her work focuses on clarity, accuracy, and public awareness.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected