Surat Cyber Crime Police have arrested a 38-year-old man who was allegedly supplying Indian bank accounts and digital credentials to cyber fraud operators based in Dubai.
Mohammad Sadiq Tambuwala, a Surat resident who had been wanted in two cases since 2023, was detained at Mumbai International Airport after returning from Dubai. A Look-Out Circular had been issued against him, according to police.
Investigators allege that Tambuwala helped arrange bank accounts for overseas cybercrime operators in return for commission and was also involved in a separate scheme using fake company documents and a fraudulent Digital Signature Certificate to access government trade systems.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
One account saw ₹5.17 crore in transactions in two days
The first case is linked to an online task scam registered in 2023.
According to police, a victim was contacted through a Telegram-linked platform and offered commissions for completing simple online tasks such as subscribing to YouTube channels.
Small returns were allegedly paid initially to build confidence.
The victim was then encouraged to put larger amounts into prepaid tasks and transferred ₹30.20 lakh across multiple bank accounts.
Police say around ₹30,450 was initially returned as commission before approximately ₹29.89 lakh was ultimately lost.
During the investigation, officers identified one bank account that allegedly recorded transactions worth ₹5.17 crore on May 11 and 12, 2023 alone.
Police later found that the same account was linked to 49 cybercrime complaints from different states, involving alleged fraudulent deposits totalling ₹86.34 lakh.
That does not necessarily mean the entire ₹5.17 crore represented proven cybercrime proceeds. Investigators will have to separate legitimate activity, if any, from transactions connected to reported frauds.
Accounts allegedly collected locally and handed to Dubai operators
Police allege that Tambuwala sourced bank accounts from people in India and passed control of them to cyber fraud operators in Dubai.
Such accounts can function as mule accounts.
Instead of money moving directly from a victim to the people running a fraud, it is first received in accounts belonging to individuals or dummy businesses and then transferred onward.
This creates layers between the victim and the ultimate beneficiary.
Investigators say Tambuwala received around 20,115 UAE dirhams, roughly ₹5 lakh, as commission through the alleged network.
Police are now examining who supplied the accounts, who actually operated them and where the money moved after entering India-based accounts.
Second case involves fake DSC and ICEGATE access
The second investigation moves beyond ordinary mule accounts.
Police allege that documents were forged in the name of a business and used to create a fake Digital Signature Certificate, or DSC.
A DSC functions as a digital identity used to authenticate certain online filings and transactions.
ICEGATE, the Indian Customs National Trade Portal, provides services to importers and exporters and requires registered users to use digital signatures for several functions.
Investigators allege that a fabricated email address and mobile number were used along with the fake DSC to access ICEGATE.
The firm’s Import-Export Code was also allegedly misused.
RoSCTL e-scrips allegedly transferred fraudulently
Police say the compromised access was then used in connection with government-issued export incentive e-scrips.
ICEGATE’s official guidance says exporters can use its e-scrip module to claim benefits under schemes including RoSCTL and RoDTEP. After Customs processes an eligible claim, the exporter can generate an e-scrip in its ICEGATE account. Those scrips can also be transferred.
RoSCTL stands for Rebate of State and Central Taxes and Levies.
It is designed to rebate certain taxes and levies embedded in exported goods that are not otherwise refunded.
According to police, seven e-scrips worth a combined ₹95.42 lakh were associated with the firm under investigation.
Four of those, worth ₹54.25 lakh, were allegedly transferred without authorisation.
Dummy company allegedly sold with login credentials
Investigators further allege that Tambuwala and previously arrested Takshal Lungiwala created a dummy company and obtained a DSC in its name.
The company’s Import-Export Code and login credentials were then allegedly supplied to a Dubai-based wanted accused for ₹50,000.
Police say this access was subsequently used in connection with fraudulent e-scrip transfers worth ₹25.36 lakh.
The available allegations therefore point to two different types of suspected facilitation.
One involved bank accounts used to receive cybercrime proceeds.
The other allegedly involved corporate identities, digital signatures and export-system credentials.
Why a fake DSC can be more serious than a stolen password
A stolen password gives access to one account.
A compromised DSC can create a stronger appearance of legitimacy because it is intended to prove that an authorised person or organisation approved a digital action.
That is why government portals such as ICEGATE rely on digital signatures for sensitive trade functions.
ICEGATE’s own documentation says exporters registered with a DSC can create e-scrip accounts and generate e-scrips after eligible claims are processed by Customs.
If a criminal successfully combines forged corporate documents, control of email and mobile numbers, an IEC and a fraudulent DSC, they may be able to impersonate a genuine business across several stages of an online process.
The Surat investigation will therefore have to determine how the DSC was obtained, which verification checks were bypassed and whether any additional companies were compromised.
Two accused had already been arrested
Kunal Sendhane of Dindoli and Takshal Lungiwala of Salabatpura had already been arrested in connection with the investigation.
Tambuwala’s arrest adds another alleged link between the local financial infrastructure and operators based in Dubai.
Police have secured his remand and are examining his phones, financial records and contacts.
They are also looking for other people who may have supplied accounts, created company documents or helped operate the alleged network.
Surat has seen several separate mule-account investigations
The case comes amid wider action against cybercrime-linked accounts in Surat.
The420.in reported in July that seven people were arrested under Operation Mule Hunt 2.0 for allegedly creating fake firms and more than 18 current accounts connected to over ₹116 crore in cybercrime transactions across 21 states.
The420.in also previously reported a separate ₹1,438 crore Surat investment racket in which investigators alleged that funds were routed to Dubai.
But together they show why bank accounts, fake companies and cross-border handlers have become critical parts of large cybercrime networks.
The current allegations against Tambuwala and the other accused have not been proved in court.
What this means for you: Never hand over control of your bank account, SIM, company login, IEC or digital signature to another person in return for commission. Those credentials can be used to move cybercrime proceeds or impersonate a business, leaving the registered holder exposed to a much wider investigation.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics