₹2 Courier Scam Uncovers Suspected ₹10 Crore Fraud Network

The420.in Staff
6 Min Read

A ₹2 courier address update scam has led Delhi Police to an alleged cyber-fraud network involving fraudulent fuel cards, stolen identities and a suspected financial trail of around ₹10 crore. Three men have been arrested, while investigators are examining the wider network.

How Did the ₹2 Courier Scam Begin?

The investigation began after Jitender Kumar Gupta received an APK file on May 7, disguised as a request to update a courier address.

After entering his banking credentials while making a ₹2 payment, unauthorised transactions were carried out from his account. Within minutes, his account was hit twice, with ₹1.98 lakh withdrawn in one transaction and another ₹1.9 lakh in a second transaction. Nearly ₹4 lakh disappeared.

Investigators later found that the stolen money had not followed a straightforward transfer route. Instead of being moved directly to another bank account, around ₹1.9 lakh was allegedly used to recharge a prepaid smart fuel-card customer ID.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

How Did Police Trace the Money?

Police registered an e-FIR and began tracing the transactions. The payment used to recharge the fuel-card customer ID became an important lead in the investigation.

The customer ID was linked to two trucks. Further scrutiny revealed transactions worth around ₹15 lakh through associated fuel cards.

Investigators examined telecom records, SIM issuance details, point-of-sale information and documents used for fuel-card enrolment as they followed the financial trail.

A woman whose identity was allegedly used to obtain a mobile connection told police that she had never taken the number. She suspected that her identity had been misused during SIM porting.

Who Has Been Arrested?

DCP (Southeast) Vineet Kumar formed a team under the supervision of Additional DCP Utkarsh. Police arrested three men identified as Nasir Hussain, 34, Sokeen, 27, and Ashish Arya, 33.

Nasir has been identified by police as the alleged mastermind. Investigators are probing a suspected financial trail of around ₹10 crore.

The investigation took police through several locations in the Mewat region, including Nuh, Nagina and Pahadi, as well as Bharatpur. Nasir was eventually traced to Rajasthan. He and Sokeen were arrested on September 28.

How Did Video KYC Help the Investigation?

Video KYC conducted for the fuel card helped investigators identify Sokeen.

The trail later led police to Ashish Arya, a former retail business executive. Police alleged that Arya had enrolled the fuel card without physically verifying the documents.

During questioning, he identified Sokeen as the person whose video KYC he had conducted. He also admitted, according to police, that he had not properly matched the photograph submitted in the documents with the person appearing on camera.

Police are also examining Nasir’s allegation that he paid Arya for arranging the fuel-card enrolment.

How Were Fraudulent Fuel Cards Allegedly Created?

Police said more than 100 suspected fuel cards have been identified. Questioning indicated that around 150 to 200 fraudulent cards may have been prepared, with each reportedly carrying a limit of ₹7.5 lakh.

According to investigators, the accused allegedly obtained truck owners’ Aadhaar, PAN and vehicle registration documents through a transport platform on the pretext of arranging bookings.

The documents were allegedly manipulated before being used for fuel-card enrolment and video KYC. Police said photographs and addresses were altered using AI-assisted tools.

What Is the Suspected Scale of the Network?

The investigation has expanded from a courier-themed APK fraud involving nearly ₹4 lakh to a suspected network with a financial trail of around ₹10 crore.

The discovery of more than 100 suspected fuel cards and indications that as many as 150 to 200 fraudulent cards may have been prepared have widened the scope of the probe.

Investigators are now examining other fuel cards, the operators involved and the broader financial trail to determine the full extent of the alleged network.

What This Means for Users

A small ₹2 courier update request can be enough to expose banking credentials and trigger much larger unauthorised transactions. Users should avoid installing APK files received through messages or unknown links and should verify courier requests through official channels.

The420 Takeaway

This case shows how a seemingly minor courier payment can be the entry point to a wider fraud network. Never install an APK sent for delivery updates or enter banking details through an unsolicited link.

About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected