Ahmedabad: The Ahmedabad Police Cyber Crime Branch has busted an alleged international ‘Boss Scam’ network and arrested two West Bengal residents accused of providing Cybercrime as a Service (CaaS) to a larger cybercrime syndicate. According to the police, Imran Ali Piyada and Injammul allegedly supplied dummy SIM cards, mobile numbers, OTPs and WhatsApp accounts that helped cybercriminals establish the digital infrastructure required for fraud. Investigators analysed data linked to around 4,500 SIM cards and examined 251 complaints registered across 26 states. Police said more than 10,000 infected devices were secured during the investigation.
The two accused were brought to Gujarat on transit warrants and are being questioned about their alleged role in the wider operation. Investigators are also examining whether foreign nationals were involved in the larger network.
Dummy SIM cards allegedly created using biometric data
According to police, Piyada is a graduate who had worked as a Point-of-Sale agent for telecom operators including Airtel, Jio, Vi and BSNL. He allegedly misused customers’ biometric details to activate mobile numbers on SIM cards without their knowledge.
The mobile numbers generated through these alleged dummy SIM cards were then supplied to cybercriminals. When the criminals attempted to create WhatsApp accounts using those numbers, the activation OTPs were received on the dummy SIM cards allegedly controlled by Piyada. The OTPs were then passed on to the concerned cybercriminals, enabling them to activate the accounts.
Police allege that the accused thereby provided an important layer of communication infrastructure for the larger cybercrime operation.
21,000 OTPs allegedly sold over five years
Police claim that Piyada sold approximately 21,000 OTPs over the past five years for e-commerce and online gaming applications. At an average price of ₹100 per OTP, he allegedly earned around ₹21 lakh.
He is also accused of selling around 900 OTPs required for activating WhatsApp accounts. At an average rate of ₹250 per OTP, the alleged earnings from these transactions were approximately ₹2.25 lakh.
Investigators allege that the dummy SIM cards and mobile numbers were used for applications including Amazon and Flipkart as well as online gaming platforms. Injammul, another graduate, allegedly coordinated with people involved in cybercrime and assisted with mobile numbers, dummy SIM cards and WhatsApp-based communication systems.
251 complaints from 26 states examined
During the investigation, the Cyber Crime Branch analysed information associated with around 4,500 SIM cards recovered from mobile devices. Investigators examined 251 complaints registered on the National Cyber Crime Reporting Portal by complainants across 26 states.
The complaints included 194 cases of online financial fraud, three Boss Scam cases, 29 online and social media-related crimes and four cases involving hacking or damage to computer systems. Police also identified complaints involving sexually explicit material and other categories of cybercrime.
Investigators are now matching the mobile numbers, digital accounts and communication channels allegedly supplied by the accused with these complaints to establish their possible role.
China, Pakistan and Hong Kong links under investigation
According to the Ahmedabad Police, technical analysis indicates that the malware allegedly used in the operation may have been developed by cybercriminals associated with China. Investigators suspect that Indian citizens were targeted through a call centre based in Islamabad, Pakistan.
Police also found that bank accounts involved in the alleged cyber fraud were accessed through a China-based VPN service. These findings have led investigators to examine a suspected multi-country cyber infrastructure involving China, India, Pakistan and Hong Kong.
The role of foreign nationals in the wider operation is also being investigated.
How the ‘Boss Scam’ allegedly works
In a typical Boss Scam, criminals allegedly impersonate an RBI official or another government authority and send a ZIP file to a company’s CEO, director or employee through WhatsApp or email. The file may contain malicious executable or system-library files. Once opened on a computer, the malware can allegedly enable criminals to gain control of a WhatsApp Web session.
The criminals then save their own mobile number under the name of the CEO or director and use the person’s profile photograph. They allegedly instruct employees in the accounts or finance department to make urgent financial transfers.
Because the genuine number may be replaced by the criminal’s number under the boss’s name, employees may fail to independently verify the request. Police are now questioning the arrested accused to identify other members, financial channels and overseas links of the alleged network.
About the author — Suvedita Nath is a science student with a growing interest in cybercrime and digital safety. She writes on online activity, cyber threats, and technology-driven risks. Her work focuses on clarity, accuracy, and public awareness.