Ahmedabad Police are investigating how ₹3.99 lakh was allegedly drained from a 64-year-old trader’s bank account through three unauthorised transactions completed within just 23 minutes.
The victim, AbbasHusen ShabbirHusen Sheikh of Bapunagar, told police that he had not authorised any of the transfers from his Union Bank account.
Rakhial Police have registered a case against an unidentified person and are examining whether the fraud involved a malicious APK file, a screen-sharing application, a phishing link or another form of unauthorised digital access.
The exact method has not yet been established.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
Three Transactions Drained ₹3.99 Lakh Within Minutes
According to the complaint, the transactions took place on September 26.
Sheikh, who runs a health and wellness business from his home in Bapunagar, maintains an account with Union Bank’s Gomtipur branch.
He returned home at around 10 pm and checked messages on his mobile phone.
That was when he allegedly discovered three debit alerts.
The first transaction, worth ₹98,000, had taken place at 5.26 pm.
A second transaction of ₹1.40 lakh followed at 5.48 pm.
Just one minute later, another ₹1.60 lakh was debited.
Together, the three transactions amounted to ₹3.99 lakh.
Sheikh told police that none of the transfers had been authorised by him.
Victim Reported Fraud Through 1930 Cybercrime Helpline
After noticing the transactions, the trader informed his son, Abidhusen.
The family then reported the incident through the national cybercrime helpline 1930.
The helpline is designed to allow victims of financial cyber fraud to report suspicious transactions quickly so that law-enforcement agencies and financial institutions can attempt to trace or freeze the money.
In cases where funds are rapidly transferred through several accounts, the timing of the complaint can be critical.
Police have not publicly disclosed whether any portion of Sheikh’s ₹3.99 lakh has been frozen or recovered.
Police Examine Possible APK, Screen-Sharing or Phishing Attack
The investigation is now focused on how somebody allegedly gained sufficient access to carry out the three transactions.
One possibility under examination is whether Sheikh’s mobile phone had been compromised through an APK file.
An APK is an installation file used by Android phones.
APK files themselves are not inherently malicious. However, cybercriminals can disguise harmful software as bank applications, traffic challans, government services or other legitimate-looking files and send them through WhatsApp or SMS.
Once installed and granted sensitive permissions, malicious software may be able to read messages, monitor activity or help criminals access financial information.
Ahmedabad has previously seen cyber fraud complaints involving malicious APK files disguised as official documents. In one separate case reported earlier this year, a businessman allegedly lost nearly ₹10 lakh after opening an “RTO Challan.apk” file received through WhatsApp.
Police have not said that such a file was definitely used in Sheikh’s case.
Screen-Sharing Applications Also Under Scanner
Investigators are also considering whether a screen-sharing or remote-access application played a role.
Legitimate screen-sharing applications allow another person to view or control a device remotely.
They are commonly used for technical support.
The same tools can be misused when fraudsters persuade victims to install them under the pretext of fixing a bank problem, completing KYC, processing a refund or providing customer support.
If sensitive information appears on the screen during that session, the person controlling or watching the device may be able to capture banking details or guide the victim into performing transactions.
Police are examining whether such access occurred before the three withdrawals.
Phishing Link Is Another Possibility
A phishing link is also among the possibilities being examined.
Such links typically lead to fake websites designed to resemble genuine banking, government or commercial services.
Victims may be asked to enter information such as usernames, passwords, card details or other credentials.
That information can then be misused by fraudsters.
However, police have not said that Sheikh clicked any particular phishing link before the money was withdrawn.
The technical investigation will have to establish whether any suspicious applications, links or unauthorised sessions were present on his device.
Bank and Digital Records Being Analysed
Rakhial Police are examining the transactions to establish where the money went after leaving the Union Bank account.
Beneficiary account records, transaction timestamps and associated digital information could help investigators reconstruct the movement of the funds.
Police are also expected to examine the victim’s mobile device for suspicious applications, permissions, browsing activity or other digital traces.
The 23-minute sequence between the first and final transaction is also likely to be relevant.
Investigators will examine whether all three transfers were carried out using the same access method and whether the recipient accounts were linked.
No suspect has yet been publicly identified.
What this means for you
Never install APK files or screen-sharing applications at the request of an unknown caller claiming to represent a bank, government agency or customer-care service. If an unauthorised bank transaction occurs, immediately contact your bank and report the fraud through 1930 so attempts can be made to trace or freeze the money.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics