A cyber fraud case has been registered in Uttar Pradesh’s Bareilly district after ₹50,000 was allegedly withdrawn from a woman’s bank account without her sharing an OTP or clicking on any suspicious link. The alleged unauthorised withdrawals took place over two days through multiple small transactions, prompting police to begin an investigation into how the money was accessed.
The complaint was filed by Shambhu Khan, a resident of Deoria Abdullah village in the Mirganj police station area. He told police that his wife, Anno Begum, holds a bank account with the Mill branch of HDFC Bank in neighbouring Rampur district. According to the complaint, ₹25,000 was withdrawn from the account on July 21 and another ₹25,000 on July 23, taking the total alleged loss to ₹50,000.
Money withdrawn through multiple small transactions
According to the complainant, the entire amount was not withdrawn in a single transaction. Instead, the ₹50,000 was allegedly taken out through several smaller transactions.
The family became aware of the withdrawals after checking the account activity and subsequently approached the police. They told investigators that neither the woman nor her husband had shared an OTP with anyone. They also denied clicking on any unknown or suspicious link, downloading an unfamiliar application or voluntarily providing banking credentials to another person.
The alleged absence of these commonly associated fraud triggers has made the transaction mechanism a key part of the investigation. Police are now trying to establish how the withdrawals were authorised and what digital or banking channel was used to access the account.
Bank records expected to reveal withdrawal method
Police have registered a case against unidentified persons on the basis of the complaint. Investigators are now seeking detailed transaction records from the bank to determine the exact method through which the money was withdrawn.
The investigation is expected to examine whether the transactions were carried out through an ATM, debit card, internet banking, a digital payment platform or another banking channel. Police will also examine the destination of the funds. If the money was transferred to another bank account or digital wallet, the transaction trail could provide important clues about the persons involved.
Investigators are also likely to examine the timing, location and technical details associated with the transactions to determine whether the account was accessed remotely or whether compromised banking credentials were used.
Technical investigation crucial in cases involving no OTP
Renowned cybercrime expert and former IPS officer Prof. Triveni Singh said that unauthorised withdrawals should not automatically be attributed to OTP sharing. According to him, investigators need to examine the complete transaction mechanism, including banking credentials, device activity, login records and the subsequent movement of funds.
He said that when a victim specifically denies sharing an OTP or clicking on a suspicious link, the investigation should focus on determining how the transaction was authenticated and which digital or banking link enabled the unauthorised movement of money.
Such an approach can help distinguish between different possibilities, including compromised credentials, misuse of banking channels, unauthorised card transactions or other forms of account compromise.
Police tracking the complete money trail
The immediate focus of the investigation is to establish where the ₹50,000 ultimately went. Police will analyse the bank records and technical evidence to identify the accounts, persons or platforms connected with the withdrawals.
Investigators may also examine whether the transactions were linked to any previously reported cyber fraud cases or accounts already flagged for suspicious activity. Such links could help establish whether the incident was an isolated case or part of a wider fraud network.
No arrest has been reported so far. Police said the exact method used to withdraw the money and the identity of those responsible will become clearer after the bank provides the relevant transaction and technical records.
The case highlights an important aspect of modern banking fraud: the absence of an OTP, suspicious link or unfamiliar application does not by itself explain how an unauthorised transaction occurred. Establishing the precise authentication method and following the money trail remain central to determining how the ₹50,000 was allegedly taken and who was behind it.