A construction and services businessman in Uttar Pradesh’s Basti district has lost more than ₹3.31 lakh after cybercriminals allegedly hacked his WhatsApp account and used it to withdraw funds from his linked bank account through three rapid-fire transactions, all executed within a single minute. The incident, reported from the Walterganj area, has prompted police to register a case against unidentified attackers as investigators trace both the digital and financial trail left behind.
Dinesh Kumar Pandey, 48, a resident of Gangapur who operates an account under the name DP Construction and Service Provider, told police the breach occurred between 1:19 pm and 1:20 pm on August 13. In that narrow window, an unidentified attacker allegedly gained unauthorised access to his WhatsApp account, accessed data stored on the device, and carried out three separate transactions totalling ₹3,31,319.27 from his linked bank account before he became aware anything was wrong.
A Minute-Long Breach With a Familiar Signature
The speed and structure of the Basti case mirror a pattern that has become increasingly common across India’s WhatsApp-linked fraud landscape over the past year. Most account takeovers of this kind do not exploit a flaw in WhatsApp’s encryption itself but rather manipulate the platform’s own account-verification and device-linking features, tricking a victim into unknowingly authorising access rather than breaking through any technical barrier.
India’s Computer Emergency Response Team issued an advisory late last year warning of a technique researchers dubbed GhostPairing, in which attackers exploit WhatsApp’s multi-device linking feature by sending victims a message resembling a photo link. When the recipient enters their phone number to view the supposed content, they unknowingly authorise a hidden device to pair with their account, granting the attacker silent, persistent access without needing an OTP or a SIM swap. A related and more established technique relies on convincing victims to forward a six-digit verification code, often under the pretext that it was sent to them by mistake, which instantly transfers control of the account once entered on the attacker’s device.
Why Business Accounts Carry Amplified Risk
Investigators examining the Basti case are focused on establishing precisely how access was obtained and whether information harvested from the compromised WhatsApp account, such as saved conversations, contact details or transaction records, was subsequently used to facilitate the bank withdrawals. Police are treating the three transactions as distinct threads, each requiring separate tracing to identify the beneficiary accounts and determine whether the funds have already moved further along a layered chain designed to frustrate recovery.
The case underscores a risk that grows more pronounced for business users, whose mobile numbers and messaging accounts are frequently tied not just to personal communication but to banking alerts, payment confirmations and client transactions. A compromised account in such cases can expose far more than private conversations, effectively handing an attacker a live map of a victim’s financial relationships and habits. Cybersecurity researchers have noted that WhatsApp remains India’s most-targeted messaging platform for exactly this reason, given its sheer ubiquity and its deep integration with everyday financial life for millions of small business owners.
Tracing Stolen Funds Through Layered Accounts
Walterganj police, having registered the case on August 14, are now cross-referencing mobile device records, WhatsApp activity logs and banking transaction data to reconstruct the precise sequence of events, including whether the attacker relied on social engineering, a technical exploit of the device-pairing feature, or a combination of both. As with most such cases, the central challenge lies less in identifying that a fraud occurred and more in tracing where the money went once it left Pandey’s account, since stolen funds are typically moved through multiple intermediary accounts within minutes to obscure the ultimate recipient.
Investigators say the outcome will depend heavily on how quickly the beneficiary accounts can be frozen and whether any of the funds remain traceable before further transfers occur, a race against time that has become a defining feature of nearly every digital fraud investigation in India today. Police have not ruled out the possibility that the Basti case is linked to a wider network operating similar WhatsApp-based frauds elsewhere in the state.
