Delhi Police have arrested two men from Jammu and Kashmir and Rajasthan in a ₹6 lakh digital-arrest fraud case after investigators traced the victim’s money through bank accounts and uncovered a digital trail allegedly linked to Cambodia.
The accused have been identified as Ritish Kumar Mehra of Kathua in Jammu and Kashmir and Mukesh Kumhar of Bhilwara in Rajasthan.
Police recovered three mobile phones, four ATM or debit cards, five cheque books and five rubber stamps during the investigation.
The case is being investigated by the South Delhi district cyber police.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
Victim Threatened Through Video Call
According to police, the complainant was contacted through a video call by people posing as law-enforcement officials.
The callers allegedly told the victim that he was involved in a criminal matter and threatened him with arrest.
They then persuaded him to transfer ₹6 lakh into bank accounts provided by them, purportedly to avoid legal action or complete a verification process.
An e-FIR was registered after the victim approached police.
Investigators then began tracing the accounts that received the money.
₹5.5 Lakh Traced to Kathua Accused
The financial trail showed that ₹5.5 lakh of the victim’s money was transferred into a Kotak Mahindra Bank account operated by Ritish Kumar Mehra, according to police.
Another ₹50,000 allegedly reached a Federal Bank account controlled by Mukesh Kumhar.
Police first traced Ritish to Kathua and arrested him there.
Information gathered during his questioning and further investigation then led police to Mukesh in Bhilwara, Rajasthan.
The allegations against both men have not yet been proved in court.
₹50 Lakh Transactions Found in Another Account
The investigation widened after police examined Mukesh’s banking history.
One account linked to him had recorded transactions totalling around ₹50 lakh, police said.
Investigators also found that the same account was connected to at least 10 complaints registered through the National Cyber Crime Reporting Portal across different states.
That does not mean the entire ₹50 lakh represents proven fraud proceeds.
Police are now examining individual transactions to determine which may be linked to cybercrime cases and whether the account was repeatedly used to receive or route stolen money.
Cambodia Link Found in Technical Investigation
Police said technical analysis of the online communications used during the fraud showed digital links to Cambodia.
Investigators are now trying to establish who was operating from Cambodia and what role those people played in the scam.
The available police account does not establish that Ritish or Mukesh themselves operated from Cambodia.
The safer conclusion is that the communication infrastructure or people directing part of the operation appear to have links to the country.
Cambodia Has Emerged in Several Indian Cyber Fraud Investigations
Indian agencies have repeatedly uncovered cybercrime networks with operational links to Cambodia and other parts of Southeast Asia.
Some networks use call centres outside India while relying on local associates to arrange bank accounts, SIM cards or cash withdrawals.
In April, Delhi Police’s IFSO unit busted a separate alleged Cambodia-linked network that used SIM-box technology to make international scam calls appear as ordinary Indian mobile calls.
In another major Delhi investigation in 2025, police said a ₹23 crore digital-arrest racket had links to Cambodia and used Indian accounts and organisations to move money.
These are separate cases, but they show why investigators increasingly focus on both the overseas operators and the Indian financial infrastructure supporting them.
Why Bank Accounts Are Critical to Digital Arrest Networks
Digital-arrest scams usually require several different roles.
One group contacts and intimidates the victim.
Another arranges bank accounts to receive the money.
Funds may then be moved rapidly through additional accounts to make recovery more difficult.
These receiving accounts are often referred to as mule accounts when they are used to transfer cybercrime proceeds on behalf of others.
The latest case illustrates why tracing these accounts is critical even when the account holder may not be the person who spoke directly to the victim.
Police Examine Phones, Cards and Cheque Books
The seized phones could help investigators identify call records, messaging accounts and communication with other members of the suspected network.
Police are also examining the ATM cards, cheque books and rubber stamps recovered during the operation.
These materials may help determine whether additional bank accounts or business entities were used to receive and move money.
Investigators are also comparing the accused’s records against the 10 NCRP complaints already linked to one of the accounts.
Overseas Operators Remain Under Investigation
The arrests appear to have exposed only the Indian side of the alleged network so far.
Police are continuing to trace the people operating through Cambodia-linked digital infrastructure and determine how instructions were communicated to the Indian account holders.
Further arrests could follow if investigators identify additional people involved in collecting accounts, routing funds or making the impersonation calls.
What this means for you
No police, CBI, customs or other legitimate agency will place you under “digital arrest” over a WhatsApp or video call or ask you to transfer money to avoid arrest. If someone makes such a demand, disconnect immediately and report it through 1930 and the National Cyber Crime Reporting Portal.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics