A seasonal tractor driver from Rajasthan’s Tonk district who studied only up to Class 6 has been arrested by Delhi Police as the first identified link in a ₹1.16 lakh UPI fraud, a case that illustrates how even modest financial crimes now leave a traceable digital trail stretching across states.
Police say 28-year-old Kailash Saini was the first beneficiary of money defrauded from a Delhi woman through a fraudulent UPI transaction. Investigators tracked him down not through a confession or an informer, but by cross-referencing banking records with data on the National Cyber Crime Reporting Portal, a method that has become the backbone of how Indian police now chase small-value digital fraud.
From an E-FIR to a Bank Account in Jaipur
The case began with an e-FIR filed by the victim after she discovered ₹1.16 lakh had left her account through a transaction she never authorised. Rather than treating the complaint as a dead end, Delhi Police’s cyber investigators reconstructed the transaction’s path, matching it against NCRP records to establish that the stolen funds first landed in an account belonging to Saini before being pushed onward through a chain of other accounts.
That layering, moving money rapidly through multiple accounts to obscure its origin, is now a routine feature of even relatively small-value fraud cases, not just the multi-crore syndicates that typically make headlines. Investigators say the technique is deliberately designed to exhaust the patience and resources of local police before a trail can be completed, making the successful trace to Saini a small but meaningful demonstration of how far banking forensics have caught up.
A Chase Across Rajasthan
Once the money trail pointed to Tonk district, a Delhi Police team travelled to Saini’s native village, only to find he had switched off his phone and fled by the time they arrived. What followed was a multi-location pursuit relying on local intelligence, technical surveillance and digital location analysis, before officers finally caught up with him in Jaipur.
The recoveries were modest by the standards of India’s larger cyber fraud busts, a single mobile phone and two bank passbooks, but investigators say those passbooks are now central to establishing how much money moved through Saini’s accounts and where it went next. Police are examining that financial activity to identify further beneficiaries in the chain.
Victim, or Willing Participant?
What makes the case worth watching is the ambiguity at its centre. Saini’s background, minimal formal education and work as a tractor driver and daily-wage labourer, fits a pattern investigators across India have flagged repeatedly this year: individuals from financially modest backgrounds recruited, sometimes knowingly for a commission and sometimes without fully grasping the consequences, to lend their bank accounts to fraud networks. Delhi Police cases through 2026 have repeatedly surfaced this same figure, a low-income mule account holder standing between an unsuspecting victim and a fraud syndicate that never appears in the paperwork at all.
Police say the question of whether Saini knowingly participated or was exploited as an unwitting mule will depend on forensic examination of his phone and banking documents. Cybersecurity experts note that criminals rarely let stolen money sit in one account for long, moving it through several beneficiary and mule accounts specifically to complicate investigations and recovery. The public, they add, should treat any unfamiliar UPI payment request or unsolicited financial instruction with suspicion, and report suspected fraud immediately to the 1930 National Cyber Crime Helpline or through the NCRP, since early reporting remains the strongest lever for freezing money before it disappears down the next layer of accounts.
