Deoghar Police have arrested five men in an alleged interstate cyber fraud operation in which victims were targeted through fake customer-care calls, cashback offers and malicious Android files disguised as government or utility-related services.
Police seized five mobile phones and eight SIM cards during the operation. Preliminary technical examination of the recovered devices and numbers allegedly showed links with cyber fraud complaints filed in multiple states.
The five accused have been identified as Sarfaraz Alam, Vijay Kumar Das, Shivam Kumar Das, Nitesh Kumar and Abhay Kumar Das. They were arrested during raids conducted in Deoghar district on September 27 following intelligence received by police.
Investigators are now analysing the phones, SIM cards and digital records to determine how many victims may have been targeted and whether other people were involved in the alleged network.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
Fake Customer-Care Calls Used to Lure Victims
Police said the accused allegedly impersonated representatives of popular payment platforms and financial services.
According to investigators, callers posed as customer-care executives linked to Google Pay, PhonePe and Paytm and offered cashback or assistance to potential victims. Some allegedly presented themselves as Airtel Payments Bank officials.
In one alleged method, victims were told that their payment bank card had been blocked and that assistance was required to reactivate it.
Police suspect that such conversations were used to gain the victim’s trust before banking information or access to the victim’s device was sought.
Fake customer-care fraud works because victims often believe they are speaking with an authorised company representative. Once that trust is established, a seemingly routine request to click a link, install an application or share information can expose banking details.
APK Files Sent in Name of PM-Kisan, Bills and RTO Challans
A second method under investigation involved APK files allegedly sent to victims in the name of PM-Kisan benefits, electricity bills and RTO challans.
An APK is the file format Android phones use to install applications. A genuine APK installs legitimate software. A malicious one can instead be designed to steal information, read messages or obtain dangerous permissions on the device.
Police allege that the files in the Deoghar case were used in attempts to gain access to victims’ phones. Once access was obtained, banking details and other private information could allegedly be exploited for fraudulent transactions.
This is particularly dangerous because banking OTPs, SMS alerts, saved contacts and payment applications may all be available on the same smartphone.
The malicious file may appear to be connected with a familiar service. A message referring to an unpaid electricity bill, pending traffic challan or government benefit can create urgency and push the recipient into installing the file without checking its origin.
Phones and SIM Cards Linked to Complaints From Other States
The interstate dimension of the case emerged during technical examination of the devices seized from the accused.
Cyber police said mobile numbers and IMEI numbers recovered during the raid were checked against available cybercrime records. Investigators found that complaints involving some of the identifiers had allegedly been registered in different states.
An IMEI number is effectively a unique identification number assigned to a mobile device. Even when SIM cards are changed, investigators can use the IMEI to help trace how a particular handset was used.
Police are now comparing the devices with previous complaints to establish which alleged frauds may be connected to the arrested men.
Investigators are also examining call records, SIM usage and financial links to identify bank accounts or other numbers that may have formed part of the wider operation.
Police said Sarfaraz Alam had also previously been named as an accused in Deoghar Cyber Police Station case number 125/25 and Shikaripara police station case number 115/24 in Dumka district. The criminal histories of the other accused are also being examined.
Deoghar Sees Repeated Cases Using Similar Cyber Fraud Methods
The latest arrests are not an isolated example of this method being detected in Deoghar.
On September 19, police reported the arrest of 14 alleged cyber fraudsters across Deoghar and Jamtara in separate raids. In that operation too, suspects were accused of posing as customer-care representatives and sending malicious APK files in the name of PM-Kisan, electricity bills and RTO challans.
Another Deoghar operation reported earlier in September involved suspects allegedly using similar fake customer-care and APK-based methods.
The repeated cases indicate why police are increasingly relying on device identifiers, SIM records and digital complaint databases instead of examining individual fraud complaints in isolation.
The five men arrested in the latest operation have been produced before a court and sent to judicial custody. The allegations remain subject to investigation and have not been proved in court.
Police said further action could follow if analysis of the recovered devices identifies additional suspects or connections with other cyber fraud cases.
What this means for you
Never install an APK received through WhatsApp, SMS or an unknown link simply because it carries the name of PM-Kisan, an electricity provider, RTO or a payment company. Genuine customer-care staff should also never require remote access to your phone to provide cashback, unblock a card or resolve a routine payment issue.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics