Faridabad Police have arrested the alleged mastermind of an interstate cybercrime gang accused of cheating an elderly man of ₹5.12 lakh through a malicious Android application disguised as an Adani Gas bill-payment tool.
The accused has been identified as Deepak Kumar Mandal, a resident of Giridih district in Jharkhand.
Police also arrested Anil Kumar Mandal of Deoghar, Jharkhand, taking the total number of arrests in the case to seven. Five alleged gang members from Surat had been arrested earlier.
The investigation has now widened significantly.
Police say they recovered data relating to around 20,000 Adani Gas consumers and 1,000 UCO Bank customers, while the gang had allegedly sent malicious APK files to 116 people.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
Victim Threatened With Gas Disconnection
The case began after an elderly resident of Sector 37 in Faridabad filed a complaint on September 1.
According to police, the victim received a message claiming that his Adani Gas bill was unpaid and warning that his gas connection would be disconnected unless payment was made immediately.
The message included a mobile number.
When the victim contacted that number, the fraudsters allegedly sent him an APK file and asked him to install it.
Once the file was opened, police say the attackers gained access to the victim’s phone.
₹5,12,334 was subsequently siphoned from his bank account.
Five Accused Were Arrested Earlier
Faridabad Cyber Central Police registered an FIR and began tracing the people linked to the transaction and malicious application.
Five accused were arrested during the earlier phase of the investigation.
Police identified them as Ashwin Bhai, Khunt Dhaval, Manish Bhai, Deep Vitthalbhai and Pithabhai Bhaya Bhai, all residents of Surat in Gujarat.
They have already been sent to jail.
The investigation then led officers to Jharkhand, where Deepak Kumar Mandal and Anil Kumar Mandal were arrested.
Both have been placed on four days of police remand.
Police Call Deepak the Gang’s Mastermind
Police describe Deepak as the alleged ringleader of the interstate operation.
Inspector Basant Kumar, SHO of Cyber Police Station Central, said questioning indicated that Deepak purchased citizen data and malicious APK files through Telegram.
The data allegedly included information related to Adani Gas customers and transport-office records.
Police say the gang used that information to make fraud calls more believable.
Instead of randomly contacting people, the callers could potentially refer to a real gas connection or other genuine customer detail.
That can make a fraudulent message appear much more convincing.
20,000 Adani Gas Customer Records Allegedly Recovered
One of the most serious findings concerns the amount of customer information found during the probe.
Police say data belonging to approximately 20,000 Adani Gas consumers was recovered.
Information linked to roughly 1,000 UCO Bank customers was also found.
Investigators are now trying to determine where the data came from, who supplied it and whether it had been obtained through a breach, insider access, purchased databases or another source.
The available police statement does not establish that Adani Gas or UCO Bank systems themselves were hacked.
That distinction is important.
Possession of customer data does not automatically prove the institution that originally held it suffered a direct cyberattack.
APK Files Sent to 116 People
Police say the gang sent APK files to 116 individuals.
Not all 116 are confirmed victims of financial loss.
Investigators are examining whether the applications were installed and whether any additional unauthorised transactions occurred.
This means the ₹5.12 lakh loss linked to the Sector 37 complainant may be only one part of the wider investigation.
Police are comparing the numbers and devices recovered from the accused with cybercrime complaints filed elsewhere.
How the APK Scam Works
An APK is the installation file used by Android devices.
APK files themselves are not malicious. Android applications are distributed using the same format.
The danger arises when criminals disguise malware as a trusted service and persuade someone to install it manually.
In this case, the file was allegedly presented as being connected with gas-bill payment.
Once a malicious application is installed and granted powerful permissions, it may be able to read messages, monitor notifications, capture information entered by the user or remotely interact with parts of the device.
The exact technical capabilities of the APK used in this case are still part of the investigation.
Telegram Allegedly Used to Buy Fraud Tools
Police say Deepak told investigators that customer data and APK files were obtained through Telegram.
Telegram itself is a legitimate messaging platform.
But private groups and channels are also sometimes used by cybercriminals to buy and sell stolen data, malware, mule accounts and other fraud infrastructure.
The allegation is significant because it suggests the gang may not have developed every part of the fraud operation itself.
Instead, different components — customer data, malicious applications and money-transfer methods — may have been sourced separately.
That reflects the increasingly specialised nature of cybercrime.
Fraud Proceeds Allegedly Used to Pay Credit Card Bills
Police say Deepak allegedly used some of the stolen money to pay outstanding credit-card bills.
Investigators are examining those payments as part of the financial trail.
Six mobile phones, SIM cards, credit cards and other electronic devices were also seized from the accused.
Those devices may help police identify additional victims, communication channels and payment accounts.
Customer Data Is a Major Part of the Fraud
The case shows why personal data has become valuable to cybercriminals.
A fraudster who knows nothing about a victim must first convince them that a call is genuine.
A fraudster who already knows the victim’s service provider or customer details begins with an advantage.
That information can be used to create messages such as:
“Your gas bill is overdue.”
“Your bank account needs verification.”
“Your service will be disconnected.”
The data does not itself authorise a transaction.
But it makes social engineering far more convincing.
Police Probe Wider Interstate Network
The arrests span Gujarat and Jharkhand, while the victim was in Haryana.
Police are therefore treating the group as an interstate cybercrime operation.
Investigators are now examining whether the accused are connected with similar APK fraud complaints in other states.
They are also trying to identify the original sources of the customer databases and the people who supplied malicious applications to the gang.
The accused have not been convicted, and the allegations remain subject to investigation and court proceedings.
What this means for you
Never install an APK file sent through WhatsApp, SMS or Telegram simply because the sender claims it is needed to pay a gas bill, bank charge or government fee. Open the company’s official app or website independently instead, especially when a message threatens immediate disconnection or account blocking.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics