Meerut: A major case of corporate cyber fraud has surfaced in Uttar Pradesh after cybercriminals allegedly stole ₹1.80 crore from Gangotri Paper Mills Pvt. Ltd. by compromising a company official’s WhatsApp account and impersonating a shareholder. Investigators believe the attackers used a malicious APK file to gain unauthorised access to the victim’s mobile phone and WhatsApp account before sending fraudulent payment instructions to the company’s accountant. Acting on what appeared to be genuine directions from senior management, the accountant transferred the money to bank accounts allegedly controlled by the fraudsters. Police have registered a criminal case and launched an investigation to identify those behind the attack and trace the stolen funds.
According to the complaint, the fraud came to light after company officials verified the transactions and discovered that the payment instructions had not been issued by the authorised shareholder. Preliminary findings indicate that the attackers created or operated a fraudulent WhatsApp profile in the name of shareholder Neeraj Agrawal, making the messages appear legitimate. Believing the requests to be authentic, the company’s accountant processed multiple fund transfers without suspecting that the communications had originated from cybercriminals.
Investigators said the attack began when Sandeep Goyal, who operates the company’s bank account, allegedly received a malicious APK file through WhatsApp. Police suspect that once the file was downloaded and installed, the attackers obtained unauthorised access to the mobile device and its WhatsApp account. Such malicious applications can potentially enable remote control of a device, intercept communications, access stored information, and facilitate account compromise. Digital forensic experts are now examining the mobile phone to determine the exact malware used and whether any additional data was accessed.
According to investigators, the fraudulent transactions were carried out in two phases. On July 17, the company’s accountant transferred ₹99.99 lakh along with an additional transfer of ₹1,000 after receiving the fraudulent instructions. On July 20, another ₹79.99 lakh and ₹1,000 were transferred to accounts allegedly specified by the fraudsters. The total financial loss amounted to approximately ₹1.80 crore. Authorities are tracing the recipient bank accounts to determine how the money was subsequently moved and whether mule accounts or layered financial channels were used to conceal the proceeds.
The complaint was lodged by Prajwal Agrawal, a resident of Defence Colony on Mawana Road, who informed police that the company operates Gangotri Paper Mills at Jhabreda Narsan in Haridwar district, Uttarakhand. The firm’s bank account is maintained with Punjab National Bank in New Mandi, Muzaffarnagar, and is managed by Sandeep Goyal. Police are examining internal communication records, banking logs, WhatsApp activity, and digital evidence to establish the sequence of events leading to the fraud.
Investigators are also analysing whether the attackers relied solely on malware or combined it with social engineering techniques to gain the victims’ trust. Cyber forensic teams are reviewing device logs, IP addresses, communication metadata, banking transactions, and linked digital accounts to identify the infrastructure used in the operation. Authorities are working to determine whether the same group has targeted other businesses using similar methods.
According to experts at the Future Crime Research Foundation, corporate WhatsApp impersonation attacks combined with malicious APK files have become an increasingly common technique used by organised cybercriminals to target businesses. They advise organisations to prohibit the installation of APK files received through messaging platforms, verify all high-value financial instructions through an independent communication channel such as a direct phone call or video confirmation, and implement multi-level payment authorisation procedures. Experts also recommend enabling multi-factor authentication, maintaining endpoint security solutions, conducting regular cybersecurity awareness training for employees, and immediately reporting suspected cyber fraud to law enforcement and financial institutions to improve the chances of recovering stolen funds.
