Gorakhpur is emerging as a cyber fraud hub, with 16 suspects under scanner and police seizing 1,308 fake QR boxes in a week-long Cyber Vajra crackdown.

Inside Cyber Vajra: 16 Suspects, Fake QR Boxes, and a Rented-Room Racket

The420 Web Correspondent
5 Min Read

Gorakhpur is emerging as a significant operational base for cybercriminals, with police investigations identifying 16 suspects allegedly linked to fraud cases registered across multiple states. Investigators believe some fraudsters have been using the city’s rented houses, lodges and hotels as a relatively low-profile base from which to target victims nationwide, a pattern that surfaced through the special ‘Cyber Vajra’ operation and led to three major crackdowns in a single week.

An Organised Network Hiding in Plain Sight

The Cyber Vajra operation found that several cybercriminals were allegedly staying in short-term rented accommodation while running online fraud schemes aimed at victims in different states, a setup that let them operate away from their home jurisdictions while remaining difficult to trace through conventional local policing. Following this discovery, police intensified verification drives at rented accommodations across the city alongside stepped-up digital surveillance and intelligence gathering.

The 16 identified individuals have bank accounts, mobile numbers and digital footprints suspected to be linked to cyber fraud cases reported from different parts of India, and authorities are now examining their financial transactions and communication records to establish the true extent of the network.

Three Crackdowns, One Common Thread

In the first case, a woman named Manisha was arrested from the Sahjanwa area after investigators found her bank accounts had received money from Andhra Pradesh, Haryana, Maharashtra, Noida and Ghaziabad, allegedly through a fraudulent microfinance company used to deceive victims into fake loan or deposit schemes. In a separate operation, police dismantled a gang accused of converting personal bank accounts into merchant accounts to facilitate fraud through fake QR payment systems, arresting Sanket Rai, Tauheed Alam and Raj Singh in connection with the case.

During the raids, police seized 1,308 fake QR boxes and 866 scanners, alongside mobile phones, SIM cards and other digital devices, equipment investigators believe was used to route cyber fraud proceeds while disguising the transactions as legitimate commercial activity. The scale of that seizure points to a laundering operation built specifically around India’s rapidly expanding UPI ecosystem, where fraudulent merchant accounts can process high volumes of transactions with minimal scrutiny.

Gorakhpur’s Rising Cyber Fraud Numbers

The city’s emergence as a fraud hub is backed by its own recent crime data. Gorakhpur recorded 2,767 cyber fraud cases between January and April 2026 alone, with losses reaching nearly ₹10.73 crore, even as police managed to freeze around ₹3.62 crore in linked accounts during the same period. Officials have separately noted that such networks have expanded into rural pockets of the district, where poor and unemployed residents are lured with promises of government scheme benefits, only to have accounts opened in their names later repurposed as mule accounts.

The fake QR code method uncovered in Gorakhpur mirrors a fraud pattern regulators are actively working to counter nationally. The National Payments Corporation of India has piloted a “SafePay” verification tick for genuine merchant codes in Mumbai, Pune, Delhi and Bengaluru, with plans to expand the initiative to 50 cities by September 2026, while several states have introduced dynamic QR codes that refresh every 60 seconds at high-risk locations such as petrol pumps.

What Comes Next

Authorities are now working to determine how the Gorakhpur-based suspects connect to cybercrime syndicates operating in other states, alongside the total number of fraud cases linked to the network. The investigation is focusing specifically on suspected mule accounts, fraudulent merchant profiles and the digital payment channels used to move stolen funds through the seized QR infrastructure.

Prof. Triveni Singh, a well-known cybercrime expert and former IPS officer, said cybercriminals are increasingly using smaller cities as operational bases to run nationwide fraud networks, precisely because such locations draw less sustained police attention than major metros. He advised the public to remain wary of unsolicited calls, investment offers, QR codes or suspicious links, and urged victims of cyber fraud to report incidents immediately through the 1930 National Cyber Helpline or the National Cyber Crime Reporting Portal, noting that prompt reporting significantly improves the odds of freezing fraudulent transactions.

Stay Connected