Haridwar: Police in Haridwar have uncovered an alleged cybercrime network operating on a model similar to the organised cyber fraud networks associated with Jamtara in Jharkhand. Five people, allegedly involved in arranging bank accounts to receive and move proceeds of online fraud, have been arrested.
According to police, the accused were allegedly assigned specific areas and targets to arrange bank accounts and were promised around 10% of the proceeds generated through cyber fraud. Police recovered 35 ATM and debit cards, 14 bank passbooks, 17 SIM cards, 18 mobile phones, two laptops and ₹37,500 in cash.
How the Haridwar Cyber Gang Allegedly Operated
Investigators allege that the network functioned by supplying bank accounts to cybercriminals involved in online fraud. Instead of directly targeting victims, members allegedly focused on arranging accounts that could be used to receive and transfer fraudulent funds.
According to police, members were given area-wise targets and asked to arrange as many bank accounts as possible. They allegedly received a commission of around 10% of the proceeds for facilitating the accounts.
Police are now examining whether the accounts were used only to receive money or whether members of the network were also involved in transferring, withdrawing or converting the proceeds.
BTech Graduate Allegedly Coordinated the Network
Police have identified Krishna Pandey as the alleged main operator of the network. He is a BTech graduate, while the other accused are reportedly educated up to Class 12.
Investigators allege that Krishna coordinated the activities of the group. Chandramani allegedly handled technical aspects relating to the bank accounts and generated UPI IDs associated with accounts made available to the network.
Police said Chandramani had previously worked as a priest at Har Ki Pauri.
Investigators are examining whether the alleged division of responsibilities indicates a structured network in which different members handled account acquisition, technical operations and movement of funds.
Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions
Bank Accounts Allegedly Obtained for ₹2,000-₹4,000
According to police, members of the alleged network approached people and offered them between ₹2,000 and ₹4,000 in exchange for access to their bank accounts.
The account holders were allegedly told that the accounts were required for online gaming transactions and that they would receive money generated through gaming activities.
Police said some of the accounts allegedly belonged to people who had not been using them for a long time. The accounts were then allegedly made available to the network.
Investigators are now trying to establish whether these account holders knowingly allowed their accounts to be used for cybercrime or whether some of their banking credentials were subsequently misused.
What Are Mule Accounts and Why Do Cybercriminals Use Them?
A mule account is a bank account used to receive, transfer or withdraw money on behalf of another person or criminal network. In cyber fraud cases, criminals often avoid sending stolen money directly to their own accounts.
Instead, fraud proceeds may pass through several accounts belonging to different individuals. This can make it harder to immediately identify the person controlling the money and can create multiple layers in the financial trail.
For investigators, identifying the actual user of a mule account is therefore different from simply identifying the person whose name appears on the bank account. KYC information, transaction patterns, UPI activity, device data, ATM withdrawals and communications can help establish who actually controlled the account.
How the Jamtara Model Relates to the Case
Jamtara, in Jharkhand, has become widely associated with organised networks involved in telephone-based and online financial fraud. Over the years, investigations into cybercrime networks have shown how different individuals can perform specialised roles, including identifying victims, making fraudulent calls, arranging SIM cards, providing bank accounts and moving money.
The Haridwar investigation is being examined against a similar model of specialised roles. Police allege that the accused primarily focused on arranging bank accounts and facilitating financial transactions rather than directly carrying out every stage of the fraud.
However, investigators will need to establish the exact nature of the network and the involvement of each accused through banking and digital evidence.
Bihar Links Under Investigation
Police said Krishna, Chandramani and Chandan Pandey are originally from Bihar and had been living in Haridwar. Krishna and Chandan are reportedly maternal cousins.
According to investigators, Krishna and Chandan are from Nalanda, while Chandramani is from Nawada.
Police have also alleged that Chandramani had contacts with cybercrime operators in Bihar. Investigators are examining these alleged connections and a reported dispute between Krishna and Chandramani concerning the distribution of proceeds allegedly received from Bihar.
The information could help investigators establish links between the Haridwar network and cybercrime operators in other parts of the country.
35 ATM Cards and 18 Mobile Phones Recovered
The 35 ATM and debit cards, 14 passbooks, 17 SIM cards, 18 mobile phones and two laptops recovered from the accused are now being examined.
Investigators are expected to analyse WhatsApp conversations, call records, UPI IDs, banking applications, transaction histories and other digital information stored on the devices.
Bank statements and KYC records will also be examined to establish how many accounts were allegedly controlled by the network, how much money passed through them and where the funds were ultimately transferred.
Cybercrime Expert Explains the Mule Account Risk
Renowned cybercrime expert and former IPS officer Prof. Triveni Singh said mule accounts have become an important component of organised cybercrime networks.
According to Singh, criminals frequently avoid using accounts directly associated with them and instead use accounts belonging to other individuals to route fraud proceeds. Investigators therefore need to establish not only the account holder but also the person actually operating the account, the devices used for transactions, UPI activity and the ultimate beneficiary of the money.
He also cautioned that allowing another person to use a bank account, ATM card or UPI facility in exchange for a small payment can expose the account holder to serious financial and legal consequences.
Investigation Into Wider Network Continues
Police are questioning the five arrested accused and examining the alleged links between account holders, mule-account providers and cybercrime operators based in Bihar.
The seized digital devices and banking records could help investigators reconstruct the alleged financial network and identify additional accounts and individuals.
The investigation remains underway, and the exact role of each accused, the total amount allegedly routed through the accounts and the involvement of other cybercriminals will depend on the evidence collected during the probe.
About the author — Ananya Aradhya writes on cybercrime, fraud, scams, cybersecurity, digital safety, and emerging threats. Her work also covers major criminal cases, financial frauds, consumer scams, and stories that highlight risks affecting people in the real and digital world.