India’s cyber and technology landscape is evolving across financial crime, quantum-resistant payments, government-linked infrastructure security, AI-enabled border defence and emerging risks from frontier AI.

Cyber Alert: Today’s Biggest Cyber Crime Stories Shaking India – 2nd October

The420.in Staff
12 Min Read

These 10 important cybercrime, cybersecurity, DFIR, AI, BFSI-fraud, policing and national-security developments have been compiled by Centre for Police Technology (CPT) in association with Algoritha Security.

Today’s strongest signal is the convergence of digital evidence, financial intelligence and cybercrime infrastructure — from India’s new banking-evidence framework and large-scale ED investigations to fraudulent SIM issuance, crypto-linked fraud and international ransomware disruption.

1. India’s New Bankers’ Books Evidence Act Takes Effect, Modernising Digital and Cloud Banking Records

The Bankers’ Books Evidence Act, 2026 came into force on 1 October, replacing the 1891 law. It adopts a technology-neutral definition covering banking records maintained in physical, electronic, digital, virtual and cloud-based forms, including contemporary storage systems.

Certification can now use manual, digital or electronic signatures.

The Act also provides that electronic or digital banking records cannot be denied evidentiary recognition merely because they are electronic, subject to the statutory requirements governing authenticity and integrity.

Why it matters: This is particularly important for cybercrime, money laundering, digital-arrest, mule-account and BFSI-fraud investigations. Bank statements and transaction records often form the backbone of the money trail.

Investigators, prosecutors and banks now have a framework better aligned with today’s digital banking architecture.

2. ED’s ₹7-Crore S.P. Oswal Digital-Arrest Investigation Exposes Mule Accounts, Crypto and Foreign Handlers

The Enforcement Directorate has arrested Sohel Akhtar alias Raju in its money-laundering investigation arising from the alleged ₹7-crore digital-arrest fraud against industrialist S.P. Oswal.

Akhtar was arrested in Kolkata after searches in West Bengal and remanded to ED custody until 6 October. He is the third person arrested in the case.

ED alleges that mule bank accounts were supplied to associates, including people operating outside India, while commissions were paid through virtual digital assets and Binance-linked accounts.

Investigators also reportedly found an application called AMMFORWARD and APKs that allegedly enabled overseas associates to receive bank-account SMS messages and OTPs. These are investigative allegations and remain subject to judicial determination.

Why it matters: The case exposes an increasingly sophisticated cybercrime architecture:

Digital Arrest → Mule Account → SMS/OTP Forwarding APK → Remote Operator → Cash → Crypto → Foreign Controller

For DFIR investigators, APKs, devices, SIMs, Binance records, bank logs and encrypted communications could help reconstruct the complete criminal chain.

3. ED Probes ₹958.66 Crore Through Pune Fintech Accounts, With ₹341.66 Crore Reportedly Received Via Payment Gateways

The Enforcement Directorate is investigating transactions totalling approximately ₹958.66 crore received in 11 accounts associated with Pune-based Edsom Fintech Pvt Ltd.

According to reporting on the investigation, approximately ₹341.66 crore was received through payment gateways.

An arrested accused, Ram Ramdhani, was remanded to ED custody until 3 October while investigators examine alleged parking and layering of funds and subsequent transfers through entities and suspected shell companies. These remain allegations under investigation.

Why it matters: Fintech and payment-gateway investigations increasingly require investigators to reconstruct:

Customer/Source → Payment Gateway → Fintech Account → Layering Account → Shell Entity → Beneficial Owner

API logs, merchant IDs, settlement records, device/IP data, KYC and bank records are therefore becoming as important as conventional forensic accounting.

4. ED Arrests Two in Alleged ₹1,417.86-Crore Investment Scheme Involving 35,759 Investors

The Enforcement Directorate has arrested S. Naveen Kumar and S. Muthuselvam under the Prevention of Money Laundering Act in an alleged investment-fraud case involving Unique Exports and associated entities.

The agency alleges that the entities collected approximately ₹1,417.86 crore from 35,759 investors, promising high returns linked to agricultural-export activities.

The investigation originated from an FIR registered by the District Crime Branch in Erode under the IPC and Tamil Nadu Protection of Interests of Depositors Act. Both accused were remanded to judicial custody.

The allegations have not yet been judicially established.

Why it matters: Large investment-fraud investigations require the combination of financial forensics, corporate records, digital communications and asset tracing.

The size of the alleged victim base also illustrates why data analytics can be crucial for identifying common payment accounts, introducers, agents and beneficiary entities across thousands of transactions.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

5. Gurugram Police Trace Cybercrime Infrastructure to Telecom POS Agent Accused of Supplying About 50 Fraudulent SIMs

Gurugram Cyber Police arrested a telecom Point-of-Sale agent from Kanpur who allegedly reused customers’ KYC documents and live photographs to activate additional SIM cards without their knowledge.

Police suspect that approximately 50 SIM cards were subsequently supplied to cybercriminals.

The trail emerged from an investigation into a ₹1.71-lakh commercial fraud in which one of the allegedly fraudulently issued SIMs had been used.

Why it matters: This is precisely why cybercrime investigations should go upstream from the criminal’s phone number.

Fraud Number → SIM → KYC → POS Agent → Other SIMs → NCRP Correlation → Other Crimes → Criminal Network

A single compromised telecom agent can potentially provide communications infrastructure to dozens of unrelated-looking cyberfraud cases.

6. Delhi Police Busts Interstate Telegram Task-and-Crypto Investment Fraud Network

Delhi Police South District Cyber Police arrested three suspects from Udham Singh Nagar, Uttarakhand, in an alleged Telegram task and cryptocurrency-investment fraud.

The investigation began after a complainant reported losing ₹7.86 lakh after being introduced through a Telegram group to online tasks and purported crypto investments promising substantial returns.

Police say the victim transferred the money in two instalments before communication ceased. The wider network is being investigated.

Why it matters: Task fraud has become a repeatable criminal funnel:

Social Media/Telegram → Small Task → Initial Trust → Fake Profit → Larger Investment → Crypto Narrative → Mule Account → Withdrawal Blocked

Investigators should correlate Telegram identities, domains and apps, beneficiary accounts, devices and cryptocurrency wallets across NCRP complaints.

Police in Mohla-Manpur-Ambagarh Chowki district say they arrested three people, including an alleged network controller, after an investigation involving technical evidence and banking-transaction analysis.

Police reportedly linked the suspected network with 176 cybercrime cases registered across multiple states.

The investigation illustrates how apparently small local cases can reveal much larger interstate networks when phone numbers, accounts and digital identifiers are checked across national cybercrime datasets.

Why it matters: India’s cybercrime-investigation model is increasingly shifting from:

One Complaint → One FIR → One Accused

toward:

One Identifier → NCRP Correlation → Hundreds of Complaints → Network → Controller

This is where graph analytics and national-level complaint correlation can significantly improve policing efficiency.

8. GPS-Denied Autonomous Drone Demonstrated at Indian Air Force Dronathon

Hyderabad-based PhoQtek Labs has reported demonstrating a GPS-denied autonomous drone during the Indian Air Force’s Dronathon 2026 at the Pokhran Field Firing Range.

The event was held from 14–16 September and was designed to test drones, autonomous systems and counter-drone technologies in realistic field environments.

The reported capability is particularly relevant because military drones operating in contested environments cannot assume continuous access to GPS/GNSS navigation.

As this is company and event reporting, the claimed performance should not be treated as independently verified operational military capability.

Why it matters: Future autonomous platforms must function under GPS jamming, spoofing, communications disruption and electronic warfare.

That pushes defence technology toward:

Sensor Fusion + Visual/Inertial Navigation + Edge AI + Resilient Communications

and creates corresponding cybersecurity and drone-forensics requirements.

9. International Operation KillSwitch Targets KillSec Ransomware Network Linked to Around 1,000 Suspected Attacks

An international law-enforcement operation led by Hamburg authorities with support from Europol and Eurojust has targeted the KillSec ransomware-as-a-service operation.

On 30 September, authorities took control of its leak site, while three suspects were provisionally arrested and eight properties were searched across Greece, Romania, Spain and the UK.

Investigators reportedly secured at least 110 terabytes of stolen data. KillSec has been linked by investigators to roughly 1,000 suspected attacks worldwide, including attacks affecting healthcare and financial-services organisations.

Why it matters: Ransomware disruption is increasingly moving beyond arresting individual hackers toward dismantling the entire Ransomware-as-a-Service ecosystem:

Developer → Affiliate → Infrastructure → Leak Site → Cryptocurrency → Initial-Access Broker → Victim Data

That model is directly relevant to international cooperation by Indian cybercrime agencies.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

10. China-Linked Hackers Impersonate AI Experts to Target Researchers in US and Japan

Cybersecurity firm Proofpoint says a China-linked threat actor it tracks as TA419 has impersonated prominent US AI and policy experts in phishing operations targeting people at think tanks, universities, defence contractors and law firms in the United States and Japan.

Reuters reported the findings on 1 October.

The attackers reportedly approached targets under the guise of AI collaboration before directing them toward credential-stealing infrastructure.

Proofpoint’s attribution is based on malware, infrastructure and targeting patterns; attribution therefore represents the security firm’s assessment rather than a judicial finding.

Why it matters: AI expertise itself has become a strategic intelligence target. Spear-phishing is increasingly exploiting professional collaboration rather than crude malicious attachments.

For Indian defence organisations, AI laboratories, universities and strategic-technology companies, the lesson is important: researchers and scientists are high-value cyber targets, and collaboration invitations should be subject to identity verification, phishing-resistant MFA and domain/link inspection.

Toady’s Signal  

Today’s strongest pattern is the convergence of digital evidence and financial intelligence.

India’s new banking-evidence law modernises how investigators can establish transaction trails, while the ED cases show cybercrime and financial-fraud proceeds moving through mule accounts, payment gateways, corporate entities and cryptocurrency.

At the infrastructure layer, fraudulent SIM issuance demonstrates how seemingly routine KYC abuse can enable dozens of cybercrimes.

The emerging investigation model is:

Complaint → SIM/Device → Bank/Payment Gateway → Mule Network → APK/OTP Infrastructure → Crypto → Foreign Handler → Digital Evidence → Asset Recovery

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected