India’s cyber and technology landscape is evolving across financial crime, quantum-resistant payments, government-linked infrastructure security, AI-enabled border defence and emerging risks from frontier AI.

Cyber Alert: Today’s Biggest Cyber Crime Stories Shaking India – 3rd October

The420.in Staff
12 Min Read

These 10 important cybercrime, cybersecurity, DFIR, AI, fraud-risk, policing and national-security developments have been compiled by Centre for Police Technology (CPT) in association with Algoritha Security.

Today’s edition prioritises developments reported or becoming operational on 2–3 October 2026 and avoids repeating yesterday’s stories unless there is a material new development.

1. ED Uncovers ₹734-Crore Fake-GST-Credit Network Built Around 135 Shell Companies

The Enforcement Directorate has arrested Gyaan Chand Jaiswal alias Babloo Jaiswal and Raaj Jaiswal following searches in Jharkhand and West Bengal.

ED alleges that the wider syndicate created 135 shell companies, issued bogus invoices exceeding ₹5,000 crore without actual supply of goods or services, and generated or passed fake Input Tax Credit exceeding ₹734 crore.

The two were remanded to judicial custody after being produced before a special PMLA court in Ranchi.

Investigators say digital devices and documents were seized and allege that part of the proceeds was layered through business and personal accounts. These are ED allegations and remain subject to adjudication.

Why it matters: This is essentially a financial-network investigation. Detecting modern GST fraud requires connecting company registrations, GSTINs, invoices, directors, bank accounts, devices, IP addresses and beneficial owners.

Graph analytics can expose hundreds of apparently independent companies as one coordinated infrastructure.

Surat Cyber Crime Cell has arrested a 28-year-old man accused of supplying a bank account used in online investment fraud.

Police say approximately ₹2.72 crore passed through the account, while NCRP-linked analysis connected it with 37 cybercrime complaints across multiple states involving roughly ₹7 crore.

The investigated fraud allegedly used WhatsApp investment groups and a fraudulent website promising extraordinarily high stock-market returns.

Why it matters: The important development is the investigative technique:

One Bank Account → NCRP Search → 37 Complaints → Multiple States → Account Supplier → Wider Network

This is the direction Indian cyber policing can scale toward — investigating criminal infrastructure rather than complaints in isolation.

3. Gurugram ₹4.72-Crore Crypto-Investment Scam Exposes Phishing App, Manipulated Profits and Mule Accounts

Gurugram Cyber Police have arrested two men in Hisar who allegedly supplied bank accounts to a network that cheated a victim of ₹4.72 crore through a purported Bitcoin/USDT investment scheme.

Investigators say the victim was approached through Telegram and WhatsApp and induced to install an application that displayed investment returns controlled from the backend.

When the victim attempted to withdraw funds, the criminals allegedly demanded another ₹1.25 crore as GST, taxes and other charges. Police are now tracing additional accounts and participants.

Why it matters: This demonstrates the anatomy of modern investment fraud:

Telegram/WhatsApp → Phishing App → Fake Dashboard → Artificial Profit → Larger Investment → Mule Accounts → Withdrawal Block → Fake Tax Demand

For DFIR teams, reverse-engineering the APK, extracting its servers and domains, and correlating them with bank accounts and NCRP complaints can potentially reveal additional victims.

4. Coimbatore Records ₹36.23 Crore in Cyberfraud Losses in Nine Months; Investment Scams Cause Biggest Damage

Coimbatore District Police data cited on 2 October shows approximately 4,535 cybercrime complaints during the first nine months of 2026 and reported losses of about ₹36.23 crore.

Of the complaints, 2,078 reportedly came through the 1930 helpline and 2,457 through the National Cyber Crime Reporting Portal.

Online-shopping complaints were numerous, but police data indicates that fake investment and trading schemes accounted for the largest financial losses.

Why it matters: Complaint volume alone is a poor measure of cybercrime severity.

Police dashboards should simultaneously measure:

Number of Complaints + Money Lost + Amount Put on Hold + Amount Frozen + Amount Restored + Repeat Infrastructure Identified

Investment scams may generate fewer complaints than low-value consumer fraud while inflicting vastly greater economic damage.

5. Moradabad Cyberfraud Money Fragmented Across 108 Bank Accounts in Five States

Cyber Police investigating the disappearance of ₹6.15 lakh from a Moradabad resident’s accounts say the money was broken into small transfers and dispersed across 108 bank accounts in Uttar Pradesh, Bihar, Jharkhand, Rajasthan and Delhi.

The complainant reportedly said he neither shared OTPs nor received transaction alerts during the relevant period.

Police are collecting KYC and transaction details for the beneficiary accounts.

Why it matters: Cybercriminals increasingly use automated or organised money-mule fan-out:

Victim Account → First Mule → 10 Accounts → 100 Accounts → Cash/Crypto/Wallet → Controller

Banks should be able to detect unusually rapid many-to-many dispersal patterns, while police need graph-analysis tools capable of reconstructing the network before funds disappear further downstream.

6. ED Arrests Ozone Urbana Promoter in Alleged ₹927.22-Crore Homebuyer Fraud

ED’s Bengaluru Zonal Office has arrested S. Vasudevan, CMD and promoter of Ozone Urbana Infra Developers, in a PMLA investigation concerning an alleged ₹927.22-crore homebuyer fraud.

A special court granted ED 14 days’ custody.

ED alleges that money collected from buyers was retained or diverted while projects were delayed or not delivered as promised. The investigation originates from multiple police FIRs and CBI cases.

The allegations have not been judicially established.

Why it matters: Large economic-offence investigations increasingly demand:

Forensic Accounting + Digital Forensics + Beneficial-Ownership Analytics

Emails, ERP and accounting systems, banking records, board approvals and related-party transactions can be as important as conventional witness evidence when reconstructing alleged diversion of funds.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

7. UP Says ₹874.58 Crore in Cybercrime Money Has Been Frozen or Put on Hold

Uttar Pradesh authorities have reported that more than ₹874.58 crore connected with cybercrime complaints has been frozen or placed on hold, alongside broader figures on organised-crime enforcement released on 2 October.

The figure represents money frozen or held, not necessarily money already restored to victims. Those concepts should not be conflated.

Why it matters: This is an important performance distinction for cyber policing.

The complete victim-centric metric should be:

Amount Lost → Reported → Put on Hold → Frozen → Seized → Court Released → Actually Restored to Victim

The next major challenge is shortening the time from a 1930 complaint to beneficiary-account freeze, ideally toward near-real-time intervention.

8. Indian Startups Put AI Processing, Thermal Imaging and Earth-Observation Payloads Into Orbit

Several Indian space-technology startups placed payloads in orbit aboard SpaceX’s Transporter-18 Falcon 9 mission on 2 October.

Participants include Dhruva Space, TakeMe2Space, SatLeo Labs and EON Space Labs, with demonstrations covering thermal imaging, Earth observation and AI-based processing in orbit.

Dhruva Space’s LEAP-2 satellite was successfully deployed, while SatLeo Labs’ TAPAS-1 is described by the company as India’s first dedicated commercial thermal payload.

Why it matters: Moving AI processing onto satellites can reduce dependence on continuously sending raw imagery to Earth.

For national security and policing, future applications could include border monitoring, disaster response, infrastructure surveillance, maritime-domain awareness and rapid anomaly detection.

It also makes satellite software, firmware and communication links increasingly important cybersecurity assets.

9. Critical Alert: FortiMail Zero-Day Actively Exploited; CISA Adds It to KEV

Fortinet has warned that CVE-2026-104286, a critical FortiMail vulnerability rated CVSS 9.8, is being exploited in the wild.

The flaw can allow an unauthenticated attacker to write arbitrary files to an underlying system through crafted HTTP/HTTPS requests, potentially enabling code or command execution.

CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue. Fortinet had not yet released fixes when the advisory was issued and instead published workarounds and indicators of compromise.

Why it matters: FortiMail frequently protects an organisation’s email perimeter, making successful compromise particularly dangerous.

Government, police, BFSI and enterprise SOCs using affected versions should prioritise:

Identify → Restrict Management Access → Apply Fortinet Workaround → Hunt IoCs → Preserve Logs → Check Persistence → Patch When Available

Organisations should not assume that applying a future patch alone will remove an attacker who has already established persistence.

10. KillSec Takedown Deepens: Alleged Ransomware Administrator Is Just 16

A major international law-enforcement operation against KillSec ransomware has produced an extraordinary finding: Europol says a 16-year-old Romanian national arrested in Alicante, Spain, is suspected of being the group’s administrator and main operator.

Investigators have linked KillSec to roughly 1,000 suspected attacks worldwide.

The German-led Operation KillSwitch involved multiple countries. Authorities provisionally arrested three suspects, searched eight properties, seized the group’s leak infrastructure and secured at least 110 TB of stolen victim data.

Investigators are also tracing cryptocurrency proceeds.

Why it matters: The case illustrates how Ransomware-as-a-Service can lower barriers to sophisticated cybercrime.

More importantly, law enforcement attacked the ecosystem rather than simply one endpoint:

Administrator → Developer → Affiliate → Infrastructure → Leak Site → Stolen Data → Cryptocurrency → Criminal Proceeds

That model offers an important template for multinational cybercrime investigations involving India.

Today’s Signal 

Three patterns stand out today.

Financial crime is becoming graph-shaped, with one mule account connecting dozens of complaints and stolen money spreading across more than 100 accounts.

DFIR is moving upstream, from victims toward APKs, SIM providers, domains and infrastructure.

And internationally, law enforcement is increasingly disrupting complete cybercrime ecosystems rather than merely arresting individual offenders.

For Indian cyber policing, the evolving model is:

1930/NCRP → Bank Account → SIM/Device → APK/Domain/IP → Graph Analytics → Criminal Infrastructure → Controller → Crypto/Asset Trail → Attachment → Victim Restitution

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected