These 10 important cybercrime, cybersecurity, DFIR, AI, BFSI-fraud, policing and national-security developments have been compiled by Centre for Police Technology (CPT) in association with Algoritha Security.
Today’s edition prioritises developments reported on 3–4 October 2026, with India first. Stories covered in the previous editions have been excluded unless there is a material new development.
1. RBI Governor warns: the next financial crisis could begin with a cyberattack
Reserve Bank of India Governor Sanjay Malhotra has warned that the next major financial crisis may originate not inside a bank but from a cyberattack, geopolitical shock or technological failure. Speaking at the Kautilya Economic Conclave on 3 October, he called for system-wide resilience extending across banks, non-banks, markets, payment infrastructure and other interconnected institutions.
Malhotra also identified elevated global debt, stretched valuations—including AI-related valuations—leverage, private credit and AI-amplified cyber threats among emerging vulnerabilities. He said India’s financial system currently remains resilient, but warned that present strength does not guarantee future immunity.
Why it matters: This is an important shift in the definition of systemic financial risk. Cybersecurity can no longer be treated only as an IT/CISO issue. A sufficiently severe attack on payments, clearing, a major bank, cloud infrastructure or another critical dependency can potentially become a financial-stability event.
2. Bhubaneswar Police bust sophisticated mule-account network allegedly linked to foreign operators
Police have arrested four people in Bhubaneswar in an investigation into a mule-account network allegedly supporting cyberfraud across India. The investigation originated from an investment scam in which a Bhubaneswar resident allegedly lost ₹91.9 lakh after being approached through Facebook and moved into a WhatsApp investment group.
Police say the network recruited people to open savings/current accounts, communicated through Telegram, WhatsApp and VPNs, and allegedly used SMS-forwarding APKs to allow remote operators to receive banking messages and operate accounts. Cryptocurrency was allegedly used for commissions, while investigators suspect links with foreign, including Chinese, operators. Eight phones and digital records were seized. These international links remain investigative allegations.
Why it matters: This case reveals a sophisticated cybercrime stack:
Mule Account → SIM/Phone → SMS-forwarding APK → Internet Banking → VPN → Telegram → Crypto Commission → Foreign Controller
For DFIR teams, forensic examination of the APKs, phones, Telegram artefacts, IP/VPN records, crypto wallets and bank-session logs could expose the wider network.
3. Doctor allegedly kept under “digital arrest” for a month loses ₹1.78 crore
A doctor in Uttar Pradesh has reported losing approximately ₹1.78 crore after fraudsters impersonating CBI officials allegedly subjected the victim to a month-long “digital arrest”. The criminals reportedly used sustained intimidation and threats of legal consequences to induce multiple financial transfers.
Why it matters: The duration is significant. Digital-arrest fraud has evolved beyond a quick social-engineering call into prolonged psychological coercion.
Investigators should reconstruct:
Initial Call → Video/Voice Sessions → Fake Documents → Device/Account Monitoring → Transfers → Mule Accounts → Layering → Controller
The case also reinforces the need for banks to detect unusual large-value transfers by customers whose historical behaviour does not match the transaction pattern.
4. Himachal Police begins systematic verification of suspicious mule bank accounts
The cyber cell of Himachal Pradesh Police has begun verification of suspicious bank accounts potentially being used as mule accounts by cybercriminals. The initiative seeks to identify account holders whose accounts are receiving or routing cybercrime proceeds and determine whether they knowingly supplied them to criminal networks.
Why it matters: This represents an important move from reactive victim investigation toward financial-infrastructure disruption.
Instead of:
Victim → FIR → Fraudster
the more scalable model is:
Suspicious Account → Transactions → Linked Accounts → NCRP Complaints → Devices/SIMs → Account Recruiter → Mule Herder → Controller
This type of proactive analysis can potentially disrupt a network before hundreds of additional victims are targeted.
5. Mumbai case exposes emerging “three-way call merge” fraud technique
Mumbai Police have registered an FIR after a 73-year-old singer was allegedly cheated of ₹45,000 in a fraud beginning with a fake parcel-delivery interaction and involving a suspected three-way call/merge-call technique.
The case demonstrates how criminals continue to exploit legitimate telecom functionality rather than relying exclusively on malware.
Why it matters: Awareness campaigns should now explicitly warn citizens against instructions such as “merge this call,” “add this number,” “dial this code,” or “stay connected while verification takes place.”
From a forensic perspective, investigators should obtain call-detail records and reconstruct the complete call topology rather than examining only the number that first contacted the victim.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
6. AI-generated online persona used in alleged cross-border romance fraud; Gurugram man arrested
Police have arrested a former IT professional in Gurugram for allegedly defrauding an Italian jewellery designer after initially presenting himself online as an AI content creator. According to the complaint, the relationship began through Instagram around discussions of AI-generated business content and subsequently developed into a romantic relationship in which marriage was allegedly promised.
Police say the victim ultimately transferred money through Western Union; a phone allegedly used in the offence has been seized. The allegations remain subject to investigation and judicial determination.
Why it matters: Generative AI is increasingly relevant to identity-based fraud, where criminals can create credible personas, images, professional portfolios and conversations at very low cost.
Future romance-fraud investigations may require:
Social Profile → AI-generated Content → Metadata → Device → IP → Payment → Beneficiary → Communication History
7. CBI chargesheet in ₹3,750-crore Reliance Communications–LIC fraud case
The Central Bureau of Investigation has filed a chargesheet in a case involving alleged fraud of approximately ₹3,750 crore connected with investments by LIC in Reliance Communications-related instruments. The chargesheet reportedly names former LIC Chief Investment Officer P. Venugopal along with executives linked with the Reliance ADA Group.
These are allegations before the court and should not be treated as established guilt.
Why it matters: Large institutional-financial fraud investigations increasingly require a combination of forensic accounting, email/e-discovery, investment approvals, board records, communications, fund-flow analytics and digital evidence.
The modern economic-offence investigation is therefore becoming:
Decision → Approval → Digital Communication → Transaction → Beneficiary → Related Party → Asset → Evidence
8. Lucknow Police launches Cyber Security Awareness Month under “Operation Digital Kavach”
Lucknow Police has launched a month-long Cyber Security Awareness campaign under Operation Digital Kavach, focusing on digital-arrest scams, malicious APKs, fraudulent customer-care numbers, fake electricity/gas disconnection messages, UPI fraud, investment scams and online-job fraud.
Police are urging victims of financial cyberfraud to report immediately through 1930 or the National Cyber Crime Reporting Portal.
Why it matters: Cybercrime prevention needs to become a routine policing function rather than an occasional awareness activity. The most effective campaigns should connect awareness directly with action:
Recognise Scam → Stop Transaction → Call 1930 → NCRP Complaint → Bank Hold/Freeze → Police Investigation
9. South Korean regulator holds emergency meeting after cyberattacks hit multiple banks
South Korea’s Financial Services Commission convened an emergency meeting with banks and financial institutions after cyber incidents affecting several major institutions. Hana Bank confirmed that personal information belonging to 89 customers had been exposed, while cyber intrusions were also reported involving Shinhan, KB and Woori.
The regulator has directed financial institutions to examine their systems and strengthen cybersecurity controls while investigations continue.
Why it matters for Indian BFSI: Concentrated attacks against several institutions illustrate sector-wide correlated cyber risk. RBI, banks and payment institutions need to model scenarios in which several financial entities—or a common cloud, telecom or technology provider—are disrupted simultaneously.
This connects directly with the RBI Governor’s warning that cyber incidents could become systemic financial events.
10. Suspected ShinyHunters hacker detained in Jordan and reportedly cooperating with FBI
A suspected member of the ShinyHunters hacking group has been detained in Jordan and is cooperating with the Federal Bureau of Investigation, according to sources cited by Reuters. The suspect, identified as Saif al-Din Khader and known online as “Rey,” is reportedly providing investigators access to electronic communications that could help identify other members of the group.
The development follows the detention of another suspected ShinyHunters member in the Netherlands. The group’s recent claims include attacks against high-profile organisations, although individual breach claims require independent verification.
Why it matters: Cybercrime investigations increasingly depend on international digital evidence and infrastructure, not simply physical arrests.
A single seized or cooperating account can potentially unlock:
Chat History → Handles → Infrastructure → Cryptocurrency → Stolen Data → Co-conspirators → Victims → Attribution
Today’s Strategic Signal
The strongest theme on 4 October is the convergence of cybersecurity and financial stability. The RBI Governor is explicitly treating cyberattacks as a possible trigger for a future systemic crisis, while Indian police investigations continue to show that organised cybercrime depends heavily on mule accounts, SMS-forwarding APKs, VPNs, cryptocurrency and remote overseas controllers.
For Police, BFSI and DFIR teams, the emerging investigation model is:
Victim → 1930/NCRP → Bank Account → Mule Network → SIM/Device → APK → IP/VPN → Crypto Wallet → Foreign Controller → Asset Trail → Recovery
And for banks, the defensive model increasingly needs to become:
Cybersecurity + Fraud Risk + AML + Transaction Monitoring + Threat Intelligence + Incident Response + Systemic Resilience
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics