India’s cyber and technology landscape is evolving across financial crime, quantum-resistant payments, government-linked infrastructure security, AI-enabled border defence and emerging risks from frontier AI.

Cyber Alert: Today’s Biggest Cyber Crime Stories Shaking India – 26th September

The420.in Staff
8 Min Read

1. CBI Arrests Alleged Operator of Ahmedabad Call Centres That Defrauded Americans of $7.21 Million

The Central Bureau of Investigation has arrested Ankit Satishchandra Pandey in a transnational cyber-enabled financial-fraud investigation involving illegal call centres allegedly operating from Ahmedabad since 2024. CBI says US victims were defrauded of more than $7.21 million.

Investigators allege callers used VoIP to impersonate officials from the US Federal Trade Commission, US Attorney’s Office, CISA and other agencies. Victims were falsely told their identities had been connected to serious online offences and were persuaded to withdraw money, purchase gold and hand it to couriers in the United States.

CBI searches in Ahmedabad also recovered electronic devices containing potential digital evidence. The allegations remain subject to investigation and trial.

Why it matters: This case exposes an increasingly sophisticated transnational architecture:

Indian Call Centre → VoIP/Spoofing → US Victim → Government Impersonation → Gold Purchase → US Courier → Laundering Network

DFIR of seized computers and phones could reveal dialler infrastructure, VoIP providers, scripts, victim databases, remote-access tools, cryptocurrency wallets and overseas controllers. It is also a strong example of why Indian cyber-policing increasingly requires rapid international evidence exchange.

2. Kanpur Police Uncover Suspected ₹250-Crore Cyber-Fraud and Mule-Account Network

Police in Kanpur have arrested four people after an investigation into suspected mule accounts allegedly exposed a cyber-fraud network involving transactions estimated at around ₹250 crore.

Investigators initially examined a suspicious bank account identified through NCRP data and found approximately ₹8 crore moving through it in only three days, with 115 cybercrime complaints across different states reportedly linked to that account. Police allege the wider network used forged Aadhaar documents to open mule accounts for receiving and transferring cyber-fraud proceeds.

Why it matters: The operational lesson is particularly important for police. Instead of investigating every complaint independently, investigators can pivot on a suspicious beneficiary account and use NCRP complaint clustering + bank transaction analytics + KYC documents + device identifiers + mobile numbers to reveal an entire fraud infrastructure.

The model is:

NCRP Complaint → Beneficiary Account → Complaint Clustering → Mule Network → KYC/Device → Controller → Money Trail

The ₹250-crore figure is a police estimate of transactions associated with the suspected network, not an independently established amount of victim loss.

3. SEBI Overhauls Settlement and Investment Rules, Including Cases Involving Fund Diversion

The Securities and Exchange Board of India approved a substantial regulatory package at its 24 September board meeting, covering portfolio management, settlement proceedings, commodity derivatives and investment-market access.

One particularly important compliance change expands the framework for settlement of certain cases involving misrepresentation of financial statements or diversion of funds, subject to specified conditions.

SEBI also approved a new Portfolio Managers Route for Investing in Mutual Fund Units (PRIM), changes affecting FPIs and commodity derivatives, and a common advertisement code for regulated entities.

Why it matters: For listed companies, auditors, CFOs and compliance officers, this is a significant development in India’s corporate-fraud and securities-enforcement architecture. It reinforces the importance of maintaining defensible evidence around financial reporting, related transactions, utilisation of funds and board decisions.

Forensic investigators increasingly need to combine:

Accounting Records → Bank Trail → Related Parties → Emails/Devices → Beneficial Ownership → Regulatory Evidence

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

4. Airtel Says Its AI Network Identified 98.4 Billion Spam Calls and 4.4 Billion Spam Messages

Airtel says its network-level AI security system has identified approximately 98.4 billion spam calls and 4.4 billion spam messages since the spam-detection platform was introduced two years ago.

The telecom operator also says its security systems have blocked more than 1.62 million malicious links delivered through SMS, messaging applications, email and browser redirects. The figures are company-reported and should therefore be understood as Airtel’s own detection metrics rather than government cybercrime statistics.

Why it matters: Telecom networks are becoming part of India’s first layer of cybercrime prevention. The most effective architecture increasingly shifts intervention before a victim reaches the malicious site:

Suspicious Caller/SMS → Telecom AI → Reputation/Behaviour Analysis → Warning/Block → DoT/I4C Intelligence → Police Investigation

The next opportunity is deeper real-time intelligence sharing among telecom operators, banks, I4C and law enforcement so that phone number + device + beneficiary account + URL + complaint can be correlated as a single fraud graph.

5. Bitget Suspends Withdrawals After Crypto Theft Exceeding $350 Million; North Korea Attribution Being Investigated

Major cryptocurrency exchange Bitget temporarily suspended withdrawals after detecting unauthorised transfers from company-controlled wallets on 24 September. Reuters reported an initial loss of approximately $351.6 million, while subsequent analysis produced higher estimates as additional blockchain transactions were identified.

Bitget CEO Gracy Chen said customer funds remained safe and that the exchange would absorb the losses from its own resources. The incident reportedly affected hot and warm wallets rather than the company’s separate self-custodial Bitget Wallet product.

Blockchain investigators have pointed toward possible North Korean involvement, but attribution remains under investigation and should not yet be treated as conclusively established.

Why it matters: For DFIR investigators, this is effectively a digital crime scene distributed across multiple blockchains. Unlike conventional bank fraud, stolen crypto can be moved internationally within minutes through chains, bridges, swaps and privacy-enhancing mechanisms.

The investigative workflow becomes:

Compromised Wallet → Transaction Hash → Address Clustering → Cross-Chain Bridge → Mixer/Swap → Exchange → KYC → Attribution → Asset Freeze

The incident also reinforces the need for Indian exchanges and VDA service providers to maintain robust wallet segregation, key-management controls, transaction anomaly detection, incident-response playbooks and rapid FIU/law-enforcement coordination.

Today’s Strategic Signal

A common theme connects all five developments: cybercrime is becoming an infrastructure problem rather than merely a complaint problem.

The investigation frontier is shifting from:

Victim → FIR → Individual Accused

toward:

NCRP + Telecom + Bank + Device + Blockchain + AI Analytics → Criminal Infrastructure → Controller → Asset

For Indian policing, the next major capability leap is therefore likely to come from a National Cybercrime Intelligence Fusion model that correlates mule accounts, SIMs, IMEIs, IPDR, malicious URLs/APKs, crypto wallets and NCRP complaints in near real time.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected