An unauthorized service desk operating inside a public sector bank branch in Bihar was exposed after an operator allegedly used a cloned credential to access the central identity system. The breach occurred at a Bank of India branch in Makhdumpur, situated within Bihar’s Jehanabad district. The illicit operation came to light when suspicious behavior prompted branch officials to demand immediate re-authentication. The operator subsequently fled the premises, leaving behind computer hardware now seized by authorities.
The incident highlights operational vulnerabilities in third-party service desks deployed across institutional banking premises. According to local reporting, the individual gained access to enrollment systems under the guise of an authorized vendor partner. When questioned regarding his credentials, the operator initially resisted verification, displaying aggressive behavior and claiming judicial connections. Following escalation to the branch manager, the operator admitted during internal questioning that he was operating the portal using duplicated credentials belonging to a legitimately certified operator before abandoning his workstation and escaping the facility.
Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions
Technical Forensics and Vendor Compliance Under Probe
Following the operator’s flight, bank officials secured the workstation, hard drives, and peripheral devices deployed at the counter. The hardware was placed under administrative custody to prevent data tampering and facilitate a forensic audit. Investigators are currently analyzing log files, IP footprints, and transaction histories to determine the operational duration of the cloned credentials and measure the volume of demographic or biometric records modified through the compromised terminal.
The bank management formally alerted senior regional leadership alongside the external vendor agency, Pay In Solution Private Limited, contracted to manage identity service operations at the branch. Representatives from the vendor firm have been summoned to clarify onboarding protocols and explain how secondary credentials were generated without mandatory biometric verification. Bank officials clarified that branch leadership had no prior knowledge of the fraudulent operation, as the desk operated under the institutional umbrella of an authorized provider.
Systemic Risks and Credential Security Vulnerabilities
The Jehanabad incident brings into focus the severe security risks associated with credential duplication within public authentication networks. Authorized operators must adhere to strict multi-factor authentication protocols, including mandatory biometric verification and location-based geo-fencing designed to prevent remote or unverified access to core identity databases. The successful deployment of a cloned identity inside a financial institution suggests potential gaps in real-time operator verification mechanisms.
Cybersecurity experts emphasize that unauthorized system entry exposes citizens to significant risks of identity theft, fraudulent updates, and unlawful record alterations. Beyond immediate regulatory violations, the breach raises concerns regarding the physical security of third-party desks housed inside trusted banking facilities. Law enforcement agencies are currently attempting to trace the origin of the cloned credentials, identify the legitimate credential holder whose identity was duplicated, and ascertain whether the scheme operated as an isolated breach or formed part of a wider syndicate.