A phone call seeking routine pension verification has left a retired railway hospital employee in Kalyan poorer by ₹7 lakh, in a case that is once again drawing attention to the vulnerability of senior citizens navigating India’s expanding digital banking ecosystem. The victim, a former ward boy at Byculla Railway Hospital, received a call from someone claiming to be from the Divisional Railway Manager’s Office, asking for his Pension Payment Order number. Within days, the money was gone from his account, despite the family insisting no password, OTP or card details were ever shared. Police have registered a case and are now working to establish exactly how the fraud was executed.
A Call That Ended Abruptly, and a Loss Discovered Later
The incident unfolded on May 5, when the retiree received the call at his Kalyan residence. The caller identified himself as a DRM Office official and said the victim’s PPO details needed to be verified for record-keeping purposes, according to the police complaint.
When the victim’s daughter told the caller that the required documents were not immediately at hand and offered to submit them later at the railway office, the line went dead. At the time, the family saw nothing alarming in this and thought little more of the exchange.
It was only afterward that they discovered ₹7 lakh had been withdrawn from the pensioner’s bank account without his knowledge or authorisation. The complainant has been categorical that no OTP, password or card information was handed over during the call, a detail that has pushed investigators to look beyond simple phishing toward more technical forms of compromise.
Investigators Weigh a Device Compromise Over Simple Phishing
Because the family insists no credentials were shared, police are now examining whether the victim’s mobile device was compromised during or shortly after the call, possibly through a malicious link, a rogue application, or another remote-access technique. This pattern has become increasingly familiar in cyber fraud cases involving elderly account holders across Indian cities, where fraudsters first build trust through a scripted call before covertly gaining control of the victim’s phone.
Cyber cells in cities such as Kolkata and Pune have registered similar cases in recent months, where callers posing as bank or government officials persuaded victims to install disguised applications or click on unfamiliar links, only for remote-access malware to quietly drain their accounts afterward. Investigators in the Kalyan case are treating this as a plausible line of inquiry, alongside the possibility of SIM-linked exploitation or a compromised banking app.
The FIR has been filed under provisions of the Bharatiya Nyaya Sanhita relating to cheating, together with relevant sections of the Information Technology Act, 2000. Police are now analysing call detail records, transaction logs, beneficiary accounts and other digital evidence to trace where the money moved and who ultimately received it.
Why Pensioners Remain a Preferred Target
Elderly citizens continue to be disproportionately targeted in India’s cyber fraud landscape, a trend that data from digital safety researchers has flagged as a growing pattern rather than a series of isolated incidents. Limited digital literacy, a generational instinct to trust figures of authority, and unfamiliarity with how banks and government offices actually communicate all combine to make retirees an easier proposition for organised fraud rings than younger, more digitally native account holders.
Pension-linked scams carry an additional layer of credibility because they exploit a process, PPO verification, that genuinely exists and that pensioners are accustomed to complying with. That familiarity is precisely what fraudsters weaponise, blurring the line between a legitimate administrative call and a criminal one until it is too late.
Cybercrime expert and former IPS officer Prof. Triveni Singh noted that fraudsters increasingly impersonate officials from government departments, banks and pension offices to gain a victim’s confidence before deploying technical means to access their finances. He said criminals typically establish trust through social engineering first and only then move to compromise financial information, and he urged citizens to independently verify any caller’s identity through official contact numbers before sharing personal or pension-related details.
Police have reiterated that pensioners and senior citizens should treat unsolicited calls about pension verification, KYC updates or bank validation with caution, and have advised anyone noticing suspicious account activity to alert their bank immediately, call the 1930 Cyber Helpline, and file a complaint on the National Cyber Crime Reporting Portal without delay.
