Three residents of Noida and Greater Noida have collectively lost ₹29.06 lakh in a cluster of unrelated cyber fraud cases registered within days of each other, illustrating how thoroughly two distinct fraud templates, malicious APK files and Telegram-based task scams, have embedded themselves into everyday digital life across the National Capital Region. Police have registered FIRs in all three cases and are examining banking and digital trails to determine whether the incidents share any underlying network.
The cases, while procedurally separate, together sketch a revealing picture of how varied the entry points into cyber fraud have become, ranging from a single tap on a malicious file to a slow-burning relationship built over weeks inside a Telegram group. Each relied on a different psychological lever, but all three ended the same way, with victims discovering too late that money once transferred was effectively unrecoverable.
A Fake Challan That Hijacked a Bank Account
The most technically damaging of the three cases involved Noida resident Manoj Kumar Patel, who received an APK file disguised as an RTO traffic challan over WhatsApp on July 3. After opening the file and entering the requested information, his WhatsApp account was compromised almost immediately, and the attackers went further than simple account takeover, allegedly forwarding his mobile calls to another number entirely, a step that effectively silenced any bank verification calls that might otherwise have alerted him to the fraud in progress.
With call forwarding in place, the attackers reportedly gained control over his banking activity and raised his transaction limit to roughly ₹21 lakh before executing three RTGS transfers totalling ₹14.55 lakh in quick succession. The scale and speed of the intrusion, from a single opened file to a fully compromised financial identity within hours, illustrates why cybersecurity researchers continue to flag RTO and traffic-challan-themed APK files as one of the most effective malware delivery formats currently circulating in India.
A Telegram Task Group That Escalated Slowly
The second case followed an entirely different rhythm. Shambhu Nath Gaurav, a Greater Noida West resident, was approached on Telegram with an offer to earn money posting Google Reviews for hotels, a task category that has become almost a signature opening move for this style of fraud nationally. He was gradually drawn into a larger group structured around coordinators and task managers, eventually being asked to complete twenty-one tasks tied to welfare and investment activities.
The platform initially displayed genuine-looking profits, encouraging Gaurav to deposit progressively larger sums, a pattern that mirrors cases documented elsewhere in India, including one in which a Pune tax consultant lost ₹2.72 crore through an almost identical Telegram review-task structure. When Gaurav eventually attempted to withdraw his funds, the withdrawal was blocked, and the fraudsters demanded further payments to release the money and complete remaining tasks, ultimately extracting ₹7.02 lakh before he recognised the scheme for what it was.
The third case, involving Sector 34 resident Shashi Sehgal, differs from the other two in that the fraud’s initial vector remains less clear. She received two suspicious messages on her phone on April 19, after which ₹4 lakh and then ₹3.49 lakh were debited from her IndusInd Bank account in quick succession, together totalling ₹7.49 lakh. Police are now working backwards from the beneficiary accounts to establish how access was initially obtained.
A Pattern That Has Outgrown Isolated Warnings
Taken together, the three Noida cases underscore a broader shift in how cybercrime is scaling across urban India, no longer as isolated, opportunistic scams but as parallel, professionalised operations each targeting a different point of vulnerability, whether technical, financial or psychological. Task-based Telegram frauds in particular have proliferated rapidly over the past year, with cases ranging from a few lakh rupees, as in Sehgal and Gaurav’s situations, to losses running into crores for victims drawn in over longer periods, a variance that reflects how the same basic script can be scaled up almost indefinitely depending on how long a victim remains engaged.
Investigators in all three Noida cases are now examining whether the beneficiary accounts share any connections, a question that could determine whether the incidents represent isolated fraud attempts or components of a single, coordinated syndicate operating across the National Capital Region.
