Noida. Cybercriminals allegedly carried out 43 suspicious transactions within just 23 minutes and transferred ₹1.56 crore from the Yes Bank account of RapiPay Fintech Private Limited, a company providing digital financial services. The transactions began at 10:41 am on October 3 and continued until 11:04 am. According to the company, all the transactions were carried out through the mobile application used by one of its field agents. The company suspects that the accused gained unauthorised access to the agent’s mobile phone or the application and used it to transfer the funds. An FIR has been registered at the Cyber Crime Police Station.
Jitin Jaishil Karkares, a resident of Cleo County, filed the complaint on behalf of the company. He told police that RapiPay Fintech provides digital financial services as a business correspondent for banks. The company offers services including cash withdrawal to customers through its field agents and direct business outlets. The company’s Yes Bank account linked to this system was allegedly targeted by cybercriminals.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
According to the complaint, the first suspicious transaction from the company’s account took place at 10:41 am on October 3. Over the next 23 minutes, a total of 43 transactions were carried out one after another. Through these transactions, ₹1.56 crore was transferred to different bank accounts. After the incident came to light, the company collected details of all the suspicious transactions and provided them to the police for investigation.
The company has provided investigators with the account numbers of the beneficiaries who received the money, their IFSC codes, account holders’ names, RRN details and other banking information. Police are examining these details to trace the movement of the funds and identify the accounts involved. Efforts are also being made to freeze the beneficiary accounts and prevent further withdrawal or transfer of the money.
The DCP Cyber said police are collecting banking records of the accounts to which the funds were transferred, along with linked mobile numbers, UPI IDs and other digital information. Investigators are trying to determine which accounts received the money and whether the funds were subsequently transferred to other accounts. The entire transaction trail and digital channels allegedly used by the cybercriminals are also being examined.
RapiPay Fintech Private Limited was established on April 6, 2009. According to the company, the Reserve Bank of India granted it permission in January 2018 to establish and operate a payment system for semi-closed prepaid payment instrument services. The permission was renewed in March 2024.
The mobile application through which the suspicious transactions were carried out was being used by field agent Dheeraj Kumar Keshari, a resident of Vindhamganj in Sonbhadra. However, the company has not accused the agent of any fraud in its complaint. The company suspects that cybercriminals may have gained unauthorised access to the agent’s mobile phone or application and misused it to conduct the transactions.
Police are now investigating how the accused allegedly gained access to the mobile application and what technical method was used to transfer such a large amount from the company’s account. The investigation will determine whether the security breach occurred through the mobile device, the application, the account or another digital channel.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics