Pune police book an employee accused of diverting ₹2.45 crore from his company using forged invoices, fake vouchers and spoofed internal emails.

Pune Employee Booked for ₹2.45 Crore Fake Invoice, Email Fraud

The420 Web Correspondent
5 Min Read

A private company in Pune’s Balewadi area has approached police alleging that one of its own employees quietly siphoned off approximately ₹2.45 crore over roughly two years by manipulating the firm’s internal payment systems, using forged vouchers, fake reimbursement claims and lookalike email accounts to make fraudulent transfers appear routine. A case has been registered against the accused under provisions relating to criminal breach of trust, cheating and forgery, and investigators are now working to reconstruct the full financial trail.

An Insider With Access to the Payment Chain

The complaint was filed by company representative Yogesh Suresh Deepankar, naming Kaustubh Shivkumar Vibhute, 34, a resident of Mundhwa, as the accused. Police allege that between June 2024 and July 2026, Vibhute exploited his position within the company’s financial processes to generate a steady stream of fraudulent payments, causing losses that eventually ran into crores of rupees.

Investigators say Vibhute’s method centred on a simple but effective manipulation: altering the bank account details of genuine suppliers listed in the company’s payment records, so that funds approved for legitimate vendors were instead routed into an account he controlled. Because the underlying invoices and reimbursement claims otherwise appeared normal, the diversions reportedly went unnoticed for an extended period.

Police further allege that Vibhute created email addresses closely resembling the company’s official domain, a tactic that allowed him to issue payment instructions that looked as though they came from legitimate internal channels. This closely mirrors the pattern of Business Email Compromise, or BEC, a fraud technique increasingly seen in Indian corporate fraud cases, where a look-alike or spoofed email is used to authorise a payment or change banking details without raising immediate suspicion among approvers. Investigators believe multiple payments were processed this way before the scheme was detected.

How the Fraud Came to Light

The alleged manipulation surfaced during the company’s internal financial audit and reconciliation of payment records, when irregularities in several transactions caught the attention of the finance team. A closer review of banking records, payment instructions and email correspondence reportedly confirmed the pattern of diversion, prompting the company to approach the police with a formal complaint rather than resolve the matter internally.

Investigators are now examining the accused’s bank accounts, computers, mobile devices, email logs and payment records to establish the complete money trail, and are also probing whether any other employee, external associate or service provider may have assisted in the scheme, or whether Vibhute acted alone. Tracing where the diverted ₹2.45 crore ultimately went, whether into further bank accounts, investments or assets, remains a key part of the ongoing investigation.

A Growing Category of Corporate Fraud

Financial crime experts say cases like this reflect a broader shift in how internal fraud is now being carried out in Indian companies. Business email compromise, fake invoices and unauthorised changes to supplier banking details have become increasingly common precisely because they exploit routine administrative trust rather than requiring any external hacking, making them harder to detect through conventional cybersecurity tools alone.

Renowned cybercrime expert and former IPS officer Prof. Triveni Singh said such offences are no longer limited to forged paperwork but increasingly blend cyber techniques, identity impersonation and exploitation of weaknesses in banking and payment workflows. He advised organisations to adopt multi-factor verification for every high-value transaction, independently confirm any change in a supplier’s beneficiary bank account before releasing payment, deploy AI-based fraud monitoring systems, and conduct regular cybersecurity audits alongside continuous staff training. Early detection of anomalous transactions, he said, remains the single most effective defence against losses escalating into the kind of scale seen in the Balewadi case.

Stay Connected