Jaipur: A sophisticated cyber fraud has come to light in Rajasthan, where a gang allegedly used the identity, photograph and previous WhatsApp conversations of a company director to trick an employee into transferring ₹6.80 crore.
The employee, who worked in the accounts department of a Jaipur-based company, followed instructions sent by what he believed was his senior and transferred the money to three different bank accounts. It was only later that he discovered that the messages had been sent by cyber fraudsters impersonating his boss.
According to the cybercrime investigation, the gang gained access to the employee’s computer through WhatsApp Web, which was already logged in on the device. The accused allegedly accessed the contact list and copied the company director’s name and profile photograph. They then removed the genuine director’s number and replaced it with their own number while retaining the same name and photograph. This allowed them to create an appearance of an authentic communication channel.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
The accused allegedly went a step further by cloning the existing WhatsApp conversation between the company director and the head of accounts. The employee therefore had little reason to suspect that the instructions were fraudulent. Acting on the message, he transferred ₹6.80 crore to three accounts.
After discovering the fraud, the victim immediately contacted the cybercrime helpline 1930 and the cybercrime police. The quick response helped investigators place a hold on around ₹3.50 crore in different bank accounts before the money could be completely siphoned off.
As the investigation progressed, eight members of the alleged gang were arrested in separate operations carried out on September 2, 3 and 4. Investigators found that several of the accused were well educated. The group allegedly included unemployed men with BTech and BSc degrees, a second-year physiotherapy student and another person pursuing BSc Nursing. A businessman operating in Punjab was also allegedly involved.
Brijmohan Dron, alias Lucky, a resident of Bhadwa village in Jaipur’s Renwal area, is a BSc graduate. Investigators allege that his role went beyond arranging bank accounts. He was allegedly responsible for moving and disposing of the proceeds of the fraud. Once the money entered an account, it was allegedly transferred through multiple accounts before being converted into cryptocurrency, including USDT.
The investigation further alleges that Dron remained in contact with overseas members of the gang through Telegram. He allegedly monitored the movement of the money, tracked successive transfers and helped coordinate its conversion into digital currency. The USDT was then allegedly sent to online cryptocurrency accounts specified by fraudsters operating from abroad.
Another accused, Sandeep, originally from Bana village in Haryana’s Adampur area, is an MA graduate. According to investigators, he was associated with a company whose bank account received around ₹2 crore of the allegedly defrauded money. He had reportedly opened a new corporate bank account around 15 days before the incident.
Investigators allege that members of the gang called Sandeep to Reengus in Jaipur and arranged accommodation for him at a hotel. In return for a commission, he allegedly allowed the gang to use the corporate account. He is accused of handing over the account’s cheque book, ATM card, Aadhaar card, PAN card and the SIM card linked to the account.
The investigation has revealed that the money initially transferred by the company’s accounts department to three beneficiary accounts was subsequently routed through more than 250 bank accounts. Several of these accounts were allegedly used as mule accounts to layer and move the proceeds.
Investigators also suspect that members operating from Singapore and Hong Kong transferred the money between different accounts using internet banking. Authorities are now examining the complete chain of bank transactions, cryptocurrency transfers and the role of suspected overseas operators.
Cybersecurity experts say the case highlights how criminals are increasingly combining technical manipulation with social engineering. Employees often trust a message simply because it carries a senior executive’s familiar name and photograph. In this case, the alleged fraudsters exploited that trust, making a fake instruction appear to be a genuine order from the company’s top management.
Follow the Centre for Police Technology on LinkedIn to stay updated on the latest developments in policing, cybersecurity, digital forensics, investigations, fraud risk management, and technology-driven public safety.
https://www.linkedin.com/company/policetechnology/