The Uttar Pradesh Anti-Terrorism Squad (ATS) has uncovered an organized cybercrime network involved in the illegal creation and modification of official identification records through unauthorized remote access software. The operation was exposed following a targeted crackdown in Prayagraj, leading to the arrest of key operative Vivek Tripathi and the raid of a Common Service Centre (CSC) in neighboring Pratapgarh district. State investigators are auditing digital footprints, financial transactions, and system access logs to determine the full reach of the fraudulent network across multiple districts in Uttar Pradesh.
Exploitation of Inactive Operator User IDs and Remote Software
Initial findings by the ATS indicate that the network systematically exploited deactivated and inactive operator credentials to gain illegal access to official enrollment and update portals. Following the termination of third-party agency contracts with several financial institutions, a substantial number of operator user credentials remained dormant within administrative systems. Investigators allege that Vivek Tripathi, a former Assistant Regional Project Manager with a private firm, collaborated with technical specialists who claimed to restore system access using software cloning techniques and authentication bypass scripts.
To execute unauthorized modifications without physically visiting authorized enrollment stations, the network relied on commercial remote access software, primarily AnyDesk. This configuration allowed unauthorized operators to log into administrative portals from unverified locations, bypassing established physical and geographical authentication protocols. The syndicate operated on a commercial scale, charging approximately ₹5,000 to re-enable each dormant user credential and levying a fee of ₹150 for every individual record update processed through the illegal interface.
Digital Footprints, Financial Laundering, and Inter-District Reach
During physical searches and digital forensic extractions, ATS officers seized mobile devices containing months of incriminating communication records. Forensic teams recovered detailed WhatsApp chat archives containing AnyDesk connection keys, daily login rosters, digital payment confirmation screenshots, and discussions regarding the manual override of previously rejected enrollment applications. Additionally, investigators secured structured spreadsheets detailing operator identities, assigned system credentials, remote connection parameters, and chronological logs of completed updates.
Financial scrutiny reveals that all illicit proceeds were collected through digital payment channels, including Unified Payments Interface (UPI) handles and dynamic QR code scanners. Law enforcement agencies are analyzing associated bank accounts to track the financial trail, calculate the total revenue generated by the operation, and identify additional accomplices. Preliminary intelligence suggests that the network extended well beyond Prayagraj, maintaining operational ties with fraudulent operators across the districts of Chitrakoot, Ayodhya, Sultanpur, and the broader Varanasi division.
Cybersecurity Advisory and Official Regulatory Safeguards
While application software like AnyDesk serves legitimate technical support functions across corporate environments, cybersecurity authorities emphasize that its misuse poses severe risks to national data infrastructure. Unauthorized remote connections compromise administrative perimeters, allowing malicious actors to alter demographic records or execute identity fraud without direct oversight. State authorities have initiated cross-verification audits between local operator logs and centralized database records to flag any compromised entries generated by the syndicate.
In response to the probe, law enforcement agencies issued a cybersecurity advisory instructing citizens to utilize exclusively verified government enrollment centers for all demographic and biometric updates. Citizens are cautioned never to permit remote screen-sharing access to unverified individuals or share one-time passwords, personal identification numbers, and biometric details with third-party agents. Authorities emphasized that the ATS investigation remains active, with further administrative and legal proceedings expected as forensic evaluations conclude.
