Crime Bengaluru

Three arrested in Rs 94 lakh Bengaluru cyber fraud case

Bengaluru cyber police have arrested three men in an alleged online trading and investment fraud in which a Peenya resident said he was made to transfer Rs 93,58,555. The complaint was filed on May 28, and the probe uncovered 507 mule bank accounts. Amit Mishra, Parashuram Sadanand Kannanavar and Tausif Ahmed were arrested on September 8 and 9. Police said fake apps captured OTPs and funds moved to a Binance crypto wallet, with IP addresses traced to Kolkata, Hong Kong and California.

Source

Indian Express — Cities · read the original report ↗

#cyber fraud#bengaluru police#mule accounts#online scam#arrests

Desk check · compared with the source

What the desk checked (5)
  • A Peenya resident was made to transfer Rs 93,58,555 in an online trading and investment fraud, complaint filed May 28. — Figure and date appear in source, based on the complainant's claim as reported by police.
  • Three men — Amit Mishra, Parashuram Sadanand Kannanavar and Tausif Ahmed — were arrested on September 8 and 9. — Attributed to unnamed police officers quoted in the source.
  • The probe found 507 mule bank accounts procured and supplied to the network. — Figure appears in source, attributed to the investigation.
  • Fake apps 'ZNPAY' and SMS-forwarding APKs intercepted OTPs; money moved to a Binance crypto wallet; mule account holders paid Rs 1.5-2 lakh. — Attributed to a police officer's statement; app functionality sent to I4C for analysis, so unverified technically.
  • Digital forensics showed IP addresses linked to Kolkata, Hong Kong and California. — Described in source as preliminary findings pending verification with service providers.

Analysts’ view opinion

AI Legal Analyst

What began as a single complaint has widened into a network of 507 alleged mule accounts, which legally turns this from a straightforward cheating case into a layered one touching IT Act offences around OTP interception and malicious apps, and potentially money-laundering questions. The routing of funds to a crypto wallet and IP trails to Kolkata, Hong Kong and California push the investigation into territory that usually needs cross-border cooperation and formal data requests to service providers. The most delicate legal question is the status of the mule account holders — victims lured by commissions, or knowing participants.

  • Three arrests are allegations, not findings of guilt; culpability will be tested in court, not settled by the investigation's narrative.
  • The account holders allegedly handed over accounts, net banking credentials and SIMs for a commission — whether that amounts to knowing complicity or being duped is the pivotal question of intent.
  • OTP and SMS interception through fake apps takes this beyond ordinary fraud into technical offences, where digital evidence must be seized and certified properly to survive scrutiny at trial.
  • Foreign IP addresses and a crypto wallet mean evidence gathering may depend on cooperation from overseas platforms and lawful requests, typically a slow process.
  • With a fourth suspect and Telegram handles untraced, the prosecution may proceed in stages, with supplementary chargesheets as more roles are established.

What to watch — Watch for whether the chargesheet is filed within the statutory period, how courts treat bail pleas, and whether mule account holders are named as accused or treated as witnesses.

The story does not establish which specific provisions have been invoked, how much of the complainant's money was frozen or recovered, or what the accused say in their defence.

Deep dive

Research brief · 8 facts · 5 dates · exam-ready

The brief

Context

Bengaluru's cyber police have cracked part of an alleged online trading and investment fraud in which a resident of Peenya said he was made to transfer nearly Rs 94 lakh to multiple bank accounts. The investigation exposed a network that procured hundreds of "mule" bank accounts — current, corporate and trust accounts — with net banking credentials and SIM cards, and used fake apps to intercept banking OTPs. Money was allegedly routed through layers of accounts into a Binance crypto wallet, with digital trails pointing to Kolkata, Hong Kong and California. Three men have been arrested; a fourth suspect and several Telegram-handle operators remain untraced.

Key facts

  • A Peenya resident filed a complaint on May 28 this year, saying he was forced to transfer Rs 93,58,555 to multiple bank accounts.
  • The probe revealed details connected to 507 bank accounts allegedly procured from individuals and supplied to the cyber fraud network.
  • About Rs 13 lakh in fraud proceeds moved through a government-owned bank account; over Rs 38 lakh passed through one private bank current account.
  • Amit Mishra, a resident of East Singhbhum district in Jharkhand, was tracked for nearly two months and arrested from a Bengaluru hotel on September 8.
  • Tausif Ahmed and Parashuram Sadanand Kannanavar, alias Pavan Kumar, both living in Bengaluru, were arrested on September 9; six mobile phones were recovered from the three accused.
  • Fake apps described as 'ZNPAY' and SMS-forwarding APKs intercepted banking OTPs and SMS alerts and forwarded them to fraudsters.
  • Mule account owners were paid Rs 1.5 lakh to Rs 2 lakh and were not allowed to leave the hotel in Kachuvanahalli during transactions.
  • Details of the fake apps and 51 other suspicious APK files were sent to the Indian Cybercrime Coordination Centre (I4C) for technical analysis.

Timeline

  1. May 28, this yearA Peenya resident files a complaint alleging he was forced to transfer Rs 93,58,555 in an online trading and investment fraud.
  2. Roughly two months before the arrestPolice, with almost no leads, trace a recovered mobile phone to a building in Lucknow and begin tracking Amit Mishra.
  3. September 8Mishra arrives in Bengaluru and is arrested from his hotel; technical analysis of his devices identifies Tausif Ahmed and Kannanavar as partners.
  4. September 9Tausif Ahmed and Parashuram Sadanand Kannanavar are arrested in Bengaluru.
  5. OngoingVerification with service providers on IP addresses in Kolkata, Hong Kong and California; a fourth suspect, Anoop alias Julpi, and Telegram handle operators remain untraced.

Who has a stake

  • Complainant, a Peenya resident — Lost Rs 93,58,555 allegedly transferred to multiple accounts; recovery depends on tracing funds routed into a crypto wallet.
  • Bengaluru cyber police — Investigating roles of each accused, tracing absconding suspects and cross-border digital trails.
  • Arrested accused: Amit Mishra, Parashuram Sadanand Kannanavar (alias Pavan Kumar), Tausif Ahmed — Face prosecution for allegedly operating the account-procurement and fund-routing network.
  • Mule account holders (current, corporate and trust account owners) — Lured with promises of huge donations and paid Rs 1.5-2 lakh; their accounts and OTPs were used to funnel fraud proceeds.
  • Banks (one government-owned, one private) — Rs 13 lakh and over Rs 38 lakh respectively moved through their accounts, raising account-monitoring questions.
  • Indian Cybercrime Coordination Centre (I4C) — Tasked with technical analysis of the fake apps and 51 other suspicious APK files.
  • Untraced suspects — Anoop alias Julpi and operators of Telegram handles '@zhangxueyou123' and '@SZNKM' are yet to be identified and located.

Why it matters

The case shows how investment-fraud proceeds are laundered at scale through hundreds of mule accounts, OTP-stealing APK files and crypto wallets, making recovery and attribution extremely hard. The use of trust and corporate current accounts, commissions to account suppliers, and IP infrastructure abroad suggests an organised, cross-border operation rather than isolated cheating. It also highlights the enforcement burden on state cyber police and central agencies such as I4C.

UPSC angle

Prelims pointers

  • Complaint filed May 28; alleged loss Rs 93,58,555 in an online trading and investment fraud in Bengaluru.
  • Probe uncovered 507 mule bank accounts supplied to the fraud network.
  • Arrests: Amit Mishra (Sept 8), Tausif Ahmed and Parashuram Sadanand Kannanavar alias Pavan Kumar (Sept 9).
  • Fake apps named 'ZNPAY' plus SMS-forwarding APKs were used to intercept banking OTPs and SMS alerts.
  • Funds were routed through multiple accounts to a Binance crypto wallet; mule account owners paid Rs 1.5-2 lakh.
  • 51 suspicious APK files sent to the Indian Cybercrime Coordination Centre (I4C); IP trails to Kolkata, Hong Kong and California.

Mains framing

The Bengaluru case illustrates the industrial architecture of contemporary cyber financial crime: a victim lured into an online trading and investment scheme loses Rs 93.58 lakh, but the theft is only the entry point to a laundering chain built on 507 procured bank accounts, commission-paid account suppliers, fake apps such as 'ZNPAY' and SMS-forwarding APKs that hijack OTPs, and conversion into a Binance crypto wallet. Causes include the easy monetisation of dormant current, corporate and trust accounts, weak transaction-monitoring at banks — Rs 13 lakh flowed through one government-owned bank account and over Rs 38 lakh through a single private bank current account — and encrypted coordination on Telegram, Botim and WhatsApp with IP infrastructure in Kolkata, Hong Kong and California. Implications run from victim non-recovery to cross-border jurisdictional gridlock, since key suspects and handles remain untraced. The way forward suggested by the source itself lies in technical capability and coordination: forensic analysis of the 51 suspicious APK files by the I4C, verification with service providers, and mapping each associate's role — with account-holder awareness essential, since those hosted in hotels and paid Rs 1.5-2 lakh became both instruments and potential accused in the chain.

Key terms

Mule bank account
An account procured from another person, with net banking credentials and SIM, used to receive and re-route fraud proceeds for a commission.
APK file
An Android application package; here, fake apps and SMS-forwarding APKs installed on phones to intercept OTPs and bank alerts.
ZNPAY
The fraudulent platform/app named in the probe, linked to several associates and to accused Amit Mishra.
I4C (Indian Cybercrime Coordination Centre)
Central body to which the fake apps and 51 other suspicious APK files were sent for technical analysis of functionality and usage.
Binance crypto wallet
The cryptocurrency wallet to which money was allegedly moved after passing through multiple mule accounts.
OTP interception
Capturing one-time passwords sent to linked SIM cards, enabling fraudsters to remotely operate victims' or mules' bank accounts.

Practice questions

  1. How do mule bank accounts and OTP-intercepting applications enable large-scale online investment fraud? Discuss with reference to the Bengaluru case involving 507 accounts.
  2. Cross-border IP infrastructure and cryptocurrency wallets complicate cyber-fraud investigations. Examine the institutional mechanisms available in India, including the role of the I4C.
  3. Should holders of trust and corporate accounts who rent out their accounts for commissions be treated as victims or accomplices? Argue with reference to the facts of this case.

Grounded only in the source report — figures and dates are the source's, not inferred.

Next storyEnvironmental side won no NGT merits appeals in six months: Report →
← All stories