Ahmedabad

Ahmedabad Cybercrime Team Uncovers ‘Boss Scam’ Network With China-Pakistan Links; 2 Held In West Bengal

By GS Team
18 Aug 20266 mins read
TukuTouch Logo
Ahmedabad Police arrested two West Bengal men for providing dummy SIMs and WhatsApp accounts to cybercriminals, uncovering a multi-country network spanning China, Pakistan, India, and Hong Kong. This follows a ₹1.50 crore "Boss Scam" on an Ahmedabad businessman. The investigation revealed a "cybercrime-as-a-service" model, with 4,500 SIMs linked and 251 nationwide complaints, suggesting a wide-ranging fraud infrastructure. Police are probing international links and cryptocurrency transfers.

Summarized by AI; it may make mistakes. Check important info

Ahmedabad Cybercrime Team Uncovers ‘Boss Scam’ Network With China-Pakistan Links; 2 Held In West Bengal

The Cyber Cell of the Ahmedabad Crime Branch has arrested two men from West Bengal for allegedly providing dummy SIM cards, mobile numbers and WhatsApp accounts to cyber fraudsters, uncovering a suspected multi-country network linked to cybercrime infrastructure in China, Pakistan, India and Hong Kong, officials said on Tuesday.

The arrests were made during an investigation into a ‘Boss Scam’ in which an Ahmedabad-based businessman was allegedly duped of ₹1.50 crore after cybercriminals impersonated officials and subsequently posed as senior company executives to induce employees to transfer money.

Police identified the arrested accused as Imran Ali Piyada, 25, a resident of South 24 Parganas, West Bengal, and Injamul Molla, 30, a resident of Beniapukur, Kolkata.

According to senior Cyber Cell officials, the investigation began after complainant Pravinbhai Nagjibhai Bawadia reported that on June 23, an unknown person sent a ZIP file to his mobile phone via WhatsApp. The sender allegedly impersonated officials associated with the Reserve Bank of India and claimed that unusual transactions had been detected in the company’s bank account, creating the impression that the account could be restricted or suspended.

Soon afterwards, another person allegedly contacted the company’s accountant through WhatsApp, using a mobile number and the complainant’s name and posing as a member of the company’s Finance Department. The accused allegedly persuaded the employee to transfer ₹1.50 crore through RTGS to a bank account controlled by them on June 24.

The complainant immediately contacted the national cybercrime helpline 1930, following which police were able to recover ₹1.13 crore of the amount lost in the fraud, police said.

How The ‘Boss Scam’ Worked

According to investigators, fraudsters first sent a malicious ZIP file to the target through WhatsApp or email, claiming it contained information relating to banking or regulatory issues.

The ZIP file allegedly contained executable and system-library files such as .exe and .dll. Once such a file was opened on a computer, attackers could potentially gain access to the WhatsApp Web session.

The fraudsters would then allegedly replace or imitate the profile of a company’s CEO or director and send urgent financial instructions to employees.

The victim would receive messages apparently coming from a senior executive asking for an immediate transfer of funds. Investigators said the criminals relied on the victim’s trust in the senior official and the urgency created by the messages, often without allowing sufficient time for independent verification.

The police said the network depended on a supply chain of dummy SIM cards, mobile numbers, OTPs and WhatsApp accounts to facilitate the impersonation.

image.png

SIM Cards Allegedly Issued Using Customers’ Biometrics

Investigators alleged that Imran, a graduate who worked as a telecom service provider through point-of-sale operations for telecom companies, misused the process used for issuing SIM cards.

Police alleged that he used customers’ biometric fingerprints to generate SIM cards in their names and subsequently activated numbers for other purposes without their knowledge. He allegedly obtained dummy SIM cards and inserted them into different handsets before supplying the associated mobile numbers to cybercriminals.

According to police, Imran also provided OTPs required to activate WhatsApp accounts on these numbers.

“The accused provided the digital communication infrastructure required by cybercriminals, from dummy SIM cards and mobile numbers to WhatsApp accounts,” senior police officials said.

Investigators further alleged that Imran sold OTPs not only for WhatsApp activation but also for e-commerce and online gaming platforms.

Police claimed that over the past five years, he had sold approximately 21,000 OTPs for e-commerce and gaming applications at an average of ₹100 each, earning more than ₹21 lakh. He allegedly sold around 900 WhatsApp activation OTPs at an average of ₹250 each, earning another ₹2.25 lakh.

Police said the investigation was continuing to establish the precise number of OTPs supplied to cybercriminals and the total proceeds generated from the activity.

4,500 SIM Cards And 251 Complaints Examined

The investigation widened after police conducted technical analysis of the mobile number allegedly used in the Ahmedabad fraud.

Investigators traced associated SIM cards, devices, additional mobile numbers and IP logs and cross-verified the information to identify the suspects and locate them in West Bengal.

During the investigation, police found references to approximately 4,500 SIM cards inserted into mobile devices associated with the network. The Cyber Crime Branch subsequently analysed 251 complaints registered on the National Cyber Crime Reporting Portal (NCRP) across 26 states.

Of these, police said 194 related to online financial fraud, three to Boss Scam cases, 29 to online and social media-related offences, eight to other cybercrimes and the remaining complaints to offences involving sexually explicit or abusive content and computer-related offences.

Police said the analysis suggested that the network’s infrastructure had been used to facilitate a range of cyber frauds rather than being limited to the Boss Scam.

image.png

Police Suspect China-Pakistan Connection

The Cyber Cell of the Crime Branch is coordinating with the Indian Cyber Crime Coordination Centre (I4C) for technical analysis of the malware and network infrastructure.

According to police, preliminary analysis suggested that the malware used in the fraud was linked to cybercriminal groups operating from China, while a call centre in Islamabad, Pakistan, was allegedly involved in targeting Indian citizens. Investigators also found that some bank accounts involved in the fraud were accessed through a China-based VPN service.

Police said the findings indicated the use of infrastructure spread across several countries to conceal the actual identity and location of those operating the network.

Officials, however, said the international links were part of the ongoing investigation and that further technical and forensic verification would be required to establish the roles of specific individuals and groups.

Around 10,000 Devices Identified

According to the Cyber Crime Branch, coordination with I4C and technical analysis helped identify around 10,000 devices that were potentially infected or exposed to the malware associated with the operation.

Police said steps were subsequently taken to secure the affected devices and block identified malicious infrastructure through appropriate government mechanisms.

Officials described the case as significant because it revealed an organised “cybercrime-as-a-service” model, where individuals did not necessarily participate directly in the final fraud but supplied SIM cards, OTPs, WhatsApp accounts and other digital infrastructure required by larger cybercrime networks.

The investigation has also found that the accused allegedly shifted their activities from Telegram-based networks to WhatsApp groups, where OTPs and other digital services were coordinated.

Police said they were examining whether the money generated through the network was converted into USDT or other cryptocurrency and moved outside the country.

Seven Phones, Router Seized

Police seized seven mobile phones, including Android handsets and keypad phones, as well as an Airtel router. The seized articles were valued at around ₹19,500.

Police are analysing WhatsApp chats, groups, mobile numbers, OTP transactions and other digital evidence to identify the principal operators of the cyber fraud network and determine whether the two arrested men were connected to additional cases.

image.png

The police said at least three victims from Gujarat had so far been identified in the investigation, while analysis of NCRP complaints indicated a much wider national footprint.

Commissioner of Police Anupam Singh Gehlot said the investigation would be expanded in coordination with telecom service providers and other agencies to identify the source of the SIM cards, trace the wider network and determine how the proceeds of the fraud were transferred.