Ahmedabad

Ahmedabad's Thaltej Recharge Company Hacked: 496 Unauthorized Transactions Drain ₹17.45 Lakh from Wallet

By GS Team
10 Oct 20262 mins read
TukuTouch Logo
Ahmedabad's UPS Solutions Pvt Ltd faced a cyber fraud, losing ₹17.45 lakh from 496 unauthorized mobile recharges. Fraudsters allegedly obtained admin panel credentials and OTPs to access the company's wallet. The incident, discovered during a financial review, prompted a police investigation under BNS and IT Act. Cyber experts are probing how the system was breached and funds diverted, impacting this international online recharge business.

Summarized by AI; it may make mistakes. Check important info

Ahmedabad's Thaltej Recharge Company Hacked: 496 Unauthorized Transactions Drain ₹17.45 Lakh from Wallet

An online mobile recharge company in Ahmedabad suffered a cyber fraud in which 496 unauthorised recharges worth ₹17.45 lakh were made from its wallet after its admin panel credentials and OTP were allegedly obtained by fraudsters.

The incident came to light on May 5, 2026, when the company's partners were reviewing financial transactions and found that payments for several recharges had not been credited to the company's bank account.

Shahid Allarakha Mir, who runs UPS Solutions Pvt Ltd at Milestone Commercial Complex on Drive-In Cinema Road in Thaltej, lodged a complaint with the Cyber Crime Police Station. Police have registered a case under various provisions of the Bharatiya Nyaya Sanhita (BNS) and the Information Technology Act and launched an investigation.

496 Unauthorized Recharges Detected During Account Check

Mir, a resident of Juhapura, operates the online recharge business with his partner, Sohel Abdulqadir Bharmal. The company provides mobile and direct-to-home (DTH) recharge services to distributors, retail dealers and API users through its website and application.

Under the company's system, users make recharges and deposit the corresponding amount into the company's bank account.

During a review of financial records on May 5, the partners noticed discrepancies between the recharges made through the company's wallet and the payments received. A detailed examination revealed that 496 transactions had been carried out outside the company's registered dealer network, resulting in recharges worth ₹17,45,201.

The partners contacted the software developer to investigate the irregularities. The developer confirmed that an unidentified person had allegedly logged into the system illegally and carried out the recharges.

The company subsequently approached the Cyber Crime Police Station to report the suspected fraud.

How Were the Admin Credentials and OTP Obtained?

According to the complaint, the fraud involved the company's admin panel user ID, password and one-time password (OTP), which were allegedly obtained by the accused to access the wallet and carry out unauthorized recharges.

The money generated through these transactions was allegedly transferred to the accused's bank account, causing a loss to the company.

Under the company's login procedure, an OTP is sent to the user's registered mobile number through software provided by Infinity Solutions when logging in for the first time.

Investigators are examining how the accused obtained the admin panel credentials and OTP, and whether they exploited a technical vulnerability to bypass the security system. Cyber experts are assisting in the investigation to establish how the system was accessed and how the fraudulent transactions were executed.