IndiaFocal.

India, in focus.

National

Cyber Command arrests three in ₹93.58 lakh online trading fraud, 507 mule accounts frozen

Three arrests and 507 frozen bank accounts have emerged from a probe into an online trading and investment fraud of ₹93.58 lakh.

Investigators probing an online trading and investment fraud of ₹93.58 lakh have arrested three people and frozen 507 bank accounts allegedly procured and supplied to cyber fraudsters, the Cyber Command said.

The case was registered on April 29, 2026, after a complainant, Harish Kumar K. N., was allegedly induced to transfer ₹93,58,555 to multiple bank accounts.

The prime accused, Amit Mishra, was arrested on September 8. His questioning brought to light the alleged involvement of Tausif Ahmed and Parashuram Sadanand Kannanavar, also known as Pavan Kumar, and both were subsequently arrested.

Mule accounts and OTP forwarding

According to the investigation, the accused allegedly obtained current, corporate and other bank accounts, along with net-banking credentials and linked SIM cards, from account holders in exchange for commissions. The account holders were allegedly lodged in hotels, where ZNPAY and SMS-forwarding APK files were installed to relay banking OTPs and text messages to cyber fraudsters.

The arrangement allegedly let the fraudsters operate the accounts remotely and move the proceeds of cybercrime, with account holders, the accused and other intermediaries said to have received commissions in return.

Examination of the seized phones is said to have revealed details of 507 bank accounts collected from various people and passed on to cyber fraudsters. In this case, about ₹13 lakh of suspected fraud proceeds moved through a nationalised bank account, while more than ₹38 lakh was routed through a current account at a private bank.

Six mobile phones were seized from the three accused. Technical details of the ZNPAY and SMS-forwarding APK, along with 51 other APK files, have been sent to the Indian Cybercrime Coordination Centre (I4C) for analysis.

Transnational trail

The digital investigation identified Telegram and WhatsApp accounts allegedly used by the accused and by other fraudsters who remain at large. Preliminary IP and geolocation analysis pointed to network locations linked to Kolkata, Hong Kong and California in the United States, and police said these are being verified through service-provider records and other technical evidence.

Investigators are now examining KYC details, bank statements, the money trail, cybercrime complaint linkages for the 507 accounts, linked SIM cards, the APK infrastructure, WhatsApp and Telegram communications, IP logs, intermediaries and the ultimate beneficiaries.

The people operating the identified Telegram IDs are yet to be traced. The probe has also indicated alleged links between the arrested accused and several other accused, whose roles and extent of involvement are still being investigated.