Ahmedabad 'boss scam' probe uncovers 4,500 SIM cards, links to China, Pakistan

Imran Ali Pyaada, a BA graduate who worked as a sales agent for telecom operators including Airtel, Jio, Vi and BSNL, is one of two men arrested in connection with a Rs 1.5 crore 'boss scam' in Ahmedabad. The investigation has exposed a network that police say supplied infrastructure for cyber fraud to elements in China and Pakistan.
Around 4,500 SIM cards were procured for the operations, police said. The case began in June, when an employee of an Ahmedabad firm transferred Rs 1.5 crore after fraudsters impersonated a senior executive. The cyber crime police recovered Rs 1.3 crore and returned it to the victim.
Pyaada and Injamul Mujibar Molla of Kolkata were arrested from West Bengal. Investigators recovered eight electronic devices, including one capable of operating four SIM cards simultaneously.
The modus operandi began with dummy SIM cards. Pyaada allegedly misused customers' biometric fingerprints and telecom service-provider applications to obtain SIM cards in their names, and activated mobile numbers without the customers' knowledge.
WhatsApp accounts were then activated on those numbers, with the activation OTPs received on the dummy SIMs passed on to people involved in cyber fraud. Investigators described the chain as running from dummy SIM to mobile number to OTP to WhatsApp account to hijack or impersonation.
In the boss scam itself, the accused sent ZIP files to company executives through WhatsApp or email, claiming they contained important official documents. The files carried malicious executables that allowed the accused to take control of the victim's WhatsApp Web session.
The accused then saved their own mobile number under the name of the company's CEO or director and sent urgent payment instructions to employees in finance or accounts departments. Employees, believing the messages came from their superior, transferred funds without independently confirming the instruction.
The network used Chinese-developed malware operated from Hong Kong, and a call centre linked to the network was traced to Islamabad, police said. Bank accounts involved in the fraud were accessed through a China-based VPN service.
Ahmedabad Police Commissioner Anupam Singh Gehlot said the accused had operated for the past four to five years. They provided around 21,000 OTPs to cybercriminals at roughly Rs 100 each, and shifted from Telegram to WhatsApp groups to evade detection.
Police found 251 complaints registered on the National Cybercrime Reporting Portal against mobile numbers linked to the accused, across 26 states. More than 10,000 infected devices connected to the network were deactivated.
The investigation is being expanded in coordination with the Indian Cybercrime Coordination Centre (I4C). Gehlot urged citizens not to open files or click on links without verification, saying such links are the primary tools used for illegal money transfers.
(With inputs from PTI)















