CBI busts cross-border tech-support and crypto extortion racket

During an overnight operation between August 5 and 6, 2026, the Central Bureau of Investigation (CBI) busted an international group running fake call centres and offices in Punjab and Delhi. This group targeted Americans with tech-support scams and cryptocurrency extortion. Four people were arrested, including the suspected leader Sourabh Rana and his associates Indermohan Singh, Harneet Singh, and Jappandeep Singh.
CBI teams searched 10 places, including a fake call centre in Mohali linked to the main suspect. They found over 20 mobile phones, 15 laptops and tablets, several hard drives, pen drives, memory cards, a lot of cash, incriminating documents, and cryptocurrency wallets. The agency said the group was highly organised and sent money out of the United States using several crypto wallets before laundering it with contacts in Delhi.
The group used digital tricks and psychological pressure. They sent pop-up alerts to victims’ computers with fake Microsoft toll-free numbers. When people called, they reached the group’s fake centres. The operators pretended to be from Microsoft, banks, or law enforcement. They told victims their computers were at risk and needed urgent repair, then took payments for these fake services.
Sometimes, the scammers made even more serious false claims, such as accusing victims of having child pornography on their computers. Victims were told that illegal material had been planted or that their personal and banking data was at risk. Under this pressure, they were forced to pay ransom in cryptocurrency, often using Bitcoin ATMs. The money was quickly moved through several wallets to hide the trail and send it out of the United States.
Some cases show how much victims lost. In 2022, a woman in Florida was told her personal and financial information had been stolen and that illegal material was on her computer. She sent about USD 440,000 through a Bitcoin ATM, and the money went to wallets linked to the suspects. In 2023, a New Jersey resident paid about USD 130,000 after being told her banking details were at risk. The CBI has found more victims in the United States and is still tracking everyone involved.
This operation shows that Indian cyber-fraud networks have changed and now focus on tricking people in Western countries from a distance. Fake Microsoft pop-ups take advantage of people’s trust in well-known brands, and threats about child pornography create fear and urgency. Using cryptocurrency and ATM deposits makes it harder to track and recover the money. Laundering money through contacts in Delhi also helps hide where the crime started.
Investigators are now looking at digital evidence from the seized devices, such as scripts, victim lists, wallet addresses, and communication records, to learn more about how the network worked and who else was involved. Modern cybercrime crosses borders: the technical setup and call centres were in India, most victims were in the United States, and the stolen money moved quickly between countries.
While arresting Rana and his three associates is a big step, the CBI says the investigation is still ongoing. Finding the crypto wallets and tracking how the money was laundered will help determine the total amount stolen and identify anyone else involved.
For Americans, this case is a strong warning that pop-ups, surprise support calls, and demands for cryptocurrency, especially with threats of criminal charges, are clear signs of organised fraud.
The raids in Punjab and Delhi show how far these groups can reach and that Indian investigators can target their main operations. As digital evidence is reviewed and Indian agencies work with US authorities, the case should reveal more about how tech-support and crypto-extortion scams have grown in recent years.
