Ahmedabad Police Commissioner Anupam Singh Gahlot has revealed details regarding a high-profile and extensive cybercrime network known as the 'Boss Scam'. The syndicate was operating a massive international network that provided crucial digital infrastructure and services to cybercriminals sitting in Pakistan and China. According to authorities, the individuals involved had been running this illicit operation for the past four to five years. Currently, law enforcement has successfully arrested two suspects from West Bengal, while further comprehensive investigations into the wider network remain ongoing.
Two Arrests Made in West Bengal
The individuals taken into custody have been identified as Imran Ali Piyada and Inzamul. During the operation, police recovered a total of seven mobile phones from the possession of the accused, comprising three Android smartphones and four basic keypad mobile phones. All of these mobile devices had active SIM cards inserted in them. In addition to the phones, authorities also seized a network router used to facilitate the fraudulent communications. Investigators are currently examining these recovered electronic items for further leads.
Call Center Operated from Islamabad
The criminal group was actively supplying necessary infrastructure and operational services to facilitate cyber attacks originating from Pakistan and China. The Police Commissioner stated that the suspects used to purchase local SIM cards and hand them over to individuals operating in foreign countries. They utilized Chinese malware and linked the operations to call centers directly managed from Islamabad. When an unsuspecting victim clicked on a provided malicious link, these perpetrators facilitated unauthorized and illegal money transfers. Investigations have revealed the massive scale of the scam, with 251 formal complaints already registered against this specific group across 26 different states throughout India. Altogether, the syndicate had acquired 4,500 SIM cards specifically for carrying out cyber fraud.
Lucrative Business of Selling OTPs
Further disclosures revealed that the accused were heavily involved in supplying One-Time Passwords to cybercriminals. The Commissioner noted that they have provided approximately 21,000 OTPs to date. In an attempt to evade law enforcement agencies and avoid detection, the operators shifted their primary coordination activities away from Telegram and onto various WhatsApp groups. The accused charged one hundred rupees for each OTP provided. Police investigations have established deep international connections behind the entire racket. Law enforcement agencies found that this criminal gang had linked roughly 10,000 electronic devices, including laptops and mobile phones, directly to their malicious network.
Modus Operandi Targeting Corporate Employees
Detailing how the criminal network executed their elaborate frauds, authorities explained that cybercriminals typically impersonate senior officials from the Reserve Bank of India or other prominent government institutions. They send a malicious ZIP file via WhatsApp or email to a company's chief executive officer, director, or other staff members. These compressed ZIP files contain harmful malware components such as executable files and system library files.
Cloning WhatsApp Profiles to Deceive Staff
Once such a malicious file is executed on a computer or laptop via WhatsApp Web, cybercriminals gain complete unauthorized control over the active WhatsApp Web session. Following this, the perpetrators save their own mobile phone number under the name of the company's CEO or director, setting the exact profile picture to mimic their identity. They then issue urgent instructions via WhatsApp to the accounts and finance department employees, claiming an immediate financial transaction is required. Because the fraudster's number replaces the real boss's contact under the identical name, employees find it extremely difficult to verify the authenticity of the message and end up transferring funds without proper verification. This entire criminal operation relies heavily on fake and dummy SIM cards to secure the required mobile numbers and active WhatsApp accounts.
Role of Accused Imran Ali Piyada
One of the arrested individuals, Imran Ali Piyada, has completed his education up to a Bachelor of Arts degree and was currently working as a Point of Sale agent for major telecom service providers including Airtel, Jio, Vi, and BSNL. The accused misused customers' biometric fingerprints and official telecom provider applications to acquire new SIM cards under innocent customers' names without their knowledge or consent. He then arranged for mobile numbers to be activated on alternative SIM cards for financial gain. These dummy SIM cards were inserted into various mobile phones and activated. The mobile numbers linked to these cards were subsequently provided to individuals involved in cyber fraud.
Substantial Earnings Through OTP Sales
In addition to supporting cyber fraud, the accused also utilized dummy SIM cards for major e-commerce applications such as Amazon and Flipkart, as well as online gaming platforms, selling the corresponding OTPs. Preliminary investigations indicate that over a period of approximately five years, the accused sold roughly 21,000 OTPs for e-commerce and online gaming at an average rate of one hundred rupees per OTP, generating over two million one hundred thousand rupees in illicit income. Furthermore, he sold around 900 OTPs required for activating WhatsApp accounts at an average rate of two hundred and fifty rupees per OTP, earning over two hundred twenty-five thousand rupees.
Involvement of Accused Inzamul
The second arrested suspect, Inzamul, has also studied up to a Bachelor of Arts degree. During the course of the investigation, authorities discovered that this accused was in direct contact with individuals orchestrating the cyber frauds and coordinated actions closely with them. Findings revealed that the suspect actively assisted in managing mobile numbers, dummy SIM cards, and the WhatsApp-based communication infrastructure utilized in executing the financial crimes. He participated directly in coordinating the usage of mobile numbers activated via dummy SIM cards alongside the primary perpetrators of the fraud.
Police Appeal and Warning to Citizens
Concluding the briefing, the Police Commissioner announced that authorities have successfully deactivated all the recovered electronic devices, delivering a major blow to the syndicate's infrastructure. Issuing a stern warning to the general public, Commissioner Anupam Singh Gahlot urged citizens to remain extremely vigilant. He cautioned individuals never to open unfamiliar files or click on unverified links without proper checks, noting that these links serve as the primary tools utilized for executing unauthorized money transfers. Further investigations regarding the broader international module and potential local associates remain actively underway.



















