The Ahmedabad City Police have dismantled a sophisticated multinational cybercrime network involving China, Pakistan, Hong Kong, and India. The gang utilized a 'Cybercrime as a Service' model to defraud thousands of users.
- Ahmedabad Police arrested two West Bengal residents providing 'Cybercrime as a Service' (CaaS) to global syndicates.
- The network spanned China, India, Pakistan, and Hong Kong to mask criminal identities.
- Over 21,000 OTPs were sold for e-commerce and gaming, generating millions in illicit profits.
- More than 10,000 infected devices were identified and secured during the operation.
The Ahmedabad City Police announced on Tuesday the successful dismantling of a multinational 'Boss Scam' network. This highly organized criminal syndicate operated by impersonating company directors and senior executives to trick employees into transferring massive sums of money. Two suspects from West Bengal, identified as Imran Ali Piyada and Injammul, were apprehended and brought to Gujarat via transit warrants.
According to official police reports, the duo provided 'Cybercrime as a Service' (CaaS) to a much larger multinational network. They acted as the digital backbone for fraudsters by supplying dummy SIM cards, mobile numbers, OTPs, and hijacked WhatsApp accounts. Piyada, a former telecom agent, allegedly exploited customers' biometric data to procure unauthorized SIM cards, which were then used to facilitate large-scale digital fraud.
Why This Matters
BozokMedia analysis shows that the evolution of the 'CaaS' model represents a terrifying shift in the criminal landscape. By decoupling the technical infrastructure (SIMs, OTPs, Malware) from the actual fraud execution, criminal syndicates can operate with unprecedented anonymity and scale, making traditional law enforcement tracking significantly harder.
The suspects weren't just selling SIM cards; they were providing the essential digital identity required to execute high-stakes corporate espionage and fraud.
The scale of the operation is staggering. Investigation into the suspects' devices revealed approximately 4,500 SIM cards. This led the Cyber Crime Branch to analyze 251 National Cyber Crime Reporting Portal (NCRP) complaints across 26 Indian states. The crimes included 194 financial frauds, multiple 'Boss Scams', and various cases of hacking and sexually explicit content. Piyada reportedly sold 21,000 OTPs for e-commerce and gaming, netting over ₹21,00,000 in commissions.
Technical forensics suggest a deep-rooted international connection. The malware utilized in these attacks is suspected to have originated in China, while the command-and-control operations were linked to a call center in Islamabad, Pakistan. To evade detection, the criminals utilized a complex infrastructure involving China-based VPN services and digital footprints spread across Hong Kong and India.
| Scam Type | Methodology | Primary Target |
|---|---|---|
| Boss Scam | Impersonating CEO via WhatsApp/Email | Corporate Employees |
| CaaS Model | Selling OTPs, SIMs, and Malware | Cyber Criminal Networks |
How the 'Boss Scam' Operates
In a 'Boss Scam', criminals masquerade as high-ranking officials, such as an RBI officer or a company CEO. They send a malicious ZIP file to a target via WhatsApp or email. This file contains executable files (like .exe or .dll) that, once opened, grant the attacker control over the victim's WhatsApp Web session. The attacker then uses the victim's identity to authorize fraudulent financial transactions.
Frequently Asked Questions
1. How can I identify a 'Boss Scam' attempt?
Be extremely cautious of any unsolicited ZIP files or attachments from 'senior officials' on WhatsApp. Always verify such requests through a direct phone call or official corporate channels.
2. What should I do if my device is infected?
Immediately disconnect from the internet, change all your financial and social media passwords from a different device, and report the incident to the national cybercrime portal.