One 18-year-old class 11 dropout from Surat was the mastermind behind a nationwide cyber fraud network using AI, fake mobile apps and encrypted messaging apps to target victims across India, the investigators said. The data show a rise in cybercriminals’ sophistication with technology and technologies.
The accused, Rohit Virendrasinh Shakya, was also charged with building and running the network that allowed cybercriminals to create fake banking and mobile applications that were said to mimic legitimate banking and mobile applications, and to mislead users and deceive them by persuading them to reveal sensitive financial information, including banking credentials, passwords, and one-time passwords (OTPs).
The syndicate employed artificial intelligence extensively in creating phishing tools, fake interfaces, and fraudulent digital services, investigators say. AI tools are said to have helped to create convincing app designs, automated communication templates, and phishing content that closely resembled official banking platforms, making it harder for victims to discern between genuine and fake applications.
The network also relied heavily on Telegram, an encrypted communication platform, to coordinate operations. Private channels and groups were reportedly used to distribute malicious applications, share stolen data, recruit associates, and communicate securely among members of the cybercrime syndicate.
Once victims downloaded the fake applications or connected with fake links, cybercriminals were able to gain access to sensitive banking information and the information of the victims’ bank accounts. The stolen credentials were then used to transfer money from the victims’ bank accounts, and so far there have been reported losses of more than ₹64 crore in multiple states.
Law enforcement agencies say the operation is one of the most advanced cyber fraud cases uncovered in recent years. The defendants provided cybercriminals with ready-made phishing kits, fake banking applications and technical assistance– essentially serving as a service provider for fraudsters instead of targeting victims directly.
The case illustrates the rapidly evolving cybercrime in India. Now that artificial intelligence is more available, cybercriminals are adopting AI technology to improve the effectiveness of phishing attacks, create realistic fake websites and applications, and automate fraudulent activities. This evolution poses new challenges for investigators and cybersecurity professionals working to protect digital users.
Investigators are looking for other members of the network, financial beneficiaries, and victims, they said. Digital devices, servers, communication records and cryptocurrency transactions are being examined to trace the full scope of the operation and discover possible international connections.
Security experts suggest that we should remain vigilant when we download mobile applications such as banking apps. To protect our banking apps, consumers should only install apps from official app stores, verify the developer’s identity, not click on suspicious links that are sent through messaging apps, and never share sensitive banking credentials or OTPs with anyone. Enabling multi-factor authentication and monitoring bank account activity regularly can also help prevent financial fraud.
The case is one more reminder of cybercrime being more sophisticated, as criminals have been using AI and encrypted communication platforms and social engineering to carry out large-scale financial scams. We are seeing digital transactions increase in India, so public awareness, stronger cybersecurity measures, and coordinated law enforcement efforts are key for tackling cyber threats.