Fake RTO e-challan case: Gujarat Police nab Jamtara gang aide handling fraud proceeds

Surat, Aug 13 (IANS) The Surat City Cyber Crime Cell in Gujarat has arrested an alleged associate of a Jamtara-based cyber fraud gang who, according to police, handled money siphoned from victims through mule bank accounts and converted the proceeds into cash before routing them back to other members of the network.

The accused, identified as 26-year-old Sitaram Mandal, a welding shop worker from Bisanpur village in Giridih district of Jharkhand, was taken into custody from Sabarmati Jail in Ahmedabad, where he was already lodged.

He was subsequently produced before a court and police obtained his two-day custody remand.

The arrest followed an investigation into a complaint in which a Surat resident’s son allegedly lost Rs 5,02,562 after downloading a fake RTO E-Challan APK file sent through WhatsApp.

Police said the incident began on November 20, 2025, when an unknown WhatsApp number sent the malicious APK file to the phone of the victim’s friend, Rakesh Sharma.

The compromised account was then used to circulate the file in a WhatsApp group involving the victim’s son’s friends.

After the victim downloaded the file, his phone was allegedly compromised without his knowledge, and Rs 5,02,562 was transferred from his bank account in multiple transactions.

The complainant contacted the national cybercrime helpline immediately after discovering the fraud and later approached the Surat Cyber Crime Cell on December 14, 2025.

A case was registered at the Cyber Crime Police Station under Sections 318(4), 336(2), 338, 336(3), 340(2), 61(2) and 3(5) of the Bharatiya Nyaya Sanhita, 2023, and Sections 66(C) and 66(D) of the Information Technology Act, 2008.

Police said a technical investigation, including scrutiny of banking transactions, led them to Mandal, who was found to be in Sabarmati Jail.

Investigators alleged that Rs 1,47,954 from the complainant’s son’s account had been used for a credit bill payment arranged through an earlier arrested accused, Nishit Nathwani.

According to police, Nathwani retained a commission of 15 to 20 per cent and deposited the remaining cash through a cash deposit machine into Mandal’s bank account.

Mandal allegedly deducted a further 5 to 10 per cent commission before handing over the remaining cash to absconding members of the Jamtara gang in Jharkhand.

Police also found that Rs 2.72 lakh linked to cyber fraud involving this and other victims had been deposited through CDM transactions into Mandal’s Axis Bank account between November 21 and December 18, 2025.

The account recorded credit transactions totalling Rs 15,87,400 between September 19, 2025 and January 8, 2026. Police said Mandal has a previous criminal record, including an FIR registered in Giridih district in 2017 under cheating, forgery and Information Technology Act provisions.

He is also named in five Ahmedabad City Cyber Crime Police Station cases registered in 2026 involving cheating, impersonation, conspiracy and offences under the IT Act.

The investigation has found that the gang used malicious APK files designed to resemble legitimate applications or services.

According to police, once a victim clicked on and installed the file, the application sought administrative permissions that could allow access to SMS messages, contacts, call logs and photographs.

The gang allegedly used genuine-looking bank names, logos and icons to persuade victims to enter banking and KYC information.

Once access to banking details was obtained, money was transferred from the victim’s bank or payment applications to mule accounts or credit cards.

The proceeds were subsequently withdrawn or converted into cash and deposited through CDMs into accounts controlled by other members of the network, according to investigators.

Police said five accused had already been arrested in connection with the case before Mandal’s arrest.

The Cyber Crime Cell has urged people not to download APK files received from unknown sources, even when they appear to relate to RTO challans, banks, KYC updates, customer support, government schemes, appointment bookings or other familiar services.

It also advised people not to click on suspicious links received through SMS or email.

–IANS

mys/dpb

Comments are closed.