Amidst the growing trend of digital banking and instant loan apps, cyber criminals have discovered a very dangerous and technologically advanced way to defraud common citizens. Cyber Crime Police has busted an inter-state gang which hacked the mobile phones of hundreds of people on the pretext of giving them instant loans on easy terms and without any paperwork and siphoned off a huge amount of around ₹3.76 crore from their accounts. The network of this gang, which targeted citizens of many cities including Delhi, Noida, Lucknow, Gurugram, Jaipur and Mumbai, was spread in different states of the country. On the basis of technical surveillance and bank trail, the police have arrested many members of the gang including the main leaders, from whom dozens of smartphones, SIM cards, laptops and fake bank passbooks have been recovered. Dangerous game of phone hacking: Remote access in one click. The working method of this gang was very vicious. The criminals used to lure people with personal loans ranging from ₹5 lakh to ₹10 lakh at very low interest rates through social media advertisements, WhatsApp and Telegram messages. As soon as a needy person contacted the given link, the fraudsters would send him to download an APK file in the name of 'loan approval form' or 'verification app'. This file was not a legitimate app, but a dangerous Trojan malware. As soon as the user installed this app on his phone, he unknowingly gave it permission to read SMS, view contacts and screen recording. After this, the entire remote control of the user's phone went to the hackers' servers. Whenever a one time password (OTP) came from a bank or payment app, it would reach the hackers even before it appeared on the victim's screen. Through this, all the deposits were withdrawn from the victim's bank account through net banking and UPI. Commission game: This is how money was transferred in more than 200 mule accounts. According to the investigating officers, a complex maze of 'Money Mule Accounts' was created to keep the defrauded amount from the grip of law enforcement agencies. Instead of keeping the stolen ₹3.76 crore in a single account, it was divided into dozens of different layers (layering): Layer 1 (Primary Accounts): The money stolen from the victim's account was first transferred to fake or rented bank accounts opened in the names of daily wage workers, students or poor people. Layer 2 (commission sharing): The money from these accounts was immediately transferred to 10 to 15 other smaller accounts. Cash withdrawals were done by paying a 'commission' of 2 to 5 percent of the total amount to the account holders. Layer 3 (Crypto and Hawala): In the final stage, this money was sent to the main leaders sitting abroad by withdrawing cash from ATMs in different cities or converting it into cryptocurrency (USDT) through P2P platforms. Due to this fast digital transfer of money, by the time the victim lodged a complaint with the cyber cell, the money had passed through five to six bank accounts and was out of the system. Police raid: Secret revealed through technical investigation and digital forensics A special task force was formed to analyze the IP addresses, bank transaction logs and mobile IMEI numbers of dozens of complaints lodged in the cyber police station. The technical surveillance team of the police matched the ATM withdrawal CCTV footage and mobile locations of the suspected bank accounts. After this, active members of the gang were nabbed by simultaneous raids at different locations in Jharkhand, West Bengal, Delhi-NCR and Rajasthan. During interrogation, the accused revealed that they used to purchase data from the dark web to specifically target people who were recently in financial crisis or who had searched for loans on Google. Necessary precautions to avoid loan fraud and hacking: After this big revelation, cyber experts have advised smartphone users to adopt some very important security rules: Never install unknown APK files: Never download or open any file (especially with .apk extension) sent by any unknown person on WhatsApp or SMS. Download verified apps only from Google Play Store or Apple App Store. Check for RBI Registered Loan Providers: Before taking a loan from any digital loan app, ensure that it is an authorized bank or non-banking financial company (NBFC) registered by the Reserve Bank of India (RBI). Review app permissions: Never give any loan or utility app access to your SMS, call logs and media files. No financial institution is required to read your messages to process the loan. Report immediately: If any kind of online financial fraud happens to you, without wasting any time call the National Cyber Helpline number 1930 within the first 2 hours (golden hour) or lodge a complaint on the official portal cybercrime.gov.in, so that the concerned bank account can be frozen immediately.