← Blogs
26 May 2026

How Cyber Mafias Earn ₹10 Lakh/Day | Cyber Frauds Real Stories | ft. Amit Dubey

How Cyber Mafias Earn ₹10 Lakh/Day | Cyber Frauds Real Stories | ft. Amit Dubey

India Has a Rs 1 Lakh Crore Cyber Crime Industry. Here Is How It Actually Works.

What an IIT Kharagpur alumnus and India's leading cyber crime investigator taught me about fraud ecosystems, why awareness campaigns fail, and how to actually protect yourself

A conversation with Prof. Amit Dubey, IIT Kharagpur alumnus, British Chevening Fellow, author, and the investigator behind India's largest cybercrime rescue operation.

There is a question that most people never think to ask about cyber fraud.

When someone gets cheated out of Rs 22 lakh online, where exactly does the money go?

Prof. Amit Dubey pulled up a case for me to illustrate the answer. The money left the victim's account and went into three accounts first. Then it scattered into somewhere between 100 and 1,250 accounts. Some of those received Rs 400. Some received Rs 300. Some received Rs 500.

The criminal had deliberately diluted the money to a level where freezing accounts becomes practically impossible. By the time you file a complaint and request a freeze on 100 accounts, the cash has already been withdrawn from most of them.

This is not an amateur operation. This is an industry.

And according to Amit, it is worth at least Rs 1 lakh crore a year in India alone.

Part 1: You Are Not Dealing With a Criminal. You Are Dealing With a Supply Chain.

The first thing Amit wants people to understand is that cyber fraud in India is not a few bad actors sitting in a room making phone calls. It is a fully organized ecosystem with specialized roles, hiring processes, training programs, and even offshore operations.

Here is how the chain works.

There is an entity whose only job is to source and classify data. They know who has money, who is likely to respond to which type of fraud, what their account numbers are, what their passwords are, and what their family situation is. They categorise targets: this person should receive a digital arrest call, this one is better for investment fraud, this one for a job portal scam.

Then there is an entity that specialises in social engineering. Their job is to call targets, build trust, and extract money through psychological manipulation.

Then there is an entity that supplies SIM cards, changed every three to seven days so that blocked numbers cannot be traced back.

Then there is an entity that supplies bank accounts, which are constantly rotated because accounts get frozen within hours of fraud.

Then there is an entity that supplies stolen mobile phones, because a new phone can be tracked to the shop that sold it.

Then there is an entity whose only job is moving the money out of India as fast as possible, within 30 minutes to two hours of a transaction.

"Everyone is playing their part," Amit said. "That is it. And when a system becomes this fragmented, breaking it becomes extremely difficult."

Part 2: The City Built for Cyber Crime

This is the detail that genuinely shocked me.

On the border of Myanmar and Thailand, there exists an area called KK Park. It was built by the Chinese mafia. It has schools, residential complexes, colleges, and every facility a person would need to live and work. Estimates suggest that between 2.5 and 3 lakh people are engaged in cyber crime there at any given time.

The target is the entire world, but India is a primary focus given its large and increasingly online population.

Young Indians have been trafficked there under the promise of legitimate jobs. They are taken to Thailand, and once there they are tortured into committing cyber crimes against Indians back home.

Amit was involved in investigating this. Three years ago a case came to him about a young man who had gone to Thailand and gone off the radar. Amit's first instinct was that the boy would not be alone.

He was right. Eventually 156 Indians were rescued by police in a Ministry of External Affairs operation. Many more remain trapped.

The operation involved victims from multiple districts in Uttar Pradesh, including Sonbhadra and Kasganj. These were ordinary people who had answered what looked like a legitimate job posting.

"Many are still there," he said quietly. "Many are still trapped."

Part 3: Why Catching the Criminal Gets You Nowhere

Here is the frustration that investigators like Amit carry every day.

When someone calls you and says they are from the Narcotics Control Bureau or the Crime Branch and demands money to avoid arrest, the number calling you is not in the criminal's name. The bank account where the money goes is registered to a vegetable vendor in West Bengal. The SIM card is from a farmer in Odisha. The phone itself is stolen.

Even if you somehow catch the person who made the call, you cannot link them to the specific fraud because the phone they used is gone, the SIM is gone, and the account is closed.

"You would take him to court," Amit said, "and prove what exactly? That this person made a call from a device that no longer exists, from a number that no longer exists, into an account that is no longer active? The court will give them bail."

He is not criticising the police. He is describing the structural impossibility of the situation. A single cybercrime case can take one or two months for a trained investigator just to map the money trail. Multiply that by the 60,000 to 70,000 complaints that pour into the 1930 helpline on a single day, and the scale of the problem becomes clear.

Part 4: The Awareness Campaign That Does Nothing

Here is something Amit said that I think deserves much more attention than it gets.

Every year, crores of rupees are spent on campaigns that tell people: do not share your OTP. Amitabh Bachchan says it on television. Posters say it. Government announcements say it. Banks say it.

Amit's assessment of all of it: useless.

"Everyone already knows not to share their OTP," he said. "Have you ever met anyone who woke up one morning and decided to call their bank and hand out their OTP to a stranger? That is not how fraud works."

The real question is how criminals get your password in the first place, since no money can move without both a password and an OTP. If someone already has your password, and you have done nothing to protect it, telling you not to share your OTP achieves nothing.

He extended this to HTTPS links. Every awareness campaign says only click HTTPS links. But criminals today exclusively use HTTPS links. The fraudulent websites impersonating Nirmala Sitharaman's investment scheme, the Supreme Court of India's cloned website used in digital arrest cases, all of them were HTTPS.

The criminal is always one step ahead of the guideline.

"You are spending money making people aware of something that is not helping them," he said. "And in the meantime, the actual methods of fraud keep evolving."

Part 5: The Chowpatty Lesson

To explain how investment fraud works at a psychological level, Amit told me a story from his own life.

He was a young man, recently arrived in Mumbai for his first posting at IIT Bombay's SAMEER lab. He and a friend went to Chowpatty beach one evening. A crowd had gathered around a shell game. Money was changing hands. People were winning. The atmosphere was exciting.

Someone bumped a Rs 500 note against his friend's hand and said it had been placed in his name. His friend held the money. Then more bets, more wins, more money in his friend's hand. Then a loss. The person running the game asked for his Rs 3,000 back. His friend handed it over. Then, surrounded by twenty people from the same gang, he handed over everything in his wallet too.

All twenty people in that crowd were part of the same operation.

"That same psychology has been simulated online," Amit said. "In an investment fraud group, every person you see posting about their returns, every person who calls you with doubts and then gets convinced, every person who thanks you for the advice that helped them profit. They are all the same person."

He described a senior officer, highly intelligent, who fell for exactly this trap. A group. Strangers sharing returns. A woman who called to say it seemed like fraud. A man who called to say he had done research and found the company was legitimate. The officer eventually invested and watched his money grow to Rs 22 lakh. Then he tried to withdraw. Nothing happened.

"Your brain has a pre-trained model," Amit said. "One person can lie. Six people cannot. Except you do not know that all six are the same person. And AI can make that six into 6,000 different faces, all with different voices, all arguing and mediating and convincing you. You will not be able to tell."

Part 6: They Are Not Hacking Your Device. They Are Hacking You.

This is the central insight of everything Amit shared.

95 to 97 percent of the cases that come to him do not involve a hacked device. The phone is fine. The criminal never needed to hack the device.

"The criminal will never hack your device to reach you. The criminal will always hack you to reach your device."

AI is not being used to break into phones. It is being used to manipulate people into handing over access themselves. Deepfake videos of Nirmala Sitharaman promising investment returns. Voice cloning used to impersonate family members. Faces and identities built from social media and deployed in targeted fraud operations.

He told me a case from three years ago where a woman kept changing her phone, her SIM, her router, and her email address, and her stalker kept finding her. She was certain she was being hacked by some sophisticated actor somewhere in the world.

The investigation eventually found a recording device planted in her bag.

"It is not always hacking," Amit said. "Sometimes the person compromised is someone near you. And because your mental picture of a hacker is someone sitting far away with computers, you never look close to home."

Part 7: The Gmail Risk Nobody Talks About

Here is something practical that Amit shared which I immediately went and checked on my own devices.

Your Gmail account is probably logged into your laptop, your tablet, your old phone sitting in a drawer, and your current phone. Every one of those devices is a door into your entire digital life: your location history, your photos, your chats, your passwords saved in Chrome, your transaction history, your Play Store from which apps can be remotely installed onto your phone.

Ten seconds with any one of those devices is enough.

He also flagged Google Backup Codes, a feature most people do not know exists. These are pre-generated OTPs that allow you to log into your Google account even without your phone. They exist for genuine emergencies, like if your phone is stolen and you need to track it.

The risk: if someone gets 10 seconds with any logged-in device, they can download those backup codes and use them to log in from anywhere, at any time, permanently.

"I have seen print shops where people hand over their Gmail address and password so the shop owner can print a document," he said. "That Gmail is on their phone. That phone has their banking apps. All of it."

The rule is simple: your Gmail should never be logged into any device you do not actively control.

Part 8: What Actually Works

Amit recommended an app called Mobi Armor, available on both the Play Store and App Store with around 1.5 million downloads, for proactive protection across several threat categories.

On QR codes: before scanning any QR code, whether on a menu, a boarding pass, a payment terminal, or a free wifi setup, run it through Mobi Armor. It tells you whether the destination is safe, where it is hosted, and when the domain was created. A legitimate hotel does not need a domain created in Turkey last week.

On links: before paying through any link you found on Google search, verify it through the app. The app checks whether the link is cloned, malicious, or fraudulently hosted. He pointed out that searches for Kedarnath helicopter booking, Ayodhya ashram booking, and Kumbh tent booking have all been used to direct people to fake payment pages that look identical to the real thing.

On apps: even Play Store apps can be fraudulent. The app checks installed applications for warning signs.

On wifi: the advice to never use public wifi is unrealistic. The app lets you scan any public wifi network before connecting to check whether it has been compromised, and if it has, it shows the IP address of the person who compromised it, since they must be physically nearby to run a wifi attack.

Part 9: What To Do in the First 10 Minutes After a Fraud

If you realise you have been defrauded, every second counts. Call 1930 immediately and file a complaint at www.cybercrime.gov.in with your transaction details.

The goal is to freeze the destination account and every account the money passes through before it reaches cash withdrawal. The system works in layers: freeze the first account, then the accounts it distributes to, then the accounts those distribute to.

The race is this: the criminal has an automated system set up to move money the moment it arrives. Your freeze request triggers a chain of freezes moving through the same layers. If your money has not yet been converted to cash, it can be recovered.

The complication: if 10 other people were also defrauded into the same account, and only Rs 4 lakh of Rs 60 lakh remains frozen, a court has to decide who gets what. This is why recovery can take anywhere from 21 days to six years.

His advice: file immediately regardless. A partial recovery is better than none, and the more complaints that arrive quickly, the stronger the case.

Part 10: India Is Actually Safer Than You Think

Amit ended with something that surprised me.

India ranks 10th globally on the cyber security index. Despite facing 1.5 to 2 million cyber attacks annually from adversaries including Pakistan, China, Turkey, and Iran, almost all of them are stopped.

"Name two successful large-scale cyber attacks on India," he said.

AIIMS. The Mumbai power grid. Oil India Limited. That is about it, despite relentless attempts.

"People criticize the goalkeeper every time one goal goes in," he said. "Nobody counts the hundred goals they stopped."

He also addressed the concern about Indian banking infrastructure being vulnerable to quantum computing attacks, noting that India launched its National Quantum Mission two years ago with Rs 8,000 crore in funding, and CDAC Bangalore is building India's first 22-qubit quantum computer this year.

His parting message to young Indians: the changes India will see in the next five years will exceed everything the last twenty years produced. The opportunities are real. But they require genuine effort and genuine research, not the passive consumption of confident-sounding content that may be wrong.

"Truth is what does not change," he said. "If you want to be part of what is coming, do your own research. That is all I ask."

The One Thing

If there is a single sentence that captures everything Amit shared, it is this:

The criminal is not hacking your phone. They are hacking your judgment. And the only defense against that is understanding exactly how the hack works.

Awareness campaigns that tell you to not share your OTP are not protecting you. Understanding that six strangers in a group chat are actually one person running a script is protecting you. Knowing that your Gmail logged into a forgotten tablet in a drawer is a wide-open door is protecting you.

The fraud industry is worth Rs 1 lakh crore because it is smarter, faster, and better organized than the awareness campaigns trying to stop it.

The only equal and opposite force is a population that understands the actual mechanics.

Newsletter

Subscribe to our newsletter

The best new roles, resources and must-watch episodes — in your inbox every week. No spam, unsubscribe anytime.

contact@waphire.com
YouTubeSpotifyInstagramLinkedInWhatsAppSubstack
Waphire

Your go-to guide for career, growth, and mentorship. Real insights from founders, Leaders, Industry Experts & CXOs to land dream jobs and win big.

© Copyright 2026. All Rights Reserved.
TermsPrivacyHelp