Mumbai CSMT Wi-Fi cyber scam: Bank GM loses ₹4.27 lakh in 28 minutes

Share:
Audio Loading voice…
Mumbai CSMT Wi-Fi cyber scam: Bank GM loses ₹4.27 lakh in 28 minutes

Synopsis

A bank general manager lost ₹4.27 lakh in just 28 minutes after a fake RTO challan APK — allegedly spread through a CSMT public Wi-Fi compromise — silently harvested his financial data. The case puts India's unsecured public hotspot infrastructure under the spotlight and signals a sharper, harder-to-detect evolution in mobile-based cyber fraud.

Key Takeaways

Gobinda Biswas , a general manager at a nationalised bank in Fort, Mumbai , lost ₹4,27,264 through five unauthorised credit card transactions on 21 July 2025 .
All five fraudulent transactions were completed within 28 minutes ; Biswas received no SMS alerts at the time.
The suspected breach began when his personal secretary Narayan Swami connected his phone to free public Wi-Fi at CSMT , allegedly allowing cybercriminals to plant a malicious APK disguised as an RTO traffic challan .
The malware reportedly auto-forwarded the infected file to more than 200 contacts on Swami's phone.
An FIR was registered at MRA Marg police station on 4 August ; investigators are examining whether a rogue hotspot or the genuine CSMT network was used.
Mumbai Police have advised citizens to avoid connecting to public Wi-Fi and to never install APK files from unverified sources.

Mumbai Police have launched an investigation into a suspected cyber fraud in which Gobinda Biswas, a 56-year-old general manager at a nationalised bank's Fort office, allegedly lost ₹4,27,264 through five unauthorised credit card transactions — all completed within 28 minutes on 21 July 2025. Investigators suspect the breach originated when Biswas's personal secretary connected his mobile phone to the free public Wi-Fi at Chhatrapati Shivaji Maharaj Terminus (CSMT) in Mumbai.

How the Attack Unfolded

According to police, Biswas's personal secretary, Narayan Swami, connected his phone to the free Wi-Fi service available at CSMT before sending a message to Biswas on 18 July. Cybercriminals allegedly compromised Swami's device through the network and planted a malicious Android application package (APK) file disguised as a Regional Transport Office (RTO) traffic challan.

The infected file was reportedly auto-forwarded through messaging applications to more than 200 contacts stored on Swami's phone, including senior bank officials. Believing the message to be a genuine challan notice, Biswas downloaded and installed the application — inadvertently giving the malware access to sensitive data on his device.

The Fraud Comes to Light

On 21 July, Biswas noticed unusual activity on his phone and deleted the application. However, police suspect the malware had already harvested critical financial information before removal. Biswas received no SMS alerts for the suspicious transactions at the time. The fraud only came to light on 3 August, when his credit card statement revealed five unauthorised transactions totalling ₹4,27,264, all executed within a 28-minute window.

The bank's credit card department subsequently attempted to reach Biswas multiple times. When communication could not be established and the transactions appeared suspicious, the credit card was blocked.

FIR Registered, Investigation Underway

Biswas filed a complaint on the National Cyber Crime Reporting Portal and approached the MRA Marg police station. An FIR was formally registered on 4 August. Investigators are now examining whether the device was compromised through the public Wi-Fi network, a rogue hotspot mimicking the genuine CSMT network, or through another method.

A Mumbai Police official said the probe is focused on identifying the malware's source and the exact technique used to access the device.

Public Warning and Cyber Safety Advisory

Mumbai Police have cautioned citizens to exercise care when connecting to public Wi-Fi networks and to avoid installing applications received from unknown or unverified sources. Cyber experts have repeatedly warned that attackers exploit fake applications, phishing messages, and unsecured public networks to harvest personal and financial data.

This case is among a growing pattern of APK-based fraud targeting mobile users in India's high-footfall public spaces. Police have advised users to verify links before clicking, avoid sharing sensitive banking credentials on suspicious platforms, and enable transaction alerts on all linked accounts. The investigation is ongoing.

Point of View

Yet millions of commuters connect to it daily. The fake-challan APK vector is particularly insidious because it exploits civic anxiety — few people ignore what looks like an official traffic fine. What is missing from the response is any accountability upstream: who operates the CSMT Wi-Fi, what security protocols are in place, and whether a rogue hotspot could have been detected and shut down in real time. Until those questions are answered publicly, advisories telling citizens to 'be careful' shift the entire burden of cybersecurity onto individual users rather than infrastructure providers.
NationPress
7 Aug 2026

Frequently Asked Questions

What happened in the Mumbai CSMT Wi-Fi cyber fraud case?
A nationalised bank general manager, Gobinda Biswas, lost ₹4,27,264 through five unauthorised credit card transactions on 21 July 2025. Police suspect the fraud began after his personal secretary connected to the free public Wi-Fi at CSMT, which allegedly allowed cybercriminals to compromise the device and spread a fake RTO challan APK to over 200 contacts, including Biswas.
How did the fake RTO challan APK scam work?
After the personal secretary's phone was allegedly compromised via CSMT's public Wi-Fi, a malicious Android APK file disguised as an RTO traffic challan was auto-forwarded through messaging apps to more than 200 contacts. When Biswas installed the file believing it to be a genuine challan, the malware reportedly accessed sensitive financial data on his device.
When was the FIR filed and which police station is investigating?
An FIR was registered on 4 August 2025 at the MRA Marg police station in Mumbai. Investigators are examining whether the device was compromised through the public Wi-Fi network, a rogue hotspot mimicking the CSMT network, or another method.
Why did Biswas not know about the transactions immediately?
Biswas reportedly did not receive any SMS alerts for the five unauthorised credit card transactions at the time they occurred on 21 July. The fraud only came to his attention on 3 August when he reviewed his credit card statement, nearly two weeks after the money was lost.
How can people protect themselves from public Wi-Fi malware attacks?
Mumbai Police have advised citizens to avoid connecting to public Wi-Fi networks in high-footfall areas and to never install APK files received via messaging apps, especially those claiming to be government notices. Cyber experts recommend enabling transaction alerts on all bank accounts and verifying any link or application through official sources before downloading.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 2 weeks ago
  2. 2 weeks ago
  3. 1 month ago
  4. 1 month ago
  5. 2 months ago
  6. 2 months ago
  7. 2 months ago
  8. 4 months ago
Google Prefer NP
On Google