Mumbai CSMT Wi-Fi cyber scam: Bank GM loses ₹4.27 lakh in 28 minutes
Synopsis
Key Takeaways
Mumbai Police have launched an investigation into a suspected cyber fraud in which Gobinda Biswas, a 56-year-old general manager at a nationalised bank's Fort office, allegedly lost ₹4,27,264 through five unauthorised credit card transactions — all completed within 28 minutes on 21 July 2025. Investigators suspect the breach originated when Biswas's personal secretary connected his mobile phone to the free public Wi-Fi at Chhatrapati Shivaji Maharaj Terminus (CSMT) in Mumbai.
How the Attack Unfolded
According to police, Biswas's personal secretary, Narayan Swami, connected his phone to the free Wi-Fi service available at CSMT before sending a message to Biswas on 18 July. Cybercriminals allegedly compromised Swami's device through the network and planted a malicious Android application package (APK) file disguised as a Regional Transport Office (RTO) traffic challan.
The infected file was reportedly auto-forwarded through messaging applications to more than 200 contacts stored on Swami's phone, including senior bank officials. Believing the message to be a genuine challan notice, Biswas downloaded and installed the application — inadvertently giving the malware access to sensitive data on his device.
The Fraud Comes to Light
On 21 July, Biswas noticed unusual activity on his phone and deleted the application. However, police suspect the malware had already harvested critical financial information before removal. Biswas received no SMS alerts for the suspicious transactions at the time. The fraud only came to light on 3 August, when his credit card statement revealed five unauthorised transactions totalling ₹4,27,264, all executed within a 28-minute window.
The bank's credit card department subsequently attempted to reach Biswas multiple times. When communication could not be established and the transactions appeared suspicious, the credit card was blocked.
FIR Registered, Investigation Underway
Biswas filed a complaint on the National Cyber Crime Reporting Portal and approached the MRA Marg police station. An FIR was formally registered on 4 August. Investigators are now examining whether the device was compromised through the public Wi-Fi network, a rogue hotspot mimicking the genuine CSMT network, or through another method.
A Mumbai Police official said the probe is focused on identifying the malware's source and the exact technique used to access the device.
Public Warning and Cyber Safety Advisory
Mumbai Police have cautioned citizens to exercise care when connecting to public Wi-Fi networks and to avoid installing applications received from unknown or unverified sources. Cyber experts have repeatedly warned that attackers exploit fake applications, phishing messages, and unsecured public networks to harvest personal and financial data.
This case is among a growing pattern of APK-based fraud targeting mobile users in India's high-footfall public spaces. Police have advised users to verify links before clicking, avoid sharing sensitive banking credentials on suspicious platforms, and enable transaction alerts on all linked accounts. The investigation is ongoing.