Fake RTO e-challan scam: Surat cyber cell arrests Jamtara gang's money handler

Share:
Audio Loading voice…
Fake RTO e-challan scam: Surat cyber cell arrests Jamtara gang's money handler

Synopsis

A welding shop worker from Jharkhand's Giridih district, already lodged in Sabarmati Jail, has been unmasked as a key money-mover for a Jamtara cyber fraud gang — skimming commissions off stolen funds before passing cash to absconding operatives. His Axis Bank account alone recorded ₹15,87,400 in suspicious credits over four months, revealing the industrial scale of India's fake-APK fraud ecosystem.

Key Takeaways

Sitaram Mandal , 26 , arrested from Sabarmati Jail, Ahmedabad as an alleged associate of the Jamtara cyber fraud gang.
A Surat resident's son lost ₹5,02,562 after downloading a fake RTO e-challan APK sent via WhatsApp on 20 November 2025 .
Mandal's Axis Bank account received ₹15,87,400 in credit transactions between 19 September 2025 and 8 January 2026 , of which ₹2.72 lakh is directly linked to fraud proceeds.
Mandal allegedly took a 5–10% cut before routing remaining cash to absconding gang members in Jharkhand .
He carries a prior 2017 FIR from Giridih and is named in five Ahmedabad cyber crime cases filed in 2026 .
This is the sixth arrest in the case; absconding Jamtara gang members remain at large.

The Surat City Cyber Crime Cell in Gujarat has arrested Sitaram Mandal, 26, an alleged associate of a Jamtara-based cyber fraud network, on charges of laundering proceeds from a fake RTO e-challan scam that drained ₹5,02,562 from a Surat resident's bank account. Mandal, a welding shop worker from Bisanpur village in Giridih district, Jharkhand, was taken into custody from Sabarmati Jail in Ahmedabad, where he was already lodged in connection with other cases. A court subsequently granted police a two-day custody remand.

How the Scam Unfolded

The fraud reportedly began on 20 November 2025, when an unknown WhatsApp number sent a malicious APK file — disguised as a legitimate RTO e-challan — to the phone of one Rakesh Sharma, a friend of the victim's son. The compromised account was then used to circulate the file within a WhatsApp group shared by the victim's son and his friends.

Once the victim downloaded and installed the file, his phone was allegedly compromised without his knowledge. The application reportedly sought administrative permissions granting access to SMS messages, contacts, call logs, and photographs. Using genuine-looking bank names, logos, and icons, the gang allegedly persuaded the victim to enter banking and KYC credentials, after which ₹5,02,562 was siphoned from his account across multiple transactions.

The complainant contacted the national cybercrime helpline immediately after discovering the fraud and formally approached the Surat Cyber Crime Cell on 14 December 2025. A case was registered at the Cyber Crime Police Station under Sections 318(4), 336(2), 338, 336(3), 340(2), 61(2) and 3(5) of the Bharatiya Nyaya Sanhita, 2023, and Sections 66(C) and 66(D) of the Information Technology Act, 2008.

Mandal's Role in the Money Trail

According to investigators, ₹1,47,954 from the victim's account was routed toward a credit bill payment arranged through a previously arrested accused, Nishit Nathwani. Nathwani allegedly retained a commission of 15 to 20 per cent and deposited the remaining cash through a cash deposit machine (CDM) into Mandal's bank account.

Mandal then allegedly deducted a further 5 to 10 per cent commission before handing over the residual cash to absconding members of the Jamtara gang in Jharkhand. Police found that ₹2.72 lakh linked to cyber fraud — from this and other victims — had been deposited via CDM transactions into Mandal's Axis Bank account between 21 November and 18 December 2025. The account recorded total credit transactions of ₹15,87,400 between 19 September 2025 and 8 January 2026.

Mandal's Criminal Background

This is not Mandal's first brush with the law. He has a prior FIR registered in Giridih district in 2017 under provisions relating to cheating, forgery, and the Information Technology Act. He is also named in five cases registered at the Ahmedabad City Cyber Crime Police Station in 2026, involving cheating, impersonation, criminal conspiracy, and IT Act offences — painting a picture of a habitual offender embedded in a larger organised network.

With five accused already arrested before Mandal's apprehension, the Surat Cyber Crime Cell continues to pursue absconding members of the Jamtara gang believed to be operating from Jharkhand.

How APK Malware Frauds Work

According to investigators, the gang engineered APK files to mimic legitimate services — RTO challans, bank notifications, KYC updates, and government scheme alerts. Once installed, these apps harvest sensitive credentials and enable unauthorised fund transfers to mule accounts or credit cards. The proceeds are then withdrawn or converted into cash and cycled through CDMs into accounts controlled by other network members, making tracing difficult.

Police Advisory

The Cyber Crime Cell has urged the public not to download APK files received from unknown sources, regardless of whether they appear to relate to RTO challans, banking services, KYC updates, customer support, government schemes, or appointment bookings. Citizens have also been advised against clicking on suspicious links received via SMS or email. This case is part of a broader national pattern of Jamtara-linked cyber fraud cells exploiting low digital literacy among mobile users.

Point of View

But the layered commission structure: Nathwani took 15–20%, Mandal took another 5–10%, and the Jamtara principals collected the rest, insulated by geography and intermediaries. This architecture makes prosecution at the top tier extremely difficult. The fact that Mandal was already in jail and still named in five fresh 2026 cases suggests the system of using incarcerated individuals as financial conduits is deliberate, not incidental — a gap in India's cyber-arrest-to-asset-freeze pipeline that investigators have yet to close.
NationPress
13 Aug 2026

Frequently Asked Questions

What is the fake RTO e-challan APK scam in Surat?
It is a cyber fraud in which criminals sent a malicious APK file disguised as an RTO e-challan notice via WhatsApp, causing a Surat resident's son to lose ₹5,02,562. Once installed, the app harvested banking credentials and enabled unauthorised transfers to mule accounts linked to a Jamtara-based gang.
Who is Sitaram Mandal and what was his role?
Sitaram Mandal is a 26-year-old welding shop worker from Bisanpur village in Giridih district, Jharkhand, allegedly serving as a money handler for the Jamtara fraud gang. He reportedly received stolen funds in his Axis Bank account, deducted a 5–10% commission, and passed the remaining cash to absconding gang members.
How much money passed through Mandal's bank account?
Mandal's Axis Bank account recorded total credit transactions of ₹15,87,400 between 19 September 2025 and 8 January 2026. Of this, ₹2.72 lakh has been directly linked by police to cyber fraud proceeds deposited via cash deposit machines.
What should people do to avoid fake APK scams?
The Surat Cyber Crime Cell advises people never to download APK files received from unknown numbers, even if they appear to be from the RTO, banks, or government agencies. Citizens should also avoid clicking suspicious links in SMS or email messages and report suspicious activity to the national cybercrime helpline.
How many people have been arrested in this case so far?
Six people have been arrested in total, with five arrested before Sitaram Mandal's custody. Absconding members of the Jamtara gang based in Jharkhand are still being pursued by the Surat Cyber Crime Cell.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest Yesterday
  2. 2 days ago
  3. 4 weeks ago
  4. 1 month ago
  5. 1 month ago
  6. 1 month ago
  7. 1 month ago
  8. 2 months ago
Google Prefer NP
On Google