Fake RTO e-challan scam: Surat cyber cell arrests Jamtara gang's money handler
Synopsis
Key Takeaways
The Surat City Cyber Crime Cell in Gujarat has arrested Sitaram Mandal, 26, an alleged associate of a Jamtara-based cyber fraud network, on charges of laundering proceeds from a fake RTO e-challan scam that drained ₹5,02,562 from a Surat resident's bank account. Mandal, a welding shop worker from Bisanpur village in Giridih district, Jharkhand, was taken into custody from Sabarmati Jail in Ahmedabad, where he was already lodged in connection with other cases. A court subsequently granted police a two-day custody remand.
How the Scam Unfolded
The fraud reportedly began on 20 November 2025, when an unknown WhatsApp number sent a malicious APK file — disguised as a legitimate RTO e-challan — to the phone of one Rakesh Sharma, a friend of the victim's son. The compromised account was then used to circulate the file within a WhatsApp group shared by the victim's son and his friends.
Once the victim downloaded and installed the file, his phone was allegedly compromised without his knowledge. The application reportedly sought administrative permissions granting access to SMS messages, contacts, call logs, and photographs. Using genuine-looking bank names, logos, and icons, the gang allegedly persuaded the victim to enter banking and KYC credentials, after which ₹5,02,562 was siphoned from his account across multiple transactions.
The complainant contacted the national cybercrime helpline immediately after discovering the fraud and formally approached the Surat Cyber Crime Cell on 14 December 2025. A case was registered at the Cyber Crime Police Station under Sections 318(4), 336(2), 338, 336(3), 340(2), 61(2) and 3(5) of the Bharatiya Nyaya Sanhita, 2023, and Sections 66(C) and 66(D) of the Information Technology Act, 2008.
Mandal's Role in the Money Trail
According to investigators, ₹1,47,954 from the victim's account was routed toward a credit bill payment arranged through a previously arrested accused, Nishit Nathwani. Nathwani allegedly retained a commission of 15 to 20 per cent and deposited the remaining cash through a cash deposit machine (CDM) into Mandal's bank account.
Mandal then allegedly deducted a further 5 to 10 per cent commission before handing over the residual cash to absconding members of the Jamtara gang in Jharkhand. Police found that ₹2.72 lakh linked to cyber fraud — from this and other victims — had been deposited via CDM transactions into Mandal's Axis Bank account between 21 November and 18 December 2025. The account recorded total credit transactions of ₹15,87,400 between 19 September 2025 and 8 January 2026.
Mandal's Criminal Background
This is not Mandal's first brush with the law. He has a prior FIR registered in Giridih district in 2017 under provisions relating to cheating, forgery, and the Information Technology Act. He is also named in five cases registered at the Ahmedabad City Cyber Crime Police Station in 2026, involving cheating, impersonation, criminal conspiracy, and IT Act offences — painting a picture of a habitual offender embedded in a larger organised network.
With five accused already arrested before Mandal's apprehension, the Surat Cyber Crime Cell continues to pursue absconding members of the Jamtara gang believed to be operating from Jharkhand.
How APK Malware Frauds Work
According to investigators, the gang engineered APK files to mimic legitimate services — RTO challans, bank notifications, KYC updates, and government scheme alerts. Once installed, these apps harvest sensitive credentials and enable unauthorised fund transfers to mule accounts or credit cards. The proceeds are then withdrawn or converted into cash and cycled through CDMs into accounts controlled by other network members, making tracing difficult.
Police Advisory
The Cyber Crime Cell has urged the public not to download APK files received from unknown sources, regardless of whether they appear to relate to RTO challans, banking services, KYC updates, customer support, government schemes, or appointment bookings. Citizens have also been advised against clicking on suspicious links received via SMS or email. This case is part of a broader national pattern of Jamtara-linked cyber fraud cells exploiting low digital literacy among mobile users.