₹1.9-crore cyber fraud foiled in Bhopal after university accountant's WhatsApp hacked

Share:
Audio Loading voice…
₹1.9-crore cyber fraud foiled in Bhopal after university accountant's WhatsApp hacked

Synopsis

A Bhopal university accountant nearly transferred ₹1.9 crore after fraudsters hacked his WhatsApp and impersonated his CMD. What stopped the heist was the accountant noticing his own account acting strangely — and a rapid police cyber response that recovered the account before the money moved.

Key Takeaways

Rishabh Bhargava , accountant at Sage University, Bhopal , received a fake WhatsApp message on 24 September 2026 at 2:30 pm impersonating CMD Sanjeev Agrawal .
The message instructed him to transfer ₹1.9 crore to a bank account in the name of Bound Builders OPC Private Limited .
Bhargava noticed his WhatsApp account had been compromised and immediately contacted Katara Hills police .
Police filed a support ticket with WhatsApp ; the account was recovered swiftly, preventing the transfer.
Subsequent verification confirmed CMD Agrawal had never authorised the payment — the message was fraudulent.
Police are investigating the identities of the persons who allegedly impersonated the CMD; SHO Sunil Dube has urged independent verification of all large payment requests received via messaging apps.

A ₹1.9-crore cyber fraud targeting Sage University in Bhopal was foiled on Thursday, 24 September 2026, after the Katara Hills police swiftly recovered a compromised WhatsApp account belonging to an accountant who had been allegedly tricked into initiating the transfer. The timely intervention prevented what could have been one of the largest single-instance digital payment frauds targeting a private educational institution in Madhya Pradesh this year.

How the Attack Unfolded

Rishabh Bhargava, an accountant at Sage University, received a WhatsApp message at around 2:30 pm purportedly from the university's Chairman and Managing Director (CMD) Sanjeev Agrawal. The message instructed him to urgently transfer ₹1.9 crore to a bank account registered in the name of Bound Builders OPC Private Limited.

Bhargava responded with 'Yes Sir' and proceeded to add the specified bank account as a beneficiary in the university's account. He subsequently noticed that his own WhatsApp account appeared to be operating without his control — a telltale sign that his account had been taken over — and immediately raised the alarm.

Police Response and Account Recovery

Bhargava contacted Katara Hills police station, triggering a rapid response from the station's cyber team. Police lodged a complaint with WhatsApp's support team and generated a recovery ticket. The applicant's email account was also deployed to expedite the support process. The compromised WhatsApp account was restored shortly afterwards, allowing Bhargava to regain full control and resume communications.

'Rishabh received a WhatsApp message from a number claiming to belong to the university's CMD and was asked to make a payment of ₹1.9 crore. He became suspicious after noticing unusual activity on his WhatsApp account and immediately approached the police,' said Katara Hills Station House Officer (SHO) Sunil Dube.

The Fraud Confirmed

Once Bhargava regained control of his account, he contacted senior colleagues at the university. They confirmed that CMD Sanjeev Agrawal had sent no such message and had not authorised any transfer. The message was entirely fabricated — a classic 'CEO fraud' or business email compromise tactic, adapted for WhatsApp.

This type of attack, where fraudsters impersonate senior executives to authorise large payments, has been rising sharply across Indian institutions. Notably, this is at least the third high-value WhatsApp impersonation fraud reported in Madhya Pradesh in recent months, according to reports.

Officers Behind the Operation

The operation was conducted under the supervision of DCP Zone-2 Vikas Kumar Lawania and Additional DCP Zone-2 Mini Tiwari, with ACP Baghsewania Umrao Singh overseeing field coordination. Constables Vipin Singh Rajawat and Jitendra Singh Dangi, who handle cyber-related work at Katara Hills police station, played a key role in recovering the compromised account.

Investigation and Advisory

Police are now investigating the identity of the individuals who allegedly impersonated the CMD and attempted to facilitate the transaction. SHO Dube issued a public advisory: 'The timely response helped prevent the ₹1.9-crore cyber fraud. People should independently verify any request for large financial transactions received through WhatsApp or other messaging platforms before acting on it.'

Cybersecurity experts broadly recommend using out-of-band verification — such as a direct phone call to the requester's known number — before processing any large transfer instruction received via messaging apps. The investigation remains ongoing.

Point of View

And aimed at a target with payment authority but no direct line-of-sight to the executive being impersonated. The fact that ₹1.9 crore nearly moved on the strength of a single WhatsApp message exposes how thin the internal controls at many Indian institutions remain. The police response was commendably fast, but the real question is why a transaction of this scale did not require multi-level offline authorisation in the first place. As fraudsters shift from email to encrypted messaging apps, institutions that have not updated their financial approval protocols are sitting targets.
NationPress
25 Sept 2026

Frequently Asked Questions

What happened in the Bhopal university cyber fraud case?
Fraudsters hacked the WhatsApp account of Rishabh Bhargava , an accountant at Sage University, Bhopal , and sent a message impersonating the university's CMD to instruct him to transfer ₹1.9 crore to a third-party account. Bhargava noticed his account was behaving abnormally, alerted Katara Hills police , and the transfer was prevented after police recovered the compromised account.
How did police prevent the ₹1.9-crore transfer?
The Katara Hills police cyber team filed a complaint with WhatsApp's support team and raised a recovery ticket, also using Bhargava's email account to expedite the process. The WhatsApp account was restored shortly afterwards, allowing him to regain control before any funds were moved.
Who is being investigated in connection with the fraud?
Police are investigating the identities of the persons who allegedly impersonated CMD Sanjeev Agrawal and attempted to redirect ₹1.9 crore to a bank account held by Bound Builders OPC Private Limited . No arrests had been announced as of the initial report.
What is 'CEO fraud' and how does it work on WhatsApp?
'CEO fraud' involves criminals impersonating a senior executive — via a cloned or hacked communication channel — to instruct a finance employee to make an urgent large transfer. In this case, the attackers reportedly gained control of an internal WhatsApp account to send a convincing instruction, bypassing normal scepticism because the message appeared to come from within the organisation.
What precautions should people take to avoid such fraud?
SHO Sunil Dube advised that any request for a large financial transaction received via WhatsApp or other messaging apps should be independently verified through a separate, trusted channel — such as a direct phone call to the requester's known number — before any action is taken. Organisations are also advised to require multi-level authorisation for high-value transfers.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 2 days ago
  2. 2 months ago
  3. 2 months ago
  4. 2 months ago
  5. 3 months ago
  6. 3 months ago
  7. 4 months ago
  8. 4 months ago
Google Prefer NP
On Google