₹5.99 Lakh Vanishes From Bhopal Man’s FD Without OTP: What Police Know About the Cyber Fraud

 | 
as

A suspected cyber fraud case reported in Bhopal has raised fresh concerns about the security of savings linked to digital banking. A 61-year-old man has alleged that ₹5.99 lakh was transferred after his fixed deposit was prematurely closed, even though he did not receive an OTP or disclose his PIN, password or card security code.

Police have registered a case and begun investigating how the transactions were authorised. At this stage, the precise method used to access the victim’s banking profile has not been officially established. Possibilities such as compromised login credentials, remote access, an already authenticated banking session or another form of account takeover can only be confirmed after the bank’s technical records and the recipient accounts are examined.

₹5.99 Lakh Transferred in Three Transactions

According to the complaint, the victim has been identified as 61-year-old Sharif Ahmad Qureshi, a resident of Afkar Colony in Bhopal. He reportedly maintains a savings account and fixed deposit with ICICI Bank’s Ashoka Garden branch.

Three online transactions were allegedly carried out through internet banking between approximately 12 noon and 12:30 pm on September 4. A total of ₹5,99,009.62 was reportedly transferred to another account.

After discovering the transactions, Qureshi contacted the National Cybercrime Helpline at 1930. Based on an e-Zero FIR received from the cyber cell, Aishbagh police reportedly registered a fraud case and started an investigation.

The allegations remain subject to police and bank verification. No conclusion should be drawn about the bank’s systems or the victim’s device until the inquiry is complete.

How Can Money Be Taken From a Fixed Deposit?

A fixed deposit generally does not have a separate internet-banking login. Instead, it is linked to the customer’s primary banking relationship, such as a savings account.

If a depositor creates or manages an FD through internet or mobile banking, the same authenticated banking profile may provide options to view the deposit, request premature closure and transfer the proceeds to the linked savings account. The money may then be moved to another bank account if the fraudster also has sufficient access to the victim’s banking session.

This means criminals do not necessarily have to “hack the FD” as an independent account. They may attempt to take control of the customer’s broader digital-banking access.

The exact process and security checks differ between banks, deposit types and transaction channels.

No OTP Does Not Necessarily Mean There Was No Authentication

The absence of an OTP message is significant, but it does not by itself reveal how the fraud occurred. An OTP may be intercepted through a compromised device or notification access. A criminal might also misuse a session that was already authenticated.

Other possibilities may include credential theft through a phishing website, unauthorized access to email or mobile banking, SIM-related fraud, malware or remote-control software. These are general fraud techniques and have not been confirmed as the cause of this particular incident.

CVC or CVV details are normally associated with card transactions. They may not be relevant when money is moved through internet banking after an FD is closed. Similarly, a card PIN is not necessarily used for an online banking transfer.

The bank’s login records, IP addresses, registered-device information, authentication logs and transaction trail will be important in determining what happened.

How Screen-Sharing Scams Can Expose Banking Information

One commonly reported method involves convincing a customer to install a screen-sharing or remote-support application. The fraudster may pretend to be a bank employee, courier representative, customer-care executive or refund agent.

After the application is installed, the victim may be instructed to open a banking app and follow several steps. Depending on the access granted, the criminal could view information displayed on the screen or remotely operate parts of the device.

Some malicious applications also request access to SMS messages, notifications or Android accessibility services. These permissions can expose sensitive information or allow actions that a normal application should not perform.

However, there is no confirmed public evidence that a remote-access application was used in the Bhopal case. It remains one possible method that investigators may examine.

What Customers Should Do to Protect Their FDs

Depositors should treat their fixed deposits as part of their overall digital-banking security. Protecting only the debit card or UPI PIN is not sufficient.

Important precautions include:

  • Never install a screen-sharing or remote-access app at the request of an unknown caller.

  • Do not open a banking app or enter credentials while another person can view or control the screen.

  • Use only the bank’s official website, application and verified customer-care channels.

  • Avoid searching online for random customer-care numbers, as fraudulent listings may appear in search results.

  • Review SMS, email and app alerts for FD closure, beneficiary addition and fund transfers.

  • Use a unique password for internet banking and secure the registered email account with two-factor authentication.

  • Regularly check linked devices, beneficiaries and transaction limits.

  • Remove unnecessary app permissions, particularly access to SMS, notifications, files and accessibility controls.

  • Never share an OTP, password, UPI PIN or card details with anyone claiming to process a refund.

What to Do Immediately After Financial Cyber Fraud

Speed can be critical after an unauthorized transfer. Contact the bank immediately and request that digital banking be blocked, recipient accounts be traced and disputed transactions be recorded.

Victims should call the government’s 24-hour financial cyber-fraud helpline at 1930 and submit a complaint through the National Cyber Crime Reporting Portal. The portal advises complainants to keep the bank or wallet name, transaction ID or UTR number, date and fraud amount ready.

Screenshots, account statements, messages, phone numbers, email addresses and suspicious application details should be preserved as evidence. The phone should not be factory-reset before investigators or security professionals have had an opportunity to examine it.

The Bhopal case demonstrates that securing an FD requires more than protecting card information. Customers must safeguard the entire digital ecosystem connected to their bank account, including their phone, SIM, email, passwords and active banking sessions.

Tags