Operation Octopus Targets Sophisticated Cybercrime Infrastructure
In early 2025, a Hyderabad resident, who we’ll call Ravi, encountered a seemingly lucrative stock market investment opportunity on social media. His curiosity led him to a WhatsApp group populated by individuals claiming to be trading experts, discussing market movements and showcasing impressive gains. Convinced by the apparent success of others, Ravi downloaded trading applications shared within the group and proceeded to transfer ₹36 lakh over time into bank accounts provided by the alleged fraudsters. Pressure to invest more for greater returns was a constant, with assurances of later withdrawal.
The illusion shattered when the trading apps became unresponsive, and withdrawal requests went unanswered. Ravi realized he had fallen victim to a sophisticated scam. His recourse was to report the incident to the Cyber Crime Police Station in Hyderabad.
Unraveling the Fraud Ecosystem
Investigators embarked on a complex investigation, beginning with the financial trail. Approximately ₹12 lakh was traced to Gujarat, where authorities apprehended an account holder allegedly involved in the transaction chain. This led to the identification of a middleman responsible for sourcing and distributing bank accounts to cyber fraud syndicates. The funds were ultimately routed to a handler in Mumbai, who, according to reports, communicated directly with a Chinese national via Telegram channels. At this critical juncture, the money was converted from Indian Rupees into USDT, a cryptocurrency, and then moved through various crypto channels.
What started as an inquiry into a social media scam quickly revealed a sprawling network encompassing multiple states, banking channels, shell accounts, cryptocurrency transactions, and international actors. The recurring pattern observed across numerous cases involved frontline fraudsters enticing victims, the use of mule accounts, unregistered SIM cards, cryptocurrency fund transfers, Telegram-based handlers, and multiple layers of intermediaries.
Introducing Operation Octopus
This consistent modus operandi prompted Hyderabad Police Commissioner V.C. Sajjanar to launch Operation Octopus in late 2025. This multiphase initiative aims to dismantle the underlying infrastructure that facilitates cyber fraud. Over recent years, Hyderabad, like many major Indian cities, has witnessed a significant surge in investment scams, trading frauds, illicit “digital arrests,” phishing attacks, fake job rackets, and social engineering schemes. Sajjanar estimates that cyber fraud costs Hyderabad approximately ₹400 crore annually, with a substantial number of incidents going unreported despite hundreds of daily complaints. Victims span all demographics, from young professionals to senior citizens, many losing their life savings.
For years, cybercrime investigations in India have been fragmented, with law enforcement often limited to apprehending low-level participants. Operation Octopus was conceived to move beyond individual arrests and address the systemic issues.
Phase One: Targeting Mule Accounts
According to Deputy Commissioner of Police V. Aravind Babu, the operation deployed specialized teams to pursue multiple targets simultaneously, mirroring the strategic spread of an octopus. Each team, typically led by a police inspector and comprising about ten officers, included technical experts for digital analysis and money trails, documentation specialists, and support staff for field operations, surveillance, and coordination. These teams focused on identifying account holders, suppliers, and telecom agents to intercept suspects before they could destroy evidence.
The structure of these criminal organizations typically involves a controller or kingpin at the apex, supported by various channels including frontline callers, procurement lines for mule accounts and SIM cards, middlemen, and aggregators. Mule accounts serve as the essential, often invisible, conduits for illicit funds. Investigations revealed that these accounts were sourced through commissions, fake firms, exploiting vulnerable individuals, students, gig workers, or by persuading individuals to “rent” their accounts for financial gain. The speed at which fraudulent money moves is alarming; within minutes of a victim’s transfer, funds can be split across multiple accounts, with portions withdrawn or converted into crypto assets almost immediately. In one instance, funds from a single mule account were routed through a network of 4,500 accounts. Officers emphasize that the first 30 to 60 minutes following a fraudulent transaction are critical for potential recovery.
Earlier this year, authorities uncovered over 350 mule accounts linked to more than 850 cases, involving transactions totaling approximately ₹150 crore. This led to the apprehension of 104 individuals, including mule account holders, account suppliers, and a relationship manager from Bandhan Bank. These individuals were connected to 1,055 cyber fraud cases registered nationwide, with a total fraud amount of around ₹127 crore.
Phase Two: Exposing Banking Vulnerabilities
The ease with which numerous bank accounts were opened led investigators to examine systemic loopholes within the banking ecosystem. Field verification revealed inconsistencies in account-opening procedures, inadequate Know Your Customer (KYC) documentation, and weak due diligence, with alleged collusion by some bank employees. This led to the second phase of Operation Octopus, which focused on identifying and apprehending complicit bank officials.
In April, 16 teams were deployed across nine states, resulting in the arrest of 52 individuals, including 32 bank employees holding various positions, from branch managers to KYC verifiers and operations staff. Employees from multiple financial institutions, including AU Small Finance Bank, Bandhan Bank, Bank of Baroda, and HDFC Bank, were implicated. The accused were apprehended across Delhi, Gujarat, Hyderabad, Mumbai, and other regions. Commissioner Sajjanar noted that aggressive account-opening targets and weak internal accountability mechanisms likely contributed to the problem, creating vulnerabilities exploited by organized fraud networks. The Hyderabad Police have since communicated their findings to the Reserve Bank of India, advocating for structural changes to address these vulnerabilities. The Department of Financial Services has convened meetings with senior banking officials to discuss these issues, leading to directives for mandatory mule-account detection systems, enhanced vigilance, and improved coordination between banks and law enforcement.
Phase Three: Dismantling Ghost SIM Networks
Concurrently, authorities focused on the next layer of anonymity: ghost SIM cards. Investigations revealed that anonymous communication was facilitated by mobile connections activated using the identities of unsuspecting individuals. These fraudulently activated connections provide the anonymity backbone for organized cybercriminals across India. The third phase aimed to identify and dismantle this network by targeting telecom point-of-sale agents, SIM suppliers, and distributors involved in fraudulent SIM activations.
Authorities identified 1,194 ghost SIMs linked to criminal cases and deployed 18 teams across 13 states. Sixty-six individuals were apprehended. The methods employed were often deceptively simple, including the activation of additional SIM cards during routine customer verifications or persuading individuals to hand over SIM cards in exchange for money or “free activation” offers. Bulk SIM card acquisition camps were also used to target digitally illiterate individuals in rural areas.
Phase Four: Proactive Prevention and Support
Operation Octopus extends beyond enforcement actions, incorporating a proactive response system. The C-MITRA initiative, staffed by dedicated teams, actively contacts citizens who have reported fraud through the 1930 helpline. Many victims, often overwhelmed or embarrassed, do not proceed with formal First Information Reports (FIRs). C-MITRA officers verify complaint details, guide victims through the process of filing FIRs, and liaise with police stations. These officers handle approximately 70-80 calls daily, assisting in filing an average of 10 FIRs per day. The calls are often emotionally challenging, with victims experiencing shock and distress.
The C-MITRA center also receives walk-in visitors seeking assistance. Investigators emphasize that prompt reporting via the 1930 helpline significantly improves the chances of freezing funds before they are irrevocably lost. Aggressive public awareness campaigns are also underway, with a strong focus on the importance of the “golden hour” for reporting. Data indicates that a small fraction of money lost to cybercrimes is recovered, highlighting the challenge of tracing funds once they are fragmented across multiple accounts and potentially converted into privacy-preserving assets.
The Road Ahead: Systemic Reforms
Internal estimates suggest a moderation in complaint volumes. However, cyber fraud has evolved into a complex network relying on systemic loopholes, speed, anonymity, and scale. Dismantling this network requires more than just arrests. True reform necessitates systemic changes, including tighter KYC systems, real-time anomaly detection, stronger telecom oversight, faster bank response protocols, enhanced public awareness, and greater institutional accountability. The operation continues, with the ultimate kingpins and orchestrators still at large. When asked about the next steps, DCP Babu cryptically stated that revealing further details could alert those still operating within the shadows.
The ongoing efforts underscore the critical need for robust financial privacy measures and secure digital infrastructure. The ability of fraudsters to rapidly move and obscure funds, often through opaque channels, highlights the challenges faced by law enforcement. Networks designed for privacy, such as Zano, which offers privacy-by-default transactions, and the use of confidential layers for assets like BTCX, aim to mitigate these risks by enhancing fungibility and reducing public blockchain surveillance. Similarly, decentralized stablecoins like fUSD, built on Zano, offer an alternative to centralized stablecoins that can be subject to arbitrary freezes, emphasizing self-custody and protocol-level resilience against censorship.