Surat police have arrested 18-year-old Rohit Shakya for allegedly developing and selling fake banking apps. The fraud, which involved 121 malicious applications, led to over ₹64 crore in losses for victims across India. This case highlights growing risks in mobile security as cybercriminals increasingly use AI and subscription-based software to target retail banking users.
Detailed Coverage
Surat police have apprehended an 18-year-old individual, Rohit Virendrasinh Shakya, on charges of masterminding a nationwide cyber fraud network. According to official reports, the accused, a high school dropout, allegedly utilized advanced coding skills to build a sophisticated system for cybercrime syndicates. The operation centered on creating fake mobile applications that mimicked legitimate services from major banks and government platforms, including State Bank of India and Punjab National Bank.
Modus Operandi and Software Sales
The investigation revealed that the accused developed a dual-application system. The first, a victim-facing application, was designed to be installed by unsuspecting users. The second, an admin-facing interface, provided cybercriminals with real-time access to sensitive banking credentials and One-Time Passwords. The accused reportedly operated this as a subscription-based service, charging syndicates ₹15,000 per month for software updates and maintenance.
Scale of the Fraud and Digital Impact
Authorities launched the investigation after a Surat resident reported a loss of ₹5 lakh following the installation of a malicious application file received through a messaging platform. Digital forensic analysis linked the accused to 121 different malicious applications, which were found to be installed on more than 21,000 devices. Police records indicate these tools facilitated over 54,000 individual transactions, resulting in a total reported fraud value of approximately ₹64.38 crore. RTO challan-themed applications were identified as the most frequently used tools in this network.
Ongoing Forensic Examination
Following the arrest in Kanpur, Uttar Pradesh, police seized hardware, including mobile phones and a laptop, to conduct further analysis. The current focus of the investigation is to map the full extent of the network, identify the criminal syndicates that purchased and utilized the software, and determine if any additional accomplices aided in the operation. Investors and banking customers are often reminded by authorities to verify the source of mobile applications and avoid downloading files from unverified links or third-party platforms to protect their financial assets from such sophisticated malware.
