Back to Mumbai

Scammers steal Rs 78.1 lakh from Parel gold loan firm in cyber heist

Scammers steal Rs 78.1 lakh from Parel gold loan firm in cyber heist

Cyber criminals stole Rs 78.1 lakh from a gold loan firm based in Parel, Mumbai, by gaining unauthorized access to its internal loan management software. The cyber heist, which took place within an hour on July 13, led to 18 fraudulent transactions being cleared through a private bank without company approval or one-time passwords (OTPs). The Central Cyber police registered a case regarding the matter on July 17.

The Parel-based firm uses an internal Loan Management System (LMS) software named "Omnifin" to manage its transactions, vendors, and third-party details. To streamline operations, this software is integrated with the firm's private bank account via an authorized third-party API service provider, Paysprint Private Limited Company.

Under this integrated system, loan disbursement instructions are transferred directly to the bank once the software completes a process. Because the entire system is API-based, it automatically notifies the bank to transfer the amount, bypassing the need for manual OTPs or separate approvals.

According to the police, the unknown scammers tampered with the original bank details and system of the gold loan company to gain access to the Omnifin software and the API system. They then executed 18 unauthorized transactions, ranging between Rs 2 lakh and Rs 7 lakh each, between 10:49 AM and 12:18 AM on July 13.

The company's director, GM Amit, discovered the discrepancy on July 14 during a routine daily reconciliation. Upon investigation, the firm found that the entries did not match any approved loan cases or customer requests. The company filed a complaint on the 1930 Cyber Helpline on July 16, followed by an FIR on July 17.

The stolen funds were transferred to a finance company and various nationalised and private bank accounts across Jammu & Kashmir, Kerala, Maharashtra, and other states.

Cyber police have since contacted the nodal officers of the receiving banks to freeze the targeted accounts. Investigators are currently gathering details on the account holders and probing whether any internal company or bank staff were involved in the fraud.

Share

Related Stories