Valsad Cyber Police Bust Telegram-Based Mule Account Network

Contents

What the arrest reveals about India’s evolving legal framework for mule accounts, encrypted-platform fraud, and Operation Mule Hunt 2.0.

Valsad, Gujarat · Operation Mule Hunt 2.0

The arrest of an alleged mastermind by the Valsad Cyber Crime Police has drawn fresh attention to one of Gujarat’s largest ongoing anti-fraud initiatives. The accused is alleged to have used encrypted platforms such as Telegram and WhatsApp, operating under fabricated identities, to recruit people across several states and persuade them to hand over debit cards, cheque books, and bank account credentials. These accounts allegedly formed the backbone of a “mule account” network through which more than Rs 5.21 crore in fraudulent transactions were routed nationally. This piece examines the legal dimensions of the case: the offences likely invoked, the evidentiary challenges of prosecuting encrypted-platform crime, and what the case signals about the direction of India’s cyber-financial enforcement strategy.

Case Snapshot

  • Agency: Valsad Cyber Crime Police, Gujarat
  • Initiative: Operation Mule Hunt 2.0 (statewide, led by Gujarat CID Crime’s Cyber Centre of Excellence)
  • Modus operandi: Recruitment of account holders via encrypted Telegram/WhatsApp identities; collection of debit cards, cheque books, and banking credentials
  • Scale alleged: Transactions exceeding Rs 5.21 crore routed through the network
  • Wider context: As part of the same statewide operation, Gujarat Police have registered well over a hundred FIRs and made hundreds of arrests, tracing cumulative cyber-fraud-linked transactions running into thousands of crores of rupees across the state

1. What Is a “Mule Account” in Legal Terms?

A mule account is a bank account — knowingly or unknowingly provided by its holder — that is used by cybercriminals to receive, layer, and transfer money obtained through online fraud. Legally, mule accounts sit at the intersection of two very different categories of liability:

  • Knowing participants who rent, sell, or hand over their accounts for a commission, fully aware that the funds are proceeds of crime. These individuals face direct criminal liability as co-conspirators or abettors.
  • Unwitting account holders who are duped — often through fake job offers, “easy income” schemes, or social engineering on messaging apps — into surrendering their banking credentials without understanding the end use. Even here, courts and investigating agencies increasingly treat gross negligence or wilful blindness as insufficient defence once credentials have facilitated a proven fraud chain, although intent remains central to sentencing.

The Valsad case appears to fall into the first category: the accused is alleged to be the organiser who actively recruited others and structured the network, rather than a passive account holder.

2. Likely Legal Provisions Invoked

While the specific charge-sheet in this case has not been fully detailed publicly, cases of this kind under Operation Mule Hunt 2.0 have typically invoked a combination of provisions from the Bharatiya Nyaya Sanhita (BNS) — which replaced the Indian Penal Code — and the Information Technology Act, 2000. The likely legal architecture is as follows:

ProvisionRelevance to the Case
Section 318, BNS (Cheating)Covers the underlying deception used to induce victims to part with money, and the deception used to recruit mule account holders under false pretences.
Section 61, BNS / Section 120B analogue (Criminal Conspiracy)Applicable where multiple individuals — recruiters, account holders, withdrawal agents — act in concert as an organised syndicate.
Section 66D, IT Act, 2000Punishes cheating by personation using a computer resource — directly relevant where fake identities were created on Telegram and WhatsApp to recruit victims and account holders.
Section 66C, IT Act, 2000Identity theft — potentially applicable if the fraudsters used stolen KYC documents or impersonated real persons while opening or operating accounts.
Prevention of Money Laundering Act (PMLA), 2002May be invoked if the “layering” of funds through multiple mule accounts is treated as money laundering of proceeds of a scheduled offence (cyber fraud/cheating).
Reserve Bank of India KYC Master DirectionsNot a criminal provision but relevant to regulatory liability of banks that opened or failed to flag suspicious mule accounts despite red flags in transaction patterns.

3. The Encrypted-Platform Problem

A defining legal challenge in this case is the alleged use of Telegram — a platform known for strong encryption and limited cooperation with law enforcement data requests compared to domestically regulated intermediaries. This raises several practical and jurisprudential issues:

  1. Intermediary liability and data requests: Under the IT Act and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, intermediaries are required to cooperate with lawful government requests for information. Foreign-headquartered platforms with limited Indian presence, however, often respond slowly or incompletely to Indian law enforcement requests, complicating attribution of anonymous or pseudonymous accounts to real individuals.
  2. Attribution of fake identities: Establishing that a specific accused person controlled a given Telegram handle typically relies on circumstantial digital evidence — device forensics, IP logs, linked phone numbers, payment trails, and financial transaction records — rather than a direct admission from the platform itself.
  3. Cross-border evidentiary cooperation: Where servers or platform operators are based outside India, Mutual Legal Assistance Treaty (MLAT) requests may be required, which are often time-consuming and can slow prosecution timelines considerably.

4. Jurisdiction Across Multiple States

Because the alleged network’s mule accounts were used to route money linked to victims and complaints across the country, the case raises classic multi-jurisdictional questions. Under the Bharatiya Nagarik Suraksha Sanhita (BNSS), the successor to the CrPC, cybercrime offences with effects spread across multiple states can typically be investigated and prosecuted from any jurisdiction where a constituent act occurred or where the complaint was first registered — a principle that Indian cybercrime cells rely on heavily. This is reinforced procedurally by the National Cyber Crime Reporting Portal (NCCRP) and the Indian Cyber Crime Coordination Centre (I4C), both of which allow state police units, such as Gujarat’s Cyber Centre of Excellence, to correlate acknowledgement numbers and FIR data from other states against accounts traced locally.

5. Operation Mule Hunt 2.0: A Legal Strategy Shift

What distinguishes this case from a standalone fraud FIR is its place within a coordinated, state-directed enforcement programme. Operation Mule Hunt 2.0 reflects a deliberate legal and investigative strategy: targeting the financial infrastructure of fraud — the mule accounts themselves — rather than pursuing individual scam calls or messages in isolation. Legally, this has several implications:

  • It enables investigators to build conspiracy and syndicate-level charges rather than isolated cheating cases, which typically carry heavier sentencing exposure and support asset attachment under the PMLA.
  • It supports faster account freezing under Section 102 of the BNSS (analogous to the earlier Section 102 CrPC power to seize property suspected to be connected with an offence), which is critical to preventing further dissipation of fraud proceeds.
  • It creates a data-driven prosecution model, using banking records and NCCRP acknowledgement numbers as a evidentiary backbone linking a single arrested individual to fraud complaints filed by victims in other states, even where those victims and the accused never had direct contact.

6. Open Legal Questions

Several questions are likely to shape how this case, and others like it, proceed through trial:

  • Mens rea of recruited account holders: Courts will need to distinguish between account holders who were themselves defrauded into providing credentials and those who knowingly profited, which materially affects whether they are treated as co-accused or as victims-turned-witnesses.
  • Compensation and restitution: With victims spread across multiple states, coordinating restitution or the return of traced funds is often legally and procedurally complex, particularly once money has passed through several layered accounts.
  • Admissibility of platform-sourced digital evidence: Chat logs, screenshots, and account metadata drawn from Telegram will need to satisfy the certification requirements under Section 63 of the Bharatiya Sakshya Adhiniyam (the evidence law successor to Section 65B of the Evidence Act) to be admissible in court.

Conclusion

The Valsad arrest is a useful illustration of how Indian cyber-financial crime enforcement is maturing — moving from reactive, complaint-driven investigation toward proactive, intelligence-led operations that target the banking infrastructure enabling fraud at scale. Legally, the case will likely test the interplay between the BNS, the IT Act, the PMLA, and evolving evidentiary standards for encrypted-platform communication. Its outcome may offer a template for how mule-account masterminds — as distinct from the account holders they recruit — are charged and prosecuted going forward.

Picture of Adarsh Singhal & Associates
Adarsh Singhal & Associates

Leave a Reply

Your email address will not be published. Required fields are marked *