A Class 11 Dropout, YouTube Tutorials, and AI: Inside the ₹64-Crore Fake Banking App Racket Busted in Surat

Contents

An 18-year-old from Kanpur who never finished high school has been named by police as the alleged architect behind one of the more startling cybercrime cases to surface in India this year — not because of who he is, but because of what he could apparently build without any formal training. Gujarat’s Surat Cyber Crime Cell says Rohit Virendrasinh Shakya, a Class 11 dropout, used YouTube tutorials and AI tools to design 121 fake banking and government apps that were downloaded over 21,000 times and allegedly enabled fraud worth more than ₹64 crore across multiple states.

Here’s what the investigation has revealed so far, and why this case says more about the state of low-cost, AI-assisted cybercrime in India than almost any single arrest in recent memory.

How the case broke open

The trail started with a single victim. A businessman in Surat’s Adajan area received a file over WhatsApp made to look like “PNB One,” Punjab National Bank’s official app. Believing it genuine, he installed it — and lost ₹5 lakh soon after. He reported the loss through India’s national cybercrime helpline, 1930, which triggered a formal investigation by the Surat City Cyber Crime Cell.

What began as a routine fraud complaint turned into a much larger technical investigation. Officers traced the fake APK file back to its developer, eventually tracking him to a hotel in Kanpur, Uttar Pradesh — where, according to reports, he had traveled to meet his girlfriend. He was arrested there, and police seized his laptop, mobile phones, and other digital devices.

The scale of what he allegedly built

According to Additional Commissioner of Police Karanraj Vaghela, digital forensic analysis of Shakya’s devices uncovered a far bigger operation than a single fake app:

  • 121 malicious APK files, closely mimicking real banking, payment, and government platforms — including SBI, PNB, Axis Bank, UCO Bank, American Express, BigBasket, PM Kisan, and RTO e-challan apps.
  • 21,672 installs of these fake apps across the country.
  • 2,928 devices police say were fully compromised.
  • 54,094 fraudulent transactions, adding up to roughly ₹64.38 crore in losses.

Investigators say the operation wasn’t a one-off — Shakya had allegedly been developing and refining these malicious apps for around two years, since he was about 16.

A two-app system, and a subscription business model

What makes the case notable from a technical standpoint is the apparent sophistication of the setup, given the alleged developer’s lack of formal training. Police say Shakya built his malware in pairs: one app installed on the victim’s phone, and a second “admin” app used by the fraudsters themselves. Through the admin app, cybercriminals could reportedly monitor OTPs, intercept banking credentials, and pull sensitive financial data off a victim’s device in real time.

Rather than selling the malware as a one-time product, police allege Shakya ran it like a software service — charging cybercrime gangs an upfront fee of around ₹15,000 to deploy an app, plus a recurring monthly fee (reports place it between ₹10,000 and ₹15,000) for continued access, updates, and support. That subscription structure allegedly connected him to established fraud networks operating out of Jamtara in Jharkhand — long known as a hub for phone-based banking scams — as well as groups in Haryana and Rajasthan.

The AI angle

What’s drawing particular attention is how Shakya reportedly acquired the skills to build all this: no cybersecurity degree, no formal coding bootcamp, and only a Class 11 education. Police say he taught himself through YouTube tutorials and leaned heavily on AI tools to write and refine the malicious code, alongside Telegram as his primary channel for distributing finished APK files to buyers.

That combination — freely available tutorials, AI coding assistance, and encrypted distribution via Telegram — is becoming a recognizable pattern in Indian cybercrime cases. It significantly lowers the technical bar for producing convincing, functional malware. A task that once required a trained developer or a black-market toolkit purchase can increasingly be assembled by a teenager working alone, iterating with AI assistance until the fake app looks and behaves closely enough like the real thing to fool cautious users.

Why this case matters beyond one arrest

A few things stand out here that go beyond the specifics of this one investigation:

1. The skills gap for building fraud tools is collapsing. This case is one of the clearer illustrations yet of how AI coding assistance is changing who can produce malware. It no longer takes a computer science background or years of experience — just persistence, tutorials, and iterative prompting.

2. Established fraud hubs are outsourcing development. The alleged connection to Jamtara-based networks suggests a division of labor emerging in Indian cybercrime: some groups specialize in social engineering and running the scam itself, while independent developers — sometimes teenagers, working alone — supply the technical tooling as a paid service.

3. Fake apps are exploiting brand trust, not just technical vulnerabilities. None of the 121 apps needed to defeat sophisticated bank security — they only needed to look convincing enough, distributed through informal channels like WhatsApp, for a user to trust and install them. That’s a user-behavior problem as much as a technology one.

4. It raises hard questions for AI tool providers and platforms. As with the Play Store liability questions raised in unrelated recent cases, this arrest will likely add to a broader conversation in India about what responsibility, if any, AI tool makers and messaging platforms like Telegram bear when their tools are used to build and distribute fraud infrastructure at this scale.

What happens next

Police say forensic examination of Shakya’s seized devices is ongoing, with investigators now working to identify additional victims, trace possible accomplices, and map how far the network of buyers extended across other states. Given the subscription-style access he allegedly sold, more arrests — of both fraud-gang operators and possibly other developers — could follow.

For everyday users, the case is a pointed reminder that a banking app’s realistic look and feel is no longer a reliable signal of legitimacy. Officials continue to advise downloading banking and government apps only from official app stores or verified bank websites — never from links shared over WhatsApp or Telegram, however convincing they appear.

Picture of Adarsh Singhal & Associates
Adarsh Singhal & Associates

Leave a Reply

Your email address will not be published. Required fields are marked *