
What Happened
On July 22, a single complaint filed at Govandi police station in Mumbai cracked open a much larger operation. The complainant told police he’d been contacted by callers claiming to represent HDFC ERGO’s health insurance office, who informed him he was entitled to a “No Claim Bonus” of ₹1,53,825 on his policy — but that a “specific procedure” needed to be completed first to claim it. That procedure involved handing over his credit card details. The fraudsters then used those details to withdraw ₹3.43 lakh through online transactions.
That one complaint triggered an investigation that, by July 14, 2026, had led Mumbai Police to raid three separate fake call centres operating out of Kurla and Asalfa (Govandi jurisdiction), arrest 12 people, and recover assets worth over ₹17 lakh — computers, laptops, mobile phones, and gold coins among the seized items.
How the Scam Worked
The operation wasn’t a lone-wolf con — it was a structured, role-divided racket:
- Data acquisition: The gang obtained genuine policyholder data and SIM cards belonging to actual HDFC health insurance customers. Police separately arrested three additional individuals whose specific role was supplying this data and SIM cards to the call centre operators — indicating a data-leak-to-fraud supply chain rather than random cold-calling.
- Impersonation: Callers posed as representatives of the insurance company, using the victims’ real policy details to sound credible — a critical ingredient, since referencing an actual policy number or premium amount makes a scam call far harder to distinguish from a genuine one.
- The hook: A fabricated financial incentive (the “No Claim Bonus”) designed to make the victim eager to cooperate rather than suspicious.
- The extraction: Under the guise of processing this bonus, victims were walked through a “procedure” that ended with their card details in the fraudsters’ hands, followed by unauthorized online transactions.
Why This Case Is Significant
1. It reveals an insurance-fraud supply chain, not just a single call centre. Most reported scams end with “X call centre busted.” Here, police traced backward from one complaint to three call centres and a separate data-supply cell. That’s a meaningful escalation — it shows organized division of labor: some people harvest data and SIMs, others run the phone operation, and presumably a third layer launders or cashes out the stolen funds. Dismantling one node rarely stops the network; this bust appears to have taken out a fuller vertical slice of it.
2. Genuine customer data was the weapon. The fact that the fraudsters had accurate HDFC policyholder details — not just phone numbers scraped at random — points to a data breach or insider leak somewhere upstream, whether from the insurer, a third-party vendor, or an aggregator platform. That’s arguably the more urgent question for regulators than the call centre itself: where did this data come from, and how many other policyholders’ details are still circulating?
3. SIM card misuse adds an identity-fraud layer. Supplying SIM cards alongside customer data suggests the gang may have used these to receive OTPs or register alternate contact numbers linked to victims’ accounts — a common technique to bypass two-factor authentication on banking apps once card or account details are already compromised.
The Legal Angle
For a case like this, several statutory provisions come into play:
Bharatiya Nyaya Sanhita, 2023
- Section 318 (cheating) and Section 319 (cheating by personation) — directly applicable, since the callers impersonated insurance company representatives to induce the victim to part with money
- Section 61 (criminal conspiracy) — relevant given the multi-cell, coordinated structure of the operation
Information Technology Act, 2000
- Section 66C (identity theft) — for use of stolen card/account credentials
- Section 66D (cheating by personation using a computer resource) — squarely fits phone-and-online fraud of this kind
Insurance Regulatory and Development Authority of India (IRDAI) guidelines on data protection and outsourcing may also come under scrutiny if the leaked policyholder data is traced back to an insurer’s own systems or an authorized intermediary, since insurers are expected to maintain safeguards over customer data shared with call centres, agents, and third-party vendors.
RBI’s card-and-banking fraud framework — the unauthorized ₹3.43 lakh withdrawal raises the question of whether the bank’s fraud-monitoring systems should have flagged the transaction pattern, and whether the victim is entitled to reversal under RBI’s Limited Liability of Customers circular, depending on how quickly the fraud was reported.
What Customers Should Take Away
- A real “bonus” or refund from an insurer is never conditional on you sharing your full card number, CVV, or OTP over the phone. No genuine insurance process requires this.
- Verify independently. If someone claims to call from your insurer, hang up and call the company back on the number printed on your policy document or its official website — not a number the caller provides.
- Treat urgency as a red flag. Scams built around “claim this now or lose it” pressure are designed to short-circuit the skepticism a slower conversation would allow.
- Report immediately. Mumbai Police have reiterated that victims of cyber fraud should contact the national cybercrime helpline 1930 or the nearest police station without delay — faster reporting significantly improves the odds of freezing transferred funds before they’re withdrawn.
Closing Thought
This bust is a reminder that insurance fraud calls succeed not because victims are careless, but because the fraudsters arrive armed with real data that makes the pretext convincing. The call centre raid and arrests are a good outcome, but the more consequential question — where the underlying policyholder data leaked from, and how far it has already spread — is likely still being investigated. Until that supply-side question is answered, similarly-armed scams are likely to resurface under a different company’s name.