Hackers Exploit a Software Flaw to Steal ₹7.34 Crore From a Gujarat Bank

Contents

Ten arrests in, a legal look at what changes when the crime isn’t a duped account holder — but a breached Core Banking System itself.

The Cyber Centre of Excellence of Gujarat CID Crime has arrested three more people in connection with the alleged hacking of the Bhavnagar District Co-operative Bank Limited, taking the total number of arrests in the case to ten. According to investigators, the cybercrime syndicate allegedly breached a vulnerability in the bank’s Core Banking System (CBS) software and siphoned off ₹7.34 crore through a sophisticated digital fraud.

Investigators say the operation was months in the making. A phishing email impersonating a business vendor was allegedly sent to a bank officer, carrying malware that quietly infected the CBS once opened. The syndicate then allegedly gained admin-level access, replaced the registered mobile numbers on four dormant accounts with numbers under their control, and manufactured a fictitious balance of roughly ₹7.35 crore — before draining it into the real banking system over a closed weekend, when the bank’s headquarters were empty and no one could intervene in real time.

10Total Arrests So Far

127+Accounts Used to Route Funds

₹7.34CrSiphoned From the Bank

1. Anatomy of the Breach

This Isn’t a Mule Case — It’s a Direct Hack

Most cyber fraud cases in this series involve a duped or complicit account holder handing over access to a real, already-existing account. This one is structurally different: the fraud didn’t originate with a victim’s mistake — it originated inside the bank’s own infrastructure. That distinction matters legally, because it shifts the case from “cheating individuals” to “compromising critical financial infrastructure.”

  1. Social engineering entry point: A phishing email disguised as vendor correspondence was allegedly sent to a bank officer months in advance, carrying malware in an attachment.
  2. Silent compromise: Once opened, the malware allegedly infected the CBS software in the background, giving the syndicate ongoing access without triggering alerts.
  3. Target selection: Investigators say the group specifically targeted dormant accounts — chosen precisely because no customer would be actively monitoring them.
  4. Identity substitution: The registered mobile numbers on those accounts were allegedly swapped for numbers controlled by the accused, defeating OTP and alert-based safeguards.
  5. Ghost balance creation: A fictitious account balance of roughly ₹7.35 crore was allegedly generated within the system — money that never actually existed as a real deposit.
  6. Extraction on a blind weekend: The funds were allegedly moved out through more than 127 accounts within minutes, timed for a weekend when the bank’s headquarters was closed and unstaffed.

2. The Statutory Framework

A Fundamentally Different Set of Charges

Information Technology Act, 2000 — Section 43

Section 43 penalises unauthorised access to a computer system, introduction of malware, and unauthorised alteration or manipulation of data — precisely what the CBS intrusion and ghost-balance creation describe. It’s the civil-liability backbone of any hacking case, alongside the criminal charge that follows.

Information Technology Act, 2000 — Section 66 & 66C

Section 66 criminalises the acts described in Section 43 when done dishonestly or fraudulently, while Section 66C addresses identity theft — the alleged swapping of registered mobile numbers to hijack account identity and bypass authentication is a direct fit.

Bharatiya Nyaya Sanhita (BNS), 2023

Cheating, criminal conspiracy, and forgery of electronic records round out the case against both the hackers and the ten (and counting) individuals who allegedly operated the 127-plus accounts used to receive and route the stolen ₹7.34 crore.

Prevention of Money Laundering Act (PMLA), 2002

Some reports indicate part of the siphoned amount was converted into cryptocurrency and moved overseas via blockchain transactions — a classic layering-and-integration pattern. If confirmed, that cross-border crypto trail is exactly the kind of fact pattern that draws the Enforcement Directorate into a parallel PMLA investigation alongside the state police case.

3. Institutional Liability

Who Answers for the Vulnerability Itself?

A hacking case against the perpetrators is only half the legal picture. The other half is what happens to the institutions whose failures made the breach possible — and here, two separate parties come into the frame.

The Bank’s Own Exposure

The Reserve Bank of India’s cybersecurity framework for banks — including co-operative banks — mandates baseline safeguards: patch management, transaction-monitoring systems, and staff protocols against phishing. If a fictitious ₹7.34 crore balance and 127-plus rapid transfers went undetected until the next business day, that raises real questions about whether the bank’s monitoring systems met regulatory expectations. Bank officials have themselves pointed to “deficiencies in cybersecurity” as having enabled the fraud — an admission that could matter both for RBI’s regulatory response and for any customer claims regarding fund security.

The Software Vendor’s Exposure

Reports suggest the bank’s Core Banking System provider had reportedly already been blacklisted by other banks over prior security concerns before this breach occurred. If that’s borne out, the vendor’s own liability — contractual, and potentially under Section 43A of the IT Act, which addresses compensation for failure to protect sensitive data through reasonable security practices — becomes a live question, separate and apart from the criminal case against the hackers themselves.

“They hacked the system and, due to deficiencies in the cybersecurity, they were able to make ghost entries and then transfer the amount, resulting in fraud. Most of the customers of our bank are farmers.”— Jitendrakumar K. Kevadiya, General Manager, Bhavnagar District Co-operative Bank

4. Jurisdiction and Evidence

A Cross-Border, Multi-State Trail

Investigators reportedly traced some of the unauthorised access to IP addresses linked to China and Russia, though the precise origin remains under verification. If confirmed, that places part of the investigation squarely in cross-border territory, where Indian agencies typically depend on Mutual Legal Assistance Treaty (MLAT) requests and international cybercrime cooperation channels — processes that are slow by design and rarely yield quick extraditions.

Closer to home, mobile-phone analysis of the arrested accused reportedly surfaced links to more than 15 cybercrime cases across at least eight states, suggesting this same account-operating network was reused across multiple, unrelated frauds — not built solely for the Bhavnagar heist. That reuse pattern is significant evidentially: it lets investigators connect this case to other pending FIRs through shared account numbers and device data, but it also means the digital evidence chain (device forensics, CBS access logs, transaction timestamps) will need rigorous certification under Section 63 of the Bharatiya Sakshya Adhiniyam to hold up when multiple linked cases eventually reach trial.

5. Closing Assessment

What This Case Signals

The Bhavnagar case marks a meaningful escalation from the mule-account cases dominating this series: here, the attackers didn’t need to deceive a single customer — they went straight for the bank’s own software. For India’s co-operative banking sector in particular, which often runs on smaller budgets and older core banking infrastructure than commercial banks, this case is likely to accelerate regulatory pressure toward mandatory cybersecurity audits and vendor accountability, not just customer-facing fraud awareness.

For the ten arrested so far, the legal exposure runs on two tracks — the alleged hackers face IT Act and BNS charges for the intrusion itself, while those who supplied or operated the 127-plus receiving accounts face liability for knowingly facilitating the movement of stolen funds, regardless of whether they understood the money’s exact origin.

Picture of Adarsh Singhal & Associates
Adarsh Singhal & Associates

Leave a Reply

Your email address will not be published. Required fields are marked *