
A legal reading of Operation Mule Hunt 2.0 — the statutes in play, the evidentiary questions ahead, and what it means for the account holder caught in between.
The Cyber Centre of Excellence (CCOE) of Gujarat CID Crime has dismantled a sprawling interstate cyber fraud network under ‘Operation Mule Hunt 2.0’, arresting 19 accused linked to 146 cybercrime cases registered across 21 states. Investigators say the syndicate routed suspicious financial transactions exceeding ₹250 crore through fake and rented bank accounts — a network with threads running from Gujarat to Dubai.
The operation cracked five major cases registered in Vadodara, Bhavnagar, Surat, Patan, and Gandhinagar. In one case alone, a single accused’s account carried transactions worth over ₹161 crore. One arrested MBA student from a private Vadodara university had opened more than ten bank accounts in the names of friends and acquaintances, handing them over to the syndicate — accounts through which ₹7.40 crore in fraudulent transactions were routed.
19Accused Arrested
146Linked Cases · 21 States
₹250Cr+Traced Transactions
1. Anatomy of the Fraud
What Is a “Mule Account,” and Why Does It Matter Legally?
A mule account is a bank account knowingly or unknowingly handed over to cybercriminals to receive, move, or launder money obtained through online fraud. The modus operandi described by investigators was methodical:
- Account holders were lured with commissions and asked to hand over Aadhaar cards, PAN cards, chequebook photographs, ATM card images, and internet banking credentials.
- To bypass repeated OTP verification, holders were persuaded to install malicious APK files, letting the syndicate operate the accounts remotely.
- Bulk-mode banking facilities were exploited to rapidly move fraud proceeds through multiple fake and rented accounts, making the trail harder to follow.
Legally, whether or not the account holder knew the exact purpose their account served, they can still be drawn into liability under India’s money-laundering and IT statutes. The defence of “I didn’t know” tends to collapse quickly once investigators establish that credentials were handed over in exchange for a commission — that exchange itself signals knowledge that something irregular was underway.
2. The Statutory Framework
Which Laws Actually Apply Here
Bharatiya Nyaya Sanhita (BNS), 2023
Police have booked the accused under relevant BNS provisions — India’s replacement for the Indian Penal Code. The operative charges typically centre on cheating, criminal conspiracy, and forgery, the standard building blocks for a large-scale fraud syndicate case.
Information Technology Act, 2000 — Section 66D
Section 66D criminalises “cheating by personation using a computer resource” — where a person misuses another’s identity through electronic means to commit fraud. The use of malicious APKs to hijack bank credentials and operate accounts remotely sits squarely within this provision.
Prevention of Money Laundering Act (PMLA), 2002
Where proceeds of crime are “layered” across multiple accounts to obscure their origin, this crosses into money laundering. Given the scale (₹250 crore+) and the international dimension (Dubai), it’s plausible the Enforcement Directorate could open a parallel investigation — PMLA proceedings typically run independently of, and alongside, the police’s own case.
RBI Regulatory Guidelines
The Reserve Bank of India has issued tightened KYC and transaction-monitoring norms specifically aimed at mule-account detection. Banks carry a due-diligence obligation to flag unusual patterns — such as large, sudden inflows into freshly opened accounts. Where that due diligence fails, banks themselves can face regulatory exposure.
3. Procedural Complications
Jurisdiction, Cross-Border Links, and Digital Evidence
Interstate Jurisdiction
With linked cases spread across 21 states, coordination becomes the case’s central logistical challenge. The National Cyber Crime Reporting Portal (NCCRP) and the Indian Cyber Crime Coordination Centre (I4C) play a key role here, stitching together FIRs filed in different states into a coherent, shared investigation. Cross-state arrests and evidence-gathering still require proper coordination under the procedural code (BNSS, formerly CrPC).
The Dubai Link
The alleged Dubai connection adds real complexity. Cases with a foreign nexus typically require cooperation through a Mutual Legal Assistance Treaty (MLAT) — a process that is often slow and procedurally heavy. India’s extradition arrangements and information-sharing channels with the UAE could become relevant as the investigation deepens.
Digital Evidence Admissibility
Evidence such as malicious APK files, banking-app access logs, and digital transaction trails must be certified correctly to be admissible in court, under Section 63 of the Bharatiya Sakshya Adhiniyam (the provision succeeding the old Section 65B of the Evidence Act, governing electronic records). Digital evidence gathered without the correct procedural certification is vulnerable to challenge at trial.
4. The Human Question
How Liable Is the Unwitting Mule?
The hardest legal question in cases like this one isn’t about the ringleaders — it’s about the account holders in the middle. Many victims are lured under the guise of “easy income” or a “loan agent” who needs their ATM card or account details temporarily. Legally, if a person knowingly exchanges their bank account, OTP, or credentials for money, they don’t escape criminal liability simply because they didn’t know exactly what crime the funds were tied to. That’s precisely why cybersecurity officials keep repeating the same warning: never share bank account details, ATM cards, or OTPs under any circumstances.
“The accused lured account holders with commissions and collected their Aadhaar cards, PAN cards, cheque book photographs, ATM card images and internet banking credentials… To avoid repeated OTP verification, they persuaded account holders to install malicious APK files, allowing the syndicate to operate the accounts remotely.”— Dr. Rajdeepsinh Zala, SP, Cyber Centre of Excellence
At the same time, a genuine subset of account holders are deceived without any intent to break the law — they have no idea their account has become a transit point for fraud, and yet find it frozen, with police and court visits to follow. This is as much a policy challenge as a legal one: investigating agencies carry the responsibility of distinguishing the knowing facilitator from the unwitting victim, so that innocent people aren’t punished alongside actual offenders.
5. Closing Assessment
What This Case Signals
This crackdown shows that cyber fraud in India has moved well past isolated scams — it now operates as an organised, interstate, and increasingly international financial crime network. Legally, the case sits at the intersection of three regimes: the BNS, the IT Act, and the PMLA — and further involvement from the Enforcement Directorate and other central agencies down the line would not be surprising.
Cases like this reinforce a broader need: strengthening banking regulation, digital literacy, and inter-agency coordination together, so that organised financial-crime infrastructure like mule-account networks can be meaningfully disrupted — not just after the fact, but before the money moves.