When the Bankers Are In On It: Two UP Bank Employees Held in ₹1.50 Crore Trading Fraud

Contents

A cyber fraud investigation in Panchkula has taken a troubling turn — the trail didn’t lead to hardened scammers hiding behind fake IDs, but to two working bank employees accused of using their own professional access to help launder stolen money.

The Arrests

Haryana’s cyber crime team has arrested two bank officials from Uttar Pradesh — Rishabh Vaish of Sitapur and Anupam Kumar Singh of Hardoi — in connection with an online trading fraud worth approximately ₹1.50 crore. Both have been remanded to seven days of police custody as investigators continue questioning them about the wider network they’re allegedly connected to.

Their arrest brings the total number of people held in this case to eight, making it one of the more expansive mule-account busts to emerge from Haryana’s cyber crime units recently.

How It Started: A Bengaluru “Construction Company” and a Fake Message

The case traces back to a complaint filed by a Panchkula resident through the government’s cyber crime portal. According to police, the victim received a message back in November 2023 from an ID claiming to represent a construction company based in Bengaluru — the opening move in what would unfold into an online trading fraud costing him roughly ₹1.50 crore.

While full details of exactly how the trading scam played out haven’t been made public, the pattern matches a familiar template seen across dozens of similar Indian cases this year: initial contact through a seemingly credible business identity, followed by persuasion into a fraudulent investment or trading scheme, and the eventual transfer of large sums that vanish through a maze of bank accounts.

Following the Money to a Bank Employee’s Account

The investigation’s breakthrough came when police traced roughly ₹20 lakh of the fraudulent proceeds to a bank account belonging to Sandeep Kumar Singh, also of Hardoi, UP. He was arrested on June 25.

Under questioning, Sandeep reportedly revealed that his own account had been opened and operated by two friends — Rishabh Vaish and Anupam Kumar Singh — who, notably, were themselves employed at a bank. Acting on this, police laid a trap and arrested Rishabh and Anupam on June 28 and 29, respectively.

This is where the case becomes more than a routine mule-account bust: the two accused weren’t outsiders paying someone to open a random account for a commission — they were bank insiders allegedly using their position and understanding of banking processes to open or facilitate fraudulent accounts that channeled stolen funds.

The Wider Network

Alongside the three men from Hardoi and Sitapur, five more accused have been arrested in connection with the same case:

AccusedLocation
Rajesh KumarEtah, UP
Aqib AliLakhimpur Kheri, UP
AkashBijnor (arrested in Gurgaon)
Vishal KumarHanumangarh, Rajasthan
MonuLakhimpur Kheri, UP

That’s eight arrests spanning four districts across two states, illustrating how a single ₹1.50 crore fraud complaint unraveled into a geographically dispersed network. Police recovered a large number of mobile phones and dozens of ATM/debit cards during the arrests — standard tools of the mule-account trade, used to control multiple accounts and withdraw or transfer funds quickly before banks can freeze them.

Why Bank Employees in the Mix Changes the Calculus

Most mule-account cases involve people recruited from outside the banking system — students, unemployed youth, or small business owners persuaded (or paid) to hand over their account credentials. When actual bank employees are implicated, the risk profile shifts considerably:

1. Insider knowledge undermines the system’s own safeguards. Bank staff understand exactly what red flags fraud-detection systems look for — unusual transaction volumes, mismatched KYC details, rapid fund movement — and can potentially help structure transactions to avoid triggering them.

2. Trust is the currency being exploited. Just as recent CEO-impersonation frauds have shown criminals targeting the authority of bank branch managers to move money, this case shows the same institutional trust being exploited from the inside — not by deceiving a bank employee, but allegedly by having one participate directly.

3. It complicates accountability. When a bank’s own staff are implicated in opening or operating accounts for cyber fraud proceeds, it raises harder questions for the institution itself — about hiring vetting, internal account-monitoring controls, and whether more employees across more branches may be quietly involved in similar schemes.

This isn’t an isolated pattern nationally. Other recent Haryana investigations have similarly traced fraud proceeds back to networks where individuals supplied bank accounts to cyber criminals for a commission, and separate cases elsewhere in India have implicated bank managers and officials directly in facilitating fraudulent account openings tied to crores in stolen funds — a sign that mule-account infrastructure increasingly leans on people with legitimate access to the banking system, not just outsiders gaming it from a distance.

What Happens Next

With seven days of police custody granted, investigators will likely focus on:

  • Establishing exactly how Rishabh and Anupam used their positions or access to facilitate the account used to launder ₹20 lakh of the ₹1.50 crore fraud
  • Determining whether other accounts tied to the two employees carried proceeds from unrelated fraud cases — a common discovery once a single mule account is scrutinized against India’s National Cyber Crime Reporting Portal
  • Tracing the recovered phones and cards to identify additional members of the eight-person network’s upstream and downstream connections
  • Establishing whether the bank itself had any indication of irregular account activity that went unflagged

A Broader Warning

For an investment or trading fraud that began with a single unsolicited message in late 2023, this case has now grown into an eight-person, cross-state investigation — with two of the accused holding jobs that were supposed to make the banking system safer, not easier to exploit. It’s a reminder that mule-account networks, the backbone of most large-scale cyber fraud in India today, don’t only recruit from the margins — they actively seek out people with institutional access, including those working inside the very banks meant to catch them.

The investigation is ongoing, and further arrests linked to the network remain likely as police continue tracing the money trail.


This article is based on reporting from Haryana Police’s cyber crime unit regarding arrests made on June 25, 28, and 29, 2026, in connection with a ₹1.50 crore online trading fraud case. Investigation into the wider network is ongoing, and further details may emerge as the probe continues.

Picture of Adarsh Singhal & Associates
Adarsh Singhal & Associates

Leave a Reply

Your email address will not be published. Required fields are marked *