Delhi-focused information on PMLA, ED and economic-offence proceedings+91 82944 31232ankitsingh.legum@gmail.com

Cyber Crime / Digital Financial Fraud

Call Centre-Based Scam Operations in India: Investigating Cyber Fraud Networks, Digital Evidence, Mule Accounts and PMLA

A modern fake call-centre operation is ordinarily not limited to one fraudulent caller. It may function as an organised cyber-fraud network involving victim databases, false digital identities, VoIP infrastructure, spoofed telephone numbers, scripted callers,

By Advocate Ankit Kumar Singh

CYBER CRIME • FAKE CALL CENTRES • DIGITAL EVIDENCE • MONEY TRAILS • PMLA

Direct Answer: A modern fake call-centre operation is ordinarily not limited to one fraudulent caller. It may function as an organised cyber-fraud network involving victim databases, false digital identities, VoIP infrastructure, spoofed telephone numbers, scripted callers, specialised closers, remote-access software, mule bank accounts, payment handlers, cryptocurrency conversion and final beneficiaries.

The communication fraud and the financial laundering trail must be investigated together.

A typical network may operate through the following sequence:

Victim Data → Fake Institutional Identity → VoIP or Spoofed Call → Psychological Manipulation → Payment Extraction → Mule Accounts → Layering or Conversion → Final Controller or Asset

Important: A legitimate call centre, BPO, customer-support company or technology service does not become unlawful merely because it operates at night, serves overseas customers, uses VoIP, permits remote working or maintains cloud-based systems.

Criminal liability depends upon the actual deception, individual knowledge, technical control, financial benefit, evidence and applicable legal provisions.

Contents

  1. What is a call-centre-based scam operation?
  2. How fake call centres evolved into organised networks
  3. Organisational structure of a fraudulent call centre
  4. Complete modus operandi
  5. Victim selection and data acquisition
  6. Caller-ID spoofing, VoIP and cloud infrastructure
  7. Psychological manipulation and digital-arrest threats
  8. Remote-access and technical-support fraud
  9. How money is extracted from victims
  10. Mule accounts, gift cards, hawala and cryptocurrency
  11. Digital evidence examined during investigation
  12. Financial evidence and beneficiary tracing
  13. Information Technology Act and BNS provisions
  14. Telecom, TRAI and OSP compliance
  15. When can PMLA apply?
  16. Company, employee and service-provider liability
  17. Cross-border investigation challenges
  18. Steps for victims
  19. Compliance measures for legitimate call centres
  20. Frequently asked questions

What Is a Call-Centre-Based Scam Operation?

A call-centre-based scam is an organised fraud in which telecommunication and digital systems are used to contact, deceive and extract money or sensitive information from victims.

The operation may impersonate:

  • a bank;
  • a credit-card company;
  • a government department;
  • a police or investigative agency;
  • a taxation authority;
  • a court;
  • a technology company;
  • a software-security provider;
  • an e-commerce platform;
  • a courier company;
  • a telecom provider;
  • an investment adviser; or
  • a genuine customer-support service.

The victim may be persuaded or threatened into:

  • revealing an OTP;
  • disclosing card or banking credentials;
  • installing remote-access software;
  • transferring money to a “safe” account;
  • buying gift cards;
  • sending cryptocurrency;
  • purchasing gold or another commodity;
  • paying a fake fine;
  • disclosing identity documents; or
  • providing access to a computer or mobile phone.

Organised Network versus Individual Fraud

An isolated fraud may involve one person using a mobile telephone.

An organised call-centre network may involve:

  • dozens of workstations;
  • multiple shifts;
  • separate calling teams;
  • training departments;
  • supervisors;
  • technical infrastructure;
  • victim databases;
  • several bank accounts;
  • cash withdrawal teams;
  • crypto conversion;
  • multiple office locations; and
  • foreign controllers or beneficiaries.

How Fake Call Centres Evolved into Organised Cyber-Fraud Networks

India’s legitimate BPO, technology and telecommunications sectors provide major lawful employment and international services.

Fraudulent networks may misuse the same infrastructure advantages:

  • English-speaking workers;
  • affordable commercial space;
  • reliable broadband;
  • cloud-based communication;
  • remote working technology;
  • digital-payment access;
  • international time-zone operations;
  • technical-support knowledge; and
  • high-volume recruitment platforms.

The research paper describes the development from small informal groups into structured operations having:

  • recruitment systems;
  • training programmes;
  • approved scripts;
  • quality monitoring;
  • performance targets;
  • commission structures;
  • technical support;
  • data-management systems; and
  • financial settlement channels.

Why the Office May Appear Legitimate

A questioned centre may possess:

  • company-incorporation documents;
  • a commercial lease;
  • employee identity cards;
  • appointment letters;
  • salary records;
  • GST registration;
  • a website;
  • office branding;
  • workstations and headsets;
  • shift rosters; and
  • apparent overseas customer-service processes.

The existence of these records neither proves legitimacy nor proves fraud.

Investigators must identify whether the actual customer interaction, service agreement, call purpose and payment trail were genuine.

Organisational Structure of a Fraudulent Call Centre

1. Principal Organiser or Controller

The principal organiser may allegedly:

  • finance the premises;
  • choose the fraud model;
  • arrange victim data;
  • hire senior operators;
  • approve scripts;
  • control the bank or crypto trail;
  • receive the largest share of proceeds;
  • manage foreign contacts; and
  • move the operation after police attention.

2. Company or Front-Entity Manager

This person may arrange:

  • incorporation;
  • office lease;
  • internet connection;
  • salary accounts;
  • vendor payments;
  • utility bills;
  • employment documents;
  • bank mandates; and
  • an apparent lawful business identity.

3. Recruiter or Human-Resources Team

Recruiters may advertise positions such as:

  • international voice process;
  • technical support;
  • customer service;
  • lead generation;
  • sales executive;
  • collection executive; or
  • night-shift BPO associate.

The recruiter’s liability depends upon whether the person knew the actual operation and knowingly misrepresented it to employees.

4. Trainer

The trainer may teach:

  • the script;
  • foreign accents;
  • false institutional identity;
  • methods of overcoming suspicion;
  • fear and urgency techniques;
  • handling objections;
  • payment instructions; and
  • methods of avoiding detection.

5. Dialler or Initial Caller

The dialler generally:

  • makes first contact;
  • confirms identity details;
  • introduces the false problem;
  • creates initial trust;
  • records the victim’s response; and
  • transfers a receptive victim to a closer.

6. Verifier

A verifier may:

  • confirm victim data;
  • check financial capacity;
  • confirm whether remote access is available;
  • determine the likely payment method;
  • validate the success of the initial caller; and
  • transfer the call to a senior operator.

7. Closer

The closer may allegedly:

  • impersonate a senior official;
  • increase fear or urgency;
  • direct the payment method;
  • keep the victim continuously connected;
  • prevent consultation with family or bank personnel;
  • obtain gift-card numbers;
  • arrange a transfer or cash delivery; and
  • receive performance-linked commission.

8. Supervisor or Floor Manager

The supervisor may:

  • allocate leads;
  • monitor calls;
  • correct scripts;
  • set daily targets;
  • approve escalations;
  • maintain collection records;
  • discipline workers;
  • report to controllers; and
  • coordinate technical and payment teams.

9. Technical Administrator

The technical administrator may control:

  • VoIP accounts;
  • SIP servers;
  • virtual telephone numbers;
  • VPN access;
  • cloud servers;
  • CRM systems;
  • websites;
  • domain names;
  • remote-access software;
  • email accounts;
  • data backups; and
  • user credentials.

10. Financial Handler

The financial handler may:

  • arrange mule accounts;
  • obtain ATM cards;
  • collect banking credentials;
  • control OTP-linked SIM cards;
  • withdraw cash;
  • purchase cryptocurrency;
  • pay workers;
  • settle commissions;
  • maintain informal ledgers; and
  • deliver value to the final controller.

Complete Modus Operandi of a Call-Centre Scam

Phase 1: Creating the Operational Front

The network may obtain:

  • a company or partnership;
  • a rented office or apartment;
  • internet connections;
  • computers and routers;
  • VoIP or cloud subscriptions;
  • domain names;
  • fake customer-support websites;
  • recruitment advertisements;
  • bank or merchant accounts; and
  • victim databases.

Phase 2: Selecting Victims

Victims may be approached through:

  • cold calls;
  • phishing email;
  • SMS or messaging applications;
  • fake search advertisements;
  • fraudulent customer-care listings;
  • browser pop-ups;
  • malicious websites;
  • social-media advertisements;
  • stolen customer databases; or
  • earlier victim lists.

Phase 3: Establishing Credibility

The caller may already know:

  • the victim’s name;
  • address;
  • telephone number;
  • email address;
  • bank name;
  • recent purchase;
  • device type;
  • family details; or
  • partial account information.

This information may cause the victim to believe that the call is genuine.

Phase 4: Creating Fear, Urgency or Trust

The victim may be told that:

  • a computer is infected;
  • a bank account has been compromised;
  • a suspicious parcel was intercepted;
  • an identity document was misused;
  • a warrant has been issued;
  • a criminal case is pending;
  • a tax amount is unpaid;
  • a refund is available;
  • money must be moved to a safe account; or
  • immediate payment will prevent arrest.

Phase 5: Taking Control

The victim may be directed to:

  • remain continuously on the call;
  • avoid speaking to relatives;
  • avoid visiting the bank;
  • install remote-access software;
  • share the screen;
  • display bank balances;
  • transfer money;
  • purchase gift cards;
  • buy cryptocurrency; or
  • withdraw cash or purchase gold.

Phase 6: Moving the Proceeds

Money may move through:

  • personal mule accounts;
  • current accounts;
  • shell companies;
  • payment aggregators;
  • merchant accounts;
  • prepaid wallets;
  • gift-card redemption accounts;
  • cash withdrawals;
  • hawala channels;
  • cryptocurrency exchanges;
  • self-hosted wallets; and
  • foreign accounts.

Phase 7: Concealment and Relocation

The operation may:

  • delete cloud accounts;
  • change domain names;
  • replace SIM cards;
  • move to another premises;
  • rename the company;
  • change VoIP providers;
  • replace bank accounts;
  • remove laptops;
  • shift employees; or
  • operate through remote agents.

Victim Selection and Data Acquisition

Victim data is often the beginning of the investigation.

Possible Data Sources

  • data breaches;
  • phishing pages;
  • fake surveys;
  • malicious mobile applications;
  • unsecured databases;
  • dishonest insiders;
  • data brokers;
  • stolen customer lists;
  • social-media profiles;
  • public directories; and
  • earlier fraud campaigns.

Evidence Used to Identify the Data Source

  • spreadsheet metadata;
  • cloud-storage access logs;
  • email attachments;
  • payment made for the database;
  • chat messages with the supplier;
  • download history;
  • file-creation date;
  • shared-drive permissions;
  • database naming conventions; and
  • overlap between victims contacted by different agents.

Possession Is Not Always Ownership

A victim list found on an employee’s laptop may have been:

  • created by that employee;
  • downloaded automatically;
  • shared by a supervisor;
  • stored on a common drive;
  • received through email;
  • copied from another workstation; or
  • placed on the device after the employee stopped using it.

User attribution must be proved through technical and surrounding evidence.

Caller-ID Spoofing, VoIP and Cloud Infrastructure

What Is Caller-ID Spoofing?

Caller-ID spoofing makes a displayed telephone number appear different from the actual originating number.

The displayed number may resemble:

  • a bank;
  • a government department;
  • a police station;
  • a local number;
  • a foreign government office;
  • a technology company; or
  • a customer-support desk.

What Is VoIP?

Voice over Internet Protocol transmits voice communications through internet-based systems.

VoIP is widely used for legitimate business communication.

Relevant investigative records may include:

  • subscriber details;
  • SIP credentials;
  • assigned telephone numbers;
  • payment records;
  • call logs;
  • IP addresses;
  • administrator accounts;
  • routing configuration;
  • recorded calls;
  • login history;
  • cloud-server location; and
  • linked email accounts.

Why Cloud Infrastructure Creates Difficulty

Cloud-based systems may allow:

  • remote access from several locations;
  • rapid deletion;
  • foreign hosting;
  • shared administrator credentials;
  • temporary virtual servers;
  • automatic scaling;
  • minimal local storage; and
  • separation between the user and the physical server.

An office raid may therefore recover the laptops but not the complete calling or customer database.

Psychological Manipulation and “Digital Arrest” Threats

The paper identifies psychological manipulation as a core feature of the scam.

Fear-Based Claims

A victim may be falsely told that:

  • the victim is under digital arrest;
  • a parcel contains narcotics;
  • a bank account was used for money laundering;
  • an identity document was used in a crime;
  • a court warrant has been issued;
  • the victim will be deported;
  • a family member is in custody; or
  • the victim must transfer funds for verification.

There Is No Lawful “Digital Arrest” by Video Call

Indian police, courts and investigative agencies do not lawfully place a person under arrest merely by directing that person to remain connected on a video call and transfer money.

Common Manipulation Techniques

  • displaying forged identity cards;
  • displaying a fake warrant;
  • using police-station or courtroom backgrounds;
  • keeping the victim isolated;
  • using legal terminology;
  • transferring the call between fake officials;
  • threatening confidentiality consequences;
  • imposing a short deadline;
  • preventing bank verification; and
  • promising return of the transferred amount.

Evidence of Scripted Conduct

  • printed scripts;
  • shared electronic templates;
  • training videos;
  • recorded practice calls;
  • quality-assessment sheets;
  • supervisor comments;
  • call recordings;
  • CRM dispositions;
  • commission charts; and
  • repeated language across victim statements.

Remote-Access and Technical-Support Fraud

Remote-access software is legitimate technology used for support, administration and collaborative work.

It may be misused to:

  • view the victim’s screen;
  • control the device;
  • access online banking;
  • read OTP messages;
  • alter displayed information;
  • initiate transactions;
  • install additional software;
  • obtain stored passwords;
  • disable security; or
  • erase evidence.

Relevant Evidence

  • remote-access session ID;
  • session time;
  • source IP address;
  • destination device;
  • application logs;
  • screen recordings;
  • chat history;
  • download records;
  • bank-login activity;
  • browser history; and
  • transaction timestamp.

Presence of Software Is Not Conclusive

The installation of remote-support software does not independently prove fraud.

The prosecution must connect it with:

  • the deceptive communication;
  • the particular victim;
  • the relevant session;
  • the person controlling the device;
  • the resulting transaction; and
  • the accused person’s knowledge.

How Money Is Extracted from Victims

Bank Transfers

The victim may be instructed to transfer money to:

  • a personal account;
  • a recently opened current account;
  • a shell company;
  • a merchant account;
  • a payment gateway;
  • a purported government account; or
  • an account described as a verification or safe account.

Gift Cards

The victim may be asked to:

  • purchase gift cards;
  • send photographs of the cards;
  • read out redemption codes;
  • destroy the purchase receipt; or
  • buy cards from multiple stores.

Cash or Gold

The victim may be instructed to:

  • withdraw cash;
  • purchase gold or bullion;
  • place it in a package;
  • deliver it to a courier;
  • use a ride-service vehicle; or
  • send it to another State.

Cryptocurrency

The victim may be directed to:

  • open an exchange account;
  • buy a stablecoin;
  • transfer it to an external wallet;
  • use a crypto ATM where available;
  • complete a peer-to-peer transaction; or
  • send funds to an online trading platform.

Mule Accounts, Gift Cards, Hawala and Cryptocurrency

What Is a Mule Account?

A mule account is an account used to receive, transfer or withdraw suspected unlawful funds.

The account holder may be:

  • a knowing participant;
  • a person paid to supply the account;
  • a negligent account holder;
  • an identity-theft victim;
  • a genuine business whose account was misused;
  • an employee acting under instructions; or
  • a person whose credentials were controlled by another individual.

Evidence of Knowing Account Supply

  • commission payment;
  • delivery of ATM card;
  • sharing of internet-banking password;
  • sharing of OTP-linked SIM;
  • repeated high-value credits;
  • rapid withdrawals;
  • false business description;
  • chat with the account arranger;
  • cash handover evidence; and
  • opening several similar accounts.

Layering through Several Accounts

A common alleged flow is:

Victim → First Beneficiary → Mule Account → Second Layer → Cash Withdrawal or Crypto Purchase → Final Controller

Hawala Allegation

A hawala allegation should be supported by evidence concerning:

  • the foreign or remote payer;
  • the domestic recipient;
  • code or token;
  • cash settlement;
  • commission;
  • corresponding ledger;
  • communication between intermediaries; and
  • the ultimate beneficiary.

Cryptocurrency Trail

Relevant evidence may include:

  • exchange KYC;
  • bank funding records;
  • transaction hashes;
  • wallet addresses;
  • device access;
  • IP addresses;
  • peer-to-peer counterparties;
  • self-hosted wallet recovery material;
  • conversion into another token; and
  • cash-out transactions.

Digital Evidence Examined during Investigation

Evidence What It May Establish Important Defence Question
Call recordings Representation made to the victim Who made the call and is the recording complete?
VoIP logs Call account, time, destination and IP Who controlled the account credentials?
CRM records Victim allocation and call outcome Who created or edited the entry?
Scripts Standardised deception or training Was the document used by the accused?
Laptop Files, communications and access Who owned and actually used the device?
Mobile phone Chats, OTPs, calls and banking access Was it personal, shared or company-issued?
Router and server logs Network activity and user connections Were logs preserved and technically authenticated?
Email Instructions, recruitment and financial coordination Who controlled the account and were messages altered?
Cloud storage Shared databases and scripts Which user uploaded or downloaded the material?
Remote-access logs Control over a victim device Can the session be connected to the accused?
Domain and hosting records Control of fraudulent websites Was the registrant genuine or impersonated?
CCTV and access logs Presence and movement at the premises Does presence prove the alleged function?

Device Attribution

For every device, investigators should identify:

  • legal owner;
  • assigned user;
  • actual user;
  • administrator;
  • serial number or IMEI;
  • login credentials;
  • period of use;
  • files created;
  • accounts accessed;
  • network connections;
  • forensic image details;
  • hash value where generated; and
  • chain of custody.

Financial Evidence and Beneficiary Tracing

Bank Records

  • account-opening form;
  • KYC documents;
  • registered mobile number;
  • email address;
  • internet-banking IP logs;
  • beneficiary creation;
  • transaction statements;
  • ATM withdrawal records;
  • cheque images;
  • cash-deposit records;
  • device fingerprint; and
  • linked accounts.

Company Records

  • incorporation records;
  • directors;
  • shareholders;
  • beneficial owners;
  • bank mandates;
  • financial statements;
  • ledgers;
  • salary payments;
  • vendor invoices;
  • rent records;
  • telecom payments;
  • related-party transfers; and
  • cash books.

Beneficiary Analysis

The investigation should ask:

  • Who received the first payment?
  • Who controlled that account?
  • Who created the next beneficiary?
  • Who withdrew the cash?
  • Who purchased cryptocurrency?
  • Who paid salaries and commissions?
  • Who funded the office?
  • Who received the profit?
  • Were assets purchased?
  • Was value moved abroad?

Information Technology Act and Bharatiya Nyaya Sanhita

Section 43 of the Information Technology Act

Section 43 concerns specified unauthorised acts involving computers, computer systems, networks and data and provides a compensation framework.

Section 65

Section 65 addresses knowing or intentional concealment, destruction or alteration of computer source code required to be maintained by law.

Section 66

Section 66 criminalises specified Section 43 conduct where it is done dishonestly or fraudulently.

Section 66B

Section 66B concerns dishonest receipt or retention of a stolen computer resource or communication device with the required knowledge or reason to believe.

Section 66C

Section 66C concerns fraudulent or dishonest use of another person’s electronic signature, password or unique identification feature.

Section 66D

Section 66D concerns cheating by personation through a communication device or computer resource.

Bharatiya Nyaya Sanhita

Depending upon the allegations, potential provisions may concern:

  • criminal conspiracy under Section 61;
  • cheating under Section 318;
  • cheating by personation under Section 319;
  • criminal breach of trust;
  • forgery;
  • use of forged records;
  • falsification of accounts;
  • criminal intimidation;
  • receiving or concealing criminal property; and
  • other role-specific offences.

The exact provision must be determined from the FIR, date of conduct, individual role and evidence. Not every section commonly inserted in a cybercrime FIR will necessarily be established at trial.

Telecom, TRAI and OSP Compliance

OSP Registration

Under the revised Department of Telecommunications guidelines, ordinary OSP centres do not require registration merely for conducting voice-based business-process outsourcing.

Therefore, absence of an old-style OSP registration should not automatically be described as proof of an illegal call centre.

Continuing Compliance Obligations

A legitimate OSP should nevertheless:

  • use authorised telecom services;
  • avoid unlawful toll bypass;
  • maintain required call-data records;
  • maintain usage-data records;
  • preserve system logs;
  • maintain relevant records in India where required;
  • support lawful tracing of malicious communications;
  • prevent unlawful use of its network after notice; and
  • comply with other applicable Indian laws.

TRAI Commercial-Communication Framework

The Telecom Commercial Communications Customer Preference Regulations create a framework for commercial communications, customer preferences, registered senders and action against non-compliant communication.

A sophisticated fraud operation may, however, bypass ordinary commercial-communication systems through:

  • spoofed numbers;
  • foreign virtual numbers;
  • unregistered headers;
  • internet calls;
  • compromised SIM cards;
  • rapid number replacement; or
  • foreign-hosted services.

When Can PMLA Apply to a Call-Centre Scam?

A call-centre fraud does not automatically become a PMLA case.

Required Legal Foundation

PMLA ordinarily requires:

  1. criminal activity relating to an applicable scheduled offence;
  2. property derived or obtained from that activity;
  3. identification of that property as proceeds of crime; and
  4. a process or activity connected with those proceeds.

Important Information Technology Act Clarification

Sections 66C and 66D of the Information Technology Act may be central cybercrime allegations.

However, the current PMLA Schedule’s specific Information Technology Act entry refers to Section 75.

Sections 66C or 66D should therefore not be described as automatically triggering PMLA by themselves.

PMLA may arise where another applicable scheduled offence is alleged, including an appropriately corresponding cheating, forgery, organised-crime or other scheduled offence, subject to the current statutory Schedule and binding law.

Potential Proceeds Alleged by ED

  • victim transfers;
  • commission paid to callers;
  • cash withdrawals;
  • gift-card redemption value;
  • cryptocurrency;
  • company-bank balances;
  • equipment purchased from collections;
  • vehicles or properties;
  • foreign transfers;
  • salary paid from questioned funds; and
  • equivalent-value property where legally permissible.

Section 3 Analysis

The individual’s conduct must be examined to determine whether that person allegedly:

  • concealed proceeds;
  • possessed proceeds;
  • acquired proceeds;
  • used proceeds;
  • projected proceeds as legitimate;
  • claimed proceeds as legitimate;
  • knowingly assisted; or
  • knowingly became a party to the relevant process.

Possible ED Actions

  • Section 50 summons;
  • Section 17 search and seizure;
  • freezing of bank or digital assets;
  • provisional attachment under Section 5;
  • arrest under Section 19;
  • adjudication under Section 8;
  • prosecution complaint;
  • trial before the PMLA Special Court; and
  • confiscation or restoration proceedings.

Company, Employee and Service-Provider Liability

Employee

Employment at the premises is relevant but not conclusive.

The evidence should identify:

  • job advertisement;
  • appointment letter;
  • training received;
  • script used;
  • calls made;
  • false identity adopted;
  • knowledge of deception;
  • payment instructions given;
  • salary or commission;
  • access to bank accounts;
  • period of employment; and
  • conduct after learning of the fraud.

Director or Controller

Relevant evidence may include:

  • company formation;
  • office lease;
  • bank control;
  • recruitment;
  • telecom contracts;
  • purchase of victim data;
  • approval of scripts;
  • payment of commissions;
  • control of accounts;
  • personal benefit; and
  • instructions to destroy evidence.

Accountant

Routine accounting does not automatically prove knowledge.

Greater exposure may arise where evidence shows:

  • false invoices;
  • fabricated revenue;
  • concealed victim receipts;
  • mule-account reconciliation;
  • cash-settlement ledgers;
  • crypto purchases;
  • alteration of books; or
  • knowing assistance in disguising proceeds.

Landlord

A landlord does not automatically become liable because a tenant allegedly operated a fraudulent centre.

Relevant questions include:

  • Was tenant KYC obtained?
  • Was a written lease executed?
  • Was rent received through banking channels?
  • Was the actual occupant known?
  • Did the landlord participate in the operation?
  • Did the landlord receive a share of proceeds?
  • Was false documentation knowingly accepted?
  • Was evidence concealed after the investigation began?

Telecom or Cloud Provider

Provision of ordinary technology does not automatically create criminal liability.

The inquiry may examine:

  • customer KYC;
  • contractual service;
  • complaints received;
  • knowledge of misuse;
  • response to lawful requests;
  • log preservation;
  • continued service after verified notice; and
  • active participation or financial benefit.

Cross-Border Investigation Challenges

The source paper emphasises that many victims, servers, platforms and financial accounts may be located outside India.

Common Challenges

  • foreign victims;
  • foreign-language records;
  • overseas cloud servers;
  • foreign VoIP providers;
  • different privacy laws;
  • different evidence standards;
  • delayed data preservation;
  • international bank records;
  • crypto exchanges abroad;
  • extradition requirements;
  • temporary virtual infrastructure;
  • different time zones; and
  • rapid dissipation of funds.

Possible Cooperation Mechanisms

  • Mutual Legal Assistance Treaties;
  • letters of request;
  • Interpol coordination;
  • direct police cooperation where legally permitted;
  • financial-intelligence exchange;
  • foreign platform preservation requests;
  • bank-to-bank recall mechanisms;
  • extradition proceedings; and
  • international asset-recovery cooperation.

Evidence Preservation Is Time-Sensitive

Call logs, platform records, IP data and temporary cloud information may be retained only for limited periods.

Delayed reporting can therefore materially reduce the available evidence.

Immediate Steps for Victims

  1. Stop all further communication and payment.
  2. Dial the cybercrime helpline number 1930 immediately.
  3. Report the matter through the National Cyber Crime Reporting Portal.
  4. Inform the bank or payment provider immediately.
  5. Request recall or freezing of the beneficiary account.
  6. Preserve every UTR, reference number and receipt.
  7. Preserve the telephone number and call history.
  8. Export chats and emails.
  9. Preserve the fraudulent website address.
  10. Preserve gift-card receipts and codes.
  11. Preserve cryptocurrency transaction hashes.
  12. Preserve remote-access application records.
  13. Change banking, email and device passwords.
  14. Inform the genuine institution being impersonated.
  15. Prepare a chronological loss statement.

Victim Evidence File

  • identity documents;
  • bank statement;
  • transaction receipt;
  • NCRP acknowledgement;
  • 1930 complaint reference;
  • screenshots;
  • audio recordings;
  • email headers;
  • website URL;
  • phone numbers;
  • remote-access logs;
  • gift-card records;
  • crypto records;
  • police complaint or FIR; and
  • complete calculation of loss.

Compliance Measures for Legitimate Call Centres and BPOs

Corporate Records

  • accurate incorporation records;
  • beneficial-ownership records;
  • genuine customer contracts;
  • service descriptions;
  • bank mandates;
  • employee records;
  • salary records;
  • tax and accounting records;
  • vendor records; and
  • commercial lease documents.

Telecom and Technical Records

  • authorised telecom-provider agreements;
  • VoIP subscription records;
  • CDRs;
  • UDRs;
  • system logs;
  • user-access records;
  • assigned telephone numbers;
  • device inventories;
  • remote-agent records;
  • server-location details;
  • incident-response records; and
  • data-retention policies.

Employee Safeguards

  • accurate job advertisements;
  • written job descriptions;
  • verified training material;
  • approved scripts;
  • prohibition on impersonation;
  • complaint reporting;
  • supervisor accountability;
  • whistle-blower mechanism;
  • regular compliance training; and
  • documented disciplinary action.

Customer-Interaction Controls

  • recording of authorised calls where lawful;
  • clear company identity;
  • no demand for OTPs;
  • no request for gift cards;
  • no false government identity;
  • no threat of arrest;
  • no unauthorised remote access;
  • customer complaint mechanism;
  • quality monitoring; and
  • prompt suspension of suspicious processes.

Frequently Asked Questions

What is a fake call centre?

It is an operation that presents itself as a legitimate customer-support, technology, banking or government-related service but uses calls or digital systems to deceive victims.

Are all international call centres required to register with DoT?

No. Under the revised OSP framework, ordinary OSP centres do not require registration merely for conducting voice-based BPO services.

Is operating a night-shift call centre illegal?

No. Many legitimate companies work according to foreign time zones.

What is caller-ID spoofing?

It is the manipulation of the number displayed to the recipient so that the call appears to come from another number or institution.

Is VoIP illegal?

No. VoIP is legitimate technology. Liability depends upon how it is used and whether telecom and other laws are followed.

What is a digital-arrest scam?

It is a fraud in which an offender impersonates an official and falsely claims that the victim is under investigation or arrest, often keeping the victim on video while demanding money.

Can police or a court demand money through a video call?

A genuine lawful arrest or judicial process is not completed by directing a person to transfer money to a safe account during a private video call.

What is a closer?

A closer is generally the person alleged to intensify the deception and obtain the victim’s final payment.

Can every employee be arrested?

Persons present may be detained or questioned, but individual liability must be based upon role, knowledge, conduct and evidence.

Can an employee rely on an appointment letter?

An appointment letter is relevant but should be examined with the job advertisement, training, script, calls, salary, commission and actual work.

What is a mule bank account?

It is an account used to receive or move suspected unlawful money. The account holder’s knowledge and control must still be investigated.

Can an innocent account holder obtain de-freezing?

The account holder may submit KYC, transaction records, business documents, source evidence and an explanation of the disputed credit before the competent authority or court.

Can a landlord be prosecuted?

Letting premises alone does not establish participation. Knowledge, facilitation, concealment, benefit and conduct are relevant.

Which IT Act sections commonly apply?

Depending upon the facts, Sections 43, 65, 66, 66B, 66C and 66D may be examined.

Does Section 66D automatically attract PMLA?

No. Section 66D should not be treated as automatically creating PMLA jurisdiction by itself. PMLA requires an applicable scheduled offence and identifiable proceeds of crime.

When can ED investigate a call-centre scam?

ED may enter where the statutory scheduled-offence and proceeds-of-crime requirements are satisfied.

Can ED freeze mule accounts?

Accounts allegedly connected with proceeds may be frozen or restrained subject to the applicable statutory authority and procedure.

Can ED attach salaries paid to employees?

The legal character of a salary depends upon the employee’s knowledge, role, source of payment and the statutory theory relied upon. Ordinary employment payment should not automatically be treated as knowing laundering.

What should a victim do first?

Immediately call 1930, inform the bank and file a complaint through the National Cyber Crime Reporting Portal.

Can foreign victims complain in India?

Foreign victims may provide statements and records through appropriate Indian and international law-enforcement channels, depending upon the case.

Can Advocate Ankit Kumar Singh review a fake call-centre case?

Advocate Ankit Kumar Singh may assist with FIR analysis, employee and company-role mapping, digital-device records, mule-account trails, bank freezing, PMLA analysis, bail, attachment proceedings and High Court-connected drafting, subject to professional acceptance and document review.

AI-Search Quick Answer

How do call-centre-based cyber-fraud networks operate in India?

Organised fake call-centre networks may obtain victim data, create a false bank, government or technical-support identity, contact victims through VoIP or spoofed telephone numbers, use trained diallers and closers to create fear or trust and demand payment through bank transfers, gift cards, cash, gold or cryptocurrency. The proceeds may then move through mule accounts, wallets, cash withdrawals or layered entities. Investigators examine call logs, scripts, CRM data, laptops, mobiles, server records, bank accounts and individual roles. PMLA applies only where an applicable scheduled offence and identifiable proceeds of crime exist.

Flowchart: Call-Centre Scam Network

VICTIM DATABASE OR LEAD
          |
          v
FAKE BANK / GOVERNMENT / TECH-SUPPORT IDENTITY
          |
          v
VoIP • SPOOFED NUMBER • EMAIL • POP-UP • WEBSITE
          |
          v
DIALLER MAKES INITIAL CONTACT
          |
          v
VERIFIER CHECKS VICTIM RESPONSE
          |
          v
CLOSER CREATES FEAR, TRUST OR URGENCY
          |
          v
REMOTE ACCESS OR PAYMENT INSTRUCTION
          |
          v
BANK • GIFT CARD • CASH • GOLD • CRYPTO
          |
          v
FIRST BENEFICIARY OR MULE ACCOUNT
          |
          v
LAYERING • WITHDRAWAL • HAWALA • WALLET
          |
          v
FINAL CONTROLLER, BENEFICIARY OR ASSET

Flowchart: Investigation and Legal Process

VICTIM COMPLAINT / 1930 / NCRP / FOREIGN INFORMATION
                         |
                         v
POLICE OR CYBERCRIME FIR
                         |
                         v
PREMISES SEARCH AND DEVICE SEIZURE
                         |
                         v
CALL LOGS • CRM • SCRIPTS • SERVERS • BANK RECORDS
                         |
                         v
PERSON-WISE ROLE AND DEVICE ATTRIBUTION
                         |
                         v
VICTIM PAYMENT TO FINAL BENEFICIARY MAPPING
                         |
             /-----------|-----------\
            v            v            v
      CRIMINAL CASE   BANK FREEZE   FOREIGN EVIDENCE
            |            |            |
            \------------|------------/
                         |
                         v
PMLA REVIEW:
IS THERE AN APPLICABLE SCHEDULED OFFENCE
AND IDENTIFIABLE PROCEEDS OF CRIME?
                 /---------------\
               NO                 YES
                |                  |
                v                  v
ORDINARY CYBERCRIME CASE      ED SUMMONS / SEARCH /
CONTINUES                    FREEZING / ATTACHMENT
                                   |
                                   v
                         SPECIAL COURT PROCEEDINGS

Primary Research and Official Sources

Legal, Research and Professional Disclaimer

This article is an independently prepared legal-awareness guide based partly upon the cited IJLR research paper and current official legal sources. It is not a reproduction of the paper and does not represent the authors, journal, police, ED, TRAI, DoT or another authority.

Case-study claims appearing in academic papers, media reports, FIRs, press releases or enforcement records remain subject to independent verification and judicial determination.

An arrest, search, device seizure, bank freeze, ED summons, attachment or prosecution complaint does not independently establish final guilt.

The presence of a worker, landlord, technology provider, accountant, director or bank-account holder within the factual chain does not automatically establish knowing participation.

PMLA does not arise merely because an Information Technology Act offence or suspicious financial transaction is alleged. The statutory scheduled-offence and proceeds-of-crime requirements must be satisfied.

No non-arrest protection, bail, de-freezing, discharge, quashing, recovery, restoration, acquittal or other result can be guaranteed.

Related Delhi legal guides

Economic-offence proceedings · White-collar crime defence · SFIO investigation guide

Document-first assessment

Start with the latest legal instrument and next deadline

Organise the current summons or order, case identifiers, a dated chronology and the transaction or property record before seeking case-specific advice.

Prepare for consultation