Police in Bengaluru, India, have arrested three men while investigating an alleged online trading and investment scam in which a city resident lost ₹93.58 lakh.
The case has expanded into a wider investigation after police uncovered 507 bank accounts allegedly used by the network to receive and move suspected fraud proceeds. Digital evidence has also pointed investigators toward connections in Kolkata, Hong Kong and California.
According to The Indian Express and matching reports in The Hindu and The Times of India, the investigation followed a complaint by a Peenya resident identified as Harish Kumar K.N. Several outlets say he was first lured on 29 April 2026 through a WhatsApp link and added to a group named “EL / E1 Investment Strategies Discussion.”
The Indian Express reported that he filed the complaint that triggered this probe on 28 May 2026, alleging he was induced to transfer ₹93,58,555 into several bank accounts. Police said he was first asked to open a demat account in the name “Farallon CM” and invest ₹50,000 before later transfers. A case was registered under relevant provisions of the IT Act and Section 318(4) of the Bharatiya Nyaya Sanhita, police told reporters.
How the network operated
Police allege that the network sourced different types of bank accounts, including current, corporate and trust accounts. The account holders allegedly provided their banking credentials, SIM cards and net banking access in return for commissions.
Investigators believe these accounts were then used to move money between multiple destinations.
A Super OYO hotel in Kachuvanahalli / Kasavanahalli allegedly served as an operating location for the group. Account holders were reportedly brought there and kept at the premises while transactions were carried out.
Police said the suspects also installed applications on the account holders’ phones, including an application identified as “ZNPAY” and APK files designed to forward SMS messages.
According to the police findings cited by The Indian Express, these applications could capture banking alerts and OTP-related messages and send them to the operators. This allegedly gave the network remote access to accounts and helped it route funds through several accounts.
Police said the account holders received between Rs 1.5 lakh and Rs 2 lakh for participating in the arrangement.
The investigation found that around Rs 13 lakh in suspected fraud proceeds moved through a government-owned (nationalised) bank account, while more than Rs 38 lakh passed through a private bank current account. Police also said the 507 accounts were linked to cybercrime cases in Karnataka, Maharashtra, Delhi and other states.
Three arrested in Bengaluru
The investigation gained momentum after police traced a mobile phone to a building in Lucknow, Uttar Pradesh.
Investigators subsequently identified Amit Mishra, a resident of East Singhbhum district in Jharkhand, as one of the suspects. Police said they monitored him for nearly two months before arresting him at a Bengaluru hotel on 8 September 2026.
Further technical analysis allegedly connected Mishra with Tausif Ahmed and Parashuram Sadanand Kannanavar, also known as Pavan Kumar. Police arrested the two Bengaluru residents on 9 September 2026.
Six mobile phones were recovered from the three arrested men.
Police are also searching for Anoop, alias Julpi, as well as people operating Telegram accounts under the handles “@zhangxueyou123” and “@SZNKM”.
Investigators are examining the alleged roles of several other individuals whose names emerged during the probe, including people linked to the ZNPAY platform (Sumon, Nick, Dilawar, Iftikhar, Abhinav and Vivek, among others named by police).
Crypto trail and international links
The movement of funds into cryptocurrency has become another part of the investigation.
Police said money routed through the mule accounts was eventually transferred to a Binance crypto wallet. Investigators are now tracing the movement of those funds as they attempt to establish the full flow of the suspected proceeds. Police also said the accused used the Dubai-based Botim app for communication.
The authorities have also submitted the ZNPAY application and 51 other suspicious APK files to the Indian Cybercrime Coordination Centre (I4C). The files are being examined to determine how they functioned and how they were used in the alleged operation.
Digital forensic checks of Telegram, Botim and WhatsApp accounts reportedly identified IP addresses associated with Kolkata, Hong Kong and California.
Police are checking those details with the relevant service providers. The verification will help investigators determine whether people outside India were involved or whether foreign infrastructure was used by the network.
Separate Bengaluru crypto-trading case
A separate Bengaluru case reported on September 8 involved a 50-year-old surgeon who allegedly lost Rs 4.47 crore after being shown nearly Rs 14 crore in fake cryptocurrency trading profits. The victim was reportedly asked to make additional payments when he attempted to withdraw the displayed funds.
The latest investigation is continuing, with police working to identify other participants, establish their individual roles and trace the movement of the suspected fraud proceeds.
Also Read: ‘Government Is Not Accepting VDAs, Not Regulating Either’: India Panel Chief on Crypto
