Skip to Content
Join the Network with Us — Join Membership


Money Gone Without OTP or Link: Bareilly Cyber Fraud Case Raises Questions

August 24, 2026

A cyber fraud case has been registered in Uttar Pradesh's Bareilly district after ₹50,000 was allegedly withdrawn from a woman's bank account without her sharing an OTP or clicking on any suspicious link. The alleged unauthorised withdrawals took place over two days through multiple small transactions, prompting police to begin an investigation into how the money was actually accessed.

How the Money Went Missing

The complaint was filed by Shambhu Khan, a resident of Deoria Abdullah village in the Mirganj police station area. He told police that his wife, Anno Begum, holds a bank account with the Mill branch of HDFC Bank in neighbouring Rampur district. According to the complaint, ₹25,000 was withdrawn from the account on July 21 and another ₹25,000 on July 23, taking the total alleged loss to ₹50,000.

Withdrawn in Multiple Small Transactions

According to the complainant, the entire amount wasn't withdrawn in a single transaction. Instead, the ₹50,000 was allegedly taken out through several smaller transactions, a pattern that adds an interesting layer to the investigation.

The family became aware of these withdrawals only after checking their account activity, and subsequently approached the police. They told investigators that neither the woman nor her husband had shared an OTP with anyone. They also denied clicking on any unknown or suspicious link, downloading an unfamiliar application, or voluntarily providing banking credentials to another person.

This alleged absence of the usual fraud triggers has made the transaction mechanism itself a key part of the investigation. Police are now trying to establish how these withdrawals were authorised and what digital or banking channel was actually used to access the account.

What the Bank Records Are Expected to Reveal

Police have registered a case against unidentified persons on the basis of the complaint, and investigators are now seeking detailed transaction records from the bank to determine the exact method used to withdraw the money. This kind of meticulous, record-by-record examination is exactly the sort of work reliable auditing services in India are built around, carefully cross-referencing transaction logs, timestamps, and access points to reconstruct precisely how funds moved out of an account.

The investigation is expected to examine whether the transactions were carried out through an ATM, debit card, internet banking, a digital payment platform, or another banking channel entirely. Police will also examine where the funds ultimately went; if the money was transferred to another bank account or digital wallet, that transaction trail could offer important clues about the people involved. Investigators are also likely to examine the timing, location, and technical details associated with each transaction, to determine whether the account was accessed remotely or whether compromised banking credentials were used.

Why This Case Needs Careful Technical Investigation

Renowned cybercrime expert and former IPS officer Prof. Triveni Singh said that unauthorised withdrawals shouldn't automatically be attributed to OTP sharing. According to him, investigators need to examine the complete transaction mechanism, including banking credentials, device activity, login records, and the subsequent movement of funds.

He explained that when a victim specifically denies sharing an OTP or clicking on a suspicious link, the investigation should instead focus on determining how the transaction was authenticated in the first place, and which digital or banking link actually enabled the unauthorised movement of money. This kind of approach, he noted, can help distinguish between different possibilities, including compromised credentials, misuse of banking channels, unauthorised card transactions, or other forms of account compromise entirely.

Tracking the Money's Final Destination

The immediate focus of this investigation is to establish exactly where the ₹50,000 ultimately went. Police will analyse bank records and technical evidence to identify the accounts, persons, or platforms connected with the withdrawals.

Investigators may also examine whether these transactions were linked to any previously reported cyber fraud cases, or accounts already flagged for suspicious activity. Such links could help establish whether this incident was an isolated case, or part of a wider, more organised fraud network.

No arrest has been reported so far. Police said the exact method used to withdraw the money, and the identity of those responsible, will become clearer once the bank provides the relevant transaction and technical records.

This case genuinely highlights an important aspect of modern banking fraud: the absence of an OTP, suspicious link, or unfamiliar app doesn't by itself explain how an unauthorised transaction occurred. Establishing the precise authentication method and following the money trail remain central to determining exactly how the ₹50,000 was allegedly taken, and who was behind it.

FAQs

Q1. How was the money allegedly withdrawn without an OTP or suspicious link?

That's exactly what investigators are trying to determine. The victim denies sharing an OTP or clicking any link, so police are examining banking channels, device activity, and login records to establish how the transaction was authenticated.

Q2. How much money was allegedly withdrawn, and over what period?

₹50,000 was allegedly withdrawn in total, ₹25,000 on July 21 and another ₹25,000 on July 23, through multiple smaller transactions rather than a single withdrawal.

Q3. Why is this case considered unusual for a cyber fraud investigation?

in News
Share this post
Archive