Videos
|
Crime

Special Report| How I4C Telemetry Spooked the “Clever” Mule Accounts Operating Freely in Odisha for Over Three Years; What Odisha Must Do Next

Sanjeev Kumar Patro
Browse all articles by Sanjeev Kumar Patro
·30 mins ago·10 min read
Special Report| How I4C Telemetry Spooked the “Clever” Mule Accounts Operating Freely in Odisha for Over Three Years; What Odisha Must Do Next
I4C Downs Curtain on Odisha 'Mule' Show

Key Points

  • A sophisticated cyber-fraud network operated out of Loisingha, Balangir, for over three years using commercial current accounts disguised as ordinary agro-trading businesses like Samaleswari Enterprises.

  • The operation relied on geographical fragmentation, avoiding local victims and routing funds from inter-state cybercrimes through business accounts to mimic legitimate commercial transactions.

  • Integration with the national Indian Cyber Crime Coordination Centre (I4C) and CFCFRMS data trail connected a Delhi-based Rs35-lakh fraud complaint to the Odisha accounts, leading to major police raids and evidence seizures.


  • Bhubaneswar: For more than three years, a sophisticated cyber-financial network allegedly operated from the quiet lanes of Loisingha in Odisha’s Balangir district, hiding behind the appearance of ordinary agro-trading businesses.

    Prasanna Kumar Nag and Jubaraj Deep allegedly operated through firms including Samaleswari Enterprises, Maa Samaleswari Agro Enterprises and Maa Agro Enterprises, turning apparently legitimate commercial banking channels into a suspected clearing route for cyber-fraud money flowing in from outside Odisha.

    Their apparent advantage was simple: stay away from local victims, stay away from ordinary savings accounts and make the money look like business transactions.

    For more than 36 months, that strategy appears to have worked.

    Argus News App

    📱 Get Argus News App

    📰 60 Word News🎬 Argus Podcast📺 Live TV and Breaking News🔔 Free Notification Alerts
    Download Free:

    Then came the I4C connection.

    A complaint from outside Odisha involving a Rs35-lakh transfer allegedly brought the Balangir accounts into a much wider national cyber-fraud data trail. What local geography had kept apart, the national cybercrime infrastructure could connect through transaction and complaint data.

    The result was a sharp change in the equation: the mule account network could no longer rely on distance between the victim, the bank account and the police station.

    Stage

    What the network allegedly did

    Why it worked

    2023 onwards

    Used commercial current accounts under agro-trading/business names

    Current accounts are built to handle higher transaction volumes

    Victim targeting

    Alleged upstream fraudsters targeted victims outside Odisha

    No obvious local victim meant fewer local complaints

    Money entry

    Fraud proceeds allegedly entered Balangir-linked business accounts

    Transactions could initially resemble commercial activity

    Layering

    Money was rapidly moved into other accounts and allegedly converted through further channels

    The original source became harder to trace

    September 2026

    National cyber-fraud data linked apparently unrelated transactions to the same accounts

    Geographic separation stopped being an effective shield

    Police action

    Balangir Cyber Crime and Economic Offences Police acted on the intelligence

    The local investigation was connected to a much larger digital trail

    The Three-Year Illusion: Why the Mule Accounts Looked “Legitimate”

    The suspected network's most important shield was not technology alone.

    It was the appearance of normal business.

    A savings account receiving repeated large-value transfers from unrelated individuals can immediately appear unusual. A commercial current account, however, is expected to handle frequent and sometimes high-value transactions.

    That difference allegedly gave the operators room to operate.

    Traditional fraud signal

    The suspected Balangir model

    Savings account

    Commercial current account

    Individual account holder

    Business entity

    Sudden personal deposits

    Transactions presented as business activity

    Local victim

    Victims allegedly located across states

    One-to-one money trail

    Multiple transfers and layered accounts

    Local complaint

    National cyber-fraud complaints

    Geography-based investigation

    Centralised digital transaction mapping

    The suspected operators therefore did not necessarily need to defeat every banking security system.

    They allegedly needed to look sufficiently ordinary for long enough.

    That is what makes the case important beyond Balangir.

    The Money Trail That Changed Everything

    At the centre of the investigation is the alleged transfer of Rs35 lakh by a Delhi-based senior citizen into the Samaleswari Enterprises account.

    The significance of that transaction was not merely its value.

    It was the possibility that the account was already visible inside a wider network of complaints and suspicious transactions.

    Money-trail step

    What investigators had to establish

    1. Victim payment

    How the Delhi victim was induced to transfer ₹35 lakh

    2. Destination account

    Why the money landed in the Balangir-linked business account

    3. Previous transactions

    Whether the same account had received money from other unrelated victims

    4. Outward transfers

    Where the money moved after entering the account

    5. Secondary accounts

    Whether downstream accounts were connected to the alleged wider syndicate

    6. Human links

    Whether account operators were connected to handlers in Chhattisgarh and elsewhere

    This is where the Indian Cyber Crime Coordination Centre (I4C) becomes central to the story.

    The strength of the system is not simply that a complaint is registered.

    It is that financial and complaint information can potentially be connected across jurisdictions.

    How I4C Telemetry Spooked the “Clever” Network

    The suspected operators appear to have relied on a very old assumption:

    A cybercrime committed in Delhi would remain a Delhi case until someone manually followed the money to Odisha.

    Modern cybercrime coordination is designed to challenge exactly that fragmentation.

    The national cybercrime infrastructure, including the Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS), enables financial-fraud complaints and transaction information to be coordinated across jurisdictions.

    Old assumption of the mule network

    What the national system changes

    Delhi complaint remains in Delhi

    Complaint can become part of a wider financial trail

    Mumbai victim is a separate case

    Common account identifiers can expose connections

    Odisha account appears geographically distant

    Bank/account/transaction identifiers connect locations

    Local police see one transaction

    Wider data can reveal repeated patterns

    Investigation starts from the account holder

    Investigation can work backwards from multiple victims and transactions

    The critical breakthrough, therefore, was not necessarily a dramatic raid.

    It was the connection of apparently unrelated dots.

    A Delhi victim.

    An Odisha business account.

    Other transaction records.

    Other states.

    And alleged links leading towards handlers outside Odisha.

    Once those dots were connected, the geography that had protected the network for years became far less useful.

    From Digital Trail to Physical Raid

    The Balangir Cyber Crime and Economic Offences Police then had a different problem.

    Digital evidence can disappear.

    A phone can be wiped.

    A laptop can be reset.

    A password can be changed.

    A remote operator can attempt to destroy or alter information.

    That makes the physical seizure of devices and documents critical to the investigation.

    Evidence seized / examined

    Why it matters

    Five mobile phones

    May contain communication, account access, OTPs, contacts and transaction information

    Laptop

    Potential source of banking, communication and digital-financial evidence

    Checkbooks

    Can establish control and operation of business accounts

    Passbooks/banking records

    Can help reconstruct the financial trail

    Corporate seals/stamps

    Can help establish how the firms were represented and operated

    Debit cards

    Can connect individuals to specific banking facilities

    Corporate registers/documents

    Can help investigators examine the authenticity and functioning of the businesses

    The forensic chain matters

    For a cyber-fraud prosecution, simply producing a seized mobile phone is not enough.

    Investigators must establish what was seized, from whom, how it was preserved, how the data was extracted and how its integrity was maintained.

    Where appropriate, forensic protocols can include isolation of devices from networks, preservation of original evidence, forensic imaging and cryptographic hashing so that the extracted material can later be tested for integrity.

    The investigation therefore has two parallel tracks:

    Financial trail + digital evidence.

    Both have to meet evidentiary requirements before they can carry the case through prosecution.

    The Corporate-Front Question

    The presence of business names and corporate documentation raises another important question:

    Were these genuine businesses that were later misused, or were the businesses created or operated primarily as vehicles for moving illicit funds?

    That distinction has to be established through investigation rather than assumed from the existence of company seals or current accounts.

    Investigation point

    Question for police

    Business registration

    Who actually registered and controlled the firms?

    KYC records

    What documents were submitted to banks?

    Physical address

    Did the businesses genuinely operate from the declared locations?

    Business activity

    Were there corresponding purchases, sales, invoices and customers?

    Banking behaviour

    Did transaction volumes match the declared business?

    Account control

    Who possessed cards, cheques, credentials and banking devices?

    Inter-state connections

    Who were the persons receiving or directing the funds?

    Communication records

    Did account operators communicate with alleged handlers?

    That evidence chain is more important than simply labelling the firms “fake”.

    The Bigger Question for Odisha: Could There Be More Such Accounts?

    This is where the Balangir case becomes a warning rather than merely an arrest story.

    If commercial current accounts can be misused as mule-account infrastructure, the problem cannot be solved only by catching the account operators after a cybercrime complaint arrives.

    Odisha has to move upstream.

    Risk area

    What Odisha should examine

    New current accounts

    Stronger scrutiny of high-risk business categories

    Existing accounts

    Periodic transaction-pattern review

    Sudden transaction velocity

    Compare actual turnover with declared business

    Multiple unrelated states

    Flag unusual interstate inflows

    Rapid onward transfers

    Identify accounts acting as transit points

    Dormant-to-active accounts

    Examine sudden spikes in activity

    Corporate shell behaviour

    Compare banking activity with GST/business records where legally available

    Multiple firms at similar addresses

    Examine common ownership/control indicators

    Bank onboarding

    Strengthen physical and documentary verification

    Police-bank coordination

    Create faster escalation channels for suspicious mule-account intelligence

    The objective should not be to criminalise legitimate businesses simply because they receive large payments.

    It should be to identify behavioural anomalies.

    What Odisha Can Learn From Other States

    Other states have experimented with stronger approaches to cyber-financial crime, but Odisha should adopt such measures only after verifying their legal, technical and operational effectiveness.

    Model / approach

    Lesson for Odisha

    Bank-branch accountability

    Examine whether weak KYC/onboarding practices are enabling mule accounts

    AI/data-led mule detection

    Identify repeated interstate transaction patterns rather than waiting for individual complaints

    Regional database integration

    Connect cybercrime, banking and financial intelligence at the state level

    Rural financial-node audits

    Do not assume cybercrime infrastructure exists only in major cities

    Rapid account freezing mechanisms

    Strengthen the speed of lawful intervention once credible fraud intelligence arrives

    Post-incident financial mapping

    Continue tracing money after the first arrest rather than treating the account holder as the end of the investigation

    The Immediate Roadmap for Odisha

    The Balangir operation points towards a five-part strategy.

    Priority

    Action

    Expected benefit

    1. Map mule accounts

    Build a state-level watch mechanism around recurring cyber-fraud-linked accounts

    Detect repeat offenders

    2. Watch transaction behaviour

    Identify rapid inflows, multiple unrelated senders and immediate onward transfers

    Detect possible layering

    3. Strengthen current-account KYC

    Give greater scrutiny to high-risk business registrations and declared activity

    Reduce use of paper businesses

    4. Integrate intelligence

    Faster coordination between I4C, Odisha Police, banks and relevant agencies

    Shorten the time between complaint and intervention

    5. Follow the money

    Investigate upstream handlers and downstream beneficiaries, not merely local account holders

    Break the larger syndicate

    The Real Lesson From Loisingha

    The most important part of the Balangir case may not be the five phones seized or even the arrest of the alleged account operators.

    It is the collapse of a strategy that depended on fragmentation.

    For years, the suspected network could allegedly sit in one place while victims were scattered across India, banking transactions passed through Odisha and handlers operated elsewhere.

    That model depended on one thing:

    Nobody connecting all the dots quickly enough.

    I4C's growing role in coordinating cyber-fraud information changes that equation.

    The challenge for Odisha now is to make sure the lesson does not end with one raid.

    Because if one network could allegedly hide behind agro-trading identities for more than three years, the question is no longer only who has been caught.

    The bigger question is:

    How many apparently ordinary business accounts are currently behaving like mule accounts – and can Odisha identify them before the next victim loses Rs35 lakh?