Special Report| How I4C Telemetry Spooked the “Clever” Mule Accounts Operating Freely in Odisha for Over Three Years; What Odisha Must Do Next

Key Points
A sophisticated cyber-fraud network operated out of Loisingha, Balangir, for over three years using commercial current accounts disguised as ordinary agro-trading businesses like Samaleswari Enterprises.
The operation relied on geographical fragmentation, avoiding local victims and routing funds from inter-state cybercrimes through business accounts to mimic legitimate commercial transactions.
Integration with the national Indian Cyber Crime Coordination Centre (I4C) and CFCFRMS data trail connected a Delhi-based Rs35-lakh fraud complaint to the Odisha accounts, leading to major police raids and evidence seizures.
Bhubaneswar: For more than three years, a sophisticated cyber-financial network allegedly operated from the quiet lanes of Loisingha in Odisha’s Balangir district, hiding behind the appearance of ordinary agro-trading businesses.
Prasanna Kumar Nag and Jubaraj Deep allegedly operated through firms including Samaleswari Enterprises, Maa Samaleswari Agro Enterprises and Maa Agro Enterprises, turning apparently legitimate commercial banking channels into a suspected clearing route for cyber-fraud money flowing in from outside Odisha.
Their apparent advantage was simple: stay away from local victims, stay away from ordinary savings accounts and make the money look like business transactions.
For more than 36 months, that strategy appears to have worked.
📱 Get Argus News App
✨Then came the I4C connection.
A complaint from outside Odisha involving a Rs35-lakh transfer allegedly brought the Balangir accounts into a much wider national cyber-fraud data trail. What local geography had kept apart, the national cybercrime infrastructure could connect through transaction and complaint data.
The result was a sharp change in the equation: the mule account network could no longer rely on distance between the victim, the bank account and the police station.
|
Stage |
What the network allegedly did |
Why it worked |
|---|
2023 onwards
Used commercial current accounts under agro-trading/business names
Current accounts are built to handle higher transaction volumes
Victim targeting
Alleged upstream fraudsters targeted victims outside Odisha
No obvious local victim meant fewer local complaints
Money entry
Fraud proceeds allegedly entered Balangir-linked business accounts
Transactions could initially resemble commercial activity
Layering
Money was rapidly moved into other accounts and allegedly converted through further channels
The original source became harder to trace
September 2026
National cyber-fraud data linked apparently unrelated transactions to the same accounts
Geographic separation stopped being an effective shield
Police action
Balangir Cyber Crime and Economic Offences Police acted on the intelligence
The local investigation was connected to a much larger digital trail
The Three-Year Illusion: Why the Mule Accounts Looked “Legitimate”
The suspected network's most important shield was not technology alone.
It was the appearance of normal business.
A savings account receiving repeated large-value transfers from unrelated individuals can immediately appear unusual. A commercial current account, however, is expected to handle frequent and sometimes high-value transactions.
That difference allegedly gave the operators room to operate.
|
Traditional fraud signal |
The suspected Balangir model |
|---|---|
|
Savings account |
Commercial current account |
|
Individual account holder |
Business entity |
|
Sudden personal deposits |
Transactions presented as business activity |
|
Local victim |
Victims allegedly located across states |
|
One-to-one money trail |
Multiple transfers and layered accounts |
|
Local complaint |
National cyber-fraud complaints |
|
Geography-based investigation |
Centralised digital transaction mapping |
The suspected operators therefore did not necessarily need to defeat every banking security system.
They allegedly needed to look sufficiently ordinary for long enough.
That is what makes the case important beyond Balangir.
The Money Trail That Changed Everything
At the centre of the investigation is the alleged transfer of Rs35 lakh by a Delhi-based senior citizen into the Samaleswari Enterprises account.
The significance of that transaction was not merely its value.
It was the possibility that the account was already visible inside a wider network of complaints and suspicious transactions.
|
Money-trail step |
What investigators had to establish |
|---|---|
|
1. Victim payment |
How the Delhi victim was induced to transfer ₹35 lakh |
|
2. Destination account |
Why the money landed in the Balangir-linked business account |
|
3. Previous transactions |
Whether the same account had received money from other unrelated victims |
|
4. Outward transfers |
Where the money moved after entering the account |
|
5. Secondary accounts |
Whether downstream accounts were connected to the alleged wider syndicate |
|
6. Human links |
Whether account operators were connected to handlers in Chhattisgarh and elsewhere |
This is where the Indian Cyber Crime Coordination Centre (I4C) becomes central to the story.
The strength of the system is not simply that a complaint is registered.
It is that financial and complaint information can potentially be connected across jurisdictions.
How I4C Telemetry Spooked the “Clever” Network
The suspected operators appear to have relied on a very old assumption:
A cybercrime committed in Delhi would remain a Delhi case until someone manually followed the money to Odisha.
Modern cybercrime coordination is designed to challenge exactly that fragmentation.
The national cybercrime infrastructure, including the Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS), enables financial-fraud complaints and transaction information to be coordinated across jurisdictions.
|
Old assumption of the mule network |
What the national system changes |
|---|---|
|
Delhi complaint remains in Delhi |
Complaint can become part of a wider financial trail |
|
Mumbai victim is a separate case |
Common account identifiers can expose connections |
|
Odisha account appears geographically distant |
Bank/account/transaction identifiers connect locations |
|
Local police see one transaction |
Wider data can reveal repeated patterns |
|
Investigation starts from the account holder |
Investigation can work backwards from multiple victims and transactions |
The critical breakthrough, therefore, was not necessarily a dramatic raid.
It was the connection of apparently unrelated dots.
A Delhi victim.
An Odisha business account.
Other transaction records.
Other states.
And alleged links leading towards handlers outside Odisha.
Once those dots were connected, the geography that had protected the network for years became far less useful.
From Digital Trail to Physical Raid
The Balangir Cyber Crime and Economic Offences Police then had a different problem.
Digital evidence can disappear.
A phone can be wiped.
A laptop can be reset.
A password can be changed.
A remote operator can attempt to destroy or alter information.
That makes the physical seizure of devices and documents critical to the investigation.
|
Evidence seized / examined |
Why it matters |
|---|---|
|
Five mobile phones |
May contain communication, account access, OTPs, contacts and transaction information |
|
Laptop |
Potential source of banking, communication and digital-financial evidence |
|
Checkbooks |
Can establish control and operation of business accounts |
|
Passbooks/banking records |
Can help reconstruct the financial trail |
|
Corporate seals/stamps |
Can help establish how the firms were represented and operated |
|
Debit cards |
Can connect individuals to specific banking facilities |
|
Corporate registers/documents |
Can help investigators examine the authenticity and functioning of the businesses |
The forensic chain matters
For a cyber-fraud prosecution, simply producing a seized mobile phone is not enough.
Investigators must establish what was seized, from whom, how it was preserved, how the data was extracted and how its integrity was maintained.
Where appropriate, forensic protocols can include isolation of devices from networks, preservation of original evidence, forensic imaging and cryptographic hashing so that the extracted material can later be tested for integrity.
The investigation therefore has two parallel tracks:
Financial trail + digital evidence.
Both have to meet evidentiary requirements before they can carry the case through prosecution.
The Corporate-Front Question
The presence of business names and corporate documentation raises another important question:
Were these genuine businesses that were later misused, or were the businesses created or operated primarily as vehicles for moving illicit funds?
That distinction has to be established through investigation rather than assumed from the existence of company seals or current accounts.
|
Investigation point |
Question for police |
|---|---|
|
Business registration |
Who actually registered and controlled the firms? |
|
KYC records |
What documents were submitted to banks? |
|
Physical address |
Did the businesses genuinely operate from the declared locations? |
|
Business activity |
Were there corresponding purchases, sales, invoices and customers? |
|
Banking behaviour |
Did transaction volumes match the declared business? |
|
Account control |
Who possessed cards, cheques, credentials and banking devices? |
|
Inter-state connections |
Who were the persons receiving or directing the funds? |
|
Communication records |
Did account operators communicate with alleged handlers? |
That evidence chain is more important than simply labelling the firms “fake”.
The Bigger Question for Odisha: Could There Be More Such Accounts?
This is where the Balangir case becomes a warning rather than merely an arrest story.
If commercial current accounts can be misused as mule-account infrastructure, the problem cannot be solved only by catching the account operators after a cybercrime complaint arrives.
Odisha has to move upstream.
|
Risk area |
What Odisha should examine |
|---|---|
|
New current accounts |
Stronger scrutiny of high-risk business categories |
|
Existing accounts |
Periodic transaction-pattern review |
|
Sudden transaction velocity |
Compare actual turnover with declared business |
|
Multiple unrelated states |
Flag unusual interstate inflows |
|
Rapid onward transfers |
Identify accounts acting as transit points |
|
Dormant-to-active accounts |
Examine sudden spikes in activity |
|
Corporate shell behaviour |
Compare banking activity with GST/business records where legally available |
|
Multiple firms at similar addresses |
Examine common ownership/control indicators |
|
Bank onboarding |
Strengthen physical and documentary verification |
|
Police-bank coordination |
Create faster escalation channels for suspicious mule-account intelligence |
The objective should not be to criminalise legitimate businesses simply because they receive large payments.
It should be to identify behavioural anomalies.
What Odisha Can Learn From Other States
Other states have experimented with stronger approaches to cyber-financial crime, but Odisha should adopt such measures only after verifying their legal, technical and operational effectiveness.
|
Model / approach |
Lesson for Odisha |
|---|---|
|
Bank-branch accountability |
Examine whether weak KYC/onboarding practices are enabling mule accounts |
|
AI/data-led mule detection |
Identify repeated interstate transaction patterns rather than waiting for individual complaints |
|
Regional database integration |
Connect cybercrime, banking and financial intelligence at the state level |
|
Rural financial-node audits |
Do not assume cybercrime infrastructure exists only in major cities |
|
Rapid account freezing mechanisms |
Strengthen the speed of lawful intervention once credible fraud intelligence arrives |
|
Post-incident financial mapping |
Continue tracing money after the first arrest rather than treating the account holder as the end of the investigation |
The Immediate Roadmap for Odisha
The Balangir operation points towards a five-part strategy.
|
Priority |
Action |
Expected benefit |
|---|---|---|
|
1. Map mule accounts |
Build a state-level watch mechanism around recurring cyber-fraud-linked accounts |
Detect repeat offenders |
|
2. Watch transaction behaviour |
Identify rapid inflows, multiple unrelated senders and immediate onward transfers |
Detect possible layering |
|
3. Strengthen current-account KYC |
Give greater scrutiny to high-risk business registrations and declared activity |
Reduce use of paper businesses |
|
4. Integrate intelligence |
Faster coordination between I4C, Odisha Police, banks and relevant agencies |
Shorten the time between complaint and intervention |
|
5. Follow the money |
Investigate upstream handlers and downstream beneficiaries, not merely local account holders |
Break the larger syndicate |
The Real Lesson From Loisingha
The most important part of the Balangir case may not be the five phones seized or even the arrest of the alleged account operators.
It is the collapse of a strategy that depended on fragmentation.
For years, the suspected network could allegedly sit in one place while victims were scattered across India, banking transactions passed through Odisha and handlers operated elsewhere.
That model depended on one thing:
Nobody connecting all the dots quickly enough.
I4C's growing role in coordinating cyber-fraud information changes that equation.
The challenge for Odisha now is to make sure the lesson does not end with one raid.
Because if one network could allegedly hide behind agro-trading identities for more than three years, the question is no longer only who has been caught.
The bigger question is:
How many apparently ordinary business accounts are currently behaving like mule accounts – and can Odisha identify them before the next victim loses Rs35 lakh?
Related Topics
Explore more stories