Surat police arrest 18 year old school dropout in Rs 64 crore AI-powered cyber fraud
- In Reports
- 01:17 PM, Jul 22, 2026
- Myind Staff
An 18-year-old school dropout has landed in police custody for allegedly running a nationwide cyber fraud operation that used artificial intelligence to create fake banking and government mobile applications. Surat City Cyber Crime Cell arrested Rohit Virendrasinh Shakya from a hotel in Kanpur, Uttar Pradesh. Police said he developed malicious Android application (APK) files and supplied them to cybercriminal gangs operating from Jharkhand's Jamtara, along with networks based in Haryana and Rajasthan. Investigators said the network helped cybercriminals steal more than Rs 64 crore from victims across India.
Police said Shakya dropped out after Class 11 but became an expert coder at the age of 16. He allegedly used AI tools and Telegram channels to create fake applications that closely resembled genuine banking, government and private-sector apps. Investigators said he sold these malicious APK files through a subscription model. Cybercriminals reportedly paid him Rs 15,000 every month for customised malware, along with regular software updates and maintenance.
According to investigators, Shakya created two different types of applications. The first was a "victim app" that users unknowingly installed on their mobile phones after receiving it through messaging platforms. The second was an "admin app" that allowed cybercriminals to remotely monitor infected devices. Police said the admin app gave fraudsters access to OTPs, banking details and other sensitive information in real time. This access allowed them to carry out fraudulent transactions without the victims noticing immediately.
The fake applications copied the appearance of several trusted organisations and services. These included SBI, Punjab National Bank (PNB), Axis Bank, UCO Bank, ICICI Bank, Union Bank, BigBasket, American Express, Aadhaar services, PM Kisan and RTO challan payment portals. Police said the fake apps looked almost identical to the original versions, making it difficult for users to identify them as malicious.
The investigation started after a Surat resident reported losing Rs 5 lakh in a cyber fraud case in May this year. Between May 15 and May 18, the victim received a fake "PNB One.apk" file through WhatsApp. Believing it to be the official Punjab National Bank application, the victim installed it on the phone. The device got compromised soon after installation. Cybercriminals gained access to the victim's banking details and transferred Rs 5 lakh from the victim's Prime Co-operative Bank account to a Union Bank account.
The victim immediately contacted the national cybercrime helpline, 1930, and reported the fraud. Surat Cyber Crime then registered an FIR and launched a detailed investigation. During the probe, investigators uncovered what they described as a large and organised cybercrime network instead of a single fraud case. The findings pointed towards a sophisticated operation that supplied malware to multiple cybercriminal groups across the country.
Digital forensic analysis revealed that Shakya had created 121 malicious APK applications. Police found that these applications had been installed on 21,672 mobile phones across India. Investigators also discovered that 2,928 devices were fully compromised after users installed the fake apps. These compromised devices were linked to 54,094 fraudulent banking transactions. Police estimated the total financial loss at around Rs 64.38 crore.
Investigators said fake RTO challan applications accounted for the highest number of fraud cases. Fake SBI and PNB applications followed closely. Police also found that Telegram played a major role in distributing the malicious APK files. Cybercrime syndicates in Jamtara, Haryana and Rajasthan allegedly received these applications through Telegram under a paid monthly subscription model. The service reportedly included regular technical support and software updates, allowing the malware to remain effective.
Following Shakya's arrest, Surat Police seized two mobile phones and a laptop from his possession. Officials have started a detailed digital forensic examination of the devices. Investigators are now trying to find out whether more cybercrime syndicates across the country used the same software. They are also examining whether other people played a role in developing, distributing or operating the malware network. The investigation remains ongoing as police continue to trace the full extent of the nationwide cyber fraud operation.

Comments