No OTP, no PIN, no CVC… yet ₹5.99 lakh was withdrawn from an FD; find out how.
No OTP was received, nor were a PIN or CVC shared, yet nearly ₹6 lakh vanished from a Fixed Deposit (FD). This cyber fraud case in Bhopal has raised serious questions about banking security. Find out how the fraudsters managed to access the FD.
Cyber fraud cases are no longer limited to standard bank accounts or UPI; fraudsters are devising new ways to access people’s savings. One such case has emerged in Bhopal, where approximately ₹6 lakh was withdrawn from the Fixed Deposit (FD) of a 61-year-old man. No OTP was sent to the individual’s mobile phone during the transfer, nor did he share his password, PIN, CVC, or any banking-related information with anyone. Let us understand how such a large sum was withdrawn from the FD.
₹5.99 lakh withdrawn in three transactions
According to the police, Sharif Ahmed Qureshi (61), a resident of Afkar Colony in Bhopal, holds a savings account and an FD with the Ashoka Garden branch of ICICI Bank. On September 4, between 12:00 PM and 12:30 PM, three online transactions were executed via net banking from his FD. A total of ₹5,99,009.62 was transferred to another account through these transactions.
Upon learning of the withdrawal, Sharif Ahmed immediately lodged a complaint with the National Cyber Crime Helpline (1930). Subsequently, based on the ‘e-Zero FIR’ received from the Cyber Cell, the Aishbagh police registered a case of fraud against the accused and initiated an investigation.
How did the fraud occur if there is no separate net banking for FDs?
While FDs do not have a separate net banking facility, they are linked to the bank’s savings account. If an FD is created via a mobile banking app, it can also be liquidated (broken) using the same app. Fraudsters can exploit this very process. According to cyber and banking experts, fraudsters lure customers into their trap using pretexts like processing a refund or recovering money. They then prompt the customer to download a screen-sharing or remote access app on their mobile and ask them to open their banking app.
How do fraudsters gain access to your mobile banking app?
Fraudsters typically do not gain direct access to the banking app; instead, they trick the customer into downloading screen-sharing or remote access apps by promising refunds, money recovery, or citing other reasons. They then instruct the customer to open the banking app and follow specific steps. Once the screen is shared, the fraudsters can view banking details displayed on the mobile, including the account balance and fixed deposit (FD) information. They then exploit this information to attempt to liquidate the FD and transfer the funds to another account.
How can you protect yourself from cyber fraud?
- Do not download any screen-sharing or remote access app on your mobile at the behest of an unknown person.
- Instead of contacting unknown numbers found online for refunds, use the bank or company’s authorized app or website.
- Do not open your banking app or enter your PIN based on someone else’s instructions.
- If you fall victim to fraud, immediately file a complaint by calling 1930 and contact your bank.

