TechNewsReel
Live

Hybrid Cyber Fraud: Stolen Phones Used to Drain Bank Accounts in Hyderabad

Attackers are combining physical theft with digital exploitation to bypass security and empty victim accounts.

TechNewsReel Newsroom · August 26, 2026

A sophisticated 'hybrid cyber fraud' scheme has emerged in Hyderabad, India, where criminals combine physical theft with digital exploitation to drain bank accounts. This method bypasses traditional security layers by securing the physical device first to gain total control over the victim's financial identity.

According to the Hyderabad Cyber Crime Division, the modus operandi begins with the physical acquisition of a mobile phone. Attackers often observe a victim's unlock pattern from a distance or employ social engineering tactics—such as pretending to be a bus conductor—to trick victims into revealing their screen lock passwords. Once the device is unlocked, the criminals harvest sensitive data stored in galleries, notes, and messages, specifically targeting photos of ID cards, bank passbooks, and written PINs. This information is then used to access UPI apps and reset net banking passwords, allowing the attackers to transfer funds out of the accounts.

The Security Gap

This trend highlights a critical vulnerability in the current mobile security ecosystem. While many users rely on multi-factor authentication (MFA), the physical possession of an unlocked device effectively nullifies these protections. By gaining access to the device's internal storage, attackers can find the very credentials—such as government IDs and password hints—that banks use to verify identity during password resets. This turns the smartphone from a security tool into a roadmap for financial theft.

Laundering and Detection

To avoid detection by law enforcement and banking fraud systems, the stolen funds are not transferred directly to the attackers. Instead, the money is laundered through a complex network of digital wallets, online gaming platforms, and 'mule accounts.' These intermediaries mask the trail of the money, making it significantly harder for investigators to trace the funds back to the primary suspects.

Law Enforcement Response

Authorities have begun cracking down on these operations. The Hyderabad Cyber Crime Division has already arrested three individuals and seized five mobile phones linked to these crimes. As these hybrid attacks become more common, officials emphasize the danger of weak device locks and the risk of storing sensitive financial documents, such as photos of passbooks or PINs, directly on a mobile device. Future investigations will likely focus on the network of mule accounts used to facilitate the laundering process.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.