Scammers Steal Rs 78 Lakh via Gold Loan Firm Software Hack in Mumbai | Mumbai News


Scammers Steal Rs 78 Lakh via Gold Loan Firm Software Hack in Mumbai
The case was registered at the Central Cyber police station on July 17 after police learnt that fraudsters gained unauthorised access to the firm’s authorised Omnifin (Loan Management System – LMS) software and third-party API system, and that fraudulent transactions were auto-generated without any company approval or one time password (OTP) and transferred to various unknown bank accounts.

Mumbai: Scammers gained illegal access to the software of a Parel-based gold loan firm and, through the app, instructed a private bank to clear 18 suspicious and unauthorised transactions totalling Rs 78.1 lakh from the company’s current account within an hour on July 13, police said.The case was registered at the Central Cyber police station on July 17 after police learnt that fraudsters gained unauthorised access to the firm’s authorised Omnifin (Loan Management System – LMS) software and third-party API system, and that fraudulent transactions were auto-generated without any company approval or one-time password (OTP) and transferred to various unknown bank accounts.While tracking the money trail, cyber police found that scammers transferred the funds to a finance company and to nationalised and private banks in Jammu & Kashmir, Kerala, Maharashtra and other states between 10.49 am and 12.18 am on July 13. “The team has sought details from the banks about the account holder to which the money has been credited. Meanwhile, the nodal officers of these banks have instructed to freeze the account. The team is gathering details as the 18 transactions was done in the range between Rs2 lakhs and Rs7 lakhs each. Probe is on to find out any internal bank or company’s staffs involvement in the fraud,” said a police officer of the Central cyber police station.During the probe, it was observed that an unknown accused tampered with the original bank details and system of the gold loan company and gained unauthorised access to its authorised Omnifin (Loan Management System – LMS) software and third-party API system.In the complaint, the company’s director GM Amit said: “Our company’s current account is our corporate account, and all financial transactions of the company are conducted through this account. As per our business process, after receiving the necessary documents and application form from the borrower, the relevant loan amount is disbursed to the borrower’s account after verification as per company rules. To streamline the loan disbursement process, our company uses a ‘Loan Management System’ (LMS) software named ‘Omnifin’. This is our internal software, and it contains complete information about all transactions, vendors, and third parties.”Police said the software was integrated with the private bank’s system through an authorised third-party API service provider, Paysprint Private Limited Company. “Due to this secure API integration, payment instructions are directly transferred to the bank. According to this system, when a request for loan disbursement comes from a borrower or a third party, the loan process is completed by the software. After the process is complete, an automatic notification is sent to the Bank via the authorized API to transfer the amount. Since this entire system is completely API-based, no manual OTP or separate approval is required. Information about money being debited from the account is automatically generated once the transaction is complete,” said the cyber police.The firm noticed discrepancies in its bank account on July 14 and found unauthorised transactions. “The transactions were not related to any approved loan account or valid as per our company’s daily routine, all transactions from the previous day are reconciled on the next day. Accordingly, on July 14, when we were verifying and reconciling the transactions, we noticed that the above entries did not match. Upon thorough investigation, it became clear that all these transactions were not related to any approved loan cases or customer requests, but were completely unauthorized and illegal,” the firm’s director said in the FIR.The company then filed a complaint on the 1930 Cyber Helpline on July 16 and lodged the FIR with the Central Cyber police against unknown cyber criminals for gaining unauthorised access to the company’s accounts by tampering with the system. The complaint was filed against the unknown cyber criminals, bank account holders and their accomplices.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *