Landing a new job usually comes with a few routine formalities, such as sharing identity documents, opening a salary account or completing verification checks. Few job seekers expect that the same process could be exploited by cybercriminals. But a new report by the Asia Pacific Group on Money Laundering (APG) documents how an international syndicate allegedly used fake recruitment to procure Indian bank accounts, debit cards and registered SIM cards that were later supplied to handlers based in the Philippines.


The Cyber Scam Hubs and Human Trafficking Report 2026 is based on an APG project co-led by Indonesia and the United Nations Office on Drugs and Crime (UNODC). It examines how organised criminal syndicates recruit victims, run cyber scam hubs and launder illicit proceeds across the Asia-Pacific region. One of its India case studies traces how fake recruitment was allegedly used to obtain bank accounts, debit cards and registered SIM cards that eventually reached cyber fraud operators in the Philippines.

How the scam worked

The India case study centres on an investigation by the Cyber Crime Police Station in Patiala, which uncovered an international syndicate allegedly involved in procuring and exporting bank accounts and SIM cards from India to handlers in the Philippines.

According to the report, the syndicate approached job seekers under the guise of remote employment verification. They were asked to open new bank accounts and hand over their passbooks, debit cards and registered SIM cards. These pre-activated bank kits and SIM cards were then allegedly supplied to Indian nationals based overseas who were involved in online cyber fraud.

The investigation began after complaints of fraudulent online job offers were received through the National Cybercrime Reporting Portal. Victims said they had been asked to deposit small registration fees into Indian bank accounts. Investigators later found that several of these accounts were being operated remotely from IP addresses geolocated in the Philippines.

The probe also uncovered consignments of SIM cards and debit cards concealed inside the seams of T-shirts and sent to Manila through private courier services using false sender details. Forensic analysis of seized mobile phones and laptops revealed conversations between Indian recruiters and overseas handlers on Telegram, WhatsApp and Signal discussing "SIM shipments," "account activation," and "salary transfers," pointing to what investigators described as a coordinated operation.

Investigators identified 18 active mule accounts linked to individuals from Patiala, Bathinda and Sangrur that allegedly channelled around ₹2.99 crore between February and June 2025. The money, received through UPI and IMPS transfers, was quickly transferred to beneficiary accounts or cryptocurrency exchanges. According to the report, the proceeds primarily came from fake recruitment and job fraud schemes.

The accused also allegedly posed as human resources executives of reputed companies and promised overseas jobs in return for "processing" or "document verification" fees. Four principal accused were arrested during the investigation, while police recovered 231 SIM cards, 18 debit cards, multiple passbooks and courier receipts. Authorities also froze part of the ₹2.99 crore identified as illicit proceeds.

The bigger picture

The Patiala investigation is one example of a broader trend highlighted in the APG report. It says fake job offers remain the most common recruitment method identified by member jurisdictions for people trafficked into cyber scam hubs, where they are often forced to carry out online fraud.

Fraudsters typically impersonate recruiters from well-known companies, promise attractive salaries for jobs requiring little experience and, in many cases, ask candidates to pay registration or processing fees before onboarding.

The report also highlights the financial ecosystem that keeps these operations running. Mule accounts, unlicensed financial service providers, virtual assets, peer-to-peer transfers, over-the-counter brokers and crypto ATMs are among the channels used to move or launder criminal proceeds. Various estimates cited in the report suggest cyber scam hubs generate tens of billions of US dollars every year and have victimised people in more than 100 jurisdictions worldwide.

The findings come as India steps up efforts to tackle cyber-enabled financial crime. The Ministry of Home Affairs has established the Cyber Fraud Mitigation Centre under the Indian Cyber Crime Coordination Centre (I4C), bringing together banks, payment service providers, telecom operators and law enforcement agencies to improve coordination against online fraud.

The APG's findings also echo recent advisories issued by CyberDost, I4C's cyber safety initiative. In one such advisory on fake job offers, CyberDost urged job seekers to verify employers before accepting offers, avoid paying registration fees and never share bank information, Aadhaar details or OTPs with unknown recruiters. It also advised people to report suspicious activity through the National Cyber Crime Reporting Portal or by calling the national cybercrime helpline, 1930.

Disclaimer: Comments posted here are the sole responsibility of the user and do not reflect the views of THE WEEK. Obscene or offensive remarks against any person, religion, community or nation are punishable under IT rules and may invite legal action.