
The Enforcement Directorate has arrested two Mumbai-based men in a money laundering investigation into an alleged nationwide cyber fraud and “digital arrest” network that investigators suspect handled transactions worth around Rs 30,000 crore.
Fahim Moin Hussain Sayed and Naim Mueen Sayyed were arrested in Mumbai on Sunday, August 23, as the agency widened its investigation into a suspected network involving bank transfers, cash withdrawals, foreign exchange transactions and shell companies.
The scale of the investigation is striking. According to the Enforcement Directorate, the suspected network is linked to around 300 victim complaints and approximately 150 to 160 FIRs registered across 20 states and Union Territories. The agency suspects that the network moved about Rs 27,000 crore through banking channels and another Rs 3,000 crore through cash transactions.
The alleged fraud component is estimated at around Rs 4,000 crore, according to sources cited in reports on the investigation.
The case began with a complaint from Goa involving a woman WHO was allegedly subjected to a digital arrest and forced to transfer Rs 2.60 crore between May and June 2025 into accounts described as “Secret Supervision Accounts”. The subsequent money trail reportedly led investigators from victim accounts to bank accounts, cash withdrawals, foreign currency conversions and entities suspected of being shell or dummy companies.
The arrests highlight how digital arrest scams can extend far beyond a fraudulent phone call or video conversation. Once victims are manipulated into transferring money, investigators face a second challenge: tracing how that money is fragmented, withdrawn, converted and moved through apparently legitimate financial channels.
Why the ED arrests matter in the Rs 30,000-crore probe
The two arrests are significant because the Enforcement Directorate is investigating the suspected financial infrastructure behind the alleged cyber fraud rather than only the initial acts of impersonation or intimidation.
The ED, which operates under the Department of Revenue in the Union Finance Ministry, investigates money laundering offences under the Prevention of Money Laundering Act, or PMLA.
In this case, investigators are examining how money allegedly obtained from victims was subsequently circulated through multiple accounts and converted into cash and foreign currency.
The distinction is important. A digital arrest operation may begin with criminals impersonating police officers, investigators, customs officials or other authorities. But the money does not necessarily remain in the first account into which the victim transfers it.
Instead, investigators may have to reconstruct a chain involving numerous bank accounts, intermediary businesses, cash handlers and foreign exchange channels. That makes the financial trail a crucial part of the case.
How the alleged digital arrest operation came to light
The ED’s investigation was triggered by the case of a woman from Goa who was allegedly subjected to a digital arrest between May and June 2025.
Fraudsters allegedly convinced her that she was involved in a serious legal matter and pressured her into transferring Rs 2.60 crore to accounts referred to as “Secret Supervision Accounts”.
The terminology itself reflects the psychological technique often associated with digital arrest fraud. Victims are made to believe that their bank accounts, identity documents or mobile numbers are connected to criminal activity and that they must follow instructions from the supposed authorities to avoid arrest.
The victim may then be kept on video or voice calls for prolonged periods while being told not to contact family members, banks or police. The objective is to create urgency and isolation before money is demanded.
There is, however, no legal process in India under which a person can be placed under “digital arrest” through a video call.
That makes the phrase itself an important warning sign. A genuine arrest is a physical legal process carried out by authorised law-enforcement personnel under applicable law. A caller ordering someone to remain on a video call while demanding money or financial transfers is not exercising legitimate arrest powers.
The money trail allegedly ran through banks, cash and forex channels
One of the most revealing elements of the investigation is the alleged movement of the victim’s money after it entered the banking system.
According to sources, investigators found that funds were deposited into bank accounts, withdrawn in cash and subsequently converted into foreign currency through Reserve Bank of India-licensed money changers.
This alleged sequence shows why tracing cyber fraud can become complicated even when the original victim transfer is visible.
A bank transfer creates a digital record. But once money is withdrawn as cash, investigators may need to establish who collected it, where it went and how it was subsequently introduced into another financial channel.
Foreign exchange transactions can add another layer to the investigation because the money may be converted from Indian rupees into another currency before being moved or used elsewhere.
The ED suspects that the broader network handled banking transactions worth approximately Rs 27,000 crore and cash transactions worth another Rs 3,000 crore.
| Investigative figure | Amount or scale |
|---|---|
| Suspected total transactions | About Rs 30,000 crore |
| Suspected bank transactions | About Rs 27,000 crore |
| Suspected cash dealings | About Rs 3,000 crore |
| Estimated fraud involving victims | About Rs 4,000 crore |
| Victim complaints | About 300 |
| FIRs | About 150-160 |
| States and Union Territories involved | 20 |
These figures should not be read as meaning that Rs 30,000 crore was necessarily stolen from victims. The reported Rs 30,000 crore figure refers to the suspected financial transactions handled by the network, while the estimated amount involved in the alleged fraud is around Rs 4,000 crore.
That distinction is crucial when assessing the scale of the investigation.
Rs 2.60 crore Goa case became the starting point
The Goa victim’s alleged loss provides a more concrete picture of how the broader investigation developed.
The woman reportedly transferred Rs 2.60 crore over a period of several weeks after being subjected to the alleged digital arrest.
For investigators, a large transfer of this kind can provide a starting point for reconstructing the financial network. Bank records can reveal the destination accounts, subsequent transfers and withdrawals, while corporate records can help establish links between account holders and companies.
That process appears to have led the ED toward a wider network rather than an isolated group of fraudsters.
The agency now suspects connections extending across multiple states and Union Territories, with around 300 victim complaints and 150-160 FIRs forming part of the investigation.
Why shell companies are important in the alleged racket
Investigators have also examined companies allegedly connected to the network.
Sources said some shell or dummy companies linked to the case had people working as drivers or employees, and individuals living in single-room accommodation were listed as company directors.
The ED suspects that such arrangements may have been part of the network’s operating method.
On paper, a company can provide an appearance of legitimacy to a bank account. If an account is held in a company’s name and accompanied by corporate documentation, transactions may initially look different from an obvious personal fraud account.
That does not mean every company with modest operations or low-profile directors is a shell company. Nor does being listed as a director establish criminal involvement by itself.
In the present case, the ED’s investigation is aimed at determining whether the companies and individuals identified in the money trail were knowingly used to facilitate the alleged laundering of proceeds from cyber fraud.
That distinction will ultimately have to be established through evidence and the legal process.
ED searches uncovered Rs 3.25 crore in cash
The investigation has already resulted in searches in Mumbai and Goa.
The ED conducted two rounds of searches, with operations taking place in July and again on August 21. During these searches, the agency seized around Rs 3.25 crore in cash, according to sources.
Cash seizures can be particularly important in money laundering investigations because they may help investigators connect bank transactions with the physical movement of suspected proceeds.
However, a seizure is not by itself proof that every amount recovered represents proceeds of crime. Investigators still have to establish the source, ownership and purpose of the money and demonstrate the relevant links required under the law.
Why digital arrest scams are difficult to stop
The financial investigation also reveals why digital arrest scams have become such a serious cybercrime challenge.
Traditional fraud often depends on stealing passwords, exploiting technical vulnerabilities or obtaining access to bank accounts. Digital arrest scams can work differently.
The criminal may not need to break into the victim’s account at all.
Instead, the fraudster persuades the victim to authorise the transaction personally.
The attack therefore targets both Technology and human behaviour. The criminals create fear, impersonate authority and manufacture a legal emergency. The victim then acts under pressure.
Once money is voluntarily transferred, the criminals can move it through several layers before investigators can intervene.
This is why speed is critical. The longer money remains in the financial system, the greater the opportunity for it to be split across accounts, withdrawn or transferred elsewhere.
What “digital arrest” actually means for victims
The term can sound official, but it is not a legitimate legal procedure.
In a typical digital arrest scam, fraudsters may claim that a victim’s Aadhaar number, bank account, mobile connection, parcel or identity documents have been linked to a criminal case. They may impersonate officials and use video calls, fake documents, uniforms, police-style backgrounds or fabricated case details to make the story appear credible.
The victim is then instructed to remain online and follow financial instructions.
That psychological pressure is often the most dangerous part of the scam.
A person who would never normally transfer millions of rupees to a stranger may do so when convinced that refusing will lead to immediate arrest or the seizure of their assets.
The Goa case illustrates how severe the consequences can become. The alleged victim transferred Rs 2.60 crore, turning what may have started as a fraudulent communication into a major financial crime investigation.
Why the investigation spans 20 states and Union Territories
The reported geographic spread is another indication that investigators are dealing with a network rather than a single local fraud operation.
Cybercrime does not follow state boundaries. A caller can target someone in Goa, route money through an account in Maharashtra, use a company registered elsewhere and move funds through another financial intermediary.
That creates jurisdictional complications for traditional policing.
The existence of approximately 150-160 FIRs across 20 states and Union Territories suggests that multiple police investigations may have encountered parts of the same broader network.
For the ED, bringing the financial records together can help investigators identify connections that are difficult to see when each fraud is investigated separately.
What happens to the two arrested accused now?
After their arrest in Mumbai, Sayed and Sayyed were produced before a special PMLA court in Mumbai.
The court granted the ED transit remand, allowing the agency to take the accused to Panaji, Goa, where the underlying case was registered. The agency was expected to produce them before the special court in Panaji and seek custodial interrogation.
Custodial interrogation allows investigators to question the accused while continuing to examine documents, financial records and other evidence connected with the case.
The arrests, however, should not be treated as a finding of guilt. The allegations remain subject to investigation and judicial proceedings, and the accused are entitled to due process.
The larger challenge for India’s cybercrime system
The case comes as Indian authorities continue to focus on digital arrest and cyber-enabled financial fraud.
At the central level, the government has repeatedly highlighted the need for faster coordination between law-enforcement agencies, banks and digital platforms in cyber fraud cases. Prime Minister Narendra Modi also reviewed grievances involving cybercrime and digital arrest frauds at the 52nd PRAGATI meeting in June and stressed faster responses and better coordination.
The reason is simple: cyber fraud can move faster than traditional investigations.
A victim may lose money within minutes, while police procedures, bank coordination and interstate investigation can take considerably longer. Every delay can make recovery more difficult.
The ED’s Mumbai arrests therefore form only one part of a much larger challenge. Identifying the people making the fraudulent calls is important, but investigators also need to dismantle the financial infrastructure that allows the proceeds to be collected and moved.
What investigators will be looking for next
The next phase of the probe is likely to focus heavily on the financial architecture allegedly supporting the network.
Investigators will need to establish how the various bank accounts were connected, who controlled the accounts, which companies were used, who handled the cash and how foreign exchange transactions fitted into the broader money trail.
The suspected network’s scale also raises questions about whether the people arrested represent the core of the operation or only one part of a larger structure.
That distinction could determine how far the investigation eventually reaches.
The approximately Rs 3.25 crore cash seizure and the suspected Rs 30,000 crore transaction volume provide investigators with important leads, but the ultimate test will be whether those financial records can be converted into legally sustainable evidence connecting individuals and entities to the alleged proceeds of crime.
A warning for anyone receiving an “arrest” call
The central lesson from the case is straightforward: a government agency will not conduct a legitimate arrest through a video call and demand money to protect a bank account or avoid custody.
Anyone receiving such a call should not transfer funds simply because the caller appears to be a police officer, government official or investigator. The caller’s identity should be independently verified using official contact channels, rather than numbers or links supplied during the suspicious communication.
People who suspect they have become victims of cyber fraud should report the incident as quickly as possible because rapid reporting can give banks and law-enforcement agencies a better opportunity to trace or freeze funds.
The ED’s latest arrests show the other side of the same problem: what begins as a frightening phone call can develop into a complex financial network involving hundreds of complaints, multiple jurisdictions, shell companies, cash transactions and foreign exchange channels.
For investigators, the challenge is now to follow that money trail to its end. For the public, the warning is simpler: there is no such thing as a legitimate “digital arrest”, and fear of immediate legal action should never be allowed to become a reason to hand control of a bank account to a stranger.
For breaking news and live news updates, like us on Facebook or follow us on Twitter and Instagram. Read more on Latest India on thefoxdaily.com.

COMMENTS 0