CBI raids ten sites, arrests four in US tech-support fraud case
The CBI searched ten sites in Punjab and Delhi and arrested four people over a Mohali call centre it says posed as Microsoft and US agencies to extort American victims.
The Enforcement Action
The Central Bureau of Investigation (CBI) has searched ten locations across Punjab and Delhi and arrested four people in connection with an alleged international tech-support fraud and extortion operation that the agency says primarily targeted citizens of the United States. According to the CBI account, carried by the official Prasar Bharati news service, the searches were conducted on the intervening night of 5-6 August 2026 and centred on a call centre operating from Mohali in Punjab.
The agency has said the operation impersonated Microsoft, financial institutions and, in some instances, law-enforcement agencies to pressure victims into parting with money. In its statement the CBI said "the main accused, along with his three accomplices, have been arrested." The public release does not name the four individuals. This report therefore describes them only by the roles the agency has assigned them: the person the CBI identifies as the principal operator of the Mohali call centre and three others said to have assisted the operation. During the searches the agency says it recovered more than twenty mobile phones, about fifteen laptops and tablets, several hard disks, pen drives and memory cards, cryptocurrency wallet material, cash and a set of documents it describes as incriminating.
It is important to be clear about what this action legally is. It is an investigation-stage step, not a court verdict. The four have been arrested and the CBI's case is at the stage of gathering and testing evidence; a chargesheet is yet to be filed and examined by a court. The arrested persons have not publicly responded to the CBI's action, and no response from them is on the public record.
How the Scheme Worked
The mechanism the CBI describes is a familiar cyber-enabled one, run at scale from a scripted call centre. According to the agency, victims first encountered pop-up messages on their computer screens that displayed counterfeit Microsoft toll-free numbers and warned, falsely, that their systems were infected or compromised. Alarmed users who rang the number were connected to operators at the call centre who posed as Microsoft technicians or as staff of financial institutions.
From there, the CBI says, the operators steered victims towards payment. In the simpler version of the script, callers were persuaded that their computers needed urgent repair or protection and were charged for services that did not exist. In a more coercive version, the agency says, operators impersonated law-enforcement officials and threatened victims with arrest or legal action unless they paid. The CBI has said that in some instances victims were falsely accused of grave offences, including possession of child sexual abuse material, and were frightened into transferring money, in several cases in the form of cryptocurrency.
The money trail, as the agency describes it, ran from the victims through cryptocurrency channels and was then layered by operators based in Delhi. Coverage of the CBI's case has cited illustrative victims, including a resident of Florida said to have transferred roughly USD 440,000 in 2022 and a resident of New Jersey said to have transferred about USD 130,000 in 2023, both through cryptocurrency machines. These figures come from reporting of the case rather than from the agency's public release, and they are offered here only to indicate the scale the investigators are examining, not as settled findings.
On the procedural history, what is on record is straightforward. The CBI registered a case, conducted coordinated searches at ten premises on the night of 5-6 August 2026, seized the electronic and financial material listed above, and arrested four people. The examination of the seized devices and wallets, and the tracing of the cryptocurrency, is the next investigative phase.
The Law Invoked
This is a CBI criminal investigation, and it is worth being precise about the legal register rather than guessing at charges that have not yet been framed. The CBI's public statement, as carried by the Prasar Bharati service, does not enumerate the specific statutory sections under which the case has been registered. In keeping with sound practice, this report does not supply section numbers that the official record does not state.
What can be said in general terms is the category of law such conduct falls under. Cases built on the deception of victims for money engage the offences of cheating and criminal intimidation in India's general penal law, while the use of fake pop-ups, spoofed identities and computer resources to deceive engages the country's information-technology statute. Where proceeds of crime are moved and layered, the anti-money-laundering framework can also come into play, which is why the tracing of cryptocurrency and the Delhi-based layering matter. None of this should be read as a list of charges the CBI has confirmed. It is the legal landscape that governs conduct of this kind, and the precise provisions will appear only when the agency files its chargesheet.
What Happens Next
The procedure from here follows the standard course of a CBI case. The four arrested persons will be produced before the competent court, which will decide on remand and, in due course, on bail. The agency will continue its investigation, examine the seized devices and cryptocurrency wallets, seek to identify further victims and money channels, and, if the evidence supports it, file a chargesheet. Only once a court takes cognizance of that chargesheet does the matter move to trial.
Because the victims are said to be in the United States, the case is likely to involve cross-border cooperation, through mutual legal assistance and coordination with foreign agencies, to corroborate victim accounts and follow the cryptocurrency. That process is slow by design.
At this stage everything the CBI has stated remains an allegation to be tested through due process. An arrest establishes that the agency has grounds to detain and question; it does not establish guilt. The presumption of innocence continues to operate, and the outcome will be decided by a court, not by the investigation.
What It Means
For ordinary computer users, the value of a case like this lies less in the arrests than in the pattern it documents, because the same script is used against Indian victims every day. Three practical lessons follow. First, genuine software companies do not display pop-up windows carrying a phone number and warning that your machine is infected; a message of that kind is itself the warning sign, and the safe response is to close the browser, not to call. Microsoft and other vendors do not cold-call users about viruses.
Second, no legitimate police force, court or tax authority anywhere collects fines or bail in gift cards, wire transfers to personal accounts, or cryptocurrency paid into a machine. A caller who claims to be an official and demands payment in these forms, especially with the threat of immediate arrest, is describing a method no real agency uses. The shocking accusation, made to induce panic, is part of the technique.
Third, verification is quick and free. If a call claims to come from your bank, hang up and dial the number printed on your card. In India, suspected cyber-financial fraud can be reported on the national helpline 1930 and at the government portal cybercrime.gov.in, and the sooner a transfer is reported, the better the chance of freezing it. The reader's aim should be calm scepticism, not fear.
FAQ
Has a court found the people arrested guilty?
No court has found them guilty. A chargesheet, FIR or provisional attachment contains allegations, not findings of guilt; the accused are presumed innocent until proven guilty, and due process continues. At present the CBI has made arrests and is investigating. Guilt can be established only by a court after a trial, and no chargesheet in this matter has yet been tested in court.
What exactly did the CBI do?
According to the agency's statement carried by the official Prasar Bharati service, the CBI searched ten locations across Punjab and Delhi on the night of 5-6 August 2026, focused on a call centre in Mohali, seized phones, laptops, storage media and cryptocurrency wallet material, and arrested four people it links to an alleged tech-support fraud and extortion operation that targeted US citizens.
Were any Indians affected?
The CBI's account describes victims in the United States. However, the method it describes, fake pop-ups, spoofed Microsoft and law-enforcement identities and demands for payment in cryptocurrency, is used against Indian residents as well, which is why the case carries a domestic safety lesson even though the named victims are abroad.
How can I tell a tech-support scam call from a genuine one?
Treat any unsolicited pop-up or call that claims your device is infected as suspect. Real vendors do not warn you this way or ask for remote access on a cold call, and no genuine agency demands payment in cryptocurrency or gift cards. When in doubt, disconnect and call the official number printed on your card or bill.
What should I do if I have already paid such a caller?
Act quickly. In India, call the cyber-crime helpline on 1930 and file a report at cybercrime.gov.in, contact your bank to flag the transaction, and preserve messages, numbers and receipts. Fast reporting improves the odds of freezing a transfer before it is layered away.
Where can I read the official statement?
The CBI's account is carried by the government's Prasar Bharati news service, which is linked in the source note below.
This report is based on the official CBI statement carried by Prasar Bharati (newsonair.gov.in). It was surfaced via coverage aggregated on Google News.
This report describes enforcement actions and allegations on the public record, attributed to the officials cited. An order, FIR or chargesheet is not a conviction; parties are presumed innocent until proven guilty.
Named in this report, or spotted an error? Corrections and responses: editor@oquilia.com. We correct errors promptly and record responses from named parties.
Sources & Citations
- CBI unearths international tech-support fraud and extortion racket in Punjab — CBI / Prasar Bharati (newsonair.gov.in)