‏إظهار الرسائل ذات التسميات Scam. إظهار كافة الرسائل
‏إظهار الرسائل ذات التسميات Scam. إظهار كافة الرسائل

From ₹15 to ₹10,887: SEBI Blocks 39 in RRP Semiconductor Stock Scam

From ₹15 to ₹10,887: SEBI Blocks 39 in RRP Semiconductor Stock Scam

SEBI has barred 39 individuals and entities from the securities market after uncovering alleged manipulation in RRP Semiconductor’s stock, which surged an extraordinary 725 times—from ₹15 to ₹10,887.10—within 19 months. The regulator flagged coordinated trading, preferential allotments, and misleading narratives as part of a pump‑and‑dump scheme.

SEBI has issued an official Interim Order (No. WTM/AS/IVD-2/ID20/32337/2026-27) in the matter of RRP Semiconductor Ltd. on April 10, 2026, barring 39 entities from the securities market. The Bombay Stock Exchange (BSE) also circulated a notice summarizing the order and listing the restrained parties.   

Key Details of the SEBI Action

  • Date of Interim Order: April 10–12, 2026
  • Entities Barred: 39 individuals and firms
  • Company Involved: RRP Semiconductor Ltd.
  • Stock Surge: From ₹15 to ₹10,887.10 in 19 months (a 725x increase)
  • Regulatory Concerns: Coordinated trading, preferential allotment at ₹12 per share, misleading narratives, evidence from call records and financial transactions

Why SEBI Intervened

  • Market Integrity Risk: Abnormal rise raised red flags
  • Investor Protection: Prevent retail investors from being trapped
  • Systematic Manipulation: Structured approach to inflate prices

Background on RRP Semiconductor

Originally focused on other businesses, the company shifted to semiconductors and issued preferential shares at ₹12 each. This narrative change, combined with coordinated trading, fueled the meteoric rise. The case highlights how sectoral buzzwords (like semiconductors) can be exploited to mislead investors.

Impact & Implications

Aspect Details
Stock Price Movement ₹15 → ₹10,887.10 (19 months)
Entities Barred 39 individuals/firms
Regulatory Tool Interim order under SEBI Act
Investor Risk Pump‑and‑dump losses for retail investors
Evidence Used Call records, financial transactions, trading patterns

Risks & Lessons for Investors

  • Beware of unnatural surges—unsustainable growth
  • Watch for preferential allotments before rallies
  • Narrative manipulation using sectoral buzzwords
  • Do due diligence on fundamentals before investing

Summary Table: SEBI Interim Order on RRP Semiconductor


Aspect Details
Order Date April 10, 2026
Order No. WTM/AS/IVD-2/ID20/32337/2026-27
Entities Barred 39 individuals/firms
Promoters Named Ira Mishra, Sumita Mishra, Ramesh Mishra
Trading Contributors Multiplier, Pace, Neo
Individuals Linked Chetan R. Shah, Bhavin Y. Mehta, Atul Goel, Nikhil Gupta
Restriction No dealing in RRP Semiconductor shares

Takeaway

SEBI’s move underscores its increasing vigilance against market manipulation and highlights the importance of investor caution in speculative stocks. For retail investors in India, this case is a reminder to avoid chasing hype‑driven rallies and rely on fundamentals rather than narratives.

Massive Browser-Based RTO Scam Targets Indian Vehicle Owners; Over 36 Fake e-Challan Domains Discovered

Massive Browser-Based RTO Scam Targets Indian Vehicle Owners; Over 36 Fake e-Challan Domains Discovered

  • Sophisticated Phishing Campaign Uses Localized Infrastructure Including Reliance Jio Numbers and State Bank Account Links; Shared Infrastructure Also Targets BFSI and Logistics Sectors
Cyble Research and Intelligence Labs (CRIL) has uncovered a large-scale browser-based phishing campaign targeting Indian vehicle owners through fake e-Challan portals. The sophisticated operation, which represents an evolution from previous malware-driven attacks, leverages over 36 fraudulent domains and exploits trust in Regional Transport Office (RTO) services to harvest banking credentials.

The investigation, which aligns with recent warnings from mainstream media including Hindustan Times, reveals an active and ongoing campaign using localized infrastructure to enhance credibility and maximize victim impact.

"This campaign demonstrates a pivot from the previously observed Android malware use to browser-based fraud, which significantly lowers the technical barriers and expands the pool of potential victims," said Daksh Nakra, Senior Manager of Research and Intelligence at Cyble. "The use of Indian mobile numbers registered with popular telecom operators and linked to State Bank of India accounts shows how attackers deliberately exploit trust in familiar institutions to increase success rates."

Campaign Overview and Attack Flow

Multi-Stage Phishing Operation

  • Victims receive SMS messages claiming overdue traffic fines.
  • Urgency created through threats of license suspension, court summons, and legal proceedings.
  • Messages contain shortened URLs mimicking legitimate e-Challan domains.
  • Victims are led to cloned government portals.

Key Technical Findings:

Dynamic Challan Fabrication

  • Portal generates realistic-looking violation records regardless of input.
  • Displays modest fine amounts (typically INR 590) with near-term expiration dates.
  • No backend verification occurs—purely psychological manipulation.
  • Replicates official MoRTH branding and NIC insignia.

Card Data Harvesting

  • Payment pages restrict options to credit/debit cards only.
  • Avoids traceable UPI and net banking transactions.
  • Collects full card details including CVV and expiry dates.
  • Claims processing through Indian banks.
  • Accepts repeated submissions, transmitting all data to attacker backend.

Localized Infrastructure for Enhanced Credibility

  • SMS sent from Indian mobile number registered with Reliance Jio Infocomm Limited.
  • Phone number linked to State Bank of India account.
  • Combination of local telecom carrier and public-sector bank association increases perceived legitimacy.

Shared Fraud Infrastructure Uncovered

  • Over 36 phishing domains impersonating e-Challan services.
  • Additional targets: HSBC-themed payment lures (BFSI sector).
  • Logistics company impersonation: DTDC, Delhivery.
  • Consistent UI patterns and payment-harvesting logic across campaigns.

Secondary Infrastructure

  • Multiple domains mimicking Parivahan services.
  • Automatically generated phishing domains suggesting rotation techniques.
  • Designed to evade takedowns and blocklists.
  • Same operational flow as primary campaign.

Anti-Detection Measures:

  • Content originally authored in Spanish, translated via browser prompts.
  • Indicates reuse of phishing templates across regions.
  • Browser-based warnings (Microsoft Defender) ignored due to urgency cues.
  • Domain generation techniques for infrastructure resilience.

Multi-Sector Risk:

  • Government service users (e-Challan, Parivahan).
  • Banking customers (HSBC-themed lures).
  • E-commerce users (DTDC, Delhivery impersonation).

Critical Recommendations

  • Never click links in unsolicited SMS claiming traffic violations.
  • Always verify fines directly through official government portals (parivahan.gov.in).
  • Scrutinize domains carefully—look for spelling variations and unusual TLDs.
  • Be suspicious of payment pages accepting only credit/debit cards.
  • Report suspicious messages to cybercrime authorities immediately.
Complete technical analysis, indicators of compromise (IoCs), MITRE ATT&CK mappings, and detection guidance are available in the full blog post here.

IoCs have been published to Cyble's GitHub repository for immediate integration into security platforms and threat intelligence feeds.

About Cyble

Cyble is a global AI-powered threat intelligence company providing organizations with real-time visibility into cyber threats through advanced research, dark web monitoring, attack surface management, and comprehensive security solutions. Cyble's platform delivers actionable intelligence enabling security teams to detect, respond to, and prevent cyberattacks before they cause significant damage.

For more information, visit www.cyble.com.

Apple Fires Several Indian-origin Employees for 'Misusing' Donation Scheme

Apple Fires Several Indian-origin Employees for 'Misusing' Donation Scheme

Apple has terminated several Indian-origin employees in the US for allegedly misusing the company's matching grants scheme. Under this program, Apple matches employees' donations to qualified charities. However, some employees reportedly created false donation records and arranged for the funds to be returned to themselves.

According to Mashable, Apple reportedly terminated 185 employees at its Cupertino headquarters for allegedly misusing the company's matching grants scheme.

The employees allegedly created false donation records and arranged for the funds to be returned to themselves, exploiting Apple's Matching Grants program.

While six individuals have been named by authorities, none of them are Indian. However, other reports indicate that many of the dismissed employees were of Indian origin.

The investigation involves charities connected to the Indian community, including the Telugu Association of North America (TANA).

The fraud scheme allegedly defrauded Apple of approximately $152,000 over three years.

The Santa Clara County district attorney’s office has charged six former employees, and warrants have been issued for their arrest.

Apple has not yet provided an official statement regarding the incident. The FBI, IRS, and DOJ are investigating the potential misuse of matching grants. The Telugu Association of North America (TANA) is among the organizations under scrutiny by the FBI, IRS, and DOJ for potential misappropriation of matching grants.

This situation highlights serious concerns about nonprofit ethics and corporate integrity.

In One of the World’s Biggest Known Deepfake Scams, UK Engg. Group Lost $2 Mn

In One of the World’s Biggest Known Deepfake Scams, UK Engg. Group Lost $2 Mn

A UK based engineering group, Arup, was targeted in a significant deepfake scam. The incident involved a hyper-realistic video created using artificial intelligence that featured a digitally cloned version of Arup's chief financial officer. This deepfake was used to deceive an employee into transferring a total of HK$200 million to various bank accounts during a video call.

Previously, Hong Kong police revealed what is one of the world's biggest known deepfake scams, but did not identify the company involved. However, Financial Times reported that it has confirmed it was the UK group Arup (officially Arup Group Limited). The engineering firm employs about 18,000 people globally and has annual revenues of more than £2bn.

The scam took place in the Hong Kong office of Arup and is considered one of the largest known deepfake scams to date.

Citing a Hong Kong police acting senior superintendent Baron Chan, the FT report said, "After a video conference joined by the company's digitally cloned CFO and other fake company employees. The staff member made a total of 15 transfers to five Hong Kong bank accounts before eventually discovering it was a scam upon following up with the group's headquarters."

Despite the substantial financial loss, Arup has confirmed that their financial stability and business operations were not affected, and none of their internal systems were compromised. The company, which is headquartered in London, has been working with the authorities, and investigations into the incident are ongoing.

Arup's east Asia chair Andy Lee stepped down in the weeks following the scam after just a year in the role. He was replaced by Michael Kwok, a former east Asia chair for the company. Lee said on his personal LinkedIn page that he had "decided to embark on a new opportunity".

This event highlights the increasing sophistication of cyber-attacks and the rising threat of deepfake technology being used for fraudulent purposes. It serves as a reminder of the importance of vigilance and the need for robust security measures to protect against such sophisticated scams.

Legal actions are being pursued in response to the deepfake scam that targeted Arup. The authorities have been notified, and investigations are ongoing. However, as of the latest updates, no arrests have been made yet¹²³. The case is classified as "obtaining property by deception," which indicates that law enforcement is treating it as a serious criminal matter.

Arup has been cooperative with the police, and while they have not disclosed details due to the ongoing nature of the investigation, they have confirmed that they are working with law enforcement to address the incident¹. The company has also expressed hope that their experience will help raise awareness about the increasing sophistication of cyber-attacks and the evolving techniques of malicious actors.

The incident underscores the importance of cybersecurity and the need for companies to stay vigilant against such advanced forms of fraud. It also highlights the challenges that law enforcement faces in tracking down and prosecuting perpetrators in the digital age, where the tools and methods used to commit crimes are constantly evolving. 

Over 100 Gujarat Engg. College Students Duped by Gurugram Startup, Misused Documents for ₹2.5 Crore Loan

Over 100 Gujarat Engg. College Students Duped by Gurugram Startup, Misused Documents for ₹2.5 Crore Loan

Over 100 students of a reputed engineering college in Ahmedabad, Gujarat have been caught in the scam of a dubious startup in Gurugram, said a report by iamGujarat.com authored by Ashish Chauhan. The students claim that the alleged startup took their documents and misused them on the pretext of giving them jobs. The startup took an education loan of Rs 2.1 lakh in the name of each student while keeping students in dark. When the students started getting calls from the bank for EMI, the students then came to know that the loan was taken in their name. Loans of more than 2.5 crore rupees have been taken in the name of 124 students.

The Gujarat Police has not yet registered a complaint in this matter because they say that this is a civil case, said the report. 

Citing the students, the report further said that these 124 students were selected in the group through campus placement in 2021. Two supposed representatives of the startup came to the Engineering college located in Sola, a suburb area of Ahmedabad city. The students says that the loan was taken two months after the students were hired. The startup claimed that they provide business consultancy to firms. This Gurugram-based startup,  the name which remain undisclosed in the report, was paying students irregularly. However, when reminders for EMIs of Rs 5,000 started coming from a well-known bank, these
students realized that the loan had been taken without their knowledge and consent.

The EMI amount was deducted from the account of the students who had balance in their bank account. While the CIBIL (credit rating) score of those who did not have a balance in their account was adversely affected. Students were not able to repay the loans, which they had not taken in first place, so their credit rating was going down. Students were mostly given work from home by this startup.

When the students confronted the representatives of the alleged company, the representatives said that the issue would be resolved quickly and that they need not worry.

One of the selected students in 2021 was automobile engineer Alwaz Pathan. He has recently filed a complaint at the Shahpur police station in Ahmedabad and has alleged fraud against two representatives of the company. "During the selection, he made us sign an agreement and took our digital signatures besides taking several documents.

"During the selection, he made us sign an agreement and took our digital signatures besides taking several documents. We were told that the job would be confirmed after a one-year probation period. Few days after my probation started, I received an SMS regarding EMI. When I asked the company about the EMI, they said that they will settle the amount in my salary. They neither gave us salary nor nor reimbursed us any amount", said Pathan.

Alwaz Pathan then realized that this startup had taken an education loan of Rs 2.10 lakh in the name of each student by misusing his documents and digital signature. Alwaz resigned from the firm but later came to know that the company had cheated 100 more students who graduated from the batch between 2021 and 2023 in this manner.

According to Alwaz Pathan, the future of the recruited students is uncertain as the company recently declared bankruptcy. "Many students do not have funds in their bank accounts. The CIBIL scores of students unwittingly caught in the scam have deteriorated." Alwaz Pathan's lawyer Irshad Mansoori said that he approached the Sola police but they refused to register a complaint. "We also approached the cyber crime police but they also did not take up the complaint.

According to information collected by Times of India from police sources, "Many students do not have funds in their bank accounts. The CIBIL scores of students unwittingly caught in the scam have deteriorated." Alwaz Pathan's lawyer Irshad Mansoori said that he approached the Sola police but they refused to register a complaint. "We also approached the cyber crime police but they also did not take up the complaint. After which we approached the Shahpur police but they refused to register an FIR as it was a civil case", said Irshad Mansoori.

"Government Giving 3 Months Free Recharge for Online Classes" Is A Fake Message Circulating on WhatsApp



Lockdown was resorted to avoid spread of coronavirus in the country and today most people are doing work from home. Due to the closure of schools and colleges, online classes are being given to children so that there is is no loss of education of children and all this has been possible only due to technology. Technology has kept each other connected even in these troubled times. But there are many people who are duping people in the name of online classes.

Recently, a message was becoming quite viral on the instant messaging app WhatsApp, in which it was claimed that the government is giving 3 months recharge absolutely free for online classes. But now the whole truth of this message has come to the fore. It has been claimed in this message that the government is providing free internet service to 100 million users for 3 months for online classes. 

Along with this, a link has also been given in the message and it is written that by clicking on this link you can also get free internet service. On clicking on the link given in the message, a fake website opens in which the photo of Prime Minister Narendra Modi has been given and it has also been claimed that users can choose their telecom operator and get free internet service for three months.

This message is completely fake, this message going viral on WhatsApp in the name of online class is completely fake . At the same time, the Press Information Bureau (PIB) has also shared a post regarding this message on the official Twitter account. In which, while warning the telecom users, it has been said that this message of free recharge for three months on WhatsApp is completely fake and do not click on the link given in it. No such announcement has been made by the Government of India. Beware of such fake website.

Importance of Real-time Tracking & How to Stay Safe from Online Scams - Explained by Blockchain.com


Social media can be a useful way to connect with others, stay informed and express yourself. However, the recent news also highlights the fact that hackers try to exploit social media security holes to their advantage.





Twitter experienced a significant security breach when some of the world’s most widely followed Verified Accounts — including those of Joe Biden, Barack Obama, Bill Gates and Elon Musk — started posting content linked to a crypto scam. 





The Twitter security team removed most of the fraudulent Tweets but unfortunately not before some people were persuaded to send bitcoin to addresses being shared by the perpetrators. An important fact to note in this online scam is that Blockchain.com wallets were not used in this scam .





By using the Blockchain.com Explorer, anyone can look up the balance of the addresses the attackers used. As all bitcoin transactions are publicly viewable, anyone can track the scam in real time. At the time of this writing, over $117,000 worth of bitcoin from 401 transactions were sent to the following two addresses: (addresses are hyperlinked below)





Address 1

Address 2





Caution is the name of the game. Blockchain.com has released a note which states ' Treat all offers of investment advice, mining opportunities, unofficial giveaway chances, or any ‘get rich quick’ scheme with the utmost caution. Blockchain.com will never offer these ‘opportunities.’ Any official cryptoasset airdrop we conduct will only occur directly in the Blockchain.com Wallet or Exchange to verified users in the Airdrop center'.





If one spots or suspect a scam, one can report the profile pages to the relevant platform (in this case Twitter) and inform the Blockchain.com team too. The company aims to help remove fraudulent scams and profiles. Blockchain.com's support team conducts all customer communication through our Support Center and will only respond on its verified social media accounts.





Keep yourself + others safe:





  • Never share your recovery phrase with anyone — especially over social media.
  • Avoid contact with any Facebook group, page, or profile claiming to represent Blockchain.com or our support team.
  • Report any suspicious activity to our Support Center, as well as the social media platforms themselves




Email Verification: Verifying your email address allows us to send login codes when suspicious or unusual activity is detected, to remind you of your wallet login ID, and to send bitcoin payment alerts when you receive funds.





Set up Two-Factor Authentication Enable two-factor authentication via SMS code, Yubikey, or Google Authenticator to further protect the wallet from unauthorized access.





Write Down Your Backup Phrase: It is the key to ensuring users' access to respective funds if one forgets his or her password .


Scam Calls: Paytm Payments Bank Submits List of 3,500 Phone Numbers to MHA, Others

Paytm Payments Bank (PPB) on Friday said it has submitted to the home ministry, Trai and CERT-In a list of 3,500 phone numbers used to make scam calls to dupe consumers in the country.

PPB claimed that it has also filed an FIR against these people with Cyber Cell for an immediate action to stop this scam.

"In a series of meetings with officials from the Trai, Ministry of Home Affairs (MHA) and CERT-In, PPB charted out and explained the various phishing and fraudulent mobile phone SMS and call scams affecting digital payments users.

"In its discussions with the authorities, the company has made it clear that these frauds erode the trust of millions of Indians," PPB said in a statement.

It added that banks like PPB can identify the phone numbers of these fraudsters and prevent future frauds and scams with proactive involvement of law enforcement, regulators and telecom operators.

"PPB has submitted a comprehensive list of 3,500 phone numbers to Telecom Regulatory Authority of India (Trai), MHA, and CERT-In, which have been actively involved in SMS and call scams. To further ensure the security of digital payments users, PPB has filed an FIR against these criminals with Cyber Cell for an immediate action to stop this scam," it said.

CERT-In a functional organisation under the Ministry of Electronics and Information Technology with the object of securing Indian cyber space.

PPB - in its conversations with the authorities - has emphasised the need for timely and effective legal action to end this menace with the involvement and support of telecom operators, the statement added.

"We are extremely happy to see the proactiveness shown by Trai and MHA in this regard... We are committed to ensuring that we block as many fraudsters and will continue to enhance our app security so that there's no stone left unturned towards safe digital payments experience," PPB MD and CEO Satish Gupta said.

PPB said these organisations have also been given a list of SMS shortcodes where the company's brand name has been falsely used in the sender identification details.

It said fraudsters send SMSes with shortcodes "PYTM" to gain trust of the user, and then defraud them.

A list of shortcodes that need to be blocked as well as the company's correct header 'iPaytm' has been submitted with Trai. The company said it has requested Trai to prohibit telcos from using/selling any shortcode similar to the word 'Paytm' such as 'PYTM'.

"Telecom operators should be directed to have stringent control on the issuance of shortcodes for bulk messages to companies. There is also a need to blacklist companies permitting such SMSes to be sent," Gupta said. PTI SR

$5.75 Mn Tax Scam Unearthed at Beverage Firm Co-owned by SAIF Partners

Vadodara, Gujarat-based Manpasand Beverages Ltd (MBL), known for MangoSip - a mango drink brand, and OXY Sip - a packaged drinking water, is suddenly in a centre of controversy as Central GST Commissionerate of Vadodara,Gujarat has unearthed a ₹ 40 crore (~ US$5.75 Mn ) goods and services tax (GST) scam in the company, which is backed by private equity firm SAIF Partners, which hold 25% stake in MBL.

According to Business Standard, citing CGST commissionerate sources, MBL allegedly created and showed sales and purchases across more than 30 fake units.

In a latest, MBL founder Dhirendra Singh, his brother Hashvardhan Singh, Managing Director Abhishek Singh and chief financial officer Paresh Thakkar were arrested after a raid on May 23 by the Central GST Commissionerate Vadodara for GST fraud amounting to ₹40 crore.

It was in 2011, when the private equity firm SAIF Partners reportedly picked up a 25 percent stake in MBL for Rs 45-50 crore, with an earnings multiple of 30.

The report further said that ever since Deloitte resigned as auditor for Manpasand Beverages has been in controversy, which is then eventually came out open when top management executives of MBL were arrested cementing the speculations.

Established in 1998, by current Chairman and Managing Director Dhirendra Singh, MBL boasted its presence in rural and tier-2 and 3 markets when its multinational competitors were ruling the metros and top cities.

MBL counts celebrities as its brands' endorsement adverts. While Bollywood actor Sunny Deol is brand endorser of 'MangoSip', actress Tapsi Pannu endorses its 'MangoSip' brand. MBL's ready-to-drink oral rehydration salts (ORS) sports drink is endorsed by boxing champ Mary Kom.



By 2018, the company was congratulating itself on reaching out to these markets with a distribution strength of 600,000 outlets.

"MBL was also on its way to setting up its fourth plant in the country. Its manufacturing plants in Vadodara, Varanasi and Sri City are either operational or under construction," said the report.

Usually the cases one comes across show companies running real units, but acquiring fake invoices here and there to claim input tax credit (ITC). But in case of MBL, it has been found that the company set up several fake units and across the country at that. Real purchase and sale transactions were then shown with values inflating with each transaction in order to claim a cumulatively large sum of input tax credit," a source said.

The company allegedly showed inter-unit transactions worth over Rs 300 crore wherein ITC would come up to Rs 40 crore. Government sources said that these transactions were found to have taken place in 2018-19.

In this case, MBL allegedly showed inter-unit transactions worth Rs 300 crore, which led to an accumulation of input tax credit (ITC) of Rs 40 crore. According to CGST commissionerate sources, the transactions took place on several occasions in 2018-19, beginning three-four months ago.

Independent chartered accountants and corporate law experts who have followed the case said the circular trading involved one of the real units showing a sales transaction to a fake unit, which is then followed by a string of similar transactions, adding a slight margin at each stage and eventually landing up as a purchase transaction by a real unit of MBL.

“The real unit which shows purchase in the end can now claim tax credit on the inflated value at each stage. Mostly, it is even difficult for auditors to find out such a long trail of 30 fake units because there are no RoC (Registrar of Companies) records. Also, there is no law in the country that prohibits such kinds of circular trading. Only CGST intelligence can smell it when they follow the trail on their system and find that these are similar or even same transactions shown again and again,” said an independent corporate law expert.

For SAIF, which is investor in companies like Book My Show, MakeMyTrip, Paytm and FirstCry among others, MBL is not its first portfolio firm that came into controversy as earlier an another SAIF Partners-backed Infrastructure Leasing & Financial Services (IL&FS) came in to controversy for alleged fraud and causing wrongful loss to the troubled infrastructure lender.

Last month, a former vice chairman of IL&FS, Hari Sankaran, was arrested by Serious Fraud Investigation Office (SFIO). He is accused of granting loans to entities that were not credit-worthy or declared as non-performing accounts causing loss to the company and its creditors.

Coincidentally, IL&FS also had Deloitte as its auditor at that time and according to SFIO the initial probe revealed the existence of major lapses in Deloitte’s audit of IL&FS subsidiary.

6 Things you must know before downloading WhatsApp Gold



Market Reports

Market Report & Surveys
IndianWeb2.com © all rights reserved