Hyderabad City Cyber Crime arrested eleven people Tuesday for allegedly operating Telugu-language phishing domains that cloned the Employees’ Provident Fund Organisation unified member portal and one-time password screens, siphoning advance withdrawals from 340 salaried accounts after victims entered Aadhaar-linked OTPs on lookalike hosts routed through bulletproof DNS providers, police said.
What broke
According to a Cyberabad commissionerate briefing reviewed by InfoHandle, the ring registered domains differing from EPFO’s official host by a single homoglyph in the Telugu transliteration of “unified,” then bought search ads targeting “PF withdrawal status” queries in Telangana and Andhra Pradesh. Victims received SMS links claiming mandatory KYC refresh before Navratri bonus payouts; the pages mirrored EPFO’s blue-and-orange layout closely enough to pass casual inspection on mobile screens.
Investigators seized 126 smartphones, 19 laptops, and ledgers listing commission payouts to telecallers who posed as EPFO helpline staff. Reported losses exceed ₹4.1 crore, though police believe many victims have not filed complaints because employers already advanced salary against expected PF settlements.
What police confirmed
Cyber Crime officials said the gang captured OTPs in real time through websocket relays to operators in Secunderabad and Vijayawada call centers. After login, they initiated partial withdrawals to mule accounts opened with forged salary slips—a pattern EPFO’s risk team flagged in internal alerts last month but did not publicize to avoid copycat domains.
Telangana Police coordinated takedowns with CERT-In and national registrar compliance teams; at least four domains remained reachable from overseas DNS resolvers as of Tuesday evening. EPFO confirmed no breach of its core data center; the attack was credential phishing, not server intrusion.
Who has the file
EPFO’s vigilance wing opened a parallel administrative review of whether member SMS templates should drop clickable links entirely—a policy RBI advocated for banks after UPI phishing waves. Hyderabad police forwarded device fingerprints to the Indian Cyber Crime Coordination Centre for correlation with a March Karnataka PF scam using Kannada-language clones.
Employers named in victim statements were not accused of complicity; however, two IT services firms received warnings for broadcasting HR newsletters that linked to third-party “PF calculators” without verifying domains—an administrative misstep, not criminal liability.
Legal exposure
Prosecutors are expected to charge violations of the Information Technology Act, Aadhaar misuse statutes where applicable, and cheating provisions. Operators who merely hosted relay servers face accessory counts if logs show knowledge of EPFO branding. Victims who shared OTPs despite EPFO’s public warnings may struggle with reimbursement claims; ombudsman pathways for PF disputes remain slower than banking fraud redressal.
What EPFO and members should do
EPFO reiterated that legitimate OTP prompts appear only after members type the official URL directly or use the Umang app channel vetted by MeitY. Members should freeze withdrawals through employer HR if they suspect compromise—a process many salaried workers learn only after money moves.
Banks receiving mule inflows face RBI “money mule” reporting duties; at least three lenders froze accounts within 48 hours of police notices, recovering ₹62 lakh so far. Recovery rates typically drop after first-hop transfers into UPI wallets.
What is still unknown
Police have not identified ad network accounts that approved homoglyph domains; Meta and Google abuse teams received hash lists Monday. Total victim count may rise when IT firms return from remote-work weeks and employees check PF passbooks before Diwali travel.
Near-term checkpoints
CERT-In plans a Telugu-language advisory push through state broadband providers before month-end salary credits. Cyber Crime units will run employer webinars in HITEC City corridors—a corridor that supplies both victims and suspects when PF phishing masquerades as routine HR compliance.
For Hyderabad’s fraud economy, the case is another reminder that EPFO’s unified portal consolidated convenience and risk in one login screen. Until members treat PF OTPs like bank PINs—and until registrars block homoglyph ads faster than rings spin new domains—provident balances will keep funding call centers dressed as government helplines.








