Almost every Indian cyber fraud ends the same way. Whatever the story that separates the victim from the money — the courier parcel with contraband in it, the trading group on Telegram, the officer on a video call demanding cooperation — the rupees leave the victim's account and arrive somewhere. That somewhere is a mule account: an ordinary savings account, opened in a real person's name with real documents, existing for no purpose except to be a station on the way to somewhere else. The stories get the headlines. The account is the infrastructure.

On 2 September the Indore Crime Branch, working under a standing effort it calls Operation Matrix, reported arresting a city resident whose account it says had carried about ₹1.50 crore in transactions, and which turned up in complaints from fifteen states — Delhi, Karnataka, Madhya Pradesh, West Bengal, Uttarakhand, Assam, Bihar, Gujarat, Haryana, Kerala, Maharashtra, Punjab, Rajasthan, Uttar Pradesh and Telangana. Police said they were still tracing where the money came from and where it went, and had not yet established how far the account holder understood what the account was doing. That last qualification matters and is easy to skip past: the economics of mule recruitment depend on people who are underpaid rather than criminal, students and daily-wage earners offered a few thousand rupees for the use of a passbook, and the person police arrest is frequently the least informed participant in the chain.

The reason a single account can appear in fifteen states at once is structural. India's payments system was built for speed and reach, and it achieved both: money moves between banks in seconds, at almost no cost, on a phone. Policing did not get the same upgrade. A complaint is filed with a local station in the victim's district, against a beneficiary account in another, held at a bank headquartered in a third, and the connection between fifty such complaints is visible only to whoever thinks to look for it. Operation Matrix is an attempt to look for it — to work from the account outward instead of from each complaint inward.

Professor Triveni Singh, a cybercrime specialist and former IPS officer, put the case for that approach plainly in comments reported alongside the arrest: identifying mule accounts, he said, helps investigators understand the larger movement of fraudulent funds. It is the difference between closing a case and mapping a system. The Reserve Bank has pressed banks for years on account-opening diligence and on monitoring for the signature of a mule account — dormant, then suddenly busy, then dormant again — and the persistence of cases like this one is the measure of how much of that remains undone at the branch counter.

Also this week · 1–2 September

A chief minister who does not speak Hindi

Tamil Nadu's CB-CID said on 2 September that it had registered a case and opened an investigation after a fabricated video began circulating in which a figure resembling the state's chief minister, Vijay, offered financial help to anyone who needed it and directed viewers to a WhatsApp number. The agency issued a public advisory telling people not to call the numbers in the recordings and not to share personal or banking details with whoever answered. One detail in the reporting is worth more than the rest: the fabricated figure was speaking Hindi. A synthetic voice can be made fluent in any language far more easily than it can be made appropriate, and a Tamil Nadu chief minister addressing the state's public in Hindi is a tell that requires no forensic tooling to notice — only the knowledge of who is supposed to be speaking, and how. We could corroborate this account in only one outlet, and we flag that here rather than in a footnote.

Also this week · Reported 2 September

₹2.96 crore, and a man of eighty-two

An 82-year-old non-resident Indian was reported to have lost about ₹2.96 crore to callers impersonating police officers — the fraud that has come to be called a "digital arrest", in which the victim is told they are the subject of a criminal case, kept on a video call for hours or days, forbidden to consult anyone, and instructed to move their savings to an account for "verification". This magazine has an explainer on the anatomy of the technique, and the pattern in this case is the familiar one: the sums are largest where the victim is old, wealthy, isolated and abroad, because the script's central instruction — tell nobody, the investigation is confidential — costs an elderly person living alone almost nothing to obey. The Prime Minister devoted part of a Mann Ki Baat broadcast to the scam at the end of October 2024, telling listeners plainly that no investigative agency conducts arrests or interrogations over video call; the archive's November 2024 edition records it. Nearly two years on, the losses per case are going up, not down.

AI Tech desk · September 2026

The repository that runs before you trust it

The month's significant AI security finding lands squarely on a country that writes a great deal of the world's software. On 2 September the research firm Manifold Security disclosed eight flaws across seven command-line AI coding agents, including Claude Code, Codex, Cursor, goose, Qwen Code, Grok Build and Hermes Agent, in a class it calls GitSpawn: a repository can nominate a command through Git's core.fsmonitor setting, and the agent runs it at startup with the user's privileges — before the prompt that asks whether the workspace is trusted. Fixes shipped for goose, Claude Code and Cursor; Manifold listed three agents as still unpatched on 1 September. No exploitation has been seen in the wild, and the attack needs a repository delivered as files with its .git directory intact rather than a normal clone. For Indian development shops running agents across client code, the practical control is unglamorous and available today: clone repositories rather than unpack them.

Digital Guard desk · September 2026

The appliance at the edge, again

The turn of the month was hard on the products enterprises buy to keep attackers out. SonicWall warned that two previously unknown flaws in its SMA 1000 remote-access appliances were being actively exploited and could be chained together, one for pre-authentication access and one for code execution. Researchers counted close to 22,000 Microsoft Exchange servers still reachable and still vulnerable to an authentication bypass that exposes every mailbox on them, long after a fix existed. Phishing campaigns were observed abusing Faronics Deploy, a legitimate endpoint-management tool, to install remote-control software. For Indian enterprises the shape of this is familiar from the archive: the internet-facing appliance and the unpatched mail server have been the country's two most reliable points of entry for a decade, and CERT-In's six-hour reporting rule — which this magazine covers in detail — assumes an organisation knows quickly that one of them has failed.

🔍 How this issue was reported

Aegis Sentry does not have reporters in the field. This issue was assembled on 2 September 2026 from published trade and specialist reporting — the Indore and Tamil Nadu items from The420.in, the international items principally from The Hacker News and BleepingComputer — together with the disclosing parties' own material, including Manifold Security on GitSpawn and SonicWall's advisory. The Tamil Nadu deepfake case rests on a single outlet, which we have said in the text rather than left for the reader to discover. Figures attributed to police are police figures. An arrest is not a conviction, and we have not named the person arrested in Indore, because the investigating officers themselves say they have not yet established his role. Where later reporting corrects any of this, we will correct it here.