126 Fake Holy Sites, 21,985 Victims: Gujarat Police Bust India’s Biggest Pilgrimage Booking Scam

Somnath • Dwarka • Tirupati • Shirdi • Rishikesh • Haridwar • Katra • Ujjain • Puri & more — Gujarat Police Crush Nationwide Pilgrimage Booking Scam
Gandhinagar, 13 August 2026, In a significant crackdown on cyber-enabled travel fraud, the Cyber Centre of Excellence, CID Crime, Gujarat Police, has arrested two key accused who allegedly created and operated more than 126 fraudulent websites impersonating dharmashalas, ashrams, trusts and hotels near major Indian pilgrimage and tourist destinations. The sites collected advance room-booking payments from citizens while posing as authorised representatives of the real establishments.
The operation, conducted under the overall directions of Police Mahānirīkṣak (DIG) Bipin Ahir of the Cyber Centre of Excellence and the supervision of Superintendent of Police Dr. Rajdeepsingh Jhala, SP Sanjay Keshwala and SP Vivek Bheda, resulted in the arrest of one accused from Delhi and one from Rajasthan. The investigating team, comprising Police Inspector B.P. Patel, PI A.B. Chaudhary, PI S.M. Soni and Additional Police Inspector V.M. Jotaniya, used a combination of human intelligence and technical analysis to dismantle the network.
Scale of the Fraud
According to the official press note (G.R. No. related to 11201018260051/2026), the fake websites targeted locations across 11 states and union territories:
- Gujarat – 41 sites (Somnath, Dwarka, Girnar, Palitana, Bhuj, Junagadh, Patan, Gandhinagar and others)
- Uttarakhand – 27 (Rishikesh, Haridwar)
- Andhra Pradesh – 18 (Tirumala, Tirupati, Visakhapatnam)
- Maharashtra – 8 (including Shirdi, Juhu, Powai, Shegaon)
- Madhya Pradesh – 7 (Ujjain)
- Odisha – 6 (Jagannath Puri)
- Tamil Nadu – 6 (including Srirangam)
- Jammu & Kashmir – 5 (Katra)
- Karnataka – 5
- Uttar Pradesh – 2 (Vrindavan)
- West Bengal – 1 (Kolkata)
Investigators estimate that approximately 21,985 citizens were defrauded through these sites. At least 70 complaints had already been registered on the National Cyber Crime Reporting Portal (NCRP). The accused maintained control of six admin/C-Panel interfaces.
The Accused
- Vikki Kumar Gupta (also referred to in records as Savkikumar/Vikki Kumar Gupta), 34, son of Rambuber Gupta, resident of RZ-70/234, Nangal Raya / Dayal Park, West Sagarpur, Delhi-110046. A BTech (Computer Science) graduate working in digital marketing and web development. He designed the websites, sourced photographs from Google and Google Maps of genuine properties, handled hosting, retained technical access (including C-Panels), received booking form data directly into his Gmail account, and forwarded customer details via WhatsApp. Preliminary findings indicate he received payment for development, SEO, mobile-number updates and Google Advertisement services, plus an alleged 35% share of proceeds from the fraudulent bookings.
- Shailesh Saini, 24, son of Subjendra Saini, resident of Nanglabandh, Dehali, Tehsil Bhusavar, District Bharatpur, Rajasthan. A student preparing for competitive examinations. He received the booking requests, telephoned victims while posing as a hotel or ashram reception manager, and collected advance payments in the name of room bookings.
Police recovered three mobile phones, one laptop and ₹29,000 in cash.
How the Scam Worked, and Why It Succeeded
The accused registered multiple domain names using the titles of real dharmashalas, ashrams, trusts and hotels, employing a variety of top-level domains (.com, .co.in, .co, .org, .in and others). Because domain registration systems generally do not require proof of authorisation or trademark ownership for ordinary commercial or place-name domains, lookalike sites could be created rapidly and at low cost. Photographs and visual elements lifted from legitimate sources made the pages appear authentic.

These sites were then pushed to potential victims through Google Search results and Google Advertisements. Booking forms on the fake pages captured names, mobile numbers and preferred dates; the data flowed straight to the developer’s inbox. The information was shared via WhatsApp to the second accused, who made the follow-up calls. Technical control of the C-Panels allowed the operators to change displayed phone numbers and content as needed.
This case underscores two structural vulnerabilities that cyber-criminals continue to exploit worldwide:
- Domain registration systems still permit the easy creation of confusingly similar domains for well-known institutions, religious trusts and tourist facilities without meaningful verification of legitimate association.
- Search and advertising platforms can surface or promote such sites to users searching for genuine pilgrimage or hotel bookings. When SEO techniques and paid advertisements are applied, fraudulent pages can appear alongside or ahead of authentic ones, eroding the trust users place in search results.
Police Action Commended
The Gujarat Cyber Centre of Excellence’s coordinated effort, spanning technical forensics, analysis of Google Sheets listing the 126 websites, recovery of WhatsApp chats and booking requests, and inter-state arrests, demonstrates effective cyber policing. Officers recognised for their work include:
Police Inspector R.R. Solanki, PI B.P. Patel, PI A.B. Chaudhary, PI P.M. Judal, PI S.M. Soni, Additional PI V.M. Jotaniya, Additional PSI Nikhil Prajapati, ASI Satishbhai Jogi, Head Constables Brijrajsinh Jhala, Manharsinh Jhala and Maulikbhai Patel.
Citizens who believe they may have been affected are urged to contact the national cyber-crime helpline 1930 or their nearest police station immediately. The case also serves as a reminder to travellers: always verify official websites and contact details of religious trusts, ashrams and hotels through independent, trusted channels before making any online advance payment.
The arrests mark a concrete step against the industrial-scale misuse of domain names and search visibility, while highlighting the continuing need for stronger safeguards in both domain policy and online advertising verification.