Bihar STF and Sheikhpura Police Crack Down on WhatsApp Hacking Fraudsters

WhatsApp Account takeover, followed by cheating is one of the most common modus operandi across India. Device Binding regulations will be a game-changer in preventing these type of cases from occuring.
In a swift and well-coordinated operation, the Bihar Special Task Force (STF) and Sheikhpura district police have dealt a firm blow to cyber crime by arresting two notorious fraudsters who specialised in hacking WhatsApp accounts to cheat people online.
Background
On August 4, 2026, a joint team conducted a targeted raid in the Sheikhopursarai police station area and arrested Mohammed Arman and Mohammed Salamat.
A case (Case No. 127/26) was registered at Sheikhopursarai police station the same day.
Modus Operandi
The accused used a classic but highly effective method of cyber fraud.
They first hacked into victims’ WhatsApp accounts.
Once in control, they messaged the real account holders’ contacts, posing as the genuine user.
They then sent fake apps and malicious links and persuaded people to transfer money online under various pretexts.
Several people fell victim to this deception before the police intervened.
Impact
Four mobile phones used in the crime were recovered from the accused during the raid.
Response
Police officials described the operation as an example of effective intelligence-based policing and seamless coordination between the STF and the district force.
The arrests form part of Bihar Police’s ongoing and intensified campaign against cyber criminals across the state.
Senior officers have reiterated their commitment to cracking down on such digital frauds.
Citizens have been advised to remain extremely cautious: never share OTPs or click on unknown links, and always verify any sudden request for money from known contacts through a direct phone call.
The successful action once again demonstrates Bihar Police’s resolve to protect citizens from online fraud and maintain pressure on cyber criminals operating in the state.
Technology fix for WhatsApp
A strong device-binding policy, requiring every WhatsApp account (or linked banking/UPI session) to be cryptographically bound to a single primary trusted device, with mandatory biometric or hardware-backed re-authentication before any new device can be linked and automatic revocation of all other sessions, would make remote OTP-based or session-hijacking attacks substantially harder for fraudsters who do not already control the victim’s phone.