Ghost Resturant Scam on Swiggy: Indian Police unravel new online scam targeting Axis Bank Card Holders

The accused obtained FSSAI certificates for kitchens that never cooked a meal, self-placed orders from stolen cards, marked them delivered and pocketed Swiggy's settlements — a case that puts merchant-onboarding fraud squarely on the foodtech agenda
Swiggy's restaurant payout pipeline was turned into a personal ATM from leaked credit cards available on Telegram.
Police arrested a 21-year-old, Garvit, son of Sanjeev Kumar, from the Kaushambi area on September 18, 2026, for a fraud worth nearly ₹30 lakh.

The modus operandi involved three fake restaurants on Swiggy, real FSSAI certificates, card data bought off a Telegram channel and spoofed video calls to Axis Bank credit cardholders.
Four mobile phones, a tablet and a laptop have been seized.
Modus Operandi
- Register the ghost kitchen. Garvit, a Rohtak resident living in Vaishali, Sector-03, with a B.Com degree and a stint in Tech Mahindra's customer care behind him, set up "Shyam ki Rasoi" and obtained an FSSAI registration for it before listing it on Swiggy. When complaints came, he launched "Radha ki Rasoi". When Swiggy banned that one, he came back with "Khana Khazana". Each iteration cleared onboarding.

FSSAI Certificate - Buy the card data: The accused told interrogators he learned the scheme from YouTube, which led him to a Telegram channel called "FAST OTP BOT". That channel supplied credit cardholder details, for a price, paid in QR codes.
- Harvest the OTP. Using the JIOJOIN app, he video-called cardholders posing as an Axis Bank customer service officer, offering to reverse service charges and late-payment fees. Victims, believing a "service request" was being raised, read out the OTP for a Swiggy order payment, which was, in fact, an order on his own restaurant.
- Cash the settlement. Orders placed on his ghost restaurants were marked delivered with no food moving. Swiggy settled the payment into his account, minus platform charges. He withdrew the balance through ATMs and cheques. On September 17, 2026, he used card data from the Telegram channel to generate a ₹38,000 order on the card of one M. Srinivas.
The case came to light on a complaint by Vishwajit Chaudhary, a manager with the operations team at Vasundhara Infraplaza, Ghaziabad; the cybercrime team traced Garvit through technical evidence and digital footprints.
Merchant Onboarding for Food Delivery Apps
For the platform economy, this is not a one-off scam story, it is a merchant-vetting story.
The alleged fraud worked only because every layer of it looked legitimate: an FSSAI-certified restaurant, real orders, real deliveries, real payouts.
The money was not stolen from Swiggy; it was routed through Swiggy, using the platform's own settlement mechanics as the laundering rail.
That puts three things under the spotlight: how thoroughly merchant onboarding verifies that a registered kitchen actually exists; how delivery verification works when the "restaurant" and the "order" are controlled by the same fraudster; and how payout anomalies, such as a small outlet with consistent high-value order flow and minimal genuine footfall, get flagged.
Seized from the accused were FAST OTP BOT Telegram chats, a Google Sheet of credit card details, FSSAI documents of the fake restaurants and the mobile numbers used.
Police say the material is being forensically examined, and that the QR codes and Telegram user IDs behind the data channel are being traced to identify others involved, meaning the channel that supplied the card data, and whoever ran it, may be next.
All details are drawn from the police press note dated September 19, 2026; the allegations rest on the investigation and the accused's interrogation disclosures, and the case is sub judice.