India's ED finds links to Cambodia in ₹7 crore transnational law enforcement impersonation scam

India’s ED Jalandhar arrested Sohail Akhtar alias Raju in Kolkata under PMLA in the S.P. Oswal digital-arrest case, after ~₹7 crore was extorted by fraudsters posing as CBI/judicial officials. Funds allegedly moved via Rigllo Ventures and Frozenman Warehousing, mule accounts, AMMFORWARD, and crypto; ED custody until 6 Oct 2026.
India's ED finds links to Cambodia in ₹7 crore transnational law enforcement impersonation scam
India’s Enforcement Directorate (ED), Jalandhar Zonal Office, has arrested Sohail Akhtar alias Raju in Kolkata under the Prevention of Money Laundering Act (PMLA), 2002, in the digital-arrest extortion case involving industrialist S.P. Oswal.
A Special PMLA court in Jalandhar remanded him to ED custody for seven days, until 6 October 2026.
What happened
On 28 September 2026, ED searched three locations in West Bengal and arrested Akhtar in Kolkata.
After transit remand from the Chief Judicial Magistrate, Kolkata, he was produced before the Jalandhar court.
The PMLA probe rests on a Ludhiana Cyber Crime Police Station FIR under the Bharatiya Nagarik Suraksha Sanhita (BNSS), 2023, and nine additional FIRs linked to the same digital-arrest group.
Fraudsters posing as CBI and judicial officials allegedly extorted about ₹7 crore from S.P. Oswal through a “digital arrest” scam.
Shell Entities, Cryptocurrency and Android app based automation
ED says the proceeds first entered accounts of two entities: M/s Rigllo Ventures Private Limited and M/s Frozenman Warehousing and Logistics.
ED’s fund-flow chart shows:
- ₹4 crore from S.P. Oswal to Frozenman, of which ₹3.40 crore returned to Oswal and ₹0.60 crore went to M/s Zaman Scrap.
- ₹3 crore from S.P. Oswal to Rigllo, of which ₹1.47 crore was transferred to 48 other persons and ₹1.53 crore returned to Oswal.
Akhtar allegedly controlled and operated Rigllo’s bank accounts and recruited mule-account providers.
The syndicate used phones with pre-installed APKs so foreign collaborators, including links cited to Nepal, could intercept OTPs and SMS for instant transfers.
An Android app named AMMFORWARD was used to move funds quickly across accounts.
Commissions were allegedly paid in virtual digital assets via Binance.
Encrypted messaging apps were used to share mule-account details with foreign associates.
Larger sums were layered through shell entities and trade-based laundering; smaller ₹2–5 lakh transfers to mule accounts were cashed out and converted to crypto after commissions.
Prior enforcement - Cambodia Links
ED earlier arrested Ruby Kalita (23 December 2025) and Amit Rathore (31 December 2025), who allegedly controlled Frozenman accounts.
Rathore allegedly supplied mule accounts to contacts in Cambodia and Vietnam and took crypto commissions via Binance.
On 14 February 2026, ED issued a provisional attachment order for ₹1.76 crore.
On 19 February 2026, a prosecution complaint was filed against Ruby Kalita, Amit Rathore, Anand Chaudhary, Atanu Chaudhary, and M/s Frozenman Warehousing and Logistics.
Further investigation continues.
Why it matters
Digital-arrest scams combine law-enforcement impersonation with remote coercion, then launder proceeds through Indian mule companies, cash-out layers, and crypto rails tied to overseas handlers.
ED’s PMLA trail, from Rigllo/Frozenman accounts to AMMFORWARD, Binance commissions, and cross-border OTP interception, maps how a domestic extortion case becomes a multi-country money-laundering network.
Written by: Cyber Security Team, Ministry of Cyber Affairs
Source: Enforcement Directorate (@dir_ed), 2 October 2026