Label: Confirmed case. Five arrests have been reported across the network and the investigation is continuing. The accused have not been tried and guilt is not established; this article reports the police account.
Gurugram cyber crime police have arrested three men for allegedly running a fake investment and insurance scam through a call centre, duping a resident of nearly Rs 26 lakh by luring him into bogus insurance policies and government bond schemes. The three are Udit Chopra, 31, Jitesh Kumar Srivastava, 34, and Himanshu Premi alias Sardar, 32, all originally from Delhi and residing in Ghaziabad. The trio posed as representatives of One Server Capital Advice LLP. The case was registered at the Manesar cyber crime police station on January 21 after the victim complained, and the three were arrested in Ghaziabad on May 25. Thirteen mobile phones, seven SIM cards and Rs 50,000 in cash were recovered.
The part that matters is the sourcing of the targets
Investigators found that two of the three, Himanshu and Jitesh, had worked at an insurance company in Ghaziabad and allegedly used company data to identify and contact potential targets. The two later set up the call centre, from which callers misled victims into investing in the fake schemes, and Udit was hired to make the fraudulent calls. This is the detail that separates this case from the ordinary investment fraud: the targeting was not random dialling, it was a customer list, and the list came from inside the industry. The remaining arrests trace the money rather than the targeting: two men said to have withdrawn cash from ATMs were arrested on May 6, and two others said to have arranged SIM cards and withdrawn cash were arrested from Uttar Pradesh on May 8.
Why insider-sourced data defeats caller verification
Almost every piece of advice on avoiding insurance impersonation fraud assumes the attacker knows nothing about you. Call the number on the company's website. Never share an OTP. Ask for your policy number. This case shows the assumption failing. If the caller has a real policy number, a real premium figure, a real renewal date and a real agent name, then every check a careful person would think to make passes, and the only defence left is a check the caller controls, which is the phone number. That is why the verification rule that matters is not about what the caller tells you. It is about who you call back, on a number you looked up yourself.
What you should take from it
- Assume a caller may know your real details. Treat accurate policy information as a warning sign, not a reassurance. Fraudsters do not need to be plausible; they need to be credible for thirty seconds, and a correct policy number supplies that on its own.
- Never call back a number the caller gives you. This is the one check that survives insider-sourced data, because it is the only step where you supply the number rather than receive it. Close the call, open the insurer's app or type the company's web address yourself, and use the contact details there.
- Bundling insurance with an investment or a bond is the shape of the trap. A legitimate insurer does not bundle a policy with a government bond scheme or with an advisory firm's investment product. The combination itself is the tell, and no amount of documentation makes it normal.
- Insurers hold the responsibility their data access implies. Two former employees had access to company data and used it commercially. Neither has been charged with a data protection offence on these facts, and I am not suggesting one is available. But the direction of travel is fixed: the industry is moving toward far more open APIs, more third-party distribution and more digitised servicing, and every one of those widens the population of people who can lawfully reach your customer record. Insider risk is becoming a structural exposure, not a rare event.
What to watch
Expect this framing to appear in the regulatory conversation rather than only in police files. The rule requiring every proposal and policy to carry the identity of the authorised salesperson from January 2027 addresses accountability for the person who sold you something, and it does not address the person who took your details and sold them to someone else. A call-centre operations standard, and rules on what an insurer employee may take out of the building, is the missing piece in the current framework. For a reader, the watch item is concrete: whether insurers start telling policyholders, at the point of data capture, that their details will not be used to market third-party financial products. If that notice does not exist in your own insurer's communications, that is worth asking about.