Monday , September 14 2026
$2 million

Researchers unveil over $2 million fake currency operation in India

Cybersecurity researchers from CloudSEK’s STRIKE team used facial recognition and GPS to uncover a large fake currency scheme worth over $2 million in India, revealing individuals and their activities on Facebook and Instagram.

A major counterfeit currency operation has been discovered, producing fake notes worth millions. Cybersecurity firm CloudSEK revealed this through its STRIKE team, estimating that ₹17.5 crore (over $2 million) in counterfeit Indian currency has circulated in six months (December 26, 2024, to June 26, 2025). They have also identified key individuals involved.

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

CloudSEK has used digital forensics, GPS data, and facial recognition to identify key individuals in Maharashtra, India.

    Source: cloudsek.com

According to Sourajeet Majumder, a security researcher at CloudSEK, “This is the first time that a cyber investigation has offered such precise attribution of counterfeit actors operating in public digital spaces. We didn’t just find content, we identified the key perpetrators.”

Reportedly, bad actors are using popular social media platforms like Facebook and Instagram in this campaign. CloudSEK’s XVigil platform played a crucial role in its detection by monitoring open-source environments for specific terms like “second series” or “A1 notes,” which are codewords used by sellers.

The investigation uncovered more than 4,500 posts promoting counterfeit currency and over 750 accounts selling fake notes. Additionally, over 410 unique phone numbers were linked to these sellers. They used Meta Ads for promotions, targeting potential buyers. Some even shared videos and handwritten notes to showcase the quality of their fake currency, establishing a risky “trust-based” black market.

   Source: cloudsek.com

CloudSEK researchers used advanced OSINT and HUMINT methods to identify group leaders and sellers, gathering facial images, phone numbers, GPS coordinates, and social media profiles of key suspects.

Researchers found accounts using names like Vivek Kumar, Karan Pawar, and Sachin Deeva. Geolocation data indicated activity in Jamade Village (Dhule district, Maharashtra) and Pune, suggesting a coordinated syndicate mainly based in Maharashtra, with Dhule as a likely hotspot.

Counterfeiters promote fake notes on social media, using hashtags like #fakecurrency. They interact with buyers on WhatsApp, providing “proof” images and live video calls for trust. Their production uses tools like Adobe Photoshop, professional printers, and paper that imitate security features such as Mahatma Gandhi watermarks and green threads.

CloudSEK shared its findings with law enforcement agencies at state and national levels, offering intelligence to disrupt a criminal network and protect financial stability.

Check Also

HOOKEDGE

New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used …