The Hyderabad City Police has requested the Reserve Bank of India (RBI) put in place a real-time intervention protocol for transactions displaying the signature pattern of a digital arrest in progress as part of measures to curb the cyber crime.
It could also institute an independent third-party cyber-safety performance assessment for scheduled commercial banks to tackle cyber financial fraud. These were among the key recommendations submitted by Hyderabad Police Commissioner V C Sajjanar, based on the findings of Operation Octopus, a two-phase pan-India investigation into cyber fraud conducted by the city police.
The operation, carried out in February and April this year, resulted in the arrest of 169 accused persons, including 32 serving bank officials across 10 banks, for their alleged role in opening and operating mule bank accounts used to facilitate cyber fraud.
“An analysis of our extensive investigation across different States has led us to certain key observations for curbing cyber fraud from the banks’ side, as they can prevent such crimes at the source,” Sajjanar told businessline.
“While the focus on financial inclusion is welcome, there should be a greater emphasis on creating financial literacy among bank customers. The police alone cannot be left to deal with such crimes. Banks and bank staff should act as the first line of defence,” the Commissioner said.
According to Sajjanar, the vulnerabilities identified during the investigation went beyond individual misconduct and pointed to systemic issues.
The letters of recommendation sent to the RBI on April 25, 2026, highlighted the limitations of the existing incentive framework and performance culture at bank branches. “The prominent key result areas (KRAs) for branch staff continue to be weighted heavily towards new account volumes and financial product sales, diverting attention from proper know your customer (KYC) verification and, at times, leading to the creation of mule accounts,” he said.
Key measures
The letter recommended reforms to incentive models and sales processes to accord equal weight to quality and safety metrics, including KYC accuracy rates and mule account incidence. It also called for counselling checkpoints for fixed deposit closures and high-value transfers.
“Premature fixed deposit closures and unusually large outward transfers have consistently been observed as the final stage of cyber fraud victim exploitation, especially in so-called ‘digital arrest’ scenarios. We have requested the RBI to examine existing system flags and how they can be optimised to serve as meaningful last-mile preventive measures,” Sajjanar said.
It has been recommended to set standards for prescribed turnaround time (TAT) for bank responses to Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS) complaints would bring in much needed predictability to the fraud response eco-system.
Banks should be directed to develop and operationalise a real-time intervention protocol for transactions displaying the signature pattern of a digital arrest in progress. There should be a prescribed escalation protocol that includes immediate contact with the cyber crime police, the Commissioner said.
“All these recommendations have been made in full recognition that RBI is far better placed and equipped than any law enforcement agency to determine appropriate regulatory response,’’ Sajjanar said.
The total NCRP complaints reported in Hyderabad city in 2025-26 were at 26,455 compared to 21,000 in 2024-25.
Published on April 29, 2026
























