Telangana Cyber Security Bureau Investigates Telemarketing Firms Over Fraudulent SMS Scam
The Telangana Cyber Security Bureau has launched a formal investigation into three telemarketing companies following widespread reports of unauthorized and fraudulent commercial SMS campaigns. The case, which has sent shockwaves through the financial technology sector, targets Onextel Limited, Nimbus Adcom Pvt Ltd, and TVL Media Pvt Ltd.
The investigation follows a detailed complaint filed by ValueFirst Digital Media Pvt Ltd, which alleged that its clients’ legitimate SMS headers and registered templates were systematically hijacked to disseminate malicious links to unsuspecting consumers.
Hijacking Trusted Identities
According to the complaint, the fraudulent operation involved a sophisticated abuse of the Distributed Ledger Technology (DLT) framework—a system originally designed to prevent spam and ensure the authenticity of business messages. The perpetrators allegedly exploited DLT “scrubbing” and hashing mechanisms to impersonate reputable entities. By doing so, they created the illusion of a legitimate transmission chain, allowing malicious messages to appear as if they were official communications from registered financial firms.
Two primary victims, KFin Technologies Limited and Nariman Finvest Pvt Ltd, bore the brunt of this deception. Both are government-registered entities that rely on secure messaging for transactional alerts and One-Time Passwords (OTPs).
In the case of KFin Technologies, the company’s registered headers, “KFINTH” and “KFINMF,” were repeatedly blacklisted by telecom service providers after fraudulent messages—containing malicious shortened links—were sent to investors. Investigations revealed that TVL Media Pvt Ltd, an entity linked to the same registered address as Onextel, had acted as the delivery telemarketer, despite being outside the list of authorized partners for KFin.
Systematic Manipulation of Delivery Chains
The complaint further highlights a pattern of deception involving Nariman Finvest. In early August, unauthorized messages bearing the “NARIMN” header were sent to consumers. While the internal records of ValueFirst indicated that the messages did not originate from their secure platform, the accompanying cryptographic hash suggested a legitimate chain.
Further scrutiny, supported by data from Vodafone Idea, exposed a complex web of operations. The evidence identified Nimbus Adcom Pvt Ltd as a reseller operating upstream of Onextel Limited, which functioned as the final delivery telemarketer. Despite repeated requests from the affected parties to identify the entities behind these transmissions, the involved firms allegedly withheld information, compounding concerns regarding their complicity in the scheme.
Legal Implications and Ongoing Probe
The repercussions of this scam have been severe. The constant blacklisting of headers effectively paralyzed essential financial communications, disrupting critical OTP and transactional alerts for thousands of investors throughout July and August.
The Telangana Cyber Security Bureau has registered the case under several stringent provisions, including Sections 318(4) and 319(2) of the Bharatiya Nyaya Sanhita. Furthermore, the authorities have invoked multiple sections of the Information Technology Act—specifically sections 43, 66, 66C, and 66D—which deal with unauthorized access, data theft, and identity fraud.
As the investigation continues, the case serves as a stark warning about the vulnerabilities within the DLT framework and the urgent need for heightened regulatory oversight of the telemarketing industry to protect digital consumers from evolving cyber-threats.
Disclaimer: This content is auto-generated for informational purposes only.
Source: Read Original News
