The Telangana Cyber Security Bureau registered a case against Onextel Limited, Nimbus Adcom Pvt Ltd, and TVL Media Pvt Ltd. These firms allegedly misused registered SMS headers and templates of financial companies to send fraudulent messages. The complaint showed these entities exploited systems to impersonate legitimate businesses and trick many consumers.
The Telangana Cyber Security Bureau has registered a case against three telemarketing companies following allegations of unauthorised transmission of fraudulent commercial SMSes using registered headers and templates belonging to financial services companies.
The case names Onextel Limited, Nimbus Adcom Pvt Ltd and TVL Media Pvt Ltd, following a complaint by ValueFirst Digital Media Pvt Ltd. The complaint concerns alleged misuse of registered SMS headers and templates belonging to KFin Technologies Limited and Nariman Finvest Pvt Ltd, both government-registered entities.
According to the complaint, the two companies independently suffered unauthorised transmission of fraudulent commercial SMSes through misuse of their registered headers and templates. ValueFirst said its internal checks and investigation found an overlapping set of unauthorised or unregistered telemarketing entities common to both incidents.
The complaint identifies Nimbus Adcom Pvt Ltd as a reseller telemarketer upstream of Onextel Limited, with Onextel identified as the final delivery telemarketer.
It alleges that Onextel Limited, Nimbus Adcom Pvt Ltd and TVL Media Pvt Ltd exploited the DLT PE-TM scrubbing/hash mechanism to impersonate registered headers and templates of unrelated Principal Entities and push fraudulent content containing malicious shortened links to consumers, while appearing, on the face of the DLT hash, to be a legitimately registered chain.
The complaint identifies Onextel as common to both matters. In the Nariman incident, Onextel was identified in ValueFirst's records and, according to the complaint, confirmed by Vodafone Idea as the final delivery telemarketer.
In the KFin incident, TVL Media was identified as the delivery telemarketer. The complaint states that TVL Media is a group entity of Onextel and that the two companies have the same registered address in Noida. Nimbus Adcom is described in the complaint as a reseller telemarketer upstream of Onextel in the Nariman chain.
KFin Technologies, according to the complaint, is registered on DLT and transmits SMSes to investors under the registered headers "KFINTH" and "KFINMF" through five authorised telemarketers and aggregators.
On July 9, the "KFINTH" header was blacklisted without notice. KFin subsequently discovered what the complaint describes as a fraudulent SMS bearing its header and containing a malicious shortened link that had been sent on the same day.
ValueFirst's platform logs showed "No Logs Found", according to the complaint, which stated that the message had not been sent through ValueFirst's chain. Delivery and scrubbing records instead identified TVL Media Pvt Ltd as the delivery telemarketer. The complaint states that TVL Media was outside KFin's five authorised telemarketers and aggregators and was connected with or routing traffic through Onextel Limited.
A second allegedly fraudulent message using the same misused template was delivered on July 30, according to the complaint. The complaint states that these incidents caused KFin's headers to be repeatedly blacklisted at the telecom and DLT scrubbing level during July and August, disrupting genuine OTP and transactional alerts to investors.
The complaint also details a separate incident involving Nariman Finvest, a registered stockbroking entity that has used ValueFirst's SMS services since January 2018 under its registered "NARIMN" header. ValueFirst was its only authorised telemarketer and aggregator, according to the complaint.
On August 3, an allegedly fraudulent SMS using the "NARIMN" header and containing a malicious shortened link was delivered. ValueFirst's records identified Onextel Limited as the telemarketer associated with the message, according to the complaint. Onextel was outside Nariman's authorised chain.
The complaint states that while ValueFirst confirmed that no such message had originated from its platform, the accompanying hash reflected ValueFirst's own chain.
According to the complaint, Vodafone Idea disclosed the delivery chain following repeated escalation. The complaint identifies Nimbus Adcom Pvt Ltd as a reseller telemarketer upstream of Onextel Limited, with Onextel identified as the final delivery telemarketer. It states that Nimbus Adcom blocked the relevant user account/header but withheld Onextel's identity despite repeated requests.
Based on the complaint, the Telangana Cyber Security Bureau registered a case under Sections 318(4) and 319(2) of the Bharatiya Nyaya Sanhita and Sections 43, 66, 66C and 66D of the Information Technology Act and further investigation is on.
