#FactCheck-No Evidence India Returned Iranian Oil After Trump-Modi Call
Executive Summary
A claim circulating on social media alleges that India refused to unload crude oil from two Iranian tankers following a call between US President Donald Trump and Prime Minister Narendra Modi, after the US announced fresh restrictions on Iranian oil exports. However, research by the CyberPeace Research Wing found the claim to be misleading. The probe revealed that two supertankers carrying Iranian crude are currently anchored off India’s western and eastern coasts. No credible evidence or reports suggest that India refused to unload the cargo or sent the vessels back.
Claim
A user on X claimed that India returned 2 million barrels of Iranian crude oil after a phone call from Donald Trump. According to the post, India had already paid for the oil and the tanker was en route, but following the call with Narendra Modi, authorities refused to unload the shipment and sent the tanker back to Iran.

Fact Check
No credible national or international media reports were found to support the claim that India refused to accept Iranian oil or returned the tankers. Given the global scrutiny on oil shipments amid tensions in West Asia, any such development would have drawn widespread coverage. According to Reuters, two large crude carriers loaded with Iranian oil reached Indian ports on April 13. The Iran-flagged Felicity arrived near Sikka port in Gujarat, while the Curacao-flagged Jaya reached Paradip port in Odisha. The report noted that this marked the first purchase of Iranian oil by Indian refiners since 2019.

Further, The Times of India reported that Felicity, owned by the National Iranian Tanker Company, anchored off Sikka on April 12 carrying around 2 million barrels of crude loaded from Kharg Island in mid-March. The second tanker, Jaya, also anchored near Paradip around the same time, having departed with a similar volume of crude in late February. While the buyers of these cargoes have not been officially disclosed, Paradip port is primarily used by Indian Oil Corporation, while Sikka port is used by Reliance Industries and Bharat Petroleum Corporation.

Conclusion
The viral claim is false and misleading. Available evidence shows that the Iranian oil tankers are stationed near Indian ports, and there is no confirmation that India refused to unload the cargo or sent the vessels back.
Related Blogs
.webp)
Introduction
The recent investigation of Patan Cyber Crime Police as part of Operation Mule Hunt 2.0 reveals the sheer scale and intricacy of India's burgeoning cyber fraud economy. Police found that a total of 13 current accounts were being operated at a cooperative bank in the Patan district of Gujarat and used for siphoning 398.43 crore of cyber fraud transaction data on 228 cybercrime cases across states. Further investigations against 14 current account holders and intermediaries show the indispensability of mule accounts in laundering criminal money. The recent incident cannot be taken as isolated; the story points at a formalised and industrialised fraud economy with a robust banking infrastructure, a growing payment gateway, and complex networks.
What Is a Mule Account and Why Should You Care?
The term "mule account" is benign but plays a critical role in modern cybercrime networks. The Reserve Bank of India defines a mule account as a bank account that serves as a vehicle to transfer money proceeds from unlawful transactions and can be operated by people coerced by the prospect of high earnings or by way of inducement.
This mechanism can be witnessed through the investigation of the Patan cybercrime incident, where an investor can be defrauded by a fake investment website, employment fraud, or a digital arrest scheme. After transactions from the victim account, funds would quickly flow into the mule account, which would be held by a legitimate KYC customer. These transactions would then be passed on, between 1 lakh and 5 lakh transactions within hours, to multiple accounts as alleged by the Indian Cyber Crime Coordination Centre (I4C) before they get difficult to trace by being passed through informal channels or converted to cryptocurrency.
In the Patan case, it is alleged that the middlemen enticed locals and offered commissions to open firms and current accounts at Harij Nagrik Sahakari Bank and subsequently gave up their ATM cards, checkbooks, SIMs, and net banking facilities to the operators of the account. It is estimated that such accounts channeled an amount of 398.43 crore to 228 Indian cybercrime cases.
The Scale of India's Mule Account Crisis
The scale of the mule account ecosystem is reflected in India's rapidly worsening cybercrime statistics. As of data from the National Cyber Crime Reporting Portal (NCCRP), a total of 22.68 lakh complaints were registered in 2024, a jump by 42% from 2023. This was not even half the rate of financial loss, which jumped by 206% in 2023 (22,845 crore) and stood at 22,495 crore in 2025 (complaints jumped to 28.15 lakh). The increase in fraudulent transactions therefore outweighs the stability in financial losses significantly.
Mule accounts are the backbone of this crime network. To curb this phenomenon, the Indian Cyber Crime Coordination Centre (I4C) launched a Suspect Registry along with Indian banks and financial institutions in September 2024. 24.67 lakh accounts of suspected mules were identified in this, preventing over 8,031 crore in fraudulent transactions. Despite these efforts, a recent statement from the ED found over 12,000 crore being routed via mule accounts, shell firms, and cryptocurrency.
This isn't isolated to certain banks. 2024 alone saw over 65,000 mule accounts detected in Karnataka. By analyzing the Citizen Financial Cyber Frauds Reporting and Management System, about 40,000 such accounts were detected in SBI branches, and thousands more were detected across the PNB, Canara Bank, Kotak Mahindra Bank, and Airtel Payments Bank. The Patan case also clearly highlights that cooperative banks' lack of compliance and lower levels of transaction-monitoring systems contribute to easily creating and using mule accounts.
Operation Mule Hunt: Gujarat's Coordinated Offensive
This bust in Patan is just one manifestation of a much wider coordinated effort by the state government. Operation Mule Hunt 1.0, which ran from November to December 2025 across the state of Gujarat, was a month-long campaign by Gujarat Police's Cyber Centre of Excellence (CCOE) that unearthed 2,289 crore of fraudulent transactions, led to the registration of 565 FIRs, arrest of 638 accused, and impounding of 913 mule accounts with connections to over 4,000 cases of cybercrime nationwide.
This was followed up with the second installment of the operation, which was kicked off in all districts of Gujarat in 2026. The two-week campaign, which began across the state on January 8 this year, resulted in the Surat City Police alone arresting 77 people and uncovering close to 23.85 crore in fraudulent transactions. In what looks like one of the single largest single-district bust-ups in the operation, the Patan incident itself, with a staggering 398.43 crore routed through only 13 accounts, is remarkable.
The extraordinary nature of the operation is seen in the intelligence capabilities that drove it. It wasn't that police accidentally stumbled upon the Patan network; they worked back on it. After using data from the union government’s inter-agency platform, SAMANVAYA, a coordination platform for data on cybercrimes and the NCCRP, they traced suspicious clusters of transactions in the Harij Nagrik Sahakari Bank accounts to build a chain of evidence connecting the accountholders to the middlemen and, from the middlemen, to the whole ring of fraud. Twenty accused have been chargesheeted under the Bharatiya Nyaya Sanhita (BNS), and fourteen have been arrested, while six are still absconding.
The Human Cost Nobody Talks About
Behind every crore of scam money lies a real person who actually lost the real money. Of the 75%+ fraud losses incurred in 2025, 75% are from investment scams alone. Victims of stock trading scams lost ₹4,636 crore, spread across 2.28 lakh complaints filed in 2024. "Digital arrest" scams, in which fraudsters posing as law enforcement officials psychologically blackmail the victims to transfer money, claimed ₹2,576 crore between 2022 and the first quarter of 2025.
For the victims it's never about the money: it's the retired teacher's lifetime savings from Chhattisgarh, the small trader's capital from Rajkot, the emergency money of the Bhopal family, or just savings from an ordinary person. And the mule accounts' networks are why most of it is never retrieved. Once the money is thrown into the layering chain, it's exponentially more difficult to trace it after every jump.
Then there's another category of victims that often gets overlooked, and they are the mule account holders themselves, many being semi-literate people from semi-urban or rural backgrounds approached with ₹10,000 in commission and with no awareness about the legalities of lending their bank details. With the BNS now they stand to get convicted for grave crimes, but the awareness of this trap is very low.
Recommendations and Suggestions
This isn't something India is facing passively. I4C, along with RBI, has developed Mule Account Hunter software. This software can be used by banks for the detection of suspect accounts through the use of behavioral analysis, device intel, and transaction pattern recognition. The Union Home Minister has directly asked all cooperative banks across the country to adopt this software at the earliest. Failure to do so, he warned, would make consumer safety from cyber fraud incomplete.
Apart from technology, three other areas need to go hand in hand: stringent KYC enforcement for cooperative and small finance banks; the prime locations of the mule recruitment network; greater awareness for the masses regarding the criminal liability one takes up when lending their accounts; and efficient inter-agency coordination so that the intelligence gathered on platforms like SAMANVAYA is converted into arrests before the accounts are dumped and the network reforms in another location.
Operation Mule Hunt 2.0 proves that this is feasible. 13 accounts in a small district of Gujarat. 398 crore. 228 victims. 14 arrested. The pipeline did exist, and it has been broken.
Yet, even as one network is broken, another is forming, somewhere right now. The accounts will appear legitimate. The holders of these accounts may not even realize what they have got into. That is the true danger of the mule accounts and work that cannot stop.
Conclusion
The Patan investigation has clearly shown that mule accounts have now moved from being a subsidiary tool of financial crime to becoming the infrastructure that underpins the economy of cyber-fraud in India. Every financial fraud, including investment fraud, digital arrest fraud, and phishing scams, is backed by a string of real bank accounts where the proceeds of crime are transferred and the trail is obscured. Though attempts such as the I4C Suspect Registry have made attempts to break down this network, it remains an overwhelming task. Robust KYC norms, real-time monitoring of transactions, and coordination between banks, police, and regulators are the key in preventing further industrialisation of cyber financial fraud in India.
References
- https://timesofindia.indiatimes.com/city/ahmedabad/operation-mule-hunt-2-0-gujarat-
- police-bust-rs-398-43-crore-cyber-fraud-14-held/articleshow/131594240.cms?utm_source=contentofinterest&utm_medium=text&utm_campaign=cppst
- https://the420.in/india-cybercrime-2024-42-percent-spike-sims-imei-mule-accounts/
- https://www.thehansindia.com/news/national/ed-explains-how-mule-accounts-and-crypto-networks-enabled-12000-crore-cyber-fraud-1047606
- https://www.zigram.tech/article/mule-accounts-tier-1-tier-2-cities-india/
- https://risk.lexisnexis.com/global/en/insights-resources/article/stopping-money-mules-in-india
- https://timesofindia.indiatimes.com/city/ahmedabad/operation-mule-hunt-2-0-gujarat-police-bust-rs-398-43-crore-cyber-fraud-14-held/articleshow/131594240.cms

Introduction
Over the past few months, cybercriminals have upped the ante with highly complex methods targeting innocent users. One such scam is a new one that exploits WhatsApp users in India and globally. A seemingly harmless picture message is the entry point to stealing money and data. Downloading seemingly harmless images via WhatsApp can unknowingly install malware on your smartphone. This malicious software can compromise your banking applications, steal passwords, and expose your personal identity. With such malware-laced instant messages now making headlines, it is advised for netizens to exercise extreme caution while handling media received on messaging platforms.
How Does the WhatsApp Photo Scam Work?
Cybercriminals began embedding malicious code in images being shared on WhatsApp. Here is how the attack typically works:
- The user receives a WhatsApp message from an unknown number with an image.
- The image may appear harmless—a greeting, meme, or holiday card—but it's packed with hidden malware.
- When the user taps to download the image, the malware gets installed on the phone in silent mode.
- Once installed, the malware is able to capture keystrokes, read messages, swipe banking applications, swipe credentials, and even hijack device functionality.
- Allegedly, in its advanced versions, it can exploit two-factor authentication (2FA) and make unauthorised transactions.
Who Is Being Targeted?
This scam targets both Android and iPhone users, with a focus on vulnerable groups like senior citizens, busy workers during peak seasons, and members of WhatsApp groups flooded with forwarded messages. Experts warn that a single careless click is enough to compromise an entire device.
What Can the Malware Do?
Upon installation, the malware grants hackers a terrifying level of access:
- Track user activity via keylogging or screen capture.
- Pilfer banking credentials and initiate fund transfers automatically.
- Obtain SMS or app-based 2FA codes, evading security layers.
- Clone identity information, such as Aadhaar details, digital wallets, and email access.
- Control device operations, including the camera and microphone.
This level of intrusion can result in not just financial loss but long-term digital impersonation or blackmail.
Safety Measures for WhatsApp Users
- Never Download Media from Suspicious Numbers
Do not download any files or pictures, even if the content appears to be familiar, unless you have faith in the source. Spread this advice among family members, particularly the older generation.
- Turn off Auto-Download in WhatsApp Settings
Navigate to Settings > Storage and Data > Media Auto-Download. Switch off auto-download for mobile data, Wi-Fi, and roaming.
- Install and Update Mobile Security Apps
Ensure your phone is equipped with a good antivirus or mobile security app that is updated from time to time.
- Block and Report Potential Scammers
WhatsApp offers the ability to block and report senders in a straightforward manner. This ensures that it notifies the platform and others as well.
- Educate Your Community
Share your knowledge on cyber hygiene with family, friends, and colleagues. Many people fall victim simply because they aren't aware of the risks, staying informed and spreading the word can make a big difference.
Advisories and Response
The Indian Cybercrime Coordination Centre (I4C) and other state cyber cells have released several alerts on increasing fraud via messaging platforms. Law enforcement agencies are appealing to the public not only to be vigilant but also to report any incident at once through the National Cybercrime Reporting Portal (cybercrime.gov.in).
Conclusion
The WhatsApp photo scam is a stark reminder that not all dangers come with a warning. A picture can now be a Trojan horse, propagating silently from device to device and draining personal money. Do not engage with unwanted media, refresh and update your privacy and security settings. Cyber criminals survive on neglect and ignorance, but through digital hygiene and vigilance, we can fight against these types of emerging threats.
References
- https://www.opswat.com/blog/how-emerging-image-based-malware-attacks-threaten-enterprise-defenses
- https://www.indiatvnews.com/technology/news/whatsapp-photo-scam-alert-downloading-random-images-could-cost-you-big-2025-05-06-988855
- https://www.hindustantimes.com/india-news/what-is-the-whatsapp-image-scam-and-how-can-you-stay-safe-from-it-101744353412848.html
- https://faq.whatsapp.com/898107234497196/?helpref=uf_share
- https://www.welivesecurity.com/en/malware/malware-hiding-in-pictures-more-likely-than-you-think/
- https://faq.whatsapp.com/573786218075805
- https://www.reversinglabs.com/blog/malware-in-images

Introduction
The Government of India has initiated a cybercrime crackdown that has resulted in the blocking of 781,000 SIM cards and 208,469 IMEI (International Mobile Equipment Identity) numbers that are associated with digital fraud as of February 2025. This data was released as a written response by the Union Minister of State for Home Affairs, Bandi Sanjay Kumar, with respect to a query presented in the Lok Sabha. A significant jump from the 669,000 SIM cards blocked in the past year, efforts aimed at combating digital fraud are in full swing, considering the increasing cases. The Indian Cyber Crime Coordination Centre (I4C) is proactively blocking other platform accounts found suspicious, such as WhatsApp Accounts (83,668) and Skype IDs (3,962) on its part, aiding in eliminating identified threat actors.
Increasing Digital Fraud And The Current Combative Measures
According to the data tabled by the Ministry of Finance in the Rajya Sabha, the first 10 months of the Financial year 2024-2025 have recorded around 2.4 million incidents covering an amount of Rs. 4,245 crore involving cases of digital Financial Fraud cases. Apart from the evident financial loss, such incidents also take an emotional toll as people are targeted regardless of their background and age, leaving everyone equally vulnerable. To address this growing problem, various government departments have dedicated measures to combat and reduce such incidents. Some of the notable initiatives/steps are as follows:
- The Citizen Financial Cyber Fraud Reporting and Management System- This includes reporting Cybercrimes through the nationwide toll-free (1930) number and registration on the National Cyber Crime Reporting Portal. On being a victim of digital fraud, one can call the toll-free number, describing details of the incident, which would further help in the investigation. After reporting the incident, the complainant receives a generated login ID/acknowledgement number that they can use for further reference.
- International Incoming Spoofed Calls Prevention System- This is a mechanism developed to counter fraudulent calls that appear to originate from within India but are actually made from international locations. This system prevents the misuse of the Calling Line Identity (CLI), which is manipulated to deceive recipients in order to carry out financial crimes like digital arrests, among other things. Coordinating with the Department of Telecommunication (DoT), private telecommunication service providers (TSPs) are being encouraged to check with their ILD (International Long-Distance) network as a measure. Airtel has recently started categorising such numbers as International numbers on their part.
- Chakshu Facility at Sanchar Saathi platform- A citizen-centric initiative, created by the Department of Telecommunications, to empower mobile subscribers. It focuses on reporting unsolicited commercial communication (spam messages) and reporting suspected fraudulent communication. (https://sancharsaathi.gov.in/).
- Aadhaar-based verification of SIM cards- A directive issued by the Prime Minister's Office to the Department of Telecommunications mandates an Aadhaar-based biometric verification for the issuance of new SIM cards. This has been done so in an effort to prevent fraud and cybercrime through mobile connections obtained using fake documents. Legal action against non-compliant retailers in the form of FIRs is also being taken.
On the part of the public, awareness of the following steps could encourage them on how to deal with such situations:
- Awareness regarding types of crimes and the tell-tale signs of the modus operandi of a criminal: A general awareness and a cautionary approach to how such crimes take place could help better prepare and respond to such malicious scams. Some important signs on the part of the offender include pressuring the victim into immediate action, insistence on video calls, and the threat of arrest in case of non-compliance. It is also important to note that no official authority, in any legal capacity, allows for enabling a digital/online arrest.
- Knowing the support channels: Awareness regarding reporting mechanisms and cyber safety hygiene tips can help in building cyber resilience amongst netizens.
Conclusion
As cybercrooks continue to find new ways of duping people of their hard-earned money, both government and netizens must make efforts to combat such crimes and increase awareness on both ends (systematic and public). Increasing developments in AI, deepfakes, and other technology often render the public inept at assessing the veracity of the source, making them susceptible to such crime. A cautionary yet proactive approach is need of the hour.
References
- https://mobileidworld.com/india-blocks-781000-sim-cards-in-major-cybercrime-crackdown/
- https://www.storyboard18.com/how-it-works/over-83k-whatsapp-accounts-used-for-digital-arrest-blocked-home-ministry-60292.htm
- https://www.business-standard.com/finance/news/digital-financial-frauds-touch-rs-4-245-crore-in-the-apr-jan-period-of-fy25-125032001214_1.html
- https://www.business-standard.com/india-news/govt-blocked-781k-sims-3k-skype-ids-83k-whatsapp-accounts-till-feb-125032500965_1.html
- https://pib.gov.in/PressReleasePage.aspx?PRID=2042130
- https://mobileidworld.com/india-mandates-aadhaar-biometric-verification-for-new-sim-cards-to-combat-fraud/
- https://pib.gov.in/PressReleaseIframePage.aspx?PRID=2067113