
Dr Reddy’s Laboratories loses ₹2.16 Cr. after Cybercriminals hack email exchange
A case of large-scale cyber fraud has been registered by the Bengaluru City Cyber Crime Police after hackers allegedly infiltrated the official email exchange between Hyderabad-based Dr Reddy’s Laboratories and Group Pharmaceuticals of Bengaluru, resulting in the diversion of a payment worth ₹2.16 crore to a fraudulent bank account.
According to the First Information Report (FIR), the complaint was lodged by Mahesh Babu K, a senior executive of Group Pharmaceuticals. The company had supplied goods to Dr Reddy’s Laboratories and was awaiting payment for the same amount. During this period, the email communication between the two companies was reportedly compromised by unidentified cyber fraudsters.
Investigations revealed that on November 3, hackers allegedly gained unauthorised access to the official email thread between Group Pharmaceuticals and Dr Reddy’s Laboratories. Through this access, they are believed to have impersonated Group Pharmaceuticals officials and sent fraudulent emails to Dr Reddy’s finance and accounts department, instructing that the payment be made to a new bank account. Believing the communication to be genuine, the finance team of Dr Reddy’s Laboratories transferred ₹2.16 crore on November 4 to the fraudulent account.
The fraud came to light when Group Pharmaceuticals noticed that the expected payment had not been received in their legitimate account. The company immediately alerted the Bengaluru Cyber Crime Police and requested that the fraudulent account be frozen to prevent further dispersal of funds.
A formal complaint was registered on November 5, and a case was booked against unknown persons under relevant provisions of the Information Technology Act, 2000, and the Bharatiya Nyaya Sanhita (BNS), 2023.
According to the FIR, multiple legal provisions have been invoked in the case. Section 318(4) of the BNS addresses cheating by dishonestly inducing a person to deliver property or money, while Section 319(2) pertains to cheating by personation, targeting frauds committed through impersonation. In addition, provisions under the IT Act have been applied: Section 66 deals with unauthorised access or alteration of computer data; Section 66C addresses identity theft, involving misuse of another person’s electronic credentials; and Section 66D covers cheating by personation using computer resources, including digital impersonation through fake emails, websites, or other online platforms.
A senior police officer confirmed that during the preliminary investigation, the fraudulent bank account was traced to Vadodara in Gujarat, where the stolen funds had already been dispersed into multiple sub-accounts. The primary account into which the payment was initially made has since been frozen, and efforts are underway to trace and recover the diverted amount.
Police officials stated that coordination has been initiated with various banks and financial intelligence units to track fund movement and identify the beneficiaries. “The investigation is progressing in coordination with cyber forensic experts and banking authorities to trace the origin of the hack and the final recipients of the funds,” a senior officer said.
The case has highlighted the growing sophistication of cybercriminals and the need for stronger digital security measures in corporate communications. Police have urged companies to verify all bank account changes through official phone calls or physical confirmation rather than relying solely on email correspondence.
The investigation remains ongoing, with the cybercrime division pursuing technical leads to identify those responsible for the fraud and to recover the misappropriated funds.
