/

Jamtara-Style Fraud Network Signals a New Cross-Border Digital Crime Era in Sri Lanka

A Sri Lanka raid on a suspected cyber fraud hub exposes how Indian and regional operators are fueling a mobile, industrial-scale scam economy stretching across South Asia

3 mins read
With Sri Lanka increasingly in the crosshairs of these international cybercrime networks, the island nation faces mounting economic and security risks.

A major police operation in southern Sri Lanka has exposed what authorities believe is a sophisticated cross-border cybercrime network involving Indian nationals, highlighting the rapid evolution of digital fraud across South Asia. The raid in the coastal town of Dodanduwa led to the arrest of 55 foreign nationals, including 35 Indians and 20 Nepalese citizens, according to Sri Lankan law enforcement officials in Galle. Investigators say the group was operating from a rented accommodation that had been converted into a coordinated digital fraud center.

The discovery of 22 computers and 152 mobile phones inside the premises immediately signaled that the operation was far from ordinary. Instead of isolated scams, authorities believe they had uncovered a structured, industrial-scale cyber fraud setup designed for mass communication and financial deception. The equipment suggests a system capable of running simultaneous outreach campaigns targeting victims across multiple countries through messaging apps, social media platforms and phone-based scams.

Sri Lankan investigators have not yet officially confirmed the exact nature of the alleged crimes, but early assessments indicate the operation may have involved phishing schemes, fake investment platforms, impersonation scams and mobile-based social engineering fraud. These methods have become increasingly common across South Asia, where rising digital banking usage has created both convenience and new vulnerabilities for users.

The arrests come amid a dramatic surge in cybercrime across the region, particularly in India, where digital fraud has reached unprecedented levels. According to official data from the Ministry of Home Affairs, cybercrime complaints in India have increased from around 2.6 lakh cases in 2021 to more than 24 lakh cases in 2025. This nearly tenfold rise reflects the scale at which online financial fraud has expanded in just a few years.

Financial losses have grown just as sharply. Over the past five years, Indians are estimated to have lost approximately ₹55,659 crore to cyber-enabled scams. In 2025 alone, losses were reported at around ₹22,495 crore, making cyber fraud one of the fastest-growing categories of financial crime in the country. Authorities also note that certain categories of scams, including fake investment schemes, UPI fraud and impersonation-based deception, are increasing at annual rates exceeding 30 percent.

The Sri Lankan case underscores how these trends are no longer confined within national borders. Instead, cybercrime networks are increasingly operating as regional ecosystems involving multiple nationalities, mobile teams and shifting operational bases. The presence of Indian and Nepalese suspects working together in Dodanduwa highlights the transnational nature of these operations, which often exploit gaps in enforcement between neighboring countries.

Cybersecurity experts describe such networks as highly “industrialized.” Unlike early cybercriminal activity, which was often carried out by individuals or small groups, modern fraud operations resemble organized call centers. They include specialized roles such as recruiters, technical operators, script writers, data handlers and supervisors who coordinate communication strategies and monitor targets. The large number of devices recovered in Sri Lanka suggests precisely this type of structured operation.

The seizure of 152 mobile phones is particularly significant, as it indicates the possible use of SIM farms and multi-account systems designed to scale fraudulent communication. Combined with 22 computers, the setup points toward a backend infrastructure capable of managing databases of victims, tracking financial flows and automating messaging campaigns. Such systems are commonly associated with large-scale digital fraud networks operating across Asia.

The rise of these scams is closely linked to South Asia’s rapid digital transformation. The expansion of mobile banking, instant payment systems and online trading platforms has created new opportunities for fraudsters. Common scams now include fake investment platforms promising high returns, impersonation of bank officials, QR code payment frauds and so-called “digital arrest” scams, where victims are coerced into transferring money under false legal threats.

A defining feature of these operations is their reliance on psychological manipulation rather than technical hacking. Victims are typically contacted through phone calls or messaging apps and pressured into revealing sensitive information such as one-time passwords or banking credentials. In many cases, urgency, fear and authority impersonation are used to force rapid financial decisions.

The Sri Lankan raid also echoes the broader “Jamtara-style” cybercrime phenomenon in India, named after a district in Jharkhand that became infamous for phone-based phishing scams. Popularized globally through the Netflix series “Jamtara – Sabka Number Ayega,” the model showed how small, coordinated groups could exploit banking users through deception and social engineering.

However, what began as a localized crime pattern has now evolved into a far more complex transnational system. Investigators increasingly report that similar fraud models are being replicated across borders, with mobile teams shifting locations frequently to avoid detection. The Dodanduwa case suggests that such networks may now be embedding themselves in rented accommodations across the region, taking advantage of anonymity and mobility.

Sri Lanka’s geography and tourism infrastructure may be unintentionally facilitating this trend. Coastal towns, with their transient populations and rental properties, can offer ideal cover for groups seeking short-term operational bases. The raid in Dodanduwa raises concerns that such locations could be increasingly exploited for illicit digital activities targeting victims across multiple jurisdictions.

The involvement of Indian nationals in the case adds another layer of regional complexity. As cybercrime investigations expand, cooperation between South Asian law enforcement agencies is expected to become increasingly important. Cross-border movement of suspects between India, Nepal and Sri Lanka reflects a growing pattern of mobile cybercrime networks that operate beyond the reach of any single national authority.

The financial stakes are enormous. With Indian losses alone exceeding ₹55,000 crore in recent years and similar upward trends reported across neighboring countries, cyber fraud is emerging as a systemic regional threat. Authorities warn that without coordinated enforcement and stronger digital safeguards, the scale of losses could continue to rise sharply.

As forensic experts begin analyzing the seized devices, investigators hope to reconstruct communication networks, financial flows and potential victim lists. These findings could determine whether the Dodanduwa group was an isolated cell or part of a larger, more sophisticated cybercrime syndicate operating across South Asia.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog