A long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened tens.
Social Engineering Examples·11 sources
Beginning at least in 2014 and escalating through 2018-2020, a network of India-based call centres ran a mass vishing campaign against Canadian taxpayers, using auto-dialed robocalls and live callers who impersonated Canada Revenue Agency (and, in escalated cases, RCMP) officers, falsely claiming victims owed back taxes and threatening immediate arrest, imprisonment, or deportation unless payment was made right away via gift cards, Bitcoin, wire transfer, or e-transfer.
CBC Marketplace traced a major hub to a Mumbai apartment building in 2018. RCMP's Greater Toronto Area Financial Crime Section opened Project OCTAVIA in October 2018 to combine public-awareness efforts, disruption, and enforcement; working with Indian police, the RCMP Liaison Office in New Delhi, CAFC, CRA, CBSA, and FINTRAC, authorities conducted a wave of raids that dismantled roughly 39-40 illegal call centres in India by 2019 and arrested dozens of operators there.
In Canada, RCMP identified and prosecuted domestic "money mules" and "money mule managers" who laundered scam proceeds back overseas, laying fraud and money-laundering charges against at least ten individuals between February and December 2020; of these, only the Dhaliwals were confirmed Canada-based residents arrested domestically, while Manik, Shrestha, Joshi, and Pao were charged via Canada-wide warrants while believed to be abroad (India, Nepal, and China respectively).
The scam used mass auto-dialers ("robo-dialers") to blast pre-recorded messages to Canadian landlines and cellphones claiming the recipient owed back taxes to the Canada Revenue Agency and must call back immediately or face arrest. Victims who called back reached a "call opener" in an India-based boiler-room call centre (a major hub was traced by CBC Marketplace to a Mumbai apartment building) who, using spoofed caller ID and scripted authority language, impersonated a CRA officer or, in escalated calls, an RCMP officer.
Callers cited fabricated case/badge numbers, threatened immediate arrest, jail, asset seizure, deportation (used disproportionately against new immigrants), or in some scripts loss of custody of children, and pressured the victim to resolve the "debt" that same call. Payment was demanded through channels that are irreversible and hard to trace: prepaid gift cards (iTunes, Steam), Bitcoin ATMs, wire transfers, e-transfers, or cash pickup, sometimes via a secondary "collector" who visited the victim in person.
Later variants layered in a fake "accountant" persona and call-tech that prevented victims from hanging up. Proceeds were laundered back to India through Canada-based "money mules" and "money mule managers" who received, cash-structured, and forwarded the funds, and through cryptocurrency conversion. The RCMP GTA Financial Crime Section (Toronto West Detachment) opened Project OCTAVIA in October 2018 to combine public-awareness work, disruption, and enforcement, coordinating with CAFC, CRA, CBSA, FINTRAC, the RCMP Liaison Office in New Delhi, India's Central Bureau of Investigation, and US authorities based in India.
Lure: an automated or live call falsely claiming to be from the Canada Revenue Agency (and, in escalated calls, the RCMP) stating the recipient owes back taxes or fines and faces immediate arrest, jail, asset seizure, or deportation unless the debt is settled on the spot; urgency was reinforced with fabricated case numbers, badge/officer names, and threats extending to loss of employment or child custody.
The "tell" that distinguished it from any genuine government contact: CRA and RCMP never initiate contact demanding immediate payment by gift card, Bitcoin, wire/e-transfer, or prepaid card, never threaten instant arrest over the phone, and never ask for payment to resolve a tax debt in a single call; genuine CRA correspondence is mailed and payment goes through CRA's own online account or cheque, never gift cards or crypto.
Indian law enforcement, working with RCMP's Liaison Office in New Delhi and India's Central Bureau of Investigation, raided and dismantled roughly 39-40 illegal call centres in the Mumbai and Noida/New Delhi areas between September 2018 and 2019, with RCMP/CAFC reporting over 60 arrests in India by early 2019 and CBC later citing 45 arrests tied to 39 raids by August 2019. On the Canadian side, RCMP's Project OCTAVIA identified domestic money-mule networks laundering proceeds back to India; on February 12, 2020, RCMP arrested and charged Brampton, Ontario residents Gurinderpreet Dhaliwal and Inderpreet Dhaliwal with fraud over $5,000, laundering proceeds of crime, and possession of property obtained by crime, seizing roughly $26,000 cash, $114,000 in jewelry, and a cash-counting machine; a Canada-wide warrant was also issued for Shantanu Manik, a foreign national believed to be in India.
RCMP continued laying charges against facilitators through 2020, including Vimal Shrestha and Bindisha Joshi of Lalitpur/Kathmandu, Nepal (announced Nov 27, 2020, with Canada-wide warrants issued for both as they were believed to be in Nepal) and Thomas Pao, who held a Mississauga address (charged Dec 3, 2020, with a Canada-wide warrant issued as he was believed to be in China); RCMP said nine individuals had been charged as of December 3, 2020, rising to ten by December 23, 2020. Only the Dhaliwals are confirmed as Canada-based residents arrested in Canada; Manik, Shrestha, Joshi, and (per the warrant) Pao were all charged in absentia while believed to be located outside Canada.
Public Safety Canada credited Project OCTAVIA with helping cut reported CRA-scam losses from $6.4 million in 2018 to $1.4 million in 2019, though RCMP and CBC both note the underlying networks adapted their scripts (e.g., adding "Bank Investigator" and "Tech Support" personas) and continued targeting Canadians afterward.
This case is a textbook illustration of how authority-impersonation vishing scales into an industrial, transnational criminal enterprise: a single scam script (fake CRA tax debt, arrest threat, gift-card payment) run through robo-dialers generated tens of millions of dollars in losses across tens of thousands of victims over roughly half a decade, disproportionately harming elderly people and new immigrants who were less familiar with how Canadian government agencies actually communicate.
It also demonstrates the limits of takedown-only enforcement: even after ~39-40 India call centres were raided and Canadian money mules were arrested and charged, RCMP itself noted the network adapted (adding "Bank Investigator" and "Tech Support" personas) and continued targeting Canadians, underscoring that disrupting the call centres does not eliminate the underlying playbook, and that user-side recognition (knowing CRA never demands gift-card/crypto payment or threatens instant phone arrest) remains a necessary complementary defense alongside law enforcement action.
RCMP/CRA/CAFC public-awareness campaigns reiterating that CRA never demands payment by gift card, cryptocurrency, e-transfer, prepaid card, or wire transfer, and never threatens immediate arrest/deportation by phone; "hang up and report to CAFC" guidance; international law-enforcement cooperation (RCMP Liaison Office-New Delhi, Indian CBI, US authorities in India, CBSA, FINTRAC) to identify and raid call centres; RCMP financial-crime units tracing domestic money-mule networks via FINTRAC financial-intelligence referrals; prosecution of Canada-based facilitators under fraud/money-laundering statutes; consumer education urging caller-ID skepticism and verification via official CRA callback numbers.
Social Engineering Examples. “CRA/RCMP Tax-Scam Vishing Network - Project OCTAVIA (2018-2020)”. Accessed 19 September 2026. https://socialengineeringexamples.com/cra-rcmp-tax-scam-vishing-project-octavia-2018-2020
The network is documented (per RCMP and CBC Marketplace reporting) as running out of boiler-room call centres in India, typically requiring bulk lists of Canadian phone numbers, VoIP or auto-dialer platforms capable of blasting robocalls at scale, and caller-ID spoofing tools that display CRA- or government-looking numbers, along with scripted personas (call opener, escalation officer, later a fake accountant) and staff trained to deliver them.
Overseas call-centre infrastructure and bulk consumer phone-number lists are largely outside Canadian regulatory reach; the realistic control shifts to Stage 3-4, where public awareness and CRA's own "we never do this" messaging blunt the impersonation regardless of how the calling infrastructure was built.
Auto-dialers ("robo-dialers") sent pre-recorded messages to large numbers of Canadian landlines and cellphones claiming the recipient owed back taxes to the CRA and instructing them to call back immediately or face arrest.
Telecom-level defenses such as carrier robocall filtering and caller-ID authentication standards (e.g., STIR/SHAKEN-style frameworks) can block or flag a portion of spoofed mass-dial traffic before it reaches subscribers, though determined operators using overseas VoIP routes can still evade full coverage.
Victims who called back reached a "call opener" in the India-based centre who, using spoofed caller ID and scripted authority language, impersonated a CRA officer or, in escalated calls, an RCMP officer, and cited fabricated case or badge numbers to establish false legitimacy.
RCMP, CRA, and CAFC public-awareness campaigns teach recipients that the CRA never initiates contact demanding immediate payment or threatening arrest, and that any callback should go to CRA's own published number rather than one given by the caller, undercutting the impersonation at first contact.
The caller threatened immediate arrest, jail, asset seizure, deportation (used disproportionately against new immigrants), or in some scripts loss of child custody, pressuring the victim to resolve the "debt" within the same call; later variants added a fake "accountant" persona and call-tech that made it harder for victims to hang up.
Consumer education specifically targeting the fear tactics used (instant arrest, deportation, asset seizure, custody loss) and "hang up immediately if pressured" guidance, repeated through CAFC bulletins and CRA's official scam-recognition page, are the documented countermeasure to the psychological escalation script.
The victim was directed to pay through channels that are largely irreversible and hard to trace, prepaid gift cards, Bitcoin ATMs, wire transfers, e-transfers, or cash handed to an in-person "collector," completing the theft of funds.
Retailer and financial-institution point-of-sale controls, gift-card rack warning signage, staff training to question large or panicked gift-card purchases, and Bitcoin-ATM operator warnings about phone-instructed transfers can intercept the payment step before funds leave the victim's control.
Canada-based "money mules" and "money mule managers," including the Dhaliwals in Brampton, received, cash-structured, and forwarded victim payments, converting some proceeds through cryptocurrency and routing funds back overseas to the organizers in India.
FINTRAC financial-intelligence referrals and RCMP financial-crime units tracing suspicious cash-structuring and fund transfers are the documented mechanism that identified and led to charges against the Canada-based money-mule network, including the Dhaliwal arrests.
Laundered proceeds reached the India-based organizers, completing the fraud objective; RCMP and CBC reporting notes that even after enforcement action the network adapted its scripts (adding "Bank Investigator" and "Tech Support" personas) and kept operating, showing the payout cycle repeating with new call centres and personas.
International law-enforcement cooperation, RCMP's Liaison Office in New Delhi working with India's Central Bureau of Investigation to raid and dismantle call centres, combined with prosecution of Canada-based facilitators, is the documented response to the payout and continuation stage, though RCMP itself notes this disrupts rather than permanently eliminates the network, which re-forms under new personas.
Browse by what this case has in common with others in the library.
Costa Rica-based ringleader Roger Roger used spoofed government caller ID to convince hundreds of elderly victims they had won sweepstakes…
NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans.
A Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
Two Quebec fraudsters acting as courier and driver for an AI-voice-cloned "grandchild in crisis" vishing scheme that defrauded Saskatchewan seniors.
A victim searching for the AnyDesk remote-access tool hit a typosquatted site with a fake Cloudflare Turnstile.
In late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and…
A Russian-speaking threat actor used disposable, one-conversation ChatGPT accounts to iteratively build and debug a Go-based Windows malware family.
A nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted…
A suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously…
A Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild.
Toronto podcast-analytics company CoHost spent two months and seven interview rounds with a candidate later revealed as an AI-fabricated persona…
A spoofed-email scheme impersonating MacEwan University's trusted general contractor, Clark Builders.
Two Quebec fraudsters acting as courier and driver for an AI-voice-cloned "grandchild in crisis" vishing scheme that defrauded Saskatchewan seniors.
A single vishing call impersonating Carnival's own IT security team convinced an employee to hand over credentials.
A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136…
Ghanaian social-media personality Frederick Kumi ("Abu Trica") and co-defendant Daniel Yussif were federally indicted for leading a romance-fraud network.
A mass SMS phishing campaign impersonating U.S. toll agencies spoofed 'unpaid toll' notices, drawing 2,000+ FBI complaints within weeks.
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.
A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support.