Case Library / Vishing (Voice Phishing) / CRA/RCMP Tax-Scam Vishing Network - Project OCTAVIA (2018-2020)

CRA/RCMP Tax-Scam Vishing Network - Project OCTAVIA (2018-2020)

A long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened tens.

Share:

Social Engineering Examples·11 sources

What Happened

Beginning at least in 2014 and escalating through 2018-2020, a network of India-based call centres ran a mass vishing campaign against Canadian taxpayers, using auto-dialed robocalls and live callers who impersonated Canada Revenue Agency (and, in escalated cases, RCMP) officers, falsely claiming victims owed back taxes and threatening immediate arrest, imprisonment, or deportation unless payment was made right away via gift cards, Bitcoin, wire transfer, or e-transfer.

CBC Marketplace traced a major hub to a Mumbai apartment building in 2018. RCMP's Greater Toronto Area Financial Crime Section opened Project OCTAVIA in October 2018 to combine public-awareness efforts, disruption, and enforcement; working with Indian police, the RCMP Liaison Office in New Delhi, CAFC, CRA, CBSA, and FINTRAC, authorities conducted a wave of raids that dismantled roughly 39-40 illegal call centres in India by 2019 and arrested dozens of operators there.

In Canada, RCMP identified and prosecuted domestic "money mules" and "money mule managers" who laundered scam proceeds back overseas, laying fraud and money-laundering charges against at least ten individuals between February and December 2020; of these, only the Dhaliwals were confirmed Canada-based residents arrested domestically, while Manik, Shrestha, Joshi, and Pao were charged via Canada-wide warrants while believed to be abroad (India, Nepal, and China respectively).

How the Attack Worked

The scam used mass auto-dialers ("robo-dialers") to blast pre-recorded messages to Canadian landlines and cellphones claiming the recipient owed back taxes to the Canada Revenue Agency and must call back immediately or face arrest. Victims who called back reached a "call opener" in an India-based boiler-room call centre (a major hub was traced by CBC Marketplace to a Mumbai apartment building) who, using spoofed caller ID and scripted authority language, impersonated a CRA officer or, in escalated calls, an RCMP officer.

Callers cited fabricated case/badge numbers, threatened immediate arrest, jail, asset seizure, deportation (used disproportionately against new immigrants), or in some scripts loss of custody of children, and pressured the victim to resolve the "debt" that same call. Payment was demanded through channels that are irreversible and hard to trace: prepaid gift cards (iTunes, Steam), Bitcoin ATMs, wire transfers, e-transfers, or cash pickup, sometimes via a secondary "collector" who visited the victim in person.

Later variants layered in a fake "accountant" persona and call-tech that prevented victims from hanging up. Proceeds were laundered back to India through Canada-based "money mules" and "money mule managers" who received, cash-structured, and forwarded the funds, and through cryptocurrency conversion. The RCMP GTA Financial Crime Section (Toronto West Detachment) opened Project OCTAVIA in October 2018 to combine public-awareness work, disruption, and enforcement, coordinating with CAFC, CRA, CBSA, FINTRAC, the RCMP Liaison Office in New Delhi, India's Central Bureau of Investigation, and US authorities based in India.

The Lure & the Tell

Lure: an automated or live call falsely claiming to be from the Canada Revenue Agency (and, in escalated calls, the RCMP) stating the recipient owes back taxes or fines and faces immediate arrest, jail, asset seizure, or deportation unless the debt is settled on the spot; urgency was reinforced with fabricated case numbers, badge/officer names, and threats extending to loss of employment or child custody.

The "tell" that distinguished it from any genuine government contact: CRA and RCMP never initiate contact demanding immediate payment by gift card, Bitcoin, wire/e-transfer, or prepaid card, never threaten instant arrest over the phone, and never ask for payment to resolve a tax debt in a single call; genuine CRA correspondence is mailed and payment goes through CRA's own online account or cheque, never gift cards or crypto.

Outcome

Indian law enforcement, working with RCMP's Liaison Office in New Delhi and India's Central Bureau of Investigation, raided and dismantled roughly 39-40 illegal call centres in the Mumbai and Noida/New Delhi areas between September 2018 and 2019, with RCMP/CAFC reporting over 60 arrests in India by early 2019 and CBC later citing 45 arrests tied to 39 raids by August 2019. On the Canadian side, RCMP's Project OCTAVIA identified domestic money-mule networks laundering proceeds back to India; on February 12, 2020, RCMP arrested and charged Brampton, Ontario residents Gurinderpreet Dhaliwal and Inderpreet Dhaliwal with fraud over $5,000, laundering proceeds of crime, and possession of property obtained by crime, seizing roughly $26,000 cash, $114,000 in jewelry, and a cash-counting machine; a Canada-wide warrant was also issued for Shantanu Manik, a foreign national believed to be in India.

RCMP continued laying charges against facilitators through 2020, including Vimal Shrestha and Bindisha Joshi of Lalitpur/Kathmandu, Nepal (announced Nov 27, 2020, with Canada-wide warrants issued for both as they were believed to be in Nepal) and Thomas Pao, who held a Mississauga address (charged Dec 3, 2020, with a Canada-wide warrant issued as he was believed to be in China); RCMP said nine individuals had been charged as of December 3, 2020, rising to ten by December 23, 2020. Only the Dhaliwals are confirmed as Canada-based residents arrested in Canada; Manik, Shrestha, Joshi, and (per the warrant) Pao were all charged in absentia while believed to be located outside Canada.

Public Safety Canada credited Project OCTAVIA with helping cut reported CRA-scam losses from $6.4 million in 2018 to $1.4 million in 2019, though RCMP and CBC both note the underlying networks adapted their scripts (e.g., adding "Bank Investigator" and "Tech Support" personas) and continued targeting Canadians afterward.

Why It Matters

This case is a textbook illustration of how authority-impersonation vishing scales into an industrial, transnational criminal enterprise: a single scam script (fake CRA tax debt, arrest threat, gift-card payment) run through robo-dialers generated tens of millions of dollars in losses across tens of thousands of victims over roughly half a decade, disproportionately harming elderly people and new immigrants who were less familiar with how Canadian government agencies actually communicate.

It also demonstrates the limits of takedown-only enforcement: even after ~39-40 India call centres were raided and Canadian money mules were arrested and charged, RCMP itself noted the network adapted (adding "Bank Investigator" and "Tech Support" personas) and continued targeting Canadians, underscoring that disrupting the call centres does not eliminate the underlying playbook, and that user-side recognition (knowing CRA never demands gift-card/crypto payment or threatens instant phone arrest) remains a necessary complementary defense alongside law enforcement action.

Defenses

RCMP/CRA/CAFC public-awareness campaigns reiterating that CRA never demands payment by gift card, cryptocurrency, e-transfer, prepaid card, or wire transfer, and never threatens immediate arrest/deportation by phone; "hang up and report to CAFC" guidance; international law-enforcement cooperation (RCMP Liaison Office-New Delhi, Indian CBI, US authorities in India, CBSA, FINTRAC) to identify and raid call centres; RCMP financial-crime units tracing domestic money-mule networks via FINTRAC financial-intelligence referrals; prosecution of Canada-based facilitators under fraud/money-laundering statutes; consumer education urging caller-ID skepticism and verification via official CRA callback numbers.

Sources
Cite this case

Social Engineering Examples. “CRA/RCMP Tax-Scam Vishing Network - Project OCTAVIA (2018-2020)”. Accessed 19 September 2026. https://socialengineeringexamples.com/cra-rcmp-tax-scam-vishing-project-octavia-2018-2020

Attack Chain & Defense
1Infrastructure setup
What happened

The network is documented (per RCMP and CBC Marketplace reporting) as running out of boiler-room call centres in India, typically requiring bulk lists of Canadian phone numbers, VoIP or auto-dialer platforms capable of blasting robocalls at scale, and caller-ID spoofing tools that display CRA- or government-looking numbers, along with scripted personas (call opener, escalation officer, later a fake accountant) and staff trained to deliver them.

The control that would have stopped it

Overseas call-centre infrastructure and bulk consumer phone-number lists are largely outside Canadian regulatory reach; the realistic control shifts to Stage 3-4, where public awareness and CRA's own "we never do this" messaging blunt the impersonation regardless of how the calling infrastructure was built.

2Mass robocall blast
What happened

Auto-dialers ("robo-dialers") sent pre-recorded messages to large numbers of Canadian landlines and cellphones claiming the recipient owed back taxes to the CRA and instructing them to call back immediately or face arrest.

The control that would have stopped it

Telecom-level defenses such as carrier robocall filtering and caller-ID authentication standards (e.g., STIR/SHAKEN-style frameworks) can block or flag a portion of spoofed mass-dial traffic before it reaches subscribers, though determined operators using overseas VoIP routes can still evade full coverage.

3Live call engagement
What happened

Victims who called back reached a "call opener" in the India-based centre who, using spoofed caller ID and scripted authority language, impersonated a CRA officer or, in escalated calls, an RCMP officer, and cited fabricated case or badge numbers to establish false legitimacy.

The control that would have stopped it

RCMP, CRA, and CAFC public-awareness campaigns teach recipients that the CRA never initiates contact demanding immediate payment or threatening arrest, and that any callback should go to CRA's own published number rather than one given by the caller, undercutting the impersonation at first contact.

4Psychological escalation
What happened

The caller threatened immediate arrest, jail, asset seizure, deportation (used disproportionately against new immigrants), or in some scripts loss of child custody, pressuring the victim to resolve the "debt" within the same call; later variants added a fake "accountant" persona and call-tech that made it harder for victims to hang up.

The control that would have stopped it

Consumer education specifically targeting the fear tactics used (instant arrest, deportation, asset seizure, custody loss) and "hang up immediately if pressured" guidance, repeated through CAFC bulletins and CRA's official scam-recognition page, are the documented countermeasure to the psychological escalation script.

5Payment extraction
What happened

The victim was directed to pay through channels that are largely irreversible and hard to trace, prepaid gift cards, Bitcoin ATMs, wire transfers, e-transfers, or cash handed to an in-person "collector," completing the theft of funds.

The control that would have stopped it

Retailer and financial-institution point-of-sale controls, gift-card rack warning signage, staff training to question large or panicked gift-card purchases, and Bitcoin-ATM operator warnings about phone-instructed transfers can intercept the payment step before funds leave the victim's control.

6Money laundering
What happened

Canada-based "money mules" and "money mule managers," including the Dhaliwals in Brampton, received, cash-structured, and forwarded victim payments, converting some proceeds through cryptocurrency and routing funds back overseas to the organizers in India.

The control that would have stopped it

FINTRAC financial-intelligence referrals and RCMP financial-crime units tracing suspicious cash-structuring and fund transfers are the documented mechanism that identified and led to charges against the Canada-based money-mule network, including the Dhaliwal arrests.

7Payout and continuation
What happened

Laundered proceeds reached the India-based organizers, completing the fraud objective; RCMP and CBC reporting notes that even after enforcement action the network adapted its scripts (adding "Bank Investigator" and "Tech Support" personas) and kept operating, showing the payout cycle repeating with new call centres and personas.

The control that would have stopped it

International law-enforcement cooperation, RCMP's Liaison Office in New Delhi working with India's Central Bureau of Investigation to raid and dismantle call centres, combined with prosecution of Canada-based facilitators, is the documented response to the payout and continuation stage, though RCMP itself notes this disrupts rather than permanently eliminates the network, which re-forms under new personas.

Quick Facts
Victim
Tens of thousands of Canadian taxpayers
(CAFC/CRA reported roughly 60,000 complaints over the scam's run; separately, CAFC reported nearly 20,000 reports and more than 5,500 victims in 2019, but that figure covers the combined CRA, SIN, tech-support, and bank-investigator scam family, not the CRA scam specifically), disproportionately elderly Canadians and new immigrants
Location
Canada (nationwide, victims); India (Mumbai, Noida, New Delhi area call centres)
Date
2014-2020
(scam active); RCMP Project OCTAVIA investigation launched October 2018; India raids concentrated 2018-2019; Canadian arrests/charges Feb 2020-Dec 2020
Impact
The CRA phone scam alone caused over $16.8 million in reported victim losses from 2014 to 2019.
RCMP reported the CRA phone scam alone caused over $16.8 million in reported victim losses from 2014-2019, rising to over $18.5 million cumulative by October 1, 2020; including the related Bank Investigator and Tech Support scams run by the same networks, total reported losses exceeded $30 million (Feb 2020) and later over $34 million (Oct 2020). Public Safety Canada separately reported CRA-scam losses fell from $6.4 million in 2018 to $1.4 million in 2019 after Project OCTAVIA disruption. CBC reported in 2018 that over $10 million had been stolen over five years with individual victims losing as little as $700 and as much as $110,000+ (one Toronto victim, Gehangir Rashidi, lost his entire $110,000 life savings via Bitcoin ATMs). These are reported-loss figures only; CAFC and RCMP both note significant underreporting.
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Government & Public Sector
Threat Actor
Organized Crime
Explore more

Related Cases

Browse by what this case has in common with others in the library.

Fake AnyDesk Installer to MetaStealer: FileFix/search-ms Variant of ClickFix

A victim searching for the AnyDesk remote-access tool hit a typosquatted site with a fake Cloudflare Turnstile.

Incident 2025Read →

Council on Foreign Relations Watering-Hole Attack (IE Zero-Day, CVE-2012-4792)

In late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and…

Incident 2012Read →

OpenAI's "ScopeCreep": Russian-Speaking Actor Used Disposable ChatGPT Accounts to Build C2-Enabled Windows Malware Distributed via a Trojanized "Crosshair-X" Gaming Tool

A Russian-speaking threat actor used disposable, one-conversation ChatGPT accounts to iteratively build and debug a Go-based Windows malware family.

Incident 2025Read →

Stuxnet: USB-borne sabotage of Iran's air-gapped Natanz enrichment plant

A nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted…

Incident 2010Read →

GTG-1002: AI-Orchestrated Cyber-Espionage Campaign Run Through Claude Code (2025)

A suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously…

Incident 2025Read →

Dominican Republic "Grandparent Scam" - Attorney/Police Impersonation Ring (D.N.J. Indictment)

A Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild.

Incident 2019Read →