Case Library / Vishing (Voice Phishing) / CRA/RCMP Tax-Scam Vishing Network - Project OCTAVIA (2018-2020)

CRA/RCMP Tax-Scam Vishing Network - Project OCTAVIA (2018-2020)

A long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened tens of thousands of Canadians with arrest or deportation over fake tax debts, stealing tens of millions of dollars before RCMP's Project OCTAVIA and Indian police raids on roughly 39-40 call centres, plus Canadian money-mule prosecutions, disrupted the operation.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Beginning at least in 2014 and escalating through 2018-2020, a network of India-based call centres ran a mass vishing campaign against Canadian taxpayers, using auto-dialed robocalls and live callers who impersonated Canada Revenue Agency (and, in escalated cases, RCMP) officers, falsely claiming victims owed back taxes and threatening immediate arrest, imprisonment, or deportation unless payment was made right away via gift cards, Bitcoin, wire transfer, or e-transfer. CBC Marketplace traced a major hub to a Mumbai apartment building in 2018. RCMP's Greater Toronto Area Financial Crime Section opened Project OCTAVIA in October 2018 to combine public-awareness efforts, disruption, and enforcement; working with Indian police, the RCMP Liaison Office in New Delhi, CAFC, CRA, CBSA, and FINTRAC, authorities conducted a wave of raids that dismantled roughly 39-40 illegal call centres in India by 2019 and arrested dozens of operators there. In Canada, RCMP identified and prosecuted domestic "money mules" and "money mule managers" who laundered scam proceeds back overseas, laying fraud and money-laundering charges against at least ten individuals between February and December 2020; of these, only the Dhaliwals were confirmed Canada-based residents arrested domestically, while Manik, Shrestha, Joshi, and Pao were charged via Canada-wide warrants while believed to be abroad (India, Nepal, and China respectively).

How the Attack Worked

The scam used mass auto-dialers ("robo-dialers") to blast pre-recorded messages to Canadian landlines and cellphones claiming the recipient owed back taxes to the Canada Revenue Agency and must call back immediately or face arrest. Victims who called back reached a "call opener" in an India-based boiler-room call centre (a major hub was traced by CBC Marketplace to a Mumbai apartment building) who, using spoofed caller ID and scripted authority language, impersonated a CRA officer or, in escalated calls, an RCMP officer. Callers cited fabricated case/badge numbers, threatened immediate arrest, jail, asset seizure, deportation (used disproportionately against new immigrants), or in some scripts loss of custody of children, and pressured the victim to resolve the "debt" that same call. Payment was demanded through channels that are irreversible and hard to trace: prepaid gift cards (iTunes, Steam), Bitcoin ATMs, wire transfers, e-transfers, or cash pickup, sometimes via a secondary "collector" who visited the victim in person. Later variants layered in a fake "accountant" persona and call-tech that prevented victims from hanging up. Proceeds were laundered back to India through Canada-based "money mules" and "money mule managers" who received, cash-structured, and forwarded the funds, and through cryptocurrency conversion. The RCMP GTA Financial Crime Section (Toronto West Detachment) opened Project OCTAVIA in October 2018 to combine public-awareness work, disruption, and enforcement, coordinating with CAFC, CRA, CBSA, FINTRAC, the RCMP Liaison Office in New Delhi, India's Central Bureau of Investigation, and US authorities based in India.

The Lure & the Tell

Lure: an automated or live call falsely claiming to be from the Canada Revenue Agency (and, in escalated calls, the RCMP) stating the recipient owes back taxes or fines and faces immediate arrest, jail, asset seizure, or deportation unless the debt is settled on the spot; urgency was reinforced with fabricated case numbers, badge/officer names, and threats extending to loss of employment or child custody. The "tell" that distinguished it from any genuine government contact: CRA and RCMP never initiate contact demanding immediate payment by gift card, Bitcoin, wire/e-transfer, or prepaid card, never threaten instant arrest over the phone, and never ask for payment to resolve a tax debt in a single call; genuine CRA correspondence is mailed and payment goes through CRA's own online account or cheque, never gift cards or crypto.

Outcome

Indian law enforcement, working with RCMP's Liaison Office in New Delhi and India's Central Bureau of Investigation, raided and dismantled roughly 39-40 illegal call centres in the Mumbai and Noida/New Delhi areas between September 2018 and 2019, with RCMP/CAFC reporting over 60 arrests in India by early 2019 and CBC later citing 45 arrests tied to 39 raids by August 2019. On the Canadian side, RCMP's Project OCTAVIA identified domestic money-mule networks laundering proceeds back to India; on February 12, 2020, RCMP arrested and charged Brampton, Ontario residents Gurinderpreet Dhaliwal and Inderpreet Dhaliwal with fraud over $5,000, laundering proceeds of crime, and possession of property obtained by crime, seizing roughly $26,000 cash, $114,000 in jewelry, and a cash-counting machine; a Canada-wide warrant was also issued for Shantanu Manik, a foreign national believed to be in India. RCMP continued laying charges against facilitators through 2020, including Vimal Shrestha and Bindisha Joshi of Lalitpur/Kathmandu, Nepal (announced Nov 27, 2020, with Canada-wide warrants issued for both as they were believed to be in Nepal) and Thomas Pao, who held a Mississauga address (charged Dec 3, 2020, with a Canada-wide warrant issued as he was believed to be in China); RCMP said nine individuals had been charged as of December 3, 2020, rising to ten by December 23, 2020. Only the Dhaliwals are confirmed as Canada-based residents arrested in Canada; Manik, Shrestha, Joshi, and (per the warrant) Pao were all charged in absentia while believed to be located outside Canada. Public Safety Canada credited Project OCTAVIA with helping cut reported CRA-scam losses from $6.4 million in 2018 to $1.4 million in 2019, though RCMP and CBC both note the underlying networks adapted their scripts (e.g., adding "Bank Investigator" and "Tech Support" personas) and continued targeting Canadians afterward.

Why It Matters

This case is a textbook illustration of how authority-impersonation vishing scales into an industrial, transnational criminal enterprise: a single scam script (fake CRA tax debt, arrest threat, gift-card payment) run through robo-dialers generated tens of millions of dollars in losses across tens of thousands of victims over roughly half a decade, disproportionately harming elderly people and new immigrants who were less familiar with how Canadian government agencies actually communicate. It also demonstrates the limits of takedown-only enforcement: even after ~39-40 India call centres were raided and Canadian money mules were arrested and charged, RCMP itself noted the network adapted (adding "Bank Investigator" and "Tech Support" personas) and continued targeting Canadians, underscoring that disrupting the call centres does not eliminate the underlying playbook, and that user-side recognition (knowing CRA never demands gift-card/crypto payment or threatens instant phone arrest) remains a necessary complementary defense alongside law enforcement action.

Defenses

RCMP/CRA/CAFC public-awareness campaigns reiterating that CRA never demands payment by gift card, cryptocurrency, e-transfer, prepaid card, or wire transfer, and never threatens immediate arrest/deportation by phone; "hang up and report to CAFC" guidance; international law-enforcement cooperation (RCMP Liaison Office-New Delhi, Indian CBI, US authorities in India, CBSA, FINTRAC) to identify and raid call centres; RCMP financial-crime units tracing domestic money-mule networks via FINTRAC financial-intelligence referrals; prosecution of Canada-based facilitators under fraud/money-laundering statutes; consumer education urging caller-ID skepticism and verification via official CRA callback numbers.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Infrastructure setup: The network is documented (per RCMP and CBC Marketplace reporting) as running out of boiler-room call centres in India, typically requiring bulk lists of Canadian phone numbers, VoIP or auto-dialer platforms capable of blasting robocalls at scale, and caller-ID spoofing tools that display CRA- or government-looking numbers, along with scripted personas (call opener, escalation officer, later a fake accountant) and staff trained to deliver them.
Countering Stage 1: Overseas call-centre infrastructure and bulk consumer phone-number lists are largely outside Canadian regulatory reach; the realistic control shifts to Stage 3-4, where public awareness and CRA's own "we never do this" messaging blunt the impersonation regardless of how the calling infrastructure was built.
2
Mass robocall blast: Auto-dialers ("robo-dialers") sent pre-recorded messages to large numbers of Canadian landlines and cellphones claiming the recipient owed back taxes to the CRA and instructing them to call back immediately or face arrest.
Countering Stage 2: Telecom-level defenses such as carrier robocall filtering and caller-ID authentication standards (e.g., STIR/SHAKEN-style frameworks) can block or flag a portion of spoofed mass-dial traffic before it reaches subscribers, though determined operators using overseas VoIP routes can still evade full coverage.
3
Live call engagement: Victims who called back reached a "call opener" in the India-based centre who, using spoofed caller ID and scripted authority language, impersonated a CRA officer or, in escalated calls, an RCMP officer, and cited fabricated case or badge numbers to establish false legitimacy.
Countering Stage 3: RCMP, CRA, and CAFC public-awareness campaigns teach recipients that the CRA never initiates contact demanding immediate payment or threatening arrest, and that any callback should go to CRA's own published number rather than one given by the caller, undercutting the impersonation at first contact.
4
Psychological escalation: The caller threatened immediate arrest, jail, asset seizure, deportation (used disproportionately against new immigrants), or in some scripts loss of child custody, pressuring the victim to resolve the "debt" within the same call; later variants added a fake "accountant" persona and call-tech that made it harder for victims to hang up.
Countering Stage 4: Consumer education specifically targeting the fear tactics used (instant arrest, deportation, asset seizure, custody loss) and "hang up immediately if pressured" guidance, repeated through CAFC bulletins and CRA's official scam-recognition page, are the documented countermeasure to the psychological escalation script.
5
Payment extraction: The victim was directed to pay through channels that are largely irreversible and hard to trace, prepaid gift cards, Bitcoin ATMs, wire transfers, e-transfers, or cash handed to an in-person "collector," completing the theft of funds.
Countering Stage 5: Retailer and financial-institution point-of-sale controls, gift-card rack warning signage, staff training to question large or panicked gift-card purchases, and Bitcoin-ATM operator warnings about phone-instructed transfers can intercept the payment step before funds leave the victim's control.
6
Money laundering: Canada-based "money mules" and "money mule managers," including the Dhaliwals in Brampton, received, cash-structured, and forwarded victim payments, converting some proceeds through cryptocurrency and routing funds back overseas to the organizers in India.
Countering Stage 6: FINTRAC financial-intelligence referrals and RCMP financial-crime units tracing suspicious cash-structuring and fund transfers are the documented mechanism that identified and led to charges against the Canada-based money-mule network, including the Dhaliwal arrests.
7
Payout and continuation: Laundered proceeds reached the India-based organizers, completing the fraud objective; RCMP and CBC reporting notes that even after enforcement action the network adapted its scripts (adding "Bank Investigator" and "Tech Support" personas) and kept operating, showing the payout cycle repeating with new call centres and personas.
Countering Stage 7: International law-enforcement cooperation, RCMP's Liaison Office in New Delhi working with India's Central Bureau of Investigation to raid and dismantle call centres, combined with prosecution of Canada-based facilitators, is the documented response to the payout and continuation stage, though RCMP itself notes this disrupts rather than permanently eliminates the network, which re-forms under new personas.
Quick Facts
Victim
Tens of thousands of Canadian taxpayers (CAFC/CRA reported roughly 60,000 complaints over the scam's run; separately, CAFC reported nearly 20,000 reports and more than 5,500 victims in 2019, but that figure covers the combined CRA, SIN, tech-support, and bank-investigator scam family, not the CRA scam specifically), disproportionately elderly Canadians and new immigrants
Location
Canada (nationwide, victims); India (Mumbai, Noida, New Delhi area call centres)
Date
2014-2020 (scam active); RCMP Project OCTAVIA investigation launched October 2018; India raids concentrated 2018-2019; Canadian arrests/charges Feb 2020-Dec 2020
Impact
RCMP reported the CRA phone scam alone caused over $16.8 million in reported victim losses from 2014-2019, rising to over $18.5 million cumulative by October 1, 2020; including the related Bank Investigator and Tech Support scams run by the same networks, total reported losses exceeded $30 million (Feb 2020) and later over $34 million (Oct 2020). Public Safety Canada separately reported CRA-scam losses fell from $6.4 million in 2018 to $1.4 million in 2019 after Project OCTAVIA disruption. CBC reported in 2018 that over $10 million had been stolen over five years with individual victims losing as little as $700 and as much as $110,000+ (one Toronto victim, Gehangir Rashidi, lost his entire $110,000 life savings via Bitcoin ATMs). These are reported-loss figures only; CAFC and RCMP both note significant underreporting.
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Government & Public Sector
Threat Actor
Organized Crime
Related

Related Cases

Roger Roger's Costa Rica Sweepstakes Call Center: VOIP-Spoofed Government Impersonation Bilks Hundreds of Elderly Victims of $4M+

Costa Rica-based telemarketing ringleader Roger Roger used VOIP-spoofed Washington D.C. caller ID and fake government-official personas to convince hundreds of…

Incident 2014Read →

NTS IT Care / Jagmeet Singh Virk Tech-Support Pop-Up Scam

NTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans, into calling a rigged India-based support…

Incident 2014Read →

Shred-It and Iron Mountain Pay $1.1 Million to Settle GSA Shredding False Claims Act Whistleblower Suit (2013)

A Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain, and Cintas billed federal agencies for GSA-spec…

Incident 2013Read →