DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad.
Social Engineering Examples·12 sources
On October 19, 2016, a federal grand jury in the Southern District of Texas returned a superseding indictment (unsealed October 27, 2016) charging 61 defendants and entities - 24 U.S.-based individuals, 32 India-based individuals, and 5 India-based call-center conglomerates - with conspiracy, wire fraud, money laundering, false personation of a U.S. federal officer, and identity theft.
The conglomerates, all based in Ahmedabad, Gujarat, ran a "telefraud" scheme in which callers impersonated IRS and USCIS officials, threatened victims across the U.S. with arrest, fines, or deportation, and directed them to pay via prepaid cards or wire transfers, which a U.S.-based network of "runners" then laundered using stolen identities. DHS-OIG, ICE Homeland Security Investigations, and TIGTA led the investigation; DOJ called it a "first-of-its-kind" nationwide takedown, arresting 20 U.S. defendants the day the indictment was unsealed and seeking extradition of dozens of India-based defendants.
Between 2017 and 2020, 24 U.S.-based defendants pleaded guilty and were sentenced (up to 20 years), and HGlobal's India-based owner Hitesh Madhubhai Patel, who had fled to Singapore, was extradited from Singapore in April 2019, pleaded guilty, and was sentenced in November 2020 to 20 years plus nearly $9 million in restitution.
Five Ahmedabad, Gujarat call-center conglomerates (HGlobal; Call Mantra, d/b/a Robust Inc./Raytheon International; Worldwide Solution; Zoriion Communications Pvt. Ltd.; Sharma BPO Services) bought victim contact lists and personal identifying information from data brokers, then had agents place spoofed calls into the U.S. impersonating IRS agents (claiming back taxes owed) or USCIS/immigration officers (claiming faulty paperwork).
Scripts threatened immediate arrest, imprisonment, fines, or deportation unless the victim paid on the spot. Compliant victims were walked through purchasing general-purpose reloadable (GPR)/prepaid stored-value cards (including iTunes and Reloadit-type cards) at retail stores and reading the card numbers over the phone, or wiring funds via MoneyGram/Western Union, or sending money orders/bank deposits.
As soon as a victim paid, the call centers routed the funds to a parallel network of U.S.-based "runners" (crews in Illinois, Arizona, Texas, Alabama, and elsewhere) who immediately registered fresh prepaid cards using stolen PII from thousands of separate identity-theft victims, then converted the loaded cards into money orders deposited into bank accounts, or picked up wires under false names using fraudulent IDs, laundering the money before banks or victims could reverse the transaction.
The five conglomerates cooperated with each other, sharing scripts, victim lead lists, and payment-processing infrastructure. The conspiracy ran from on or about January 2012/2013 through the October 2016 indictment.
Lure: an incoming call from a spoofed number that appeared to be from the IRS or a federal immigration call center, with a caller claiming to be a federal officer who cited the victim's real personal details (from purchased data-broker lead lists) and asserted the victim owed unpaid back taxes or had defective immigration paperwork. Tell: the U.S. government never initiates enforcement contact by phone with threats of immediate arrest/deportation, never demands payment via prepaid gift cards (iTunes, Reloadit, etc.) read over the phone, and never demands a single wire transfer or money order to resolve a "debt" under threat of same-day arrest; the artificial urgency and card-payment channel were the signature (and now widely publicized) tells of the scam.
61 defendants/entities were charged in the Oct. 19, 2016 superseding indictment (unsealed Oct. 27, 2016): 24 U.S.-based individuals plus 32 India-based individuals and the 5 India-based call-center conglomerates. 20 U.S. defendants were arrested the day the indictment was unsealed. Over the following years, 24 U.S.-based defendants pleaded guilty and were sentenced in SDTX (plus one each in the District of Arizona and Northern District of Georgia) to terms ranging from probation up to 20 years; among the harshest: Miteshkumar Patel (runner-crew manager) 240 months, Viraj Patel 165 months, Rajubhai Patel 151 months, Sunny Joshi 151 months, Hardik Patel (India-based call-center co-owner/manager who later moved to the U.S.) 188 months, Rajesh Bhatt 145 months, Bhavesh Patel 121 months.
Many U.S. defendants also faced deportation to India upon completing their sentences. Separately, HGlobal's India-based owner/funder Hitesh Madhubhai Patel (a.k.a. Hitesh Hinglaj) fled India for Singapore in 2018, was apprehended there by Singaporean authorities on a U.S. provisional arrest warrant on Sept. 21, 2018, and was extradited from Singapore (not India) to the U.S. on April 18, 2019; he pleaded guilty in Jan. 2020 and was sentenced Nov. 30, 2020 to 20 years in prison plus $8,970,396 restitution, the highest-profile India-based conviction to date.
Charges remained pending against numerous other India-based defendants who were not extradited as of the last public updates in this research.
This remains one of the largest and most thoroughly documented vishing/government-impersonation prosecutions in U.S. history and a template for how such scams are dismantled: it shows the full anatomy of a transnational telefraud operation (offshore call centers, data-broker-sourced victim lists, live scripted authority-impersonation calls, and a domestic runner network for near-instant laundering via prepaid cards and wires) and demonstrates that even offshore-based conspirators can face extradition and lengthy U.S. sentences.
It is also a clear case study in the gap between headline-grabbing charging-document loss figures ("hundreds of millions," "$300M+") and lower, independently tracked regulator figures (TIGTA's ~$60-73M), a distinction useful for teaching how to read fraud-loss claims critically. The scam's core mechanics (spoofed caller ID, IRS/immigration threats, demand for gift-card/wire payment) remain the exact pattern still used in ongoing IRS-impersonation and government-impersonation vishing scams today.
DOJ/DHS-OIG/HSI/TIGTA/IRS-CI joint multi-year investigation and coordinated nationwide arrest operation; extradition requests to India for numerous India-based defendants (separate from Hitesh Madhubhai Patel's Singapore extradition, see outcome); public-awareness messaging at the announcement press conference ("if you get this call, do not pay, it is not the U.S. government calling you"); TIGTA and IRS ongoing consumer-facing warnings about IRS-impersonation phone scams (IRS never initiates contact by threatening phone call demanding immediate payment via gift/prepaid cards or wire transfer); FTC/consumer guidance to hang up, verify independently via official agency phone numbers, and never pay government debts with gift cards or wires; card issuers and MoneyGram/Western Union AML-suspicious-activity monitoring cited by investigators as part of how the money trail was traced.
Social Engineering Examples. “India-Based IRS/USCIS Impersonation Call-Center Takedown (U.S. v. HGlobal et al., 61 Defendants)”. Accessed 19 September 2026. https://socialengineeringexamples.com/india-irs-uscis-vishing-call-center-takedown-2016
per the DOJ indictment and defendants' own plea admissions, the Ahmedabad call-center conglomerates bought victim contact lists and personal identifying information (PII) from commercial data brokers and other sources, giving callers real names, addresses, and other personal details to cite on the call and sound authoritative.
consumer exposure to data-broker lead lists is very hard for an individual to control at the source; the realistic control is downstream, teaching that a caller knowing your name or address is not proof of legitimacy, rather than trying to eliminate the lead-list market itself.
call centers used commercial telephony/VOIP infrastructure and caller-ID spoofing so calls appeared to originate from legitimate U.S. government numbers, consistent with the spoofing pattern TIGTA documented across IRS-impersonation scams of this era generally.
telecom carriers' caller-ID authentication frameworks (e.g. STIR/SHAKEN-style call-authentication standards) and consumer call-blocking/scam-labeling apps target spoofed-number delivery directly, and are the nearest practical control since the spoofing technique itself sits largely outside any individual victim's reach.
agents, following prepared call scripts (per indictment and plea admissions), placed calls impersonating IRS agents (claiming back taxes owed) or USCIS/immigration officers (claiming defective paperwork), often opening with the victim's real personal details from the purchased lead lists to establish false credibility.
the public-awareness messaging DOJ, TIGTA, and IRS repeated at and after the takedown, that the U.S. government does not initiate enforcement contact by unsolicited phone call, is the direct countermeasure; hanging up and calling the agency back on its official published number, rather than trusting the inbound caller, neutralizes this stage.
scripts threatened immediate arrest, imprisonment, fines, or deportation unless the victim paid before the call ended, a documented pattern across the indictment and TIGTA's consumer warnings, designed to prevent the victim from pausing to verify independently.
recognizing "pay immediately or be arrested" as a scam hallmark (per TIGTA/FTC guidance) and simply ending the call to verify independently breaks the artificial time pressure this stage depends on to prevent victims from thinking it through.
compliant victims were walked through purchasing GPR/prepaid stored-value cards (including iTunes and Reloadit-type cards) and reading the card numbers over the phone, or wiring funds via MoneyGram/Western Union, or sending money orders/bank deposits.
the single most emphasized public warning in TIGTA/FTC materials, that no legitimate government agency demands payment via prepaid gift cards or a one-time wire transfer, targets this exact stage; several retailers have since added point-of-sale warnings when customers buy large amounts of gift cards for this reason.
Rapid laundering via runner network and stolen-identity card registration: upon payment, call centers routed funds same-day to a U.S.-based runner network, who immediately registered fresh prepaid cards using stolen PII from separate identity-theft victims, then converted the loaded cards into money orders deposited into bank accounts or picked up wires under false identities, moving the money before it could be traced or reversed.
this stage is largely invisible to the original victim and hardest to interdict in real time; the realistic control sits with card issuers' and MoneyGram/Western Union's anti-money-laundering and suspicious-activity monitoring, which investigators credited with helping trace the money trail after the fact.
laundered proceeds were split between the India-based call-center operators and the U.S.-based runner crews (who kept a fee or percentage per transaction), funding continued operations that scaled the scheme to over 15,000 direct victims across a roughly four-year run before the 2016 takedown.
no consumer-facing control reaches this final stage; the terminal countermeasure is the coordinated multi-agency (DHS-OIG/ICE-HSI/TIGTA/DOJ) financial and telecom-record investigation and prosecution that ultimately identified, charged, and dismantled the network, since sustained laundering requires the conspiracy to keep operating undetected.
Browse by what this case has in common with others in the library.
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
Fraudsters impersonating Leoni AG executives tricked its Romanian subsidiary into wiring roughly EUR 40 million ($44.6M) to attackers.
Posing as NatWest bank security, vishing criminals convinced Surrey solicitor Karen Mackie to wire £734,000 of client money to fraudulent…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A spoofed-email scheme impersonating MacEwan University's trusted general contractor, Clark Builders.
A Pune CFO wired Rs 56 lakh after a Microsoft Teams message impersonating her Italian CEO demanded an urgent transfer.
A long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened…
FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages.
A suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously…
Scammers impersonating PG&E threaten customers and small businesses with immediate service disconnection.
Hornetsecurity documented a QR-phishing (quishing) email sent to a single employee at a US-based MSP that spoofed an MFA-reactivation notice…
A complex criminal phishing scheme induced Argan, Inc. to send two outbound wires in March 2023, producing a roughly $3…
Attackers hijacked a staff email account and used fake solar-panel invoices to trick the US charity into wiring $997,400 to…
A US Attorney's Office (EDVA) court order seized seven domains spoofing the Singapore International Monetary Exchange that pig-butchering scammers used.
A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M.
Impersonators posing as two School District of Philadelphia vendors switched payments to ACH and diverted nearly $700,000 into fraud accounts.
eSentire's Threat Response Unit blocked 10 separate attacks across six unnamed law firms in Jan-Feb 2023, foiling two parallel campaigns.
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
A US Attorney's Office (EDVA) court order seized seven domains spoofing the Singapore International Monetary Exchange that pig-butchering scammers used.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".
A Houston- and California-based ring spoofed business emails to trick five companies and a New Jersey township into wiring over…