DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad, India call-center conglomerates for a 2012-2016 IRS/USCIS impersonation vishing scheme that threatened over 15,000 U.S. victims with arrest or deportation to extort payment via prepaid cards and wires.
Reviewed by the Social Engineering Examples team.
On October 19, 2016, a federal grand jury in the Southern District of Texas returned a superseding indictment (unsealed October 27, 2016) charging 61 defendants and entities - 24 U.S.-based individuals, 32 India-based individuals, and 5 India-based call-center conglomerates - with conspiracy, wire fraud, money laundering, false personation of a U.S. federal officer, and identity theft. The conglomerates, all based in Ahmedabad, Gujarat, ran a "telefraud" scheme in which callers impersonated IRS and USCIS officials, threatened victims across the U.S. with arrest, fines, or deportation, and directed them to pay via prepaid cards or wire transfers, which a U.S.-based network of "runners" then laundered using stolen identities. DHS-OIG, ICE Homeland Security Investigations, and TIGTA led the investigation; DOJ called it a "first-of-its-kind" nationwide takedown, arresting 20 U.S. defendants the day the indictment was unsealed and seeking extradition of dozens of India-based defendants. Between 2017 and 2020, 24 U.S.-based defendants pleaded guilty and were sentenced (up to 20 years), and HGlobal's India-based owner Hitesh Madhubhai Patel, who had fled to Singapore, was extradited from Singapore in April 2019, pleaded guilty, and was sentenced in November 2020 to 20 years plus nearly $9 million in restitution.
Five Ahmedabad, Gujarat call-center conglomerates (HGlobal; Call Mantra, d/b/a Robust Inc./Raytheon International; Worldwide Solution; Zoriion Communications Pvt. Ltd.; Sharma BPO Services) bought victim contact lists and personal identifying information from data brokers, then had agents place spoofed calls into the U.S. impersonating IRS agents (claiming back taxes owed) or USCIS/immigration officers (claiming faulty paperwork). Scripts threatened immediate arrest, imprisonment, fines, or deportation unless the victim paid on the spot. Compliant victims were walked through purchasing general-purpose reloadable (GPR)/prepaid stored-value cards (including iTunes and Reloadit-type cards) at retail stores and reading the card numbers over the phone, or wiring funds via MoneyGram/Western Union, or sending money orders/bank deposits. As soon as a victim paid, the call centers routed the funds to a parallel network of U.S.-based "runners" (crews in Illinois, Arizona, Texas, Alabama, and elsewhere) who immediately registered fresh prepaid cards using stolen PII from thousands of separate identity-theft victims, then converted the loaded cards into money orders deposited into bank accounts, or picked up wires under false names using fraudulent IDs, laundering the money before banks or victims could reverse the transaction. The five conglomerates cooperated with each other, sharing scripts, victim lead lists, and payment-processing infrastructure. The conspiracy ran from on or about January 2012/2013 through the October 2016 indictment.
Lure: an incoming call from a spoofed number that appeared to be from the IRS or a federal immigration call center, with a caller claiming to be a federal officer who cited the victim's real personal details (from purchased data-broker lead lists) and asserted the victim owed unpaid back taxes or had defective immigration paperwork. Tell: the U.S. government never initiates enforcement contact by phone with threats of immediate arrest/deportation, never demands payment via prepaid gift cards (iTunes, Reloadit, etc.) read over the phone, and never demands a single wire transfer or money order to resolve a "debt" under threat of same-day arrest; the artificial urgency and card-payment channel were the signature (and now widely publicized) tells of the scam.
61 defendants/entities were charged in the Oct. 19, 2016 superseding indictment (unsealed Oct. 27, 2016): 24 U.S.-based individuals plus 32 India-based individuals and the 5 India-based call-center conglomerates. 20 U.S. defendants were arrested the day the indictment was unsealed. Over the following years, 24 U.S.-based defendants pleaded guilty and were sentenced in SDTX (plus one each in the District of Arizona and Northern District of Georgia) to terms ranging from probation up to 20 years; among the harshest: Miteshkumar Patel (runner-crew manager) 240 months, Viraj Patel 165 months, Rajubhai Patel 151 months, Sunny Joshi 151 months, Hardik Patel (India-based call-center co-owner/manager who later moved to the U.S.) 188 months, Rajesh Bhatt 145 months, Bhavesh Patel 121 months. Many U.S. defendants also faced deportation to India upon completing their sentences. Separately, HGlobal's India-based owner/funder Hitesh Madhubhai Patel (a.k.a. Hitesh Hinglaj) fled India for Singapore in 2018, was apprehended there by Singaporean authorities on a U.S. provisional arrest warrant on Sept. 21, 2018, and was extradited from Singapore (not India) to the U.S. on April 18, 2019; he pleaded guilty in Jan. 2020 and was sentenced Nov. 30, 2020 to 20 years in prison plus $8,970,396 restitution, the highest-profile India-based conviction to date. Charges remained pending against numerous other India-based defendants who were not extradited as of the last public updates in this research.
This remains one of the largest and most thoroughly documented vishing/government-impersonation prosecutions in U.S. history and a template for how such scams are dismantled: it shows the full anatomy of a transnational telefraud operation (offshore call centers, data-broker-sourced victim lists, live scripted authority-impersonation calls, and a domestic runner network for near-instant laundering via prepaid cards and wires) and demonstrates that even offshore-based conspirators can face extradition and lengthy U.S. sentences. It is also a clear case study in the gap between headline-grabbing charging-document loss figures ("hundreds of millions," "$300M+") and lower, independently tracked regulator figures (TIGTA's ~$60-73M), a distinction useful for teaching how to read fraud-loss claims critically. The scam's core mechanics (spoofed caller ID, IRS/immigration threats, demand for gift-card/wire payment) remain the exact pattern still used in ongoing IRS-impersonation and government-impersonation vishing scams today.
DOJ/DHS-OIG/HSI/TIGTA/IRS-CI joint multi-year investigation and coordinated nationwide arrest operation; extradition requests to India for numerous India-based defendants (separate from Hitesh Madhubhai Patel's Singapore extradition, see outcome); public-awareness messaging at the announcement press conference ("if you get this call, do not pay, it is not the U.S. government calling you"); TIGTA and IRS ongoing consumer-facing warnings about IRS-impersonation phone scams (IRS never initiates contact by threatening phone call demanding immediate payment via gift/prepaid cards or wire transfer); FTC/consumer guidance to hang up, verify independently via official agency phone numbers, and never pay government debts with gift cards or wires; card issuers and MoneyGram/Western Union AML-suspicious-activity monitoring cited by investigators as part of how the money trail was traced.
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
Fraudsters impersonating Leoni AG's senior executives tricked the German cable manufacturer's Romanian subsidiary finance team into wiring roughly EUR 40…
Posing as NatWest bank security, vishing criminals exploited a landline callback delay to convince Surrey solicitor Karen Mackie to wire…