Case Library / Vishing (Voice Phishing) / India-Based IRS/USCIS Impersonation Call-Center Takedown (U.S. v. HGlobal et al., 61 Defendants)

India-Based IRS/USCIS Impersonation Call-Center Takedown (U.S. v. HGlobal et al., 61 Defendants)

DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad, India call-center conglomerates for a 2012-2016 IRS/USCIS impersonation vishing scheme that threatened over 15,000 U.S. victims with arrest or deportation to extort payment via prepaid cards and wires.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

On October 19, 2016, a federal grand jury in the Southern District of Texas returned a superseding indictment (unsealed October 27, 2016) charging 61 defendants and entities - 24 U.S.-based individuals, 32 India-based individuals, and 5 India-based call-center conglomerates - with conspiracy, wire fraud, money laundering, false personation of a U.S. federal officer, and identity theft. The conglomerates, all based in Ahmedabad, Gujarat, ran a "telefraud" scheme in which callers impersonated IRS and USCIS officials, threatened victims across the U.S. with arrest, fines, or deportation, and directed them to pay via prepaid cards or wire transfers, which a U.S.-based network of "runners" then laundered using stolen identities. DHS-OIG, ICE Homeland Security Investigations, and TIGTA led the investigation; DOJ called it a "first-of-its-kind" nationwide takedown, arresting 20 U.S. defendants the day the indictment was unsealed and seeking extradition of dozens of India-based defendants. Between 2017 and 2020, 24 U.S.-based defendants pleaded guilty and were sentenced (up to 20 years), and HGlobal's India-based owner Hitesh Madhubhai Patel, who had fled to Singapore, was extradited from Singapore in April 2019, pleaded guilty, and was sentenced in November 2020 to 20 years plus nearly $9 million in restitution.

How the Attack Worked

Five Ahmedabad, Gujarat call-center conglomerates (HGlobal; Call Mantra, d/b/a Robust Inc./Raytheon International; Worldwide Solution; Zoriion Communications Pvt. Ltd.; Sharma BPO Services) bought victim contact lists and personal identifying information from data brokers, then had agents place spoofed calls into the U.S. impersonating IRS agents (claiming back taxes owed) or USCIS/immigration officers (claiming faulty paperwork). Scripts threatened immediate arrest, imprisonment, fines, or deportation unless the victim paid on the spot. Compliant victims were walked through purchasing general-purpose reloadable (GPR)/prepaid stored-value cards (including iTunes and Reloadit-type cards) at retail stores and reading the card numbers over the phone, or wiring funds via MoneyGram/Western Union, or sending money orders/bank deposits. As soon as a victim paid, the call centers routed the funds to a parallel network of U.S.-based "runners" (crews in Illinois, Arizona, Texas, Alabama, and elsewhere) who immediately registered fresh prepaid cards using stolen PII from thousands of separate identity-theft victims, then converted the loaded cards into money orders deposited into bank accounts, or picked up wires under false names using fraudulent IDs, laundering the money before banks or victims could reverse the transaction. The five conglomerates cooperated with each other, sharing scripts, victim lead lists, and payment-processing infrastructure. The conspiracy ran from on or about January 2012/2013 through the October 2016 indictment.

The Lure & the Tell

Lure: an incoming call from a spoofed number that appeared to be from the IRS or a federal immigration call center, with a caller claiming to be a federal officer who cited the victim's real personal details (from purchased data-broker lead lists) and asserted the victim owed unpaid back taxes or had defective immigration paperwork. Tell: the U.S. government never initiates enforcement contact by phone with threats of immediate arrest/deportation, never demands payment via prepaid gift cards (iTunes, Reloadit, etc.) read over the phone, and never demands a single wire transfer or money order to resolve a "debt" under threat of same-day arrest; the artificial urgency and card-payment channel were the signature (and now widely publicized) tells of the scam.

Outcome

61 defendants/entities were charged in the Oct. 19, 2016 superseding indictment (unsealed Oct. 27, 2016): 24 U.S.-based individuals plus 32 India-based individuals and the 5 India-based call-center conglomerates. 20 U.S. defendants were arrested the day the indictment was unsealed. Over the following years, 24 U.S.-based defendants pleaded guilty and were sentenced in SDTX (plus one each in the District of Arizona and Northern District of Georgia) to terms ranging from probation up to 20 years; among the harshest: Miteshkumar Patel (runner-crew manager) 240 months, Viraj Patel 165 months, Rajubhai Patel 151 months, Sunny Joshi 151 months, Hardik Patel (India-based call-center co-owner/manager who later moved to the U.S.) 188 months, Rajesh Bhatt 145 months, Bhavesh Patel 121 months. Many U.S. defendants also faced deportation to India upon completing their sentences. Separately, HGlobal's India-based owner/funder Hitesh Madhubhai Patel (a.k.a. Hitesh Hinglaj) fled India for Singapore in 2018, was apprehended there by Singaporean authorities on a U.S. provisional arrest warrant on Sept. 21, 2018, and was extradited from Singapore (not India) to the U.S. on April 18, 2019; he pleaded guilty in Jan. 2020 and was sentenced Nov. 30, 2020 to 20 years in prison plus $8,970,396 restitution, the highest-profile India-based conviction to date. Charges remained pending against numerous other India-based defendants who were not extradited as of the last public updates in this research.

Why It Matters

This remains one of the largest and most thoroughly documented vishing/government-impersonation prosecutions in U.S. history and a template for how such scams are dismantled: it shows the full anatomy of a transnational telefraud operation (offshore call centers, data-broker-sourced victim lists, live scripted authority-impersonation calls, and a domestic runner network for near-instant laundering via prepaid cards and wires) and demonstrates that even offshore-based conspirators can face extradition and lengthy U.S. sentences. It is also a clear case study in the gap between headline-grabbing charging-document loss figures ("hundreds of millions," "$300M+") and lower, independently tracked regulator figures (TIGTA's ~$60-73M), a distinction useful for teaching how to read fraud-loss claims critically. The scam's core mechanics (spoofed caller ID, IRS/immigration threats, demand for gift-card/wire payment) remain the exact pattern still used in ongoing IRS-impersonation and government-impersonation vishing scams today.

Defenses

DOJ/DHS-OIG/HSI/TIGTA/IRS-CI joint multi-year investigation and coordinated nationwide arrest operation; extradition requests to India for numerous India-based defendants (separate from Hitesh Madhubhai Patel's Singapore extradition, see outcome); public-awareness messaging at the announcement press conference ("if you get this call, do not pay, it is not the U.S. government calling you"); TIGTA and IRS ongoing consumer-facing warnings about IRS-impersonation phone scams (IRS never initiates contact by threatening phone call demanding immediate payment via gift/prepaid cards or wire transfer); FTC/consumer guidance to hang up, verify independently via official agency phone numbers, and never pay government debts with gift cards or wires; card issuers and MoneyGram/Western Union AML-suspicious-activity monitoring cited by investigators as part of how the money trail was traced.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and victim-list acquisition: per the DOJ indictment and defendants' own plea admissions, the Ahmedabad call-center conglomerates bought victim contact lists and personal identifying information (PII) from commercial data brokers and other sources, giving callers real names, addresses, and other personal details to cite on the call and sound authoritative.
Countering Stage 1: consumer exposure to data-broker lead lists is very hard for an individual to control at the source; the realistic control is downstream, teaching that a caller knowing your name or address is not proof of legitimacy, rather than trying to eliminate the lead-list market itself.
2
Telephony infrastructure and caller-ID spoofing setup: call centers used commercial telephony/VOIP infrastructure and caller-ID spoofing so calls appeared to originate from legitimate U.S. government numbers, consistent with the spoofing pattern TIGTA documented across IRS-impersonation scams of this era generally.
Countering Stage 2: telecom carriers' caller-ID authentication frameworks (e.g. STIR/SHAKEN-style call-authentication standards) and consumer call-blocking/scam-labeling apps target spoofed-number delivery directly, and are the nearest practical control since the spoofing technique itself sits largely outside any individual victim's reach.
3
Scripted authority-impersonation contact: agents, following prepared call scripts (per indictment and plea admissions), placed calls impersonating IRS agents (claiming back taxes owed) or USCIS/immigration officers (claiming defective paperwork), often opening with the victim's real personal details from the purchased lead lists to establish false credibility.
Countering Stage 3: the public-awareness messaging DOJ, TIGTA, and IRS repeated at and after the takedown, that the U.S. government does not initiate enforcement contact by unsolicited phone call, is the direct countermeasure; hanging up and calling the agency back on its official published number, rather than trusting the inbound caller, neutralizes this stage.
4
Threat-based pretext and urgency escalation: scripts threatened immediate arrest, imprisonment, fines, or deportation unless the victim paid before the call ended, a documented pattern across the indictment and TIGTA's consumer warnings, designed to prevent the victim from pausing to verify independently.
Countering Stage 4: recognizing "pay immediately or be arrested" as a scam hallmark (per TIGTA/FTC guidance) and simply ending the call to verify independently breaks the artificial time pressure this stage depends on to prevent victims from thinking it through.
5
Payment-channel instruction and extraction: compliant victims were walked through purchasing GPR/prepaid stored-value cards (including iTunes and Reloadit-type cards) and reading the card numbers over the phone, or wiring funds via MoneyGram/Western Union, or sending money orders/bank deposits.
Countering Stage 5: the single most emphasized public warning in TIGTA/FTC materials, that no legitimate government agency demands payment via prepaid gift cards or a one-time wire transfer, targets this exact stage; several retailers have since added point-of-sale warnings when customers buy large amounts of gift cards for this reason.
6
Rapid laundering via runner network and stolen-identity card registration: upon payment, call centers routed funds same-day to a U.S.-based runner network, who immediately registered fresh prepaid cards using stolen PII from separate identity-theft victims, then converted the loaded cards into money orders deposited into bank accounts or picked up wires under false identities, moving the money before it could be traced or reversed.
Countering Stage 6: this stage is largely invisible to the original victim and hardest to interdict in real time; the realistic control sits with card issuers' and MoneyGram/Western Union's anti-money-laundering and suspicious-activity monitoring, which investigators credited with helping trace the money trail after the fact.
7
Profit distribution and network sustainment (objective completion): laundered proceeds were split between the India-based call-center operators and the U.S.-based runner crews (who kept a fee or percentage per transaction), funding continued operations that scaled the scheme to over 15,000 direct victims across a roughly four-year run before the 2016 takedown.
Countering Stage 7: no consumer-facing control reaches this final stage; the terminal countermeasure is the coordinated multi-agency (DHS-OIG/ICE-HSI/TIGTA/DOJ) financial and telecom-record investigation and prosecution that ultimately identified, charged, and dismantled the network, since sustained laundering requires the conspiracy to keep operating undetected.
Quick Facts
Victim
Approximately 15,000+ U.S. residents deceived into paying the scam directly (elderly and immigrant populations disproportionately targeted), plus tens of thousands of separate identity-theft victims whose stolen PII was used to register the laundering prepaid cards
Location
Call centers in Ahmedabad, Gujarat, India; U.S. runner networks in Illinois, Arizona, Texas, Alabama, Georgia, California, Florida, New Jersey, Indiana; prosecuted in U.S. District Court, Southern District of Texas (Houston Division), with related sentencings in the District of Arizona and Northern District of Georgia
Date
2016-10-19 (grand jury returns superseding indictment; unsealed 2016-10-27); underlying scheme ran 2012/2013-2016; sentencings 2018-01-29 through 2020-11-30
Impact
DOJ's Oct. 2016 indictment alleged "hundreds of millions of dollars" in losses (a Fox News/press-conference figure cited $300M+) and over 15,000 known U.S. victims with upwards of 50,000 identities misappropriated to register prepaid cards - these are charging-document allegations, not judicially confirmed loss findings. (One outlier: NBC News' Oct. 2016 story cited a lower "$50 million" estimate from the same press conference, versus the "$300M+"/"hundreds of millions" figure reported by AP, Fox News, USA Today, CNN, Boston Globe, and ICE's own release.) TIGTA's own tracked/reported-victim figures were substantially lower and grew over time: ~12,027 victims reporting >$60.7M in losses as of Sept. 30, 2017, rising to more than 14,700 taxpayers reporting upwards of $72.8M as of TIGTA's Sept. 30, 2018 reporting period (figure independently corroborated by the U.S. Senate Special Committee on Aging's "Fighting Fraud" report). Individual defendants were held accountable at sentencing for specific laundered-funds ranges, e.g. Miteshkumar Patel for $9.5-25M, Hardik Patel for $3.5-9.5M, Sunny Joshi/Rajesh Bhatt (Call Mantra runners) for up to ~$9.5M; Hitesh Madhubhai Patel (HGlobal owner) was ordered to pay $8,970,396 in restitution at his 2020 sentencing.
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Financial Services & Insurance, Government & Public Sector
Threat Actor
Organized Crime
Related

Related Cases

Snapchat W-2 Payroll Phishing Breach (2016)

A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…

Incident 2016Read →

Leoni AG CEO Fraud (2016)

Fraudsters impersonating Leoni AG's senior executives tricked the German cable manufacturer's Romanian subsidiary finance team into wiring roughly EUR 40…

Incident 2016Read →

NatWest "Vishing" Callback Fraud Costs Surrey Solicitor Karen Mackie £734,000 and Her Career

Posing as NatWest bank security, vishing criminals exploited a landline callback delay to convince Surrey solicitor Karen Mackie to wire…

Incident 2015Read →