How Cybercriminals Allegedly Used a Company’s GSTIN to Show ₹9.32 Crore in Fake Transactions
Learn how cybercriminals allegedly misused a company’s GSTIN to show ₹9.32 crore in fake transactions and how businesses can prevent GST identity theft.

Imagine checking your company’s GST account one morning and discovering that your business has apparently done ₹9.32 crore worth of transactions you never made.
That is reportedly what happened to a private company in Gorakhpur.
According to a complaint filed by the company’s director, unidentified cybercriminals allegedly gained unauthorized access to the company’s GST portal, changed its registered mobile number and email address, and used its GSTIN to generate fraudulent invoices.
The company says it had nothing to do with these transactions.
The incident has raised an important question for businesses across India:
Can your GST identity be stolen and misused just like your email or bank account?
The answer is yes and the consequences can be serious.
A ₹9.32 Crore Surprise on the GST Portal
Sanjeev Kumar Jaiswal, director of HiVerner Private Limited, reportedly discovered something was wrong after the company’s GST account was accessed without authorization.
According to his complaint, the attackers allegedly changed the mobile number and email address linked to the GST account. This meant the company could no longer receive the usual notifications and alerts connected to its account.
The alleged unauthorized activity reportedly took place on May 3, 2026, when fraudulent billing was generated using the company’s GST credentials.
The problem came to light after the registered mobile number was changed again on May 13.
When Jaiswal checked the GST portal, he reportedly found transactions that the company had never created.
The total turnover reflected against the company’s GSTIN was approximately:
₹9,32,08,966
There was just one problem.
The company says it never made those sales.
According to the complaint, HiVerner Private Limited did not issue the invoices, did not provide the goods or services mentioned in them and did not receive payments related to the transactions.
So how did these transactions appear under its GST identity?
That is now a key question for investigators.
What Is GST Identity Theft?
GST identity theft occurs when cybercriminals gain unauthorized access to a company's GSTIN, GST portal account, registered email, mobile number or other tax-related credentials and use them for fraudulent activities.
Think of it this way.
Your GSTIN is part of your company's digital identity. If someone gets unauthorized control over the account associated with it, they may be able to misuse that identity to create transactions that appear to come from your business.
This can potentially involve:
Fake GST invoices
Fictitious sales and purchases
Fraudulent transactions
Misuse of Input Tax Credit (ITC)
Unauthorized changes to GST account details
Impersonation of a legitimate business
And the company whose GSTIN is being misused may not immediately know what is happening.
That is what makes GST identity theft particularly dangerous.
Why Fake GST Invoices Are a Serious Problem
At first glance, a fake invoice may look like a simple accounting issue.
It isn't.
Fraudulent invoices can potentially be used by other businesses to claim Input Tax Credit (ITC) on transactions that never actually happened.
If the alleged invoices in this case were used by other entities to claim ITC, the investigation could extend far beyond the company whose GST account was compromised.
Authorities may need to determine:
Who created the invoices?
Who accessed the GST account?
Which entities received the invoices?
Was ITC claimed using them?
Were any payments made?
Where did the financial benefit go?
Were other GSTINs involved?
This is why a compromised GST account could potentially be just one piece of a much larger fake invoice network.
How Could Cybercriminals Access a GST Account?
The exact method used in the Gorakhpur case will need to be established through investigation.
But in general, attackers can target the credentials and systems surrounding an online account rather than attacking the government portal itself.
Common entry points can include:
Phishing:
An employee receives a convincing email or message designed to steal login credentials.
Compromised email accounts:
If an attacker controls the email connected to a business account, they may be able to intercept important notifications or account-related information.
Weak or reused passwords:
Using the same password across multiple platforms can allow one compromised account to become a gateway to others.
Social engineering:
Attackers may manipulate employees into revealing confidential information or approving unauthorized actions.
Compromised devices:
Malware on a laptop or phone can potentially expose credentials and sensitive information.
This is why protecting a GST account is not simply about protecting one password.
It is about protecting the entire digital environment around it.
The Warning Sign Businesses Shouldn't Ignore
One detail in this case stands out: the alleged change to the company's registered mobile number and email address.
Changes to account recovery details may seem like routine administrative activity.
But for a business, an unexpected change to a registered email address, phone number or other critical account setting should immediately raise a red flag.
If notifications suddenly stop arriving, login behaviour looks unusual or account information changes without authorization, businesses should investigate immediately.
Silence from a critical business account isn't always a good sign.
Sometimes, it can mean someone else has taken control.
Gorakhpur Has Seen Other Cybercrime Incidents Too
The GST identity theft case isn't the only cybercrime incident reported in Gorakhpur.
In another case, the servers of Rayraika Marketing and Gauri Trading were reportedly hacked on June 1, 2025.
According to the complaint in that case, cybercriminals allegedly demanded a large cryptocurrency ransom and threatened to destroy the companies' servers if the ransom was not paid.
The attack reportedly disrupted business operations for two days.
Cyber police registered a case and began an investigation.
Together, incidents like these highlight how businesses can face very different types of cyber threats from ransomware attacks that disrupt operations to identity-based attacks that quietly misuse business credentials.
How Businesses Can Prevent GST Identity Theft
You don't need to wait for suspicious invoices to appear before taking action.
A few cybersecurity practices can significantly reduce the risk.
1. Protect GST Login Credentials
Use strong, unique passwords and avoid sharing credentials through WhatsApp, email or unsecured documents.
2. Secure the Registered Email and Mobile Number
Your GST account is only as secure as the accounts connected to it. Protect the email addresses and mobile numbers used for authentication and notifications.
3. Enable Multi-Factor Authentication
Where available, use multi-factor authentication (MFA) to add another layer of protection beyond passwords.
4. Monitor GST Activity Regularly
Don't check your GST account only when filing returns.
Regularly review invoices, filings, account details and other activity for anything unusual.
5. Restrict Access
Not every employee needs access to tax and financial systems. Limit access to authorized personnel and review permissions regularly.
6. Train Employees to Spot Phishing
A single convincing phishing message can become the starting point for a much larger attack.
Employees should know how to identify suspicious links, fake login pages and unusual requests for credentials.
7. Investigate Unexpected Changes Immediately
If the registered email, mobile number or other account information changes without authorization, treat it as a potential security incident.
The faster you respond, the easier it may be to limit the damage.
What Should You Do If Your GST Account Is Compromised?
If you discover unauthorized GST activity, don't ignore it or assume it will resolve itself.
Start by securing the compromised account and associated email and mobile credentials.
Then document everything you find including suspicious invoices, account changes, notifications and transaction details.
You should also report the incident to the appropriate authorities and seek professional cybersecurity assistance to determine how the compromise happened and whether other systems or accounts were affected.
A proper investigation can help answer the most important question:
Did the attacker compromise only the GST account, or was the wider business network also exposed?
The Bigger Cybersecurity Lesson
The Gorakhpur GST fraud case is a reminder that cybercriminals don't always want to steal money directly.
Sometimes, they want to steal trust.
A legitimate GSTIN can make fraudulent transactions appear connected to a real business. A compromised email account can make a fake request look genuine. A stolen login can give attackers access to systems that employees trust every day.
That's why cybersecurity today is about more than protecting computers.
It's about protecting your digital identity, business reputation, financial records and customer trust.
And the most dangerous attacks aren't always the ones that make noise.
Sometimes, they quietly sit inside your systems until someone finally notices something doesn't add up.
Don't Wait for ₹9.32 Crore to Tell You There's a Problem
The alleged misuse of a company's GSTIN shows how quickly a compromised digital account can turn into a major business and compliance concern.
But you don't have to wait for suspicious transactions, fake invoices or a data breach to discover your weaknesses.
WhiteKnight helps businesses identify security gaps before cybercriminals can exploit them.
With proactive security assessments and cybersecurity expertise, WhiteKnight can help you understand where your business may be vulnerable and strengthen your security posture before an incident occurs.
Because cybersecurity isn't just about responding after something goes wrong.
It's about finding the weakness before the attacker does.
Protect your digital identity. Strengthen your security. Stay ahead with WhiteKnight.
Cyber fraud is evolving fast, making digital awareness more important than ever. For more on how scammers use WhatsApp to spread malware, check out “WhatsApp Malware Scam in India: How to Stay Safe.”


