1. Executive Summary — The Old ₹5 Note Trap
India Today reported on 10 October 2026 that a 42-year-old farmer in Gujarat allegedly lost ₹1,06,400 after responding to a Facebook/Reels advertisement offering ₹17 lakh for an old ₹5 note. He reportedly sent photographs of two notes to the advertiser through WhatsApp and expected a total payout of ₹34 lakh.
The callers allegedly introduced a parcel-delivery story and asked for an initial ₹750 payment through a QR code. Further demands followed: ₹25,500 on 7 October under a claim that the parcel carrier had been caught, then ₹53,000 on 8 October under another release-related pretext. The report says the victim later contacted Valan police.
2. Reported Timeline — How the Payments Escalated
| When | Reported event | Security interpretation |
|---|---|---|
| About 15 days earlier | The victim reportedly saw an ad in Facebook/Reels offering ₹17 lakh for an old ₹5 note, contacted the number and sent photos of two notes by WhatsApp. | The high-value lure and direct contact move the conversation away from a verifiable marketplace process. |
| 6 October 2026 | A caller allegedly promised a parcel containing ₹34 lakh and requested ₹750 by QR code. | A small first payment tests compliance and creates a sunk-cost commitment. |
| 7 October 2026 | The victim was reportedly told the courier had been caught; ₹25,500 was demanded. | A manufactured emergency is used to justify a larger payment. |
| 8 October 2026 | Another caller allegedly demanded ₹53,000 under a further release-related story. | Changing reasons keep the promised payout just out of reach. |
| After the transfers | The report says total loss reached ₹1,06,400 and the victim approached local police. | Payment records and communications are key evidence for investigators. |
Amount reconciliation note: The three specific amounts listed in the report—₹750, ₹25,500 and ₹53,000—sum to ₹79,250, while the reported total is ₹1,06,400. The article does not itemise the remaining ₹27,150. Transaction records would be needed to account for all transfers; the difference alone does not establish anything beyond that reporting gap.
3. Attack Flow — From High-Value Lure to Repeated Transfers
The supplied research document includes this flow diagram summarising the reported pattern. It is a social-engineering sequence, not a confirmed technical attack chain.

Source: attack-flow figure provided inside the CyberRakshakLabs research DOCX.
The flow shows why a social-media scam can cause financial loss without exploiting a software vulnerability. The attacker’s leverage is the promised payout and the invented obstacles between the victim and that payout.
4. How the Advance-Fee Manipulation Works
1. Extraordinary reward
The offer creates a large expectation around a low-value item before an independent valuation or credible buyer can be checked.
2. Personal engagement
Direct calls and WhatsApp messages make the promise feel specific and conversational.
3. First payment
A small delivery fee can make the process seem plausible and lower resistance to the next request.
4. Moving goalposts
Each new “problem” is presented as the final barrier to receiving the large payout.
The fraud pattern resembles advance-fee scams in which a victim must keep paying purported handling, tax, clearance, courier or release costs to receive money that never arrives. The exact script and all transfers in this individual case must still be established from evidence.
5. What the Evidence Supports — and What Remains Unknown
| Question | Current assessment |
|---|---|
| Was a high-value old-note advertisement reported? | Yes. India Today describes the advertisement and subsequent complaint. |
| Were QR-code and follow-on payments reported? | Yes. The article lists specific demands and reports a total loss of ₹1,06,400. |
| Has the identity of the people behind the calls been established? | Not by the supplied research or the cited report. |
| Is wider identity-data theft confirmed? | No. The victim reportedly sent photos of the notes; broader identity-data theft is not established. |
| Is there a named group, malware, C2 or technical IoC? | No. The source does not establish any such technical infrastructure or attribution. |
| Is the case finally adjudicated? | No such finding is cited here; the report says police began investigating. |
6. Data and Payment Trail — Preserve the Evidence
For investigators and the victim, the most actionable evidence may be ordinary records rather than malware artefacts.
- Preserve the original Facebook/Reels advertisement URL, account/page name, screenshots and the date/time it was seen.
- Keep WhatsApp chat exports, phone numbers, call logs, voice messages and any parcel or courier claims.
- Retain QR-code images, UPI IDs, beneficiary details, bank statements, transaction IDs and payment receipts.
- Build a transfer-by-transfer timeline and compare it against bank/payment-provider records.
- Do not publish full phone numbers, payment details or identity documents while seeking help.
Do not infer broader identity theft just because the victim shared pictures of currency notes. Additional data exposure would need separate evidence.
7. Warning Signs — When to Stop the Conversation
A very large price is promised without a credible buyer or independent assessment.
The seller is asked to pay before receiving the promised proceeds.
Every payment supposedly solves a new courier, tax, clearance or release problem.
Payment is directed to an unfamiliar beneficiary under time pressure.
The payout is always one transfer away, but never arrives.
Calls and urgency leave little time for independent verification.
8. What Victims Should Do in India
- Stop immediately. Do not pay a final “refund”, “tax”, “release” or “recovery” fee.
- Contact the bank or payment provider quickly. Report the transactions and ask whether a hold, recall or other fraud-response action is available.
- Call 1930 promptly for financial cyber fraud and file a report through cybercrime.gov.in. Also contact local police.
- Preserve records. Keep the advertisement, messages, phone numbers, QR code, transaction references and bank confirmations.
- Report the ad/account to the relevant social platform and warn family members about similar offers.
- Beware of recovery scams. Anyone promising guaranteed recovery for an advance fee may be extending the fraud.
9. Prevention for Users, Marketplaces and Payment Services
For users
Verify collectible value with reputable numismatic dealers or recognised associations. Do not transfer money to receive a buyer’s promised payment.
For families
Pause high-value offers and discuss them with a trusted person before sharing information or moving funds.
For social platforms
Review reports of unrealistic currency-buying ads, repeat advertiser behaviour and phone-number reuse; make reporting paths easy to find.
For payment providers
Use appropriate scam-warning, rapid-reporting and transaction-review controls while respecting applicable procedures and evidence requirements.
These are defensive recommendations. The source does not identify the specific platform controls, accounts or payment rails involved in this case beyond the reported social-media ad, WhatsApp contact and QR-based payment.
Assessment: HIGH public-awareness relevance. The reported case illustrates how an implausibly high collectible offer can become an advance-fee payment loop. The strongest defensible framing is a reported Facebook-ad scam under police investigation—not a confirmed malware operation or a technically attributed campaign.
Core takeaway: Never send repeated fees to unlock a promised payout. Stop the payment loop early, contact the bank/payment provider, report promptly and preserve the evidence.
- Primary public report: India Today — “Gujarat man loses Rs 1 lakh in Facebook scam promising Rs 17 lakh for old Rs 5 note” (10 October 2026). Report attributes the incident details to a police complaint and says police began investigating.
- Supplied source: CyberRakshakLabs DOCX, “The Old ₹5 Note Trap: Facebook Marketplace Extortion Scam,” dated 11 October 2026, including the attack-flow figure.
- Evidence boundary: Reported allegations are attributed to the public source. No independent access to police records, payment data or original platform logs is claimed in this article.
The promised payout is the bait. The “last fee” is the trap.
Think Before You Click. Stay Aware. Stay Secure.
CyberRakshakLabs — Threat Intelligence for a Safer Tomorrow.