CYBERRAKSHAK LABS · RESEARCH #058

🚨 The Old ₹5 Note Trap: How a Facebook Ad Led to a ₹1.06 Lakh Scam

A reported offer of ₹17 lakh for an old ₹5 note allegedly drew a Gujarat farmer into a three-day advance-fee scam. The cited report says he lost ₹1,06,400 after repeated demands framed as parcel and release-related costs.

By Vivek Kumar · Published 11 October 2026
RESEARCH#058
CATEGORYCyber Fraud / Social Engineering / Advance-Fee Fraud
CRL ASSESSMENTHIGH
RESEARCH LEVELDeep Research
PUBLISHED2026-10-11
Source & social links:
LinkedIn Post ↗WhatsApp ↗YouTube ↗
How CyberRakshakLabs researches threats →
A ₹5 note became the opening hook. A ₹750 QR payment became the first commitment. Then the story changed—and the demands grew. The reported lesson is simple: a promised payout should never require repeated advance payments to unlock it.
₹17LPromised for one old ₹5 note, according to the report
₹1,06,400Total loss reported by India Today
3 daysReported period of escalating payment demands
Evidence boundary: This analysis is based on public reporting of a police complaint, not a completed court finding or direct forensic examination. The report says police began investigating. No named threat actor, malware, malicious domain, IP address or technical intrusion method is established by the supplied material.
1. Executive Summary — The Old ₹5 Note Trap

India Today reported on 10 October 2026 that a 42-year-old farmer in Gujarat allegedly lost ₹1,06,400 after responding to a Facebook/Reels advertisement offering ₹17 lakh for an old ₹5 note. He reportedly sent photographs of two notes to the advertiser through WhatsApp and expected a total payout of ₹34 lakh.

The callers allegedly introduced a parcel-delivery story and asked for an initial ₹750 payment through a QR code. Further demands followed: ₹25,500 on 7 October under a claim that the parcel carrier had been caught, then ₹53,000 on 8 October under another release-related pretext. The report says the victim later contacted Valan police.

Defensive headline: An unusually large promised payment plus an upfront fee is a warning sign—not proof of a legitimate buyer. Do not pay to unlock a prize, sale price or payout.
2. Reported Timeline — How the Payments Escalated
WhenReported eventSecurity interpretation
About 15 days earlierThe victim reportedly saw an ad in Facebook/Reels offering ₹17 lakh for an old ₹5 note, contacted the number and sent photos of two notes by WhatsApp.The high-value lure and direct contact move the conversation away from a verifiable marketplace process.
6 October 2026A caller allegedly promised a parcel containing ₹34 lakh and requested ₹750 by QR code.A small first payment tests compliance and creates a sunk-cost commitment.
7 October 2026The victim was reportedly told the courier had been caught; ₹25,500 was demanded.A manufactured emergency is used to justify a larger payment.
8 October 2026Another caller allegedly demanded ₹53,000 under a further release-related story.Changing reasons keep the promised payout just out of reach.
After the transfersThe report says total loss reached ₹1,06,400 and the victim approached local police.Payment records and communications are key evidence for investigators.

Amount reconciliation note: The three specific amounts listed in the report—₹750, ₹25,500 and ₹53,000—sum to ₹79,250, while the reported total is ₹1,06,400. The article does not itemise the remaining ₹27,150. Transaction records would be needed to account for all transfers; the difference alone does not establish anything beyond that reporting gap.

3. Attack Flow — From High-Value Lure to Repeated Transfers

The supplied research document includes this flow diagram summarising the reported pattern. It is a social-engineering sequence, not a confirmed technical attack chain.

Attack flow: high-value old five-rupee note offer, victim engagement and note photos, fake collection story, small QR fee, escalating demands, repeated transfers, victim report, and containment and evidence preservation

Source: attack-flow figure provided inside the CyberRakshakLabs research DOCX.

The flow shows why a social-media scam can cause financial loss without exploiting a software vulnerability. The attacker’s leverage is the promised payout and the invented obstacles between the victim and that payout.

4. How the Advance-Fee Manipulation Works

1. Extraordinary reward

The offer creates a large expectation around a low-value item before an independent valuation or credible buyer can be checked.

2. Personal engagement

Direct calls and WhatsApp messages make the promise feel specific and conversational.

3. First payment

A small delivery fee can make the process seem plausible and lower resistance to the next request.

4. Moving goalposts

Each new “problem” is presented as the final barrier to receiving the large payout.

The fraud pattern resembles advance-fee scams in which a victim must keep paying purported handling, tax, clearance, courier or release costs to receive money that never arrives. The exact script and all transfers in this individual case must still be established from evidence.

5. What the Evidence Supports — and What Remains Unknown
QuestionCurrent assessment
Was a high-value old-note advertisement reported?Yes. India Today describes the advertisement and subsequent complaint.
Were QR-code and follow-on payments reported?Yes. The article lists specific demands and reports a total loss of ₹1,06,400.
Has the identity of the people behind the calls been established?Not by the supplied research or the cited report.
Is wider identity-data theft confirmed?No. The victim reportedly sent photos of the notes; broader identity-data theft is not established.
Is there a named group, malware, C2 or technical IoC?No. The source does not establish any such technical infrastructure or attribution.
Is the case finally adjudicated?No such finding is cited here; the report says police began investigating.
6. Data and Payment Trail — Preserve the Evidence

For investigators and the victim, the most actionable evidence may be ordinary records rather than malware artefacts.

  • Preserve the original Facebook/Reels advertisement URL, account/page name, screenshots and the date/time it was seen.
  • Keep WhatsApp chat exports, phone numbers, call logs, voice messages and any parcel or courier claims.
  • Retain QR-code images, UPI IDs, beneficiary details, bank statements, transaction IDs and payment receipts.
  • Build a transfer-by-transfer timeline and compare it against bank/payment-provider records.
  • Do not publish full phone numbers, payment details or identity documents while seeking help.

Do not infer broader identity theft just because the victim shared pictures of currency notes. Additional data exposure would need separate evidence.

7. Warning Signs — When to Stop the Conversation
Unrealistic valuation
A very large price is promised without a credible buyer or independent assessment.
Upfront fee
The seller is asked to pay before receiving the promised proceeds.
Ever-changing emergency
Every payment supposedly solves a new courier, tax, clearance or release problem.
Unverified QR or account
Payment is directed to an unfamiliar beneficiary under time pressure.
Moving finish line
The payout is always one transfer away, but never arrives.
Pressure to stay engaged
Calls and urgency leave little time for independent verification.
Simple rule: A legitimate buyer pays the seller. A stranger asking you to keep paying to release your own promised payment is a major warning sign.
8. What Victims Should Do in India
STOP PAYMENTS→CONTACT BANK→REPORT→PRESERVE EVIDENCE
  • Stop immediately. Do not pay a final “refund”, “tax”, “release” or “recovery” fee.
  • Contact the bank or payment provider quickly. Report the transactions and ask whether a hold, recall or other fraud-response action is available.
  • Call 1930 promptly for financial cyber fraud and file a report through cybercrime.gov.in. Also contact local police.
  • Preserve records. Keep the advertisement, messages, phone numbers, QR code, transaction references and bank confirmations.
  • Report the ad/account to the relevant social platform and warn family members about similar offers.
  • Beware of recovery scams. Anyone promising guaranteed recovery for an advance fee may be extending the fraud.
9. Prevention for Users, Marketplaces and Payment Services

For users

Verify collectible value with reputable numismatic dealers or recognised associations. Do not transfer money to receive a buyer’s promised payment.

For families

Pause high-value offers and discuss them with a trusted person before sharing information or moving funds.

For social platforms

Review reports of unrealistic currency-buying ads, repeat advertiser behaviour and phone-number reuse; make reporting paths easy to find.

For payment providers

Use appropriate scam-warning, rapid-reporting and transaction-review controls while respecting applicable procedures and evidence requirements.

These are defensive recommendations. The source does not identify the specific platform controls, accounts or payment rails involved in this case beyond the reported social-media ad, WhatsApp contact and QR-based payment.

CyberRakshakLabs Assessment

Assessment: HIGH public-awareness relevance. The reported case illustrates how an implausibly high collectible offer can become an advance-fee payment loop. The strongest defensible framing is a reported Facebook-ad scam under police investigation—not a confirmed malware operation or a technically attributed campaign.

Core takeaway: Never send repeated fees to unlock a promised payout. Stop the payment loop early, contact the bank/payment provider, report promptly and preserve the evidence.

Sources & Verification Notes

The promised payout is the bait. The “last fee” is the trap.

Think Before You Click. Stay Aware. Stay Secure.

CyberRakshakLabs — Threat Intelligence for a Safer Tomorrow.