Technologyadmin7/25/2025
Bengaluru, July 25, 2025 — CloudSEK has exposed a well-organized counterfeit currency network flourishing openly on social media platforms. In a first-of-its-kind investigation, CloudSEK’s STRIKE team has not only quantified the spread—₹17.5 crore worth of fake Indian currency in just six months—but also attributed key individuals behind the operation using facial recognition, GPS data, and digital forensics.
What was once confined to the dark web and underground print shops has now emerged in broad daylight—on Facebook and Instagram. CloudSEK’s XVigil platform was the key enabler in detecting, correlating, and mapping the full threat landscape. By configuring watchwords like “second series” or “A1 notes,” the platform monitored open-source environments and flagged:
These campaigns utilized codewords like “second currency” and “A1 note” and ran paid promotions through Meta Ads, openly soliciting buyers. Some sellers even demonstrated the legitimacy of their counterfeit products using videos, handwritten notes, and video calls—creating a dangerously trust-based black market in plain sight.
Using advanced Open Source Intelligence (OSINT) and Human Intelligence (HUMINT) techniques powered by CloudSEK’s proprietary platform XVigil, the researchers were able to:
“This is the first time that a cyber investigation has offered such precise attribution of counterfeit actors operating in public digital spaces. We didn’t just find content—we identified the key perpetrators,” said Sourajeet Majumder, security researcher at CloudSEK
The report highlights a sophisticated yet surprisingly open modus operandi:
This systematic breakdown, supported by visuals and digital evidence in the report, reveals a blueprint for how counterfeit money is produced, marketed, and distributed across the country—all via social platforms that were never designed to deal with such threats.
CloudSEK’s report warns of severe consequences:
The report offers actionable recommendations for LEAs and social platforms:
As part of CloudSEK’s commitment to responsible disclosure and aiding ongoing investigations, the findings from this counterfeit currency operation have been formally shared with relevant law enforcement agencies at both the state and national levels.
This includes comprehensive intelligence such as threat actor profiles, phone numbers, GPS locations, and digital evidence collected during the investigation. By proactively collaborating with investigative authorities, CloudSEK aims to assist in the timely disruption of this criminal network and contribute to safeguarding the country’s financial stability and national security.