The Telangana Cyber Security Bureau (TGCSB) has registered a case against three telemarketing companies for allegedly misusing the authorised SMS identities of two SEBI-registered financial firms to send fraudulent messages containing malicious links, an action that reportedly disrupted genuine OTPs and transactional alerts sent to investors.
The case followed a complaint from Value First Digital Media, a messaging services provider, concerning two of its clients, K Technologies and N Finvest. According to the complaint, the companies’ authorised SMS headers were used to deliver messages that did not pass through the provider’s platform.
In the first instance, a fake SMS containing a malicious link was sent to a mobile number on July 9 and July 30 using one client’s SMS header. The telecom service provider subsequently blacklisted the header. The complainant said delivery records indicated that the messages had been routed through another company that was not among the client’s five authorised telemarketers.
A second incident involved a fraudulent message that allegedly mimicked the authorised header of the other client. It was delivered to a mobile number on August 3, after which the service provider also blacklisted that header. At the complainant’s request, the provider later shared details of the message delivery chain, which included the names of the three accused companies.
The complaint alleged that two of the three companies shared the same registered address in Noida. A TGCSB official, quoting the complaint, said the accused companies had allegedly exploited the Distributed Ledger Technology system used to regulate commercial SMSes so that the messages appeared to come from a legitimate chain.
The DLT framework is used to manage commercial communication identities and routes, including the sender headers that help recipients and service providers identify messages from registered entities. In this case, the alleged misuse had consequences beyond the fraudulent messages themselves. The complainant said repeated blacklisting of the clients’ headers disrupted genuine OTPs and transactional alerts to investors.
Such alerts are used for actions including account access, transaction confirmation and other time-sensitive financial communication. The complaint does not establish how many users or messages were affected, and the extent of any financial loss was not specified in the report.
TGCSB registered the case on Friday under sections 318(4), relating to cheating, and 319(2), relating to cheating by personation, of the Bharatiya Nyaya Sanhita. Police also invoked Sections 43, 66, 66C and 66D of the Information Technology Act.
The provisions cover alleged unauthorised access or damage involving computer systems, computer-related offences, identity theft and cheating by personation using a computer resource. The charges are based on the complaint and remain subject to investigation.
A TGCSB investigator said the bureau would seek details of the alleged fraudulent activities from the complainant and other concerned entities to identify the accused. The next stage of the investigation will focus on the message-delivery chain and the role of the three telemarketing companies.

