Legally researched and updated: 9 October 2026

Best ED Lawyer in Delhi for Part-Time Job, QR-Code and Phishing Scam PMLA Cases: What Happens When Cyber-Fraud Money Reaches Shell Companies?

Create a current Delhi Headquarters Unit article around the 2026 part-time-job/QR/phishing investigation pattern. Explain how cyber-fraud proceeds may move from mule accounts into dummy or shell entities and why directors, CAs, account operators and beneficiaries require different role analysis. The article should connect cybercrime evidence with PMLA without repeating the site's general cyber or shell-company content.

Legal research and analysis by Advocate Ankit Kumar Singh .

Important Disclosure: “Best ED Lawyer in Delhi” Is a Search Phrase, Not an Official Ranking

The title uses the phrase:

BEST ED LAWYER IN DELHI.

This reflects the way persons facing high-stakes Enforcement Directorate proceedings may search for specialist counsel.

It is not:

  • an Enforcement Directorate ranking;
  • a Delhi High Court ranking;
  • a Supreme Court ranking;
  • a Government certification;
  • a Bar Council ranking;
  • a “No.1” designation; or
  • a guarantee of bail, non-arrest or closure.

For a cyber-fraud PMLA investigation, the more useful question is:

CAN COUNSEL SEPARATE THE CLIENT'S ACTUAL ROLE FROM THE THOUSANDS OF TRANSACTIONS, ACCOUNTS, COMPANIES, DEVICES AND PERSONS IN THE INVESTIGATION?

Direct Answer: Cyber-Fraud Money Reaching a Company Does Not Make Every Director or Professional a Money Launderer

A PMLA investigation may begin with cybercrime evidence showing:

VICTIM → MULE ACCOUNT → SECOND-LAYER ACCOUNT → COMPANY / FIRM → DEBIT CARD / PAYMENT PLATFORM → FOREIGN WITHDRAWAL OR VDA → PROPERTY / BENEFICIARY.

But criminal liability is not determined by drawing one red box around everyone who appears anywhere in that chain.

The analysis must ask separately:

  • what property is alleged to be proceeds of crime;
  • which scheduled offence generated it;
  • when the particular person entered the chain;
  • what that person knew;
  • what that person controlled;
  • what transaction that person performed;
  • whether that person benefited;
  • whether the person's documents/devices corroborate control; and
  • whether the conduct satisfies the applicable PMLA provision.

Therefore:

DIRECTOR ≠ CA ≠ BANK SIGNATORY ≠ ACCOUNT OPERATOR ≠ MULE ACCOUNT HOLDER ≠ BENEFICIAL OWNER ≠ ULTIMATE BENEFICIARY.

The 5 March 2026 ED Headquarters Unit Case

On 5 March 2026, ED stated that its Headquarters Unit, New Delhi had arrested two Chartered Accountants on 28 February 2026 in a cyber-fraud investigation.

According to ED's public allegations, citizens across India were induced to transfer funds through:

  • investment opportunities;
  • part-time-job schemes;
  • QR-code scams;
  • phishing operations; and
  • other fraudulent digital inducements.

ED alleged that approximately:

₹641 CRORE

was initially credited into mule accounts and thereafter layered through a network of dummy/shell entities.

ED further alleged that amounts were transferred using Indian bank-issued cards to the UAE-based PYYPL platform.

According to the release, funds were thereafter allegedly:

  • withdrawn through overseas ATMs/POS, particularly in Dubai; or
  • converted to VDAs through Binance and further routed through custodial/non-custodial wallets.

The allegations remain subject to proof in the competent proceedings.

Why the Delhi High Court Judgment Is More Useful Than a Generic “Shell Company” Article

The Delhi High Court's 2 February 2026 judgment in:

BHASKAR YADAV v. DIRECTORATE OF ENFORCEMENT

and the connected Ashok Kumar Sharma matter provides a detailed public description of the prosecution case.

The judgment refers to:

ECIR/HIU-1/07/2024 DATED 28 MARCH 2024.

It records the prosecution case involving:

  • part-time-job and investment fraud;
  • websites, WhatsApp and Telegram;
  • primary and mule bank accounts;
  • multiple layers of bank transfers;
  • Indian bank-issued debit cards;
  • PYYPL;
  • overseas withdrawals;
  • cryptocurrency acquisition;
  • mobile-number convergence;
  • email convergence;
  • banking credentials;
  • UPI IDs;
  • merchant QR codes;
  • SIM cards;
  • OTP forwarding; and
  • forensic analysis of seized mobile-phone data.

That evidentiary architecture is the focus of this article.

The question is not merely whether a company is “shell”.

The question is:

WHO CONTROLLED THE DIGITAL AND BANKING INFRASTRUCTURE THROUGH WHICH THE ALLEGED PROCEEDS MOVED?

How the Alleged Cyber-Fraud Money Trail Was Structured

The public prosecution case can be simplified into the following investigative sequence:

1. CYBER INDUCEMENT

Victim receives:

  • part-time-job offer;
  • investment opportunity;
  • QR/payment instruction;
  • phishing communication; or
  • other online inducement.

↓

2. FIRST RECEIVING ACCOUNT

Victim sends money to an account supplied by the fraud network.

↓

3. MULE ACCOUNT NETWORK

Money is allegedly moved rapidly through other accounts.

↓

4. CORPORATE / FIRM ACCOUNTS

A company, partnership, proprietorship or other entity may appear as an intermediate account holder.

↓

5. CONTROL INFRASTRUCTURE

Investigators look at:

  • SIM;
  • mobile;
  • email;
  • OTP;
  • debit card;
  • UPI;
  • merchant QR;
  • net banking;
  • authorised signatory;
  • device; and
  • instructions.

↓

6. CROSS-BORDER / VDA CONVERSION

The prosecution case in the 2026 matter refers to PYYPL, overseas cash withdrawal and cryptocurrency.

↓

7. BENEFICIAL DESTINATION

Investigators ultimately ask:

WHO ENDED UP WITH THE VALUE?

The PMLA Bridge: Cyber Fraud Is the Predicate Story; Proceeds of Crime Are the Money-Laundering Story

PMLA does not criminalise a QR code, Telegram account or corporate structure merely because it appears suspicious.

The investigation must connect:

CRIMINAL ACTIVITY RELATING TO A SCHEDULED OFFENCE

to:

PROPERTY DERIVED OR OBTAINED DIRECTLY OR INDIRECTLY FROM THAT CRIMINAL ACTIVITY.

That property can then become the alleged:

PROCEEDS OF CRIME.

The Section 3 inquiry is then person-specific:

Did the particular person:

  • directly or indirectly attempt to indulge;
  • knowingly assist;
  • knowingly become a party; or
  • actually become involved

in a process/activity connected with those alleged proceeds within the statutory framework?

The defence should therefore force the case back into:

PROPERTY + SOURCE + TRANSACTION + PERSON + KNOWLEDGE + CONTROL + CONDUCT.

Director Liability: Do Not Stop at the MCA Master Data

A director's name appearing in MCA records answers:

WHO HELD A CORPORATE OFFICE?

It does not by itself answer:

WHO LAUNDERED THE MONEY?

For each director, analyse:

  • date of appointment;
  • date of resignation;
  • shareholding;
  • Board participation;
  • actual management;
  • bank-signatory status;
  • DSC custody;
  • email access;
  • SIM/mobile control;
  • cheque-book custody;
  • merchant credentials;
  • transaction instructions;
  • commercial knowledge;
  • remuneration;
  • commission;
  • relationship with controlling persons; and
  • benefit received.

Section 70

Where a company-related PMLA contravention is alleged, the Section 70 framework requires attention to:

  • who was in charge of the company;
  • who was responsible for conduct of business;
  • knowledge;
  • due diligence;
  • consent;
  • connivance; and
  • neglect.

Therefore:

DIRECTORSHIP IS EVIDENCE OF A CORPORATE ROLE — NOT AN AUTOMATIC SUBSTITUTE FOR THE INGREDIENTS OF PMLA LIABILITY.

Chartered Accountants: Professional Status Is Not the Offence — Actual Conduct Matters

The March 2026 public case is significant because professional accused were alleged to have played an operational role in the entity/account structure.

That distinction is essential.

Routine Professional Role

A CA may legitimately:

  • incorporate or advise on entities;
  • provide accounting;
  • audit;
  • prepare tax returns;
  • certify documents;
  • advise on company law;
  • prepare financial statements; or
  • assist with banking documentation.

Those functions do not, by themselves, establish Section 3 involvement.

Operational Role Allegation

The analysis changes where evidence allegedly establishes that the professional:

  • arranged mule accounts;
  • controlled bank accounts;
  • held customer kits;
  • controlled SIMs;
  • controlled OTPs;
  • held debit cards;
  • operated shell/dummy entities;
  • gave transaction instructions;
  • received proceeds;
  • received commission;
  • coordinated with upstream fraud operators; or
  • helped move value outside India.

The defence should therefore reconstruct:

WHAT WAS PROFESSIONAL WORK?

versus:

WHAT IS ALLEGED TO HAVE BEEN TRANSACTIONAL CONTROL?

Account Operator vs Authorised Signatory vs Beneficial Controller

These expressions should not be used interchangeably.

Role Question
Account Holder In whose legal name was the account?
Authorised Signatory Who was formally authorised by the entity?
Credential Holder Who possessed login/password/OTP access?
Card Holder Who physically or digitally controlled the debit card?
SIM Controller Who possessed the bank-linked SIM?
Transaction Operator Who actually initiated transfers?
Beneficial Controller Who instructed or controlled the account despite another person's name?
Ultimate Beneficiary Who ultimately retained or enjoyed the value?

The Delhi High Court record concerning allegedly shared:

  • mobile numbers;
  • bank accounts;
  • email IDs;
  • SIMs;
  • OTP-forwarding arrangements; and
  • PYYPL transactions

illustrates why digital control evidence may be more probative than the designation printed on a company form.

Mule Account Holder: The Account Name Is Only the Beginning

A mule-account investigation should identify:

  • who opened the account;
  • who recruited the holder;
  • whether commission was paid;
  • who supplied KYC;
  • who retained the passbook/cheque book;
  • who held the debit card;
  • who held the SIM;
  • who controlled OTPs;
  • who controlled internet banking;
  • who created the UPI ID;
  • who created the merchant QR;
  • which device accessed the account;
  • where the device was located;
  • who instructed transfers;
  • how quickly funds moved onward; and
  • what the holder knew about the source.

A genuine defence may differ materially between:

  • an account seller;
  • a deceived account holder;
  • a paid mule;
  • a person whose KYC was misused;
  • a person who surrendered credentials;
  • a person who actively routed funds; and
  • a controller operating an account in somebody else's name.

Beneficiary Analysis: Follow Value, Not Merely the Last Bank Credit

The person receiving an alleged cyber-fraud-linked transfer may say:

  • it was sale consideration;
  • it was repayment;
  • it was salary;
  • it was professional fee;
  • it was a loan;
  • it was reimbursement;
  • it was investment;
  • it was family transfer; or
  • it belonged to somebody else.

Each explanation should be tested against:

  • contract;
  • invoice;
  • delivery;
  • ledger;
  • GST record;
  • income-tax record;
  • bank trail;
  • communications;
  • timing;
  • onward transfer;
  • asset purchase;
  • cash withdrawal;
  • crypto acquisition; and
  • relationship between parties.

The strongest defence is often:

DOCUMENTED COMMERCIAL EXPLANATION + SOURCE TRAIL + USE TRAIL + ABSENCE OF CONTROL OVER THE FRAUD NETWORK.

“Shell Company” Is an Investigative Description — The PMLA Case Still Needs Person-Specific Proof

This article does not repeat the site's separate detailed guide on proving genuine commercial substance.

For present purposes, the important point is narrower:

CALLING AN ENTITY A “SHELL” OR “DUMMY” DOES NOT ANSWER WHO COMMITTED THE ALLEGED SECTION 3 PROCESS OR ACTIVITY.

The investigation should still identify:

  • incorporator;
  • shareholder;
  • director;
  • actual controller;
  • bank signatory;
  • credential holder;
  • invoice generator;
  • account operator;
  • person issuing instructions;
  • fund source;
  • fund destination;
  • actual business activity;
  • employees;
  • office;
  • tax trail;
  • contracts; and
  • beneficiary.

The defence question is therefore:

WHAT EXACTLY DID THIS ENTITY AND THIS PARTICULAR PERSON DO?

The Digital Evidence ED May Correlate

A modern cyber-PMLA case can combine traditional bank evidence with digital-forensic evidence.

Victim-Side Evidence

  • NCRP complaint;
  • 1930 record where available;
  • bank debit;
  • UPI transaction;
  • QR code;
  • WhatsApp/Telegram chat;
  • fake investment dashboard;
  • phishing URL;
  • email;
  • screen recording;
  • call record.

Account-Side Evidence

  • KYC;
  • video KYC;
  • account-opening form;
  • mobile number;
  • email;
  • device;
  • IP address;
  • UPI ID;
  • merchant QR;
  • ATM/debit card;
  • OTP logs;
  • beneficiary addition;
  • transaction timestamps.

Corporate Evidence

  • MCA records;
  • DSC;
  • registered-office data;
  • shareholding;
  • directors;
  • authorised signatories;
  • GST;
  • invoices;
  • books;
  • employees;
  • commercial contracts.

Device / Communication Evidence

  • WhatsApp;
  • Telegram;
  • Zoho or other email;
  • SMS-forwarding applications;
  • cloud accounts;
  • contact lists;
  • deleted-data recovery;
  • screenshots;
  • wallet addresses.

Cross-Border / VDA Evidence

  • foreign payment-platform records;
  • card authorisation;
  • ATM/POS location;
  • exchange KYC;
  • deposit address;
  • withdrawal address;
  • blockchain transaction hash;
  • custodial wallet;
  • non-custodial wallet;
  • P2P counterparty.

A Separate 2026 Headquarters Unit Phishing Case Shows the Other Direction of the Money Trail

The ED Headquarters Unit's 15 June 2026 Coinbase phishing press release concerns a different case.

According to ED:

  • fake websites resembling Coinbase allegedly obtained victim login and authentication information;
  • crypto was transferred from victim accounts to controlled wallets;
  • assets were converted into other VDAs;
  • funds moved through multiple wallets;
  • crypto was ultimately converted to INR through P2P transactions;
  • bank accounts of individuals, family members, group entities and associates allegedly received the sale proceeds; and
  • funds were allegedly used to acquire movable/immovable properties.

This is the reverse-looking evidentiary pattern:

STOLEN VDA → WALLETS → P2P → INR BANK ACCOUNTS → GROUP / FAMILY / ENTITY ACCOUNTS → ASSETS.

The March and June 2026 cases are separate.

Together, they demonstrate why a cyber-PMLA lawyer must be able to trace value in both directions:

FIAT → VDA

and:

VDA → FIAT.

Section 50 Summons: Prepare the Role Before the Statement

In a multi-entity cyber investigation, a person summoned under Section 50 should understand:

WHY ED THINKS THIS PERSON IS RELEVANT.

Before appearance, prepare an evidence-based role chronology covering:

  • occupation;
  • company relationship;
  • directorship period;
  • shareholding;
  • CA/professional engagement;
  • bank authority;
  • SIM/mobile ownership;
  • email ownership;
  • account access;
  • merchant/QR access;
  • payments;
  • fees/commission;
  • relationship with co-accused/persons under investigation;
  • travel;
  • foreign accounts/platforms;
  • crypto activity;
  • property purchases;
  • devices;
  • records held.

Do not guess.

Do not adopt another accused person's explanation merely because it appears convenient.

Do not use:

“I was only a director.”

where bank/device evidence may show more.

Equally, do not casually admit:

“I controlled the company.”

where your actual role was limited and documentary evidence shows that limitation.

Bail Risk in a Cyber-Fraud PMLA Case

The Delhi High Court rejected the anticipatory-bail applications in the connected February 2026 matters.

The judgment addressed:

  • Section 45 twin conditions;
  • complexity of alleged fund layering;
  • ongoing investigation;
  • need asserted for custodial interrogation;
  • digital evidence;
  • alleged destruction of evidence;
  • alleged account/entity control; and
  • the continuing receipt of cyber complaints.

On 18 February 2026, the Supreme Court declined to interfere with the High Court order in Bhaskar Yadav's SLP and granted ten days to surrender.

Importantly, the Supreme Court expressly clarified that:

THE OBSERVATIONS IN THE HIGH COURT ORDER WOULD HAVE NO BEARING ON REGULAR BAIL PROCEEDINGS.

Therefore:

ANTICIPATORY-BAIL REJECTION IS NOT A CONVICTION.

A regular-bail application must be prepared on the record and procedural position then existing.

Role-Based Defence Matrix

Person Key Evidence Central Defence Question
Director MCA, Board, bank mandate, emails, actual management Was the person actually in control or merely holding office?
Chartered Accountant Engagement, invoices, incorporation, bank/KYC work, communications Professional service or operational laundering role?
Authorised Signatory Mandate, transaction logs, device, OTP, instructions Formal authority or actual transaction control?
Account Operator SIM, OTP, IP, device, debit card, net banking Who actually moved the money?
Mule Account Holder KYC, commission, credentials, chats, account custody Deceived holder, paid mule or knowing participant?
Dummy Director DSC, signatures, KYC, remuneration, account access Nominal name only or actual knowledge/participation?
Beneficiary Source, invoice, loan, onward use, asset purchase Legitimate receipt or knowing receipt/use of alleged PoC?
Bank / Fintech Personnel KYC, onboarding, alerts, overrides, communications Ordinary institutional function, negligence or knowing facilitation?

This matrix should be completed:

PERSON BY PERSON.

Not:

COMPANY GROUP BY COMPANY GROUP.

Cyber-Fraud to PMLA Role-Mapping Flowchart

In a cyber-fraud PMLA matter, the money trail identifies the transaction chain, but legal liability must still be analysed person by person using evidence of knowledge, control, conduct and benefit.

What Documents Should Be Collected Immediately?

For a director, CA, signatory, account operator or beneficiary connected to a shell/dummy-entity allegation, preserve:

  • ED summons/notices;
  • search documents;
  • seizure records;
  • arrest material where applicable;
  • company master data;
  • incorporation records;
  • shareholding history;
  • director history;
  • resignation evidence;
  • Board minutes;
  • DSC custody evidence;
  • bank-account opening forms;
  • authorised-signatory forms;
  • bank statements;
  • debit-card records;
  • SIM ownership;
  • email ownership;
  • device inventory;
  • UPI IDs;
  • merchant QR records;
  • OTP/SMS records where available;
  • professional engagement letters;
  • CA/professional invoices;
  • GST returns;
  • ITRs;
  • sales/purchase invoices;
  • employee records;
  • office rent/electricity/internet;
  • commercial agreements;
  • loan agreements;
  • source-of-funds evidence;
  • crypto exchange records;
  • wallet addresses;
  • P2P records;
  • property purchase documents;
  • Telegram/WhatsApp/email records;
  • NCRP complaint references disclosed in case papers; and
  • a date-wise personal chronology.

Do not delete devices, chats or emails after learning of an investigation.

Preserve original evidence and take legal advice before producing or explaining it.

Common Defence Mistakes in Part-Time-Job / QR / Phishing PMLA Cases

  • Saying “I was only a director” without examining bank/device evidence.
  • Saying “I am a CA, therefore everything I did was professional work.”
  • Assuming authorised signatory means beneficial owner.
  • Assuming nominee director means innocent without checking conduct.
  • Assuming receipt of money automatically proves laundering.
  • Ignoring the scheduled-offence/proceeds-of-crime link.
  • Ignoring exact entry date into the money trail.
  • Not separating company liability from individual liability.
  • Not mapping Section 70 separately.
  • Destroying/deleting digital data.
  • Changing phones without preserving forensic material.
  • Giving speculative answers under Section 50.
  • Using another person's explanation without checking records.
  • Calling an entity “genuine” based only on GST/CIN.
  • Calling an entity “shell” merely because it has low turnover.
  • Ignoring common email/mobile/device evidence.
  • Ignoring debit-card/POS evidence.
  • Ignoring foreign fintech records.
  • Ignoring wallet/P2P evidence.
  • Ignoring the ultimate beneficiary.
  • Mixing the March 2026 part-time-job/QR case with the separate June 2026 Coinbase phishing case.
  • Describing bail-stage allegations as final findings of guilt.

Frequently Asked Questions

1. Is a part-time-job scam automatically a PMLA case?

No. PMLA requires the statutory link between a scheduled offence, proceeds of crime and a process/activity connected with those proceeds.

2. Can cyber-fraud money become proceeds of crime?

Yes where the property is derived or obtained from criminal activity relating to a scheduled offence within Section 2(1)(u).

3. What did ED allege in the 5 March 2026 Headquarters Unit case?

ED alleged that approximately ₹641 crore from investment, part-time-job, QR-code, phishing and other cyber frauds moved through mule accounts and dummy/shell entities before cross-border/crypto movement.

4. Does every director of a shell company become guilty under PMLA?

No. The person's actual Section 3 conduct and, where relevant, Section 70 responsibility/knowledge/consent/connivance/neglect require individual analysis.

5. Can a Chartered Accountant be prosecuted merely for incorporating companies?

Professional status or incorporation work alone does not automatically establish money laundering. The investigation must examine the alleged conduct, knowledge, control and connection with proceeds of crime.

6. Is an authorised bank signatory automatically the beneficial owner?

No. Formal signing authority and ultimate beneficial control are different questions.

7. What is a mule account?

In cyber-fraud investigations the expression generally refers to an account used to receive or transmit illicitly obtained funds, often for another person's benefit or control. The individual holder's knowledge and participation must still be established.

8. Why are SIM cards and OTPs important?

They can help investigators determine who actually controlled a bank account or transaction even where the account was legally in another person's name.

9. Why are merchant QR codes relevant?

A QR/merchant credential may help identify the receiving account, merchant profile, linked mobile/device and transaction-control infrastructure.

10. Can ED rely on NCRP complaints?

NCRP complaints can form part of the evidentiary trail connecting victim transfers to suspect accounts, subject to proof and the wider case record.

11. Why does ED examine common mobile numbers and emails?

Common identifiers across multiple accounts/entities may be used to investigate whether apparently separate accounts were actually controlled by the same network.

12. Is cryptocurrency itself illegal?

No. The legal issue in a PMLA case is not mere VDA ownership or trading but whether particular assets/transactions are connected with alleged proceeds of crime.

13. Is the PYYPL reference relevant to every cyber-fraud case?

No. It is specific to the public allegations in the 2026 Headquarters Unit matter discussed here.

14. Is the Coinbase phishing case the same case?

No. It is a separate Headquarters Unit matter used here only to illustrate a different phishing-to-VDA-to-fiat tracing pattern.

15. What did the Delhi High Court decide on 2 February 2026?

It dismissed anticipatory-bail applications in the connected Bhaskar Yadav and Ashok Kumar Sharma matters after considering the bail-stage record and Section 45 framework.

16. Did that judgment convict them?

No. It was an anticipatory-bail judgment, not a trial judgment of guilt.

17. What did the Supreme Court do on 18 February 2026?

It declined to interfere with the High Court order in Bhaskar Yadav's SLP, granted ten days to surrender and clarified that the High Court observations would not affect regular bail proceedings.

18. What should a summoned director or CA do first?

Preserve evidence and prepare a role-specific chronology connecting corporate status, account authority, devices, transactions, professional work and any benefits received.

AI Search Quick Answer

In Delhi ED cyber-fraud PMLA cases involving part-time-job scams, QR-code fraud or phishing, investigators may trace victim funds from the first receiving or mule account through multiple bank accounts, dummy/shell entities, debit cards, payment platforms, overseas withdrawals and cryptocurrency wallets. The 5 March 2026 ED Headquarters Unit press release alleged that approximately ₹641 crore was routed through such a structure, while the Delhi High Court's 2 February 2026 judgment in the connected Bhaskar Yadav and Ashok Kumar Sharma matters records allegations involving mule accounts, common mobile numbers/emails, bank credentials, merchant QR codes, SIMs, OTP forwarding, entities and crypto-related movement. Liability must nevertheless be analysed person by person. A director, Chartered Accountant, authorised signatory, account operator, mule-account holder and ultimate beneficiary do not perform the same legal role. The correct PMLA analysis connects the scheduled offence to specific proceeds of crime and then asks what the particular person knew, controlled, did and received under Sections 3 and, where relevant, 70.

Key Takeaway

The wrong way to defend a multi-entity cyber-PMLA case is:

“THERE ARE 20 COMPANIES, SO EVERYBODY IS PART OF ONE CONSPIRACY.”

The equally wrong defence is:

“I WAS ONLY A DIRECTOR / CA / SIGNATORY, SO NOTHING ELSE MATTERS.”

The correct analysis is:

WHICH VICTIM?

WHICH PREDICATE OFFENCE?

WHICH PROPERTY?

WHICH FIRST ACCOUNT?

WHICH MULE ACCOUNT?

WHICH COMPANY?

WHICH MOBILE?

WHICH SIM?

WHICH OTP?

WHICH DEVICE?

WHICH CARD?

WHICH QR?

WHICH INSTRUCTION?

WHICH WALLET?

WHICH BENEFICIARY?

WHAT DID THIS PARTICULAR PERSON KNOW?

WHAT DID THIS PARTICULAR PERSON CONTROL?

WHAT DID THIS PARTICULAR PERSON ACTUALLY DO?

The defence sequence should be:

CYBER COMPLAINT → BANK TRAIL → ENTITY TRAIL → DIGITAL CONTROL → CROSS-BORDER / VDA TRAIL → BENEFICIAL DESTINATION → SECTION 3 ROLE → SECTION 70 WHERE APPLICABLE → SUMMONS / SEARCH / BAIL / TRIAL STRATEGY.

Professional Legal Review and Coordination

Advocate Ankit Kumar Singh undertakes legal research, drafting and litigation work concerning PMLA/ED investigations, cyber-enabled financial fraud, mule-account allegations, corporate layering, Section 50 proceedings, bank/account evidence, digital evidence and related proceedings depending upon the facts, jurisdiction and accepted professional engagement.

A cyber-fraud PMLA review may include:

  • predicate-FIR review;
  • scheduled-offence analysis;
  • ECIR-stage chronology;
  • proceeds-of-crime mapping;
  • NCRP complaint mapping;
  • mule-account analysis;
  • corporate/entity mapping;
  • director-role analysis;
  • Section 70 analysis;
  • CA/professional-role analysis;
  • authorised-signatory analysis;
  • bank-account control analysis;
  • SIM/OTP/device analysis;
  • merchant QR / UPI review;
  • Telegram / WhatsApp evidence;
  • foreign-fintech trail;
  • VDA/wallet trail;
  • P2P transaction review;
  • beneficiary analysis;
  • Section 50 preparation;
  • search/seizure response;
  • bank-freeze / attachment analysis;
  • anticipatory/regular-bail strategy;
  • Delhi High Court proceedings;
  • Special Court coordination; and
  • Supreme Court coordination through Advocate-on-Record where required.

Advocate Ankit Kumar Singh
Supreme Court of India | Patna High Court | Allahabad High Court at Prayagraj | Jharkhand High Court at Ranchi | Calcutta High Court | Delhi High Court and Delhi Courts/Tribunals | Matters concerning Bhopal, Madhya Pradesh | Multiple District Courts

Phone: 8294431232
Email: ankitsingh.legum@gmail.com
Website: advocateankitkumarsingh.in

References to Delhi describe the investigating/court nexus and professional scope and do not represent a claim of a permanent Delhi office. Supreme Court filings require an Advocate-on-Record, and local/authorised counsel may be coordinated where appropriate.

No arrest, bail, attachment, prosecution, investigation or trial outcome can be guaranteed.

Official Sources

Add Advocate Ankit Kumar Singh as a Preferred Source on Google

Readers who want to see more legal research, court updates, cyber law, PMLA, ED, criminal-law and litigation content from Advocate Ankit Kumar Singh can add advocateankitkumarsingh.in as a Preferred Source on Google.

Add advocateankitkumarsingh.in as a Preferred Source on Google

Conclusion

The important 2026 Delhi cyber-PMLA lesson is not simply:

“ED IS INVESTIGATING SHELL COMPANIES.”

It is:

DIGITAL CONTROL + BANK CONTROL + ENTITY CONTROL + BENEFICIAL CONTROL

can be reconstructed from different evidence.

Where money generated through a part-time-job, QR-code, investment or phishing fraud reaches a company account, ED may examine:

  • who incorporated the entity;
  • who opened the account;
  • who supplied KYC;
  • who held the SIM;
  • who received the OTP;
  • who possessed the debit card;
  • who operated net banking;
  • who controlled merchant QR/UPI;
  • who communicated with upstream operators;
  • who moved money onward;
  • who converted it to VDA/cash;
  • who purchased property; and
  • who ultimately benefited.

But the same evidence must be analysed:

PERSON BY PERSON.

A:

  • director;
  • Chartered Accountant;
  • dummy director;
  • authorised signatory;
  • mule-account holder;
  • credential controller;
  • company;
  • fintech intermediary; and
  • beneficiary

cannot automatically be assigned the same role merely because the money trail touches each of them.

The strongest PMLA analysis returns to:

THE SPECIFIC PROPERTY, THE SPECIFIC TRANSACTION, THE SPECIFIC DEVICE OR ACCOUNT, THE SPECIFIC INSTRUCTION, THE SPECIFIC KNOWLEDGE, AND THE SPECIFIC PERSON.

Professional / Legal Disclaimer: This article discusses publicly available allegations, judicial records and Enforcement Directorate press releases concerning ongoing or prosecuted cyber-fraud/PMLA matters. References to persons, entities, “shell companies”, “dummy companies”, syndicates, money laundering, proceeds of crime or other alleged conduct should be understood in the procedural context in which the source uses them and do not constitute an independent finding of guilt by the author. The Delhi High Court judgment discussed was a bail-stage determination, and the Supreme Court expressly stated that the High Court observations would not affect regular-bail proceedings in the SLP before it. “Best ED Lawyer in Delhi” is used only as a user-supplied search-intent phrase and is not an official institutional ranking or endorsement.