Fintech Payment Gateways and Online Investment Fraud under PMLA: How ED Traces Merchant Accounts, Mule Funds and Layering

Direct Answer: A fintech company, payment gateway or payment aggregator does not become guilty of money laundering merely because a fraudulent merchant used its technology or payment infrastructure.

The Directorate of Enforcement may, however, examine the intermediary where investor funds were collected through:

  • merchant IDs created on a payment platform;
  • UPI IDs or payment links linked with alleged mule accounts;
  • payment-aggregator escrow accounts;
  • shell merchants or paper entities;
  • fraudulently onboarded sub-merchants;
  • third-party settlement accounts;
  • multiple fintech or gateway layers;
  • cryptocurrency wallets;
  • foreign payment arrangements; or
  • accounts controlled by the ultimate operators of the investment scheme.

The legal inquiry should determine:

  • whether the entity was a payment aggregator handling funds or only a technology gateway;
  • what merchant due diligence was undertaken;
  • who controlled the merchant account and settlement bank account;
  • whether transaction alerts or investor complaints were ignored;
  • whether the intermediary knowingly assisted the movement or concealment of alleged proceeds of crime;
  • whether officers consented, connived or negligently facilitated the conduct;
  • whether the intermediary derived any benefit beyond ordinary commercial charges;
  • whether funds belonging to innocent merchants were mixed with suspected proceeds; and
  • whether the investigation has identified a legally sustainable scheduled offence.

Advocate Ankit Kumar Singh
Supreme Court of India | Patna High Court | Other High Courts | Allahabad High Court and Lucknow Bench | Jharkhand High Court at Ranchi | Calcutta High Court | High Court of Madhya Pradesh Matters concerning Bhopal

Professional assistance may include fintech and merchant-structure mapping, payment-flow analysis, Section 50 summons preparation, escrow-account reconciliation, bank-freezing and attachment proceedings, director-role analysis, arrest-risk review, Section 45 bail preparation, victim tracing and proceedings before the appropriate Special Court, High Court or Supreme Court.

What Is a Payment Aggregator?

Under the Reserve Bank of India’s regulatory framework, a payment aggregator facilitates merchants in accepting different payment instruments from customers without each merchant creating an independent payment-integration system.

A payment aggregator ordinarily:

  • connects merchants with acquiring institutions;
  • receives payments from customers;
  • pools those payments;
  • maintains the collections through the prescribed escrow structure; and
  • transfers the amounts to merchants according to the settlement cycle.

Because a payment aggregator handles funds, its regulatory and evidentiary position is materially different from that of a technology-only service provider.

Read RBI Guidelines on Regulation of Payment Aggregators and Payment Gateways

What Is a Payment Gateway?

Under the RBI framework, a payment gateway provides the technological infrastructure used to route and process an online payment transaction without itself handling the funds.

A payment gateway may provide:

  • payment-page integration;
  • transaction routing;
  • tokenisation or security infrastructure;
  • API connectivity;
  • authentication support;
  • transaction-status communication;
  • fraud-screening technology;
  • dashboard access; and
  • technical connectivity between merchants and regulated payment participants.

The commercial label is not conclusive. ED and the courts may examine what the entity actually did.

An entity describing itself as a gateway may require closer examination where it:

  • received or pooled customer funds;
  • controlled settlements;
  • selected settlement beneficiaries;
  • maintained merchant balances;
  • issued payment links in its own merchant structure;
  • operated a master-merchant or sub-merchant model;
  • allowed settlement to unrelated third parties; or
  • performed functions ordinarily associated with payment aggregation.

Why Is the Aggregator-Gateway Distinction Important?

The distinction affects:

  • RBI authorisation;
  • fund-handling responsibility;
  • escrow-account obligations;
  • merchant onboarding;
  • KYC and anti-money-laundering compliance;
  • settlement and reconciliation records;
  • transaction-monitoring expectations;
  • access to customer and merchant data;
  • the ability to stop or hold settlements; and
  • the evidence available in a PMLA investigation.

A pure technology provider may possess detailed routing and device records even where it never held the investor’s money.

A payment aggregator may possess both the technical data and the merchant-wise settlement trail.

What Is Online Investment Fraud?

Online investment fraud commonly involves an internet-based representation that money will be invested in a genuine financial or commercial opportunity.

The representation may concern:

  • listed shares;
  • pre-IPO or IPO allotments;
  • institutional trading accounts;
  • options or commodity trading;
  • forex or contract-for-difference trading;
  • cryptocurrency or token mining;
  • algorithmic trading;
  • portfolio-management services;
  • copy trading;
  • digital gold;
  • advertisement-viewing income;
  • task-completion income;
  • referral commissions;
  • fixed daily returns;
  • investment clubs;
  • private placement opportunities; or
  • another allegedly high-return investment product.

The defining issue is not the description used by the platform. It is whether the investors were dishonestly induced to part with money through false representations.

Common Structure of a Fake Investment Application

  1. Social-Media Contact: The victim is contacted through WhatsApp, Telegram, Instagram, Facebook, YouTube, SMS or another platform.
  2. Trust Creation: The operators display alleged experts, profit screenshots, testimonials, market commentary or fabricated records.
  3. Application or Website: The victim is directed to download an APK, use a website or access a fake trading dashboard.
  4. Initial Deposit: A relatively small payment is requested through UPI, bank transfer, card, payment link or cryptocurrency.
  5. Artificial Profit: The dashboard shows profits that may not correspond with any genuine market transaction.
  6. Inducement to Increase Funds: The victim is offered premium access, institutional allotment, a larger profit opportunity or a limited-time scheme.
  7. Changing Beneficiary Accounts: Payments are directed to several companies, individuals or merchant accounts.
  8. Small Withdrawal: A limited amount may be returned to create confidence.
  9. Withdrawal Block: The victim is later prevented from withdrawing the displayed balance.
  10. Additional Demands: The operators demand tax, margin, verification, liquidity, insurance or release fees.
  11. Disappearance: The app, website, social-media group or customer-support number becomes inaccessible.

SEBI-Identified Warning Signs

SEBI has cautioned investors against fake trading applications and investment scams involving:

  • guaranteed or near-certain returns;
  • unverified application links or APK files;
  • social-media investment groups;
  • false claims of exclusive institutional access;
  • fake analysts or advisers;
  • fabricated profit displays;
  • payments to third-party accounts;
  • unregistered entities;
  • pressure to invest additional amounts; and
  • blocked withdrawals accompanied by further payment demands.

Read SEBI’s Investor Warning on Fake Trading Applications

Read SEBI’s Guide on Identifying Investment Scams

When Does an Online Investment Fraud Become a PMLA Matter?

An online investment fraud does not fall under the PMLA merely because:

  • a large amount is involved;
  • the transaction occurred digitally;
  • a payment gateway was used;
  • several bank accounts were involved;
  • the accused operated from another country;
  • cryptocurrency was used; or
  • the police registered an FIR.

A PMLA investigation requires criminal activity relating to a scheduled offence and property derived or obtained from that criminal activity.

The usual analytical sequence is:

SCHEDULED CRIMINAL ACTIVITY

↓

MONEY OR PROPERTY OBTAINED FROM VICTIMS

↓

IDENTIFICATION OF PROCEEDS OF CRIME

↓

COLLECTION THROUGH BANK / UPI / MERCHANT / GATEWAY CHANNELS

↓

TRANSFER, POSSESSION, USE, CONCEALMENT OR LAYERING

↓

ALLEGED ACTIVITY UNDER SECTION 3 PMLA

Scheduled Offence in an Investment-Fraud Case

Depending on the facts and the applicable date, the predicate case may allege:

  • criminal conspiracy;
  • cheating;
  • cheating by personation;
  • dishonest inducement to deliver property;
  • forgery of valuable securities or electronic records;
  • use of forged documents;
  • fraud under the Companies Act;
  • manipulative or deceptive securities-market conduct;
  • offences having cross-border implications; or
  • another offence appearing in the Schedule to the PMLA.

The current Schedule must be checked provision by provision.

Important: The mere inclusion of an Information Technology Act provision in a cyber FIR does not automatically mean that the provision is a scheduled offence. The exact PMLA Schedule, the corresponding criminal provision and the date of the alleged conduct must be examined.

For post-1 July 2024 cases, the relevant Bharatiya Nyaya Sanhita provisions and their relationship with the existing PMLA Schedule should be analysed carefully rather than assumed.

What Are Proceeds of Crime in an Investment Scam?

Proceeds of crime may include the money or property allegedly derived or obtained from investors through the scheduled criminal activity.

The alleged proceeds may appear as:

  • balances in beneficiary bank accounts;
  • merchant settlements;
  • funds held in an aggregator’s escrow account;
  • amounts transferred to shell entities;
  • cryptocurrency or stablecoins;
  • cash withdrawals;
  • hawala settlements;
  • immovable property;
  • shares or securities;
  • vehicles and luxury assets;
  • payments to promoters or employees;
  • commissions paid to account providers;
  • payments to call centres or advertisers;
  • foreign remittances; or
  • property allegedly equivalent in value.

Every credit in a merchant, gateway or escrow account should not automatically be treated as proceeds of crime. Merchant-wise and transaction-wise reconciliation remains essential.

Typical Payment Flow in a Genuine Online Transaction

CUSTOMER

↓

PAYMENT INSTRUMENT
UPI / CARD / NET BANKING / WALLET

↓

ISSUING BANK OR PAYMENT PARTICIPANT

↓

PAYMENT GATEWAY OR ROUTING INFRASTRUCTURE

↓

PAYMENT AGGREGATOR / ACQUIRER

↓

ESCROW OR SETTLEMENT PROCESS

↓

VERIFIED MERCHANT BANK ACCOUNT

↓

GENUINE GOODS OR SERVICES

Typical Alleged Fraud Flow

INVESTOR

↓

FAKE TRADING OR INVESTMENT APPLICATION

↓

PAYMENT LINK / UPI ID / MERCHANT ID

↓

MULE ACCOUNT OR SHELL MERCHANT

↓

PAYMENT AGGREGATOR SETTLEMENT

↓

SECOND-LAYER COMPANY OR INDIVIDUAL ACCOUNT

↓

MULTIPLE RAPID TRANSFERS

↓

CASH / HAWALA / CRYPTOCURRENCY / FOREIGN REMITTANCE / ASSET

↓

ULTIMATE BENEFICIARY

This is an illustrative analytical model. It is not proof that every entity in a payment chain knew of the underlying fraud.

What Is a Mule Account?

A mule account is commonly understood as an account used to receive or move funds for another person.

The account holder may be:

  • an active participant;
  • a paid account provider;
  • a dummy proprietor or director;
  • an employee acting on instructions;
  • a person deceived about the purpose;
  • a person whose credentials were misused;
  • a financially vulnerable person lending the account; or
  • a legitimate business whose account was compromised.

The investigation should determine:

  • who opened the account;
  • who supplied the KYC documents;
  • who controlled the mobile number and email;
  • who possessed the cheque book or banking token;
  • who operated internet banking;
  • which IP address and device were used;
  • who withdrew or transferred the money;
  • what consideration the account holder received; and
  • whether the account holder knew the nature of the funds.

What Is a Shell Merchant?

A shell merchant may be alleged where a merchant account was created in the name of an entity that:

  • did not conduct the declared business;
  • had no genuine customers;
  • had no capacity to supply the represented goods or services;
  • used a fabricated website;
  • settled funds to an unrelated account;
  • was controlled by another person;
  • used dummy directors or proprietors;
  • shared contact details with several merchants;
  • was created only to receive and transfer funds; or
  • misrepresented its merchant category or business model.

A newly incorporated, low-turnover or home-based business is not automatically a shell merchant. Commercial substance and actual activity must be tested through records.

Merchant Laundering and Undisclosed Sub-Merchants

Payment or transaction laundering may be alleged where:

  • one approved merchant processes payments for another undisclosed business;
  • a legitimate merchant ID is used for prohibited or fraudulent activity;
  • the website presented during onboarding differs from the actual business;
  • payments are generated through undisclosed sub-merchants;
  • the merchant category is false or misleading;
  • the settlement beneficiary is changed after onboarding;
  • the merchant sells services different from those approved;
  • API credentials are shared with another person; or
  • a master-merchant arrangement conceals the ultimate seller.

RBI Merchant-Onboarding Requirements

RBI’s payment-aggregator framework requires a Board-approved merchant-onboarding policy.

The payment aggregator is expected to undertake background and antecedent checks so that merchants:

  • do not have a mala fide intention to dupe customers;
  • do not sell fake or counterfeit products;
  • do not sell prohibited products or services;
  • disclose clear terms and conditions;
  • provide return and refund timelines; and
  • maintain the required security standards.

A merchant-onboarding file may include:

  • certificate of incorporation or registration;
  • constitutional documents;
  • PAN and GST records;
  • director, partner or proprietor KYC;
  • beneficial-owner declaration;
  • bank-account verification;
  • cancelled cheque or bank confirmation;
  • website and application review;
  • domain-ownership details;
  • licence or regulatory-registration verification;
  • business-model description;
  • expected transaction volume;
  • average transaction value;
  • refund and chargeback profile;
  • merchant-category classification;
  • physical or video verification where applicable;
  • adverse-media and antecedent checks;
  • merchant agreement;
  • sub-merchant disclosures; and
  • periodic review records.

Does Defective Merchant KYC Automatically Establish Money Laundering?

No.

Weak, incomplete or negligent merchant onboarding may result in:

  • regulatory action;
  • contractual liability;
  • compliance findings;
  • enhanced scrutiny;
  • account restrictions;
  • civil claims;
  • evidentiary inferences; or
  • investigation of responsible officers.

A PMLA allegation against the payment intermediary should still establish the required connection with proceeds of crime and the person-specific conduct contemplated by Section 3 or Section 70.

Regulatory non-compliance and criminal money laundering are not legally identical.

Payment Aggregator Escrow Accounts

RBI requires non-bank payment aggregators to maintain customer collections in an escrow account with a scheduled commercial bank.

The regulatory structure is intended to:

  • segregate collected funds;
  • facilitate merchant settlement;
  • process refunds and reversals;
  • maintain sufficient balance for merchant dues;
  • limit permitted credits and debits;
  • prevent use of collected funds for unrelated business; and
  • permit reconciliation and audit.

Settlement funds should not be co-mingled with an unrelated business of the payment aggregator.

The aggregator is also required to provide the escrow bank with the merchant list and keep that information updated.

Why Can an Escrow Account Be Frozen?

ED may allege that a portion of an escrow balance represents:

  • unsettled investor funds;
  • merchant settlements due to alleged shell entities;
  • refund amounts connected with fraudulent transactions;
  • funds awaiting onward transfer;
  • commission derived from the alleged activity; or
  • property relevant to tracing the proceeds of crime.

The presence of suspected funds does not automatically mean that the entire pooled balance belongs to the accused.

An escrow-freezing review should separately identify:

  • suspected merchant transactions;
  • innocent merchants;
  • customer refunds;
  • chargebacks;
  • payment-aggregator fees;
  • tax deductions;
  • bank reversals;
  • pre-funded merchant balances;
  • funds received after the alleged period;
  • unrelated business receipts; and
  • the exact amount alleged as proceeds of crime.

Escrow Reconciliation Matrix

PAYMENT AGGREGATOR ESCROW RECONCILIATION

Escrow Bank:
Account:
Relevant Period:
Opening Balance:
Closing Balance:

Merchant ID:
Merchant Legal Name:
Merchant Website / Application:
Settlement Bank Account:
Beneficial Owner:
Transaction Count:
Gross Customer Collections:
Refunds:
Reversals:
Chargebacks:
Aggregator Fee:
Taxes:
Reserve / Holdback:
Net Settlement Due:
Settlement Completed:
Amount Frozen:
Amount Alleged as Proceeds of Crime:
Innocent Third-Party Amount:
Supporting Documents:
Required Legal Relief:

Reporting-Entity and AML Obligations

The PMLA defines a financial institution to include a payment system operator, and a reporting entity includes a financial institution.

The exact status of an entity should be assessed from:

  • its RBI authorisation;
  • its function under the Payment and Settlement Systems Act;
  • whether it operates a payment system;
  • whether it handles funds;
  • its domestic or cross-border model;
  • its contracts with banks and merchants;
  • its FIU-IND registration; and
  • the actual services provided.

Relevant reporting-entity obligations may include:

  • verification of client identity;
  • identification of beneficial owners;
  • maintenance of transaction records;
  • ongoing monitoring;
  • enhanced due diligence for higher-risk transactions;
  • recording the purpose and intended nature of transactions;
  • reporting prescribed transactions to FIU-IND;
  • preserving records for the statutory period; and
  • responding to lawful information requests.

Read the PMLA Provisions concerning Reporting Entities

Payment Aggregator-Cross Border

RBI’s cross-border payment-aggregator framework regulates entities facilitating online import and export payments.

Relevant requirements include:

  • appropriate RBI authorisation or approval;
  • FIU-IND registration for applicable non-bank entities;
  • merchant customer due diligence;
  • import and export collection accounts;
  • compliance with permissible goods and services requirements;
  • foreign-exchange compliance;
  • transaction monitoring;
  • beneficial-ownership review; and
  • record maintenance.

Read RBI Regulation of Payment Aggregator-Cross Border

How ED Reconstructs the Investor Money Trail

The ED may prepare a transaction-level chain beginning with the victim and ending with the alleged beneficiary.

The investigation may collect:

  • victim bank statements;
  • UPI transaction references;
  • virtual payment addresses;
  • merchant IDs;
  • payment-link IDs;
  • gateway transaction IDs;
  • aggregator settlement reports;
  • escrow-account statements;
  • merchant ledgers;
  • acquiring-bank records;
  • refund and chargeback data;
  • beneficiary-bank statements;
  • subsequent transfers;
  • cash withdrawals;
  • cryptocurrency-exchange records;
  • blockchain addresses;
  • foreign-remittance data;
  • device and IP logs;
  • merchant-dashboard access logs; and
  • communications directing the movement of money.

Payment-Trail Matrix

ONLINE INVESTMENT FRAUD — PAYMENT-TRAIL MATRIX

Victim:
Date:
Amount:
Payment Method:
Bank / Card / UPI:
UTR / Reference:
UPI ID:
Payment Link:
Gateway Transaction ID:
Merchant ID:
Displayed Merchant Name:
Legal Merchant Name:
Merchant Beneficial Owner:
Aggregator:
Gateway:
Acquiring Bank:
Escrow Account:
Settlement Date:
Settlement Amount:
Settlement Bank Account:
Immediate Next Transfer:
Second-Layer Account:
Cash Withdrawal:
Crypto Purchase:
Foreign Transfer:
Asset Purchased:
Ultimate Beneficiary Alleged:
Defence Explanation:
Supporting Record:

Transaction Patterns That May Trigger Scrutiny

  • high transaction volume immediately after merchant onboarding;
  • activity inconsistent with the merchant’s declared business;
  • thousands of unrelated individual payers;
  • multiple payments with investment-related narration;
  • rapid settlement followed by immediate onward transfer;
  • settlements to accounts different from verified merchant accounts;
  • repeated requests to change settlement beneficiaries;
  • high refund or complaint rates;
  • blocked refunds;
  • large transaction spikes after long inactivity;
  • common directors across several merchants;
  • common mobile numbers, emails, IP addresses or premises;
  • multiple merchants controlled through one dashboard;
  • merchant websites that disappear after onboarding;
  • payments for financial products without appropriate registration;
  • funds routed to crypto exchanges;
  • payments divided across several merchant IDs;
  • round-number settlements;
  • same-day transfers through multiple entities; and
  • customer complaints describing the same false investment representation.

These are indicators requiring investigation. They do not, individually or collectively, prove guilt without reliable evidence and person-specific attribution.

Fake Profits and Cycling Back Investor Funds

Some fraudulent schemes allegedly return a limited portion of newly collected funds to earlier investors.

The return may be described as:

  • profit;
  • daily income;
  • commission;
  • successful withdrawal;
  • referral bonus;
  • trading gain;
  • mining income; or
  • promotional reward.

The purpose may be alleged to be:

  • creating confidence;
  • encouraging larger deposits;
  • generating favourable testimonials;
  • demonstrating false liquidity;
  • delaying complaints; and
  • attracting new participants.

Beneficial Ownership of a Merchant Account

The legal owner appearing in payment-platform records may not be the person exercising actual control.

ED may examine:

  • who funded incorporation;
  • who selected the proprietor or directors;
  • who supplied onboarding documents;
  • who created the website;
  • who controlled the merchant dashboard;
  • who generated payment links;
  • who changed settlement details;
  • who possessed the registered mobile number;
  • who controlled email and domain access;
  • who communicated with the payment aggregator;
  • who received the settlement funds;
  • who directed onward transfers;
  • who retained commissions; and
  • who ultimately enjoyed the funds or assets.

Merchant Beneficial-Ownership Matrix

MERCHANT AND BENEFICIAL-OWNER REVIEW

Merchant Legal Name:
Merchant ID:
Entity Type:
Incorporation / Registration:
Declared Business:
Actual Business:
Website:
Application:
Registered Address:
Operational Address:

Proprietor / Directors:
Shareholders:
Significant Beneficial Owner:
Bank KYC Beneficial Owner:
Settlement Account Holder:
Authorised Signatory:
Registered Mobile Number:
Registered Email:
Domain Owner:
Dashboard Administrator:
API Key Controller:
Payment-Link Creator:
Person Communicating with Aggregator:
Person Directing Settlements:
Person Receiving Economic Benefit:

Discrepancy:
Explanation:
Documents Required:
PMLA Risk:

Records Commonly Sought from a Payment Aggregator or Gateway

Merchant-Onboarding Records

  • application form;
  • KYC records;
  • beneficial-owner declaration;
  • merchant agreement;
  • bank verification;
  • business-model note;
  • website-review report;
  • licence-verification report;
  • antecedent check;
  • risk classification;
  • expected transaction profile;
  • merchant-category code;
  • sub-merchant details;
  • physical or video verification;
  • approval notes; and
  • periodic review records.

Transaction and Settlement Records

  • transaction-level data;
  • payment instrument;
  • UTR and gateway reference;
  • merchant and sub-merchant ID;
  • escrow credits;
  • settlement statements;
  • settlement beneficiary changes;
  • refund records;
  • chargeback records;
  • reserve and holdback records;
  • commission and fee records;
  • failed transaction reports;
  • reconciliation reports;
  • inter-escrow transfers; and
  • banker and auditor certificates.

Monitoring and Complaint Records

  • risk alerts;
  • velocity alerts;
  • fraud-rule triggers;
  • manual-review notes;
  • customer complaints;
  • merchant explanations;
  • refund complaints;
  • account-suspension decisions;
  • settlement-hold decisions;
  • escalation emails;
  • regulatory reports;
  • suspicious transaction reporting records;
  • law-enforcement notices; and
  • action taken after each alert.

Digital and Access Records

  • merchant-dashboard logs;
  • IP addresses;
  • device identifiers;
  • API credentials;
  • login timestamps;
  • password-reset records;
  • registered mobile and email changes;
  • webhook and callback logs;
  • payment-link generation records;
  • administrator actions;
  • data exports;
  • settlement-account modification logs;
  • customer-support tickets;
  • internal chats; and
  • employee-access logs.

Digital Evidence in a Fintech Investigation

Digital evidence may demonstrate:

  • who controlled the fake application;
  • who accessed merchant dashboards;
  • which devices generated payment links;
  • who changed settlement accounts;
  • which employees approved merchants;
  • whether multiple merchants were controlled from one IP address;
  • whether transaction alerts were overridden;
  • who directed release of held settlements;
  • whether customer complaints were suppressed;
  • who communicated with alleged scheme operators;
  • whether merchant credentials were compromised; and
  • whether evidence was altered after the investigation began.

Attribution should not be based only on the existence of an IP address or device record. Shared networks, remote access, compromised credentials and third-party service providers must be examined.

Section 50 Summons to a Payment Company

ED may summon:

  • promoters;
  • directors;
  • chief executive officers;
  • chief financial officers;
  • chief compliance officers;
  • principal officers;
  • AML and transaction-monitoring personnel;
  • merchant-onboarding officers;
  • risk analysts;
  • nodal officers;
  • technology and data custodians;
  • settlement and reconciliation teams;
  • bank relationship managers;
  • internal auditors;
  • statutory auditors;
  • merchant representatives; and
  • persons controlling beneficiary accounts.

The statement should be prepared according to the person’s actual function.

A compliance officer should not guess technical issues. A technology officer should not speculate about a merchant’s beneficial ownership. A director should not adopt a common statement inconsistent with the actual delegation of responsibility.

Questions Commonly Asked by ED

  • What was the entity’s RBI status?
  • Was it acting as an aggregator, gateway or both?
  • Did it handle or control funds?
  • Who onboarded the merchant?
  • What KYC and beneficial-ownership checks were completed?
  • Was the merchant’s business regulated by SEBI or another authority?
  • Was the website or application verified?
  • What transaction profile was declared?
  • When did transaction volume increase?
  • How many customer complaints were received?
  • Were settlements held after alerts?
  • Who authorised continued processing?
  • Were settlement accounts changed?
  • Were payments made to third parties?
  • Were sub-merchants disclosed?
  • Who controlled the dashboard and API credentials?
  • What funds remained in escrow?
  • What amount was paid as fees or commission?
  • Were suspicious transactions reported?
  • Who was the ultimate beneficial owner?

Section 17 Search, Seizure and Freezing

Where the statutory conditions are satisfied, ED may search fintech offices or related premises and seize or freeze:

  • merchant-onboarding files;
  • computers and mobile devices;
  • servers and databases;
  • payment-system logs;
  • settlement and escrow records;
  • emails and internal chats;
  • KYC and beneficial-owner records;
  • bank statements;
  • company records;
  • merchant agreements;
  • risk-alert records;
  • cryptocurrency-wallet information;
  • cash or property documents; and
  • accounts containing suspected proceeds of crime.

The legality and scope of freezing should be assessed account by account and amount by amount.

Search and Freezing Response Checklist

  • Verify the identity and authority of officers.
  • Record the beginning and conclusion time.
  • Identify every premise searched.
  • Preserve the search authorisation details available lawfully.
  • Maintain a list of devices and records accessed.
  • Review the panchnama before signing.
  • Record objections accurately.
  • Obtain copies of seizure or freezing documents.
  • Identify privileged or unrelated material.
  • Preserve business-continuity data lawfully.
  • Issue an immediate document-preservation notice.
  • Do not delete, alter or reconstruct records.
  • Prepare merchant-wise escrow reconciliation.
  • Identify innocent customer and merchant funds.
  • Assess the Section 17(4) and adjudication process.

Provisional Attachment under Section 5

ED may provisionally attach property where the statutory requirements are alleged to be satisfied.

In a fintech-investment-fraud matter, the property may include:

  • bank balances;
  • escrow balances;
  • merchant receivables;
  • payment-company commissions;
  • shares in fintech or merchant entities;
  • cryptocurrency;
  • immovable property;
  • vehicles;
  • investments;
  • property purchased through shell entities; or
  • equivalent-value assets.

The attachment response should examine:

  • the scheduled offence;
  • the identified investor losses;
  • the alleged proceeds of crime;
  • merchant-wise attribution;
  • ownership of the attached property;
  • date and source of acquisition;
  • legitimate pooled funds;
  • third-party and creditor interests;
  • customer refund obligations;
  • the payment company’s fee component;
  • beneficial ownership;
  • equivalent-value reasoning;
  • valuation; and
  • proportionality.

Can the Entire Payment Gateway Balance Be Treated as Proceeds of Crime?

Not automatically.

The investigation should distinguish:

  • fraud-linked customer payments;
  • legitimate merchant collections;
  • amounts already refunded;
  • chargeback reserves;
  • payments due to innocent merchants;
  • statutory taxes;
  • bank reversals;
  • the intermediary’s lawful contractual fees;
  • funds preceding the alleged fraud; and
  • funds received after processing was stopped.

A pooled account presents tracing difficulty. It does not eliminate the need for a reasoned and evidence-based attribution.

When Can a Payment Aggregator or Gateway Face PMLA Exposure?

Risk may arise where evidence allegedly demonstrates that the entity or its responsible officers:

  • knowingly onboarded sham merchants;
  • accepted false KYC with awareness of its falsity;
  • permitted undisclosed sub-merchants;
  • continued processing after clear fraud alerts;
  • released settlements after receiving specific complaints or notices;
  • facilitated third-party settlement contrary to the approved structure;
  • helped create merchant layers to conceal the beneficiary;
  • shared or sold merchant IDs for fraudulent collections;
  • controlled shell merchants;
  • received an abnormal benefit linked to the activity;
  • altered records to conceal transactions;
  • assisted conversion into cryptocurrency or foreign remittances;
  • knowingly became a party to the laundering process; or
  • actually participated in possession, use, concealment or projection of the alleged proceeds.

When May a Payment Intermediary Have a Strong Defence?

Relevant defence factors may include:

  • valid RBI authorisation or applicable regulatory status;
  • clear separation between gateway and aggregator functions;
  • complete merchant KYC;
  • accurate beneficial-owner verification;
  • independent bank-account verification;
  • website and licence checks;
  • risk-based merchant classification;
  • transaction monitoring;
  • timely settlement holds;
  • prompt merchant suspension;
  • cooperation with banks and law enforcement;
  • filing of required reports;
  • preservation and supply of records;
  • absence of personal benefit;
  • ordinary and pre-agreed commercial fees;
  • no control over the merchant’s fraudulent representations;
  • no knowledge of the scheduled offence;
  • evidence of credential compromise or merchant deception;
  • documented escalation by responsible officers; and
  • effective due diligence and compliance controls.

Regulatory Breach versus Section 3 PMLA

The following distinctions should be maintained:

Regulatory or Operational Issue PMLA Criminal Inquiry
Incomplete merchant KYC Whether the deficiency was knowing and connected with handling or concealing proceeds of crime
Delayed merchant review Whether the responsible person knowingly permitted continued laundering activity
Escrow reconciliation error Whether funds were deliberately diverted, concealed or projected as legitimate
High fraud or chargeback rate Whether alerts established knowledge and person-specific participation
Technology vulnerability Whether the system was compromised or intentionally provided for fraudulent use
Incorrect merchant category Whether the classification was an error or a deliberate device to disguise the true business
Failure to stop one merchant promptly Whether the omission amounts to negligence, consent, connivance or knowing assistance on the evidence

Section 70: Offences by Companies

Where an alleged contravention occurs through a company, Section 70 may bring within scrutiny:

  • the company;
  • the person in charge of and responsible for its business;
  • directors;
  • managers;
  • secretaries;
  • compliance officers; and
  • other officers whose consent, connivance or attributable neglect is alleged.

The provision recognises the relevance of:

  • lack of knowledge; and
  • due diligence exercised to prevent the contravention.

Every director or employee is not automatically liable.

Read Section 70 PMLA

Individual-Role Matrix for Fintech Officers

FINTECH OFFICER — INDIVIDUAL PMLA ROLE REVIEW

Name:
Designation:
Period of Office:
Department:
Board Role:
Merchant-Onboarding Role:
KYC Approval Authority:
Transaction-Monitoring Role:
Settlement Authority:
Escrow Access:
Dashboard Access:
Data Access:
Merchant Suspension Authority:
Reports Received:
Complaints Received:
Alerts Escalated:
Instructions Given:
Documents Signed:
Communications with Merchant:
Personal Benefit:
Knowledge Alleged:
Consent Alleged:
Connivance Alleged:
Neglect Alleged:
Due-Diligence Steps:
Contradictory Evidence:
Immediate Legal Risk:

Arrest under Section 19

A director or officer cannot lawfully be arrested merely because:

  • the company processed the payment;
  • the merchant committed fraud;
  • the person held a senior designation;
  • KYC was imperfect;
  • the account was frozen;
  • an ECIR was recorded;
  • the person was summoned; or
  • the investigation remains incomplete.

Section 19 requires material in possession and a written reason to believe that the particular person is guilty of the PMLA offence.

The officer’s individual knowledge, participation, control, benefit and conduct must be examined.

Bail under Section 45

A fintech officer’s bail application should address:

  • the exact scheduled offence;
  • the identified proceeds of crime;
  • the officer’s individual role;
  • the distinction between regulatory failure and knowing laundering;
  • merchant deception of the payment company;
  • due-diligence records;
  • absence of personal benefit;
  • ordinary commercial fees;
  • records already secured;
  • documentary nature of the case;
  • cooperation with summons;
  • lack of control over merchant funds after settlement;
  • absence of criminal antecedents;
  • conditions capable of preventing future risk;
  • custody period;
  • trial delay; and
  • parity with other participants.

Recent Official ED Investigation Patterns

Official ED press releases issued during 2026 have described allegations involving:

  • fake investment applications promoted through social-media and messaging groups;
  • artificial display of profits;
  • additional tax or fee demands when withdrawal was attempted;
  • mule bank accounts and shell entities;
  • payment-gateway companies and merchant accounts;
  • common directors, premises and financial linkages;
  • multiple UPI IDs;
  • cycling a small portion of funds back to investors;
  • cryptocurrency wallets and cross-border operators;
  • freezing of multiple bank accounts; and
  • prosecution complaints involving fintech intermediaries and merchant entities.

These are allegations in ongoing or filed enforcement proceedings. They do not establish guilt against every entity or person referred to in the press releases.

ED Press Release dated 15 June 2026 — Online Investment Fraud

ED Press Release dated 17 March 2026 — HPZ Token Investment Scam

ED Press Release dated 9 May 2026 — Global Media App Fraud

Immediate Steps for an Investment-Fraud Victim

  1. Call 1930 immediately: Speed is critical because funds may move through several accounts within minutes.
  2. Complete the NCRP complaint: Use the acknowledgement number to complete the complaint on the cybercrime portal.
  3. Notify the bank: Request fraud marking, recall and beneficiary-bank escalation.
  4. Notify the payment intermediary: Provide the payment reference, merchant name, merchant ID and fraud details.
  5. Preserve evidence: Save applications, APK files, websites, chats, advertisements, call recordings and payment records.
  6. Do not pay further fees: Additional tax, verification or withdrawal charges may be part of the fraud.
  7. File a detailed police complaint: Identify every transaction and representation.
  8. Verify regulatory claims: Check SEBI or other regulator registrations independently.
  9. Track freezing status: Obtain information through the investigating agency according to law.
  10. Prepare a quantified loss file: Distinguish actual payments from fake profits displayed by the application.

National Cybercrime Reporting Portal

Evidence That a Victim Should Preserve

  • bank statements;
  • UPI and transaction references;
  • beneficiary account numbers;
  • merchant names displayed at payment;
  • gateway transaction IDs;
  • payment links;
  • QR codes;
  • screenshots of the fake dashboard;
  • withdrawal requests;
  • withdrawal rejection messages;
  • tax and fee demands;
  • WhatsApp and Telegram chats;
  • social-media advertisements;
  • group invitations;
  • phone numbers;
  • email addresses;
  • website URLs;
  • APK or application files;
  • app-store listing;
  • fake registration certificates;
  • call recordings;
  • cryptocurrency-wallet addresses;
  • exchange transaction records;
  • identity documents supplied to the fraudsters; and
  • 1930 and NCRP acknowledgement details.

Victim-Loss Matrix

ONLINE INVESTMENT FRAUD — VICTIM LOSS MATRIX

Victim:
Police / NCRP Complaint:
1930 Acknowledgement:
Application / Website:
Social-Media Group:
Represented Investment:
Represented Adviser / Broker:

Transaction 1:
Date:
Amount:
Mode:
UTR:
Beneficiary:
Merchant Name:
Payment Gateway:
Merchant ID:

Transaction 2:
Date:
Amount:
Mode:
UTR:
Beneficiary:
Merchant Name:
Payment Gateway:
Merchant ID:

Total Actual Amount Paid:
Amount Actually Withdrawn:
Net Quantifiable Loss:
Fake Profit Displayed:
Additional Fee Demanded:
Accounts Reported:
Accounts Frozen:
Property Attached:
Claim Submitted:
Supporting Evidence:
Immediate Legal Step:

Can Victims Recover Money through PMLA Proceedings?

PMLA provides for confiscation and, subject to the statutory conditions, restoration of confiscated or attached property to a claimant having a legitimate interest and a quantifiable loss.

A victim may need to establish:

  • identity;
  • actual payment;
  • transaction reference;
  • connection with the fraudulent scheme;
  • quantifiable loss;
  • good faith;
  • reasonable precautions;
  • absence of involvement in money laundering;
  • connection between the claimed property and the loss; and
  • compliance with the applicable restoration procedure.

Restoration is not automatic merely because the victim filed a complaint.

Claims by Innocent Merchants and Third Parties

A legitimate merchant may be affected where a pooled escrow or settlement account is frozen.

The merchant should prepare:

  • merchant agreement;
  • KYC and beneficial-owner documents;
  • proof of genuine business;
  • customer invoices;
  • delivery or service evidence;
  • transaction-level reconciliation;
  • refund and chargeback records;
  • tax records;
  • settlement reports;
  • proof that its customers are unrelated to the fraud;
  • source and ownership of the withheld balance;
  • employee and operational records; and
  • a precise amount claimed for release.

A general assertion that the funds are legitimate may be insufficient where the account is pooled.

Fintech Internal Investigation after a Fraud Alert

A regulated or responsible fintech entity should consider an immediate internal review covering:

  • merchant onboarding;
  • beneficial ownership;
  • website and application verification;
  • transaction profile;
  • risk alerts;
  • customer complaints;
  • refund and chargeback data;
  • settlement beneficiary changes;
  • employee approvals;
  • dashboard and API access;
  • sub-merchant activity;
  • bank and escrow reconciliation;
  • law-enforcement communications;
  • FIU and regulatory reporting;
  • data preservation;
  • conflict of interest;
  • employee collusion; and
  • remedial measures.

Legal Hold and Data Preservation

After becoming aware of an investigation or credible fraud allegation, no person should:

  • delete transaction logs;
  • alter merchant KYC;
  • backdate due-diligence reports;
  • manufacture website-verification records;
  • change risk-alert histories;
  • remove internal messages;
  • overwrite dashboard-access logs;
  • destroy devices;
  • close accounts to conceal the trail;
  • transfer funds to avoid freezing;
  • coach employees to adopt a false common account; or
  • create documents that did not exist during onboarding.

Missing records should be addressed honestly through retention policies, custodian statements, backup searches and alternative evidence.

Fintech PMLA Response File

FINTECH / PAYMENT INTERMEDIARY — PMLA RESPONSE FILE

Entity:
RBI Status:
FIU Registration:
Domestic PA:
Payment Gateway:
PA-CB:
Bank Partner:
Escrow Bank:
Principal Officer:
Nodal Officer:

Merchant:
Merchant ID:
Onboarding Date:
Declared Business:
Actual Business:
KYC Completed:
Beneficial Owner Verified:
Bank Account Verified:
Website Verified:
Regulatory Licence Verified:
Risk Category:
Expected Volume:
Actual Volume:
First Alert:
First Complaint:
Settlement Hold:
Merchant Suspended:
Law Enforcement Notified:
FIU Report:
Funds in Escrow:
Funds Settled:
Refunds:
Chargebacks:
Fees Earned:

Officer Responsible:
Individual Role:
Knowledge Alleged:
Due Diligence:
Contradictory Evidence:
Immediate Legal Remedy:

Common Mistakes by Payment Companies

  • Treating every entity as a technology-only gateway despite handling funds.
  • Failing to verify the merchant’s actual business.
  • Relying only on incorporation and GST documents.
  • Ignoring whether the investment activity required regulatory registration.
  • Failing to identify the ultimate beneficial owner.
  • Permitting settlement to an unrelated account.
  • Allowing undisclosed sub-merchants.
  • Ignoring transaction volume inconsistent with the declared profile.
  • Failing to review sudden complaint spikes.
  • Releasing held funds without documented approval.
  • Failing to preserve merchant dashboard logs.
  • Giving one common statement for employees with different functions.
  • Describing regulatory compliance as complete without supporting records.
  • Failing to separate innocent merchant balances.
  • Failing to reconcile the escrow account transaction by transaction.
  • Assuming that ordinary commercial fees can never be scrutinised.
  • Assuming that defective KYC automatically proves money laundering.
  • Deleting or reconstructing records after receiving a summons.
  • Failing to distinguish negligence from knowing assistance.
  • Ignoring the individual requirements of Sections 3, 19, 45 and 70.

Common Mistakes by Victims

  • Waiting several days before calling 1930.
  • Paying additional tax or release charges.
  • Deleting the application or chats.
  • Reporting only the final payment.
  • Failing to provide UTR and beneficiary details.
  • Claiming fake dashboard profits as actual financial loss.
  • Continuing communication with a fake recovery agent.
  • Sharing further identity documents or OTPs.
  • Failing to notify the bank and payment intermediary.
  • Investing further to recover the earlier loss.
  • Relying on a social-media group’s alleged SEBI registration.
  • Ignoring payments made to unrelated third-party accounts.
  • Failing to preserve the APK or website URL.
  • Filing inconsistent complaints before different authorities.
  • Expecting immediate restoration merely because an account was frozen.

Frequently Asked Questions

What is the difference between a payment aggregator and a payment gateway?

A payment aggregator receives, pools and settles customer funds to merchants. A payment gateway ordinarily provides technological routing infrastructure without handling the funds.

Can a payment gateway be investigated under PMLA?

Yes. It may possess relevant transaction and digital evidence, and it may be investigated where its actual conduct allegedly connects it with the proceeds of crime. Investigation does not itself establish guilt.

Is every payment aggregator a reporting entity?

The entity’s status should be examined from the PMLA definitions, its payment-system function, RBI authorisation, FIU registration and actual business model. Overbroad assumptions should be avoided.

Does a payment gateway become liable whenever a merchant commits fraud?

No. Liability depends on the intermediary’s actual role, knowledge, conduct, controls, benefit and connection with the alleged proceeds of crime.

Does incomplete merchant KYC prove money laundering?

No. It may establish a regulatory or compliance issue. A PMLA offence requires the statutory connection with proceeds of crime and the required person-specific participation.

Why does ED examine payment-gateway logs?

Logs can identify merchant IDs, payment links, IP addresses, devices, settlement changes, dashboard controllers and the movement of funds.

What is merchant laundering?

It commonly refers to processing payments for an undisclosed or misrepresented business through a merchant account approved for another purpose.

What is a mule merchant?

It is an entity or merchant account allegedly used to collect or transfer money for another person, often without genuine business corresponding to the payment description.

Can the entire escrow account be frozen?

An account may be frozen under the statutory framework, but the affected parties may challenge the scope and demonstrate innocent merchant funds, refunds, chargebacks and unrelated balances.

Are all funds in a payment-aggregator escrow account proceeds of crime?

No. The account may contain funds belonging to multiple merchants and customers. Transaction-level attribution is essential.

Can an innocent merchant seek release of its settlement?

Potentially yes. The merchant should establish genuine business, transaction-level ownership and the precise amount unrelated to the alleged fraud before the competent authority or court.

Can a fintech director be arrested because of designation?

No. Section 19 requires material and a written reason to believe concerning the particular person’s guilt. Designation alone is insufficient.

Can a compliance officer face investigation?

Yes, where the officer’s actions, alerts, approvals or alleged omissions are relevant. Liability remains person-specific and depends on knowledge, responsibility and due diligence.

Can ordinary gateway fees be attached?

The ED may scrutinise whether fees are legitimate commercial income or property connected with the alleged laundering activity. The contractual basis, rate and knowledge of the intermediary are relevant.

Does use of cryptocurrency automatically establish PMLA?

No. Cryptocurrency may be a payment or transfer method. The investigation must still establish proceeds of crime and the person’s conduct under Section 3.

What should a victim do immediately?

Call 1930, complete the cybercrime portal complaint, notify the bank and payment intermediary and preserve every payment and communication record.

Should a victim pay tax to release fake trading profits?

No payment should be made merely because an unverified application dem