NEWS
The Mahape Apple Scam Raid Left the Owners Free
Navi Mumbai police took 13 people off a fake Apple Support floor in Mahape, while the owners, cash-out men, and irreversible USDT payments remain outside the van.
Navi Mumbai cyber police took 13 people off a rented IT-park floor that posed as Apple Support and as U.S. banks. The Thursday night raid hit TradeXpert Services at Unit 24, Millennium Business Park, Mahape, after a tip about a fake Apple support call centre that was working the United States on the night shift.
The people in custody ran the phones. The couple who leased the office, and the men who turned panic into USDT and Apple gift cards, were not in the building.
Police Walked Into Unit 24 After Dark
Newsband, the local English daily, said a team led by ACP Vishal Hire and Senior Inspector Vishal Patil of the Navi Mumbai Cyber police station went in around 11 pm on August 13. Nine agents sat at computers reading English scripts to callers in the United States. Four others were supervising, police said.
The Times of India named the shift bosses as Parth Bharatbhai Patel, 27, of Ghansoli, described as a partner and manager; Jobin Jacob Balumal, 28, of Powai, a team leader who used the name John on the line; Naeem Haroon Rashid Sheikh, 41, of Panvel, who used the name Tom; and Sameer Farid Sheikh, 31, of Thane, also a team leader. Hindustan Times later reported that the nine floor agents were arrested with them, bringing the total to 13.
Patil told the Times of India the office had no licence. Patel, under questioning, said he and his partner Mustafa Khan, a resident of Mumbra, had run the Apple night shift since May 2026. Police seized six phones, 255 Vodafone Idea SIM cards, two SIM boxes, two servers, two CPUs, a laptop, nine cheque books, and printed scripts.
- May 2026: Patel and Khan begin the night-shift Apple floor in Mahape, police said.
- May 6 to June 6, 2026: WhatsApp on a call-centre phone logs 5,301 USDT taken in, the FIR says.
- August 13, 2026: Police raid Unit 24 around 11 pm and take 13 people into custody.
The SIM boxes and the 255 company SIMs are the part of the kit that makes a rented cubicle look, to a frightened caller in Ohio or Florida, like a help desk on the other end of an Apple or bank number.

Five Names Are Still Missing
The FIR, as reported by Hindustan Times, says the alleged masterminds remain absconding. Police have opened a search for Mustafa Khan; his wife, Zareen; Purvank Shrimali, alias KR; a man identified as Iggy; and a man identified as Sheikh Bhai.
WHAT WE KNOW
- The floor: Thirteen people, the manager, three team leaders, and nine agents, are in custody after the Unit 24 raid.
- The owners: Patel told police he and Mustafa Khan had run the Apple night shift from May 2026, and that Zareen handled admin on both shifts.
- The second product: Police said Mustafa and Zareen were also running an illegal stock-trading call centre from the same operation.
- The cash men: Police said Iggy and Sheikh moved large sums to Khan through USDT TRON QR codes and Apple gift vouchers taken from U.S. callers.
WHAT IS UNCONFIRMED
- The full take: The Rs 5.03 lakh figure on 5,301 USDT is one month of chat logs, and police said the book will grow as devices are read.
- Where the five are: As of the August 19 Hindustan Times account of the FIR, none of the five named absconders had been found.
The nine agents police listed live in Palghar, Kandivli, Nalasopara, Badlapur, Mira Bhayandar, Thane, and Kurla. They look like hired commuters on a night roster. Mustafa is described as the Mumbra partner who sent the bait texts, and Zareen as the person who kept the office running after sunrise. That split, floor staff in the van and owners still named in the FIR as missing, is the part of these raids that keeps repeating across Navi Mumbai’s IT parks.
The $499 Text and a Virus Called CHAMPI
According to the FIR, Khan would push a message onto Apple phones in the United States claiming that $499 (about Rs 47,000) had just come out of a bank account. The text gave a number to call if the charge was not theirs. When the owner called, the number rang into Mahape.
THE PITCH ON THE LINE
- The bait: A $499 debit text on an Apple phone, with a number to call if the charge is wrong.
- The Apple desk: An agent poses as tech support and says a virus named CHAMPI is on the phone and has opened the bank account to thieves.
- The banker: The call is passed to a team leader using a fake American name, who says the balance must move to a “secure” account.
- The QR code: Agents send a crypto wallet code and press the caller to transfer the money.
- The fallback: If the caller refuses, they are told to buy a gift card of the same value and read out the 16-digit number. Team leaders also took card numbers, expiry dates, and CVVs to buy the cards themselves, the FIR says.
Hindustan Times said scripts on the office computers told agents how to hold an American accent, and that an application named in the FIR as Microsipe was used to take the inbound U.S. calls. Times of India said the gift cards were referred to on the floor as “Apple for Everything.” The scare was technical enough to sound like a real support queue and crude enough to end in a card number or a QR code.
Gift Cards and USDT Leave No Refund
Police put about Rs 5.03 lakh on 5,301 USDT logged in WhatsApp between May 6 and June 6, Hindustan Times reported. Newsband described that same figure as cryptocurrency seized in the raid. Either way, it is one month of stablecoin, not a closed victim list, and Patil told the Times of India the rupee total is likely to rise as the machines are examined.
That payment mix is the point of the floor. A U.S. bank can often claw back a card charge. It cannot claw back a spent Apple gift card, and it cannot freeze a USDT transfer on TRON once the QR code has been paid. The Federal Trade Commission, in its March 2025 release of 2024 data, said Americans reported more than $12.5 billion lost to fraud and $2.95 billion reported lost to imposters, the second-highest loss category after investment scams. In that year, the FTC said, losses paid by bank transfer or cryptocurrency exceeded all other payment methods combined.
Phone calls were the second most common way scammers first reached people, after email. Imposter scams, which include someone pretending to be a well-known business or a technical support expert, were the most reported fraud type in the 2.6 million fraud reports the FTC took in. Christopher Mufarrige, director of the FTC’s Bureau of Consumer Protection, said the figures show “scammers’ tactics are constantly evolving.”
Apple’s own rule is blunt. Its support pages tell customers they should never use Apple gift cards to pay other people, and they should treat an unexpected request for a 16-digit number as a scam involving Apple gift cards. Contact Apple Support, the page says, if you think you already handed one over. By the time a Mahape agent has the digits, the value has usually been drained.
What Apple Tells People to Do Instead
Apple publishes a plain instruction for the exact call this floor was making. Do not answer an unsolicited person who claims to be Apple Support. Hang up, then reach the company through its own listed channels. Apple says it will never ask for a password, a device passcode, or a two-factor code to give support, and it will never ask you to switch those protections off.
If you get an unsolicited or suspicious phone call from someone claiming to be from Apple or Apple Support, just hang up.
Apple Support, official guidance on phony support calls
The same page, on phony support calls and other scams, says scammers spoof Caller ID, invent an urgent problem such as a fake Apple Pay charge, and then push for money or gift cards before the person on the line has time to think. That is the Unit 24 script with a local virus name bolted on. Report the call, Apple says, at ReportFraud.ftc.gov or to local police.
The people this pitch is built for are often older. In a May 2026 account, the FBI described an investigation of a fraudulent call center in India in which Special Agent Ron Miller found a woman in her 70s who had already sent more than $500,000 in cash, wires, and gift cards. The FBI’s 2025 Internet Crime Complaint Center report, cited in that piece, said people over 60 filed more than 201,000 complaints and reported more than $7.7 billion in losses. The Mahape $499 text is a small door into that same room.
Mahape Has Hosted This Desk Before
Unit 24 is new. The dual-shift model is not. In November 2025, Hindustan Times reported that Navi Mumbai police had taken 17 people off a Turbhe floor that sold illegal stock tips to Indians by day and fake tech support to Americans by night. In July 2026, the Times of India reported that the same cyber station had raided another rented office in a Mahape IT park and arrested three men over a fake motor-insurance pitch. In March 2026, Navi Mumbai police, in a video circulated by IANS, described a Mahape floor that lured people with high share-market returns.
| When | Where | What the floor sold | Taken in |
|---|---|---|---|
| November 2025 | Turbhe | Stock tips by day, U.S. tech support by night | 17 held |
| July 2026 | Mahape IT park | Fake vehicle-insurance renewals | 3 held |
| August 2026 | Unit 24, Mahape MBP | Fake Apple and bank support, paid in USDT and gift cards | 13 held; 5 named as absconding |
The pattern that keeps landing on this beat is not a lone rogue agent. It is a rented room in a glass park, a night roster that speaks English at U.S. hours, a day roster that works Indian numbers, and a cash-out layer that does not sit at the headsets. When Pune police cracked a Kharadi fake call centre in 2025, they named 118 executives as accused and then sent teams toward Navi Mumbai and Ahmedabad looking for owners who, officers said, visited about once a fortnight. The people who read the script get booked. The people who send the QR codes are the search.
The Book Is Still Being Counted
Police registered the Mahape case under Bharatiya Nyaya Sanhita sections 318(4) for cheating, 319(2) for cheating by personation, 3(5) for joint liability, and 238 for giving false information, Hindustan Times reported. Further technical analysis of the two servers and the laptop is still ahead, and Newsband said investigators are trying to map the rest of the network.
Until that work is done, the public number is still a month of USDT on a WhatsApp thread and a stack of SIM cards on an evidence table. Mustafa Khan, Zareen, Purvank Shrimali, Iggy, and Sheikh Bhai are the names attached to the office, the bait texts, and the wallets. They were not among the 13 people walked out of Unit 24.