
The Telangana Cyber Security Bureau filed a criminal case against Onextel Limited, Nimbus Adcom Pvt Ltd and TVL Media Pvt Ltd on August 10, 2026, for sending fraudulent commercial SMS using the registered headers of KFin Technologies and Nariman Finvest.
The complaint, lodged by ValueFirst Digital Media, alleges that the three firms hijacked the Digital Link Transmission (DLT) PE‑TM scrubbing hash to impersonate legitimate financial entities. On July 9, KFin Technologies’ “KFINTH” header was blacklisted after a fake SMS containing a malicious link was traced to the chain. A second fraudulent message using the same hijacked template appeared on July 30, further disrupting KFin’s OTP and alert services.
In the Nariman Finvest case, a bogus “NARIMN” header message was delivered on August 3, with Onextel Limited identified as the final delivery telemarketer outside Nariman’s authorized network. ValueFirst’s logs showed no trace of the message on its platform, yet the DLT hash pointed to its own chain, highlighting a sophisticated spoofing scheme. Both incidents led to repeated blacklisting of the legitimate headers at telecom and DLT scrubbing levels.
The case names Onextel as the common link, with Nimbus Adcom acting as a reseller upstream and TVL Media as a delivery agent linked to Onextel’s Noida address. Telangana’s police are now probing the alleged irregularities under Sections 318(4) and 319(2) of the Indian Penal Code and Sections 43, 66, 66C and 66D of the Information Technology Act. The investigation will likely involve the Telecom Regulatory Authority of India, Vodafone Idea and the DLT platform operators.
Telecom analysts warn that if the probe confirms the breaching of DLT scrubbing protocols, the three firms could face criminal charges and hefty fines, while the telecom sector may tighten its header‑registration and verification processes to prevent repeat incidents.