A suspected GST identity theft case has come to light in Gorakhpur, where unidentified cybercriminals allegedly gained unauthorized access to a private company’s GST portal and used its GSTIN to generate fake invoices showing transactions worth ₹9.32 crore.
Sanjeev Kumar Jaiswal, director of HiVerner Private Limited and a resident of Bhatat area of Gulriha, has approached the Ministry of Finance, stating that the company had no role in the transactions recorded on its GST account. The complaint has reportedly been forwarded to the concerned authority for further action.
According to the complaint, the alleged breach occurred around 2 months before the fraud was discovered. The attackers reportedly changed the mobile number and email address linked to the company’s GST account, preventing it from receiving regular alerts and notifications.
The alleged unauthorized activity took place on May 3, when fraudulent billing was reportedly generated using the company’s GST credentials. The company became aware of the issue after its registered mobile number was restored on May 13, 2026. Jaiswal then checked the GST portal and found transaction and billing details that the company had not created.
The disputed transactions showed a turnover of ₹9,32,08,966 against the company’s GSTIN. Jaiswal stated that HiVerner Private Limited had neither issued the invoices nor supplied any goods or services linked to them. He also said the company received no payments from these transactions.
The incident has raised concerns that the GSTIN may have been used by a wider network for fake invoicing and possible fraudulent input tax credit (ITC) claims. Businesses receiving the disputed invoices may have potentially used them to claim ITC, creating possible financial losses for the government.
The complaint has called for an investigation into the transactions, invoices and entities involved. Investigators are expected to examine GST login activity, changes to account details, IP and digital access records, invoice information, bank transactions and the movement of any tax credit linked to the disputed billing.
The case comes after another cyberattack involving companies in Gorakhpur. On June 1, 2025, the servers of Rayraika Marketing and Gauri Trading were allegedly hacked. The attackers reportedly demanded cryptocurrency as ransom and threatened to destroy the servers. Operations were disrupted for 2 days. Cyber police registered a case, but no major breakthrough has reportedly been made.
GST identity theft can involve unauthorized access to a company’s GSTIN, login credentials, registered phone number or email address. Such access can be used to create fake invoices, record fictitious transactions or support fraudulent ITC claims.
The Gorakhpur case will now focus on how the GST account was accessed, who changed the registered details, who generated the invoices and where the alleged financial gains went.
Also read: Viksit Workforce for a Viksit Bharat
Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter
About us:
The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.


