The cheap trick that drained a Pune firm of Rs 10 lakh: a letter, a domain, and a one-line ask
A single-character swap in a sender address turned a routine accounts-payment into a six-figure loss. The pattern is older than the internet, and the defences against it are not new either.

On 16 July 2026, The Indian Express carried a small item that deserves a larger audience: a Pune-headquartered firm, working through what looked like a routine accounts-payable exchange, lost around Rs 10 lakh to a sender whose email address differed from the real counterparty's by a single pair of letters, ".com" rewritten as ".cam". The payment cleared. The conversation stopped. By the time anyone realised the chat had been with someone else, the money was already in pieces across accounts built to vanish. The story is reported by The Indian Express in broad strokes, and the specific facts reported are limited to the financial loss figure, the vector of the deception, and the city. What it captures, though, is the simplest kind of confidence fraud now travelling under a new envelope.
The thesis here is unhappily plain. The internet's address system was never built to be readable by humans under time pressure; it was built to be routable by machines. Every grammatical shortcut, the colon, the slash, the dot that separates top-level domain from second-level, was a concession to operators who never expected ordinary office staff to type them correctly while the boss is asking why the invoice is late. That mismatch is now the cheapest attack surface in global commerce. The Indian Express item, small as it looks next to the day's other fare, is a textbook instance of what it costs.
The trick is not new
Spoofing a counterparty's email is the original sin of business email compromise, the form of fraud that the FBI's Internet Crime Complaint Center first catalogued by name in the mid-2010s. The newer wrinkle, the one that touched the Pune firm, is the look-alike domain: an attacker registers "acme-corp.cam" or "acmecorp.cam" once the real sender is "acmecorp.com", and waits. The numbers behind BEC are ungainly to repeat because they shift year to year, but the pattern of loss has run into the tens of billions of dollars globally for nearly a decade. What changed is that the cost of registering a look-alike domain, hosting a mail server, and imitating a firm's invoicing template has collapsed to roughly what a young fraudster spends on lunch. The Indian Express item is interesting less for the method than for what the method now costs the victim: in the Pune case, ten lakh rupees, transferred in what reads as a single polite exchange.
The lever that hasn't been pulled
There is a structural fix, and the small-business sector in particular has not been given a reason to use it. Domain-based Message Authentication, Reporting, and Conformance, the email-validation framework that lets a receiving server refuse mail from any domain not authorised to send it, has been a stable standard for years; the major Indian mail providers and global ones alike now advertise some level of enforcement. The catch is that enforcement is meaningful only when a domain's owner publishes the record. Many small and mid-sized firms treat the act of publishing a sender-policy record as IT housekeeping rather than as the financial control it effectively is. The Pune case, as The Indian Express reports it, has the hallmarks of a vendor-side imitation that any reasonably tight policy record would have rejected at the mail-server door. Until that record becomes something a chartered accountant suggests a client install the way they suggest a GST reconciliation tool, the look-alike trick will keep working.
Why the regulator has the harder job
Domain seizures and takedowns do work; they are also slow and follow the money, not the message. The Maharashtra Cyber cell, which typically handles the more sophisticated of these complaints, has built out a respectable track record on the recovery side over the last three years, but the Indian Express's two-line treatment of the case does not let a reader infer which agency is currently in the loop. The harder regulatory question sits upstream, with the registry operators who, for a few dollars, sold the look-alike domain in the first place. The .cam registry is operated out of Cameroon by a commercial registry operator; its pricing tiers do not differ meaningfully from any other new-generic top-level domain, and its abuse-handling workflow is rated as compliant with industry norms by the relevant ICANN-style bodies. That is, in a sense, the structural scandal: a perfectly legal piece of address-space was rented for the purpose of impersonating another firm, and the registrar's incentive to ask why is approximately zero, because registrars compete on speed and price, not on whether their inventory is used for fraud. Until a sanctions regime penalises registrars whose domains become routinised vectors of reported crime, that incentive will not move.
The bigger ledger
It is worth being honest about what one story in one city proves. The Indian Express item tells us a Pune firm lost around Rs 10 lakh to a look-alike domain. It does not tell us the firm's turnover, the segment, the existing controls, or how the cash moved after the payment cleared. It does not name the imitated counterparty, the registrar of the look-alike, or the bank that processed the transfer. The original is short and the assumption is that there is a longer police record behind it. What we can responsibly say is that, in global business email compromise losses measured in tens of billions, a six-figure-rupee loss to a single small firm is a rounding error, and that the patterns visible in the big-loss cases, slow detection, multiple-hop accounts, look-alike infrastructure, are visible in the small one too. That is the generalisation worth holding onto, even where the specifics run out.
The Pune firm's loss is reported as Rs 10 lakh. The structural cost of the trick, multiplied across every small business in every industrial city that handles its accounts by email, is the number nobody publishes, which is precisely why the small cases deserve the long treatment.
This publication framed this story as a structural-pattern piece rather than a single-incident report. The Indian Express's two-line item was treated as a window onto a mature fraud market, not the whole story.