KPMG's forensic audit of the ₹646-crore fraud at IDFC FIRST Bank's Chandigarh branch has delivered the outcome depositors and investors needed to hear: no systemic compromise. The core banking system (CBS) remained intact throughout, and no similar incidents surfaced across the wider network.
The fraud itself was decidedly low-tech. A group of branch employees colluded with external third parties and employees of the customer—Haryana state government departments—to engineer the scheme. They used forged cheques, fake signatures, and synthetic documentation (including fabricated FD receipts) to bypass manual, branch-level authorization controls.
The analog nature of the attack underscores a hard truth in Indian banking: no amount of digital security locks out the risk of coordinated human misconduct. The conspirators exploited trust and procedural gaps at the branch level, not vulnerabilities in the bank's technology infrastructure.
IDFC FIRST Bank has moved decisively in the aftermath. The lender has already fully repaid the ~₹645 crore principal to affected government accounts, ensuring zero loss to the customer. Nineteen individuals connected to the collusion have been taken into custody.








