Quick Summary
A 63 year old retired schoolteacher’s dormant demat account was allegedly hijacked from inside her own broker. As per the police complaint, a Motilal Oswal employee forged her signature, updated her KYC, and quietly sold ₹1.58 crore worth of shares between August 2024 and January 2025, routing the money to his personal bank account. He has been booked for forgery, criminal breach of trust, identity theft, and cheating, and the case is under investigation. This page tells the full story, then gives you the five minute checks that protect every dormant account, including the ones your parents hold.
“Beta, I haven’t logged into my account for weeks… but my shares are gone.”
That is what the 63-year-old woman told her son, confused and worried.
A retired schoolteacher, she had put aside her life’s savings in the stock market, all managed by a trusted name, Motilal Oswal.
For someone who barely checked her portfolio once a month, waking up to a drained demat account was nothing short of a nightmare.
This was not phishing, and not some fake Telegram group.
This was worse, a betrayal from inside the very institution she trusted with her life savings.
A Dormant Account and a Criminal Opportunity
Every scam needs a door, and this one found the quietest door in the market, an account nobody was watching.
The woman’s demat account had been dormant since July 2023. Like many senior citizens, she was not chasing daily trades or derivatives.
Her portfolio had been built over years, brick by brick, for long-term safety. But dormant accounts, it turns out, are exactly the soft targets scamsters love.
Sometime in August 2024, a Motilal Oswal employee named Gaurang Mandalia allegedly accessed her dormant account and reactivated it using forged documents.
As per the police complaint, he forged her signature to update KYC details, allowing himself to operate the account freely without raising suspicion.
From that moment, the gates were open.
Between August 2024 and January 2025, Mandalia allegedly began selling shares from her portfolio, discreetly, steadily. No dramatic moves. No large dumps. Just quiet siphoning.
And every time a sale happened, the money did not go to her registered bank account. It allegedly went into Mandalia’s personal bank account.
Total damage: ₹1.58 crore worth of shares, gone.
How Was KYC Updated Without Her Knowing?
The son’s words to investigators carry the part that should worry every family with an untouched portfolio.
“My mother does not even know how to open her Motilal Oswal app. She has never submitted any updated KYC forms. She does not do online trading. So how on earth were her details changed?”
That is the bone-chilling part.
This was not a clever phishing link or a password leak. This was someone inside the system, with full access, allegedly faking documents, altering data, and conducting trades as if he owned the account.
It was not just theft. It was a complete hijack of identity and control, and where ordinary unauthorised trading ends and this begins, the difference is worth knowing.
What allegedly happened here went further; the account itself was taken.
Trades pushed on you without consent have their own battlefield and their own tribunal wins, walked through victim by victim in our guide on Motilal Oswal unauthorised trading.
How Did ₹1.58 Crore Go Unnoticed for Five Months?
The question burning on every investor’s mind deserves a straight look, because the answer is the lesson.
Where were the alerts? The red flags? The internal checks?
It appears Mandalia may have been smart about timing and quantities, selling just enough to avoid suspicion and spacing out the trades.
He knew how the system worked, and he allegedly used it with surgical precision.
The KYC change also mattered, because whoever controls the registered contact details controls what the account owner sees. Change the email, and every alert, every contract note, every warning goes somewhere else.
And this is not the only time this broker’s internal controls have come up short.
The regulator has fined it repeatedly for exactly this family of failure: unwatched terminals, unverified people, unmonitored accounts, and the full six-order record is counted inside our page: SEBI penalty against Motilal Oswal.
By January 2025, when the family finally pieced it together, it was too late. The shares were sold. The money was withdrawn.
What Action Has Been Taken Against the Broker & Employee?
Motilal Oswal has reportedly taken action and filed a complaint.
Mandalia has been booked under IPC sections relating to forgery, criminal breach of trust, identity theft, and cheating, and the matter is under police investigation.
The company says it is cooperating fully and conducting an internal audit.
But for the victim, those words do not mean much anymore.
“She asks me every other day if the shares will come back,” her son says. “I do not have the heart to tell her the truth, that they are gone.”
Is Your Dormant Account Safe? The Five-Minute Check
Her story is painful to read. Yours does not have to become one, and the protection costs five minutes.
Run these checks today, on your own account and on every portfolio your parents or grandparents hold untouched:
- Log in and match the registered email and mobile against the real ones.
- Download the latest holding statement and compare it with what you believe you own.
- Check the last KYC modification date, and question any change you did not make.
- Turn on SMS and email alerts for every transaction, not just trades.
- Review the demat transaction statement for any debit you cannot explain.
- Set one calendar reminder a month, five minutes, forever.
A dormant account with alerts on is a locked door. A dormant account nobody checks is an open invitation.
And if the login refuses you when you try these checks, do not shrug and postpone, because every documented Motilal Oswal login issue pattern, and what it takes to get back in, is worth ten minutes of your attention today.
Just checked a parent’s account and found a detail that does not match your memory?
Do not wait to be sure. We will review the account trail, identify what changed and when, and file the matter on every forum it belongs on, from the broker’s compliance desk to the regulator and beyond, while the trail is still fresh.
Where Does a Case Like This Get Reported?
A fraud this deep runs on two tracks at once, and both matter.
The criminal track, because forgery and identity theft are police matters, which is exactly where this case sits today.
And the securities track, because the account, the broker, and the shares all live inside SEBI’s world, where the broker answers for its systems and its people.
That road, from the grievance desk emails to SCORES and the exchange, is laid out stage by stage in our guide on how to file complaint against Motilal Oswal online.
Walk both. The police pursue the person. The securities route pursues the institution that let it happen.
Conclusion
This story is not just about one victim or one rogue employee. It is about a hole in the system, one that any unscrupulous insider can exploit when controls are weak, and audits are lazy.
The scam needed no AI, no hacking, no deepfakes. All it allegedly took was a trusted employee, a printer, and a signature.
So if you have accounts you do not check often, check them. If your parents have portfolios lying untouched, review them. And if anything feels even slightly off, act fast.
Because by the time that one letter or alert arrives, it might already be too late.
Report. Recover. Stay Fraud Free.
As per a police complaint, a Motilal Oswal employee allegedly reactivated a senior citizen's dormant demat account using forged KYC documents and sold ₹1.58 crore worth of shares over five months, routing the proceeds to his personal account. The case is under investigation. The account was dormant, the owner rarely logged in, and the trades were allegedly small and spaced out to avoid triggering suspicion. Control of the KYC details also meant alerts and statements could be diverted away from the real owner. Recovery depends on the police investigation, the broker's liability for its systems, and how quickly the fraud was reported. Pursue both tracks together, the criminal complaint against the individual and the securities complaint against the broker. Verify the registered email and mobile, enable transaction alerts, check the last KYC modification date, and review holding statements monthly. Five minutes of checking closes the exact door this case walked through. Start with a written complaint to the broker's grievance desk from your registered email, escalate to SEBI SCORES if unresolved in 30 days, and file a police complaint in parallel wherever forgery or identity theft appears. Speed protects both the evidence and the money.Frequently Asked Questions






