Ahmedabad: In a first-of-its-kind regulatory action over a cybersecurity breach in GIFT City, the International Financial Services Centres Authority (IFSCA) directed a GIFT City-registered angel fund to deposit US$ 100,000 into its bank account and barred it from launching new schemes after cybercriminals diverted a startup investment to a fraudulent account.In an ex parte ad interim order dated July 13, the IFSCA’s Quasi-Judicial Authority for Enforcement (QJAE) ordered We Founder Circle Angel Accelerator LLP (IFSC Branch) to deposit the amount within 60 days.The action stems from a Business Email Compromise (BEC) attack, a sophisticated phishing scam in which hackers infiltrate email conversations and alter payment instructions. According to GIFT City sources, cybercriminals silently inserted themselves into communication between transaction participants and replaced the beneficiary’s bank account details before the transfer was executed.On April 30, the fund manager for the We Founder Circle Global Angels Fund, transferred US$ 100,000 (around Rs 94 lakh) to BentoLabs AI, Inc. However, the money never reached the intended recipient.The IFSCA order states that “unauthorised third parties had allegedly infiltrated the active email communication chain among transaction participants through fraudulent impersonation email IDs and circulated manipulated bank account details.” Consequently, the funds were transferred to “an unintended beneficiary account maintained with Bank of America in the name of Sherrygold LLC DBA BentoLabs AI Inc, instead of the legitimate beneficiary account intended for the transaction.”The fund initiated a Society for Worldwide Interbank Financial Telecommunication (SWIFT) recall on May 4, filed a cybercrime complaint in India, and lodged complaints with the FBI’s Internet Crime Complaint Center (IC3) and the US Federal Trade Commission (FTC). Despite these efforts, the 17 investors in the fund had not recovered their money.Based on complaint filed by the investors on June 16, IFSCA sought details of the fund’s efforts to resolve the matter. The regulator noted that “the Noticee (the fund) failed to furnish any response within a week.” During a personal hearing, representatives of the fund argued that “the issue involved is complex due to the cross-border nature of the transactions” and sought “one to two months to conclude the matter.”Investors were also informed that resolving the issue could take “approximately two to three months,” citing the complexity of Simple Agreement for Future Equity (SAFE) contracts.The regulator found the fund to be prima facie in violation of Regulation 118 of the IFSCA (Fund Management) Regulations, 2025, which requires fund managers to “render at all times high standards of service, exercise due diligence, ensure proper care and exercise independent professional judgement.”The order observed: “It prima facie appears that the Noticee (the fund) did not do proper due diligence and it appears that it has failed to fulfil its obligations.” It further held that the fund lacked “robust systems and controls in its business, which has adversely impacted the interests of the investors.”Commenting on the order, Ajay Jaisingh, co-founder of an ancillary service provider company at GIFT IFSC, said, “The order reflects real regulatory judgement and sound governance. The lesson is simple: governance isn’t about doing the right thing after a problem arises—it’s about having controls that prevent the problem or protect investors before harm occurs.”
