โš    Classified โ€” Clearance Required   โš 
๐Ÿ”
Network Forensics Extension
BMP/CYB/CB-01/NET-EXT ยท Extended Repository Audit
Classified under the Cyber Crimes Act. Release is contingent on prior review of related technical evidence.

Numeric code required.
๐Ÿ”Ž   Investigator's Cipher
The thief did not act once. They returned again and again โ€” silently, invisibly โ€” until the damage was complete. The digital trail counted every single move. That total, precisely as recorded in the forensics, is all you need.
CLEARANCE DENIED โ€” INCORRECT VALUE
๐Ÿ’ก Hint
You have already seen this number. It appears in the technical evidence as a measure of scale โ€” not a date, not a reference number, not a name. A count.
SUPPLEMENTAL FORENSICS โ€” RESTRICTED
NETWORK FORENSICS EXTENSION โ€” API AUDIT HISTORY
PaySpark Technologies ยท payspark-internal/fraud-engine ยท Full Event Timeline
โœ“ Clearance verified ยท BMP/CYB/CB-01/NET-EXT
Bengaluru Metro Police โ€” Cyber Forensics Division Supplement to: BMP/CYB/CB-01/03
Scope
Extended audit of all POST events logged by the aro_nexusBridge_v2.py module against endpoint https://api.nexpay.sg/v2/external/ingest. Event records were reconstructed from server-side egress logs surviving the firewall purge, cross-referenced against NexPay API gateway records received under international cooperation.
API Call History โ€” Monthly Breakdown
PeriodEventsData Volume (est.)Note
Sep 202342504 MBFirst recorded activity โ€” low-volume test phase
Oct 202367804 MBVolume increase โ€” model output batching adjusted
Nov 202358696 MBReduced activity โ€” PaySpark Q3 audit period
Dec 2023891.068 GBSignificant increase post-audit clearance
Jan 20241021.224 GBNexPay FraudShield v2 enters beta โ€” correlation noted
Feb 2024941.128 GB
Mar 20241181.416 GB
Apr 20241271.524 GBFATF advisory notice issued against NexPay (04 Apr)
May 20241501.800 GBHighest monthly volume โ€” activity ceased upon repo deletion
TOTAL847~10.16 GB8 months, 27 days of sustained operation
Endpoint Analysis
The receiving endpoint api.nexpay.sg/v2/external/ingest was examined under the international cooperation request. NexPay's API gateway logs confirm this endpoint was purpose-built to receive data in PaySpark's exact fraud model output schema โ€” including field names, data types, and transaction ID structure. The endpoint predates the first API call by at least 6 weeks.
This endpoint did not exist for any other client. It was engineered specifically to receive PaySpark's model output. The integration was not opportunistic โ€” it was designed in advance of the first data transfer.
API Key Lifecycle
The API key NXP-2024-โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ was issued by NexPay on 22 August 2023 โ€” two weeks before the first recorded transfer event. The key carried a 12-month expiry. It was set to auto-renew. Renewal occurred in August 2024, confirming that the arrangement was intended to be ongoing beyond the period of operation.
The key was issued and set to renew before a single byte of PaySpark data had been transmitted. Both parties anticipated long-term, continuous operation.
โ† Back to Evidence Pack B