OTP Interception via SIM Swapping — How to Identify & Stay Safe

INDIA — By BharatSecure Threat Intelligence Team ·

Severity: Critical | View Full Scam Details

SIM Swap Fraud in India 2026: How Scammers Are Stealing Your OTPs and Draining Bank Accounts

Your phone loses signal for a few minutes — and by the time it returns, your savings are gone. SIM swapping is one of India's most critical banking frauds right now, with reported losses running into hundreds of crores across the country.


What Is OTP Interception via SIM Swapping?

SIM swapping is a fraud where attackers convince your mobile operator to issue a duplicate SIM card for your number — giving them full control of every call and SMS you receive, including the OTPs that protect your bank accounts. Because India's entire digital banking stack — UPI, net banking, Aadhaar-OTP authentication — relies on your mobile number, one successful SIM swap can unlock everything.

The Ministry of Home Affairs (MHA) and the Reserve Bank of India (RBI) have both flagged rising complaints related to this form of cyber fraud. CERT-In (cert-in.org.in) has issued advisories warning citizens about the sophistication of social-engineering attacks used to execute SIM swaps. India's Indian Cyber Crime Coordination Centre (I4C), operating under cybercrime.gov.in, continues to track this as a high-priority threat category.

Anyone with a bank-linked mobile number is a potential target — salaried professionals, small business owners, senior citizens, and even students.


Exactly How This Scam Works — Step by Step

  1. Target selection. Fraudsters scan social media (Facebook, Instagram), job portals, and dating apps for people who have recently shared personal details or show signs of financial stress.
  2. First contact. The caller reaches out via WhatsApp or phone, posing as a representative from a bank or telecom company. They claim there is an urgent security issue — your SIM is expiring, your KYC is incomplete, or your account has suspicious activity.
  3. Trust-building. To appear legitimate, the caller may send a fake verification SMS or read back partial account details obtained from data leaks, making the conversation feel official.
  4. Information extraction. Under the pressure of "act now or lose access," the victim shares their Aadhaar number, date of birth, and — critically — an OTP sent to their phone.
  5. SIM swap request. Armed with your details, the fraudster approaches your telecom provider — reportedly sometimes using deceit or bribery — and requests a duplicate SIM, claiming the original is lost or damaged.
  6. Your SIM goes dead. Your phone loses network signal. The new SIM, held by the fraudster, is now active on your number.
  7. Account takeover. All incoming OTPs — from banks including those impersonating SBI and HDFC communications — now arrive on the attacker's device. They initiate UPI transfers, net-banking withdrawals, and credit card transactions before you realise what has happened.
  8. Money is gone. By the time the victim notices the signal loss and contacts their bank, funds have already been moved out.

Real Warning Signs (What to Watch For)


What Happens to Victims

The financial damage can be immediate and severe. Victims in reported cases have lost entire savings through UPI transactions initiated using intercepted OTPs, with aggregate losses across India estimated in the hundreds of crores in recent years. UPI transactions are near-instant, and the RBI's chargeback framework for unauthorised transfers requires a complaint to be filed with the bank within three working days for the best chance of recovery — time that most victims lose while still trying to understand why their SIM stopped working.

Beyond money, the emotional toll is significant. A successful SIM swap gives attackers access not just to bank accounts but potentially to Aadhaar-linked services, email accounts, and other platforms tied to your mobile number. Victims report anxiety, loss of trust in digital banking, and prolonged disputes with banks and telecom providers that can stretch over weeks.


What RBI, CERT-In, and I4C Say

The RBI has consistently advised customers that no bank representative will ever ask for an OTP, PIN, or full card number over a call or message. Customers are urged to report unauthorised transactions immediately to their bank and to the 1930 National Cybercrime Helpline.

CERT-In (cert-in.org.in) has issued public advisories highlighting social-engineering attacks targeting mobile users, emphasising that citizens should verify any telecom or banking-related request through official channels only — not through numbers received in unsolicited calls.

I4C / cybercrime.gov.in maintains the national reporting portal for cyber fraud. The 1930 helpline is operational 24×7 and can trigger a financial freeze on reported accounts, improving the chance of fund recovery.

Telecom Regulatory Authority of India (TRAI) guidelines require operators to follow strict verification before processing SIM replacement requests — if you believe your operator failed to follow due process, this is a complaint you can raise with TRAI as well.


How to Protect Yourself

  1. Never share OTPs, PINs, or Aadhaar details over any call or message — not even to someone who sounds like a bank or telecom official.
  2. Set a SIM lock or port freeze with your telecom provider if available; contact your operator's customer care to ask about this option.
  3. Register for bank transaction alerts via email as a backup channel — if your SIM is swapped, email alerts will still reach you.
  4. Use app-based authenticators (like Google Authenticator) instead of SMS OTPs wherever your bank or service offers it.
  5. Immediately call your telecom operator if your phone loses signal unexpectedly — ask whether a SIM change request was submitted.
  6. Verify caller identity independently. If someone calls claiming to be from your bank, hang up and call the official number printed on the back of your card.
  7. Enable UPI transaction limits and set low per-transaction caps in your UPI app settings to reduce exposure.
  8. Keep your Aadhaar biometric lock enabled via the UIDAI mAadhaar app to prevent misuse of your Aadhaar details.

What to Do If You've Been Targeted

  1. Call 1930 immediately. This is India's 24×7 cybercrime helpline — report the fraud and request a hold on transactions linked to your number.
  2. File a complaint at cybercrime.gov.in — document every detail: the caller's number, time of contact, and what information was shared.
  3. Call your bank's fraud hotline and request an immediate freeze on your account and all UPI-linked services.
  4. Visit your telecom store in person with photo ID to revoke the fraudulent SIM and restore your number.
  5. Lock your Aadhaar biometrics via the UIDAI website (uidai.gov.in) or mAadhaar app to prevent further misuse.
  6. File an FIR at your nearest police station — required for insurance claims and formal bank dispute processes.
  7. Inform your bank in writing within three working days of the incident to comply with RBI's unauthorised transaction reporting window.

Frequently Asked Questions

Can a SIM swap happen without me doing anything? Yes. In reported cases, attackers have obtained duplicate SIMs using your personal details — Aadhaar number, date of birth, address — which they extract through phishing calls or purchase from data breaches. You do not need to hand over your physical SIM for this to happen.

How quickly can I lose money after a SIM swap? Extremely quickly. Once the new SIM is active and OTPs are being intercepted, attackers can initiate and complete UPI transfers within minutes. This is why an unexplained loss of mobile signal should be treated as an emergency, not a routine network glitch.

Will my bank refund money lost to SIM swap fraud? This depends on individual circumstances and how quickly you report the fraud. The RBI's framework for unauthorised electronic transactions places responsibility on banks for third-party breaches, but timelines and outcomes vary. File a complaint with your bank immediately and escalate to the RBI Banking Ombudsman if unresolved. Consult a legal professional for advice specific to your case.

Does this scam only affect customers of specific banks? No. Reports indicate that victims across multiple banks — including those where scammers have been reported impersonating SBI and HDFC communications — have been affected. Any bank account linked to a mobile number is at risk. The vulnerability is in the SMS-based OTP system, not in any single bank.


If you received a suspicious call about your SIM or bank account, scan the message or report it instantly at BharatSecure.app. For financial fraud already in progress, call 1930 right now — every minute counts.

Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.

Related Scams in Our Database

Verify Any Suspicious Message

Check any suspicious message, link, or call for free at bharatsecure.app.