SIM Swap Fraud with Leaked Data — How to Identify & Stay Safe
INDIA — By BharatSecure Threat Intelligence Team ·
Severity: Critical | View Full Scam Details
SIM Swap Fraud Using Leaked Data: How Indian Mobile Users Lost Crores in 2025–26
Your mobile number is the master key to your bank account — and scammers have found a way to steal it using your own leaked personal data. With data breaches exposing millions of Indian records, SIM swap fraud has become one of the most financially devastating cybercimes targeting UPI and net-banking users today.
What Is SIM Swap Fraud with Leaked Data?
SIM swap fraud occurs when fraudsters convince your mobile operator to transfer your number to a SIM card in their possession. What makes the current wave especially dangerous is the fuel powering it: leaked personal data. Aadhaar numbers, PAN details, addresses, and account information harvested from dark web data dumps give scammers enough ammunition to impersonate victims convincingly to telecom customer care.
India has seen a sharp rise in data breaches affecting millions of citizens. This leaked data is traded on dark web marketplaces and used directly to execute SIM swaps. According to government figures cited by the Ministry of Home Affairs, victims have reported losses running into hundreds of crores from SIM swap and related telecom frauds.
The scam targets anyone who uses UPI, net banking, or OTP-based authentication — which means virtually every smartphone user in India is a potential victim.
Exactly How This Scam Works — Step by Step
Data harvested. Scammers collect your Aadhaar number, PAN, address, and mobile number from dark web dumps, phishing links shared on WhatsApp, or targeted email attacks.
Social engineering begins. You receive a call or message — apparently from your telecom provider — warning that your number will be deactivated unless you verify your identity immediately. The urgency is manufactured to bypass your scepticism.
You share details. Believing the caller is a legitimate customer care agent, you confirm your Aadhaar details, date of birth, or the last four digits of your account number — information the scammer already partly knows, making the conversation feel authentic.
SIM swap executed. Using your details, the fraudster contacts your mobile operator (or visits an outlet with forged documents) and gets your number ported to their SIM card. Your phone loses signal.
OTPs intercepted. With your number now active on their device, scammers receive every OTP sent by your bank, UPI app, and email provider.
Accounts drained. They log into your net banking or UPI app, reset passwords using OTPs, and transfer funds to mule accounts. In cases reported to police, victims have lost amounts as large as ₹5 crore in a single attack initiated by leaked personal data.
Real Warning Signs (What to Watch For)
- Your phone suddenly loses signal or shows "No Service" or "SOS Only" — especially in an area with normal coverage
- You receive an unexpected OTP you did not request
- A caller claims to be from Airtel, Jio, Vi, or BSNL and asks you to "confirm your Aadhaar" to avoid deactivation
- You stop receiving calls and SMS without explanation
- Bank alerts arrive for transactions you did not initiate
- Emails or WhatsApp messages ask you to click a link to "update your KYC" with your telecom provider
- Unusual messages about your bank credentials appearing on your registered email
What Happens to Victims
Once a SIM swap succeeds, the financial damage can be near-instantaneous. UPI transactions are processed in real time; by the time a victim realises their SIM is dead and contacts their bank, several transfers may already be complete. RBI guidelines require banks to investigate fraud complaints, but reversals on UPI are subject to dispute timelines that can stretch weeks or months — during which the victim has no access to the stolen funds. In cases reported publicly, victims have lost life savings, business capital, and retirement funds within hours.
Beyond the financial loss, victims often face prolonged distress — repeated calls to banks, police stations, and telecom operators, loss of access to all OTP-linked services, and the anxiety of knowing their Aadhaar and PAN details remain in circulation. The misuse of Aadhaar-linked identities can also complicate loan applications and credit records long after the immediate fraud is resolved. Consulting a legal professional is advisable for case-specific guidance on identity restoration.
What RBI, CERT-In, and I4C Say
RBI has repeatedly advised customers never to share OTPs, account details, or Aadhaar numbers over phone calls or messages, regardless of how legitimate the caller appears. Its guidelines specifically warn that bank representatives will never ask for OTPs.
CERT-In (cert-in.org.in), India's nodal cybersecurity agency, has issued advisories on social engineering attacks exploiting telecom impersonation, urging users to enable SIM lock features and report suspicious contacts.
I4C (Indian Cybercrime Coordination Centre) operates the 1930 cybercrime helpline and the portal cybercrime.gov.in — both dedicated to rapid-response fraud reporting. The Ministry of Home Affairs has collaborated with RBI and CERT-In to raise public awareness, yet reporting rates remain low due to limited awareness about these channels.
Under the IT (Amendment) Rules 2021 and the DPDP Act 2023, data fiduciaries have obligations around breach disclosure and user data protection — a legal framework that supports victims in establishing liability when personal data misuse is demonstrated.
How to Protect Yourself
- Set a SIM lock or port freeze — contact your telecom provider and request an additional verification layer for any SIM swap or porting request.
- Never confirm Aadhaar, PAN, or OTPs over an unsolicited call — legitimate operators do not call you to verify identity this way.
- Enable app-based or hardware-based two-factor authentication wherever available, rather than SMS OTP alone.
- Regularly check your CIBIL or credit report for unfamiliar accounts or loan enquiries that could signal identity misuse.
- Use a masked Aadhaar (Virtual ID) for KYC requirements wherever possible, minimising exposure of your actual Aadhaar number.
- Immediately call your bank if your phone loses service unexpectedly — do not wait to investigate why.
- Treat unsolicited urgency as a red flag — any message threatening deactivation within hours is a classic social engineering tactic; hang up and call the official number.
What to Do If You've Been Targeted
Act within the first hour — every minute matters.
- Call 1930 (National Cybercrime Helpline) immediately to log the fraud and request a transaction hold alert to banks in the network.
- Call your bank's 24×7 fraud helpline and ask them to freeze your account and reverse any pending UPI transactions.
- Contact your telecom operator's fraud desk to report the unauthorised SIM swap and restore your number.
- File a complaint at cybercrime.gov.in — keep your acknowledgement number; you will need it for bank escalations.
- Visit your nearest police station to file an FIR; this is required for insurance claims and formal bank dispute processes.
- Notify UIDAI (1947 helpline) if you believe your Aadhaar was used fraudulently, and consider locking your Aadhaar biometrics via the myAadhaar portal.
- Consult a lawyer for case-specific legal remedies under the BNS 2023 and IT Act.
Frequently Asked Questions
How do scammers get my Aadhaar and PAN details in the first place? In cases reported to authorities, this information is obtained from dark web data dumps originating from large-scale breaches, from phishing pages disguised as bank or government portals, and through WhatsApp or email links that install data-harvesting malware. Once your details appear in one breach, they are often re-sold and used in multiple fraud attempts.
Can my bank reverse the UPI transfer after a SIM swap fraud? Banks are required under RBI guidelines to investigate unauthorised transaction complaints, and limited reversal is possible — especially if reported within hours. However, UPI transfers are real-time settlements, and recovery depends on whether the beneficiary account has already been emptied. Early reporting to 1930 significantly improves the chances of a freeze on the recipient account. Seek legal advice for your specific situation.
Will locking my Aadhaar biometrics prevent a SIM swap? Locking your Aadhaar biometrics via the myAadhaar portal prevents anyone from using your fingerprint or iris scan for Aadhaar-based authentication — which is one channel sometimes exploited for fraudulent SIM issuance. It does not, however, prevent document-based or OTP-based SIM swap attempts. It is one useful layer among several.
What is the difference between a SIM swap and SIM cloning? A SIM swap involves the fraudster convincing the telecom operator to port your number to a new SIM — the process is social and procedural. SIM cloning, by contrast, involves physically copying the SIM's cryptographic data and is technically far more complex. The data-driven SIM swap described in this article is currently the far more common threat to Indian consumers.
If you received a suspicious call about your SIM or mobile KYC, scan the message or describe the incident at BharatSecure.app for an instant threat check. Report fraud immediately on 1930 or at cybercrime.gov.in — early reporting saves money.
Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.
Verify Any Suspicious Message
Check any suspicious message, link, or call for free at bharatsecure.app.