Khabar 24h SIMPLE EXPLAINERS ON WORLD AFFAIRS, SCIENCE, HEALTH AND MORE.

KHABAR 24H

Simple explainers on world affairs, science, health and more.

All news under one minute

Technology Read in one minute

What Is SIM Swap Fraud? How Criminals Hijack Phone Numbers in India

Your phone number has become the master key to your digital life: bank OTPs, UPI verification, password resets and Aadhaar-linked services all flow through it. SIM swap fraud targets exactly this. Criminals convince your mobile operator to issue a replacement SIM for your number to a SIM card they control, and from that moment your calls, SMS and OTPs go to them. Without touching your phone, they can drain bank accounts and hijack identities. This guide explains how SIM swap fraud works in India, the warning signs, and how to protect yourself.

How criminals hijack a number

The attack is social engineering aimed at the operator, not technical hacking of your phone. First, criminals collect your personal details: full name, date of birth, address, sometimes an ID copy, harvested from data breaches, phishing, social media or corrupt insiders. Then they impersonate you to the operator, visiting a store with forged documents or calling customer care, claiming the SIM was lost and requesting a duplicate. Indian operators have tightened processes, requiring biometric or OTP verification for SIM replacement, but determined criminals use forged documents, insider collusion or porting tricks. Once the new SIM activates, your phone loses network, and every OTP the bank sends goes to the attacker’s device. The window between swap and detection is when the money moves.

Why a phone number is such a valuable target

The number’s power comes from its role as a trust anchor. Banks send transaction OTPs to it. UPI apps verify devices through it. Password resets for email and social media often fall back to SMS. Aadhaar-linked services use it for authentication. Compromising the number therefore compromises everything downstream in one move, which is why SIM swap is the master key attack. The irony is that SMS-based two-factor authentication, meant as a security upgrade, becomes the vulnerability: it assumes control of the number proves identity, an assumption SIM swap breaks. This is why security experts urge moving important accounts to app-based authentication that does not depend on the phone number.

Warning signs of a SIM swap in progress

The signature symptom is sudden, unexplained loss of mobile signal: no calls, no SMS, no data, while everything else about the phone seems fine. It is often accompanied by a flood of OTP messages just before the swap completes, as the attacker tests access, or notifications from your operator about a SIM change request you never made. Some victims receive phishing calls beforehand, fishing for the personal details needed for the impersonation. If your phone abruptly shows No Service in a place with normally good coverage, do not assume a network glitch: contact your operator immediately from another phone or landline and ask whether a SIM replacement was issued.

How to protect your number

Several defences raise the bar substantially.

  • Set a SIM PIN and a strong customer-care password or PIN with your operator, so impersonators face an extra barrier.
  • Reduce SMS dependence: move banking, email and important accounts to authenticator-app 2FA, which survives a SIM swap.
  • Guard personal details: limit what you share publicly, and treat unexpected calls asking for ID details as hostile.
  • Register for your operator’s SIM-change alerts and read them; they are the early warning system.
  • Consider separating roles: keep the number linked to banking stable and rarely shared, using a second number for public listings.
  • Ask your operator about SIM-swap protection features or port-out locks if offered.

No defence is perfect against insider collusion, but layered barriers deter all but the most determined attackers.

If it happens to you

Speed is everything. Contact your operator immediately to reverse the unauthorised SIM issue and regain your number. Call your bank’s fraud helpline to freeze accounts and cards; in India, the 1930 cyber helpline can help coordinate rapid response. Change passwords for email and financial accounts from a secure device, and review every transaction from the attack window. File a police complaint and a report on the cybercrime portal; official documentation supports fraud claims with banks. Then rebuild with the protections above, so the same attack cannot succeed twice.

FAQs

Can eSIM users be SIM-swapped? Yes. The attack targets the operator’s issuance process, not the SIM format. eSIM users should use the same protections.

How common is SIM swap fraud in India? It is a documented and recurring fraud category, often combined with phishing to gather the personal details needed for impersonation.

Does 2FA via SMS make me vulnerable? SMS 2FA is better than no 2FA, but for high-value accounts, authenticator apps or hardware keys remove the phone-number dependency entirely.

Your phone number is too important to be protected by obscurity. Harden it like the master key it is: operator PINs, minimal SMS dependence, and instant response to the sudden silence of a swapped SIM.

Compiled by the Khabar 24h Editorial Desk from publicly available sources.

Avatar photo
Written by
Khabar 24h Editorial Desk

Khabar 24h Editorial Desk — our explainers are prepared by the Khabar 24h editorial team using AI-assisted research tools, and every piece is reviewed by a human editor before publishing. We do not claim original reporting: our work is turning complex topics into simple, accurate summaries. Spotted an error? Write to contact@khabar24h.com — our corrections policy aims for same-day review.

More from this author →