This article is for educational and legal awareness purposes only. It does not constitute legal advice or solicitation. Please consult a qualified advocate for advice on specific legal matters.
Introduction
A SIM swap fraud does not begin with a hacked bank account — it begins with a phone call the victim never made. By the time the fraud is discovered, the victim’s mobile number has been silently transferred to a SIM card in someone else’s possession, and every OTP meant to protect the victim’s bank account, UPI app, and email has instead reached the fraudster. This article explains how SIM swap fraud is carried out, the provisions it attracts under the Bharatiya Nyaya Sanhita (BNS), the Information Technology Act, and the Telecommunications Act, 2023, and how to report and recover from it.
What Is SIM Swap Fraud
SIM swap fraud (also called SIM swapping or a port-out scam) is the fraudulent procurement of a duplicate SIM card on a victim’s existing mobile number, without the victim’s knowledge. Once the duplicate SIM is activated, the victim’s original SIM is deactivated by the network, and all calls, SMS, and — critically — One-Time Passwords (OTPs) sent to that number reach the fraudster instead of the victim.
This differs from ordinary UPI phishing or vishing, where a victim is tricked into directly sharing a PIN or OTP. In a SIM swap, the victim may do nothing wrong in the moment — the deception is practised on the telecom operator, and the victim typically only realises something is wrong when their phone loses network signal entirely.
How SIM Swap Fraud Works
Step 1 — Data Collection
The fraudster first gathers the victim’s personal details — name, date of birth, address, and often the last few digits of an ID document such as Aadhaar or PAN — typically through prior phishing messages, data leaks, or reconnaissance on social media and public records.
Step 2 — Approaching the Telecom Operator
Using this information, the fraudster approaches the telecom operator — at a retail outlet or through customer care — and requests a duplicate SIM, usually claiming the original is lost, damaged, or needs an upgrade (for example, to an eSIM). The request is supported with forged or fraudulently obtained identity documents, or exploits weak verification at the outlet, to pass off as the genuine subscriber.
Step 3 — Activation and Deactivation
Once the telecom operator processes the request, the new SIM activates and the original is deactivated in the same swap. The victim typically notices only when their phone shows “No Service” or “Emergency Calls Only” — by which point the fraudster already controls the number.
Step 4 — Financial Takeover
With control of the number, the fraudster requests OTPs for banking apps, UPI apps, email password resets, and two-factor authentication codes, and uses them to drain bank accounts, take over linked accounts, or transfer funds before the victim can react.
Legal Provisions Applicable to SIM Swap Fraud
Telecommunications Act, 2023
The Telecommunications Act, 2023 (which replaced the colonial-era Indian Telegraph Act, 1885 for most purposes) directly addresses the act of fraudulently obtaining a SIM. Under Section 42(3) of the Act, whoever —
- obtains subscriber identity modules (SIMs) or other telecommunication identifiers through fraud, cheating or personation [Section 42(3)(e)], or
- tampers with telecommunication identifiers [Section 42(3)(c)],
“shall be punishable with imprisonment for a term which may extend to three years, or with fine which may extend up to fifty lakh rupees, or with both.” Under Section 42(7), offences under Section 42 — including this one — are cognizable and non-bailable. Section 42(6) extends the same punishment to anyone who abets, attempts, or conspires in such an offence, which can cover a complicit retail agent at the telecom outlet.
This provision speaks most directly to the fraudulent-duplicate-SIM step itself, distinct from what happens afterward with the stolen OTPs.
Bharatiya Nyaya Sanhita (BNS), 2023
The BNS replaced the Indian Penal Code with effect from 1 July 2024. For a SIM swap carried out on or after that date, the following provisions typically apply:
- Section 318 BNS — Cheating. Deceiving the telecom operator into believing the fraudster is the genuine subscriber, and thereby inducing it to issue a SIM it would not otherwise issue, falls within the definition of cheating. Punishment ranges from imprisonment up to three years (basic cheating) to up to seven years, depending on which sub-section applies.
- Section 319 BNS — Cheating by Personation, the provision most squarely applicable to a SIM swap: “A person is said to cheat by personation if he cheats by pretending to be some other person, or by knowingly substituting one person for another, or representing that he or any other person is a person other than he or such other person really is.” A fraudster presenting as the victim to obtain a duplicate SIM fits this definition exactly. Punishment: imprisonment up to five years, or fine, or both.
- Section 336 BNS — Forgery, where the fraudster fabricates a false document (such as a forged ID) to support the SIM request. Punishment up to two years generally, and up to seven years where the forgery is intended for cheating.
- Section 337 BNS — Forgery of a Government-issued identity document, including a voter identity card or Aadhaar Card, carries imprisonment up to seven years.
- Section 340 BNS — Using a forged document as genuine. Presenting the forged ID to the telecom operator’s staff attracts the same punishment as the forgery itself.
Information Technology Act, 2000
Once the fraudster uses the hijacked number to intercept OTPs and access online banking or UPI accounts, the following IT Act provisions apply:
- Section 66C — Identity theft: “Whoever, fraudulently or dishonestly make use of the electronic signature, password or any other unique identification feature of any other person, shall be punished with imprisonment of either description for a term which may extend to three years and shall also be liable to fine which may extend to rupees one lakh.”
- Section 66D — Cheating by personation using a computer resource: “Whoever, by means of any communication device or computer resource cheats by personating, shall be punished with imprisonment of either description for a term which may extend to three years and shall also be liable to fine which may extend to one lakh rupees.”
- Section 43 — Provides a civil-liability route: unauthorised access to, or extraction of data from, a computer system (including online banking systems accessed using the stolen OTP) can support a compensation claim independent of criminal proceedings.
In practice, an FIR arising from a SIM swap fraud typically invokes BNS Sections 318 and 319 together with IT Act Sections 66C and 66D, and Section 42(3) of the Telecommunications Act, 2023 where the telecom-side fraud is separately pursued.
Step-by-Step: What to Do If You Suspect a SIM Swap
Step 1 — Recognise the Warning Sign
The clearest early sign is a sudden, unexplained loss of mobile network — “No Service” or “Emergency Calls Only” — without a known outage. Unexpected SMS alerts about a SIM replacement request, or apps/passwords being reset, are also warning signs.
Step 2 — Contact the Telecom Operator Immediately
Call the telecom operator’s customer care from another phone (or ask someone else to call), report the suspected unauthorised SIM swap, and request that the fraudulent SIM be blocked and the original SIM restored. Insist on being connected to the fraud/security desk, not general support.
Step 3 — Alert Your Bank
Simultaneously contact your bank’s 24×7 helpline to freeze or restrict online/mobile banking and UPI access linked to that number, since the fraudster’s window to act is short.
Step 4 — Call 1930 (National Cyber Crime Helpline)
Call 1930, the toll-free National Cyber Crime Helpline, as soon as any unauthorised transaction is discovered. Provide the bank name, account number, transaction details, and the approximate time the phone lost network — the helpline can alert connected banks to freeze funds before withdrawal. Note the acknowledgement number.
Step 5 — File a Complaint on cybercrime.gov.in
File a formal complaint on the National Cyber Crime Reporting Portal under the appropriate fraud category, describing the SIM swap and any resulting financial loss, and attach supporting evidence (SMS alerts, bank statements, screenshots).
Step 6 — Report the Fraudulent SIM via Sanchar Saathi
The Department of Telecommunications’ Sanchar Saathi portal provides citizen-facing tools relevant to SIM swap fraud:
- Chakshu (accessible at sancharsaathi.gov.in/sfc) — for reporting suspected fraud communications (calls, SMS, WhatsApp) intended to defraud, impersonate, or otherwise misuse telecom resources.
- TAFCOP (Telecom Analytics for Fraud Management and Consumer Protection) — lets a subscriber check how many mobile connections are registered in their name and flag any unrecognised connection.
- CEIR (Central Equipment Identity Register) — for blocking a lost or stolen handset across all networks by IMEI.
Step 7 — File an FIR
Visit the nearest police station or cyber crime cell and insist on registering a First Information Report (FIR), citing BNS Sections 318 and 319, IT Act Sections 66C and 66D, and Section 42(3) of the Telecommunications Act, 2023 for the fraudulent SIM procurement itself. If police decline to register an FIR, a complaint can be made to the Superintendent of Police (Cyber) or to the Judicial Magistrate under Section 175(3) of the Bharatiya Nagarik Suraksha Sanhita (BNSS), 2023.
Documentation Checklist
- Screenshot or note of the time the phone lost network signal
- Any SMS/email alerts about SIM replacement, password resets, or login attempts
- Bank statement showing the unauthorised transaction(s)
- Acknowledgement numbers from 1930, cybercrime.gov.in, and the telecom operator’s complaint
- FIR copy
- Correspondence with the telecom operator and the bank
RBI Liability Framework for the Resulting Bank Fraud
Where a SIM swap leads to unauthorised debit from a bank account, the RBI’s Master Direction on “Customer Protection — Limiting Liability of Customers in Unauthorised Electronic Banking Transactions” (Circular RBI/2017-18/15, dated 6 July 2017) applies as for other unauthorised electronic transactions. A customer who reports the unauthorised transaction within three working days of the alert generally bears zero liability where the loss arises from a third-party breach rather than the customer’s own negligence; reporting between 4 and 7 working days caps liability at prescribed limits by account type. Because a SIM swap is engineered through the telecom operator rather than the customer sharing an OTP directly, affected customers are often well placed to argue zero liability, provided the bank is notified promptly and in writing.
Prevention Tips
- Set a PIN or password with your telecom operator for any SIM-replacement or porting request, where the operator offers this option.
- Treat an unexplained loss of network signal as an emergency, not a technical glitch — verify immediately with the telecom operator.
- Avoid oversharing personal identifiers (date of birth, last four digits of Aadhaar/PAN) on social media or with unverified callers claiming to be from a bank, telecom operator, or government department.
- Register for SMS/email transaction alerts on all bank and UPI accounts so unauthorised activity is visible even if the phone itself is unreachable.
- Periodically check TAFCOP on the Sanchar Saathi portal to confirm no unrecognised connections are active in your name.
- Enable app-based (rather than SMS-only) two-factor authentication where the service allows it, since app-based authenticators are not affected by a SIM swap.
Useful Resources
- National Cyber Crime Reporting Portal — File complaints online
- Sanchar Saathi Portal — TAFCOP, CEIR, and Chakshu fraud-reporting tools
- Chakshu — Report Suspected Fraud Communication — Report fraudulent calls/SMS/SIM-related misuse
- RBI — Reserve Bank of India — Customer liability guidelines for unauthorised electronic transactions
- Indian Kanoon — Search Indian case law and statutes
Disclaimer: The information provided on this website is for general legal awareness and educational purposes only. It does not constitute legal advice, advertisement, or solicitation. No reader should act or refrain from acting based on this information without seeking professional legal counsel. Advocate Akhil Singh and this website are not liable for any actions taken based on the content provided herein.