SIM Swap Fraud in India: Mobile Number Takeover, UPI Loss, Bank Refund, FIR & Telecom Remedies
By Adv. Govind Bali, Fastrack Legal Solutions LLP | Reviewed on 20 August 2026
SIM-swap fraud occurs when an offender causes a mobile number to be activated on another physical SIM or eSIM without the lawful subscriber’s authority. Once the victim’s existing SIM loses network access, the offender may receive calls and SMS messages linked to that number, reset email or banking credentials, register UPI on another device, take over messaging accounts and defeat SMS-based authentication.
A successful SIM swap is usually not a single offence committed at one moment. It may involve identity-document misuse, personation before a telecom operator or point of sale, unauthorised replacement or porting, account compromise, interception of authentication messages, addition of beneficiaries, UPI or card transactions and laundering through several recipient accounts.
Immediate legal answer: If a phone suddenly shows “No Service”, “SIM not provisioned” or unexplained network loss, contact the telecom operator from another number at once and suspend the replacement SIM. Simultaneously block mobile/net banking and UPI, secure the linked email, call 1930 if money has moved or is at imminent risk, file at cybercrime.gov.in, preserve every alert and complaint number, and give a written police complaint seeking telecom, device and bank-record preservation.
Key Takeaways
- Loss of network service may be a routine outage, device fault or SIM failure, but unexplained loss combined with password-reset or transaction alerts must be treated as a possible account takeover.
- Do not wait for the telecom store to open before protecting bank accounts; use alternate-phone helplines and online blocking channels immediately.
- Under RBI’s customer-protection directions, the timing and cause of an unauthorised transaction determine liability. Reporting within three working days is critical in a qualifying third-party breach.
- The bank bears the burden of proving customer liability under the RBI framework; refund is not automatically defeated merely because a valid OTP or device authentication appears in the transaction record.
- Section 42(3)(e) of the Telecommunications Act, 2023 specifically criminalises obtaining SIMs or other telecommunication identifiers through fraud, cheating or personation.
- Telecommunications Act section 42 offences are cognizable and non-bailable, and the Act prescribes a minimum trial-court level.
- Section 173 BNSS permits information concerning a cognizable offence to be given at any police station irrespective of where the offence occurred.
- A police complaint, telecom complaint, bank dispute and RBI Ombudsman complaint serve different purposes and may need to proceed together.
1. What Is SIM-Swap Fraud?
A mobile number is a telecommunication identifier. In a lawful replacement, the subscriber requests a fresh SIM or eSIM because the earlier SIM is lost, damaged or being upgraded. In fraud, another person uses forged, stolen or manipulated identity information, corrupt assistance, social engineering or an unauthorised process to obtain control of the number.
The expression “SIM swap” is often used loosely. Legally and technically, the incident may be:
- an unauthorised replacement SIM;
- an eSIM activation or profile transfer;
- a fraudulent mobile-number port;
- activation of a connection using another person’s identity;
- takeover of the telecom self-care account;
- SIM cloning or tampering, which is technically distinct from a replacement; or
- a phone/account compromise that only appears to be a SIM swap.
The distinction matters because the responsible systems, records and accused persons differ. A replacement-SIM case requires the replacement request, customer-verification record, point-of-sale details, ICCID/eSIM profile and activation logs. A porting case additionally requires the unique porting process and recipient operator’s records. A device compromise requires forensic examination of the handset and applications.
2. Warning Signs of a Mobile-Number Takeover
- The phone unexpectedly loses voice, SMS and mobile-data service while nearby users on the same network have service.
- The device displays “No SIM”, “SIM not provisioned”, “Emergency calls only” or a registration failure.
- The operator sends a replacement, eSIM, porting or service-deactivation message that the subscriber did not request.
- Calls to the number ring on another device or callers report that an unknown person answered.
- Bank, email, cloud or social-media password-reset alerts appear without request.
- A UPI application reports registration on a new device, change of mobile number or creation of a new UPI PIN.
- Security emails show an unfamiliar login, device, IP address or location.
- Messages are marked read, a messaging account logs out, or contacts receive unusual requests for money.
- A telecom-store or customer-care record shows a replacement or port request not made by the subscriber.
Network loss alone is not proof of fraud. The subscriber should test the device, restart it, check for an outage and place the SIM in another compatible handset if safe to do so. But those checks must not delay protective action where banking or account-security alerts are also present.
3. Emergency Response: The Correct Order of Action
Step 1: Suspend the unauthorised SIM or eSIM
From an alternate phone, contact the telecom operator’s fraud or customer-care channel. Ask the operator to suspend outgoing and incoming services on the replacement profile, freeze any pending port, preserve all records and issue a complaint number. Visit an authorised store with original identity documents as soon as possible, but do not treat the physical visit as a reason to postpone emergency suspension.
Ask for written confirmation of:
- the date and exact time of the replacement, eSIM activation or porting request;
- the channel, store and point-of-sale identifier used;
- the verification and KYC method;
- the old and new SIM identifiers, subject to lawful disclosure;
- the activation and suspension times;
- changes to the subscriber profile or registered email; and
- the operator complaint/escalation reference.
Step 2: Block the financial channels
- Notify every linked bank through its 24×7 unauthorised-transaction channel.
- Block mobile banking, internet banking, cards and new-beneficiary transfers.
- Deregister or suspend UPI on the compromised number and device.
- Notify linked wallets and prepaid-payment instruments.
- Request immediate prevention of further transactions, beneficiary freeze/recall where available and a written complaint number.
- Do not rely only on a branch visit; the reporting timestamp can determine liability.
Step 3: Secure the root accounts
The linked email often controls password recovery for several services. From a clean device, change its password, terminate unknown sessions, replace SMS-only authentication where possible and secure cloud, social-media, messaging, tax, demat and business accounts. Preserve access logs and security alerts before they expire.
Step 4: Report the financial fraud
Call the national cyber-fraud helpline 1930 immediately and file the complaint on the National Cyber Crime Reporting Portal. Speed is crucial because transferred funds may move through multiple accounts within minutes. For the recovery process, see our detailed guide on cyber-fraud money recovery, bank holds and restitution remedies.
Step 5: Make a written police complaint
The complaint should seek registration of the appropriate FIR and immediate preservation from the telecom operator, banks, UPI participants, email provider and device/application providers. Attach the chronology, transaction records, complaint acknowledgements and proof that the replacement/porting request was unauthorised.
4. Evidence That Must Be Preserved
| Evidence source | Records to preserve or request |
|---|---|
| Victim’s device | Network status, SIM settings, call/SMS logs, security alerts, screenshots, device identifiers and original handset |
| Telecom operator | Replacement/eSIM/port request, KYC and authentication trail, point-of-sale details, old/new SIM identifiers, activation logs, self-care logins, CDR/IPDR and complaint recordings as lawfully available |
| Bank | Transaction log, authentication method, device binding, login IP/device, beneficiary addition, risk alerts, SMS/email delivery, fraud score and complaint timestamps |
| UPI participants | Device-registration event, UPI PIN creation/reset trail, PSP/TPAP records, payer/payee VPA, RRN, beneficiary bank and dispute record |
| Email/cloud provider | Login history, recovery changes, IP addresses, session/device details and security notifications |
| Police/NCRP/1930 | Acknowledgement, diary/FIR number, transaction hold request, bank replies and investigating-officer details |
Do not factory-reset the phone, discard the original SIM, delete security emails or overwrite the relevant account history. A screenshot is useful, but it is not a substitute for the source record, metadata, platform logs and a compliant certificate under section 63 of the Bharatiya Sakshya Adhiniyam, 2023.
5. Telecommunications Act, 2023: Specific SIM-Fraud Offences
Section 42 of the Telecommunications Act, 2023 is directly relevant:
- Section 42(2): directly, indirectly or through personation gaining or attempting unauthorised access to a telecommunication network or an authorised entity’s data, transferring such data, or unlawfully intercepting a message may attract imprisonment up to three years, fine up to ₹2 crore, or both.
- Section 42(3)(b)–(c): unauthorised use or tampering of telecommunication identifiers may apply on the proved facts.
- Section 42(3)(e): obtaining subscriber identity modules or other telecommunication identifiers through fraud, cheating or personation is punishable with imprisonment up to three years, fine up to ₹50 lakh, or both.
- Section 42(6): abetment, attempt and conspiracy are also addressed.
- Section 42(7): all offences specified in section 42 are cognizable and non-bailable.
- Section 42(8): no court inferior to a Chief Metropolitan Magistrate or Chief Judicial Magistrate of the first class may try an offence under the Act.
The Telecommunications Act operates in addition to other liabilities. Section 50 extends the Act to relevant conduct outside India where the offence involves a telecommunication service provided in India, or telecom equipment/network located in India.
6. Telecom Cyber Security Rules and Operator Duties
The Telecommunications (Telecom Cyber Security) Rules, 2024, as amended, prohibit endangering telecom cyber security through misuse of telecom equipment, identifiers, networks or services by fraud, cheating, personation, fraudulent messages or other unlawful use. Telecommunication entities must implement security policies, identify and reduce security-incident risks, respond rapidly and comply with Central Government directions.
The 2025 amendments strengthened the framework around telecom identifiers and introduced mechanisms including mobile-number validation. A victim’s individual refund or compensation claim, however, must still be founded on the operator’s service obligation, the actual replacement/KYC failure, contract, regulatory complaint process and proof of resulting loss. The existence of a cyber-security rule does not by itself establish every element of civil damages.
7. Sanchar Saathi: What It Can and Cannot Do
The Department of Telecommunications’ Sanchar Saathi/DoT eServices portal provides tools including “Know Mobile Connections in Your Name” through TAFCOP and reporting of suspected fraudulent communications through Chakshu. These tools help detect unauthorised connections and report suspicious calls/messages.
Chakshu is not a substitute for reporting an already completed cybercrime or financial loss. If money has been debited, use 1930, the National Cyber Crime Reporting Portal, the bank’s fraud channel and the police process. A suspected-fraud communication report and an FIR are legally different records.
8. Bharatiya Nyaya Sanhita and IT Act Provisions
Depending on the acts proved, a SIM-swap case may also attract the Bharatiya Nyaya Sanhita, 2023 and the Information Technology Act, 2000.
| Provision | Potential application |
|---|---|
| Section 318 BNS | Cheating through deception causing dishonest delivery of property or a harmful act/omission |
| Section 319 BNS | Cheating by pretending to be another person, substituting one person for another, or representing a false identity |
| BNS forgery/false-electronic-record provisions | Forged KYC, identity or electronic records, depending on the document and intention proved |
| Section 66C IT Act | Dishonest or fraudulent use of another person’s electronic signature, password or unique identification feature |
| Section 66D IT Act | Cheating by personation through a communication device or computer resource |
| Sections 43 and 66 IT Act | Specified unauthorised access or computer-related conduct, with the required dishonest or fraudulent intention for criminal liability under section 66 |
| Sections 72/72A IT Act | Unauthorised disclosure in the specific confidentiality/privacy or contractual circumstances covered by those provisions |
Sections should not be added mechanically. For example, a failed attempt to obtain a SIM may engage attempt or telecom provisions even if no bank property was delivered. Cheating by delivery of property requires proof of its statutory ingredients. Forgery requires a false document or false electronic record, not merely an oral lie.
9. FIR, Zero FIR and Police-Refusal Remedies
Under section 173(1) of the Bharatiya Nagarik Suraksha Sanhita, 2023, information relating to a cognizable offence may be given orally or electronically to the officer in charge of a police station irrespective of the area where the offence was committed. Electronically supplied information must be signed within three days, and the informant/victim is entitled to a free copy of the recorded information.
If the station refuses registration, section 173(4) permits the substance to be sent in writing and by post to the Superintendent of Police. If the remedy still fails, an affidavit-supported application may be made to the Magistrate under sections 173(4) and 175(3), subject to the statutory process. See our guide on Zero FIR, e-FIR and remedies for police refusal.
Jurisdiction
SIM-swap transactions may involve the subscriber’s location, telecom point of sale, operator system, offender, recipient bank and place where messages were received. Sections 197–202 BNSS address the ordinary place of trial, offences spanning several areas, act/consequence jurisdiction and cheating through electronic communications. A Zero FIR secures prompt registration but does not prevent lawful transfer to the competent investigating unit.
10. RBI Rules on Customer Liability for Unauthorised Transactions
The RBI’s 6 July 2017 circular on limiting customer liability in unauthorised electronic banking transactions remains central to bank-account claims. It classifies liability by the source of the breach and reporting time.
| Situation | Customer-liability position under the RBI framework |
|---|---|
| Contributory fraud, negligence or deficiency of the bank | Zero liability, irrespective of whether the customer reported the transaction |
| Third-party breach; deficiency lies neither with bank nor customer; reported within three working days of the bank’s communication | Zero liability |
| Qualifying third-party breach reported within four to seven working days | Limited to the transaction value or the prescribed account-category cap, whichever is lower |
| Third-party breach reported beyond seven working days | Determined under the bank’s Board-approved policy |
| Loss caused by customer negligence, such as sharing payment credentials | Customer bears loss until reporting; loss after reporting is borne by the bank |
On notification, the bank is directed to make a shadow reversal within ten working days, value-dated to the unauthorised transaction, without waiting for insurance settlement. Liability and compensation must be resolved within the bank’s Board-approved period, not exceeding ninety days. Importantly, the circular places the burden of proving customer liability on the bank.
A SIM swap does not automatically establish a “third-party breach” for RBI-liability purposes. The bank may allege customer negligence; the customer may allege failure in telecom KYC, bank device-binding, behavioural monitoring or authentication controls. The dispute must be decided from evidence, not merely from the fact that an OTP was technically generated or used.
11. What the Bank Complaint Must Demand
- Registration as an unauthorised electronic transaction, not a generic service request.
- The exact date and time of the complaint acknowledgement.
- Immediate disabling of digital channels and prevention of further loss.
- Beneficiary-bank recall/hold and inter-bank fraud communication.
- Shadow reversal under the applicable RBI directions.
- Preservation of authentication, device-binding, IP, beneficiary-addition and risk-engine records.
- A reasoned determination identifying whether the bank alleges bank deficiency, third-party breach or customer negligence.
- A copy/link of the bank’s Board-approved customer-liability policy.
- Interest correction and removal of charges caused by the disputed debit.
- A final speaking response for escalation to the RBI Ombudsman.
If the receiving account is later frozen because the fraud proceeds moved through it, the holder’s remedy is separate. See our article on cyber-cell account freezes, layer accounts and de-freezing procedure.
12. UPI and Wallet Complaints
Raise the transaction dispute first through the UPI application/PSP and bank using the transaction’s RRN. NPCI provides an official UPI Help and dispute-redressal portal. A UPI complaint is not a substitute for the bank’s unauthorised-transaction complaint, 1930 report or FIR where fraud is alleged.
For non-bank prepaid-payment instruments, RBI’s PPI Master Directions contain a parallel customer-liability framework. The correct regulated entity and scheme must be identified from who issued the wallet/PPI and who maintained the debited account.
13. RBI Ombudsman Escalation in 2026
The customer must first complain to the bank or other RBI-regulated entity. Under the current Reserve Bank–Integrated Ombudsman framework, an Ombudsman complaint may be filed if no reply is received within thirty days or the applicable higher RBI/NPCI/card-network timeline, or if the customer is dissatisfied with the response.
The complaint must ordinarily be lodged within ninety days from expiry of the applicable response period or from the last communication of the regulated entity, whichever is later. Filing through RBI’s Complaint Management System is free. The complaint should annex the bank complaint, acknowledgement, transaction details, telecom record, 1930/NCRP/FIR material, bank response and relief sought.
A police investigation into a criminal offence does not by itself make the banking-service grievance identical to a court proceeding. However, a matter already pending or adjudicated on the same grievance before a court, tribunal, arbitrator or other judicial/quasi-judicial forum may affect Ombudsman maintainability. Forum strategy must therefore be planned before parallel filings.
14. Complaint Against the Telecom Operator
- Lodge a written complaint with the operator and obtain a docket number.
- Escalate through the operator’s published grievance and appellate mechanism.
- Demand preservation, an internal fraud investigation and a reasoned response.
- Use Sanchar Saathi/TAFCOP to inspect other connections issued in the subscriber’s name.
- Report a dishonest point of sale, dealer or insider specifically, with store and personnel details where known.
- Do not demand disclosure that the operator can lawfully provide only to police or under a court/government direction; instead, seek preservation and have the investigating agency requisition it.
A consumer claim may be considered where deficient telecom service or verification caused loss, subject to the applicable consumer-law position, contract, proof of deficiency, causation, limitation and forum jurisdiction. The financial loss must be linked to the telecom failure; the mere fact of replacement does not prove that every later transaction was caused by it.
15. Civil, Consumer and Writ Remedies
Depending on the parties and facts, relief may be pursued through a consumer complaint, civil action, contractual grievance mechanism or writ jurisdiction against a public authority. Possible relief includes:
- restoration and protection of the mobile number;
- declaration that replacement/porting was unauthorised;
- production or preservation of KYC and activation records;
- reversal of unauthorised banking losses under regulatory directions;
- compensation for proved deficiency and consequential loss;
- correction of adverse account or credit consequences; and
- urgent restraint against further use of compromised identifiers.
The appropriate forum depends on the defendant, relief, value, territorial facts and availability of an efficacious statutory remedy. Telecom and banking claims should not be combined mechanically if doing so creates jurisdictional objections or obscures distinct causes of action.
16. Limitation, Court Fee and Procedure
- Cybercrime/FIR: no court fee is payable. Report immediately because telecom, IP, device and bank records are retention-sensitive.
- Bank complaint: notify at once. RBI customer liability is expressly linked to working days from receipt of the transaction communication.
- RBI Ombudsman: first approach the regulated entity; then comply with the current thirty-day response and ninety-day filing rules described above. No filing fee is charged.
- Telecom grievance: follow the operator’s current complaint and appellate timelines; preserve each docket and response.
- Consumer complaint: limitation is ordinarily two years from accrual under section 69 of the Consumer Protection Act, 2019, subject to condonation for sufficient cause. Fee depends on consideration/value and the current Consumer Protection Rules.
- Civil suit: limitation, valuation, pecuniary jurisdiction and court fee depend on the cause of action and relief. Damages and injunction claims must be separately valued under the applicable State law.
- Magistrate application: filing/process requirements are governed by BNSS and the concerned State criminal-court rules; an affidavit is required for the section 175(3) investigation route.
17. Defence Where a Dealer, Employee or Subscriber Is Accused
An allegation of SIM fraud requires proof of attribution and intention. A dealer’s credentials may be misused; an employee may have followed a system approval; an accused subscriber may be a mule or victim of identity theft. Equally, a paper KYC file cannot neutralise evidence of personation or deliberate circumvention.
- Preserve point-of-sale access logs, CCTV, KYC inputs, authentication results and approval hierarchy.
- Identify who initiated, verified and activated the replacement.
- Separate negligence, contractual breach, regulatory contravention and criminal intention.
- Do not alter customer records or contact the complainant to procure withdrawal.
- Secure forensic images of relevant workstations/devices through lawful procedure.
- Assess anticipatory or regular bail promptly because section 42 offences are cognizable and non-bailable.
- Challenge provisions whose ingredients are absent, while offering verifiable records and cooperation.
Bail analysis must account for the number of victims, financial loss, conspiracy, access to subscriber systems, risk of evidence manipulation, recoveries, criminal history and cooperation. A general three-year maximum does not make a Telecommunications Act section 42 offence bailable; section 42(7) expressly classifies all section 42 offences as non-bailable.
18. Common Mistakes That Weaken Recovery
- Waiting until the next working day to notify the bank.
- Reporting only to the telecom operator and not disabling banking/UPI.
- Obtaining a new SIM but failing to preserve the unauthorised replacement record.
- Factory-resetting the phone or deleting security alerts.
- Telling the bank only that “money is missing” without invoking the unauthorised-transaction framework.
- Failing to record the exact time of every complaint.
- Assuming use of an OTP conclusively proves customer negligence.
- Conversely, assuming every SIM swap automatically guarantees a bank refund.
- Filing a vague FIR without telecom identifiers, UTR/RRN, beneficiary details or a preservation request.
- Paying an unofficial recovery agent claiming access to 1930 or the bank.
19. Lawyer-Ready Documents Checklist
- One-page chronology with exact dates and times.
- Original handset and old SIM/eSIM details.
- Telecom outage/replacement/porting messages.
- Operator complaint and escalation references.
- Identity documents and proof of lawful subscription.
- Bank statement and disputed transaction list.
- UTR/RRN, VPA, beneficiary and transaction-channel details.
- Bank fraud complaint, acknowledgement and final response.
- UPI/PSP/wallet dispute records.
- 1930 and NCRP acknowledgement.
- Police complaint, Zero FIR/FIR and investigating-officer details.
- Email/cloud/social account security logs.
- TAFCOP result showing connections issued in the person’s name.
- Section 63 BSA certificate and forensic report where available.
Frequently Asked Questions
How can I know whether my SIM has been swapped?
Unexpected network loss combined with an unrequested replacement/porting message, password reset, UPI registration or unknown login is a strong warning. Only the telecom operator’s records can conclusively confirm whether another SIM/eSIM profile was activated.
Should I call the telecom company or bank first?
Both must be contacted immediately, preferably in parallel through alternate devices. Suspend the telecom identifier and block financial channels without waiting for a branch or store visit.
Will the bank refund money lost after a SIM swap?
Not automatically. Liability depends on bank deficiency, third-party breach, customer negligence, reporting time and evidence. RBI directions provide zero or limited liability in specified cases and place the burden of proving customer liability on the bank.
Is use of a correct OTP proof that I authorised the payment?
No conclusive presumption arises merely from a technically valid OTP. In a SIM takeover, the issue is who controlled the number/device and how authentication was compromised. The bank may still rely on other evidence of customer conduct, so the complete authentication trail is required.
Is obtaining a SIM through another person’s identity bailable?
Section 42(3)(e) of the Telecommunications Act punishes obtaining a SIM or telecom identifier through fraud, cheating or personation. Section 42(7) states that all offences under section 42 are cognizable and non-bailable.
Can I file a Zero FIR for SIM-swap fraud?
Yes, where the information discloses a cognizable offence. Section 173 BNSS allows it to be given at any police station irrespective of area. The case may later be transferred to the competent cyber unit.
What if no money was stolen?
Unauthorised obtaining or tampering of the SIM/identifier, attempted access, personation and related conduct may still be offences. Report promptly to prevent account takeover and preserve the evidence.
Can I check how many SIMs are issued in my name?
Yes. The DoT’s TAFCOP service under Sanchar Saathi permits users to check mobile connections issued in their name and report connections they do not recognise.
Can I approach the RBI Ombudsman immediately?
The bank or regulated entity must first receive the complaint. The current Ombudsman framework then permits escalation after the applicable response period or earlier unsatisfactory resolution, subject to maintainability and limitation.
Conclusion
SIM-swap fraud is a race between the offender’s account takeover and the victim’s containment measures. The strongest response is simultaneous: suspend the telecom identifier, block financial access, secure the email, report through 1930/NCRP, demand bank and telecom preservation, and register the criminal case.
For recovery, the decisive evidence is the timeline. The exact moment of network loss, replacement activation, bank alert, customer report, beneficiary addition and transaction determines causation and regulatory liability. A precise chronology supported by system records is stronger than either side’s assumption about an OTP.
This article provides general legal information as of 20 August 2026. It is not legal advice or solicitation. Telecom regulations, banking directions, platform processes and court practice are fact-specific and may change. Where financial loss is occurring, contact the telecom operator, bank, 1930 and police immediately.