SIM Swap & OTP Fraud in India 2026: Bank Liability, Telecom Negligence, 1930/NCRP, FIR, Refund & Recovery

By Adv. Govind Bali

SIM swap fraud is one of the most dangerous forms of account-takeover fraud because the victim may lose control of the mobile number that receives banking alerts, one-time passwords, password-reset messages and account-recovery codes. The fraudster does not necessarily need physical possession of the victim’s phone. If a duplicate SIM or eSIM is fraudulently issued for the victim’s number, the genuine SIM may suddenly lose network connectivity while the attacker begins receiving OTPs and alerts.

In 2026, the legal position is increasingly important because Indian courts have begun treating SIM-swap cases as more than ordinary ‘customer shared OTP’ disputes. Where the customer did not share credentials, reported promptly and the fraud arose through a third-party breach or negligent duplicate-SIM issuance, RBI’s customer-protection framework and the duties of telecom service providers can become central to recovery.

This guide explains the immediate response, bank-liability framework, telecom remedies, criminal-law provisions, 1930/NCRP process, evidence required, RBI Ombudsman route and recent 2026 judgments.

Quick Answer: What Should You Do If Your SIM Suddenly Stops Working and Money Is Debited?

  1. Assume a SIM-swap risk immediately if your phone unexpectedly loses network in a location where service is normally available.
  2. Use another phone to contact your telecom operator and ask whether any SIM replacement, eSIM activation, porting, ownership change or KYC update has occurred.
  3. Contact every bank linked to that mobile number and block internet banking, mobile banking, UPI, cards and high-value transfers as appropriate.
  4. Report every unauthorised transaction to the bank immediately and obtain complaint numbers and timestamps.
  5. Call 1930 for financial cyber fraud and submit the complaint on the National Cyber Crime Reporting Portal.
  6. Change email, banking and financial-account passwords from a clean device.
  7. Ask the telecom operator to preserve the duplicate-SIM application, KYC material, activation logs, point-of-sale details and internal approval trail.
  8. Ask the bank to preserve login IPs, device identifiers, beneficiary-addition logs, transaction-limit changes, OTP-generation/delivery logs and fraud-monitoring alerts.
  9. Submit a detailed cyber-police complaint and seek FIR registration where cognizable offences are disclosed.
  10. If the bank rejects liability, invoke the RBI customer-protection framework and, where necessary, the Reserve Bank – Integrated Ombudsman Scheme, 2026.

What Is SIM Swap Fraud?

A SIM swap occurs when control of a mobile number is moved from the legitimate subscriber’s SIM to another SIM or eSIM. In a fraudulent SIM swap, the attacker impersonates the subscriber or abuses the replacement process so that the telecom operator activates a new SIM for the same number.

Once the fraudulent SIM is active, the original SIM may stop receiving calls and messages. The attacker may then receive banking OTPs, password-reset codes, UPI alerts and account-recovery messages. If the attacker has already obtained login credentials through phishing, malware, data leakage, social engineering or another source, control of the mobile number can defeat an important layer of two-factor authentication.

RBI itself has specifically warned customers about SIM-swap and SIM-cloning fraud, noting that fraudsters may obtain a duplicate SIM for the mobile number registered with the bank and then use OTPs received on the duplicate SIM to carry out unauthorised transactions.

Common SIM Swap Fraud Pattern

Stage What the fraudster may do What the victim may observe
1. Data collection Obtains name, mobile number, PAN/Aadhaar details, email, bank relationship or login information. Often nothing unusual.
2. Impersonation Approaches telecom operator, retailer or service channel pretending to be the subscriber. Possible unexpected KYC or service messages.
3. Duplicate SIM/eSIM Gets replacement SIM activated. Original phone suddenly loses network.
4. Account takeover Resets passwords, adds beneficiaries, raises transaction limits or activates UPI/net banking. Victim may receive no OTP because OTP goes to duplicate SIM.
5. Fund transfer Moves money rapidly through mule/layer accounts. Victim notices debit after email alert, delayed SMS, app access or bank call.

The Most Important Warning Sign: Sudden Loss of Mobile Network

An unexplained loss of network should not be treated only as a telecom inconvenience, particularly where the mobile number is linked to bank accounts. The 2026 Bombay High Court decision in Subodh C. Korde v. Union of India examined repeated unauthorised SIM replacements followed by the addition of beneficiaries, enhancement of transfer limits and eight unauthorised transactions. The Court recognised SIM swapping as a mechanism by which criminals intercept OTPs and banking alerts.

As a practical rule, if the phone suddenly shows ‘No Service’ or loses network for an unusual period, the subscriber should immediately contact the telecom operator from another number and simultaneously secure linked banking accounts.

TRAI’s Seven-Day Anti-Fraud Porting Restriction

TRAI’s Telecommunication Mobile Number Portability (Ninth Amendment) Regulations, 2024 introduced an anti-fraud safeguard specifically aimed at fraudulent SIM swaps. A Unique Porting Code is not to be issued where seven days have not elapsed from the date of SIM swap or replacement. The rule has been in force since 1 July 2024.

This does not by itself prevent every fraudulent SIM replacement, but it reduces the risk of an attacker immediately moving the compromised number to another operator and making reversal more difficult.

Bank Liability in SIM Swap Fraud: RBI’s 2017 Customer-Protection Framework

The most important banking rule remains RBI’s circular dated 6 July 2017 on limiting customer liability in unauthorised electronic banking transactions. The circular applies to scheduled commercial banks, including small finance banks and payments banks, with corresponding RBI frameworks for other categories.

The liability analysis is not simply ‘OTP was used, therefore the customer authorised the payment’. The core question is who was responsible for the breach and how quickly the customer reported the unauthorised transaction.

Zero Liability

RBI provides for zero customer liability in two important situations:

  • where the unauthorised transaction results from contributory fraud, negligence or deficiency on the part of the bank, irrespective of when the customer reports it; and
  • where there is a third-party breach, the deficiency lies neither with the bank nor the customer, and the customer reports the unauthorised transaction within three working days of receiving the bank’s communication about it.

Limited Liability for Reporting in Four to Seven Working Days

Where the responsibility lies neither with the bank nor with the customer and reporting occurs within four to seven working days, customer liability is capped according to the RBI framework and the type of account.

Customer Negligence

If the loss occurs because the customer himself or herself negligently shared payment credentials, RBI states that the customer bears the loss up to the time the unauthorised transaction is reported. Loss occurring after reporting must be borne by the bank.

This makes evidence critical. A bank cannot mechanically infer customer negligence merely because an OTP was successfully entered. In a genuine SIM swap, the OTP may have been delivered to the fraudster’s duplicate SIM.

Burden of Proof Is on the Bank

RBI’s circular expressly places the burden of proving customer liability on the bank. This can be decisive where the bank alleges that the customer must have shared OTPs but cannot establish how or when that occurred.

Shadow Reversal Within Ten Working Days

Where the customer is entitled to zero or limited liability, RBI requires the bank, on notification, to credit the amount involved in the unauthorised electronic transaction within ten working days, without waiting for settlement of an insurance claim. The credit is to be value-dated to the date of the unauthorised transaction.

2026 Bombay High Court: Subodh C. Korde v. Union of India

In Subodh C. Korde v. Union of India, decided on 6 April 2026, the Bombay High Court dealt directly with a SIM-swap banking fraud involving eight unauthorised transactions totalling ₹38.04 lakh.

The Court found that the petitioner had not shared his password or OTP, that his SIM had been swapped, and that he had acted promptly after becoming aware of the debit. The Court rejected the bank’s attempt to place the entire burden on the customer merely because OTP authentication had occurred.

Applying the RBI circular, the Court held that the customer was entitled to zero liability and directed HDFC Bank to remit ₹38.04 lakh with interest. The judgment is significant because it expressly recognises that successful OTP authentication is not conclusive proof that the legitimate subscriber received or used the OTP.

PNP Polytex and the 2026 SIM-Swap Refund Line

In PNP Polytex Private Limited v. Reserve Bank of India, decided on 28 April 2026, the Bombay High Court again dealt with a substantial cyber fraud involving a duplicate SIM. The case reinforces the importance of RBI’s zero-liability framework where the customer has not contributed to the fraud and reports the unauthorised transactions promptly.

For businesses, this is especially important because corporate accounts may involve higher transfer limits, multiple beneficiaries and larger losses. A company should preserve board/authorisation records, transaction mandates, internal access logs and the telecom trail immediately after detection.

2026 Karnataka High Court: Telecom Provider Can Be Liable for Negligent SIM Replacement

In Sri Basaveshwara Pattana Sahakara Bank Niyamitha v. Canara Bank and the connected BSNL matter decided on 1 June 2026, the Karnataka High Court examined a fraud in which a duplicate SIM was issued and approximately ₹87.70 lakh was siphoned through unauthorised transactions.

The Court treated negligent issuance of the duplicate SIM as a serious failure because the telecom provider controls the mobile-number layer on which OTP-based authentication depends. It held BSNL civilly liable where negligent or wrongful duplicate-SIM issuance enabled the fraud.

This judgment is important because SIM-swap litigation may involve two distinct liability tracks:

  • Bank/customer liability under RBI’s unauthorised-transaction framework; and
  • Telecom-provider liability where deficient KYC, employee misconduct or negligent duplicate-SIM issuance directly enabled the fraud.

Do Not Accept the Statement ‘OTP Was Used, So the Transaction Is Valid’ Without Investigation

In a conventional OTP-sharing fraud, the customer may voluntarily disclose an OTP to the fraudster. In SIM-swap fraud, the entire point is that the fraudster may receive the OTP directly on the duplicate SIM.

The correct investigation should therefore examine:

  • when the genuine SIM lost network;
  • when replacement was requested and activated;
  • who requested the replacement;
  • what KYC documents and photographs were used;
  • which telecom outlet or digital channel processed the replacement;
  • who approved it;
  • when the bank generated each OTP;
  • where and to which SIM/session the OTP was delivered;
  • whether beneficiaries were newly added;
  • whether transaction limits were increased;
  • whether bank fraud-monitoring systems generated alerts; and
  • what device, IP address and geolocation were associated with the fraudulent banking session.

Immediate Action Against the Telecom Operator

Contact the operator immediately and obtain a complaint number. The request should not merely say ‘network not working’. State expressly that you suspect an unauthorised SIM swap or duplicate SIM issuance and require immediate restoration of the number.

Ask the operator to preserve:

  • SIM swap/replacement request;
  • customer application form or digital request;
  • photograph and KYC documents submitted;
  • e-KYC/D-KYC logs where applicable;
  • point-of-sale/franchise/service-centre details;
  • employee/agent ID that processed and approved the request;
  • date and exact time of request and activation;
  • old and new SIM identifiers;
  • IP/device details for online eSIM activity, where available;
  • SMS/email/alternate-number alerts generated by the operator; and
  • any subsequent porting or ownership-change request.

Do not rely only on call-centre conversations. Send a written email or grievance so that the timeline is documented.

Immediate Action Against the Bank

Report the transaction through every available official channel and preserve the complaint number. The RBI framework makes reporting time important, so the complaint timestamp should be beyond dispute.

Ask the bank to:

  • block further digital transactions;
  • disable compromised mobile/internet banking credentials;
  • freeze or recall transfers where operationally possible;
  • mark every disputed transaction as unauthorised;
  • preserve beneficiary-addition logs and cooling-period records;
  • preserve transfer-limit enhancement records;
  • preserve login IPs, device IDs and session logs;
  • preserve OTP generation, dispatch and delivery records;
  • preserve fraud-engine alerts and manual approvals;
  • preserve call-centre, email and complaint records; and
  • apply the RBI customer-liability circular rather than treating the matter only as a police dispute.

1930 and NCRP: Financial Cyber-Fraud Response

For financial fraud, call 1930 immediately and submit the complaint on the National Cyber Crime Reporting Portal. The purpose of rapid reporting is to allow the cyber-fraud response system and participating banks/financial institutions to trace and place holds on funds before they are dissipated through successive accounts.

For a detailed victim-side recovery workflow, see our guide on Cyber Financial Fraud Recovery in India 2026.

A 1930/NCRP complaint does not replace a bank complaint. Both should be made immediately because they serve different purposes: the bank complaint preserves the customer’s liability/reversal claim, while 1930/NCRP supports tracing, holds and police action.

Cyber Complaint vs FIR

Submitting an NCRP complaint does not automatically mean that an FIR has been registered. Where the facts disclose cognizable offences, the victim should pursue registration of information under Section 173 BNSS and preserve the NCRP acknowledgement, bank complaint, telecom complaint and transaction chronology.

For the current BNSS route, including Zero FIR and police-refusal remedies, see Cybercrime Complaint vs FIR in India 2026.

Which Criminal Provisions Can Apply?

The sections depend on the actual method used. Commonly relevant provisions may include:

  • Section 66C, Information Technology Act, 2000: fraudulent or dishonest use of another person’s electronic signature, password or unique identification feature;
  • Section 66D, Information Technology Act: cheating by personation using a communication device or computer resource;
  • Section 319, Bharatiya Nyaya Sanhita: cheating by personation;
  • Section 318(4), BNS: cheating that dishonestly induces delivery of property, punishable with imprisonment up to seven years and fine;
  • forgery/use of forged records provisions where fake KYC, forged identity documents or fabricated electronic records are used; and
  • conspiracy, receiving/handling proceeds, criminal breach of trust or other provisions depending on the role of telecom insiders, bank insiders, mule-account holders and other participants.

The complaint should describe facts first and avoid forcing every possible penal section into the narrative without evidence.

Evidence Checklist for a SIM Swap Case

Source Evidence to preserve
Victim device screenshots of ‘No Service’, call logs, SMS, bank alerts, email alerts, app notifications, device details
Telecom SIM replacement request, KYC, photo, agent ID, outlet, approval logs, activation time, SIM identifiers
Bank account statements, beneficiary additions, limit changes, login IPs, device IDs, OTP logs, fraud alerts
1930/NCRP acknowledgement number, complaint copy, transaction details, status updates
Police complaint, FIR/Zero FIR, seizure/hold communications, notices and statements
Email/cloud security alerts, login-history exports, password-reset notices and original headers
Corporate victim authorised-user matrix, board mandates, internal approval chain, cyber-security logs and incident report

Why the Timeline Matters

A useful chronology should record exact timestamps:

  1. last time the genuine SIM was working;
  2. first observed network loss;
  3. time the fraudulent SIM was requested and activated;
  4. time beneficiaries were added;
  5. time transaction limits changed;
  6. time each disputed transaction occurred;
  7. time the bank sent each alert;
  8. time the victim first learned of the fraud;
  9. time the bank was notified;
  10. time 1930/NCRP was notified; and
  11. time telecom and police complaints were made.

This chronology directly affects RBI liability analysis and may also show whether the telecom operator or bank had an opportunity to prevent further loss.

What If the Bank Says the Customer Must Have Shared the OTP?

Ask the bank to identify the evidence on which that allegation is based. RBI places the burden of proving customer liability on the bank. In a SIM-swap case, important questions include whether the OTP went to the genuine SIM at all and whether the customer had network connectivity at the relevant time.

The Subodh Korde judgment demonstrates why a bare assertion that ‘OTP authentication was successful’ may be insufficient where telecom records establish SIM swapping and the customer denies receiving the OTP.

What If the Telecom Operator Says Its KYC Was Proper?

Seek the actual KYC and replacement record. A conclusion cannot be tested without the underlying material. Compare the photograph, signatures, identity documents, address, request reason, old SIM status, service centre, activation time and approving employee.

Where a duplicate SIM was issued to an impostor through deficient verification, civil/consumer remedies against the operator may arise in addition to criminal investigation. The Karnataka High Court’s June 2026 BSNL decision is a major authority on this point.

RBI Integrated Ombudsman Scheme, 2026

From 1 July 2026, the Reserve Bank – Integrated Ombudsman Scheme, 2026 replaced the 2021 scheme for new complaints. It provides a cost-free alternate grievance mechanism for complaints involving deficiency in service by covered RBI-regulated entities.

The victim should first complain to the bank. If the bank rejects the complaint wholly or partly, gives an unsatisfactory response, or does not respond within the applicable period, the complaint may be escalated through RBI’s Complaint Management System subject to the Scheme’s maintainability and limitation requirements.

The Ombudsman route does not replace a cyber-police complaint. One concerns banking-service deficiency and customer redress; the other concerns investigation of the criminal fraud.

Can the Victim Proceed Against Both the Bank and Telecom Company?

Potentially yes, because the legal duties are different. The bank’s obligations may arise under RBI customer-protection directions, contractual banking duties and the facts of its fraud controls. The telecom operator’s obligations arise from proper subscriber verification, service standards and the integrity of the SIM-replacement process.

The victim should avoid double recovery for the same loss, but that does not prevent investigation of independent negligence or deficiency by different entities.

What If the Customer Actually Shared an OTP Before the SIM Swap?

The case becomes fact-sensitive. RBI’s framework distinguishes customer negligence from third-party breaches. If the customer voluntarily shared credentials, liability may attach to the customer for losses occurring before reporting. But a bank or telecom provider cannot assume every later transaction was authorised merely because one credential was previously shared.

The transaction sequence should be broken down event by event: credential compromise, SIM replacement, beneficiary addition, limit change, OTP delivery and each debit.

What If the Fraud Involves UPI?

Immediately disable UPI access, complain to the bank/PSP app, call 1930 and record the UTR/transaction IDs. UPI fraud can move money within seconds through multiple accounts, so early reporting is critical. The same SIM-swap evidence—duplicate-SIM timeline, device changes and OTP/account-recovery events—should be preserved.

What If the Fraud Involves a Company or Corporate Mobile Number?

Corporate victims should act on two fronts. First, secure the bank account and telecom number. Second, preserve internal governance records showing who was authorised to request SIM replacement, who controlled net banking and whether any employee approved the change.

DoT has strengthened SIM-swap/replacement controls for business connections, including KYC-based replacement procedures. A company should obtain the operator’s complete request and approval trail and compare it with its authorised-signatory records.

Common Mistakes After a SIM Swap

  • Waiting several hours to see whether network service returns.
  • Reporting only to the telecom operator but not the bank.
  • Reporting only to the bank but not 1930/NCRP.
  • Failing to obtain complaint numbers and timestamps.
  • Changing phones or deleting apps before preserving evidence.
  • Allowing the bank to close the complaint merely because OTP was used.
  • Failing to demand the duplicate-SIM KYC record.
  • Not checking whether beneficiaries or transfer limits were changed before the debit.
  • Waiting for the criminal investigation to end before invoking RBI customer-protection rules.
  • Sending vague complaints without a transaction-by-transaction chronology.

Suggested Legal Notice / Representation Structure

A structured representation to the bank or telecom operator should identify:

  1. subscriber/customer details;
  2. registered mobile number and bank account;
  3. date and time of genuine SIM network loss;
  4. unauthorised SIM swap/replacement details;
  5. each disputed banking transaction;
  6. date/time of bank and telecom reporting;
  7. 1930/NCRP acknowledgement;
  8. police/FIR details;
  9. specific documents sought for preservation and disclosure;
  10. RBI zero-liability grounds, where applicable; and
  11. precise relief sought—reversal/refund, interest, account restoration, preservation of records and investigation.

Frequently Asked Questions

Does losing mobile signal mean my SIM has definitely been swapped?

No. Network loss can have ordinary technical causes. But unexplained sudden loss of service on a bank-linked number is a serious warning sign and should be verified immediately with the telecom operator.

Can money be stolen without me sharing an OTP?

Yes. In SIM-swap fraud, the OTP may be delivered to the fraudster’s duplicate SIM rather than to the genuine subscriber.

Is the bank automatically liable for every SIM-swap loss?

No. Liability depends on the RBI framework, the cause of the breach, customer conduct, reporting time and evidence. But the bank bears the burden of proving customer liability under RBI’s unauthorised-transaction directions.

What is the three-working-day rule?

Where a third-party breach lies neither with the bank nor the customer, RBI provides zero customer liability if the customer reports the unauthorised transaction within three working days of receiving the bank’s communication regarding it.

Can the telecom operator be held liable?

Where negligent or unauthorised duplicate-SIM issuance directly enables the fraud, civil or consumer liability may arise. The Karnataka High Court’s June 2026 BSNL judgment is a significant example.

Should I file both an NCRP complaint and FIR?

NCRP/1930 reporting is essential for cyber-financial fraud response, but it is not automatically the same as a registered FIR. Where cognizable offences are disclosed, FIR registration should be pursued under the BNSS framework.

Can I complain to RBI Ombudsman?

Yes, subject to the Reserve Bank – Integrated Ombudsman Scheme, 2026, after first approaching the regulated entity and satisfying the Scheme’s procedural requirements.

Can the fraudster port my number immediately after the SIM swap?

TRAI’s current MNP framework requires seven days to elapse after SIM swap/replacement before a Unique Porting Code can be issued.

Key Takeaways

A SIM swap converts control of a phone number into control of a financial-authentication channel. The correct response is therefore simultaneous—not sequential:

Telecom lock-down + bank blocking and unauthorised-transaction complaint + 1930/NCRP + cyber-police/FIR process + evidence preservation.

The strongest recovery cases are built on timestamps and records. The victim should prove when the genuine SIM stopped working, when the duplicate SIM was activated, when the bank changed beneficiaries or limits, when the transactions occurred, and how quickly every institution was notified.

Most importantly, OTP usage does not automatically establish customer consent. The 2026 Bombay High Court and Karnataka High Court decisions show that courts are increasingly examining the underlying authentication and SIM-replacement process rather than stopping at the fact that an OTP was technically entered.

Authoritative Sources and Recent Cases

  • Reserve Bank of India, Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions, 6 July 2017.
  • Reserve Bank – Integrated Ombudsman Scheme, 2026, effective 1 July 2026.
  • TRAI, Telecommunication Mobile Number Portability (Ninth Amendment) Regulations, 2024 and current MNP FAQs.
  • Information Technology Act, 2000, Sections 66C and 66D.
  • Bharatiya Nyaya Sanhita, 2023, Sections 318 and 319.
  • Subodh C. Korde v. Union of India, Bombay High Court, 6 April 2026.
  • PNP Polytex Private Limited v. Reserve Bank of India, Bombay High Court, 28 April 2026.
  • Sri Basaveshwara Pattana Sahakara Bank Niyamitha v. Canara Bank and connected matter, Karnataka High Court, 1 June 2026.

Related Fastrack Legal Solutions Guides

Disclaimer

This article is published for general legal information and public awareness. It is not legal advice for any particular dispute and is not an advertisement or solicitation. Liability in SIM-swap and unauthorised-transaction matters depends on the bank category, account type, reporting timeline, customer conduct, telecom records, payment channel, criminal investigation and applicable RBI/DoT/TRAI directions.

Leave a Comment

Your email address will not be published. Required fields are marked *