Skip to main content

SIM-Swap Fraud: How Criminals Hijack Your Phone Number, Steal SMS OTPs and Gain Access to Banking, UPI, Email and Social Accounts

How attackers use stolen personal data and SIM replacement to take over calls, SMS OTPs, banking, UPI, email and social media accounts

By Mittapalli Sriram
Published: Oct 07, 2026
5 mins read
👁️ 12 Unique Views
SIM-Swap Fraud: How Criminals Hijack Your Phone Number, Steal SMS OTPs and Gain Access to Banking, UPI, Email and Social Accounts
The scale of inference: Optimized for multimodal workloads.
Premium Insight

Why It Matters

SIM-swap fraud matters in India because mobile numbers are widely used for banking, UPI, OTPs and account recovery. India has introduced safeguards such as a seven-day restriction on mobile-number porting after a SIM swap, but the article notes that this does not cover every way a number can be taken over.

Your phone loses signal in the middle of the day. You restart it. Nothing changes. You blame the network and move on.

Meanwhile, someone else may be getting your calls and messages. That is how a SIM-swap attack can start, and a sudden “No Service” message can be an important warning sign.

What Is a SIM Swap?

Your phone number is linked to your account with your telecom company, rather than being permanently tied to the physical SIM card in your phone. If the number is transferred to a replacement SIM, the old SIM stops working and the replacement SIM becomes active.

This is a normal process when you lose your phone or need to replace a damaged SIM. SIM-swap fraud abuses that same process: a criminal tries to get your number transferred to a SIM they control.

How Attackers Take Over a Number

It can begin with personal details such as your name, date of birth, address and phone number. Some information may come from data breaches, while other details can be gathered from social media or through phishing and impersonation.

The attacker may then try to convince a telecom provider that the legitimate SIM was lost or needs to be replaced. They may use stolen information or fraudulent documents as part of the attempt.

Another route is mobile number porting, which allows a subscriber to move the same number to another network. If a fraudulent porting request succeeds, the original SIM can lose service while the number becomes active with the new operator.

Why SMS Codes Are the Weak Spot

Many banks, UPI apps, email services and social media accounts use one-time passwords (OTPs) sent by SMS as one form of account verification.

A SIM swap can undermine that protection because the SMS is delivered to the mobile number, not necessarily to the original physical SIM. If an attacker gains control of the number, they may receive SMS-based verification codes and attempt to use them to access accounts.

SMS-based verification therefore should not be treated as the only layer protecting important accounts. Where available, stronger options such as authenticator apps, security keys or passkeys can reduce reliance on a mobile number.

What India Has Done About It

India introduced an additional safeguard against fraudulent mobile number porting after a SIM swap or replacement. TRAI's Telecommunication Mobile Number Portability (Ninth Amendment) Regulations, 2024 came into force on 1 July 2024. Under the amended rules, a Unique Porting Code (UPC) cannot be allocated if the request is made before seven days have passed since the SIM swap or replacement. This measure was specifically introduced to help curb fraudulent porting after a SIM swap or replacement.

The seven-day restriction applies to mobile number portability. It does not mean that every type of SIM-swap fraud is prevented, so users still need to protect their accounts and respond quickly if their mobile service suddenly stops working.

How to Protect Yourself

You cannot control every step of a telecom company's SIM-replacement process, but you can make a stolen number less useful. Take an unexpected loss of mobile service seriously. If your signal stays dead while other phones nearby are working normally, contact your operator from another phone and check your bank and UPI accounts for unusual activity.

Never share OTPs or sensitive personal details with callers, even if they sound official. Be especially cautious of anyone asking for verification codes or account information.

For important accounts, consider moving away from SMS-based verification where stronger options are available. An authenticator app or passkey can reduce your dependence on your phone number. Secure your email account carefully because it can be used for password recovery for other services.

Finally, turn on transaction alerts. If you notice a transaction or account activity you did not authorize, contact your bank immediately and take steps to secure the affected account.

A SIM swap is not necessarily a hack of your phone itself. It is an attack on the system surrounding your mobile number. That is why the safest approach is simple: do not let one phone number be the only lock protecting your important accounts.

Found this analysis insightful?

Share with colleagues, engineers, and your network.

Link copied to clipboard!