India Warns of New eSIM Scam Enabling Bank Fraud Through Mobile Number Hijacking

Silhouette of a young woman standing in front of a large projected fingerprint pattern, illustrating the concept of biometric identification or data privacy and security.

Indian authorities have issued warnings about a new eSIM-based fraud scheme targeting mobile users across the country. The Indian Cyber Crime Coordination Centre (I4C), operating under the Ministry of Home Affairs (MHA), has identified a scam where criminals hijack victims’ mobile numbers through fraudulent eSIM activation processes. The latest threat emerges amid a broader global surge in SIM-swap attacks, which have seen a 1,055 percent increase in some regions.

The scheme begins when fraudsters contact potential victims while impersonating telecom operator representatives. They send fake eSIM activation links via SMS or email. When victims interact with these links, their physical SIM cards are converted to eSIMs controlled by the perpetrators, causing the victims’ phones to lose network connectivity and cease receiving calls or messages.

Once the number is compromised, all communications, including bank one-time passwords (OTPs), are redirected to the fraudsters’ devices. The redirection enables unauthorized bank transactions without requiring physical cards or account credentials. In one documented instance, criminals withdrew Rs 4 lakh from a victim’s account using this method. The attack vector is particularly concerning given India’s recent push toward digital payment systems and UPI transactions.

“If your phone suddenly loses network signals, contact your bank and mobile service provider immediately,” advises the I4C. The organization emphasizes that users should only initiate eSIM activation through official telecom operator channels and avoid clicking links from unknown sources. The guidance follows the agency’s broader crackdown on mobile fraud, which has included blocking hundreds of thousands of fraudulent SIM cards.

The vulnerability stems from the digital nature of eSIM technology, which enables remote SIM card management without physical access. The legitimate feature, designed for convenience, can be exploited through social engineering tactics rather than technical vulnerabilities in the eSIM system itself. The GSMA’s standardized eSIM specifications include robust security measures, but these can be circumvented through human manipulation.

Security experts note that even users who have disabled UPI or ATM services linked to their mobile numbers remain vulnerable once their numbers are compromised. The speed of these attacks is particularly notable, with account compromises potentially occurring within minutes of successful number hijacking. The pattern mirrors situations seen in other regions where similar remote phone number hijacking schemes have emerged.

The I4C has issued specific guidance for mobile users, recommending direct verification with service providers for any SIM-related requests and avoiding interaction with unsolicited communications claiming to be from operators. The recommendations support India’s broader telecommunications security initiatives implemented to combat rising mobile fraud incidents.

Sources: OdishaBytes, Moneycontrol, The CSR Journal, NDTV