🚨 The SIM Swap That Became a ₹26 Lakh Corporate Heist
How one lost mobile signal became the first warning sign of a reported business-banking compromise.
Executive Summary
The supplied CyberRakshakLabs research describes a recent Mumbai case involving a Goregaon-based family-run travel company. The company reportedly lost around ₹25.6 lakh after its bank-linked mobile number became the target of a SIM-swap fraud. Three men from Jalandhar were reportedly arrested.
According to the supplied account, the attackers allegedly obtained control of the company's mobile number, allowing calls and SMS—including banking OTPs—to reach the attacker-controlled SIM. The company later discovered unauthorised transfers.
What Happened?
According to the police account cited in the supplied article, the mobile number linked to the company's bank account stopped working on 20 July. The company's accountant contacted the telecom provider and, because the SIM was under a corporate plan, was asked to send an email. He reportedly received information that a replacement SIM would be activated within four hours, but the number did not become operational.
The company checked its bank account the following day and discovered unauthorised transfers totalling approximately ₹25.6 lakh. An FIR was subsequently registered with Mumbai's North Cyber Police.
The supplied material reports these events as a police/account-based incident narrative; it does not provide a full forensic report establishing every technical step of the compromise.
The Attack Chain
The supplied source connects this model with RBI consumer guidance describing SIM swap/cloning as a fraud technique in which criminals obtain a duplicate SIM for a bank-linked number and use OTPs delivered to that SIM for unauthorised transactions.
The Money Trail
The investigation reportedly identified two beneficiaries, Ricky Gill and Daljeet Singh, as recipients of transferred funds. The supplied article reports that the 1930 cybercrime helpline helped block ₹18 lakh.
Of the remaining approximately ₹7.5 lakh, police reportedly said some was withdrawn in cash while most was allegedly converted into gold. A third accused, Gurukamal Singh, was also reportedly involved in placing gold orders and collecting deliveries. All three were reported as arrested.
The First Warning Was the Mobile Number
The supplied police account says the telecom provider sends a text alert to the existing SIM user before processing a SIM deactivation/replacement. The article states that this alert apparently was not noticed by anyone at the company.
That creates a useful detection concept for organisations: a telecom notification can become a cyber-attack detection signal.
Traditional SOC monitoring often focuses on EDR, SIEM, firewall, identity and email alerts. A corporate SIM change can sit outside those systems even though the number may be a dependency for financial authentication.
SIM Swap Is an Authentication Attack
A common security model is username + password + OTP. But the OTP's protection depends on the integrity of the channel that receives it.
That is why a phone number can function as an authentication dependency, not merely as a communication channel.
Why Businesses Are Attractive Targets
Corporate accounts can support vendor payments, salaries, travel bookings, supplier payments, tax payments, customer refunds and operational expenses. The attacker may therefore not need to compromise the company's entire IT environment if a critical financial-authentication dependency can be abused.
The Corporate SIM Problem
The reported number was under a corporate plan, making the SIM replacement process an organisational security dependency.
Organisations should know who is responsible for monitoring corporate SIM changes and how a telecom event is escalated to finance, IT and security teams.
The “No Network” Indicator
This matters especially when the number is linked to corporate banking, UPI, credit cards, email recovery, MFA, cloud accounts or critical business applications.
What Should a Business Do?
Controls Organisations Should Implement
Telecom Security Is Cybersecurity
The supplied article frames the modern security boundary as broader than endpoint, email, identity, cloud and network controls. Mobile and banking infrastructure also matter.
The Department of Telecommunications is cited in the supplied source as treating SIM cards and IMEI numbers as important elements of digital identity and directing users toward Sanchar Saathi. The source also notes additional KYC requirements around SIM replacement and business connections.
Threat Intelligence Assessment
The supplied source does not provide enough technical detail to claim a complete MITRE ATT&CK chain for this particular case. The key intelligence finding presented by CyberRakshakLabs is the relationship between unexpected mobile-service loss and financial authentication risk.
CyberRakshakLabs Final Takeaway
No Network ≠ Network Problem.
Sometimes:
Detect the signal. Verify the SIM. Freeze the money. Follow the trail.
Think Before You Click. Stay Aware. Stay Secure.