CYBERRAKSHAK LABS · RESEARCH #046

🚨 The SIM Swap That Became a ₹26 Lakh Corporate Heist

How one lost mobile signal became the first warning sign of a reported business-banking compromise.

By Vivek Kumar · Published 29 September 2026
RESEARCH#046
CATEGORYCyber Fraud / SIM Swap / Financial Security
CRL ASSESSMENTHIGH
RESEARCH LEVELDeep Research
PUBLISHED2026-09-29
Source & social links: LinkedIn Post ↗ WhatsApp ↗YouTube ↗
How CyberRakshakLabs researches threats →
The first warning may not come from your bank. In the reported Mumbai case, a corporate mobile number suddenly stopped working before approximately ₹25.6 lakh was transferred from a travel company's bank account. The supplied source attributes the incident to a SIM-swap fraud and reports three arrests, but the technical details publicly established for the case should not be expanded beyond those reported facts.
₹25.6LReported unauthorised transfers from the company account.
₹18LAmount reportedly blocked with help from the 1930 cybercrime helpline.
NO SIGNALUnexpected loss of service can be an early warning when a number is tied to financial authentication.
Executive Summary

The supplied CyberRakshakLabs research describes a recent Mumbai case involving a Goregaon-based family-run travel company. The company reportedly lost around ₹25.6 lakh after its bank-linked mobile number became the target of a SIM-swap fraud. Three men from Jalandhar were reportedly arrested.

According to the supplied account, the attackers allegedly obtained control of the company's mobile number, allowing calls and SMS—including banking OTPs—to reach the attacker-controlled SIM. The company later discovered unauthorised transfers.

Cybersecurity lesson: when a finance-linked corporate number suddenly loses network service, treat the event as a potential security signal—not automatically as a normal telecom outage.
What Happened?

According to the police account cited in the supplied article, the mobile number linked to the company's bank account stopped working on 20 July. The company's accountant contacted the telecom provider and, because the SIM was under a corporate plan, was asked to send an email. He reportedly received information that a replacement SIM would be activated within four hours, but the number did not become operational.

The company checked its bank account the following day and discovered unauthorised transfers totalling approximately ₹25.6 lakh. An FIR was subsequently registered with Mumbai's North Cyber Police.

The supplied material reports these events as a police/account-based incident narrative; it does not provide a full forensic report establishing every technical step of the compromise.

The Attack Chain
SIM Replacement / SIM Swap
↓
Attacker Gains Control of Mobile Number
↓
Calls & SMS Redirected
↓
Banking OTPs Potentially Received by Attacker
↓
Banking Access / Transaction Authentication
↓
Unauthorised Transfers
↓
Beneficiary Accounts → Cash / Gold

The supplied source connects this model with RBI consumer guidance describing SIM swap/cloning as a fraud technique in which criminals obtain a duplicate SIM for a bank-linked number and use OTPs delivered to that SIM for unauthorised transactions.

The Money Trail

The investigation reportedly identified two beneficiaries, Ricky Gill and Daljeet Singh, as recipients of transferred funds. The supplied article reports that the 1930 cybercrime helpline helped block ₹18 lakh.

Of the remaining approximately ₹7.5 lakh, police reportedly said some was withdrawn in cash while most was allegedly converted into gold. A third accused, Gurukamal Singh, was also reportedly involved in placing gold orders and collecting deliveries. All three were reported as arrested.

Follow the money. A financial cybercrime investigation does not necessarily end at the first unauthorised bank transfer.
The First Warning Was the Mobile Number

The supplied police account says the telecom provider sends a text alert to the existing SIM user before processing a SIM deactivation/replacement. The article states that this alert apparently was not noticed by anyone at the company.

That creates a useful detection concept for organisations: a telecom notification can become a cyber-attack detection signal.

Security signal: “Why did our finance-linked mobile number suddenly stop working?”

Traditional SOC monitoring often focuses on EDR, SIEM, firewall, identity and email alerts. A corporate SIM change can sit outside those systems even though the number may be a dependency for financial authentication.

SIM Swap Is an Authentication Attack

A common security model is username + password + OTP. But the OTP's protection depends on the integrity of the channel that receives it.

Identity Information
↓
SIM Replacement
↓
Mobile Number Control
↓
SMS / OTP Control
↓
Financial Authentication

That is why a phone number can function as an authentication dependency, not merely as a communication channel.

Why Businesses Are Attractive Targets

Corporate accounts can support vendor payments, salaries, travel bookings, supplier payments, tax payments, customer refunds and operational expenses. The attacker may therefore not need to compromise the company's entire IT environment if a critical financial-authentication dependency can be abused.

Mobile identity → banking access → financial transactions is a security relationship that should be documented and monitored.
The Corporate SIM Problem

The reported number was under a corporate plan, making the SIM replacement process an organisational security dependency.

Inventory relationship: Mobile Number → Employee/Owner → Business Function → Bank Account → Applications

Organisations should know who is responsible for monitoring corporate SIM changes and how a telecom event is escalated to finance, IT and security teams.

The “No Network” Indicator
🚨 UNEXPECTED LOSS OF MOBILE NETWORK = INVESTIGATE

This matters especially when the number is linked to corporate banking, UPI, credit cards, email recovery, MFA, cloud accounts or critical business applications.

Don't simply restart the phone.
Don't wait until the next day.
Don't assume the telecom provider is experiencing an outage.
Verify immediately.
What Should a Business Do?
1 — Contact the telecom provider. Ask whether a SIM replacement, SIM swap, eSIM activation or number-porting request was initiated.
2 — Contact the bank. Request monitoring, appropriate transaction restrictions, transaction review and protection of digital-banking access.
3 — Check financial activity. Review IMPS, NEFT, RTGS, UPI, cards, newly added beneficiaries and account-login activity.
4 — Check email. Look for telecom notifications, bank alerts, password resets, OTP requests, forwarding rules and new-login alerts.
5 — Check identity systems. Review whether the mobile number is tied to Microsoft 365, Google Workspace, VPN, password recovery, cloud or administrator accounts.
6 — Report immediately. The supplied article directs victims of financial cyber fraud in India to 1930 and the National Cyber Crime Reporting Portal.
Controls Organisations Should Implement
Critical-number monitoring: maintain a relationship between mobile number, employee, business function, bank account and applications.
Dual control: avoid allowing one person to independently change SIM access, access banking and approve payments.
Out-of-band verification: a SIM change should trigger verification through an independent channel.
Bank transaction controls: use transaction limits, beneficiary cooling periods where available, dual approval, alerts and behavioural monitoring.
Reduce SMS dependency where appropriate: evaluate authenticator-based MFA, hardware security keys, phishing-resistant authentication, device-bound authentication and stronger bank approval mechanisms.
Telecom Security Is Cybersecurity

The supplied article frames the modern security boundary as broader than endpoint, email, identity, cloud and network controls. Mobile and banking infrastructure also matter.

Endpoint
Email
Identity
Cloud
Network
Mobile
Banking

The Department of Telecommunications is cited in the supplied source as treating SIM cards and IMEI numbers as important elements of digital identity and directing users toward Sanchar Saathi. The source also notes additional KYC requirements around SIM replacement and business connections.

Threat Intelligence Assessment
Incident: Reported corporate SIM-swap-enabled financial fraud
Victim: Goregaon-based family-run travel company
Reported loss: ₹25.6 lakh / approximately ₹26 lakh
Reported arrests: 3
Reported amount blocked: ₹18 lakh
Initial warning: Corporate mobile number suddenly stopped working

The supplied source does not provide enough technical detail to claim a complete MITRE ATT&CK chain for this particular case. The key intelligence finding presented by CyberRakshakLabs is the relationship between unexpected mobile-service loss and financial authentication risk.

CyberRakshakLabs Final Takeaway
The attacker didn't necessarily need to break through the travel company's firewall. The reported attack targeted something much simpler: the phone number—and that phone number was connected to the company's financial identity.
Your mobile number is not just a communication channel. If it is tied to banking and authentication, it is part of your security perimeter.

No Network ≠ Network Problem.

Sometimes:

No Network → Security Incident

Detect the signal. Verify the SIM. Freeze the money. Follow the trail.

Think Before You Click. Stay Aware. Stay Secure.