Bihar cyber investigators are moving from POS operators accused of issuing illegal SIM cards to tracing the fraudsters who purchased and used those numbers.

Bihar Cyber Probe Shifts From Fake SIM Sellers to Fraudsters Using Illegal Numbers

The420 Web Correspondent
9 Min Read

Bihar cybercrime investigators are widening their crackdown on illegally issued SIM cards, moving beyond Point of Sale operators accused of creating the connections to the cyber fraudsters who allegedly purchased and used them.

According to investigation details, Bihar’s Cyber Crime and Security Unit has arrested 12 POS operators across Bhagalpur, Nalanda, Nawada, Sheikhpura and Jamui over the past month. The operators are accused of helping issue 388 SIM cards using forged or misused identity documents.

Investigators say analysis of those numbers has revealed links to hundreds of cyber-fraud complaints from different parts of India.

The next stage of the probe is now focused on identifying who ultimately took possession of the SIM cards and how they reached fraud operators in Bihar and neighbouring states.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

Identity documents allegedly reused to issue extra SIM cards

Investigators suspect that some POS operators obtained Aadhaar details, birth certificates and other identity documents from ordinary customers and later misused that information to obtain additional mobile connections.

In some cases, customers may have provided their documents while seeking a legitimate mobile, Aadhaar or KYC-related service.

Police are examining whether those records were copied, altered or reused without the customers knowing that additional SIM cards were being activated in their names.

This type of identity misuse has emerged in other Bihar investigations as well.

In Nalanda, cyber police recently arrested a POS operator accused of illegally activating SIM cards and another man suspected of arranging SIMs and bank accounts in the names of vulnerable people before supplying them to interstate fraudsters.

A separate Bhagalpur investigation also led to the arrest of a POS agent accused of issuing SIM cards using villagers’ details and selling them onward to cybercriminals.

Investigators now tracing the buyers

The current investigation is moving beyond the first stage of the supply chain.

A SIM dealer or POS operator can activate a number, but investigators still need to establish who collected it, who paid for it and who eventually used it to contact fraud victims.

That distinction is important because possession and use may involve several intermediaries.

A fraud network can obtain a SIM from one district, move it through a local supplier and then use it hundreds of kilometres away.

According to investigators, some of the suspicious SIM cards issued in Bihar have shown activity in Jharkhand, West Bengal and Odisha.

Police are now examining call-detail records, handset identifiers, recharge patterns and other technical data to identify users behind the numbers.

Hundreds of complaints reportedly linked to the numbers

Investigators say the 388 SIM cards under scrutiny have surfaced in more than 700 cybercrime complaints across India.

That figure should be read carefully.

A SIM appearing in a complaint does not automatically mean every reported fraud has been proved to have been committed by the same person or network.

The investigation still needs to establish when each number was used, which device it operated from and whether the subscriber identity attached to the SIM was genuine or fabricated.

The larger significance is that a relatively small pool of mobile numbers can potentially appear repeatedly across complaints if they are circulated among organised fraud groups.

That is why authorities are increasingly treating illegal SIM supply as cybercrime infrastructure rather than simply a telecom-rule violation.

CBI probe separately exposed more than 700 suspicious SIMs

The Bihar action comes alongside a separate CBI investigation into an illegal SIM-box network.

Earlier this month, the agency arrested a telecom area distributor from Mahua in Vaishali district after analysing more than 1,300 SIM cards found in connection with a SIM-box operation originally detected in Supaul.

The CBI said more than 700 SIM cards had allegedly been issued by the distributor by misusing credentials belonging to over a dozen POS outlets.

Data connected to the 1,300-card SIM-box operation was linked to at least 73 cybercrime cases across India, including digital-arrest frauds.

The CBI said several subscribers whose identities were used had no idea that additional SIM cards existed in their names.

Some had allegedly been induced to complete repeated e-KYC steps, while in other cases biometric information gathered for an earlier purpose may have been reused.

What is a SIM box and why illegal SIMs matter

A SIM box is a device capable of holding and operating multiple SIM cards.

It can route large numbers of calls while making them appear to originate from ordinary domestic mobile numbers.

That makes the technology attractive to fraud groups because overseas or internet-originated calls can be presented to victims as familiar Indian numbers.

The CBI’s Bihar investigation found more than 1,300 SIM cards associated with one suspected SIM-box operation.

But SIM cards do not need to be placed in a SIM box to be useful to criminals.

A fraudster can also use illegally activated numbers for WhatsApp accounts, fake customer-care calls, investment scams, phishing campaigns or impersonation of police and government officers.

Digital-arrest scams among suspected uses

One of the fraud categories under scrutiny is the so-called digital-arrest scam.

In these cases, criminals pose as police officers, CBI or other government investigators and tell victims that their identity, phone number or bank account is connected to a serious crime.

Victims are then pressured to remain on calls or video chats and transfer money to supposed “safe” or “verification” accounts.

There is no legal process in India called a digital arrest.

Fraudsters nevertheless benefit from using mobile numbers registered under unrelated identities because those numbers make it harder for victims and investigators to immediately identify the people behind the calls.

Five Bihar districts form part of wider crackdown

The CCSU’s recent operations have reportedly covered Bhagalpur, Nalanda, Nawada, Sheikhpura and Jamui.

Cybercrime teams have been examining SIM sellers, Aadhaar-related service centres and other outlets suspected of mishandling customer identity information.

Separate September operations in Nawada and Sheikhpura also resulted in the recovery of suspicious SIM cards, biometric devices, banking documents and identity-related records.

The investigation is now moving toward mapping how the SIMs left those outlets and entered interstate fraud networks.

Telecom distribution controls under scrutiny

The cases raise questions about how fraudulent mobile connections can continue to pass through authorised telecom-distribution channels.

POS agents are expected to complete prescribed customer-verification procedures before activating a SIM.

When the identity attached to a number belongs to someone who never requested that connection, it suggests either deception of the customer, misuse of stored identity information or manipulation of the verification process.

The CBI’s Vaishali investigation is particularly relevant because the agency alleges that credentials belonging to more than a dozen POS outlets were misused to issue hundreds of SIM cards.

That means investigators are not only pursuing the people placing fraudulent calls.

They are increasingly examining the infrastructure that allows criminals to obtain large pools of seemingly legitimate Indian numbers.

What this means for you: Check how many mobile connections are registered in your name through the government’s Sanchar Saathi services and report numbers you do not recognise. Never allow a SIM dealer to repeat biometric or e-KYC verification without a clear explanation of why it is necessary.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected