Bihar Police has intensified a crackdown on suspicious SIM-card issuance after investigators linked dozens of numbers issued through Aadhaar centres, cyber cafes and telecom agents to cybercrime complaints across the country.
Operations in Nawada and Sheikhpura have resulted in the recovery of hundreds of SIM cards, biometric devices, bank documents and digital equipment, while police examine whether villagers’ Aadhaar details and biometric verification were allegedly misused to activate additional connections without their knowledge.
The investigation is now trying to connect three layers of the suspected network: the people whose identities were used, the agents who issued the SIM cards and the cybercriminals who allegedly used those numbers.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Ninety-six SIM cards linked to 159 cybercrime complaints
The scale of the Nawada findings is significant.
Police action against Bhola Aadhaar Centre found that 74 SIM cards issued through the centre were linked to 125 complaints recorded on the National Cyber Crime Reporting Portal.
Those complaints involved reported fraud losses of around ₹51.81 lakh.
Another 22 SIM cards issued through Bhola Cyber Cafe were linked to 34 complaints involving ₹39.29 lakh. Together, the 96 SIMs were linked to 159 complaints and approximately ₹91.11 lakh in reported losses.
Investigators recovered printers, mobile phones, biometric equipment, micro-ATMs, scanners and banking documents during the operation.
Fino Payments Bank cards and passbooks, Ujjivan Bank documents and an HDFC Bank scanner were among the materials seized.
The existence of these items does not by itself establish that every device or bank document was used for fraud. Police are examining them to reconstruct how the suspected SIM-issuance process worked.
Villagers allegedly approached for KYC and government-related work
Investigators suspect that rural residents and people with limited digital familiarity were approached for apparently routine services.
These allegedly included mobile number porting, KYC updates, ration-card work, job-card assistance and other government-related processes.
During those interactions, Aadhaar details and biometric verification may have been collected legitimately for one purpose but allegedly reused to activate additional SIM cards.
If that happened, the person whose identity appeared on the telecom records may have had no idea that extra numbers existed in their name.
That creates a serious problem when those SIMs are later used for fraud.
The first documentary trail can point towards an innocent villager rather than the person actually controlling the mobile number.
Police are therefore examining issuance records, POS activity and biometric-verification data alongside cybercrime complaints.
Sheikhpura raid leads to arrest and recovery of 235 SIMs
A separate operation in Sheikhpura led to the arrest of POS agent Vijay Kumar.
Police said 40 SIM cards issued through his point-of-sale facility were linked to 60 cybercrime complaints from different states involving alleged losses of ₹16.25 lakh.
The search produced 235 SIM cards, two laptops, four smartphones, one keypad phone, two fingerprint readers and a UPI scanner.
Investigators also recovered six passbooks, two ATM cards and seven Aadhaar-PAN documents.
Those seizures give police a larger pool of data to examine for additional SIM activations and possible financial links.
Cases have been registered as Nawada Case No. 90/26 and Sheikhpura Case No. 33/2026.
Why fraud networks need SIM cards in other people’s names
Cybercriminals depend heavily on mobile numbers.
A SIM can be used to create WhatsApp accounts, receive OTPs, register digital-payment services, contact victims or maintain accounts on online platforms.
If that SIM is registered in someone else’s name, the criminal gains another layer of separation from the offence.
That is why identity misuse at telecom shops or digital-service centres can become a supply-chain problem for cybercrime.
The person making a fraudulent call may be in one state, while the SIM appears in the records of a villager hundreds of kilometres away.
The beneficiary bank account may belong to yet another person.
Breaking that chain requires investigators to look beyond the person whose Aadhaar appears on the SIM registration.
Bihar’s cybercrime hotspot belt makes SIM tracing important
Nawada and Sheikhpura are already among Bihar’s major cybercrime hotspots.
The Indian Express recently reported that Nawada ranks second and Sheikhpura fifteenth among India’s top cybercrime districts, while the wider Nalanda-Nawada-Sheikhpura belt is associated with OTP scams, fake banking calls, KYC fraud and phishing.
That does not mean ordinary residents of these districts are involved in cybercrime.
It means investigators are seeing a disproportionately large concentration of reported fraud infrastructure and suspect numbers originating from the region.
The present raids show how police are increasingly working backwards from NCRP complaints to the telecom point where the SIM was originally issued.
That can help identify whether a phone number was knowingly obtained by a fraudster or issued by misusing someone else’s identity.
Digital and banking records may reveal who was paid
Investigators are also examining the financial side of the suspected SIM network.
Bank passbooks, ATM cards, UPI-related equipment and digital devices recovered during the searches could help establish whether agents were being paid for supplying pre-activated SIM cards.
Police will need to trace those payments carefully.
A bank account appearing in seized material does not automatically prove involvement in cybercrime.
Investigators must connect the account with specific SIM issuances, payments or communication between suspected members of the network.
The CCSU is also matching SIM numbers against NCRP complaints from other states to determine whether the same issuance points repeatedly appear in unrelated fraud cases.
If they do, that could reveal a systematic supply operation rather than isolated KYC violations.
What this means for you
You can check how many mobile connections are registered in your name through the government’s Sanchar Saathi service. If you find a SIM you do not recognise, report it rather than assuming it is harmless.
The420 Insight
The important part of this investigation is not just the number of SIM cards seized. It is the possibility that legitimate Aadhaar and biometric verification points were allegedly being turned into supply nodes for cybercrime. If investigators can prove that identities were repeatedly reused to create anonymous telecom access, the case could expose an entire support layer behind fraud calls made across India.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics