Gurugram Police have arrested four people, including a woman, for allegedly exploiting a reassigned mobile number to gain access to an elderly man’s bank account and siphon off ₹32.10 lakh.
The accused allegedly discovered that a mobile number newly allotted to one of them was still linked to the victim’s bank account. Transaction alerts began arriving on the recycled number, after which the group allegedly activated net banking, applied for a fresh debit card and intercepted the card outside the victim’s home.
Police arrested the four accused from Delhi on September 23. They have been identified as Kunal Kashyap and Ankit, both linked to Kalkaji, Mohammed Sahil of Tughlakabad Extension and Sangeeta of Asha Kiran Apartments.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Fraud surfaced after family found unauthorised transactions
The case came to light after the victim’s daughter-in-law approached Cyber Crime East police on September 13.
She told police that multiple unauthorised transactions had been carried out from her father-in-law’s bank account between March 7 and June 2.
When the family contacted the bank, they learned that a new debit card had been issued in the elderly account holder’s name even though he had never requested one.
That discovery prompted police to examine the bank account, the registered mobile number and the process through which the replacement card had been issued.
Investigators eventually traced the case to Delhi.
Old number had been reassigned to one accused
Police say the mobile number registered with the bank had remained inactive for a long period and was later reassigned by the telecom company.
The number was allotted to Kunal Kashyap.
Once the SIM became active, banking transaction messages connected to the elderly man’s account allegedly began reaching the new user.
Instead of reporting the mismatch, police allege that Kashyap and his associates decided to exploit it.
The group allegedly used the information available through those banking messages to gain further access to the account.
This is different from a conventional SIM-swap attack.
In a SIM-swap case, fraudsters usually trick a telecom company into transferring a victim’s active number to another SIM. Here, police say the number had already become inactive and was legitimately recycled to a new subscriber, while the bank account had apparently not been updated with a new number.
Net banking activated using recycled SIM
Police allege that the accused used the reassigned number to activate net banking linked to the elderly man’s account.
They then requested a fresh debit card in his name.
The card was sent to the genuine account holder’s registered residential address.
Instead, investigators say the accused monitored the delivery and reached the area around the victim’s home before the card was handed over.
They allegedly collected the card from the delivery person by posing as the intended recipient.
Once they had possession of a genuine debit card linked to the account, they were able to begin spending and withdrawing money.
₹32.10 lakh withdrawn through shopping and cash transactions
Police say unauthorised transactions worth approximately ₹32.10 lakh were carried out between March and June.
The money was allegedly used for both cash withdrawals and purchases.
During the arrests, police recovered 10 silver coins, a pair of gold earrings and two iPhones.
Investigators suspect the items were purchased using part of the money taken from the victim’s account.
Police are now examining the accused persons’ phones, banking records and other digital evidence to determine how the remaining funds moved.
They are also looking into whether the same group used recycled mobile numbers to target other accounts.
Why recycled numbers can become a banking risk
Telecom companies routinely recycle mobile numbers that remain inactive beyond a prescribed period.
The practice itself is normal.
The risk emerges when an old number remains linked to banking, email, UPI or other financial accounts even after the original subscriber stops using it.
If the number is later allotted to another person, that new subscriber may begin receiving OTPs, banking alerts or account-related messages intended for the previous user.
Those messages alone should not normally be enough to take over an account.
But if combined with weak authentication processes, exposed personal information or additional social engineering, they can create a route into financial services.
The Gurugram case shows how an old mobile number can become a security problem long after its original owner has stopped using it.
Debit card interception added a physical layer to the fraud
The case also stands out because the alleged fraud was not purely digital.
The group is accused of combining digital access with physical interception of the debit card.
That required knowing where the card would be delivered, monitoring the victim’s address and collecting the shipment before the genuine account holder received it.
It is an example of how cyber fraud can blend online account takeover with traditional impersonation.
Even strong online controls can fail if a replacement card reaches the wrong person.
Banks also face questions over account recovery controls
The case raises questions about how banks verify identity when customers activate net banking or request replacement debit cards.
A recycled phone number should not, on its own, be enough to establish ownership of an existing bank account.
Investigators will likely examine what additional information was supplied, how the net-banking activation was authenticated and whether the debit-card request triggered any secondary verification.
The police have not yet publicly explained the full authentication sequence.
That means it would be premature to conclude that possession of the recycled number alone gave the accused complete access.
The final mechanism will depend on banking logs and digital evidence.
Four accused remain under investigation
The arrests establish police suspicion, not guilt.
Investigators still need to prove the individual role of each accused and trace the ₹32.10 lakh money trail.
Police are also examining whether other people helped obtain or use the debit card and whether similar accounts were targeted.
The case highlights an often overlooked security step: updating every financial institution when a mobile number is abandoned.
What this means for you: If you stop using a mobile number, immediately remove it from bank accounts, UPI apps, email accounts and other financial services. Do not assume that a deactivated number disappears permanently — it may later be reassigned to someone else.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics