The Karnataka High Court ruling on June 5, 2026, held Bharat Sanchar Nigam Limited (BSNL) liable for a cooperative bank’s Rs 50.5 lakh loss in a SIM swap fraud. The court found that BSNL’s negligent issuance of a duplicate Subscriber Identity Module (SIM) card directly enabled the theft.
The ruling names a deeper problem than the liability question it settles. A duplicate SIM can give a fraudster control of a victim’s entire financial identity because India’s digital payments architecture treats the mobile number registered for One Time Password (OTP) authentication as the master channel on which the security of the whole system depends.
What the Karnataka High Court held: Justice Suraj Govindaraj decided two connected petitions, one by the cooperative bank seeking higher compensation and one by BSNL challenging its liability, against a Permanent Lok Adalat award that had granted the bank only Rs 5 lakh. The key findings:
- TSP as custodian: The court treated a telecom service provider (TSP) as a custodian of mobile connectivity, comparing it to a vault keeper, and held that a provider who carelessly or dishonestly issues a duplicate SIM bears responsibility for the fraud that the SIM enables.
- Proximate cause: The court held the duplicate SIM was the proximate cause of the loss, reasoning that no one could have diverted the OTPs and no fraud could have occurred without the SIM’s issuance.
- Verification was worthless: Applying the principle that a thing speaks for itself, the court held that the very fact a duplicate SIM reached a non-subscriber proved BSNL either skipped verification or performed it so perfunctorily as to render it worthless.
- Vicarious liability: The court held BSNL vicariously liable for its employee, rejecting the argument that the absence of a criminal chargesheet absolved it and holding that evidence too thin for a criminal conviction can still establish civil negligence on the balance of probabilities.
- Insurance does not offset the loss: The court held that the money the bank recovered must be adjusted against the loss, but insurance proceeds under an independent policy cannot reduce the wrongdoer’s liability.
- The award: The court directed BSNL to pay Rs 50,50,762 as net loss plus Rs 5 lakh as consequential damages, with 9% annual interest from February 7, 2019, and a default interest of 12% if BSNL misses the three-month window.
Why the mobile number is the weakest link: The Unified Payments Interface (UPI) ties three things to one anchor, the mobile number registered with the bank:
- The bank account: When a user sets up a UPI app, the National Payments Corporation of India (NPCI) maps the number to every linked bank account.
- The UPI ID: The app verifies the number through an SMS from the active SIM, then the user sets a UPI PIN using debit card details.
- The authentication: The same number carries the OTPs that authenticate internet banking, card transactions, and Real Time Gross Settlement (RTGS) and National Electronic Funds Transfer (NEFT) transfers.
Control the number, and a fraudster controls the second factor across every one of these channels at once.
Device binding does not close the gap: UPI carries a defence that the mobile number alone cannot defeat. Through device binding, NPCI ties a UPI account to one physical handset:
- UPI rejects every transaction that does not come from the bound device.
- Re-binding after a SIM or phone change needs the user to re-register for UPI, which requires the registered SIM to be active and the debit card details.
- Regenerating a forgotten UPI PIN also needs the debit card’s last six digits and expiry.
This is why a SIM swap rarely lets a fraudster clone a UPI app outright. The flaw sits one layer deeper: the mobile number remains the fallback channel that resets UPI PINs, authorises transactions, and authenticates internet and RTGS or NEFT banking. The Karnataka Bank lost money through seven unauthorised RTGS and NEFT transactions on internet banking, not through a cloned UPI app. Device binding hardens the app; it does nothing for every other service that still trusts an OTP sent to a hijacked number.
How a SIM swap breaks everything downstream: A SIM swap needs no hacking and no broken encryption. It exploits the one point outside the digital system: a person at a telecom counter issuing a replacement SIM. The mechanics:
- A fraudster social-engineers or bribes a telecom employee or exploits weak verification to get a duplicate SIM for the target’s number.
- Once the SIM goes active, every OTP, alert, and authentication message flows to the fraudster instead of the victim.
- In the Karnataka case, the fraudsters used exactly this route: once they held the duplicate SIM, they intercepted the OTPs and moved Rs 87.7 lakh within hours.
Who pays depends on how the OTP was compromised: Two 2026 High Court rulings now map the liability landscape, and they fall on opposite sides depending on the attack:
- SIM swap, telecom pays: The Karnataka ruling above puts the loss on the telecom operator, whose negligent SIM issuance enabled the fraud.
- Phishing, customer pays: In the Delhi High Court ruling of June 2026, a division bench held that a customer’s bare denial of sharing an OTP cannot fasten liability on a bank, treating the act of clicking a phishing link as negligence that places the full loss on the customer under Reserve Bank of India (RBI) rules.
The distinction is the attack vector. A customer tricked into surrendering an OTP bears the loss; a customer who lost an OTP to a SIM swap they had no part in can shift it, but only when investigators prove the swap. The RBI’s 2017 liability framework already places SIM swap fraud, where fault lies outside the customer, in the zero-liability category.
The scale of the exposure:
- The UPI ecosystem processes over a thousand crore transactions monthly, all resting on OTP authentication.
- UPI frauds rose 85% in FY24, as per RBI and NPCI data.
- Bank frauds of Rs 1 lakh and above climbed to 29,082 cases worth Rs 1,457 crore in 2023-24.
- The Department of Telecommunications (DoT) has flagged 79.42 lakh fraudulent SIMs and disconnected 73.14 lakh of them.
Why this is structural, not a one-off failure: The system’s security is only as strong as its weakest link, and that link sits outside the payments ecosystem’s control:
- NPCI controls the rails.
- Banks control accounts.
- Telecom operators control the mobile number, the key to all of it, and their duplicate-SIM verification, as the Karnataka case shows, can be loose enough for a single employee to exploit.
No amount of two-factor authentication at the payments layer protects a user when a fraudster can capture the second factor itself at a telecom counter.
Where the rules are heading: Regulators are tightening the telecom layer rather than redesigning the dependency.
- TRAI’s Ninth Amendment to the Mobile Number Portability rules, in force since July 2024, imposes a seven day cooling-off period after a SIM swap before a subscriber can port the number.
- The DoT mandated SIM binding for messaging apps in November 2025 to curb the discarded-SIM tactic, requiring a continuous link between a user’s SIM and the app, though it has extended the deadline to December 2026.
These measures harden how a duplicate SIM is issued and ported, but experts have told MediaNama that continuous SIM validation may be technically infeasible because modern operating systems hide SIM identifiers from apps and most systems bind to the device rather than the SIM.
None of these measures changes the underlying design: as long as control of a mobile number remains the master key to a person’s bank account, every duplicate SIM issued without verification stays a live threat to the financial system layered on top of it.
Also read:
- Who is liable when an OTP-secured transaction turns into fraud? Delhi HC puts onus on customer
- RBI sets up Q-SAFE: Expert committee to evaluate uses and security risks of quantum technology
- Lowdown: RBI’s new advisory pushes for tighter data use, AI safeguards, vendor checks
For You
- Read Reasoned by Nikhil Pahwa: How AI is changing our world
- Sign up for MediaNama's Daily Newsletter to receive regular updates
- Sponsor a MediaNama Event























