惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
M
MIT News - Artificial intelligence
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
F
Fortinet All Blogs
L
LangChain Blog
D
Docker
G
Google Developers Blog
B
Blog RSS Feed
Google DeepMind News
Google DeepMind News
Vercel News
Vercel News
Recent Announcements
Recent Announcements
MyScale Blog
MyScale Blog
Microsoft Azure Blog
Microsoft Azure Blog
A
About on SuperTechFans
T
The Blog of Author Tim Ferriss
Recorded Future
Recorded Future
I
InfoQ
博客园 - 【当耐特】
The Cloudflare Blog
P
Proofpoint News Feed
GbyAI
GbyAI
博客园 - 司徒正美
U
Unit 42
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
H
Hackread – Cybersecurity News, Data Breaches, AI and More
B
Blog
Hugging Face - Blog
Hugging Face - Blog
博客园_首页
Stack Overflow Blog
Stack Overflow Blog
Microsoft Security Blog
Microsoft Security Blog
爱范儿
爱范儿
Jina AI
Jina AI
量子位
阮一峰的网络日志
阮一峰的网络日志
月光博客
月光博客
有赞技术团队
有赞技术团队
罗磊的独立博客
博客园 - 三生石上(FineUI控件)
Y
Y Combinator Blog
Apple Machine Learning Research
Apple Machine Learning Research
V
V2EX
大猫的无限游戏
大猫的无限游戏
F
Full Disclosure
雷峰网
雷峰网
美团技术团队
酷 壳 – CoolShell
酷 壳 – CoolShell
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
S
SegmentFault 最新的问题

MEDIANAMA

India in talks with US, Anthropic for Mythos access; no Indian firms in Project Glasswing yet Eternal Q4FY26: All Users Pay Higher Platform Fee, Only Some Get Discounts Amazon, Meta to challenge PhonePe-Google Pay dominance as UPI cap delayed since 2020 Meta failed to protect the safety of under-13s: European Commission If markets and regulators are ready for network slicing, we are ready: JIO Why defining ‘news’ won’t fix the free speech problems of draft IT Rules? #NAMA Eternal Q4FY26: Goyal Dismisses AI Disruption Risk as Zomato Quietly Builds Agentic Commerce Infrastructure Karnataka files appeal challenging the bike taxi ban lift in the Supreme Court How did WhatsApp turn 17 govt. flags into 9,400 digital arrest scam bans? Google Wallet integrates Aadhaar as digital ID, expands India’s mobile identity ecosystem Kerala HC issues notice on MediaOne’s Facebook page block in India MeitY warns VPN providers against enabling access to blocked betting platforms Shreya Singhal targeted private censorship. Today’s threat is the State #NAMA Amazon scales its quick delivery service ‘Amazon Now’ in 100 cities Can MeitY issue binding rules via advisories? Experts raise alarm over draft IT Rules #NAMA How 2019 election code of ethics became India’s three-hour content takedown mandate #NAMA Australia proposes new levy on big tech to fund news, opens draft law for consultation ‘judge, jury, executioner’: experts warn of Inter-Departmental Committee (IDC) overreach under New draft IT Rules Lowdown: TRAI flags low deployment under PM-WANI in public Wi-Fi consultation paper Why the NBFC licence matters for MobiKwik China blocks Meta-Manus deal, asserts origin-country jurisdiction: what this means for India ‘No transparency’: experts warn of expanding powers to block online speech in India #NAMA X launches standalone iOS messaging app XChat with encryption in India How India’s content takedown framework was built and where It has gone wrong #NAMA Claude Mythos puts India on alert: CERT-In, telcos, banks assess unprecedented cyber risks Explained: why did the RBI cancel Paytm’s banking licence? Meta now instantly blocks content in India Govt. asks ZEE5 to halt ‘Lawrence of Punjab’ web series release Online Gaming Rules notified, to be in effect from May 1, what are the major changes? RBI mandates additional factor authentication for e-mandates No notice, no explanation, no recourse: how content creators experience censorship in India #NAMA Telangana Police invokes UAPA to demand TeluguScribe’s user data from X Lowdown: RBI releases draft PPI rules covering capital requirements, wallet limits & escrow norms MeitY tightens AI label rules, mandates continuous disclosure Watch Live: IT Rules and the Future of Online Speech in India, Delhi April 23, #NAMA Govt. defends 4 PM YouTube ban, cites foreign influence and ‘digital lobbying’ in Delhi HC Anthropic’s Mythos AI accessed without approval via third-party vendor route: Report YouTube expands AI likeness detection tool to celebrities amid deepfake surge ECI orders 3-hour takedown rule for AI and fake content in elections Final Call: IT Rules and the Future of Online Speech in India, Delhi April 23, #NAMA Announcing Speakers: Victims of Censorship | IT Rules and the Future of Online Speech in India, Delhi April 23, #NAMA Apple withholds financial data as India App Store antitrust case heads to final hearing Sony rolls out age checks in Playstation in the UK, users to prove age to access chat Vercel confirms hack via third-party AI tool, says sensitive data safe Karnataka High Court stays blocking orders against Proton Mail J&K DMs impose sweeping 60-day social media curbs; IFF calls them “illegal, overbroad” Flipkart plans ticketing entry, food delivery pilot in May ahead of IPO ANI v OpenAI: Not Everything an LLM Does is Copyright Infringement EU’s “safe by design” age-verification app cracked in minutes, raising data security fears Molitics’ Instagram suspended days after Facebook ban Speaker Announcement: IT Rules and the Future of Online Speech in India, April 23, 2026, Delhi X has only responded to 13 out of 94 takedown notices since 2024: Centre tells Gujarat HC Jio Financial Services Q4FY26 profit declines 14% to Rs 272 crore Bombay HC cracks down on fake ‘NSE’ social media handles amid rising impersonation fraud Government drops proposal to mandate Aadhaar app on smartphones Ola’s Krutrim quietly shuts down its agentic AI assistant ‘Kruti’ Anthropic taps Peter Thiel-backed Persona for Claude ID checks, raising DPDP concerns YouTube rolls out option to turn off Shorts, expands time controls Amnesty calls for ‘immediate withdrawal’ of India’s 2026 IT Amendment Rules, cites threat to free speech and privacy Lowdown: Insurers have to comply with DPDP as IRDAI updates Cyber Security Guidelines European Commission proposes Google have to share search data with rivals under the DMA AIGEG: MeitY’s new AI governance body excludes regulators recommended by its own AI guidelines Amazon acquires Globalstar for $11.57 Billion: What it means for India European Commission rolls out privacy-focused age verification app for child safety Reading List: IT Rules and the future of online speech in India, April 23, Delhi #NAMA Digital rule, colonial echo – India’s IT Rules 2021 amendments Agenda: IT Rules and the future of online speech in India, Delhi, April 23 #NAMA Motorola gets court order to block YouTube videos critical of its phones in India Apple and Google promote ‘nudify’ apps despite policy bans, report finds National security could be used to mandate registration of online games HBO Max enters India via JioHotstar partnership Andhra Pradesh police detain stand-up comedian Anudeep Katikala over YouTube video jokes Aptoide sues Google for app store monopoly, alleges ‘anticompetitive chokehold’ HBO Pushes X to Unmask User Behind Euphoria Season 3 Spoilers Delhi HC directs DoT, MeitY to take action against Tucows for failing to take down infringing URLs in Premier League case Claude users say accounts suspended after being incorrectly flagged as minors MeitY may let users, intermediaries join content-blocking hearings Sucheta Dalal challenges Delhi Court order using ‘Right to Be Forgotten’ in Sterling Biotech case Govt launches Rs 10,000 Cr Startup India Fund of Funds 2.0 to bridge early-stage funding gap in deep tech Advisories as Law? Panelists Debate Legal Sanctity Under Draft IT Rules Amendments Independent journalists in Punjab allege censorship by ruling AAP using copyright strikes, IT act Supreme Court Issues Notice on PIL Seeking Biometric Verification of Voters Fact-check: MP Nishikant Dubey’s claim on X community notes & Australian tax is false “No scientific evidence”: 438 scientists call for pause on age-based controls until benefits and risks understood Developer partially bypasses Google’s AI watermark, undermining detection India’s deepfake rules rely on Event Announcement: IT Rules and the Future of Online Speech in India, April 23, #NAMA UK plans jail risk for tech executives over failure to remove intimate images Press bodies demand ‘unconditional withdrawal’ of draft amendment to IT Rules, warns of free speech threat Zoho revenue crosses Rs 12,000 crore in FY25, but profit slips 3% YouTube’s AI avatar tool for Shorts raises questions around India’s deepfake rules, personality rights Instagram expands safety settings on teen accounts with 13+ content ratings Digi Yatra is eyeing international travel roll-out with passport-based enrolment Meta’s new AI model Muse Spark is coming to WhatsApp. Here is what that means for Indian users Andhra Pradesh explores DigiLocker age tokens for social media curbs on children aged 13-16 Kunal Kamra tells Bombay HC police sent “thousands” of takedown notices via Sahyog portal Extra safeguard for the elderly: RBI suggests trusted person approval for high-value digital payments Delhi court orders Google to remove Sterling Biotech case links, cites ‘right to be forgotten’ RBI Proposes 1-hour delay, customer controls for digital payments as frauds surge Should only MIB-authorised apps be allowed to stream free TV on Smart TVs? TRAI Seeks Inputs OpenAI releases child safety policy framework recommendations to combat AI-enabled CSAM
Duplicate SIM exposes a structural flaw in UPI, Karnataka HC ruling shows
Aakriti Bansal · 2026-06-08 · via MEDIANAMA

The Karnataka High Court ruling on June 5, 2026, held Bharat Sanchar Nigam Limited (BSNL) liable for a cooperative bank’s Rs 50.5 lakh loss in a SIM swap fraud. The court found that BSNL’s negligent issuance of a duplicate Subscriber Identity Module (SIM) card directly enabled the theft.

The ruling names a deeper problem than the liability question it settles. A duplicate SIM can give a fraudster control of a victim’s entire financial identity because India’s digital payments architecture treats the mobile number registered for One Time Password (OTP) authentication as the master channel on which the security of the whole system depends.

What the Karnataka High Court held: Justice Suraj Govindaraj decided two connected petitions, one by the cooperative bank seeking higher compensation and one by BSNL challenging its liability, against a Permanent Lok Adalat award that had granted the bank only Rs 5 lakh. The key findings:

  • TSP as custodian: The court treated a telecom service provider (TSP) as a custodian of mobile connectivity, comparing it to a vault keeper, and held that a provider who carelessly or dishonestly issues a duplicate SIM bears responsibility for the fraud that the SIM enables.
  • Proximate cause: The court held the duplicate SIM was the proximate cause of the loss, reasoning that no one could have diverted the OTPs and no fraud could have occurred without the SIM’s issuance.
  • Verification was worthless: Applying the principle that a thing speaks for itself, the court held that the very fact a duplicate SIM reached a non-subscriber proved BSNL either skipped verification or performed it so perfunctorily as to render it worthless.
  • Vicarious liability: The court held BSNL vicariously liable for its employee, rejecting the argument that the absence of a criminal chargesheet absolved it and holding that evidence too thin for a criminal conviction can still establish civil negligence on the balance of probabilities.
  • Insurance does not offset the loss: The court held that the money the bank recovered must be adjusted against the loss, but insurance proceeds under an independent policy cannot reduce the wrongdoer’s liability.
  • The award: The court directed BSNL to pay Rs 50,50,762 as net loss plus Rs 5 lakh as consequential damages, with 9% annual interest from February 7, 2019, and a default interest of 12% if BSNL misses the three-month window.

Why the mobile number is the weakest link: The Unified Payments Interface (UPI) ties three things to one anchor, the mobile number registered with the bank:

  • The bank account: When a user sets up a UPI app, the National Payments Corporation of India (NPCI) maps the number to every linked bank account.
  • The UPI ID: The app verifies the number through an SMS from the active SIM, then the user sets a UPI PIN using debit card details.
  • The authentication: The same number carries the OTPs that authenticate internet banking, card transactions, and Real Time Gross Settlement (RTGS) and National Electronic Funds Transfer (NEFT) transfers.

Control the number, and a fraudster controls the second factor across every one of these channels at once.

Device binding does not close the gap: UPI carries a defence that the mobile number alone cannot defeat. Through device binding, NPCI ties a UPI account to one physical handset:

  • UPI rejects every transaction that does not come from the bound device.
  • Re-binding after a SIM or phone change needs the user to re-register for UPI, which requires the registered SIM to be active and the debit card details.
  • Regenerating a forgotten UPI PIN also needs the debit card’s last six digits and expiry.

This is why a SIM swap rarely lets a fraudster clone a UPI app outright. The flaw sits one layer deeper: the mobile number remains the fallback channel that resets UPI PINs, authorises transactions, and authenticates internet and RTGS or NEFT banking. The Karnataka Bank lost money through seven unauthorised RTGS and NEFT transactions on internet banking, not through a cloned UPI app. Device binding hardens the app; it does nothing for every other service that still trusts an OTP sent to a hijacked number.

How a SIM swap breaks everything downstream: A SIM swap needs no hacking and no broken encryption. It exploits the one point outside the digital system: a person at a telecom counter issuing a replacement SIM. The mechanics:

  • A fraudster social-engineers or bribes a telecom employee or exploits weak verification to get a duplicate SIM for the target’s number.
  • Once the SIM goes active, every OTP, alert, and authentication message flows to the fraudster instead of the victim.
  • In the Karnataka case, the fraudsters used exactly this route: once they held the duplicate SIM, they intercepted the OTPs and moved Rs 87.7 lakh within hours.

Who pays depends on how the OTP was compromised: Two 2026 High Court rulings now map the liability landscape, and they fall on opposite sides depending on the attack:

  • SIM swap, telecom pays: The Karnataka ruling above puts the loss on the telecom operator, whose negligent SIM issuance enabled the fraud.
  • Phishing, customer pays: In the Delhi High Court ruling of June 2026, a division bench held that a customer’s bare denial of sharing an OTP cannot fasten liability on a bank, treating the act of clicking a phishing link as negligence that places the full loss on the customer under Reserve Bank of India (RBI) rules.

The distinction is the attack vector. A customer tricked into surrendering an OTP bears the loss; a customer who lost an OTP to a SIM swap they had no part in can shift it, but only when investigators prove the swap. The RBI’s 2017 liability framework already places SIM swap fraud, where fault lies outside the customer, in the zero-liability category.

The scale of the exposure:

Why this is structural, not a one-off failure: The system’s security is only as strong as its weakest link, and that link sits outside the payments ecosystem’s control:

  • NPCI controls the rails.
  • Banks control accounts.
  • Telecom operators control the mobile number, the key to all of it, and their duplicate-SIM verification, as the Karnataka case shows, can be loose enough for a single employee to exploit.

No amount of two-factor authentication at the payments layer protects a user when a fraudster can capture the second factor itself at a telecom counter.

Where the rules are heading: Regulators are tightening the telecom layer rather than redesigning the dependency.

  • TRAI’s Ninth Amendment to the Mobile Number Portability rules, in force since July 2024, imposes a seven day cooling-off period after a SIM swap before a subscriber can port the number.
  • The DoT mandated SIM binding for messaging apps in November 2025 to curb the discarded-SIM tactic, requiring a continuous link between a user’s SIM and the app, though it has extended the deadline to December 2026.

These measures harden how a duplicate SIM is issued and ported, but experts have told MediaNama that continuous SIM validation may be technically infeasible because modern operating systems hide SIM identifiers from apps and most systems bind to the device rather than the SIM.

None of these measures changes the underlying design: as long as control of a mobile number remains the master key to a person’s bank account, every duplicate SIM issued without verification stays a live threat to the financial system layered on top of it.

Also read:

Post navigation

OpenAI’s new Lockdown Mode restricts web-connected features like Deep Research and Agent Mode to protect sensitive data from prompt injection attacks, though the company admits it’s not a complete solution.

Ixigo approved a 54.66% stake in hotel startup Brevistay for Rs 65.69 crore and invested in two early-stage AI firms, Proactai and Vestra.AI, as part of its strategy to deepen AI capabilities in travel.