Combatting Telecom KYC Fraud and Ghost SIM Cards
In India, fraudulent SIM card acquisition remains one of the fastest-growing cybercrime vectors. Criminal gangs acquire active pre-paid SIM cards registered under innocent citizens’ names to conduct financial scams, OTP interception, and phishing campaigns.
The root cause of this epidemic is almost always unmasked identity photocopies submitted at roadside mobile shops and third-party telecom kiosks.
How Telecom Retailer Fraud Works
- Duplicate Copies: When you apply for a new mobile number, the vendor may print two or three copies of your Aadhaar instead of one.
- Ghost Activations: The duplicate copy—bearing your unmasked 12-digit number, clean photo, and scannable QR code—is submitted as KYC for a completely different SIM card without your knowledge.
- Cyber Investigation Trap: Months later, when that burner SIM card is traced during a cyber fraud investigation, law enforcement knocks on your door because the telecom provider’s database lists you as the legal subscriber.
DoT Protections and Masked Submissions
The Department of Telecommunications (DoT) has issued strict directives requiring telecom operators to secure subscriber acquisition processes:
- Aadhaar QR Neutralization: Always scramble the QR code so third-party mobile apps cannot pull your raw Aadhaar XML data.
- First 8 Digits Redaction: Masking the initial 8 digits complies fully with UIDAI regulations and Section 8A while leaving the last 4 digits visible for internal audit matching.
- Watermark Enforcement: The watermark
FOR SIM REGISTRATION ONLY — [DATE]permanently restricts the utility of the paper copy to the single transaction you authorized.