The arrest of three men by Mumbai Cyber Police has exposed a hidden layer of the cyber-fraud economy: the industrial supply of Indian SIM cards and one-time passwords to handlers operating from Cambodia. The case began with a 68-year-old Andheri resident losing Rs 22.3 lakh in an alleged share-investment scam, but the police account points to a wider system built on fake identities, large-scale mobile activation and cross-border digital payments.
The arrests matter because many online frauds are described primarily through the deception used against victims. In this case, the police investigation also traced the infrastructure that allows fraudsters to create WhatsApp accounts, contact targets and maintain apparently Indian digital identities while operating from outside the country. That infrastructure included hundreds of SIM cards, mobile phones, OTP-generation activity and cryptocurrency-based payments.
According to police, Pramod Kumar, 34, a college dropout from Delhi, used at least 6,000 SIM cards and supplied six-digit activation OTPs to Cambodia-based cybercriminals. The police said he charged between Rs 12,500 and Rs 2,500 per OTP, depending on the transaction, and received payment in cryptocurrency. The money was allegedly converted into cash through private money exchanges or transferred to digital wallets.
The other two arrested men, Dharmendra Gupta, 43, and Rajeev Gupta, 51, both from Uttar Pradesh, allegedly supplied fake SIM cards to Kumar. Police said the cards were used to create WhatsApp accounts, with activation OTPs then sent to handlers in Cambodia. The alleged arrangement illustrates how a fraud operation can be divided into specialised tasks: one group supplies identity-linked telecom access, another generates or transfers verification codes, and overseas handlers communicate with victims.
That separation complicates enforcement. The person communicating with a victim may not be the person who obtained the SIM card, generated the OTP or received the payment. It also means that a local arrest can reveal only one part of a chain that extends across states, platforms and national borders.
The immediate case was triggered when the Andheri resident reported losing Rs 22.3 lakh in April. Police said the victim had been added to a Telegram group and then contacted on WhatsApp by people posing as representatives of a reputed investment company. The fraudsters promised high returns from share-market investments and later demanded more money when the victim attempted to withdraw the investment and the purported profits.
The sequence reflects a familiar digital-fraud pattern: recruitment into a closed online group, the use of institutional impersonation, an initial investment narrative and escalating demands at the point of withdrawal. In this case, however, the investigation went beyond the victim’s transaction history. DCP (Cyber) Bajrang Bansode said technical analysis helped police identify the accused, while Senior Police Inspector Sandeep Patil described the complaint and the impersonation method.
Police seized 100 mobile phones, 669 SIM cards, a computer, two chequebooks and a passbook from Kumar’s residence in Delhi. Assistant Police Inspector Nitin Gachhe said Kumar was involved in “OTP farming”, which involved generating OTPs from fake SIM cards using basic mobile phones and selling them to handlers in Cambodia and elsewhere through Telegram.
The seized material is significant not simply because of its volume, but because it shows the physical side of an apparently digital crime. Behind a WhatsApp account or a Telegram message can be a stock of handsets, SIM cards, account records, payment channels and people managing activation requests. The digital interface conceals a logistics operation.
Police also found a Chinese-language WhatsApp display name on Kumar’s phone that was used to advertise SIM and WhatsApp numbers with OTPs for sale. Assistant Inspector Vijay Ghorpade said cybercriminals contacted Kumar after seeing the display name and placed orders through WhatsApp. This suggests that the supply network itself operated through online marketplaces and informal contacts rather than through a single central organisation described in the police account.
The technical mechanism is straightforward but consequential. OTPs are designed to confirm control over a mobile number during registration or login. When large numbers of SIM cards are acquired or fraudulently activated, the verification layer can be converted into a service for creating accounts at scale. Police said SIM or OTP farming involves managing large numbers of SIM cards to generate and receive thousands of OTPs, helping bypass online verification systems and facilitating digital identity fraud.
A cyber police officer also said fraudsters may use specialised SIM boxes to connect hundreds or thousands of mobile numbers directly to computers or the internet. The supplied police account does not establish that a SIM box was used in this particular case, but the reference indicates the type of equipment investigators associate with large-scale SIM management.
The distinction between this case and an isolated fake account is therefore important. A single fraudulent number may be used for one conversation or one transaction. A SIM-farming operation attempts to create repeatable capacity: more numbers, more accounts, more contacts and potentially more targets. That capacity can be rented or sold to other actors, allowing fraud networks to expand without every participant needing to acquire telecom access independently.
The case also highlights the difficulty of governing mobile identities across jurisdictions. The Enforcement Directorate in Delhi was reported by police to have identified 36,000 active Indian SIM cards being operated from Cambodia in June. Nearly 5,300 were reportedly linked to cyber-fraud cases involving Rs 100 crore across India. These figures were cited in the police account and are not independently detailed in the supplied material, but they indicate the scale that investigators are examining.
Police said the probe found that Indian mobile numbers were fraudulently activated and supplied to Malaysian nationals who allegedly operated them from Cambodia to target victims in India. This creates an enforcement gap between the location where a number is activated, the location from which a fraud message is sent and the location where the victim loses money. Each stage may fall under different investigative, regulatory or international-cooperation processes.
For telecom and digital platforms, the case raises questions about how identity verification is monitored after activation. The existence of an OTP does not by itself establish that the person using an account is legitimate. When hundreds of SIM cards are accumulated by one operator, the pattern may become visible only through coordinated analysis of subscriber records, device activity, activation behaviour, payment trails and complaints.
The police investigation appears to have followed that broader route. Technical analysis connected the original complaint to the alleged supplier, while the seizure of phones, SIM cards and financial documents provided investigators with material to examine the network. The police account does not specify what further action will follow against the Cambodia-based handlers or how the allegedly fraudulent SIMs were activated, leaving those parts of the chain unresolved.
For residents, the practical risk is not limited to losing money through an investment scam. A mobile number is increasingly used as a gateway to messaging accounts, financial services and digital identity checks. When that gateway is obtained through fraudulent activation or supplied to a remote operator, the abuse can be difficult for victims to distinguish from legitimate communication. The impersonation of a reputed investment company adds another layer of credibility to the fraud.
The Mumbai case therefore shifts attention from the final scam call to the systems that make repeated digital impersonation possible. It shows how a local complaint can lead to evidence of interstate procurement, cross-border operation and cryptocurrency settlement. The arrests establish the police allegation against the three men, but the full scale of the network, the role of overseas handlers and the safeguards that failed during SIM activation remain matters for the continuing investigation.
The next stage will depend on how investigators trace the seized devices, SIM cards, payment records and communications, and whether those records identify additional suppliers or handlers. Until then, the case confirms one central fact: cyber fraud is not only a problem of deceptive messages. It is also a problem of the telecom and verification infrastructure that enables those messages to reach victims at scale.

