OTP Farming Scam Exposed: Mumbai Police Bust Network Selling Verification Codes for ₹1,246 Each

 | 
SD

Cybercriminals are increasingly finding new ways to exploit mobile numbers and online verification systems, and a recent Mumbai Police investigation has uncovered an operation involving what investigators describe as “OTP farming.” The alleged network reportedly generated verification codes using large numbers of Indian SIM cards and supplied them to overseas cybercrime operators.

Mumbai Crime Branch's Western Region Cyber Police have arrested three people in connection with the case. Investigators seized 669 active SIM cards and 100 mobile phones, along with computers and other electronic equipment allegedly used in the operation.

According to police, the network had links with cybercriminals operating from Cambodia. Verification OTPs used to activate Indian WhatsApp accounts were allegedly supplied to overseas handlers, who could then use those Indian numbers while approaching potential victims.

Investigators said payments of up to $13, equivalent to roughly ₹1,246, were allegedly made for an OTP in cryptocurrency.

What Exactly Is OTP Farming?

A one-time password, commonly known as an OTP, is normally generated to verify a user's identity while creating an account, signing in or completing certain transactions.

OTP farming abuses this verification mechanism on a large scale.

Instead of obtaining just one number or verification code, criminals can arrange numerous SIM cards and mobile devices to repeatedly receive OTPs. Those codes can then be used to activate accounts or provide verified-looking digital identities to other fraudsters.

In the Mumbai case, investigators allege that SIM cards were inserted into basic keypad phones and used to receive verification codes for WhatsApp accounts. The codes were then reportedly supplied to overseas operators.

₹22.30 Lakh Investment Fraud Led Police to the Network

The alleged operation came to light during an investigation into a major online investment fraud.

According to police, an Andheri resident had lost around ₹22.30 lakh after being approached by fraudsters claiming to represent a reputed investment company. The victim was allegedly promised attractive returns from share-market investments.

When cyber investigators followed the digital trail, they uncovered what police say was a broader network supplying Indian SIM cards and WhatsApp verification details to overseas cybercriminals.

The three arrested men have been identified as Pramod Kumar alias Bipin, Dharmendra Gupta and Rajiv Kumar Gupta.

How the Alleged SIM Network Operated

Police investigations indicate that different people allegedly handled different stages of the operation.

Investigators allege that SIM cards were activated using identity documents belonging to unsuspecting people without their knowledge. These SIMs were then passed through intermediaries before reaching the person allegedly operating the OTP farming setup.

The SIM cards were placed in mobile phones to receive WhatsApp verification codes. Those OTPs were allegedly passed to Cambodia-based handlers through messaging platforms.

The overseas operators could then activate WhatsApp accounts associated with Indian mobile numbers and use them while targeting people in India.

Police reports also indicate that payments for the verification codes were made using cryptocurrency.

669 Active SIM Cards and 100 Phones Seized

The scale of the equipment recovered gives an indication of how extensively the alleged operation was set up.

Police reported seizing 91 keypad phones and nine smartphones, taking the total number of recovered mobile handsets to 100.

Investigators also recovered 669 active SIM cards, a computer CPU, Wi-Fi equipment, a fingerprint scanner and other electronic accessories. Police are continuing their investigation to identify additional links to the alleged network.

Why Indian WhatsApp Numbers Are Valuable to Fraudsters

An Indian mobile number can make an unsolicited WhatsApp message appear more familiar to someone in India than a message originating from an unknown international number.

According to investigators, the overseas handlers allegedly used Indian WhatsApp accounts while targeting prospective victims with fraudulent investment offers.

The Mumbai case shows why an OTP should be treated as a sensitive authentication credential. A verification code can sometimes provide the final authorization needed to activate an online account.

How to Protect Yourself From OTP-Based Cyber Fraud

Never disclose an OTP received on your phone to an unknown caller or person contacting you through WhatsApp, Telegram, SMS or another messaging service. Banks, legitimate financial institutions and government agencies generally do not need you to hand over confidential authentication credentials to an unsolicited caller.

Be particularly cautious if you suddenly receive OTPs for accounts or services you did not request. Repeated unexplained OTPs can indicate that someone is attempting to register or access a service using your mobile number.

Similarly, do not install APK files or unknown applications sent through WhatsApp or Telegram, and avoid clicking investment links received from unfamiliar numbers.

Investment offers promising guaranteed or unusually high returns should also be independently verified before any money is transferred.

What to Do If Money Is Lost in a Cyber Scam

Speed can be important after an online financial fraud.

Victims in India can report cybercrime through the government's National Cyber Crime Reporting Portal. The portal accepts complaints involving online financial fraud, mobile-related cybercrime, social-media crime and several other categories.

For financial cyber fraud, victims should also contact the 1930 cybercrime helpline as quickly as possible and inform their bank or payment provider so that appropriate action can be initiated. Mumbai Police also advised victims to report such incidents promptly.

OTP Farming Shows How Cybercrime Infrastructure Is Evolving

This case is significant because the alleged criminals were not simply trying to trick victims into revealing an OTP. Investigators say they had established an infrastructure for generating and supplying verification codes and Indian-linked accounts to other fraudsters.

Police are now investigating the wider network, including overseas operators, the origin of the SIM cards, mule bank accounts allegedly used to move fraudulent proceeds and other people who may have been connected with the operation.

For mobile users, the lesson is straightforward: an OTP should be treated with the same caution as a password or banking PIN. If an unexpected verification code arrives on your phone, do not share it with anyone and check whether someone may be attempting to use your number for an account you did not authorize.

Tags