March, 2026

One SIM to Rule Them All: Examining OTPs and SIM Binding for Digital Security

In December 2025, a 59-year-old man from Hyderabad was scammed out of INR 2.49 lakh after receiving a fraudulent One-Time Password (OTP) for a Unified Payments Interface (UPI) transaction. This incident is part of a troubling trend, as cybersecurity incidents in India surged from 10.3 lakh in 2022 to 22.68 lakh in 2024, coinciding with over 86% of households going online by October 2025. Authorities have responded by blocking over 11.14 lakh Subscriber Identity Module (SIM) cards and 2.96 lakh International Mobile Equipment Identity (IMEI) numbers linked to such frauds, underscoring the urgent need for improved security measures.

In November 2025, the Department of Telecommunications (DoT) mandated that application-based communication services (ABCS) maintain a continuous link with the active SIM in a user’s device (The DoT directive). The DoT directive, under the Telecommunications (Telecom Cyber Security) Rules, 2024, has come into effect from March 01, 2026 and was rooted not only in curbing the rise in cybercrime but also in maintaining national security. Despite measures such as one-time passwords (OTPs) and SIM binding being projected as effective defence mechanisms, these methods have been linked to cyber fraud, underscoring the need for layered security approaches in India. This article examines the measures and steps necessary to establish a secure cyberspace.

What is SIM Binding and why is it seen as a solution?

SIM binding refers to linking a digital account or application to a specific physical SIM card’s unique identifier, like the International Mobile Subscriber Identity or the Integrated Circuit Card Identification. To verify, the app checks whether the device's SIM matches the registered identifier, either before logging in or during use. If the SIM data does not match, access to the user’s account or application is blocked. This ensures that only the device’s SIM can access the account or application, preventing unauthorised access by individuals using stolen credentials or fake SIMs.

Without SIM binding, digital ecosystems are vulnerable, allowing scammers to exploit weaknesses such as SIM swapping and cloning to compromise accounts, intercept OTPs, and bypass identity verification mechanisms, thereby facilitating large-scale financial fraud and identity theft. SIM swapping is a type of fraud in which a cybercriminal obtains a replacement SIM card for a victim’s number, thereby gaining control over calls, messages, and OTPs and PINs. This leads to unauthorised access to financial accounts and services, paving the way for identity theft and fraud.

SIM cloning, on the other hand, creates a duplicate of a victim's SIM using specialised software, allowing the attacker to impersonate the victim's mobile connection without disabling the original SIM. This enables monitoring of calls and messages, tracking the victim’s location, and intercepting SMS-based OTPs to access accounts, often without the victim's knowledge and authorisation. One could argue that stronger, layered measures governing SIM issuance, verification, and binding could aid secure digital transactions, preserve trust in mobile-based authentication systems, and curb systemic abuse of identity-linked services.

SIM Binding and Its Efficacy for Digital Security and Cyber Crime Prevention

SIM binding, while touted as a digital security measure, has some limitations. The rise of dual-SIM smartphones in India complicates app authentication, as users often switch SIMs for better rates, leading to confusion about which SIM is bound to an app. Typically, the primary SIM is used, but this requires frequent re-authentication when switching.

eSIM technology further complicates matters. Digital SIMs enable users to switch carriers without physical cards and host multiple profiles, making it challenging to bind to a specific virtual identifier. Although solutions like eSIMs with unique EIDs exist, many apps and telecom operators lack the necessary infrastructure upgrades. Moreover, legitimate device changes, such as phone upgrades, can lock users out of essential services, including banking. Eliminating SIM binding risks exposing users to several types of fraud, including SIM swapping and OTP interception. Thus, finding a balance between security and usability is crucial.

While the DoT directive aims to bolster security, it raises concerns about surveillance and data governance. Continuous SIM binding creates a permanent data trail, allowing providers to track device and SIM usage, monitor app activity, and build detailed user profiles. The implementation of the Digital Personal Data Protection Act, 2023 (DPDP Act), presents challenges for organisations, including lawful data processing, obtaining explicit consent, and effective data minimisation and retention strategies. This approach could inadvertently create a chilling effect, as ABCS become tethered to KYC-verified SIMs. Effective compliance would therefore require transparent governance, secure data storage, and auditable mechanisms for consent management to mitigate regulatory risks, ensure freedom of speech, and safeguard user privacy.

The "one person, one phone, one SIM" model fails to accommodate realities like migrant workers changing SIMs, refugees without stable access, families sharing devices, and travellers using local SIMs. This rigidity risks excluding vulnerable populations from essential services. Functional and accessibility hindrances, such as a business operating via ABCS requiring repeated logins every 6 hours or losing access to ABCS during international travel when users need a local SIM, merely create inconveniences for an ordinary user. Mandatory SIM binding also limits user control and choice. It is unclear whether users can opt out, how their data is collected, or if they can request deletion or address misuse. Without clear guidelines, SIM binding may erode trust, compromise privacy, and undermine consent and digital inclusion.

OTPs (discussed in detail in the following section) and SIM binding are just two cogs in the broader security ecosystem. In most digital systems, OTPs are utilised at two key stages. First, during the SIM binding process, an OTP verifies the ownership and activity of the mobile number. Second, OTPs are triggered during sensitive actions, such as password resets, changes to contact details, financial transactions, or account recovery, confirming that the user authorises the action and has access to the linked number.

SIM binding, on the other hand, links an account to a specific SIM or device over time, ensuring continuity between the user and the system. In contrast, OTPs confirm that the user initiates a particular action at that moment. Together, they create a layered security model addressing both long-term association and real-time authorisation.

OTPs as a Verification Mechanism

The 2020 COVID-19 pandemic and its associated lockdowns accelerated the adoption of contactless and online payments. The increasing popularity of these methods has made OTPs one of the most commonly used verification tools in India. An OTP is a password valid for only one login session or transaction on a computer system or other digital device. To use an OTP process, a login or transaction triggers the system to generate a unique OTP, sent to user’s phone via SMS or email. The user enters this OTP to gain access, provided it matches and is within the time limit.

OTPs are used to authenticate identities across various platforms. They play a crucial role in e-commerce deliveries by approving payments and logins; in UPI transactions for money transfers and cardless withdrawals; in cab rides to verify the rider’s identity; and in accessing essential services such as e-KYC for telecom, banking, and tax filing, among others. Today, it is nearly impossible to go through daily life without encountering an OTP.

Despite their widespread use in India, relying solely on OTPs poses security risks. A 2022 report revealed that payment fraud using OTPs is common, as seen in the case of the Hyderabad resident who was a victim of an OTP scam. Regulatory bodies, including the Reserve Bank of India, have recognised the declining effectiveness of OTPs. In September 2025, the body issued new directions to implement stronger Two-Factor Authentication measures that do not rely solely on SMS-based OTPs.

OTP-based authentication shifts the security burden to end users, discouraging institutions from investing in stronger backend safeguards. When a user enters the OTP manually, fraud may be seen as user error, limiting institutions' liability and their motivation to implement stronger controls, such as behavioural analytics. Recent studies indicate that merchants win approximately 45% of disputed chargebacks, achieving a response rate of 53%. These underscore how the effectiveness of an OTP also protects institutions.

These vulnerabilities of OTPs highlight the need for enhanced authentication to protect India's digital economy. Furthermore, relying solely on one security mechanism creates gaps. An OTP-only approach can't detect SIM swap or cloning attacks, as wrongdoers still receive OTPs and appear legitimate. On the other hand, SIM binding without OTP verification fails to confirm user intent during high-risk actions, even if it recognises the device or SIM. Therefore, adequate account security requires both controls working together to address each other's limitations.

Regulatory and Compliance Considerations

The DoT directive attempts to operationalise SIM binding as a response to the systemic vulnerabilities identified above. Under the DoT directive, ABCS remain linked to the SIM card in the user’s device. If a web-based version is available, sessions must be logged out every six hours, allowing users to re-link via a QR code. This provision partially addresses session continuity risks but introduces user inconvenience and friction when operating across multiple devices. These requirements should be implemented within 90 days, with a compliance report due 120 days thereafter. Users travelling abroad will not be affected as long as the SIM card remains in the device and they are using international roaming, offering temporary accommodation for users by addressing challenges that arise when users share devices or are reliant on their local SIM abroad.

The DoT directive was not the first instance of SIM binding being recommended as an enhanced security measure for stronger authentication. For example, the Securities and Exchange Board of India (SEBI) proposed SIM binding to strengthen login security by linking user access to their trading and demat accounts to their mobile SIM. As of 2021, the RBI also mandates "dynamic or non-replicable" authentication for digital payments, recognising device and SIM-based methods as valid forms of strong customer authentication in India's digital payment ecosystem. Taken together, these measures signal an intent to move beyond models that rely solely on OTPs. However, these models do not fully address the liability gaps identified earlier in this article: when authentication succeeds, but fraud occurs, and the institution is exonerated.

The challenges mentioned in this article are not unique to India, with international regulations offering instructive parallels and cautions. The United Nations Conference on Trade and Development reports that 90% of countries have some legislation in place to counter cybercrimes. Under the EU’s General Data Protection Regulation, there are strict limitations on device tracking and data collection. Over 160 countries, including India, require SIM card registration, though verification methods differ. For instance, Bangladesh, Jordan, and Saudi Arabia use fingerprints, while China, Namibia, and Singapore employ facial recognition. Singapore limits individuals to three SIM cards. In Europe, countries such as Belgium, Spain, and Italy require identification for SIM card ownership, while Estonia enhances security through Mobile-ID. At the multilateral level, cooperative frameworks such as the UN Convention against Cybercrime and Europol operations aim to establish comprehensive cross-border initiatives to counter crimes committed using increasingly sophisticated information and communication technologies.

These developments show a global shift towards stronger, device-linked authentication to combat fraud. However, these approaches to resolving cybercrime show that stronger security is achievable but requires careful, consequential design choices, especially regarding data minimisation and user consent – principles India ought to adopt post the operationalisation of the DPDP Act.

Future Outlook and Conclusion

The DoT directive has received a mixed response. While the intent aligns with global best practices for telecom security, its implementation has raised important questions about feasibility, operational impact, and user experience. The industry opposes mandatory logouts every 6 hours, fearing they could disrupt ongoing conversations and workflows, while telecom operators support them as essential for reducing fraud and cybercrime.

Relying only on OTPs and SIM binding is inadequate to combat SIM-related cybercrimes. A multi-layered security approach is essential. Alternatives to OTPs include push notification approvals, token-based authentication, zero-knowledge proof, cryptographic signatures, and risk-based authentication. Effective SIM-based authentication measures should consist of mandatory registration and verification of Point of Sale agents, penalties for non-compliance, AI systems to detect fraud, customer tools to monitor unauthorised SIMs, enhanced SIM swap protocols with real-time alerts, and a ban on bulk SIM sales to unverified businesses. These measures, however, will have to be such that they apply purpose limitation and are compliant with data privacy principles.

If the goal of implementing SIM binding is to verify identity, various countries have adopted privacy-preserving measures to that end. Examples include the European Digital Identity Wallet and two-factor authentication, which requires at least two out of three factors: knowledge (such as a PIN or password), possession (such as a phone or token), or inherence (like a fingerprint or facial recognition) for online transactions, as specified in the revised Payment Services Directive. Such initiatives that allow identity verification without compromising the user's privacy should be considered as well.

Together, these steps, along with the alternatives recommended, create a comprehensive security framework that addresses vulnerabilities within the ecosystem. Real-time monitoring and rapid countermeasures will be effective only when stakeholders collaborate at both national and international levels. Therefore, it is crucial to move beyond SIM-based authentication and adopt holistic strategies to ensure safety in today’s digital landscape.

Anahida Bhardwaj is an Associate in the Privacy and Policy Team at DSCI. Based in Delhi, she is interested in emerging tech, internet governance, and AI. She can be reached at : anahida.bhardwaj@dsci.in or policy@dsci.in

Author: Anahida Bhardwaj