Duplicate SIM exposes a structural flaw in UPI, Karnataka HC ruling shows
Karnataka High Court held BSNL liable for a SIM swap fraud, and the ruling highlights how one mobile number can unlock many financial channels.
Intelligence analysis by GPT-5.4 Mini

The court’s June 5, 2026 ruling says a duplicate SIM directly enabled a cooperative bank’s loss and makes the telecom operator pay. The article argues the deeper issue is that India’s payment stack still leans too heavily on the registered mobile number as a master key.
A phone number here works like one master key for several locks. If someone steals that key by getting a fake SIM, they can grab the secret codes used to move money and break into more than one banking door.
Analysis
What the court held
The Karnataka High Court said BSNL was responsible for a cooperative bank’s loss in a SIM swap fraud because the duplicate SIM was what allowed the thieves to intercept OTPs and move money. The article says Justice Suraj Govindaraj rejected BSNL’s challenge to a Permanent Lok Adalat award and held the telecom company liable for the bank’s net loss, along with consequential damages and interest.
Why this goes beyond liability
The article’s larger point is that the mobile number remains the weakest link in a payments system that otherwise looks digital and secure. In UPI, that number is tied to the user’s bank account mapping, used to verify registration through SMS, and also serves as the channel for OTPs used in internet banking, card payments, and RTGS/NEFT transfers.
Device binding helps UPI reject transactions from an unregistered handset, but that safeguard does not protect every other service that still trusts an OTP sent to the registered number. The article notes that the fraud in this case did not happen through a cloned UPI app; it happened through internet banking and bank transfers after the number itself was taken over.
The liability split
The piece contrasts this ruling with a June 2026 Delhi High Court decision on phishing, where a customer who clicked a phishing link was treated as negligent. The article says that distinction matters: where the customer hands over an OTP, liability can stay with the customer; where a SIM swap happens outside the customer’s control, the loss can shift to the telecom side if the swap is proved.
The broader risk
With UPI processing over a thousand crore transactions a month, the article argues that any channel relying on the same mobile number for authentication inherits the same exposure. The ruling settles one dispute, but it also exposes how much of India’s payment security still depends on telecom-level verification.
Key points
- The Karnataka High Court held BSNL liable for a cooperative bank’s loss in a SIM swap fraud.
- The court said the duplicate SIM was the proximate cause because it enabled OTP interception and the transfers that followed.
- The article argues that UPI and other banking services rely too heavily on the registered mobile number as a master authentication channel.
- Device binding helps protect UPI transactions, but it does not protect internet banking, card payments, RTGS, or NEFT when the SIM itself is compromised.
- The piece contrasts SIM swap fraud with phishing and says liability depends on whether the OTP loss came from telecom negligence or customer error.
If the ruling pushes telecom firms to verify SIM replacements more carefully, it could reduce one of the easiest ways criminals hijack payment accounts. It may also force banks and regulators to rethink how much trust they place in a single mobile number.
If SIM replacement checks stay weak, a fraudster can keep using the phone network to intercept OTPs and drain accounts without touching the customer’s device. That would leave UPI and linked banking services exposed whenever telecom-side verification fails.


