Grahak Mitra

How to secure your accounts after a SIM swap (India)

Last updated: 2026-07-11

While your number was on the attacker's SIM, every account that uses SMS one-time passwords (OTPs) to log in or reset a password could have been reached — so once you have your number back, re-secure those accounts in priority order: email and bank/UPI first, then everything else. Do this from a device you trust, not the phone that was affected.

This is the step after the emergency. If your number is still on the attacker's SIM right now — your phone shows "no service", calls and SMS have stopped — start with the reclaim, bank-freeze, and reporting steps here first: SIM swap fraud: signs and what to do. Come back to this page once your number is verified on your own SIM again; only then can you safely re-secure the accounts below.

Why the accounts still need securing

Getting your number back stops new OTPs from flowing to the attacker. It does not undo what they may have already done while they held it: logged into your accounts, changed a password, added their own recovery email or phone, or set up mail forwarding. Each of those keeps working after the SIM is back with you — until you find and remove it. That is what this checklist is for.

Re-secure your accounts, in priority order

Work top-down, from a different, trusted device. The order matters: your email is the master key that can reset almost everything else, and your bank/UPI is where money moves — so those come first, before social media and the rest.

PriorityAccountWhat to do on it
1Email (your main inbox)The master key — it can reset your bank, UPI, and social logins. Change the password; remove any attacker-set forwarding rules, filters, or changed recovery email/phone; turn on two-factor; sign out all other sessions. Full order: secure your email first, in the right order.
2Bank & UPIChange your net-banking password and UPI PIN. Check for payees, mandates, or beneficiaries you did not add, and for transactions you did not make. If any money moved, report it (see below).
3Other money apps & walletsWallets, trading, and shopping apps that hold money or cards: change the password, check saved cards and recent orders, and remove any address or payee you did not add.
4WhatsApp & messagingRe-verify your number and set a two-step PIN. Steps: hacked WhatsApp: how to recover your account.
5Social media (Instagram, Facebook, others)Change the password, turn on two-factor, remove unknown sessions and connected apps, and confirm your recovery email/phone is still yours. Steps: hacked Instagram or Facebook: recover and lock it down.
6Everything else that used SMS-OTPAny other account you signed into or reset with an SMS code: change the password and check its recovery settings for changes you did not make.

On every account, the two things to look for are the same: a password you no longer set, and a recovery email, phone, or forwarding rule the attacker added to keep a way back in. Change the first; remove the second. A password change alone does not close a door the attacker left propped open.

Harden against the next SIM swap: move off SMS-OTP

The reason a SIM swap was so damaging is that many accounts trust a code sent to your phone number by SMS. Whoever holds your number holds those codes. So the lasting fix is to stop relying on SMS for the important accounts:

You may not be able to move every account off SMS — some only offer SMS codes. That is fine; move the ones you can, starting with the master keys, so a single SIM swap can no longer be a skeleton key to your whole digital life.

Report, and check for money lost

File a complaint at cybercrime.gov.in. If the SIM swap led to any money leaving a bank or UPI account, also call 1930, the national cyber-crime helpline, and note the reference and acknowledgement numbers. The full first-hour money steps are here: UPI fraud — what to do in the first hour.

Beware a second scam: never pay a "recovery agent", "ethical hacker", or "hacker-for-hire" who promises to secure your accounts or recover lost money for a fee — that is a fresh fraud. The only real routes are each account provider's own settings and account-recovery flow and, to report, cybercrime.gov.in and 1930. Do every step above from a different, trusted device if you think the attacker still had access to your phone.

If you still find something wrong

Keep every complaint acknowledgement number. If an account provider's recovery flow does not restore control, keep trying it, and use the National Consumer Helpline (1915) for guidance. All official channels are linked below so you can act directly.

Was this helpful? (anonymous — no sign-up, nothing stored about you)

Official sources (verify everything here — and you can act directly through them)