1,300 SIM cards, two states, one arrest: Why this CBI find alarms
On September 12, the Central Bureau of Investigation (CBI) put out a note that it had searched 10 locations in Vaishali district of Bihar and Jagatsinghpur district of Odisha and arrested a person: Airtel’s area distributor for Mahua.
The CBI said the searches were part of an investigation into an illegal SIM-box operation detected in Bihar’s Supaul last year, a case that was eventually transferred to the CBI. More than 1,300 SIM cards had been found in the house where the box was running. Analysis of those connections, the CBI claimed, linked them to at least 73 cybercrime cases across India, including ‘digital arrest’ frauds. Bulk of the cards had been issued in Bihar and Odisha.
More than 700 cards, the CBI claimed, were issued by the arrested Mahua distributor by allegedly misusing the credentials of over a dozen points of sale in Bihar’s Vaishali. Subscribers later told investigators they had never sought numbers in their names. Some appeared to have been induced to complete extra e-KYC; in other cases, biometric data taken for another purpose was allegedly reused. The CBI said phones, laptops and SIMs were seized as part of the investigation.
The reason all of this matters in Bihar is what the CBI note implies next. These cards were not smuggled in from a foreign call centre. They are alleged to have been issued on the licenced telecom last mile in the same state that first found the box, then fed into a machine that can make a fraud call look like coming from any other Indian mobile network. Supaul was the box. Vaishali, on CBI’s telling, was a tap. Odisha is on the map because a large share of the 1,300 SIMs were issued there as well as in Bihar.
Digital arrest is a con. A caller claims to be police, a bank or a central agency, holds the victim on a video call and demands money to “clear” a case that does not exist. The call has to look local. A box loaded with Bihar and Odisha numbers could do that work.
The victim may sit in another state. If the CBI is right, the connection was born at a counter in Vaishali. That is why an unnamed distributor in Mahua is not a footnote to a national cyber tally. Bihar sits on both ends of the file: the first find last year and the alleged issue-point this week.
A SIM box is a bank of modules that holds many SIMs at once, places calls as if each card were an ordinary handset, and can cycle to another number when one is reported and cut. To the person who picks up, the number can look entirely routine. That is the point of the inventory.
Ministers often announce two tallies in one breath: SIMs disconnected and IMEIs (International Mobile Equipment Identities) blocked. They are not the same tool. An IMEI is the identity of a device. If it is blacklisted on the Central Equipment Identity Register, Indian networks can refuse that handset. That matters against stolen phones and machines already logged in a fraud complaint. A SIM is the connection. Kill the handset and a network that still has new cards simply moves the stock.
The government has been cutting both. By June 30, more than 1.57 million SIM cards and 577,000 IMEIs had been blocked on the basis of police reports. Separately, the ASTR system had disconnected more than 8.8 million connections that failed re-verification by mid-July.
But those are different nets: one starts from a crime file, the other from identity analytics. Both are large. Neither is what the Mahua note describes. Those cuts are strongest after a number or a face has already been flagged. The allegation here is that cards were still being generated upstream on valid point-of-sale credentials before anyone had a fraud IMEI to ban.
DoT has kept tightening the paper around that counter—blacklisting points of sale, ending paper KYC, freezing duplicate SIMs and issuing fresh Telecommunications (User Identification) Rules in August. In the same season, it warned that tampering with an IMEI, assembling a SIM box or obtaining a SIM by fraud can attract up to three years in prison and a fine of Rs 50 lakh under the Telecommunications Act, 2023. This file is the test of whether those rules bite the person who holds the shop login, not only the handset that makes the call.
The CBI’s account points at the weakest joint in a system that looks digital. A distributor sits above a cluster of outlets. Those outlets hold credentials to run legitimate e-KYC. A customer arrives for one connection. Extra authorisations are generated from those logins. The extra SIMs, investigators suspect, never reached the people named on them.
Digitisation removed carbon paper. It did not remove the human being who turns an identity into a live number. That is not an argument against biometric KYC. It is why audits of customer-acquisition forms and e-KYC discrepancies are not clerical work.
The architecture is not unique to Vaishali. In December 2025, the CBI opened a separate Delhi file on a firm alleged to have taken about 21,000 bulk SIMs. Some numbers, the agency said, had operated across 203 to 387 IMEIs and fired one-second automated calls—the pattern of a box or an auto-dialler, not a household phone. The two cases are not the same conspiracy. They are the same shape: a legitimate connection enters the system, someone multiplies it, the number goes into a machine, and an ordinary person answers a call that already looks Indian.
It does not prove that the Mahua distributor personally ran each of those frauds. The CBI’s claim is narrower and still serious: this stock of cards is linked, on its analysis, to 73 cybercrime files, and more than 700 of the cards were issued through misused Vaishali point-of-sale credentials. Airtel is in the note only as the operator on whose network the arrested man was an area distributor. That is in no way a finding against the company.
The legal road is specific. The CBI is investigating cheating, forgery and extortion under the Bharatiya Nyaya Sanhita, 2023; identity theft and computer-related offences under the Information Technology Act, 2000; and offences under the Telecommunications Act.
The questions an IMEI blacklist cannot answer are the ones this file now has to answer in court. Whose credentials were used? How many SIMs left one genuine visit? Where did the cards go after activation? How many can one compromised distributor feed before the pattern shows?
The arrest does not mean the boxes are empty. It means something Bihar should not file under “cybercrime elsewhere”. The 1,300 SIMs in that house had already passed through a system built to know whom they belonged to. If the CBI is right, they belonged to the counter first, and only then to the box.

