Hyderabad Cyber Gangs Steal Phones to Drain Bank Accounts
Criminals combine physical theft with social engineering to bypass mobile security and empty victim accounts.
Cyber gangs in Hyderabad are increasingly stealing mobile phones as a primary gateway to drain victims' bank accounts. This hybrid approach combines physical theft with digital fraud to bypass traditional security measures.
According to the Hyderabad Cyber Crime Police, who have arrested three individuals in connection with these crimes, the gangs target mobile devices to gain direct access to financial apps. The criminals obtain screen locks by observing victims enter their PINs or patterns in public spaces, or by tricking victims into revealing their credentials during fraudulent recovery calls. Once the device is unlocked, fraudsters use the stolen SIM cards to receive one-time passwords (OTPs), allowing them to reset UPI and net banking credentials and transfer funds out of the accounts.
The Shift to Physical-to-Digital Crime
This activity is part of a broader emerging trend known as 'physical-to-digital' crime. Unlike traditional remote phishing or smishing attacks that rely on deceptive links sent via email or text, this method uses the physical theft of a device as the primary vector for financial fraud. By possessing the hardware and the SIM card, attackers can circumvent many of the multi-factor authentication layers that typically protect online banking, as the trusted device and the registered phone number are both in the criminal's possession.
Security Implications
This trend highlights a critical vulnerability in mobile-based banking security. It demonstrates that physical possession of a device can lead to total financial loss if biometric or passcode security is compromised. The speed of these attacks is further accelerated by the use of online gaming apps and mule bank accounts, which the Hyderabad Cyber Crime Police note are frequently used to move and layer stolen funds, making them harder for authorities to trace and recover.
Future Outlook
As these gangs refine their social engineering tactics to bypass screen locks, security experts suggest a need for stronger device-level encryption and the decoupling of banking authentication from SIM-based OTPs. Authorities continue to investigate the scale of these operations to determine if these gangs are operating as isolated cells or as part of a larger, coordinated network across the region.