The directorate of enforcement (ED) has unearthed an alleged cross-border cyber fraud network involving the fraudulent activation of thousands of Indian mobile subscriber identity module (SIM) cards supplied to foreign nationals, who subsequently used them from Cambodia to perpetrate cybercrimes across India.
According to ED, the investigation centres on a Malaysian national who allegedly obtained Indian mobile numbers that had been fraudulently activated by point-of-sale (POS) vendors. These numbers were later operated from Cambodia and used in cyber fraud schemes targeting victims across multiple Indian states.
The money laundering investigation stems from a first information report (FIR) registered by the cyber police station under the deputy commissioner of police (Crime), Jodhpur, against certain SIM card vendors accused of misusing telecom connections.
ED said its investigation revealed a large-scale operation in which thousands of mobile numbers were activated fraudulently in India and routed to overseas operators.
Analysis of around 230,000 mobile numbers uncovered a significant international link. Investigators found that about 36,000 SIM cards were active in Cambodia. Of these, nearly 5,300 mobile numbers were allegedly linked to cyber fraud cases registered across India, resulting in financial losses running into hundreds of crores of rupees.
The agency said the fraudsters primarily used these mobile numbers to make WhatsApp calls and facilitate various cybercrime operations targeting Indian citizens.
According to ED, the investigation has identified several individuals who allegedly played a key role in the SIM card supply chain.
The agency named Rahul Kumar Jha, Mohammad Sharif and Sandeep Bhatt as key accused who allegedly worked in connivance with SIM vendors Prakash Bheel, Ramavatar Rathi, Hareesh Malakar and Hemant Panwar to supply hundreds of SIM cards to Malaysian nationals.
The accused vendors reportedly possessed authorised point-of-sale (PoS) IDs issued by telecom operators, including Airtel, Jio and Vi, for the activation and issuance of SIM cards.
Investigators alleged that the vendors targeted less educated and unsuspecting individuals by offering services such as mobile number porting or new SIM issuance. During the activation process, they allegedly activated additional SIM cards using the customers' credentials without their knowledge.
These extra SIM cards were then allegedly supplied to foreign nationals through intermediaries in exchange for commissions paid on each activated SIM card.
ED said search operations led to the seizure of incriminating documents and materials that could help establish the financial trail and operational structure of the network.
The agency has also identified around 30 bank accounts linked to the accused persons as part of the ongoing financial investigation.
In addition, investigators gathered information on various movable and immovable assets allegedly linked to those involved in the racket.
Officials believe the findings could help uncover the proceeds of crime generated through the alleged cyber fraud activities and trace the wider network behind the operation.
The case highlights growing concerns among enforcement agencies about the misuse of Indian telecom infrastructure by international cybercrime syndicates operating from countries such as Cambodia, which has emerged as a hub for several organised cyber fraud networks targeting victims worldwide.
The use of fraudulently activated Indian mobile numbers enables cybercriminals operating abroad to appear legitimate to potential victims in India, making it easier to execute scams via voice calls, messaging apps, and other digital communication channels.
ED said further investigation is underway to identify additional beneficiaries, financial transactions and international links associated with the network.
The agency is also expected to examine the role of intermediaries and the movement of funds generated through the alleged cyber fraud operations.