A new fraud tactic making the rounds doesn't require scammers to physically swap your SIM card at all, it just needs you to dial a few numbers on your own keypad. Cybersecurity analysts and law enforcement are now warning about USSD-based call forwarding scams, where victims are tricked into dialling code sequences like *21# that silently redirect all their incoming calls, including voice OTPs and multi-factor authentication checks, straight to a scammer's device.
From Physical SIM Swaps to a Sneakier Trick
Stricter KYC rules from telecom regulators made it much harder for fraudsters to get duplicate SIM cards issued in someone else's name. So criminals pivoted to something simpler: USSD codes, a decades-old feature built into mobile networks that lets users tweak call settings instantly, without any password or identity check.
The scam usually starts with a missed call, followed by an urgent SMS or automated call pretending to be from a courier company, utility provider, or bank. The message claims a delivery is pending or an account needs urgent verification, and instructs the victim to dial a specific code, something like *21# followed by a ten-digit number. The moment that code is dialled, the carrier automatically starts forwarding all incoming calls to the attacker. Since phone numbers are the anchor for banking OTPs, account recovery, and two-factor authentication almost everywhere, that one dialled code hands the attacker the keys to a person's financial and digital life.
Where the Real Vulnerability Lies
Experts point out that this isn't purely about people being careless, it's also about weak data security further up the chain. Leaked contact details from corporate databases and third-party vendors give scammers exactly what they need to build convincing, personalised scripts. Many companies that spend heavily on marketing still lag behind on the security side, leaving customer data exposed in ways that make these scams easier to pull off.
India's Digital Personal Data Protection (DPDP) Act is meant to change that equation. It classifies phone numbers and related metadata as sensitive personal data, and allows regulators to impose penalties of up to ₹100–200 crore per breach on companies that fail to secure it, pushing telecom operators and enterprises to close these legacy security gaps and enforce stronger authentication.
What Experts Recommend
On the enforcement side, cybersecurity specialists are calling for centralised threat-research hubs to track emerging fraud tactics in real time, and for police training to shift from occasional annual sessions to continuous weekly updates, given how fast these exploit methods evolve. Public awareness campaigns in regional languages are also seen as essential, especially to reach older citizens and younger users who are frequently targeted.
For individuals, the advice is simple: never dial an unknown code containing * or # just because an unverified caller or SMS asks you to. If you suspect call forwarding has been activated without your knowledge, you can check it through your carrier's settings, or immediately dial ##002# to instantly cancel any active call forwarding on your device.
FAQs
Q1. How does the USSD call forwarding scam work?
Scammers trick victims into dialling a code like *21# followed by a number, which activates call forwarding and silently redirects all incoming calls, including OTPs, to the attacker's phone.
Q2. Do I need a new SIM card for this scam to work on me?
No. Unlike SIM swap fraud, this scam works entirely through USSD codes dialled on the victim's own existing phone, no physical SIM replacement needed.
Q3. How can I check or undo unauthorised call forwarding?
You can check your call forwarding status through your carrier's network settings, and dialling ##002# instantly cancels all active call forwarding on your device.