SIM swap
Fraud pattern where the attacker convinces the telco to port the victim's MSISDN to a SIM the attacker holds. Once active, the new SIM receives all SMS OTPs, letting the attacker reset banking, wallet and email credentials. TRAI mandates a 24-hour OTP cool-off after any SIM swap.