SIM Card and OTP Code Data Theft Syndicate Busted, 25,000 Data Leaked
The Cyber Crime Directorate (Ditressiber) of the East Java Regional Police has uncovered a large-scale practice of personal data misuse for issuing thousands of illegal SIM cards. Thousands of these mobile cards were used to produce One-Time Password (OTP) codes, which were then sold illegally. In this bust, investigators suspect the involvement of rogue elements from mobile providers, as tens of thousands of SIM cards used originated from official operators but were activated en masse using other people’s identities.
Cyber Crime Director (Dirressiber) of East Java Police, Commissioner Bimo Ariyanto, explained that the case began with the discovery of suspicious activity on a website called FastSim, which sells OTP activation services at bargain prices without requiring a physical card.
“Around April 2026, the Cyber Directorate detected a website named FastSim selling [OTP access] SIM cards at very low prices,” Bimo said at East Java Police Headquarters in Surabaya on Tuesday (12/5).
Police then investigated the website and arrested three operators at different locations. First, suspect DBS was arrested in Bali, where he acted as the mastermind behind creating the FastSim website and managing the modem pool.
Then, suspect IGVS, arrested in Karangasem, Bali, served as admin and customer service. Finally, suspect MA was nabbed in Tanah Laut, South Kalimantan, where he handled SIM card registrations using other people’s identities.
Bimo explained that on the FastSim site, customers simply pay Rp500 to Rp8,000 via the website to obtain OTP activation codes usable in apps like WhatsApp, Instagram, Telegram, and Shopee.
“By just buying through FastSim, they receive the OTP code and can immediately access social media without getting a physical SIM card,” he clarified.
Technically, the gang committed the crime by exploiting a device called a modem pool, a machine capable of holding dozens to hundreds of SIM cards at once, controlled via computer.
The perpetrators first registered thousands of SIM cards en masse using stolen identities from others, aided by scripts or specific applications.
Once activated, these SIM cards were not sold physically but only used for their ability to receive activation SMS automatically. The OTP codes in those messages were then sold via the FastSim website.
When a buyer needs to register a social media or shopping app account using a private number, the gang sends the verification code or OTP from the illegal SIM card to the customer.
This practice is strongly suspected to be the gateway for thousands of untraceable anonymous accounts, often ending up used for fraud, scamming, and other illegal cyber activities.
“We strongly suspect these SIM cards are used by scammers and other cyber criminals,” Bimo emphasised.
Operating since September 2025, Bimo said the syndicate is believed to have reaped profits of Rp1.2 billion.
In addition to arresting the suspects, police seized evidence including 33 modem pool units, 11 laptops, and 25,400 illegally registered SIM cards.
Currently, East Java Police are delving into the origins of the stolen personal data via a script-like application. Moreover, investigators suspect insider involvement from mobile providers, given that the cards used come from major operators.
“Personal data was extracted from a script-based application. We are still investigating who inputted the personal data into that application. We will probe whether there are rogue provider elements involved in this syndicate,” he stated.
The suspects are now charged under Article 51 paragraph (1) in conjunction with Article 35 of the Electronic Information and Transactions Law, facing a maximum penalty of 12 years’ imprisonment and a fine of Rp12 billion.