USSD Call Forwarding Scam Exposed: How *21# Hijacks Mobile Verification Calls
Cybercriminals are leveraging outdated USSD call forwarding mechanisms, such as the *21# code, to intercept voice-based one-time passwords and compromise financial accounts without requiring physical SIM card manipulation. Security researchers and regulatory bodies have raised alarms about a growing fraud technique that enables attackers to remotely control victim phone numbers by exploiting legacy mobile network protocols. By诱导 users into entering specific USSD code sequences, cybercriminals activate call forwarding settings that reroute all incoming voice communications—including authentication calls and multi-factor verification prompts—to devices under their control. This method effectively bypasses traditional security measures and grants unauthorized access to banking platforms, messaging services, and identity verification systems.
Shift from Traditional SIM Swapping to Covert Call Forwarding Tactics
Over the past decade, stricter regulatory requirements and enhanced customer verification processes have made physical SIM card duplication increasingly challenging for fraud networks. In response, malicious actors have turned to established telecommunications infrastructure designed for basic user configuration functions. USSD codes, originally developed to allow immediate adjustments to call settings without additional authentication, provide a vulnerability that can be exploited through social engineering tactics. The attack typically initiates with a missed call followed by a deceptive message or automated voice call impersonating legitimate organizations. Victims receive instructions to dial specific numeric sequences, often under the guise of resolving urgent account issues or pending deliveries. When users input these codes, attackers gain control over call routing parameters, redirecting critical verification calls to their own devices.
Systemic Risks and Regulatory Implications
Experts emphasize that the prevalence of this fraud model stems from broader systemic weaknesses in data protection frameworks. Leaked personal information from corporate databases, customer service systems, and third-party vendors enables attackers to craft highly targeted phishing campaigns. While many organizations prioritize public-facing security initiatives, internal infrastructure audits frequently reveal gaps in encryption standards and access control protocols. India’s Digital Personal Data Protection Act introduces stringent obligations for entities handling sensitive information, mandating penalties of up to ₹100 crore for data breaches. The legislation classifies mobile numbers and associated metadata as critical personally identifiable information, compelling telecom providers and enterprises to address legacy security flaws, implement multi-factor administrative controls, and safeguard user records against unauthorized access.
Mitigation Strategies and Industry Response
To address the escalating threat of USSD-based exploitation, cybersecurity professionals recommend a coordinated national approach. Specialized research units within law enforcement agencies must monitor emerging attack patterns in real time and develop standardized response protocols for investigative teams. Continuous training programs for officers should replace sporadic educational sessions with regular technical updates to keep pace with evolving exploit methodologies. Public education campaigns in multiple regional languages are also crucial to inform high-risk groups, including elderly users and young adults, about protective measures. For individual users, immediate steps include avoiding unsolicited requests to dial unknown codes and verifying suspicious communications through official channels. Regulatory bodies must enforce stricter oversight of telecom operators to ensure compliance with updated security mandates and prevent further exploitation of outdated network protocols.
