Almost all published advice on avoiding insurance impersonation fraud rests on one assumption: the attacker knows nothing about you. Check the policy number. Ask for the premium amount. Never share an OTP. Call the number on the company's website. Every one of these works because the caller is working blind.

Recent arrests have shown that the assumption does not always hold. In a case reported in May 2026, two of three men arrested over a Rs 26 lakh fraud were found to have previously worked at an insurance company in Ghaziabad, and investigators said they used company data to identify and contact potential targets before setting up a call centre. In a case reported in August 2026, a call centre used an insurance company's data to target customers, and again the possession of accurate customer details was the mechanism that made the fraud work. Neither case involved a technical breach. In both, the data was simply carried out of the building by people who had lawful access to it.

What the pattern looks like

The common shape is this. Someone with access to customer or policy records builds a list. The list is sold, rented, or used to run a call centre. The caller contacts the customer using accurate, specific details: a real policy number, a real premium figure, a real renewal date, a real agent or relationship-manager name, sometimes a real reference from an earlier interaction. The customer, who has no reason to doubt a caller who knows their details, is moved to a position where the request sounds procedural rather than criminal. Money follows.

Why this defeats the standard advice is easy to see. A caller who says your policy number is 12345678, your premium is Rs 4,200, your renewal is due on the 14th, and your agent is Mr X passes every check the customer thinks of as verification. The customer's only remaining defence is to call a number they obtained independently, which is a different habit from the one they are currently using, and requires them to distrust contact information supplied during the very call in which they are being asked to trust the caller.

The regulatory position, stated carefully

IRDAI has moved to address the sale-side problem. From January 2027, every proposal, policy and certificate is required to carry the identity of the authorised salesperson, and a policyholder who is mis-sold is intended to be able to identify who sold it. That is a real improvement in accountability for the person who sold you a policy. It is worth being clear that it is not the same thing as protecting the record you already gave the insurer.

On the data side, IRDAI's Information and Cybersecurity Guidelines, 2026 set requirements for insurers around information security, access control, and the systems that hold policyholder data. What those guidelines do not do, on their face, is create a specific offence or a specific liability for an employee who removes or sells a customer list. The data protection position in India in respect of this kind of act depends on the Digital Personal Data Protection Act and on how it is applied to the commercial relationships involved, and the practical enforcement position is still developing. I am describing the disclosed regulatory position here, not giving a legal opinion, and if you have been affected the question for a lawyer is not whether the rules exist but whether they have been applied to your facts.

The honest summary is that the accountability rules are ahead of the data-protection rules in this industry. The sale is now traceable; the record is not yet clearly protected in the way a customer would expect.

Why this is getting worse rather than better

Every structural change the industry has embraced in recent years widens the population of people who can lawfully reach a policyholder record. Open APIs mean more integration partners. Aggressive intermediation means more people between the insurer and the customer. Digitised servicing means more of the relationship held in systems rather than in a relationship manager's memory, which means a list is now a more complete and more portable asset. A relationship manager who could previously tell you your premium because they knew you now becomes a source of a list containing your premium for everyone. The technical and business changes are individually sensible. Their combined effect on the size of the exposed population is not something the sale-side rules were designed for.

What to actually do about it

  • Change the one habit that survives insider-sourced data: never call back a number the caller gives you. Every other check can be defeated by an accurate policy number. This one cannot, because it is the only step where you supply the contact information. Close the call, then open the insurer's app or type the company's web address yourself.
  • Treat accurate knowledge as a warning, not a reassurance. This inverts the usual instinct. When a stranger knows your policy number and your premium, that is evidence about where they got it, and the honest reading is that the data is not as protected as you assumed.
  • Ask your insurer, in writing, what they do with your data. Ask whether your details are used to market third-party financial products, whether you can be placed on a do-not-call list, and what access controls apply to your record. A clear answer is informative. An evasion is also informative.
  • Minimise what you give voluntarily. You do not need to authorise marketing communications you have not read, and you do not need to keep an email address current for products you have cancelled. Review the consents you have given across your financial services once a year.
  • Register a nominee and an emergency contact on every policy. This is a servicing step rather than a security step, but it is also the step that makes a fraudulent call to you easier to catch, because a second person is checking the correspondence.
  • Report data misuse to the insurer and to the police, not only to the platform. If you believe your details were used to target you, say so in those terms when you report, and ask for the report to record it. A fraud report that describes only the loss, and not the source of the targeting data, loses the one piece of information that might prevent the next offence.

What to watch on the regulatory side

Two things are worth following. First, whether the sales-person tagging requirement from January 2027 is used for its intended purpose, which is to make mis-selling traceable, and whether it is extended to any notion of data use rather than only data capture. Second, whether any insurer-facing standard emerges for what an employee may take out of the building, and whether a call-centre operations standard is imposed, which is the layer most directly implicated in the pattern described here. Neither exists as a specific, named obligation in the way the tagging rule does, and that is the gap. If you are an agent or an employee reading this, the compliance question worth asking your organisation is what happens to the data you can see, not only what you are permitted to do with a customer's face-to-face interaction.

The one-sentence version

Assume a caller may know your real details, so the only check that carries weight is one where you supply the number yourself, and treat the fact that a stranger knew them as information about the industry rather than as evidence about the caller's honesty.