A SIM swap is the takeover of a victim's phone number by persuading their mobile carrier to move it to an attacker-controlled SIM. Because phone numbers receive password resets and one-time codes, a successful swap unlocks email, banking and cryptocurrency accounts. US complaints and losses have both fallen sharply since 2022 as carriers hardened the process.
Key facts
Category
Identity theft
First documented
2015
Typical loss
$5k–$500k USD, per victim
Main channels
mobile carrier retail store, carrier phone support, insider at a carrier, phishing for personal details
Who is targeted
People known to hold cryptocurrency, identified from social media or breach data; Holders of desirable short social media handles, targeted for the account rather than money; Executives and public figures whose contact details are findable; Anyone whose personal details appear in a breach — the attack needs identity data, not wealth
Documented origins
United States, United Kingdom, Canada, Nigeria
Main targets
United States, United Kingdom, Canada, Australia, Ireland, Singapore
Case files
4 documented cases
Last reviewed
2026-09-06
The stages of the scheme, in order, with the point where it can still be stopped.
What it is
A SIM swap is the theft of a phone number.
Not the handset, not the SIM card in your pocket — the number itself. Someone contacts your mobile
carrier, claims to be you, says the handset was lost or the SIM was damaged, and asks for the number
to be moved to a new SIM. If the carrier agrees, your phone stops working and theirs starts receiving
your calls and texts.
That matters because of what a phone number has quietly become. It is the reset mechanism for email.
Email is the reset mechanism for everything else. And any account still using text-message
verification now sends its codes to a stranger.
The Justice Department describes it plainly: fraudulently inducing a carrier “to reassign a cellular
phone number from a victim’s SIM card to a SIM card controlled by the criminal actor, in order to
access a victim’s social media or virtual currency accounts.”
There is genuinely good news here, which is rare on this site. US complaints fell from 2,026 in 2022
to 971 in 2025, and reported losses fell 76%, from $72.7 million to $17.4 million. Carriers
hardened the process and platforms moved off SMS. But the average loss per complaint is still about
$17,900, among the highest of any category the FBI tracks.
How it actually works
Your details are assembled
Name, address, date of birth, account number, the last four digits of a card. Bought from breach
data, scraped from public records, or phished directly. Wealth is not the selection criterion —
identifiable data is.
An identity is manufactured
Sometimes just a confident phone call. In the prosecuted US case below, an actual identification
card printer was used to produce a physical fake from the victim’s stolen details.
The carrier is persuaded
In store or on a support line. A lost handset, a damaged SIM, an upgrade, a switch to a new
provider. Insider assistance at carriers has also featured in prosecutions. The number moves.
Your phone goes dead
Service stops. This is the only warning the attack gives, and most people assume it is a network
fault and wait for it to come back.
Where it could have stopped
Sudden, unexplained loss of mobile service is the one signal this attack produces, and it arrives before the account takeovers do. Treat it as an emergency: call your carrier from another phone immediately and ask whether your number has been transferred. The window between the swap and the first drained account is often less than an hour.
Resets cascade
Email first, because it controls everything else. Then banking, exchanges, social accounts,
cloud storage. Codes and reset links now arrive on the attacker’s device.
Accounts are emptied, irreversible first
Cryptocurrency exchanges are the priority, because a withdrawal cannot be undone. Bank transfers
and card spending follow. Social accounts are sometimes the objective in their own right.
Why it works
The attack does not happen on your device. No amount of care with your own passwords, patches or
downloads prevents it. It happens to a retail employee or a support agent who has never met you, and
their incentive is to be helpful to a customer who seems locked out.
Phone numbers were never designed for this. They became the universal identity anchor by accident,
because they were the thing everyone already had. Nothing about the number-porting system was built
with account security in mind.
The one warning arrives disguised as an ordinary annoyance. Losing signal is a thing that happens.
By the time it looks suspicious, the cascade has usually finished.
The cascade order is chosen well. Email is taken first, which means the notification emails about
every subsequent takeover arrive in a mailbox the attacker controls.
And the target list is public. People who post about cryptocurrency, hold short handles, or appear
in breach dumps alongside a phone number are identifiable without any special access.
Where it comes from
Unlike most schemes on this site, SIM swapping is substantially domestic wherever it happens. The
attacker has to interact with a carrier in the victim’s own country — in a store, on a support line,
or through an insider — which is why prosecutions reach actual defendants far more often here than in
compound-based fraud.
The US case record includes loose networks of young men coordinating on messaging platforms, splitting
roles between the person who compiles identity data, the person who performs the swap, and the person
who empties the accounts. The Alabama case below fits that shape exactly: Council performed the swap
and was paid in bitcoin by co-conspirators who did the rest.
Carrier insiders have featured in several prosecutions, which is part of why the mitigations that work
are ones the carrier cannot override casually — a port-out PIN is checked by a system rather than by a
person’s judgement.
The most significant recent development is displacement rather than defeat. The FBI’s August 2026
advisory describes actors asking victims directly to forward a verification code, achieving the same
account takeover without touching a carrier at all. Harden one route and the cheaper one gets used.
In September 2026 the FBI warned about OAuth consent phishing — a technique that obtains lasting access to an account without ever taking a password. The victim is sent a link that asks them to approve an application, and the resulting token cannot be cancelled by changing the password. Since late 2025 the FBI has observed actors impersonating government officials, media figures and event organisers on messaging apps to deliver these requests.
In August 2026 the FBI warned that sexual exploitation actors are illegally accessing victims' social media and personal accounts to steal explicit content and sell it on criminal marketplaces — often without the victim ever knowing. The intrusion methods are ordinary account-takeover techniques, including one that turns on persuading the victim to hand over a verification code.
In May 2025 an Alabama man was sentenced to 14 months in prison for his part in taking over the US Securities and Exchange Commission's account on X. He obtained control by performing a SIM swap: using a printer to make a fraudulent identification card from a victim's stolen personal details, impersonating that person at a mobile carrier, and taking over their phone number. Co-conspirators then posted a false announcement in the SEC chairman's name that moved the price of bitcoin by more than $1,000 within minutes.
US SIM swap complaints fell from 2,026 in 2022 to 971 in 2025, and reported losses fell from $72.7 million to $17.4 million over the same period — a 76% drop. It is one of the few categories in FBI data where both measures moved down together, and the likeliest explanation is that carriers and platforms changed how the attack works rather than that criminals lost interest.
Your phone loses service for no reason and does not recover. This is the warning.
Unexpected texts about a SIM change, a port request or a new device on your account.
Password reset emails you did not request, particularly for your email account.
Being locked out of email or an exchange with no explanation.
A call claiming to be your carrier asking to verify details or read out a code.
A text saying an account will be disabled unless you reply with a verification code. That is the codeless version of the same attack.
Notification of a new login from an unfamiliar location.
Someone asking about your crypto holdings in a public or semi-public setting.
If it’s happening to you
If your phone has just lost service. Assume the worst and act in this order, from another phone.
Call your carrier and ask whether your number has been ported or moved to a new SIM. Say the
words “SIM swap” — most carriers have a dedicated process.
Get the number restored and locked, and set a port-out PIN before you hang up.
Secure email first, from a device that is not the affected phone: change the password, revoke
active sessions, remove any unfamiliar recovery phone or address, and check for forwarding rules
the attacker may have added.
Then exchanges and banking, in that order, because crypto withdrawals are the irreversible ones.
Call your bank and any exchange you use, and tell them your number was compromised.
Report it. See where to report. In the US, IC3 is the route that can
trigger a fast freeze on a wire.
Check what else used that number — cloud storage, social accounts, work systems, password
managers.
Preventing it. Three measures, in order of value:
Set a port-out PIN or number lock with your carrier. This is the one that actually stops the
attack, and it works even against an attacker with perfect identity data and a convincing fake ID.
Move two-factor authentication off SMS. An authenticator app is better; a hardware security key is
better still and cannot be phished at all. Prioritise email and any cryptocurrency exchange.
Remove your phone number as a recovery method where the account offers an alternative, and take an
account inventory of what a stolen number would currently unlock.
And never forward a verification code, to anyone, for any reason — including someone claiming to
be a platform’s support team saying your account will be disabled.
Where the money goes
Cryptocurrency first, always, because it is the only asset that cannot be pulled back. Exchange
balances are withdrawn to wallets the attacker controls within minutes of the takeover, then split and
moved through the same laundering chain as other crypto proceeds: hopped between chains, mixed, and
converted through over-the-counter brokers.
Bank funds move second and more cautiously, because they can be recalled. Card spending and account
takeover for resale — particularly of short social media handles, which have their own market — round
it out.
The speed is the defining operational fact. From swap to emptied exchange account is often under an
hour, which is why the response to losing mobile signal has to be immediate rather than considered.
No agency publishes a line item for most of the schemes on this site, so these charts show the
official categories that contain this scheme. Each series is labelled with the agency's
own category name. See how the mapping works.
2025 Internet Crime Report.
FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: 971 SIM swap complaints and $17,366,758 in losses in 2025, plus the 2023 and 2024 comparison.
2024 Internet Crime Report.
FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: 2,026 SIM swap complaints and $72,652,571 in losses in 2022.
Your phone loses signal and does not get it back. That is usually the only warning, and it arrives before the account takeovers do. Treat sudden unexplained loss of service as urgent rather than as a network fault — call your carrier from another phone immediately.
Does two-factor authentication protect me?
Only if it is not tied to your phone number. SMS-based codes are exactly what a SIM swap steals. An authenticator app or a hardware security key stays on your device and is not affected by a number being moved, which is why moving off SMS is the single most effective step available.
What is a port-out PIN and should I have one?
It is a separate code your carrier requires before transferring your number, sometimes called a number lock or transfer PIN. Yes — set one. It costs nothing and it defeats the attack even when the attacker has all your personal details and a convincing fake ID.
How do they get past the carrier's checks?
By impersonating you with information bought from breaches, and sometimes with a forged identity document. In one prosecuted US case the defendant used an ID card printer to manufacture a physical fake from a victim's stolen details. Insider assistance at carriers has also featured in prosecutions.
Why is cryptocurrency taken first?
Because it cannot be reversed. Bank transfers can sometimes be recalled and card payments charged back; a withdrawal from an exchange to an attacker's wallet is final. Attackers work the irreversible accounts first, which is why exchange accounts should be the ones with hardware-key protection.
Is it getting better or worse?
Better, on both measures. US complaints halved and losses fell 76% between 2022 and 2025, after carriers hardened the port-out process and regulators required authentication. The average loss per complaint is still around $17,900, so it remains a serious low-volume crime.
Where the money goes after it leaves, and where it becomes hard to recover.
Reporting is what produces the enforcement data on this page. Find the right agency and phone
number for your country on the report page. If money moved in the last
few hours, call your bank first.