Your phone loses signal in the middle of the afternoon. No bars, no calls, no text messages. You assume it is a dead zone or a network outage and keep working. An hour later you try to log into your email and the password no longer works. By the time you reach a customer service line, your bank account, your cryptocurrency wallet, or both have already been emptied, and the security alerts that should have warned you along the way never arrived, because they were sent to a device you have never seen.
That sequence has a name: SIM swap fraud. It is not a hack in the movie sense of someone breaking encryption or planting malware. It is a con run against a person at a phone company, or a corrupt employee paid to look the other way, and it works because so much of modern account security still runs through a single phone number. Once a criminal controls that number, the codes meant to prove your identity get delivered straight to them instead. This piece walks through how the swap actually happens, why it defeats the most common form of two-factor authentication, what it has cost real, named victims, and the specific steps that make a phone number harder to steal.
What Happens During a SIM Swap
Every phone number is tied to a small chip called a SIM card, which tells the network which device should receive that number's calls, texts, and data. A SIM swap, also called a SIM hijack or port-out fraud, happens when a criminal convinces your carrier to move your number onto a SIM card the criminal controls, instead of the one in your own phone.
The Federal Trade Commission describes the mechanics in plain terms: scammers "call your cell phone service provider and say your phone was lost or damaged. Then they ask the provider to activate a new SIM card connected to your phone number on a new phone – a phone they own." If the representative is fooled, or paid to look the other way, the swap can go through in minutes.
Your phone goes silent.
The criminal's phone lights up with your calls, your texts, and every one-time passcode your bank, email provider, or exchange sends to "your" number. Criminals typically build a profile of a target's name, address, and account details from breached databases and web-tracking data before ever calling a carrier, the same kind of profile that tracking cookies and browsing data can help assemble without a single data breach involved.
Two warning signs the FTC tells consumers to watch for: your phone "suddenly stops working: no data, no text messages, no phone calls," or you receive an unexpected notification from your carrier that a new SIM card or device has been activated on your line. Either one is worth calling your carrier about immediately, from a different phone.
The FBI's Own Definition of the Crime
IC3 — the FBI's clearinghouse for public fraud reports, formally the Internet Crime Complaint Center — defines the crime type this way in its 2025 Internet Crime Report: "SIM Swap: The use of unsophisticated social engineering techniques against mobile service providers to transfer a victim's phone service to a mobile device in the criminal's possession." The FBI is describing a conversation, not a technical exploit.
No malware, no cracked password, and no software vulnerability is required.
The entire attack is aimed at one employee who has the power to move a phone number, whether that employee is fooled or paid.
How Criminals Actually Get the Swap Done
Two methods show up again and again in prosecuted cases: impersonating the victim well enough to fool a legitimate employee, and simply paying an employee to skip the verification step altogether. Both are documented in U.S. federal court records, not speculation.
Impersonation at the Carrier Counter
In January 2024, the U.S. Securities and Exchange Commission's own account on X, formerly Twitter, was hijacked and used to falsely announce that the agency had approved spot Bitcoin exchange-traded funds, a decision the market had been waiting on for months. According to the Department of Justice, the man behind it, Eric Council Jr., then 26, of Huntsville, Alabama, "used an identification card printer to create a fraudulent identification card with a victim's personally identifiable information obtained from co-conspirators," then used that fake ID to convince a retail store employee to activate a new SIM in the victim's name. The stolen phone number gave the conspirators the password-reset code they needed to take over the SEC's account. Forging a convincing ID this way relies on the same design tools behind other document-forgery scams, including criminals who fake bank statements and proof-of-funds letters to pass a different institution's review.
The fallout reached financial markets within minutes. Per the DOJ's account, "immediately following the false announcement, the price of BTC increased by more than $1,000 per BTC. Following the correction, the value of BTC decreased by more than $2,000 per BTC." Council pleaded guilty to conspiracy to commit aggravated identity theft and access device fraud and was sentenced on May 16, 2025, to 14 months in prison and three years of supervised release. Then-U.S. Attorney Jeanine Pirro did not mince words: "SIM swap schemes threaten the financial security of average citizens, financial institutions, and government agencies. Don't fool yourself into thinking you can't be caught."
Paying Off an Employee From the Inside
The other method skips impersonation altogether. In 2018, cryptocurrency investor Michael Terpin was targeted in a SIM swap that became one of the most closely litigated cases in the field. According to the U.S. Court of Appeals for the Ninth Circuit's published opinion in Terpin's later lawsuit against AT&T, the person responsible was a teenager, Ellis Pinsky, who "bribed an employee at an AT&T authorized retailer, Jahmil Smith, to bypass AT&T's security measures and 'swap' Terpin's phone number to a SIM Pinsky and his associate controlled." Pinsky then requested password-reset messages on Terpin's email accounts, found cryptocurrency credentials in a discarded file on Terpin's cloud storage, and, per the court's opinion, stole $24 million.
Terpin sued Pinsky and Pinsky's associate, Nicholas Truglia, separately from his case against the carrier itself. Per the same appellate opinion, he obtained a $22 million judgment against Pinsky and a $75 million judgment against Truglia, who was also prosecuted criminally. Truglia pleaded guilty in December 2021 to conspiracy to commit wire fraud for laundering the stolen funds through his own cryptocurrency exchange account, according to Krebs on Security's coverage of the plea. A civil jury had separately awarded Terpin a $75.8 million verdict against Truglia back in May 2019. Terpin's own reaction, quoted in that same reporting: "the intentional theft of $24 million, whether taken at the point of a gun in a bank or through a SIM card swap, is a major felony."
Why It Defeats SMS-Based Two-Factor Authentication
Two-factor authentication is supposed to stop a criminal who already has your password from getting into your account, by requiring a second proof of identity, usually a one-time code. The most common version of that code, delivered by text message, assumes the phone receiving the text is still yours. A SIM swap breaks that assumption completely. The FTC states it plainly: "Hackers can take over your phone number through a SIM card swap attack and get text messages sent to your number, including those with a verification code."
The FTC ranks the common options by strength. Text or email codes are the weakest, because both channels can be hijacked. Authenticator apps are better: "using an app is safer because the passcode isn't susceptible to a SIM card swap attack or to someone hacking your email." Physical security keys rank highest of all, described by the agency as "the strongest method of two-factor authentication because they don't use credentials that hackers can steal."
What NIST Actually Requires of Verifiers
This is not just consumer advice. It is the federal government's own technical standard. The National Institute of Standards and Technology's Digital Identity Guidelines state that use of the telephone network for out-of-band verification "is RESTRICTED," and instruct any organization still using it to "consider risk indicators such as device swap, SIM change, number porting, or other abnormal behavior before using the PSTN to deliver an out-of-band authentication secret." The agency that sets federal cybersecurity standards has already concluded that SMS codes need a documented workaround, specifically because of the risk this article covers. The Cybersecurity and Infrastructure Security Agency goes further in its own fact sheet on phishing-resistant multifactor authentication, naming FIDO2 and WebAuthn-based hardware keys and passkeys as the only widely available method that resists phishing entirely, a bar that push notifications and app-based codes do not fully clear, even though both sit well above SMS.
The Scale of the Problem, in the FBI's Own Numbers
IC3 has tracked SIM swap fraud as its own reportable category since 2021. Its 2025 Internet Crime Report puts total complaints across every fraud type at 1,008,597, with $20.877 billion in reported losses for the year, a 26 percent increase over 2024. Against that backdrop, the report's three-year comparison table for SIM swap specifically looks like this:
Read on its own, that looks like a crime in decline. It probably is not.
IC3 lets each complainant select only one primary crime type. Once a stolen phone number is used to drain a bank account or a crypto wallet, many victims and investigators code that loss under "Identity Theft," "Investment," or "Cryptocurrency" instead of "SIM Swap," because that is where the money actually went. IC3's own cryptocurrency-nexus table lists 121 SIM-swap complaints tied to crypto losses of $4,405,259 in 2025, a real figure that sits beside the category totals rather than folded into them. The falling SIM-swap-labeled total almost certainly understates how often a hijacked phone number is the opening move in a larger, differently categorized theft.
Older adults carry a disproportionate share of what does get reported under the SIM-swap label. IC3's elder-fraud tables show victims age 60 and older filed 222 SIM-swap complaints in 2025, with $6,741,791 in losses, up slightly from 205 complaints and $6,342,329 in 2024, though both years remain below the $15,148,072 lost by that age group in 2023.
The Money: What SIM Swap Fraud Has Cost Named Victims
The Terpin case above is not an outlier in scale, and it was not even the first SIM-swap conviction in the United States. Cryptocurrency shows up in nearly every large SIM-swap case for a practical reason: transfers cannot be reversed once confirmed, the same finality that makes crypto the preferred payout in a pig-butchering scam that runs for months rather than minutes.
The First Conviction: Forty Victims, One College-Age Hacker
That distinction belongs to Joel Ortiz, prosecuted in Santa Clara County, California, while still college-age. He pleaded guilty and was sentenced on March 14, 2019, to 10 years in prison, reported at the time as the first SIM-swapping conviction in the country. According to Vice/Motherboard's coverage, Ortiz hijacked roughly 40 victims' phone numbers and stole more than $5 million in cryptocurrency. Deputy District Attorney Erin West said the sentence sent a message: "in looking at Joel's sentence, 10 years, it shows that our community will not tolerate this type of crime." Investigator Samy Tarazi put it more simply: "we think justice has been served."
When the Target Is an Institution, Not a Person
Most SIM swap victims are individuals. The Eric Council case above shows what happens when the same technique is pointed at an institution instead: a few minutes of stolen phone access moved the price of Bitcoin by thousands of dollars in each direction before the SEC could issue a correction.
No single person's account was drained.
The damage was to market trust, and it still carried a federal prison sentence.
Carrier Defenses: Port Freezes, PIN Locks, and What the FCC Now Requires
Because both documented methods above exploit weaknesses at the carrier, not on the victim's own device, federal regulators eventually stepped in on the carrier side. The Federal Communications Commission adopted new rules in November 2023, commonly cited by their docket number, FCC 23-95, that took effect the following year. Per a summary of the order from the law firm Davis Wright Tremaine, the rule requires wireless carriers to use authentication that is reasonably designed to confirm a customer's identity before any SIM change or number port, and bars carriers from relying solely on easily obtained information such as a name, address, or the last few digits of a Social Security number. Carriers must also notify the customer immediately, in clear language, before completing any SIM swap or port-out, and must offer every customer, prepaid or postpaid, a free account-lock feature built specifically to block unauthorized porting.
The rule also targets the insider-bribery method directly: carriers are required to restrict employee access to customer account data until a customer has been authenticated, and to keep authentication logs for at least three years, the kind of access control that, had it been airtight at that AT&T retail location in 2018, would have made Ellis Pinsky's bribe useless.
Setting a Port-Freeze PIN, Carrier by Carrier
Consumers do not have to wait on a carrier to enforce the rule on its own. All three major U.S. carriers already offer a free, self-service lock:
Beyond the Carrier: Locking Down the Accounts a Stolen Number Can Reach
A port freeze at your carrier is the first layer, not the only one. The next question is what a criminal could still do with your phone number if a swap somehow got through anyway. For most people the honest answer is: reset the email password, then use email to reset everything else. That makes your primary email account the single point of failure worth protecting hardest.
Two changes matter most: move two-factor authentication for your email and any financial or exchange account off SMS and onto an authenticator app or hardware security key, per the FTC, NIST, and CISA guidance above, and set a recovery method for your email that does not depend on your phone number at all, such as a backup email address or a printed set of recovery codes stored offline. Also review which accounts still list your phone number as the "forgot password" option.
Each one is a door a stolen number can open.
A practical order of operations: set a carrier PIN or port-freeze today, switch your email and bank two-factor authentication to an authenticator app this week, and add a hardware security key to your email and any cryptocurrency exchange account if you hold meaningful value there. Start with the email account. Once a criminal controls your inbox, resetting every other password becomes trivial no matter how the initial access happened.
The same pattern shows up outside the United States. In the United Kingdom, the fraud-prevention service Cifas reported a 1,055% surge in unauthorized SIM swaps logged to the UK's National Fraud Database in 2024, nearly 3,000 cases, up from 289 in 2023. Cifas policy director Simon Miller described the pattern bluntly: "criminals are exploiting vulnerabilities in the system to assume control of people's mobile identities, with devastating consequences." Whatever the country, the underlying weakness is identical: a phone number that was never designed to double as a password.
The Bottom Line
SIM swap fraud does not require a criminal to break any encryption or write a single line of malicious code. It requires convincing, or paying, one person at a phone company to move your number onto a SIM they control, and from there it defeats the exact security measure, a text-message code, that most people still treat as sufficient. The FBI's own numbers show reported cases falling, but the agency's own accounting rules mean a hijacked number that leads to an identity-theft or cryptocurrency loss often gets counted somewhere else, which makes the true toll larger than the SIM-swap line item alone suggests. The fixes that matter are specific and available today: a port-freeze PIN at your carrier, two-factor authentication moved off SMS and onto an authenticator app or hardware security key, and a recovery plan for your most important accounts that does not run through your phone number at all. None of it is complicated, and most of it takes less time than the fraud itself.