Skip to main content

SIM Swap Fraud: How Criminals Hijack Your Phone Number to Steal Money

ByUpdated September 4, 2026
Reviewed by
Fact checked by
SIM Swap Fraud: How Criminals Hijack Your Phone Number to Steal Money

Your phone loses signal in the middle of the afternoon. No bars, no calls, no text messages. You assume it is a dead zone or a network outage and keep working. An hour later you try to log into your email and the password no longer works. By the time you reach a customer service line, your bank account, your cryptocurrency wallet, or both have already been emptied, and the security alerts that should have warned you along the way never arrived, because they were sent to a device you have never seen.

That sequence has a name: SIM swap fraud. It is not a hack in the movie sense of someone breaking encryption or planting malware. It is a con run against a person at a phone company, or a corrupt employee paid to look the other way, and it works because so much of modern account security still runs through a single phone number. Once a criminal controls that number, the codes meant to prove your identity get delivered straight to them instead. This piece walks through how the swap actually happens, why it defeats the most common form of two-factor authentication, what it has cost real, named victims, and the specific steps that make a phone number harder to steal.

KEY TAKEAWAYS

  • A SIM swap moves your phone number onto a SIM card a criminal controls, either by fooling a carrier employee with a fake ID or by bribing one to skip verification, according to the FBI and federal court records.
  • It defeats SMS-based two-factor authentication because the one-time codes get delivered to the criminal's device instead of yours; NIST classifies telephone-network delivery of codes as a RESTRICTED authenticator for exactly this reason.
  • The FBI's IC3 recorded 971 SIM-swap complaints and $17,366,758 in reported losses in 2025, down from 1,075 complaints and $48,798,103 in 2023, though the agency's own crime-coding rules mean the real toll is likely undercounted.
  • In the most litigated U.S. case, a teenager bribed an AT&T retail employee to swap Michael Terpin's number and stole $24 million in cryptocurrency; a federal appeals court revived Terpin's lawsuit against AT&T itself in September 2024.
  • A SIM swap even briefly moved the price of Bitcoin by more than $1,000 after hijacking the SEC's own X account in January 2024, according to the Department of Justice.
  • FCC rules that took effect in 2024 require carriers to verify identity before any SIM change, notify customers immediately, and offer a free port-freeze lock to every customer, prepaid or postpaid.
  • Authenticator apps and hardware security keys are not vulnerable to a SIM swap because they do not rely on your phone number at all, unlike SMS codes, according to the FTC and CISA.

What Happens During a SIM Swap

Every phone number is tied to a small chip called a SIM card, which tells the network which device should receive that number's calls, texts, and data. A SIM swap, also called a SIM hijack or port-out fraud, happens when a criminal convinces your carrier to move your number onto a SIM card the criminal controls, instead of the one in your own phone.

The Federal Trade Commission describes the mechanics in plain terms: scammers "call your cell phone service provider and say your phone was lost or damaged. Then they ask the provider to activate a new SIM card connected to your phone number on a new phone – a phone they own." If the representative is fooled, or paid to look the other way, the swap can go through in minutes.

Your phone goes silent.

The criminal's phone lights up with your calls, your texts, and every one-time passcode your bank, email provider, or exchange sends to "your" number. Criminals typically build a profile of a target's name, address, and account details from breached databases and web-tracking data before ever calling a carrier, the same kind of profile that tracking cookies and browsing data can help assemble without a single data breach involved.

Two warning signs the FTC tells consumers to watch for: your phone "suddenly stops working: no data, no text messages, no phone calls," or you receive an unexpected notification from your carrier that a new SIM card or device has been activated on your line. Either one is worth calling your carrier about immediately, from a different phone.

The FBI's Own Definition of the Crime

IC3 — the FBI's clearinghouse for public fraud reports, formally the Internet Crime Complaint Center — defines the crime type this way in its 2025 Internet Crime Report: "SIM Swap: The use of unsophisticated social engineering techniques against mobile service providers to transfer a victim's phone service to a mobile device in the criminal's possession." The FBI is describing a conversation, not a technical exploit.

No malware, no cracked password, and no software vulnerability is required.

The entire attack is aimed at one employee who has the power to move a phone number, whether that employee is fooled or paid.

How Criminals Actually Get the Swap Done

Two methods show up again and again in prosecuted cases: impersonating the victim well enough to fool a legitimate employee, and simply paying an employee to skip the verification step altogether. Both are documented in U.S. federal court records, not speculation.

Impersonation at the Carrier Counter

In January 2024, the U.S. Securities and Exchange Commission's own account on X, formerly Twitter, was hijacked and used to falsely announce that the agency had approved spot Bitcoin exchange-traded funds, a decision the market had been waiting on for months. According to the Department of Justice, the man behind it, Eric Council Jr., then 26, of Huntsville, Alabama, "used an identification card printer to create a fraudulent identification card with a victim's personally identifiable information obtained from co-conspirators," then used that fake ID to convince a retail store employee to activate a new SIM in the victim's name. The stolen phone number gave the conspirators the password-reset code they needed to take over the SEC's account. Forging a convincing ID this way relies on the same design tools behind other document-forgery scams, including criminals who fake bank statements and proof-of-funds letters to pass a different institution's review.

The fallout reached financial markets within minutes. Per the DOJ's account, "immediately following the false announcement, the price of BTC increased by more than $1,000 per BTC. Following the correction, the value of BTC decreased by more than $2,000 per BTC." Council pleaded guilty to conspiracy to commit aggravated identity theft and access device fraud and was sentenced on May 16, 2025, to 14 months in prison and three years of supervised release. Then-U.S. Attorney Jeanine Pirro did not mince words: "SIM swap schemes threaten the financial security of average citizens, financial institutions, and government agencies. Don't fool yourself into thinking you can't be caught."

Paying Off an Employee From the Inside

The other method skips impersonation altogether. In 2018, cryptocurrency investor Michael Terpin was targeted in a SIM swap that became one of the most closely litigated cases in the field. According to the U.S. Court of Appeals for the Ninth Circuit's published opinion in Terpin's later lawsuit against AT&T, the person responsible was a teenager, Ellis Pinsky, who "bribed an employee at an AT&T authorized retailer, Jahmil Smith, to bypass AT&T's security measures and 'swap' Terpin's phone number to a SIM Pinsky and his associate controlled." Pinsky then requested password-reset messages on Terpin's email accounts, found cryptocurrency credentials in a discarded file on Terpin's cloud storage, and, per the court's opinion, stole $24 million.

Terpin sued Pinsky and Pinsky's associate, Nicholas Truglia, separately from his case against the carrier itself. Per the same appellate opinion, he obtained a $22 million judgment against Pinsky and a $75 million judgment against Truglia, who was also prosecuted criminally. Truglia pleaded guilty in December 2021 to conspiracy to commit wire fraud for laundering the stolen funds through his own cryptocurrency exchange account, according to Krebs on Security's coverage of the plea. A civil jury had separately awarded Terpin a $75.8 million verdict against Truglia back in May 2019. Terpin's own reaction, quoted in that same reporting: "the intentional theft of $24 million, whether taken at the point of a gun in a bank or through a SIM card swap, is a major felony."

Why It Defeats SMS-Based Two-Factor Authentication

Two-factor authentication is supposed to stop a criminal who already has your password from getting into your account, by requiring a second proof of identity, usually a one-time code. The most common version of that code, delivered by text message, assumes the phone receiving the text is still yours. A SIM swap breaks that assumption completely. The FTC states it plainly: "Hackers can take over your phone number through a SIM card swap attack and get text messages sent to your number, including those with a verification code."

The FTC ranks the common options by strength. Text or email codes are the weakest, because both channels can be hijacked. Authenticator apps are better: "using an app is safer because the passcode isn't susceptible to a SIM card swap attack or to someone hacking your email." Physical security keys rank highest of all, described by the agency as "the strongest method of two-factor authentication because they don't use credentials that hackers can steal."

MethodVulnerable to a SIM swap?What the guidance says
SMS or voice call codeYes, directly. The code goes wherever your phone number currently points.NIST classifies telephone-network delivery as a RESTRICTED authenticator; the FTC calls it the weakest of the three options.
Authenticator app (Google Authenticator, Microsoft Authenticator, Duo, and similar)No. Codes generate on the device itself, independent of your phone number.FTC: safer "because the passcode isn't susceptible to a SIM card swap attack."
Hardware security key or passkey (FIDO2/WebAuthn)No. Cannot be phished or intercepted remotely.CISA names FIDO2/WebAuthn as the only widely available phishing-resistant method; the FTC calls keys the strongest option.

What NIST Actually Requires of Verifiers

This is not just consumer advice. It is the federal government's own technical standard. The National Institute of Standards and Technology's Digital Identity Guidelines state that use of the telephone network for out-of-band verification "is RESTRICTED," and instruct any organization still using it to "consider risk indicators such as device swap, SIM change, number porting, or other abnormal behavior before using the PSTN to deliver an out-of-band authentication secret." The agency that sets federal cybersecurity standards has already concluded that SMS codes need a documented workaround, specifically because of the risk this article covers. The Cybersecurity and Infrastructure Security Agency goes further in its own fact sheet on phishing-resistant multifactor authentication, naming FIDO2 and WebAuthn-based hardware keys and passkeys as the only widely available method that resists phishing entirely, a bar that push notifications and app-based codes do not fully clear, even though both sit well above SMS.

The Scale of the Problem, in the FBI's Own Numbers

IC3 has tracked SIM swap fraud as its own reportable category since 2021. Its 2025 Internet Crime Report puts total complaints across every fraud type at 1,008,597, with $20.877 billion in reported losses for the year, a 26 percent increase over 2024. Against that backdrop, the report's three-year comparison table for SIM swap specifically looks like this:

YearSIM swap complaints reported to IC3Reported losses
20231,075$48,798,103
2024982$25,983,946
2025971$17,366,758

Read on its own, that looks like a crime in decline. It probably is not.

IC3 lets each complainant select only one primary crime type. Once a stolen phone number is used to drain a bank account or a crypto wallet, many victims and investigators code that loss under "Identity Theft," "Investment," or "Cryptocurrency" instead of "SIM Swap," because that is where the money actually went. IC3's own cryptocurrency-nexus table lists 121 SIM-swap complaints tied to crypto losses of $4,405,259 in 2025, a real figure that sits beside the category totals rather than folded into them. The falling SIM-swap-labeled total almost certainly understates how often a hijacked phone number is the opening move in a larger, differently categorized theft.

Older adults carry a disproportionate share of what does get reported under the SIM-swap label. IC3's elder-fraud tables show victims age 60 and older filed 222 SIM-swap complaints in 2025, with $6,741,791 in losses, up slightly from 205 complaints and $6,342,329 in 2024, though both years remain below the $15,148,072 lost by that age group in 2023.

The Money: What SIM Swap Fraud Has Cost Named Victims

The Terpin case above is not an outlier in scale, and it was not even the first SIM-swap conviction in the United States. Cryptocurrency shows up in nearly every large SIM-swap case for a practical reason: transfers cannot be reversed once confirmed, the same finality that makes crypto the preferred payout in a pig-butchering scam that runs for months rather than minutes.

The First Conviction: Forty Victims, One College-Age Hacker

That distinction belongs to Joel Ortiz, prosecuted in Santa Clara County, California, while still college-age. He pleaded guilty and was sentenced on March 14, 2019, to 10 years in prison, reported at the time as the first SIM-swapping conviction in the country. According to Vice/Motherboard's coverage, Ortiz hijacked roughly 40 victims' phone numbers and stole more than $5 million in cryptocurrency. Deputy District Attorney Erin West said the sentence sent a message: "in looking at Joel's sentence, 10 years, it shows that our community will not tolerate this type of crime." Investigator Samy Tarazi put it more simply: "we think justice has been served."

When the Target Is an Institution, Not a Person

Most SIM swap victims are individuals. The Eric Council case above shows what happens when the same technique is pointed at an institution instead: a few minutes of stolen phone access moved the price of Bitcoin by thousands of dollars in each direction before the SEC could issue a correction.

No single person's account was drained.

The damage was to market trust, and it still carried a federal prison sentence.

Carrier Defenses: Port Freezes, PIN Locks, and What the FCC Now Requires

Because both documented methods above exploit weaknesses at the carrier, not on the victim's own device, federal regulators eventually stepped in on the carrier side. The Federal Communications Commission adopted new rules in November 2023, commonly cited by their docket number, FCC 23-95, that took effect the following year. Per a summary of the order from the law firm Davis Wright Tremaine, the rule requires wireless carriers to use authentication that is reasonably designed to confirm a customer's identity before any SIM change or number port, and bars carriers from relying solely on easily obtained information such as a name, address, or the last few digits of a Social Security number. Carriers must also notify the customer immediately, in clear language, before completing any SIM swap or port-out, and must offer every customer, prepaid or postpaid, a free account-lock feature built specifically to block unauthorized porting.

The rule also targets the insider-bribery method directly: carriers are required to restrict employee access to customer account data until a customer has been authenticated, and to keep authentication logs for at least three years, the kind of access control that, had it been airtight at that AT&T retail location in 2018, would have made Ellis Pinsky's bribe useless.

Setting a Port-Freeze PIN, Carrier by Carrier

Consumers do not have to wait on a carrier to enforce the rule on its own. All three major U.S. carriers already offer a free, self-service lock:

CarrierFeatureWhere to set it
AT&TWireless Account LockmyAT&T app or att.com, under Profile then Sign-in Info, to set an Account Passcode required for any transfer
T-MobileAccount PINA 6 to 15 digit PIN set in the PIN/Passcode section of the T-Mobile account, required before any port-out is processed
VerizonNumber Transfer PINMy Verizon app or verizon.com, under Profile and Settings, then Security, as a separate PIN from the general account password

Beyond the Carrier: Locking Down the Accounts a Stolen Number Can Reach

A port freeze at your carrier is the first layer, not the only one. The next question is what a criminal could still do with your phone number if a swap somehow got through anyway. For most people the honest answer is: reset the email password, then use email to reset everything else. That makes your primary email account the single point of failure worth protecting hardest.

Two changes matter most: move two-factor authentication for your email and any financial or exchange account off SMS and onto an authenticator app or hardware security key, per the FTC, NIST, and CISA guidance above, and set a recovery method for your email that does not depend on your phone number at all, such as a backup email address or a printed set of recovery codes stored offline. Also review which accounts still list your phone number as the "forgot password" option.

Each one is a door a stolen number can open.

A practical order of operations: set a carrier PIN or port-freeze today, switch your email and bank two-factor authentication to an authenticator app this week, and add a hardware security key to your email and any cryptocurrency exchange account if you hold meaningful value there. Start with the email account. Once a criminal controls your inbox, resetting every other password becomes trivial no matter how the initial access happened.

The same pattern shows up outside the United States. In the United Kingdom, the fraud-prevention service Cifas reported a 1,055% surge in unauthorized SIM swaps logged to the UK's National Fraud Database in 2024, nearly 3,000 cases, up from 289 in 2023. Cifas policy director Simon Miller described the pattern bluntly: "criminals are exploiting vulnerabilities in the system to assume control of people's mobile identities, with devastating consequences." Whatever the country, the underlying weakness is identical: a phone number that was never designed to double as a password.

The Bottom Line

SIM swap fraud does not require a criminal to break any encryption or write a single line of malicious code. It requires convincing, or paying, one person at a phone company to move your number onto a SIM they control, and from there it defeats the exact security measure, a text-message code, that most people still treat as sufficient. The FBI's own numbers show reported cases falling, but the agency's own accounting rules mean a hijacked number that leads to an identity-theft or cryptocurrency loss often gets counted somewhere else, which makes the true toll larger than the SIM-swap line item alone suggests. The fixes that matter are specific and available today: a port-freeze PIN at your carrier, two-factor authentication moved off SMS and onto an authenticator app or hardware security key, and a recovery plan for your most important accounts that does not run through your phone number at all. None of it is complicated, and most of it takes less time than the fraud itself.

Key Terms Used in This Guide

Pig Butchering

A long-con scam that combines a fabricated romantic or friendly relationship with a fake investment platform, gradually escalating deposits over weeks or months before the scammer disappears with the funds.

Learn more

Business Email Compromise (BEC)

A scam in which a criminal gains access to, or convincingly spoofs, a real business email account to redirect a legitimate payment or invoice to a fraudulent account.

Learn more

SIM Swap

A fraud technique where a criminal convinces or bribes a mobile carrier employee to transfer a victim's phone number onto a SIM card the criminal controls, intercepting SMS-based verification codes.

Learn more

Was this article helpful?

Comments

Get weekly Scams & Fraud Protection tips

No spam — one email a week, unsubscribe anytime.