BSG utilizes HTTP cookies (and similar or complementary technologies) to 1) make this website safe, functional, and accessible (through the use of mandatory cookies) and 2) understand how you use our website (through the use of optional cookies) in order to improve your experience and to provide you with personalized content.
The information in the cookie text files may be related to your personal preferences or your device and is intended to make the site operate according to your expectations. The information contained in cookies does not usually identify your identity directly but is helpful in providing you with a more personalized user experience.
In accordance with the requirements of the General Data Protection Regulation (GDPR) privacy and security law that governs how the personal data of individuals in the EU may be processed and transferred, we provide you the possibility to prohibit the use of certain types of cookies when you use our website.
Read our Cookie Notice and the Privacy Policy for detailed information on how BGS collects and uses cookies. Please note that prohibiting the use of certain types of cookies may affect your interaction with the website and limit the accessibility of services we offer you. Choose the appropriate category below to learn more and to disable cookies.
SIM swap fraud is an account-takeover attack in which a criminal transfers a victim’s phone number to a SIM card they control, intercepting calls and SMS — including one-time passwords.
In a SIM swap attack, the criminal convinces a mobile carrier — through social engineering, phishing, or a paid insider — to port the victim’s number to a new SIM. From that moment, every SMS one-time password lands on the attacker’s device, enabling password resets and fraudulent transfers before the victim notices their phone has lost service. The UK’s Cifas recorded a 1,055% surge in unauthorised SIM swaps in 2024, and the FBI’s IC3 has logged tens of millions of dollars in annual losses. For businesses, the practical defenses are to move high-risk verifications off the SMS channel (for example, to voice OTP, where the code exists only in a live call) and to screen numbers for recent SIM or porting changes before sending any code. Example: a trading platform blocks withdrawal codes to numbers whose SIM changed in the last 72 hours.
Bulk SMS alone leaks budget. Verify the list, then run WhatsApp-first with SMS fallback.
SIM swaps jumped 1,055% in a year. Voice OTP takes your riskiest codes off the SMS rail.
Telegram OTP is free — until it silently fails. Know the limits and when to add fallback.