SIM Swap Fraud
What is SIM Swap Fraud?
SIM swap fraud is an account-takeover attack in which a criminal transfers a victim’s phone number to a SIM card they control, intercepting calls and SMS — including one-time passwords.
In a SIM swap attack, the criminal convinces a mobile carrier — through social engineering, phishing, or a paid insider — to port the victim’s number to a new SIM. From that moment, every SMS one-time password lands on the attacker’s device, enabling password resets and fraudulent transfers before the victim notices their phone has lost service. The UK’s Cifas recorded a 1,055% surge in unauthorised SIM swaps in 2024, and the FBI’s IC3 has logged tens of millions of dollars in annual losses. For businesses, the practical defenses are to move high-risk verifications off the SMS channel (for example, to voice OTP, where the code exists only in a live call) and to screen numbers for recent SIM or porting changes before sending any code. Example: a trading platform blocks withdrawal codes to numbers whose SIM changed in the last 72 hours.
For more on this, see BSG's OTP SMS vs. Flash Calls: Multi-Factor Authentication Solutions Compared.
Related terms
Related BSG products