How to protect your customers from the growing threat of SIM swap fraud

by Paul McGuire | March 28, 2025
SIM Swap Fraud

SIM Swap fraud happens when an attacker convinces a mobile carrier to transfer a victim’s phone number to a SIM card controlled by the attacker — giving them access to every SMS OTP sent to that number. Preventing SIM Swap fraud requires detection at the network layer: a direct API query to the mobile operator that identifies whether a SIM card change has happened recently. This is typically performed before a high-risk or high-value transaction is allowed to proceed. SMS-based two-factor authentication has no defence against a successful SIM swap. SNA is also unable to detect or prevent SIM Swap fraud; a specific additional carrier-level API call is required.

 

SIM swap fraud on the rise

In the UK, reports of SIM swap fraud are now doubling year-on-year, according to Action Fraud. Now over a decade old, this type of fraud even affects those using eSIMs, since bad actors can convince mobile networks to switch a number from a physical SIM to an eSIM.

 

In the US, SIM swap fraudsters are increasingly targeting senior executives using sophisticated phishing techniques, with nearly $50 million in losses from 1,075 SIM-swapping attacks investigated by the FBI in 2023. The fraud has even prompted the Federal Communications Commission to consider reinforcing regulation to protect consumers and businesses in the US.

 

How does SIM Swap fraud work?

SIM swap fraud is a type of account takeover (ATO) attack where criminals take control of a victim’s phone number by tricking or bribing an MNO employee into transferring it to a new SIM. They typically gather personal details through phishing, social engineering, data breaches or a combination of these methods.

 

Once they control the number, they intercept calls and texts, with the real prize being able to receive vulnerable SMS one-time passwords (OTPs) used for two-factor authentication (2FA), invalidating the security layer that two-factor authentication codes provide. This allows them to reset passwords, gain access to bank accounts, cryptocurrency wallets, personal data, and even apply for loans. They also look to exploit fast payment systems like Apple/Android Pay and make point-of-sale (POS) transactions. The financial impact of SIM swapping can be significant, with losses ranging from hundreds to severe cases such as the alleged $24M crypto theft from 2018.

 

Phishing scams are the preferred method for fraudsters, where victims are tricked into entering sensitive personal information into fake websites that expertly resemble genuine sites such as those for insurance, government or car financing services. Fraudsters are using increasingly sophisticated techniques to mimic high-demand services on a regional basis, with some claiming a 100% success rate on victims.

 

Once they have gathered the necessary information from a victim, they request a swap to a new SIM with the MNO, often using an MNOs own mobile app. Victims are then tricked or manipulated to approve verification requests when the fraudsters impersonate officials or representatives. Once the victim unknowingly approves the request, the MNO disables the original SIM and activates a new one controlled by the fraudster.

 

Protect your customers with SIM-based authentication‍

‍For SIM swap fraud to work, the criminal must possess a SIM card with a victim’s mobile number mapped to it.

But each SIM card also has a unique identity number (called the International Mobile Subscriber Identity, or IMSI) – so the new SIM card issued to the criminal will have a different IMSI to the original.

With SIM-based authentication, it’s now possible to check for this difference and stop SIM swap fraudsters from gaining further access.

The technology to authenticate the identity of each SIM card is a core part of every mobile network – it’s how MNOs can bill their customers correctly. But only recently has it become available for identity management and fraud prevention.

 

SIM-based authentication can also provide strong foundations for mobile identity, because it leverages existing cryptographically secure, mobile network technology. It also means removing human-dependent security, replacing knowledge-based authentication with a possession factor and eliminating phishing and ATO risks. The benefits can cut fraud for your business, reduce operational costs and give your customers a better experience.

 

Further reading on our blog:

 

A day in the life of a SIM swap fraudster

Replace usernames with proof of possession to tackle rising SIM swap fraud

SIM swap fraud: what is it and how to fix it

 

Introducing IDlayr

IDlayr is reinventing online identity for the mobile era, helping banks and large enterprises to cut fraud, reduce operating costs and improve the user experience. IDlayr lets you use your mobile number, instead of email, to prove your identity online; because a mobile identity is more secure, easier to use, and always with you.

 

For more information, schedule a demo with our team and learn how we can help you move to a mobile identity based solution.‍

Paul McGuire - IDlayr

About the author: Paul McGuire

Paul McGuire is CEO of IDlayr. He has spent over two decades at the intersection of mobile, telecoms, and digital identity. He works directly with banks, payment platforms, and large consumer apps deploying Silent Network Authentication to replace SMS OTP, eliminating ATO and SIM Swap fraud risk. He has held senior leadership roles across mobile and technology businesses in the USA and internationally.

SIM Swap fraud is an account takeover attack where criminals convince a mobile carrier to transfer a victim’s phone number to a new SIM card they control. Once the transfer is complete, any SMS OTP sent to that number goes to the attacker, not the legitimate user, allowing them to bypass two-factor authentication and access accounts.

Attackers first gather personal information on the target through phishing, social engineering, or data breaches. They then contact the victim’s mobile carrier and use that information to impersonate the victim and request a SIM swap. Once approved, the original SIM is deactivated and the attacker’s SIM is activated on the number. All subsequent SMS messages go to the attacker.

SMS-based 2FA sends a one-time code to a phone number, not to a specific SIM card. Once a SIM swap is complete, the phone number is active on the attacker’s device. The 2FA code is delivered there, not to the legitimate user. The authentication system sees a valid code entry and has no way to detect the number has moved to a different SIM.

SIM Swap detection APIs query mobile network operators directly for recent SIM change events on a given phone number. Before a high-value transaction, the API can be used to check whether a SIM swap occurred within a defined time window. If a recent swap is detected, the transaction can be blocked, stepped up, or flagged for review.

The most effective defence pairs SIM Swap detection with Silent Network Authentication (SNA). SIM Swap detection flags accounts where a recent swap occurred. SNA verifies that the SIM currently in the user’s device matches their phone number in real time. Together they close the attack at the network layer before a fraudulent transaction can complete.

Yes. eSIMs are vulnerable to the same attack in a slightly different form. There is no physical SIM that needs to be issued, so the attack can be quicker — attackers convince carriers to re-provision the user’s number to an eSIM they control. SIM Swap detection APIs cover eSIM swap events as well as physical SIM swaps.

SIM Swap moves a number to a new SIM card on the same carrier. Port-out fraud moves the number to a different carrier entirely. Both give the attacker control of incoming SMS OTPs. SIM Swap detection APIs typically cover both, since both involve a change to the MSISDN-to-SIM binding.

A SIM swap can be completed by a carrier in minutes once an attacker has the right personal information. The attacker can then begin intercepting SMS OTPs immediately. Most fraud occurs within minutes of the swap, often before the legitimate user notices their phone has lost service.