What’s actually happening
SIM swap fraud works by targeting the weakest link in the chain, which usually isn’t your phone at all. It’s your mobile carrier. An attacker gathers enough personal details about you, often pulled from old data breaches, social media, or a convincing phone call, to impersonate you to your carrier’s customer service. Once they’ve convinced the carrier they’re you, they request your phone number be transferred to a SIM card they control. From that moment, your number belongs to them. Calls and texts meant for you, including the one-time codes banks and email providers send to verify your identity, go straight to the attacker instead.
The FBI’s Internet Crime Complaint Center has tracked this specifically since 2018 and issued a formal public warning describing the pattern. Even as reported dollar losses have moved up and down year to year, officials have been clear that the reported numbers understate the real scope, since a SIM swap is usually just the first step. The actual financial damage, often draining a bank or cryptocurrency account, tends to get logged under a different fraud category entirely, separate from the SIM swap that made it possible.
Why this one is unusually hard to see coming









