Scammers are using SIM-swap fraud to hijack mobile phone numbers and gain unauthorized access to personal and financial accounts [1].

This tactic bypasses traditional security measures by redirecting a victim's identity to a device controlled by the attacker. Because many banks and email providers rely on mobile numbers for identity verification, a successful swap can lead to total account takeover in minutes [3].

SIM-swap fraud occurs when an attacker illegally transfers a victim's mobile number to a SIM card they control [1]. This process allows the fraudster to intercept all incoming calls and SMS messages intended for the original owner [1]. By controlling the phone number, the attacker can receive one-time passwords (OTPs) used for two-factor authentication [1].

Once the attacker has access to these codes, they can reset passwords for email accounts, social media, and banking portals [2]. This allows them to steal money or personal data directly from the victim's accounts [2]. The process is often invisible to the victim until their phone suddenly loses all network connectivity, a sign that the number has been moved to another device [3].

Reports indicate this practice is occurring globally, with specific examples noted in the U.S., including Florida and the Southern District of New York [4, 3]. The primary goal of these attacks is to gain unauthorized access to financial assets [2].

Security experts said that relying solely on SMS-based authentication creates a vulnerability that scammers can exploit. While mobile carriers have implemented various security checks to prevent unauthorized transfers, fraudsters continue to find ways to deceive customer service representatives or use compromised employee credentials to facilitate the swap [3].

A successful swap can lead to total account takeover in minutes.

The prevalence of SIM-swap fraud highlights a critical weakness in SMS-based two-factor authentication. As financial institutions continue to rely on mobile numbers as a primary trust anchor, the shift toward hardware security keys or app-based authenticators becomes necessary to decouple identity verification from the cellular network.