Academy/Fraud/SIM Swap Fraud
Critical severityFraud

SIM Swap Fraud

In a SIM swap, an attacker convinces a mobile carrier to transfer a victim's phone number to a SIM card the attacker controls. Once they own the number, every SMS OTP and 2FA code sent to that number goes to them, not the victim — rendering SMS-based security useless.

Think of it this way

Imagine someone walks into a post office, claims to be you, and asks all your mail to be redirected to their address. From that moment, everything sent to you goes to them — including your bank statements, password resets, and verification codes. SIM swap is that, but for your phone number.

How it works

The attacker first gathers personal information about the victim — name, date of birth, address, last 4 digits of their ID — often from social media or earlier data breaches. They call the mobile carrier, impersonate the victim, claim their phone was lost or damaged, and request a SIM replacement. Many carrier staff do not verify thoroughly. Once the swap completes, the victim's phone loses signal and the attacker receives all their calls and SMSes.

Real-world scenarios

Scenario 1

Mobile money theft

In Nigeria, a fraudster uses a victim's NIN and date of birth (found on social media) to convince a network provider to port the victim's number. They then reset the victim's fintech app password using the SMS OTP, log in, and transfer all funds within minutes.

Scenario 2

Crypto wallet drain

An attacker targets a crypto exchange user, swaps their SIM, resets the account password via SMS, bypasses 2FA, and withdraws all cryptocurrency to an external wallet in under 10 minutes.

How Anomira detects this

Anomira detects SIM swap patterns by identifying when a trusted user account suddenly authenticates from a completely new device or location, especially when combined with a recent OTP flood, and when the login is followed immediately by high-risk actions like password change or fund transfer.

What to do

  • Move away from SMS OTP for high-value actions — use authenticator apps (TOTP) or hardware keys instead.
  • Alert users if their account is accessed after a new SIM is activated on their number.
  • Require a 24-hour cooling period before allowing transfers from accounts that recently changed their 2FA method.
  • Partner with telcos or use carrier-agnostic SIM-swap detection APIs.
  • Educate users about social engineering risks and advise them to set a PIN with their carrier.

Related attacks

See this attack in your live API traffic

Anomira detects sim swap fraud automatically — no configuration needed.