The United Kingdom has experienced a dramatic surge in SIM swap fraud, with unauthorized SIM transfers increasing by 1,055 percent in 2024. According to data from Cifas, the UK’s fraud prevention service, nearly 3,000 cases were reported compared to 289 cases in the previous year. The increase coincides with broader concerns about identity fraud, which reached a record high of 421,000 cases in the UK during the same period.
SIM swap fraud, also known as SIM hijacking or port-out scams, occurs when criminals convince mobile carriers to transfer a victim’s phone number to a SIM card under their control. The technique allows fraudsters to intercept calls and text messages, including those containing two-factor authentication codes used to access accounts and digital assets. The threat has become especially serious as federal agencies warn against the vulnerabilities of SMS-based two-factor authentication.
The financial impact of these attacks has been substantial. The FBI’s Internet Crime Complaint Center (IC3) documented approximately $26 million in losses from SIM swapping incidents in 2024 in the United States alone, following a trend that saw victims lose $48 million to similar attacks in 2023.
Rather than targeting the phone’s hardware or software, attackers exploit vulnerabilities in mobile carrier authentication processes. They typically use personal information obtained from data breaches to successfully impersonate legitimate customers during carrier interactions. In response, some providers like AT&T have implemented new security features such as Wireless Account Lock to prevent unauthorized SIM transfers.
“The widespread availability of personal data from countless data breaches provides the fuel for attackers,” says Mohammed Khalil, a security researcher. “Our collective reliance on insecure SMS for two-factor authentication creates the vulnerability. And the rise of easily transferable digital assets, especially cryptocurrency, provides a massive financial incentive for these attacks.”
While eSIM technology offers enhanced physical security compared to traditional SIM cards, it remains vulnerable to remote swap attacks. “An eSIM is physically more secure, but it does not inherently protect you from a remote SIM swap attack,” explains Khalil. “The vulnerability lies with the carrier’s human and procedural authentication process, not the form factor of the SIM.”
Security experts advise immediate action if a phone displays “No Service,” as this may indicate an active SIM swap attack. Swift response is essential to minimize potential damage and restore account control. The FCC has recently strengthened regulations around SIM swap prevention, requiring carriers to implement more robust authentication procedures for number transfers.
Sources: DeepStrike.io, Clayhidon Parish Council