How it works
Many banks and mobile-money services rely on the registered phone number as the main authentication and recovery channel. In a SIM swap, the fraudster persuades or bribes staff at the network operator, or presents stolen or forged identity documents, to have the victim's number moved onto a new SIM. The victim's phone loses service, and one-time passwords and reset messages now go to the fraudster.
The takeover follows a recognizable sequence: SIM change, then a PIN or password reset, then a new device or new payee, then rapid transfers out, often to mule accounts or wallets. Each step is legitimate when the customer performs it, which is why a check on any single event rarely stops the fraud. The order of the steps and the short gaps between them are what matter.
In mobile-money markets the wallet is tied to the SIM itself, so a swap can give direct access to the balance and to any linked bank accounts. In several markets, network operators make SIM-change data available to banks so a recent swap can be checked before a high-risk action is allowed.
Red flags
- Customer reports a sudden loss of mobile service shortly before disputed transactions
- A PIN, password or credential reset soon after a SIM change on the registered number
- Login or wallet access from a new device, quickly followed by new payees or raised limits
- Changes to email or alternate contact details in the same session as the reset
- Outbound transfers that empty the account to recipients the customer has never paid
Signals the engine evaluates
- Time since the last SIM change on the registered number, where operator data is available
- Ordered sequence of SIM change, credential reset, device change, new payee and transfer, and the time between each step
- Device and location of the session against the customer's known devices and locations
- Value and destination of transfers after a credential reset, including whether destinations link to known mule accounts
Investigation and response
- 01Hold or recall pending transfers and freeze the account while the customer is contacted through a channel other than the affected number.
- 02Work with the customer and the network operator to confirm the swap and restore control of the number and credentials.
- 03Trace the receiving accounts and wallets, and request recalls from the receiving institutions.
- 04Link the destinations to any open mule cases and file suspicious transaction reports with the financial intelligence unit, such as the FIC in South Africa or the NFIU in Nigeria.