Skip to main content

BankingMobile money & remittances10 of 28

SIM-swap takeover

Moving a victim's phone number onto a SIM the fraudster controls, then using intercepted one-time passwords to take over bank and wallet accounts.

STEP 1SIM changeSTEP 2PIN resetSTEP 3New deviceSTEP 4New payeeSTEP 5TransferMINUTES, NOT DAYS
Illustrative patternA SIM change on the registered number is followed in quick succession by a PIN reset, a new device, a new payee and a transfer out.

How it works

Many banks and mobile-money services rely on the registered phone number as the main authentication and recovery channel. In a SIM swap, the fraudster persuades or bribes staff at the network operator, or presents stolen or forged identity documents, to have the victim's number moved onto a new SIM. The victim's phone loses service, and one-time passwords and reset messages now go to the fraudster.

The takeover follows a recognizable sequence: SIM change, then a PIN or password reset, then a new device or new payee, then rapid transfers out, often to mule accounts or wallets. Each step is legitimate when the customer performs it, which is why a check on any single event rarely stops the fraud. The order of the steps and the short gaps between them are what matter.

In mobile-money markets the wallet is tied to the SIM itself, so a swap can give direct access to the balance and to any linked bank accounts. In several markets, network operators make SIM-change data available to banks so a recent swap can be checked before a high-risk action is allowed.

Red flags

  • Customer reports a sudden loss of mobile service shortly before disputed transactions
  • A PIN, password or credential reset soon after a SIM change on the registered number
  • Login or wallet access from a new device, quickly followed by new payees or raised limits
  • Changes to email or alternate contact details in the same session as the reset
  • Outbound transfers that empty the account to recipients the customer has never paid

Signals the engine evaluates

  • Time since the last SIM change on the registered number, where operator data is available
  • Ordered sequence of SIM change, credential reset, device change, new payee and transfer, and the time between each step
  • Device and location of the session against the customer's known devices and locations
  • Value and destination of transfers after a credential reset, including whether destinations link to known mule accounts

Investigation and response

  1. 01Hold or recall pending transfers and freeze the account while the customer is contacted through a channel other than the affected number.
  2. 02Work with the customer and the network operator to confirm the swap and restore control of the number and credentials.
  3. 03Trace the receiving accounts and wallets, and request recalls from the receiving institutions.
  4. 04Link the destinations to any open mule cases and file suspicious transaction reports with the financial intelligence unit, such as the FIC in South Africa or the NFIU in Nigeria.
Get started

Catch sim-swap takeover before the loss

See how FinCrimes scores this pattern against your own historical data in a backtest, before anything goes live.

Browse the library