Skip to main content

Financial crime4 min read

SIM-swap account takeover: the signals in the first minutes

In a SIM-swap takeover, the attacker never has to break into the bank. They take control of the phone number the bank trusts, use it to reset access and move the money, usually within minutes of the swap.

How the takeover works

Most banks and mobile-money operators treat the customer’s phone number as proof of identity. One-time passcodes, password resets and payment confirmations are sent to it by text message, so whoever controls the number can pass those checks.

A SIM swap moves the number to a new SIM card held by the fraudster. The attacker first gathers enough personal information to impersonate the customer, through phishing, data exposed in an unrelated breach or a convincing phone call. They then persuade the mobile network operator to issue a replacement SIM, by posing as the customer at a store or call center, presenting forged documents or working with a corrupt insider. The moment the new SIM activates, the customer’s own phone loses service.

For a mobile-money wallet, the number is often the account itself, so control of the SIM can mean direct control of the funds. For a bank account, the attacker usually needs some credentials as well, and the passcodes now arriving on their handset let them reset the rest.

The signals in the first minutes

Takeovers follow a tight sequence, because the attacker knows the customer will soon notice the dead phone and call for help. Genuine customers who change a SIM typically keep using the same banking app on the same handset, so the silence of that handset is a signal in its own right.

The signals tend to arrive in roughly this order:

  • SIM change: the number registered to the account has recently moved to a new SIM
  • Credential reset: a password, PIN or app registration is reset using a passcode sent to that number
  • Device change: the session comes from a device the customer has never used, sometimes in an unfamiliar location
  • Profile changes: contact details, notification settings or transaction limits are altered
  • New payee: a beneficiary is added, frequently an account or wallet that is itself newly opened
  • Rapid outbound transfer: most of the available balance is sent to the new payee, sometimes split across several
  • Silence from the usual device: the customer’s own handset, now without service, drops out of activity entirely

Why the sequence matters more than any single event

Each of these events happens legitimately every day. Customers replace lost phones, upgrade handsets, forget passwords and pay new people. A rule that blocked every transfer after a SIM change would frustrate large numbers of genuine customers and would soon be switched off.

The strength of the signal lies in the combination and the timing. A SIM change followed within the hour by a reset from a new device, a new payee and a transfer close to the full balance is a very different picture from a SIM change followed by ordinary activity on the customer’s usual device. Scoring the sequence against the customer’s own history, rather than a population average, separates the two.

Speed is part of the signal as well. Genuine customers rarely add a payee and empty an account within minutes of getting a new SIM. Attackers almost always do, because they are racing the victim’s call to the contact center.

Interdiction for banks and mobile-money operators

The aim is to put a decision point between the takeover and the money leaving. Controls work best when they scale with the risk: a low-risk SIM change can pass with a light check, while a high-risk sequence earns a hold and a call from the fraud team.

Institutions usually combine several controls:

  • SIM-change checks: where the mobile network operator makes SIM-change data available, query it at login, at credential reset and before high-risk payments
  • Cooling-off periods: restrict new payees, limit increases and large transfers for a set time after a SIM change or credential reset
  • Step-up authentication that does not rely on text messages, such as in-app approval on the previously registered device, biometrics or a callback to a known alternate contact
  • Holds on first payments to new beneficiaries when other takeover signals are present
  • Linked controls for operators that run both the mobile network and the wallet, so a SIM swap automatically raises the risk on the associated wallet

After the hold

Stopping the transfer is the first step. The customer should then be contacted through a channel the attacker does not control, such as a registered email address or a branch visit, and the SIM and credentials restored. The receiving accounts deserve as much attention as the victim’s. They are often mule accounts used across many takeovers, and linking them by shared devices, phone numbers and identity details can expose the wider operation.

Dark Pools FinCrimes includes a SIM-swap takeover typology that flags the device and behavioral break in real time and can recommend approve, review or block before a payment is booked. Alerts route through SLA queues, and an AI copilot assembles the takeover timeline for the investigator, so the case and any SAR filing start from the evidence.

Each confirmed case should also feed back into detection. The devices, payees and timing from one takeover often reappear in the next, and rules tuned on confirmed cases catch the repeat sooner.

Get started

Take the next step

Talk to the team behind this research about how the same thinking applies to your program.

All insights