Fraud Prevention

SIM swap fraud explained for risk teams

SIM swap fraud is a social-engineering attack that redirects a victim's phone number to a SIM card the attacker controls. Once the number is theirs, SMS-based authentication becomes the attacker's tool rather than the customer's defence. This page explains how SIM swap works, why it remains effective against standard fintech security stacks, and what signals are available to reduce exposure.

How SIM swap fraud works, briefly

The attacker gathers enough personal information to pass a carrier's identity verification, then requests a SIM replacement, claiming the original is lost or damaged. Once the carrier reassigns the number, the victim's SIM stops working and every inbound call and SMS, including OTPs and password reset links, routes to the attacker's device instead. No authentication server, app or OTP flaw is exploited: the carrier does the work for the attacker, so any platform relying on SMS for login, withdrawal authorisation, account recovery or contact-detail changes is exposed. For the mechanics of catching a swap before an OTP is sent and the checks to build into an authentication flow, see SIM swap detection for account takeover prevention.

The attack is particularly effective in fintech and crypto, where account access converts quickly to financial loss, and it needs only enough social-engineering ability to pass a carrier's verification process, which in many markets remains low-friction.

Regulatory context

UK regulators have signalled that SMS-only authentication for high-risk payments is increasingly difficult to justify. The FCA's PS24/17 update to the Financial Crime Guide asks firms to hold a documented, risk-based view of their financial crime systems and controls; a telecom signal such as SIM swap prevention is one evidenced input a firm can point to when demonstrating those controls are proportionate. This is a general summary, not legal or regulatory advice; confirm specifics against the FCA's published text.

In the Netherlands and Germany, similar expectations apply under PSD2's Strong Customer Authentication requirements. Firms operating across GB, NL, DE and FR face a consistent regulatory direction: layering telecom signals into fraud decisions is expected, not optional.

The FCC adopted new SIM swap and port-out rules in the US market in 2023, effective July 2024, requiring carriers to apply multi-factor identity verification before reassigning a number. UK and EU carriers are under analogous, if not identically codified, pressure.

What risk teams can do

Three layers combine well in practice:

What Telebase returns

Telebase returns a SIM swap signal for GB, DE, NL and FR numbers via a per-query API call. The signal is in early access while carrier registration completes. Today, querying a number in those markets returns simSwap: UNKNOWN. The carrier data feed is not yet active. When live, the field returns SWAPPED, NO_SWAP, or UNKNOWN.

Live signals today: carrier, country, number type (mobile, landline, VoIP) and active status. $0.05 per query. No annual commitment. No monthly fee.

Early access: SIM swap detection is launching for GB, DE, NL and FR.

If your risk team is building or evaluating fraud controls that incorporate SIM swap signals, get in touch. Early access gives you the signal before general availability and the ability to test it against your specific carrier and number mix. Carrier, country, number type and active status are queryable now.

Request early access