Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is SIM-swap-assisted account takeover?

SIM-swap-assisted takeover uses unauthorised control of a victim's mobile number to receive calls, messages or recovery codes intended for them.

The important evidence is the change in control of the number and how that lines up with the affected account activity.

Start with the mobile-provider timeline

Useful records may include:

  • SIM/eSIM replacement;
  • porting;
  • account/customer-service contacts;
  • activation time;
  • old/new SIM identifiers;
  • service interruption;
  • account-security changes.

A useful sequence might look like:

12:41Victim phone loses service.
12:44Replacement eSIM activated.
12:51Password-recovery SMS requested.
12:54Account password reset.
12:58New session created.

That alignment can be powerful.

Service loss alone is not enough

Phones lose service for innocent reasons too.

A number transfer also does not prove that every linked account was accessed.

So connect the mobile event to:

  • recovery-code requests;
  • password resets;
  • MFA changes;
  • new sessions;
  • downstream account activity.

Keep the identities separate

The mobile subscriber, account holder, person requesting the SIM change and person using the downstream account may all differ.

Provider customer-service records may help identify how the transfer was authorised, but the human actor still requires separate evidence.

SIM swap may be only one part of the attack

The attacker may also need:

  • existing credentials;
  • leaked personal data;
  • social engineering;
  • access to another recovery channel.

The practical point is: align the mobile-number control window with recovery and account activity. Treat the SIM change, downstream takeover and offender attribution as related but separate propositions.

Reference: CIM-057Cyber Incidents & Offender Methods