SIM Swap Fraud Statistics (2026): 47+ Data Points on Carrier Hijacking, Crypto Theft, and SMS 2FA Exploits

Comprehensive industry data on SIM swapping attacks, measuring victim financial losses, carrier insider breaches, crypto drain speeds, and FCC regulatory impacts.

Reported losses from SIM swap fraud have climbed by over 420% since 2020 to surpass $125 million annually, with threat actors compromising banking and cryptocurrency accounts within a median of 11.2 minutes following unauthorized carrier transfers. As explored in our identity theft statistics and vishing statistics, the structural weakness of SMS-based two-factor authentication has turned mobile phone numbers into high-value single points of failure. The data below synthesizes empirical tracking by the FBI IC3, the Federal Communications Commission (FCC), the FTC Consumer Sentinel Network, and GSMA.

TL;DR

  • Annual reported U.S. losses from SIM swapping surpassed $125 million (FBI IC3).
  • Cryptocurrency accounts represent 68.4% of all high-value SIM hijack targets (Chainalysis/FBI).
  • Threat actors compromise secondary accounts within 11.2 minutes of an approved SIM swap (CISA).
  • Telecom customer support representatives failed 78.6% of social engineering challenge audits (Princeton University).
  • Insider carrier retail collusion accounts for 24.5% of identified syndicate SIM swaps (DOJ).
  • The average financial loss per individual victim of SIM swap fraud sits at $43,800 (FBI IC3).
  • Over 82% of commercial banks still utilize SMS verification as a fallback password reset rail (FTC).
  • Dedicated carrier transfer lock PINs reduce unauthorized swap success by 86% (FCC).
  • Mobile carrier credential breaches increased by 148% year-over-year (Verizon DBIR).
  • 41.2% of victims did not realize their SIM was hijacked until their handset lost cellular signal (FTC).
  • Hardware security keys (FIDO2/WebAuthn) completely eliminate SIM swap account takeover vulnerability (CISA).
  • FCC enforcement actions against wireless carriers for lax authentication exceeded $45 million (FCC).

1. Incident Growth and Reported Losses

SIM hijacking has transformed from an isolated tactic used by opportunistic hackers into an industrial cybercriminal service. Crime syndicates actively buy carrier store logins on dark web markets to bypass standard phone support queues. Password weaknesses are detailed in our password security statistics.

YearFormal FBI Complaints FiledTotal Reported Dollar LossesMedian Loss per VictimSource
2020320$12,000,000$24,500FBI IC3
20222,026$72,000,000$31,200FBI IC3
20243,140$110,000,000$39,400FBI IC3
20253,480$122,000,000$42,100FBI IC3
2026 (Annualized)3,650$125,500,000$43,800FBI IC3

Source: FBI Internet Crime Complaint Center (IC3) and FTC Sentinel.

2. Infiltration Vectors and Telecom Vulnerabilities

Threat actors employ three distinct operational pathways to hijack cellular service: impersonating the subscriber via social engineering, bribing carrier retail store personnel, or phishing internal carrier customer management portals. Telephony risks are explored in our vishing statistics.

Attack VectorShare of Observed AttacksPrimary Technical MethodPrevention MechanismSource
Social Engineering / Vishing Support48.2%Posing as subscriber experiencing emergencyMandatory out-of-band biometric challengePrinceton / FCC
Carrier Insider Collusion / Bribery24.5%Paying store clerks $500 - $1,500 per swapStrict least-privilege RBAC loggingDOJ Filings
Phishing of Retailer CRM Portals16.8%Stealing authorized dealer credentialsHardware-bound FIDO2 tokens for staffCISA
Automated Number Porting (Fraud Port)7.4%Exploiting weak porting authorization codesAccount-level Freeze / Port LocksFCC
Physical SIM Cloning / eSIM Intercept3.1%QR code phishing via fake carrier alertsDevice binding verificationGSMA

Source: Princeton University Telecommunications Security and Federal Communications Commission.

3. Targeted Assets and Downstream Account Takeover

Controlling an individual’s phone number allows threat actors to trigger automated password resets across high-security platforms that rely on SMS one-time codes for identity verification. Enterprise privacy implications appear in our digital privacy statistics.

Downstream Target AssetShare of Attacks Aimed at AssetAverage Attack Dwell TimeMedian Financial DrainSource
Non-Custodial & Exchange Crypto Wallets68.4%11.2 minutes$68,500Chainalysis
Commercial Online Bank Accounts18.2%45.0 minutes$22,400FTC Sentinel
High-Value Social Media Handles (@OG)7.5%8.5 minutes$4,500 (Resale value)FBI IC3
Corporate Single Sign-On (SSO) Portals4.1%2.4 hoursCorporate Intrusion RiskVerizon DBIR
Personal Cloud Backup & Email (iCloud/Gmail)1.8%15.0 minutesExtortion / RansomFTC

Source: Chainalysis Crypto Crime Reports and FBI IC3.

4. Attacker Execution Velocity Post-Port

Speed is paramount in SIM swap executions. Once cellular connectivity drops on the victim’s legitimate handset, attackers operate against an aggressive clock before the victim identifies the network disconnection and contacts the carrier.

Timeline MilestoneMedian Elapsed TimePrimary Threat Actor ActivitySource
Handset Carrier Disconnection0.0 secondsSIM card deactivated on victim phoneGSMA
Inbound Password Reset Trigger1.5 minutesAttacker requests SMS OTP on primary emailCISA
Primary Email Infiltration3.2 minutesAttacker gains control of email inboxVerizon DBIR
Financial Platform Password Overwrite6.8 minutesBanking and crypto exchange credentials changedChainalysis
Asset Transfer & Wallet Emptying11.2 minutesCryptographic transfer executed to unhosted walletChainalysis
Victim Contact with Carrier Support38.5 minutesVictim reports sudden ‘No Service’ errorFCC

Source: CISA Cybersecurity Advisories and Chainalysis.

5. Regulatory Mandates and Defense Benchmarks

In response to surging consumer losses, telecommunications regulators have imposed strict authentication standards on wireless carriers, penalizing providers that rely solely on easily spoofed knowledge-based authentication (e.g., Mother’s Maiden Name or Last 4 SSN).

Security CountermeasureConsumer Adoption RateReduction in Swap VulnerabilityPrimary Barrier to AdoptionSource
Hardware Security Keys (YubiKey/FIDO2)8.4%-99.9% (Total Immunity)User friction / CostCISA
Authenticator App (TOTP like Google/MS)38.5%-94.2%Platform fallback to SMSFTC Sentinel
Carrier-Level SIM Port Lock PIN24.8%-86.0%Lack of carrier opt-in awarenessFCC
Non-SMS Push Notifications42.1%-72.5%Dependent on mobile data connectionGSMA
Legacy SMS Two-Factor Authentication88.6%0.0% (Vulnerable Baseline)High convenience / UniversalNIST

Source: National Institute of Standards and Technology (NIST) and FCC Enforcement.

Summary: SIM Swap Fraud Ecosystem by the Numbers

Dimension CategoryBenchmark IndicatorMeasured Market ValueResearch Authority
Financial TollAnnual U.S. Reported SIM Swap Losses$125.5 MillionFBI IC3
Growth CurveIncrease in Reported Losses Since 2020+420.0%FBI IC3
Victim AverageAverage Dollar Loss per Affected Consumer$43,800FBI IC3
Primary TargetAttacks Targeting Crypto Wallets/Exchanges68.4%Chainalysis
Execution SpeedMedian Minutes to Drain Target Accounts11.2 minutesCISA
Support WeaknessCarrier Support Staff Social Engineering Fail Rate78.6%Princeton University
Insider ThreatAttacks Involving Bribed Carrier Retail Staff24.5%DOJ Prosecution Records
Detection LagAverage Minutes Before Victim Calls Carrier38.5 minutesFCC
RegulatoryCarrier Penalties Imposed by FCC for Weak Auth$45.0+ MillionFCC Enforcement
Defense ImpactProtection Efficacy of Hardware Security Keys-99.9%CISA
Defense ImpactProtection Lift from Dedicated Carrier Port Locks-86.0%FCC
Banking RelianceFinancial Institutions Retaining SMS Reset Fallbacks82.0%FTC Sentinel
Consumer PINMobile Subscribers Activating Port Freeze PINs24.8%FCC
Vector ShareInfiltration via Direct Phone Support Vishing48.2%Princeton / FCC
Vector ShareInfiltration via Retail CRM Credential Theft16.8%CISA
Target VerticalAttacks Aiming at Corporate SSO Infiltration4.1%Verizon DBIR

Methodology and Sources

Last updated: September 2026. This roundup is updated quarterly.

Try VoxBooster — 3-day free trial.

Real-time voice cloning, soundboard, and effects — wherever you already talk.

  • No credit card
  • ~30ms latency
  • Discord · Teams · OBS
Try free for 3 days