Key Takeways
- US SIM-swap losses reported to the FBI peaked at $72.6 million in 2022 and were $26.0 million in 2024 — but the decline is misleading, not reassuring.
- SIM swap is an access step, not the endgame: the number is stolen to intercept OTPs and drain bank and crypto accounts, which are then booked under other crime categories.
- Regulators are acting on both sides: the FCC now requires carriers to secure SIM changes, and NIST has restricted SMS OTP for enterprises.
- The durable defense is to stop trusting SMS codes and verify SIM possession at the carrier level — the basis of silent verification.
SIM Swap Fraud Statistics 2026: The Numbers Every Security Team Should Know
SIM swap fraud has a reputation problem: the headline numbers look like they are getting better, while security teams on the ground know the threat is not going away. Reconciling those two facts is the whole point of this roundup. Below are the latest verifiable statistics on SIM swapping — drawn from primary sources like the FBI’s Internet Crime Complaint Center — alongside the context that explains what the numbers actually mean for anyone still protecting accounts with SMS one-time passcodes.
In short: according to the FBI’s Internet Crime Complaint Center, US victims reported $26.0 million in SIM-swap losses across 982 complaints in 2024, down from a $72.6 million peak in 2022. Those figures capture only reported complaints, though, and exclude the downstream account drains a SIM swap enables — so they substantially understate the real cost, which is why regulators and enterprises are still treating it as a rising threat.
Here is the full picture — the multi-year data, who gets targeted, why reported losses are falling while risk is not, the regulatory response, and what the numbers mean for how you verify users.
SIM swap fraud statistics 2026: the headline numbers
The most authoritative US dataset is the FBI’s Internet Crime Complaint Center (IC3) Annual Report. Here is the multi-year trend in reported SIM-swap complaints and losses:
Source: FBI IC3 (2022 SIM-swap PSA for 2021; 2024 IC3 Annual Report for 2022–2024). Figures reflect reported complaints only.
Read quickly, this looks like a problem in retreat: complaints down more than half from the 2022 peak, losses down roughly two-thirds. Read carefully, it is nothing of the sort — and the next section explains why.
SIM swap fraud statistics at a glance
The most-quoted figures from the current data, in one place:
- $72.6 million — peak US SIM-swap losses reported to the FBI IC3, in 2022.
- $26.0 million — US SIM-swap losses reported to the IC3 in 2024.
- 982 — US SIM-swap complaints filed with the IC3 in 2024.
- ~64% — drop in reported US losses from 2022 to 2024, despite no evidence the underlying threat eased.
- 2024 — the year the FCC’s SIM-swap and port-out protection rules took effect for US carriers.
- Restricted — NIST’s classification of SMS one-time passcodes as an authenticator.
Why falling numbers don’t mean falling risk
Three structural facts make the reported decline a poor proxy for the real threat level.
1. IC3 captures reported complaints, not total incidents
The IC3 figures reflect only crimes that victims chose to report to one federal portal. Most fraud never gets reported there — victims go to their bank, their carrier, or nowhere at all. When a headline number depends on voluntary reporting, a fall can mean less reporting just as easily as less crime.
2. SIM swap is a gateway, not the payload
This is the crucial point most summaries miss. A SIM swap is rarely the crime itself; it is the access step that unlocks the crime. An attacker swaps the SIM to intercept a one-time code, then uses that code to reset a password, drain a bank account, or empty a crypto wallet. The eventual loss is typically recorded under that category — bank fraud, investment fraud, crypto theft — not under “SIM swap.” The result is a systematic undercount: the technique that enabled millions in losses shows up as a few hundred complaints. We walk through this attack chain in detail in our guide to SIM-swap fraud protection in the USA.
3. The rest of the world is moving the other way
Where the US reported numbers dipped, several other markets reported sharp increases over the same period, with fraud-prevention agencies describing triple-digit percentage surges in unauthorized SIM swaps and number ports. Crypto-related SIM-swap theft in particular has continued to run into the tens of millions of dollars annually. Taken together, the global signal is an attack that is consolidating and professionalizing, not disappearing.
Who gets targeted
SIM swap is not a random, high-volume scam; it is a targeted one, aimed where a single successful takeover pays off. The most exposed profiles are:
- Crypto holders and exchange users — irreversible transactions make wallets the highest-value target, and crypto SIM-swap losses remain a large share of the total.
- High-net-worth and executive accounts — banking, brokerage and email accounts whose compromise unlocks further access.
- Anyone whose recovery still depends on SMS — if a phone number can reset the password, the number becomes the master key.
The common thread is dependence on the phone number as a recovery and authentication factor. That is precisely the dependency SMS OTP creates and silent verification removes.
The true cost of a single SIM swap
The IC3 loss figure is only the money victims reported losing. For a business, one successful SIM swap on a customer or employee account carries a much wider cost that never appears in that statistic:
- Direct loss — the drained funds, transferred balance or stolen crypto, which for on-chain assets is effectively irreversible.
- Remediation — fraud investigation, support hours, account restoration and forced credential resets across the affected user base.
- Chargebacks and reimbursement — many institutions absorb the loss to retain the customer, converting a fraud event into a direct P&L hit.
- Regulatory and legal exposure — breach-notification obligations and, increasingly, scrutiny of whether reasonable authentication controls were in place.
- Churn and reputation — a customer whose account is drained rarely stays, and public incidents erode trust well beyond the individual affected.
Add these together and the fully loaded cost of a single takeover typically dwarfs the average per-complaint figure — which is exactly why enterprises evaluate prevention on total risk reduction, not on the headline loss number alone.
Why SIM swap works: the SMS OTP dependency
SIM swap fraud is not a flaw in one carrier or one bank; it is a flaw in the model. As long as controlling a phone number is enough to receive the code that authorizes sensitive actions, stealing the number is a reliable path to the account. The FBI’s own SIM-swap public service announcement describes exactly this pattern: attackers use social engineering, insider access, or phishing to move a number to a SIM they control, then intercept the one-time codes.
This is why the defense cannot just be “better OTP.” Any method that delivers a secret to a phone number inherits the number’s vulnerability. The way out is to stop treating code receipt as proof and instead verify that the original SIM is present — a check a swapped SIM fails. That is the principle behind silent network authentication and carrier-level number verification.
How a SIM swap attack actually unfolds
Understanding the mechanics is what makes the statistics actionable. Per the FBI’s SIM-swap advisory, a typical attack runs in five stages:
- Reconnaissance. The attacker gathers the victim’s personal details from data breaches, data brokers, phishing and social media — enough to pass a carrier’s identity checks.
- Carrier social engineering. Posing as the victim (or using a bribed insider), the attacker convinces the mobile carrier to move the number to a SIM they control.
- Takeover of the line. The number activates on the attacker’s SIM and the victim’s phone silently loses service — often the first and only visible sign.
- Code interception. With the number in hand, the attacker receives SMS one-time codes and password-reset links for the victim’s accounts.
- Monetization. Bank transfers, crypto withdrawals and email takeovers follow within minutes — and are recorded as those crimes, not as “SIM swap.”
Notice that stage four is the linchpin, and it is the exact step carrier-level verification neutralizes: if possession of the original SIM is required, an intercepted code is worthless.
SIM swap in the broader account-takeover picture
SIM swap is one of several account-takeover techniques, but it is uniquely effective against the SMS-based defenses most accounts still use:
The pattern is clear: every SMS-dependent defense has a bypass, and SIM swap is the most reliable of them. Removing the dependence on the code — not hardening its delivery — is what closes the category.
The regulatory response is squeezing SMS from both sides
Two US regulators are converging on the same conclusion from different angles, which is itself a strong signal about where risk is heading.
The FCC is tightening the carriers. In rules adopted in 2023 and effective in 2024, the FCC now requires wireless providers to use secure customer authentication before a SIM change or port-out and to notify customers immediately when one is requested — directly targeting the mechanics of a swap.
NIST is tightening the enterprises. In its updated Digital Identity Guidelines, NIST classifies SMS one-time passcodes as a restricted authenticator, pushing organizations toward stronger, possession-based methods. When the agency that sets the baseline for federal identity practice moves a control into a “use with caution” tier, private-sector audits and insurers tend to follow.
The message from both is consistent: the phone-number-plus-SMS-code model is being actively deprecated. Enterprises that get ahead of it are reducing both fraud exposure and future compliance friction at once.
What the data means for enterprises
Strip away the year-to-year noise and the statistics point to one durable conclusion: the risk is not the raw number of SIM swaps, it is your dependence on the phone number as a trusted factor. Every account whose login, reset or step-up relies on an SMS code is one successful swap away from takeover, regardless of what this year’s IC3 total happens to be.
There is also a timing signal in the data. The same carrier network APIs that regulators are leaning on are now available to enterprises — so for the first time, a business can check SIM-swap risk in real time and verify possession silently, rather than hoping the carrier stopped the swap. The defensive tooling has caught up with the threat; the question is whether your verification stack has.
A useful exercise is to map your own phone-number dependency: list every place a phone number can unlock or recover an account — signup, login, password reset, step-up, support-desk verification — and mark which still rely on an SMS code as proof. Each of those is a SIM-swap exposure point, and the map usually reveals more of them than teams expect. Closing them does not require ripping out SMS overnight; it requires putting a possession check in front of the code so a swapped SIM cannot pass, starting with the highest-value flows.
What to watch in 2026 and beyond
Three trends will shape SIM-swap risk over the next few years:
- Real-time SIM-swap detection goes mainstream. The same carrier network APIs that enable silent verification also expose a live SIM-change signal, so enterprises can now check swap risk before every sensitive action instead of reacting after a loss.
- Regulatory pressure compounds. With FCC rules now in force and NIST steering enterprises off SMS, expect audits, insurers and partners to start asking how you verify possession — not just whether you have MFA.
- Attackers adapt to eSIM and AI. As eSIM adoption grows and AI makes social engineering cheaper and more convincing, the reconnaissance and impersonation stages get easier — raising the premium on defenses that do not depend on a human spotting the fraud.
The through-line: defense is shifting from “stop the swap at the carrier” to “assume swaps happen and verify possession at the moment of risk.” That is a strategy enterprises can control directly.
How to defend against SIM swap fraud
A practical, layered defense looks like this:
- Stop using SMS OTP as the sole factor. Treat code receipt as a weak signal, not proof, especially for high-value actions.
- Verify SIM possession silently. Use carrier-level number verification so a swapped SIM fails the check — the core capability of NumberVerify2, a service within Message Central’s authentication and fraud-prevention suite.
- Check SIM-swap risk before sensitive actions. Read a real-time SIM-change signal and step up verification before payouts, transfers, resets and KYC re-checks.
- Keep OTP as a fallback, not the front door. Retain SMS OTP Verification and WhatsApp OTP for Wi-Fi-only or unsupported cases, behind the silent check rather than in front of it.
- Instrument and monitor. Log verification channel and outcome, and watch for spikes in recent-SIM-change flags that may indicate a targeted campaign.
For the full attacker playbook and defense breakdown, see our SIM-swap fraud protection guide.
Stopping SIM swap with Message Central
Message Central’s NumberVerify2 is a dedicated service in the authentication and fraud-prevention suite that verifies SIM possession at the carrier level in under a second and returns a SIM-swap risk signal you can act on. It works alongside SMS OTP Verification and WhatsApp OTP as fallback, so the majority of users are checked silently while coverage stays universal. To see how it would perform against SIM-swap risk on your own traffic, talk to our team.
Frequently asked questions
How much money is lost to SIM swap fraud?
US victims reported $26.0 million in SIM-swap losses to the FBI’s Internet Crime Complaint Center in 2024, down from a $72.6 million peak in 2022. These figures cover reported complaints only and exclude the downstream bank and crypto losses a swap enables, so the true economic impact is considerably higher.
Is SIM swap fraud increasing or decreasing?
US reported losses have fallen since 2022, but that likely reflects reporting and categorization shifts rather than a real decline — SIM swap is usually an access step whose losses are booked under other crime types. Several other markets report sharp increases, and regulators including the FCC continue to treat it as a growing threat.
How can businesses prevent SIM swap fraud?
Stop relying on SMS codes as proof and verify SIM possession at the carrier level, so a swapped SIM fails the check. Add a real-time SIM-swap risk signal before sensitive actions, and keep OTP only as a fallback. This is the approach behind NumberVerify2 and silent network authentication.

.svg%20(1).png)

