A phone that goes silent without warning, no bars, no incoming texts, ranks among the clearest signs that a SIM swap is already underway, according to the FBI’s Internet Crime Complaint Center. Criminals convinced carriers to port more than $68 million worth of victims’ phone numbers in 2021 alone, a single-year loss that has since declined but never disappeared entirely.
Both figures come from the same federal tracking system that logs identity-theft complaints nationwide, and neither requires a victim to have clicked a bad link or downloaded anything. The scam starts with a phone call to a carrier, not malware on a device.
The moment a phone goes silent
Once a swap succeeds, the consequences move fast. The FBI’s 2022 public service announcement describes the mechanism in blunt terms: “the victim’s calls, texts, and other data are diverted to the criminal’s device” the instant a carrier activates the new SIM. From that point, any text message meant for the real owner, including a one-time login code, lands in the attacker’s phone instead.
That single diversion is often enough to unlock accounts far beyond the phone itself. Banks, brokerages and cryptocurrency exchanges that rely on a text message as a second login factor cannot tell the difference between the rightful owner’s phone and a criminal’s, because the network itself has already been told the number belongs to the new device. Cryptocurrency holders have absorbed some of the largest individual losses tied to the technique, since a crypto exchange account reset by text message can be emptied within minutes of a successful swap, long before the actual owner notices a signal problem and calls a carrier to ask why.
How a stranger convinces a carrier to move a number
Getting a carrier to make that switch takes persuasion, not hacking skill. The FBI attributes most successful swaps to social engineering, describing fraudsters who use “social engineering techniques to convince the telephone company employee to port the victim’s phone number to the fraudster’s SIM,” often while posing as the account holder on a support call or in a retail store.
The pitch usually works because the criminal already arrived with real details. Names, addresses, the last four digits of a Social Security number and answers to security questions typically come from an earlier data breach or a separate phishing message, giving the impersonation just enough polish to pass a carrier’s identity check. In a smaller share of cases the FBI has tied to insider involvement, the fraudster does not need to convince anyone at all, instead paying a carrier or retail-store employee directly to make the switch, which is part of why the agency’s recommendations for wireless providers focus as much on employee verification procedures as on customer-facing tools.
The rule the FCC wrote after the losses spiked
Regulators eventually responded directly to those numbers. A rule the Federal Communications Commission published in the Federal Register now requires wireless carriers to use “secure methods to authenticate customers that are reasonably designed to confirm a customer’s identity” before processing any SIM change or number port, to notify customers immediately when one is requested, and to offer free account locks that block unauthorized swaps outright. The rule took effect January 8, 2024, and also bars customer service staff from viewing account details until that authentication step clears.
The FCC’s own framing at the time, reported by The Record, tied the rule directly to scale: the agency pointed to billions of dollars in cumulative losses and described multiple criminal groups that had become specialists in exploiting the exact gap the new authentication rules were designed to close.
What the numbers looked like before and after the rule
The trend line bends right where the rule takes hold. Complaint data tracked on the scam’s own record shows IC3 logging 2,026 SIM-swap complaints in 2022, a 26 percent jump from the year before, before the count fell to 1,075 in 2023 and 982 in 2024, the two years the FCC’s authentication and notification rule was in force.
Dollar losses fell along the same curve. A tally of the FBI’s year-by-year figures puts reported losses at roughly $72.6 million in 2022, $48.8 million in 2023 and $25,983,946 in 2024, the most recent year on record, a drop of nearly two-thirds from the 2022 peak in just two years of the authentication rule being active.
Falling numbers do not mean the free account lock the FCC now requires has gone unused for a reason. IC3 still logged 982 complaints and nearly $26 million in reported losses for 2024, proof the rule cut the scheme down sharply without erasing it, and that a silent phone is still worth treating as a warning rather than a coincidence.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- A geomagnetic storm is forecast to hit Earth today, pushing the northern lights unusually far south
- A recalled pill hid a stimulant dose linked to heart attacks and death
- Four U.S. startups fired up their first small nuclear reactors, aiming to power AI data centers on-site
- Card skimmers hidden on gas pumps and ATMs are draining accounts, and here’s the tell