SIM swap fraud and online banking

SIM swap fraud moves a victim's phone number to a SIM card the fraudster holds. From then on the SMS codes for online banking arrive on the fraudster's phone. ENISA, the EU cybersecurity agency, surveyed 48 mobile operators in 22 European countries on the attack, and online banking was the service they named as most affected.

SIM card, ejector pin and smartphone on a table

How the swap happens

A SIM swap is a normal service: a customer gets a new SIM card after a loss, a new phone or a move to another provider. ENISA's report Countering SIM-Swapping describes how attackers abuse it. In the survey, 98 percent of the operators offered the swap in store and 79 percent also remotely. The attacker convinces staff with stolen personal data, or works with an employee in a store, and the number moves to the new card.

From that moment the attacker receives all calls and SMS for the number, including one-time codes sent for online banking. Almost half of the operators (48 percent) had no SIM swapping incident in the twelve months before the survey, while operators in France, Switzerland and the United Kingdom reported more than 50 each.

Why banks are the target

Banks have used SMS codes for more than a decade to confirm logins and transfers, and the operators in the survey named online banking as the service most affected by fraudulent SIM swaps. A swapped number turns a stolen password into a working second factor, which makes the swap a step in account takeover fraud.

The payment that follows is unauthorized. Under section 675v of the Civil Code the customer carries the full loss only after fraud, intent or gross negligence.

An API between operators and banks

ENISA describes a technical answer that several EU countries use: mobile operators offer banks an application programming interface that tells them whether a SIM swap happened recently. Before a transfer the bank queries the customer's operator, and if the SIM changed within a set window, such as 24 hours, it runs extra checks before it sends a code. In Italy the regulator AGCOM coordinated a trial with the Bank of Italy, banks and operators.

The longer-term answer is to stop relying on SMS. Passkeys and app-based approvals tie the second factor to a registered device. Behavioral biometrics does not depend on the phone number at all.

Upcoming events on fraud and digital identity in Germany

What is SIM swapping?

SIM swapping is the transfer of a phone number to a new SIM card. As a service it replaces a lost or damaged card; as fraud it moves the number to a card the attacker controls, so calls and SMS codes reach the attacker.

How can a bank detect a SIM swap?

By asking the mobile operator. Where operators offer a SIM swap API, the bank checks the date of the last swap before it sends a one-time code and holds the transfer for extra checks if the swap is recent. ENISA also recommends that operators notify customers of changes and limit staff access to customer data.

SIM swap fraud and Finance Loop

Finance Loop is the meeting place for the authentication and fraud teams at banks and payment firms that are moving customers off SMS codes. Finance Loop highlighted fAInance by Sopra Steria and Fraunhofer IAIS, which had a station on AI against financial crime.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.