What Is SIM Swapping? Understanding the Attack Behind Modern Account Takeovers
Recently, I watched a YouTube deep dive into some of the most notorious SIM swapping cases and how hackers used this social engineering exploit to steal millions of dollars from high profile investors, executives, and even celebrities. What shocked me most wasnât just the scale of the crypto thefts, but the attackers themselves. Some were barely teenagers, sitting behind a computer screen, yet capable of pulling off some of the most brazen account takeover attacks in modern cybersecurity history.
But before we get into those stories, itâs important to understand the core exploit that made all of this possible. Letâs take a closer look at the SIM swapping attack that powered these multimillion dollar heists.
SIM swapping, also known as SIM hijacking or SIM port out fraud, is a cybersecurity attack where criminals trick a mobile carrier into transferring a victimâs phone number to a SIM card controlled by the attacker. Once the attacker gains control of the number, they can intercept:
- SMS two factor authentication (2FA) codes
- Password reset links
- Banking and crypto login alerts
- Account recovery messages
This gives the attacker everything they need to perform a full account takeover, often within minutes.
SIM swapping remains effective because it exploits a weak link in modern cybersecurity: phone numbers are still treated as identity, even though theyâre easy to steal.
Real World SIM Swapping Cases: How Hackers Stole Millions in Cryptocurrency
Joseph OâConnor (âPlugWalkJoeâ): $784,000 in Stolen Crypto
Joseph OâConnor, known online as âPlugWalkJoe,â was an infamous hacker who helped orchestrate a SIM swapping attack against Greg Bennett, a senior executive at a major cryptocurrency company. With a combination of social engineering and precise timing, OâConnor and his co conspirators convinced the carrier to transfer Bennettâs phone number to a SIM card under their control, a single successful port out that opened the door to Bennettâs digital life.
Once the attackers seized control of his number, the situation escalated quickly. Password resets began firing. Authentication codes flowed straight into their hands. Within minutes, OâConnorâs crew breached Bennettâs crypto accounts and siphoned $784,000 in digital assets, leaving the executive locked out and unaware until the damage was already done.
OâConnor was eventually arrested, extradited, and convicted. This serves as a high profile reminder that SIM swapping isnât an obscure cybercrime but a mainstream, highly effective attack vector capable of dismantling even well protected financial accounts.
Ellis Pinsky: $23.8 Million Stolen at Age 15
Ellis Pinsky was only 15 years old when he became the unlikely mastermind behind one of the largest SIM swapping crypto thefts ever recorded. Operating from his suburban bedroom, Pinsky and his crew set their sights on Michael Terpin, a well known cryptocurrency investor whose public profile made him an irresistible target for these types of hackers.
The attack began with a quiet but devastating move: hijacking Terpinâs phone number. Once the SIM swap succeeded, the group gained full control over Terpinâs SMS messages, authentication codes, and password resets. What followed was swift and surgical. Within minutes, Pinskyâs team breached Terpinâs crypto accounts and siphoned out $23.8 million in digital assets, leaving Terpin locked out and scrambling to understand how his entire portfolio had vanished overnight.
The sheer scale of the theft, combined with the attackerâs age, shocked the cybersecurity world. Terpin later described Pinsky as âBaby Al Capone,â underscoring how SIM swapping has evolved into a high stakes attack vector capable of empowering even teenagers to execute multimillion dollar heists.
Today, Pinsky has stepped away from the world of illicit hacking. He went on to earn degrees in computer science and philosophy, redirecting his skills toward cybersecurity and using his experience to educate others about the online threats he once exploited.
Why SIM Swapping Is Still a Major Cybersecurity Threat in 2026
You might assume that after nearly a decade, this security weakness would have been fixed. It hasnât. Despite growing awareness in the cybersecurity community, SIM swapping remains a widespread and rapidly evolving threat. Hereâs why:
- SMS 2FA Is Still Common
Many banks, crypto exchanges, and financial platforms still rely on SMS verification codes, making them vulnerable to SIM hijacking. - Mobile Carriers are Susceptible to Social Engineering
Attackers impersonate victims, exploit weak verification processes, or even bribe employees. A single successful call can compromise an entire digital identity. - Personal Data Is Everywhere
Data breaches, OSINT tools, and leaked databases give attackers everything they need to impersonate victims convincingly. - Cryptocurrency Is a Prime Target
Crypto transfers are instant, irreversible, and easily laundered through mixers or cross chain bridges. - High Value Targets Are Easy to Identify
Crypto investors, influencers, and executives often reveal holdings publicly, making them ideal targets for SIM swapping attacks.
SIM swapping persists because the underlying infrastructure hasnât evolved and it remains simple, scalable, and profitable.
How to Protect Yourself From SIM Swapping (Practical Cybersecurity Tips)
- Stop Using SMS for Two Factor Authentication
This is the most important step. Replace SMS 2FA with:- Authenticator apps (Authy, Google Authenticator, Microsoft Authenticator)
- Hardware security keys (YubiKey, Google Titan)
- Passkeys, where supported
- Add a Carrier Port Out PIN
Most carriers allow you to set a port out PIN or account security code. This adds friction for attackers attempting unauthorized number transfers. - Avoid Phone Number Based Account Recovery
Use email based or app based recovery methods whenever possible. - Reduce Your Personal Data Exposure
Attackers rely on personal information to impersonate victims. Improve your cybersecurity posture by:- Removing yourself from data broker sites
- Limiting personal details on social media
- Using a separate âpublicâ email for online profiles
- Use a Private Number for Sensitive Accounts
Some cybersecurity professionals maintain a second phone number used exclusively for MFA and itâs never shared publicly. - Watch for Sudden Loss of Mobile Service
If your phone unexpectedly loses service, it may indicate an active SIM swap. Act immediately:- Contact your carrier
- Change passwords
- Revoke active sessions
- Lock crypto accounts
- Use Hardware Security Keys for Crypto Exchanges
Most major exchanges support hardware keys, which make SIM swapping useless.
Final Thoughts: SIM Swapping Isnât Going Away, But Your Risk Can
SIM swapping remains one of the most dangerous and underestimated cybersecurity threats today. As recently as June 2026, cybersecurity expert Torsten George found himself targeted in a SIM swapping attack. Criminals successfully ported his phone number and attempted an account takeover by intercepting a one time password (OTP) meant for him. Fortunately, George recognized the signs immediately and contacted his carrier before the attackers could gain full control, a close call that underscores how real and active this threat still is.
As long as phone numbers continue to function as a form of identity verification, attackers will exploit them. The path forward is clear: move away from SMS based authentication and adopt phishing resistant security methods like hardware security keys, authenticator apps, and passkeys. With a few proactive steps, individuals and organizations can dramatically reduce their exposure to SIM swapping attacks and strengthen their overall security posture.
Show References
Joseph OâConnor (âPlugWalkJoeâ) â SIM Swapping & Twitter Hack
- U.S. Department of Justice. (2023, June 23). U.K. citizen sentenced to five years in prison for cybercrime offenses. United States Attorneyâs Office, Southern District of New York.
https://www.justice.gov/usao-sdny/pr/uk-citizen-sentenced-five-years-prison-cybercrime-offenses - Page, C. (2025, November 17). UK prosecutors seize ÂŁ4.11M from Twitter mega hack culprit. The Register.
https://www.theregister.com/2025/11/17/plugwalkjoe_confiscation_order/ - ITV News. (2025, November 17). British man behind celebrity scams ordered to repay over ÂŁ4m in Bitcoin. Yahoo News UK.
https://uk.news.yahoo.com/british-man-behind-celebrity-scams-ordered-to-repay-over-4m-in-bitcoin-174501676.html - Stephens, M. (2025, November 17). British cybercriminal ordered to pay ÂŁ4.1m over celebrity hacking scam. The Telegraph.
https://www.telegraph.co.uk/news/2025/11/17/british-cybercriminal-pay-41m-celebrity-hacking-scam/ - Cyberly News. (2025). British hacker ordered to repay more than ÂŁ4 million after global celebrity Twitter breach and multi platform crypto fraud. Cyberly News.
https://cyberlynews.com/british-hacker-ordered-to-repay-more-than-4-million-after-global-celebrity-twitter-breach-and-multi-platform-crypto-fraud/
Ellis Pinsky & Michael Terpin â SIM Swapping Case
- Terpin, M. (2019). Complaint for damages: Michael Terpin v. Ellis Pinsky et al.
https://www.documentcloud.org/documents/6119430-Michael-Terpin-v-Ellis-Pinsky-Complaint - Popper, N. (2019, May 10). Teenager accused of stealing $24 million in cryptocurrency. The New York Times.
https://www.nytimes.com/2019/05/10/technology/cryptocurrency-hacking-sim-swapping.html
Torsten George â 2026 SIM Swapping Attempt
- George, T. (2026, March 10). SIM swaps expose a critical flaw in identity security. SecurityWeek.
https://www.securityweek.com/sim-swaps-expose-a-critical-flaw-in-identity-security/ - Waldman, A. (2026, June 22). He thought he was secure; his phone number was stolen anyway. Dark Reading.
https://www.darkreading.com/attacks-breaches/he-thought-he-was-secure-his-phone-number-was-stolen-anyway - Gerber, G. (2026, June 28). He thought he was secure; his phone number was stolen anyway. SIGS Community Network.
https://www.sigs.com/news/he-thought-he-was-secure-his-phone-number-was-stolen-anyway - UNDERCODE News. (2026). He thought he was secure, until a SIM swap stole his number in silence: The hidden collapse of OTP security.
https://undercode.news/sim-swap-collapse-otp-security/
SIM Swapping Trends & FBI Data
- Federal Bureau of Investigation. (2024). Internet Crime Report 2024. Internet Crime Complaint Center (IC3).
https://www.ic3.gov/Media/PDF/AnnualReport/2024_IC3Report.pdf - Federal Bureau of Investigation. (2023). Internet Crime Report 2023. Internet Crime Complaint Center (IC3).
https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf