# SIM Swapping: The Cybersecurity Threat Still Stealing Millions in 2026 > By Johnathan Belcher — July 9, 2026 — 11 min read ## What Is SIM Swapping? Understanding the Attack Behind Modern Account Takeovers SIM swapping, also known as SIM hijacking or SIM port out fraud, is a cybersecurity attack where criminals trick a mobile carrier into transferring a victim's phone number to a SIM card controlled by the attacker. Once the attacker gains control of the number, they can intercept SMS two factor authentication (2FA) codes, password reset links, banking and crypto login alerts, and account recovery messages — giving them everything needed to perform a full account takeover, often within minutes. SIM swapping remains effective because it exploits a weak link in modern cybersecurity: phone numbers are still treated as identity, even though they're easy to steal. ## Real World SIM Swapping Cases: How Hackers Stole Millions in Cryptocurrency **Joseph O'Connor ("PlugWalkJoe"): $784,000 in Stolen Crypto** — O'Connor helped orchestrate a SIM swapping attack against a senior crypto company executive, siphoning $784,000 in digital assets before being arrested, extradited, and convicted. **Ellis Pinsky: $23.8 Million Stolen at Age 15** — At 15, Pinsky and his crew hijacked crypto investor Michael Terpin's phone number and stole $23.8 million in digital assets. Pinsky later went straight, earning degrees in computer science and philosophy and now educates others about the threats he once exploited. ## Why SIM Swapping Is Still a Major Cybersecurity Threat in 2026 1. SMS 2FA is still common across banks, crypto exchanges, and financial platforms. 2. Mobile carriers are susceptible to social engineering (impersonation, weak verification, bribery). 3. Personal data is everywhere thanks to breaches, OSINT tools, and leaked databases. 4. Cryptocurrency transfers are instant, irreversible, and easily laundered. 5. High-value targets (investors, influencers, executives) are easy to identify publicly. ## How to Protect Yourself From SIM Swapping 1. Stop using SMS for two-factor authentication — use authenticator apps, hardware security keys, or passkeys instead. 2. Add a carrier port-out PIN or account security code. 3. Avoid phone-number-based account recovery; prefer email or app-based recovery. 4. Reduce personal data exposure (data broker removal, limit social media details, separate "public" email). 5. Use a private number reserved exclusively for MFA. 6. Watch for sudden loss of mobile service as a sign of an active SIM swap, and act immediately (contact carrier, change passwords, revoke sessions, lock crypto accounts). 7. Use hardware security keys for crypto exchanges, which make SIM swapping useless. ## Final Thoughts As long as phone numbers continue to function as a form of identity verification, attackers will exploit them. The path forward is moving away from SMS-based authentication toward phishing-resistant methods like hardware security keys, authenticator apps, and passkeys.