SIM Swapping: The Cybersecurity Threat Still Stealing Millions in 2026

by Johnathan Belcher 📅 July 9, 2026 ⏱️ 11 min read
SIM swapping cybersecurity concept image

What Is SIM Swapping? Understanding the Attack Behind Modern Account Takeovers

Recently, I watched a YouTube deep dive into some of the most notorious SIM swapping cases and how hackers used this social engineering exploit to steal millions of dollars from high profile investors, executives, and even celebrities. What shocked me most wasn’t just the scale of the crypto thefts, but the attackers themselves. Some were barely teenagers, sitting behind a computer screen, yet capable of pulling off some of the most brazen account takeover attacks in modern cybersecurity history.

But before we get into those stories, it’s important to understand the core exploit that made all of this possible. Let’s take a closer look at the SIM swapping attack that powered these multimillion dollar heists.

SIM swapping, also known as SIM hijacking or SIM port out fraud, is a cybersecurity attack where criminals trick a mobile carrier into transferring a victim’s phone number to a SIM card controlled by the attacker. Once the attacker gains control of the number, they can intercept:

  • SMS two factor authentication (2FA) codes
  • Password reset links
  • Banking and crypto login alerts
  • Account recovery messages

This gives the attacker everything they need to perform a full account takeover, often within minutes.

SIM swapping remains effective because it exploits a weak link in modern cybersecurity: phone numbers are still treated as identity, even though they’re easy to steal.

Real World SIM Swapping Cases: How Hackers Stole Millions in Cryptocurrency

Joseph O’Connor (“PlugWalkJoe”): $784,000 in Stolen Crypto

Joseph O’Connor, known online as “PlugWalkJoe,” was an infamous hacker who helped orchestrate a SIM swapping attack against Greg Bennett, a senior executive at a major cryptocurrency company. With a combination of social engineering and precise timing, O’Connor and his co conspirators convinced the carrier to transfer Bennett’s phone number to a SIM card under their control, a single successful port out that opened the door to Bennett’s digital life.

Once the attackers seized control of his number, the situation escalated quickly. Password resets began firing. Authentication codes flowed straight into their hands. Within minutes, O’Connor’s crew breached Bennett’s crypto accounts and siphoned $784,000 in digital assets, leaving the executive locked out and unaware until the damage was already done.

O’Connor was eventually arrested, extradited, and convicted. This serves as a high profile reminder that SIM swapping isn’t an obscure cybercrime but a mainstream, highly effective attack vector capable of dismantling even well protected financial accounts.

Ellis Pinsky: $23.8 Million Stolen at Age 15

Ellis Pinsky was only 15 years old when he became the unlikely mastermind behind one of the largest SIM swapping crypto thefts ever recorded. Operating from his suburban bedroom, Pinsky and his crew set their sights on Michael Terpin, a well known cryptocurrency investor whose public profile made him an irresistible target for these types of hackers.

The attack began with a quiet but devastating move: hijacking Terpin’s phone number. Once the SIM swap succeeded, the group gained full control over Terpin’s SMS messages, authentication codes, and password resets. What followed was swift and surgical. Within minutes, Pinsky’s team breached Terpin’s crypto accounts and siphoned out $23.8 million in digital assets, leaving Terpin locked out and scrambling to understand how his entire portfolio had vanished overnight.

The sheer scale of the theft, combined with the attacker’s age, shocked the cybersecurity world. Terpin later described Pinsky as “Baby Al Capone,” underscoring how SIM swapping has evolved into a high stakes attack vector capable of empowering even teenagers to execute multimillion dollar heists.

Today, Pinsky has stepped away from the world of illicit hacking. He went on to earn degrees in computer science and philosophy, redirecting his skills toward cybersecurity and using his experience to educate others about the online threats he once exploited.

Why SIM Swapping Is Still a Major Cybersecurity Threat in 2026

You might assume that after nearly a decade, this security weakness would have been fixed. It hasn’t. Despite growing awareness in the cybersecurity community, SIM swapping remains a widespread and rapidly evolving threat. Here’s why:

  1. SMS 2FA Is Still Common
    Many banks, crypto exchanges, and financial platforms still rely on SMS verification codes, making them vulnerable to SIM hijacking.
  2. Mobile Carriers are Susceptible to Social Engineering
    Attackers impersonate victims, exploit weak verification processes, or even bribe employees. A single successful call can compromise an entire digital identity.
  3. Personal Data Is Everywhere
    Data breaches, OSINT tools, and leaked databases give attackers everything they need to impersonate victims convincingly.
  4. Cryptocurrency Is a Prime Target
    Crypto transfers are instant, irreversible, and easily laundered through mixers or cross chain bridges.
  5. High Value Targets Are Easy to Identify
    Crypto investors, influencers, and executives often reveal holdings publicly, making them ideal targets for SIM swapping attacks.

SIM swapping persists because the underlying infrastructure hasn’t evolved and it remains simple, scalable, and profitable.

How to Protect Yourself From SIM Swapping (Practical Cybersecurity Tips)

  1. Stop Using SMS for Two Factor Authentication
    This is the most important step. Replace SMS 2FA with:
    • Authenticator apps (Authy, Google Authenticator, Microsoft Authenticator)
    • Hardware security keys (YubiKey, Google Titan)
    • Passkeys, where supported
    SMS should be considered insecure for any high value account.
  2. Add a Carrier Port Out PIN
    Most carriers allow you to set a port out PIN or account security code. This adds friction for attackers attempting unauthorized number transfers.
  3. Avoid Phone Number Based Account Recovery
    Use email based or app based recovery methods whenever possible.
  4. Reduce Your Personal Data Exposure
    Attackers rely on personal information to impersonate victims. Improve your cybersecurity posture by:
    • Removing yourself from data broker sites
    • Limiting personal details on social media
    • Using a separate “public” email for online profiles
  5. Use a Private Number for Sensitive Accounts
    Some cybersecurity professionals maintain a second phone number used exclusively for MFA and it’s never shared publicly.
  6. Watch for Sudden Loss of Mobile Service
    If your phone unexpectedly loses service, it may indicate an active SIM swap. Act immediately:
    • Contact your carrier
    • Change passwords
    • Revoke active sessions
    • Lock crypto accounts
  7. Use Hardware Security Keys for Crypto Exchanges
    Most major exchanges support hardware keys, which make SIM swapping useless.

Final Thoughts: SIM Swapping Isn’t Going Away, But Your Risk Can

SIM swapping remains one of the most dangerous and underestimated cybersecurity threats today. As recently as June 2026, cybersecurity expert Torsten George found himself targeted in a SIM swapping attack. Criminals successfully ported his phone number and attempted an account takeover by intercepting a one time password (OTP) meant for him. Fortunately, George recognized the signs immediately and contacted his carrier before the attackers could gain full control, a close call that underscores how real and active this threat still is.

As long as phone numbers continue to function as a form of identity verification, attackers will exploit them. The path forward is clear: move away from SMS based authentication and adopt phishing resistant security methods like hardware security keys, authenticator apps, and passkeys. With a few proactive steps, individuals and organizations can dramatically reduce their exposure to SIM swapping attacks and strengthen their overall security posture.

Show References

Joseph O’Connor (“PlugWalkJoe”) — SIM Swapping & Twitter Hack

Ellis Pinsky & Michael Terpin — SIM Swapping Case

Torsten George — 2026 SIM Swapping Attempt

SIM Swapping Trends & FBI Data

← Back to Blog