SIM Swap Scams: How Criminals Hijack Your Number for Cash
A SIM swap lets a thief take over your phone number without touching your phone. A fresh court case shows how the attack works — and how to stop it.

Your phone number is the master key to your digital life — your email recovery, your social accounts, your payment apps, your exchange logins. And a criminal does not need to steal your phone to take it. In a SIM swap, the attacker convinces your mobile carrier to move your number onto their SIM card. From that moment, every SMS code meant for you lands in their hands: password resets, login confirmations, withdrawal approvals. This week, a New Zealand court sentenced a man who ran exactly this play, and the details show how exposed anyone earning online really is.
A sentencing this week shows exactly how it works
In Auckland, 44-year-old Kiel MacGregor was sentenced for his role in an identity-theft ring that hijacked the phone numbers of customers of telecom provider Spark. The method was almost embarrassingly low-tech. MacGregor walked into Spark retail stores carrying an altered ID — a legitimate customer’s details, but his own photo — and asked staff to transfer the victim’s number to a new device he controlled. The staff, as the court heard, unwittingly helped him take over victims’ phones.
The court documents lay out what happened next in plain language: “After the victim’s phone number is swapped to the offender’s SIM, they receive authentication messages from the bank, allowing the transfer of large sums of money.” From one victim alone, MacGregor moved $33,082 from a personal account and $11,241 from a company account — more than $44,000 — and then impersonated the man again, using selfies with the forged licence, to buy $31,300 in Bitcoin through a local cryptocurrency exchange. The offending began in October 2022, and the judge noted MacGregor was not even the mastermind: “Other people had a far greater financial stake in what was going on.”
He is far from the only example. In September 2026, cybersecurity firm Cyble flagged SIM swapping as one of the year’s most damaging telecom attack patterns, noting that a single fraudulent number transfer bypasses almost every downstream security control at once. Cyble pointed to the case of Eric Council Jr., a 26-year-old from Alabama sentenced to 14 months in federal prison for his role in a SIM-swap scheme that took over an employee account tied to the SEC’s official X account, where the attackers posted a fake Bitcoin ETF approval that briefly moved markets. And in April 2026, a New Zealand man lost signal at 1:30pm, received a text saying his number had been swapped to a new SIM, and watched criminals reset his internet banking password via SMS and nearly drain $20,000 — all inside a 15-minute window.
The attack in four moves
- 1The harvest: the attacker collects your name, date of birth, phone number and ID details from data breaches, social media, or phishing. Creators and freelancers who publish a phone number for client work hand this over for free.
- 2The store call: posing as you, the attacker contacts your carrier — in person with a doctored ID, or by phone — and asks for a SIM replacement or number transfer. One distracted or careless agent is all it takes.
- 3The takeover: your phone silently loses service. You assume it is a network glitch. Meanwhile, every SMS verification code for your email, bank, exchange and social accounts arrives on the attacker’s phone.
- 4The drain: password resets are requested and confirmed, withdrawal OTPs are intercepted, and funds — especially crypto, which cannot be charged back — are moved out before you realise anything happened.
Why online earners are prime targets
Most people are bad targets because stealing their number yields a bank login and not much else. Online earners are different. Your phone number is often the recovery method for your email, which is the recovery method for everything else — a chain that ends at your earnings. If you get paid in USDT or other crypto, the payoff is instant and irreversible: there is no fraud department to reverse a blockchain transfer. A hijacked creator account is worth double — the attacker gets the wallet and then uses your trusted face to pitch fake giveaways to your followers, just as compromised brand accounts have been used to promote scam tokens. Only days ago, on 3 October, Microsoft confirmed that unknown attackers had seized its official X account to promote a fake “$Clippy” crypto token before the company regained control. If that can happen to a 13-million-follower corporate account, a solo earner’s SMS-only security is a soft target.
- Your number is public: clients, brands and collaborators often need your phone number — exactly the detail a SIM swapper needs.
- Your money is digital and instant: bank balances, mobile wallets and crypto payouts all unlock through the same SMS codes the attacker intercepts.
- Crypto payouts do not reverse: unlike a card chargeback, a drained wallet transfer is gone for good.
- Your audience is leverage: a hijacked account with followers becomes a launchpad for the next round of scams.
How to lock your number down
- 1Put a PIN or lock on your carrier account: call your network provider and ask for a SIM-swap lock, port-out protection, or an account PIN that must be given before any SIM change. This is the single most effective defence against the in-store attack.
- 2Move your 2FA off SMS: wherever you are offered a choice between text-message codes and an authenticator app, always choose the app. Security guidance published in September 2026 put it bluntly: authenticator-app 2FA is your best protection against SIM swap attacks.
- 3Remove your phone number as a recovery option where you can: on your email and exchange accounts, replace SMS recovery with an authenticator app or hardware key, so a swapped number no longer equals a password reset.
- 4Keep a separate number for public contact: use one number on your profiles, invoices and client chats, and a private number — known only to your bank and carrier — for account security.
- 5Watch for the warning sign: a sudden, unexplained loss of mobile service is the signature symptom of a SIM swap in progress. Treat it as an emergency, not a network outage.
If your phone suddenly loses signal
Contact your carrier immediately from another device and ask whether a SIM change was requested — if so, demand it be reversed now. Then, from a secure device, change the passwords on your email and exchange accounts, move 2FA to an authenticator app, and check for unrecognised logins, password-change emails, or withdrawals you did not make. Speed matters: in the reported cases, the money moved within minutes.
Keep your earnings where they belong
Scams evolve, but verified work does not. eBizEarn microtasks spell out exactly what to do and how rewards work — with payouts you can secure properly.
Share this article
eBizEarn Team
Writing for the eBizEarn blog — practical guides on social-media tasks, rewards, and staying safe online.
Related articles
SafetyFake Brand-Deal DMs: How Scammers Are Trapping Creators
Scammers are posing as brands in creators’ DMs, offering paid campaigns — then sending phishing links and QR codes. Here is the playbook and how to spot it.
SafetyThe WhatsApp Job That Starts at Rs 200 and Ends in Ruin
A WhatsApp text offers easy task work, pays Rs 200 on day one, then asks for deposits to unlock bigger earnings. September 2026 cases show how the trap closes.
SafetyThe Overpayment Trap: When a Client Pays You Too Much
A client ‘accidentally’ overpays you and asks for the difference back. It’s one of the oldest scams in online work. Here’s the playbook and how to stop it cold.

Translate