Cases of Sim-swap fraud—a cybercrime method where hackers hijack mobile phone numbers to gain control of victims’ digital lives—have soared more than tenfold in the past year, according to data from the UK’s National Fraud Database.
The database, run by fraud prevention body Cifas, recorded 2,826 unauthorised Sim-swap incidents in 2024, a sharp increase from just 289 in 2023. This form of fraud is increasingly being used to bypass two-factor authentication (2FA) and seize control of emails, financial accounts, and social media profiles. The method was reportedly used in cyberattacks targeting Marks & Spencer and the Co-op, where attackers tricked IT teams into resetting passwords.
Once a victim’s number is transferred to a new Sim—or increasingly, an eSim, which requires only digital activation—fraudsters can intercept security texts and calls, effectively assuming control over the person’s identity online.
“Phones are absolutely central to our lives,” said Simon Miller of Cifas. “Scammers are exploiting telecom vulnerabilities using personal data often sourced from the dark web. It’s incredibly damaging.”
Older adults have emerged as the most at-risk group: 29% of Sim-swap victims were over 61, according to the data. Cifas also warned that data protection laws, particularly GDPR, may be unintentionally discouraging data sharing between firms—hampering coordinated efforts to detect fraud.
A forthcoming report from the National Fraud Intelligence Bureau underscores the scale of the threat: Sim-swap fraud resulted in £5.35 million in losses over the past year, with eSim-related incidents spiking from 18 in 2022 to 763 in 2023. However, the report clarifies that eSims are not inherently more vulnerable—though criminals are quick to exploit new technologies.
One victim, a 64-year-old retired man from Surrey, known only as Alan, shared how quickly his identity was compromised. After receiving what seemed like a routine customer service call from a Vodafone impersonator, both his and his wife’s phones went offline within hours. Hackers had not only hijacked his number but redirected his email and attempted to spend thousands using his American Express and Barclays accounts.
“I’ve never suffered any theft or burglary, but that’s how I’m feeling,” Alan said. “It’s like your personal life has been invaded.”
The fraudsters used Alan’s information to request a transfer from a physical Sim to an eSim, allowing them to intercept all subsequent correspondence. Although the financial transactions were blocked, Alan said the emotional and logistical aftermath was severe. He’s now considering dumping his mobile number entirely.
The consumer group Which? has urged mobile users to set up additional security layers with their network providers and avoid posting sensitive personal information online.
With telecom companies pushing toward eSim adoption, experts warn that improved identity verification and cross-sector collaboration are critical to stemming the tide of digital identity theft.

