
Polish cybercrime officers, working with the FBI and US Homeland Security Investigations, have arrested four people connected to a SIM-swapping operation that stole the equivalent of at least $5 million in cryptocurrency. The gang broke into systems used by telecom partners and employee email accounts to gather personal data. They then used that information to convince mobile carriers to transfer victims’ phone numbers to SIM cards controlled by the attackers — a technique known as SIM swapping.
With the victim’s phone number in hand, the gang intercepted SMS verification codes, reset account passwords on cryptocurrency exchanges, and drained the balances. The stolen funds were then scattered through bank accounts and digital wallets worldwide to hide the trail. The suspects face up to 25 years in prison for organized crime, hacking, and money laundering.
How to check if you’re affected
Affected products include any mobile carrier account that protects cryptocurrency or financial logins using SMS text messages as the only form of two-factor authentication.
You likely aren’t directly targeted by this particular gang — arrests tend to disrupt these networks significantly. But SIM swapping is a widespread technique, and the best time to defend against it is before an attack happens:
- Switch from SMS codes to an authenticator app. Apps like Google Authenticator or Authy generate codes on your device and can’t be redirected by a SIM swap. Most crypto exchanges, banks, and email providers support this option under security settings.
- Call your mobile carrier and ask about a SIM lock or port freeze. Many carriers will add a PIN or note that prevents your number from being transferred without extra verification.
- Use a separate email address for financial accounts — one that isn’t publicly tied to you — so attackers can’t easily reset passwords using your known address.
