A SIM card is, effectively, a portable identity token. Once compromised, it gives attackers a back door into bank accounts, digital wallets, investment apps and other high-risk transactional environments. As a result, SIM card fraud exposes individuals and institutions to cascading financial and compliance risks.
SIM swap fraud, identity impersonation and large-scale SIM-farm operations are no longer fringe problems. Instead, they now function as industrialised criminal enterprises operating at scale.
The Communications Risk Information Centre 2025 Telecommunications Sector Report found that telecoms fraud, including SIM-swap, subscription, and identity fraud, cost South Africa around R5.3 billion in 2024. That figure reflects a broader truth.
The SIM card as an identity vulnerability
Every SIM-based attack is an identity-based attack. In turn, every identity-based breach cascades directly into AML, fraud and financial crime risk, making SIM card fraud a systemic concern rather than a technical anomaly.
The SIM card’s central role in Identity Verification (IDV) makes it an attractive target for sophisticated cyber and financial criminals. From SIM swap scams used to plunder victims’ bank accounts to widespread identity impersonation campaigns, SIM-related crime continues to proliferate in South Africa and globally. Increasingly, SIM card fraud underpins these attacks by exploiting weak authentication dependencies.
SIM crime is no longer a side-issue sitting at the edges of the financial system. It has become a central threat to identity integrity itself and therefore to the foundations of digital banking, payments, fintech and regulatory compliance. And criminals understand this better than anyone.
SIM cards have emerged as a vulnerability because we use them not only to access telecoms services, but also to authenticate ourselves to digital banking platforms and other online services. Consequently, SIM swaps remain one of the most dangerous cybercrimes that South Africans face today, and a core enabler of SIM card fraud.
How SIM swap attacks work
This occurs when a criminal convinces a mobile network to transfer a phone number to a new SIM card under their control. They usually achieve this using personal information stolen in phishing attacks or purchased on the dark web.
Once the transfer happens, the criminal intercepts calls and text messages, including OTPs. This access allows them to enter online accounts and drain funds.
A SIM card is, effectively, a portable identity token. Once compromised, it gives attackers a back door into bank accounts, digital wallets, investment apps and high-risk transactional environments. Put plainly: the SIM card has become the weakest link in the identity chain.
The rise of SIM farms
Under the Regulation of Interception of Communications and Provision of Communication Related Information Act (RICA), networks must register all SIM cards with users’ ID numbers and proof of address. However, South Africans frequently swap SIMs. In addition, RICA-authorised SIMs remain freely available at repair shops and informal trading outlets. As a result, RICA has not stopped SIM crime or reduced SIM card fraud at scale.
Combatting SIM-related crimes has become even harder with the advent of SIM farms. These are often cross-border operations run at massive scale. A SIM farm is a device that houses many SIM cards. It allows criminals to industrialise identity impersonation campaigns behind prepaid or stolen SIMs, significantly amplifying SIM card fraud.
Where businesses underestimate IDV
Each illegal SIM in circulation represents a counterfeit identity. This opens material risks for organisations and end-users alike. Businesses remain especially vulnerable when they rely on SMS-based OTPs for multi-factor authentication (MFA). Criminals exploit swapped SIMs to steal user data and funds across banking, fintech and e-commerce apps.
What’s more, banks spend tens of millions of rand annually on expensive SMS OTPs. They also absorb the cost of false positives, failed message deliveries and repeated know your customer (KYC) re-verification following SIM swaps. In this context, SMS-based MFA is simply not sufficient to outsmart identity thieves behind SIM card fraud. The industry’s dependency on SMS-based MFA has created a false sense of security.
While OTPs play an important role, they are far too vulnerable to stand alone:
- While advanced deepfake attacks can bypass weaker biometric systems, strong smartphone security such as FaceID significantly raises the barrier to entry. These systems verify that a real, live face matches the enrolled user. In parallel, AI-based IDV can detect subtle lighting or textual inconsistencies to identify manipulated images.
- Companies can also deploy behavioural intelligence. This approach uses digital identity data, transactional histories and typical online behaviours to build profiles that criminals struggle to replicate.
- Push-notification MFA provides another layer of defence. It approves actions through a pre-registered device or app, without relying on the vulnerable SMS network.
- Other tools, such as Google Authenticator or hardware security keys, operate independently of phone numbers. As a result, they remain far less susceptible to SIM attacks and SIM card fraud.
Modern identity verification needs to be layered, risk-based and adaptive. These technologies exist. The problem is not capability. It’s coordination.
A call for cooperation
2FA and SMS OTPs form the backbone of digital authentication. However, they also represent a structural flaw in the financial ecosystem’s defences against financial crime.
Siloed KYC and IDV operations significantly contribute to this vulnerability. When a SIM swap occurs, criminals can instantly access messaging platforms, impersonate victims and solicit money from their contacts. For this reason, unified data intelligence has become essential in tackling SIM card fraud.
Telcos know when SIM swaps occur. Banks know when high-risk transactions spike. Regulators see emerging patterns first. But these signals remain unshared or shared too slowly to matter. This is where RegTech needs to step in.
All accountable institutions should form a proactive compliance ecosystem that identifies threats before they proliferate. This requires cross-sector collaboration and stronger frameworks for KYC and anti-money laundering (AML) compliance, even where data privacy standards differ.
Technology, monitoring and public education
Using technology to facilitate IDV provides an obvious starting point for sharing intelligence about suspect users and transactions. Mobile networks, financial institutions, regulators and prosecutors can act more decisively when they share verified data.
With instant vetting, organisations can onboard customers faster while authorities respond to alerts. However, IDV alone is not enough. Continuous monitoring of customer behaviour and transactions remains critical to detect emerging risks, accelerate investigations and maintain auditability.
Public education also plays a crucial role. Users must understand SIM crime, their
responsibility in protecting their identities, and where to seek help. Clear guidance from service providers strengthens consumer resilience. In turn, compliant businesses provide leadership that helps build a broader network to combat SIM fraud and SIM card fraud more effectively.
A SIM compromise is never just a telecom incident. It’s an AML incident. It’s a fraud incident. It’s a financial crime incident. Every weak link – every unverified identity, every siloed database, every unreported SIM swap – gives criminals a foothold. To reclaim identity integrity, the ecosystem must move as one.
Bradley Elliott | CEO | RelyComply | mail me |




























