Skip to content
Back to Blog
high severity August 26, 2026 · 5 min read Unverified claim — what this is

SIM swap fraud in the UK hit nearly 3,000 cases — does it affect you?

If you are a customer of SIM swap fraud in the UK, here’s what is being claimed, and what it would mean for you.

Cifas confirmed unauthorised SIM swaps in the UK rose 1,055% in 2024, to nearly 3,000 cases. Criminals moved a person’s mobile number without consent and used the texts that followed to get into accounts. Police estimated £5.35 million was lost to this fraud across 2023 and 2024.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
SIM swap fraud in the UK hit nearly 3,000 cases — does it affect you?

In 2024 the UK fraud-prevention service Cifas recorded a 1,055% rise in unauthorised SIM swaps filed to its National Fraud Database — from 289 cases in 2023 to nearly 3,000. In those cases a person’s mobile number was moved to a different SIM without their consent, so login codes and password-reset texts went to someone else, who then took over accounts.

Watch SIM swap fraud in the UK

Get alerted the next time SIM swap fraud in the UK files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.

We’ll email you only about SIM swap fraud in the UK’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.

Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals — $499/mo or $4,990/yr.

Cifas published the figures in its Fraudscape 2025 report on 3 April 2025 and in a newsroom statement on 7 May 2025. A police National Fraud Intelligence Bureau report, cited by The Times on 11 May 2025, put estimated losses from SIM-swap fraud at £5.35 million across 2023 and 2024. Later Cifas figures showed the rise did not stop there: unauthorised SIM swaps went up a further 38% in 2025.

The headlines count cases. They skip what the attacker actually holds

Coverage has led with the percentage, the round number, and the £5.35 million. Those figures are real. They are also the wrong shape if you are trying to work out whether this has anything to do with you.

This was not a hack of one company that spilled a file of customers. Cifas did not lose a database. There is no public list of the people inside those nearly 3,000 filings, and nothing a website can scan will tell you whether your number was one of them. The filings are reports from organisations that spotted a swap. If it happens to you, you will not hear it from a headline. You will hear it when your phone loses signal and the texts your bank thinks it is sending to you arrive on a handset you have never seen.

What most write-ups also skip is that the criminals usually did not break into the mobile network. They persuaded it. Networks still identify customers with the ordinary personal details that have been sitting in old breaches, people-search sites and the open electoral register for years — a name, a current address, a date of birth, sometimes a previous address or the name of someone in the household. The 1,055% jump is not news that a new cache of private data was allegedly stolen in 2024. It is news that using that already-public pack of details to take a phone number now works, thousands of times a year.

Once the number has moved, the attacker is not reading your family chat. They are receiving the codes that banks, email providers and government services still treat as proof it is you. For a few hours they are you, as far as those services can tell. Giving you a replacement SIM later does not unread those codes or put money back.

What to actually expect

  • You will not get a letter or email confirming you were, or were not, one of the 2024 cases. Any message that offers to “check if you were affected” is not from Cifas or the police. Ignore it — stories like this are regularly followed by fake alerts.
  • The live warning is practical, not postal: sudden loss of signal, a network message about a SIM or number move you did not request, or a bank or email alert about a login or reset you did not start.
  • If you genuinely need a new SIM or to switch network, staff may ask more questions than they used to. That is a direct result of these figures, not proof you have already been hit.
  • This did not end in December 2024. Cifas later recorded another 38% rise in 2025, so the same method is still being used against UK numbers.

What you can and cannot fix

The swaps that already happened cannot be undone in the way that matters. Codes received during those windows cannot be unread. Money already moved is a matter for the bank, not a reset button. The older personal details used to request the swaps were already in circulation; they cannot be recalled. And nobody can run your name against the 2024 filings and give you an all-clear — that database is not a public lookup, and a “clean” result from any website would not mean you were safe.

This incident did not publish a new list of home addresses or national insurance numbers. What it showed is that a phone number is still being treated as your identity, and that a name becomes dangerous when it is joined to the extra facts that people-search listings still sell: relatives, phone numbers, employers and previous addresses. Those listings, unlike old leaked files, can actually be taken down.

  • Put a block on the number itself. Call your mobile network from a working phone and ask them to add a passcode or extra restriction on SIM changes and number moves, so quoting your name and address is not enough. That is the step that matches this fraud.
  • Stop relying on texts to prove it is you. Where your bank or email lets you approve logins in their own app instead of by text, turn that on and turn the texts off. The cases Cifas counted were built on those texts.
  • Shrink the public pack of details used to impersonate you. Remove or suppress people-search and directory listings that show your address, old addresses and who you live with. A bare name is weak. The same name joined to a household, a previous address and a phone number is what a call-centre check looks like — and unlike a leaked file, those listings can be taken down.
  • If the phone dies and you did not ask for a new SIM, use another phone and contact the network first to report a suspected unauthorised swap, then your bank, then your main email, in that order. Assume any reset texts may already have gone to someone else.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on SIM swap fraud in the UK.

  1. Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Check your exposure
SIM swap fraud in the UK is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High includes account details that can be misused directly
Disclosed August 26, 2026
Last reviewed August 26, 2026
Affected Unconfirmed
Data exposed Phone numbersSMS login codesaccess to bank and email accounts
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email