SIM Swap Fraud

SIM swap fraud occurs when cybercriminals convince mobile providers to transfer a user’s phone number to their device, enabling them to bypass two-factor authentication and access sensitive information, and it’s on the rise.

Get in touch

The recent cyberattack targeting Marks & Spencer and Co-op represents a concerning example of the growing threat posed by SIM swap fraud.

While investigators are still uncovering the full technical details, reporting from The Times indicates that attackers employed this technique to infiltrate M&S and Co-op’s internal systems—likely by compromising an employee's mobile number and subsequently convincing IT personnel to reset critical access credentials.

SIM swap fraud has evolved into an increasingly dangerous and widespread attack vector. CIFAS, the UK's national fraud prevention service, reports an alarming tenfold increase in SIM swap incidents—rising from fewer than 300 cases in 2022 to nearly 3,000 in 2023.

At Croft, we have strengthened identity verification practices to reduce the risk of SIM swap fraud.

If we manage your mobile account, submit your details, and one of our mobile team members will contact you to add SIM swap fraud protection to your account.

Request to opt into SIM swap fraud protection

You are currently viewing a placeholder content from HubSpot. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.

More Information

How Does SIM Swap Fraud Work?

SIM swap fraud represents a sophisticated threat to digital security. This attack occurs when cybercriminals persuade a user’s mobile carrier to transfer the user’s phone number to a device they control, either through a new physical SIM card or an eSIM, mainly to bypass two-factor authentication.

These transfers can occur through various channels, including phone calls where scammers impersonate an employee or through online support chats.

The consequences are immediate and severe. Once your number is transferred, all communications intended for you, including calls, text messages, and, critically, one-time security codes (2FA), are diverted to the fraudster's device. This gives them potential access to your email accounts, sensitive business information and business portals that rely on phone verification.

The recent M&S breach highlights the escalating threat posed by this type of attack. Cybercriminals apparently exploited SIM swap techniques to infiltrate the company's systems, bypassing security protocols and gaining unauthorised access to sensitive internal processes.

This high-profile incident reveals a critical vulnerability: numerous organisations continue to use phone numbers as a verification method for employee authentication, inadvertently exposing themselves to the same tactics that have proven effective against individual consumers.

This increasingly common attack methodology demands immediate attention and proactive security measures from businesses of all sizes.

What is Croft Doing About SIM Swap Fraud?

We have strengthened identity verification practices to mitigate the risk of SIM swap fraud.

If your business mobile services are managed by Croft we have added an extra step to the verification process when requesting a SIM swap.  You can opt in to setting up a password for your account, which you will need to provide when requesting a SIM swap on your business account. The password will change monthly to add an extra layer of security.

To opt in, please fill out the form on this page to protect your account against this threat.

SIM card fraud expert working on a mobile phone

Other Ways to Reduce the Risk of SIM Swap Fraud

There are additional steps your organisation and employees can take to reduce the risks of SIM swap fraud, these include:

Be selective about sharing personal information online. Limit where you share your business phone number, invoice information, and other personal identifiers that could help criminals impersonate an employee to service providers.

Security Awareness Training. Understanding how phishing attempts work enables you and your team to identify suspicious communications and avoid submitting sensitive information to fraudulent websites. Deploy security awareness training in your organisation to educate your employees about phishing attacks.

Upgrade your authentication methods. Whenever possible, move beyond SMS-based verification to more secure options like Google Authenticator, Microsoft Authenticator, Duo, or Authy—none of which rely on your mobile number. Croft can assist your organisation in setting these up.

Protecting your business requires partnership between you and your service providers. At Croft MSP, we're committed to helping you implement comprehensive security strategies that address evolving threats.

Some of our clients

Testimonials

What our clients say

Our move to Croft went seamlessly. We received great service from people who value our business and we are saving money as a business. What’s not to like?

Laurent Perrier

David Hesketh, Managing Director

Croft has supplied our mobile telephone contract for over ten years including assisting us with moving our fleet of over 500 numbers to the EE network. The support and account management received have been exceptional. We are extremely satisfied with the team at Croft and look forward to the relationship continuing in years to come.

T. Rowe Price

Jo Smyth, Production Support Analyst

I would highly recommend Croft who provided us with the perfect solution when it was time to review our mobile communications contract. They guided us through the transfer process from our previous supplier and everything went very smoothly.

A1 Automotive

Jim Kecheran, General Manager

What a refreshing change – excellent service is a rare thing these days and it’s great to know it still exists at Croft!

I can’t thank them enough for all the support over the past month. Their advice and help have been absolutely amazing and I’m not sure what I would have done without their team stepping in. I’ve just been so impressed with every single person I have spoken to.

Heehaw Digital

Gillian Somerville, Office Manager

Partners and Accreditations

Croft business mobile services Vodafone logo
Croft business mobile services O2 logo
Croft business mobile services EE logo
Croft business mobile services Three logo
Croft accreditations Cyber Essentials Plus logo
Web filtering and alrting Microsoft Solutions Partner logo

Discuss challenges. Get Solutions

Speak to one of our business mobile specialists about your technology challenges.

Get in touch

You are currently viewing a placeholder content from HubSpot. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.

More Information